Ask these five questions before you sign, not after. Most AI procurement risk for a law firm is created at this stage, not at the point of use, because a demo shows you what a tool does and tells you nothing about where your data goes, who controls it, or what happens when you leave.
Can the vendor show you where your data actually goes?
Ask for verifiable data-flow transparency, not a sentence in a sales deck. That means a vendor who can show you, concretely, which systems and subcontractors touch your case data between upload and output, not just tell you it is “secure.” Ours is written down in plain terms on how we protect your data.
Do the contract terms stop your data being reused or moved abroad?
A vendor’s privacy policy can change. Your contract should not let it, without your consent. Ask for contractual restrictions with real force behind them on secondary use of your data and on cross-border transfer, so a policy update six months in cannot quietly change where your clients’ information ends up.
Who controls where your privileged data is processed?
Client data crossing into a jurisdiction with weaker safeguards, or being processed by a subcontractor you were never told about, is a risk you cannot see from a demo. Ask for jurisdictional control over where privileged data is processed, in writing, not as a default you have to go looking for. Our security page sets out where processing happens and under what controls.
Can the vendor explain how the model reached its output?
“The AI wrote it” is not a defence a fee earner can stand behind when a document goes on the record, and courts have already made that point about litigants in person, let alone regulated firms. Ask for model-level explainability: can the vendor show you why a tool produced a particular output, not just that it produced one.
Our own answer, and its limits. A figure in a LegalDocs Assist output is either taken verbatim from the document it came from or computed in code from figures that were. The model drafts the prose around them, it does not calculate. The Confirm screen shows extracted facts next to the source document they were drawn from so a fee earner can check them before signing, although lists such as treatment events and schedule of loss headings are not on that screen yet and are on the build. On the impecuniosity assessment, where the figures matter most, a provenance gate records how each one was derived and an independent re-derivation checks the finished passage against a separate calculation before it reaches the file.
What happens to your data when you leave?
This should be certain before you sign, not negotiated on the way out. Ask exactly when data is deleted, whether deletion is verifiable, and whether copies survive in backups, logs, or a vendor’s own training data. Exit and deletion certainty is the question firms ask least and need most.
Where does this framework come from?
These five questions echo a procurement framework set out by Eleonora Dimitrova in a guest piece for Legal Futures this month, arguing that AI regulatory risk for law firms is created at procurement stage, not at the point of use. It is an opinion piece, not SRA guidance, but it is a useful checklist worth putting to any vendor, including us.
FAQ
What should a firm ask an AI vendor before signing a contract?
Five things: where your data actually flows, whether the contract restricts secondary use and cross-border transfer, who controls where privileged data is processed, whether the vendor can explain how the model reaches its output, and what happens to your data when you leave.
Why does it matter where an AI vendor processes privileged data?
Client data crossing into a jurisdiction with weaker safeguards, or being processed by a subcontractor you were never told about, is a data protection and privilege risk you cannot see from a demo. You need contractual and technical control over location, not just a promise.
What is model-level explainability and why does a law firm need it?
It is the vendor’s ability to show why a tool produced a particular output, not just that it produced one. For legal drafting, that matters because a fee earner has to be able to stand behind the document, and "the AI wrote it" is not an accepted defence for an error.
What happens to a firm’s data when it stops using an AI vendor?
That should be contractually certain before you sign, not negotiated on the way out. Ask exactly when data is deleted, whether deletion is verifiable, and whether any copies survive in backups, logs or a vendor’s own model training data.
Craig Budsworth (FCILEx) writes on AI and legal process for LegalDocs Assist.
LegalDocs Assist is the AI document tool built for claimant law firms. See it in action or get in touch.
© LegalDocs Assist. www.legaldocs-assist.co.uk