Skip to Content (custom)

Angle

Protecting Your Law Firm in the Age of AI: It’s Time To Build Walls  

  • Law Firm Advisory

Key Takeaway: Generative AI offers transformative value for law firms. Realizing this value requires integrating information from multiple internal repositories. This creates significant risk, including inadvertent breaches of ethical screens, non-compliance with client outside counsel guidelines (OCGs), and unauthorized internal exposure to highly sensitive firm data. Safely scaling AI requires sophisticated information barriers that automatically enforce complex security controls, integrate directly with leading platforms like Claude, Harvey, and Legora, and deliver defensible audit trails that satisfy clients and firm leadership alike.

Law firms are making significant investments in generative AI to reshape how they engage and deliver service to clients. But giving lawyers the best AI experience requires giving AI tools like Harvey, Legora, and Claude broad access to firm information and intelligence. That means allowing AI to index, retrieve, and synthesize work product, communications, and other sensitive internal operational data.

Unfortunately, these AI tools do not understand how to enforce confidentiality in context, and confidentiality is critical to the practice of law. Without real-time access controls at the point of retrieval, a single prompt may bypass an ethical wall, violate an outside counsel guideline (OCG), or expose highly confidential HR and financial information to personnel who shouldn't see it.

AI Providers Are Embracing “Confidentiality-Aware” AI

Recognizing that serving law firms means addressing a strict set of professional responsibility, conflicts, confidentiality, and security requirements, AI providers are enhancing their offerings to support law firms’ must-haves related to those concerns.
 
The only effective, defensible way to do this at scale is to connect a firm’s tools with its existing confidentiality systems of record. This begins with building supported integrations to assimilate access policies from industry-standard applications like Intapp Walls. That way, these AI tools can then ingest client, matter, user, and group permissions, enforce real-time restrictions, and deliver auditable compliance logs.

This strategy makes perfect sense from an engineering standpoint. Replicating the decades of software research and development work baked into confidentiality management software, including nuanced functionality responding to the intricacies of legal conflicts, client terms, and professional responsibility, lies outside the core expertise of AI providers focused on generative reasoning. It also represents a governance and risk burden that AI providers are wise to leave to expert systems.

Harvey presents the textbook example of this approach. Harvey announced its Intapp partnership in early 2026 and released a direct Intapp Walls connector in July 2026. In August 2026, Legora quickly followed suit, announcing an even broader Intapp partnership.

Managing AI Risk: The Three Approaches Firms Are Taking to Confidentiality Management

As law firms evaluate integration and wait for other AI providers to release comparable integrations, they are taking different paths to align their data infrastructure and security models to support broader AI adoption. Three approaches, each with its own persona and call-to-action, predominate:

Profile One: The Eager Executors

Approach: "Put critical security infrastructure in place today; extend controls to AI tools as they enable integration."

To properly secure cloud AI tools such as Harvey, firms need a cloud-native compliance system of record in place that is ready to integrate. That’s why many firms are adopting the latest cloud iteration of Intapp Walls as their core security layer. Leveraging nearly two decades of market leadership, Intapp Walls now includes capabilities specifically designed to govern AI confidentiality. 

As AI providers build out native integration pathways to consume Intapp's centralized rules intelligence, eager executors ensure that their security architecture is ready, allowing them to move rapidly and accelerate broad internal adoption with confidence.

Advice: Deploy Intapp Walls in the cloud, configure unified matter policies, and establish direct AI integrations with guidance from a qualified advisor.

Profile Two: The Pragmatic Planners

Approach: "Monitor the market; tie investment to native AI integration releases and peer references."

Firms moving at a more deliberate pace prioritize active diligence over early deployment. These firms first assess the requirements for adopting Intapp Walls in the cloud, implementing integrations, and configuring a unified environment.

Pragmatic planners evaluate how early adopters navigate these rollouts. They base investment decisions on validating provider functionality and integrations, verifying peer references, and learning from the real-world success of other firms.

Advice: Assess Intapp Walls cloud migration readiness by working with an experienced partner to document the current on-premises framework, map security rules, define migration requirements, and develop a cost-effective implementation plan.

Profile Three: The Document Management System Traditionalists

Approach: “Native document management system (DMS) security is all we need. Full speed ahead!"

Some firms take the position that the access controls set in their DMS provide sufficient protection for AI. Rather than implementing dedicated external information barrier software, they rely entirely on the native security and policy management provided by tools like iManage. 

This approach controls AI tools connected only to the DMS but does not extend restrictions to network file shares, Microsoft SharePoint, Microsoft Teams, or other repositories where many firms store significant amounts of sensitive data.

This creates long-term compliance risk and significant exposure if AI adoption extends to incorporate data sources beyond the DMS.

Advice: Take stock of your existing data estate and AI exposure. Assess the data footprint and confidentiality controls, identify governance gaps, and implement required improvements.

Pointing the Way: Readiness Accelerates Adoption

Every law firm must confront a simple reality: the speed of generative AI innovation continues to outpace ad-hoc approaches to information security.

Repository-level permissions or independently developed AI controls may provide limited short-term protection. But in practice, this strategy postpones the necessary governance work while exposing a firm to significant risk.

The firms best positioned to capitalize on legal AI are not necessarily those rushing to deploy every new tool on day one. Rather, they are the firms ensuring that they have a centralized, cloud-native confidentiality system of record ready today. They are ensuring that whenever they choose to activate platforms such as Harvey, Claude, Microsoft 365 Copilot, or others, their security posture is already compliant, defensible, and ready to scale tomorrow.

Learn more about Epiq Intapp Walls Implementation and Consulting.

Praj Kulkarni
Praj Kulkarni, Senior Director
Praj Kulkarni leads Intapp technical operations at Epiq, partnering with clients to solve complex challenges across technology, business processes, data integration, and policy. Praj has delivered dozens of successful deployments and change management initiatives, focusing on managing client projects and supporting client care and managed solutions.


The contents of this article are intended to convey general information only and not to provide legal advice or opinions.

Subscribe to Future Blog Posts

Learn more about Epiq's Service offerings
Our Services
Related

Related

Related