Competence
The opinion treats understanding a tool’s benefits and risks as part of competence — not optional literacy. In practice that means your people need to know what the system can and cannot see, and why it sometimes refuses.
LEGAL AI & AUTOMATION FOR LAW FIRMS
A firm can buy a capable model this afternoon. What it cannot buy is a system that inherits every matter permission, cites only what it can point at, refuses the questions it should refuse, and leaves a record a partner can supervise. That is the build.
Deployed inside your own Azure or AWS environment.Not a wrapper around a consumer chatbot, and not a tool that learns from your matters.
“Which documents in this matter cap indemnity, and where does each one sit?”
What comes back
Eleven documents, each with the clause quoted and a link to the exact page in the document management system. Two disagree with each other, and that disagreement is flagged rather than reconciled.
What a lawyer still does
The lawyer opens the two that conflict. The system has found them; it has not decided which one governs.
ON THE RECORDQuery, documents returned, permission set applied, timestamp, user.
01 / THE TEST EVERY LEGAL AI TOOL HAS TO PASS
ABA Formal Opinion 512, issued 29 July 2024. It does not prohibit these tools. It sets out the duties they have to be built around, which is a far more useful thing for a buyer.
The opinion treats understanding a tool’s benefits and risks as part of competence — not optional literacy. In practice that means your people need to know what the system can and cannot see, and why it sometimes refuses.
Client information cannot simply be fed into a tool. Where a tool learns from inputs or shares an environment across firms, informed consent may be part of the analysis. Building inside your own tenant removes most of that question rather than answering it.
In some circumstances clients need to be told how these tools are used in their matter. That is a firm decision, not a vendor one, but the system should be able to tell you exactly what it did on a matter so the conversation is possible.
Courts have sanctioned lawyers who filed briefs containing authorities a tool invented. Every design decision on this page — retrieval-only citation, marked gaps, no smoothing over uncertainty — exists because of this failure mode.
Output has to be supervised the way a junior’s work is supervised, which means a partner needs to be able to see what was used and what was assumed. Unauditable output is unsupervisable output.
If a task now takes two hours instead of eight, billing eight is a problem. This is a business-model question rather than a technical one, and it is worth deciding deliberately before the efficiency arrives rather than after.
State bars have issued their own guidance as well, so the rules that bind you depend on your jurisdiction. The practical point for a build is the same everywhere: architecture answers most of these duties structurally. A system running inside your environment, inheriting your permissions, citing only retrieved sources and logging what it did satisfies more of this list by design than any policy document can by assertion.
02 / HOW THESE PROJECTS ACTUALLY FAIL
The most common legal AI failure is not a hallucination. It is a retrieval index built across the whole document store, which quietly becomes a route around the ethical walls the firm spent years configuring — and nobody notices, because it never looks like a breach. It looks like a helpful summary.
Permissions have to be applied at query time, by the system that already owns them. Anything else is a copy of your access model that will drift out of date the first time a matter is walled.
The rules are not reimplemented in the AI layer. They are read from the document management system at the moment of the query, so a permission change takes effect immediately and a walled matter is walled everywhere.
03 / WHAT WE ACTUALLY BUILD
Most firms should start at the third group, where no client material is involved at all, and earn their way toward the others. We will say so even though it is the smallest first project.
The firm has answered this question before. The problem is that the answer is inside a matter nobody remembers, filed under a client name nobody recognises.
The assembly work that surrounds analysis — gathering, organising, summarising — rather than the analysis itself.
No client confidentiality is engaged here, which is why this is often the safest and fastest place for a firm to start.
Where the firm already owns good legal software, the gap is usually between the systems rather than inside any one of them.
04 / WHERE IT RUNS
The models are broadly the same wherever they run. Everything that matters to a risk committee is about the boundary they run inside and what surrounds them.
An enterprise model instance in your own Azure subscription, with the document store and identity you already run. Data stays within the environment your firm controls and your existing permissions carry through.
This is where most firms land, because the governance question is largely answered by the architecture rather than by a contract clause.
The same shape where the firm’s infrastructure is already there. Nothing about the design depends on a particular cloud — it depends on the environment being yours.
We build to your security team’s standards and hand over documentation they can actually review.
If your research and review platforms already do a job well, we connect and orchestrate them rather than rebuild them. The value is frequently in the workflow between systems, not in another system.
We will tell you when the honest answer is to use what you have and automate around it.
05 / THE ENGAGEMENT
Every firm has confidential material in more places than the document management system — inboxes, shared drives, someone’s desktop. Finding that out is unglamorous, and it is the work that decides whether any of this can be done safely.
RELEVANT WORK
The citation-controlled retrieval, the refusal behaviour and the audit trail described here were developed for document-heavy professional work where an answer nobody could trace back to a source was not a minor defect but a real problem. Legal work needs the same discipline for sharper reasons.
We are not naming firms or publishing engagement details on a public page. On a call we will go through the architecture properly, including the parts that were harder than expected and what we would design differently now.
How the retrieval side works06 / START WHERE THE RISK IS LOWEST
Not the second one. The questions they will ask decide the architecture, so having them in the room early is faster than designing something and then discovering what will not be approved.
You will be talking to the people who would build it, not an account manager.info@chronexa.io
Rather write it down first?
A FEW GOOD QUESTIONS
There is a specific one. On 29 July 2024 the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first formal guidance on generative AI, addressing competence, confidentiality, communication with clients, candor to the tribunal, supervision and fees. It does not prohibit these tools; it sets out the conditions for using them properly, including that a lawyer must think carefully before putting client information into a tool and that informed consent can be part of the analysis. State bars have issued their own guidance too, so the applicable rules depend on your jurisdiction. The practical consequence for a build is that architecture does most of the ethical work: a system inside your own environment, inheriting your permissions, with an audit trail, answers most of these questions structurally rather than by policy.
By not letting it write authorities at all. Citations come from retrieval over sources the system can point at — your documents, your subscribed materials, published sources — rather than from the model’s memory, and anything it cannot support is marked as an open question instead of being written over smoothly. This is not a theoretical concern: courts have sanctioned lawyers for filing briefs containing authorities that a tool fabricated, and that specific failure is the reason the design refuses to produce a confident-sounding paragraph it cannot substantiate. A lawyer still verifies. The system’s job is to make verification quick rather than to make it feel unnecessary.
They have to be enforced by the same system that enforces them today, which in most firms means the document management platform. This is the single most common way legal AI projects go wrong: someone builds a retrieval index over everything the firm holds, and it quietly becomes a route around permissions the firm spent years configuring. We build retrieval that inherits matter-level permissions at query time, so a lawyer who is not on a matter gets nothing — not a summary, not a redacted answer, not even confirmation that responsive documents exist. Attempts are logged, because a refusal is as much a part of the record as an answer.
Almost certainly not by virtue of being a law firm, and it is worth saying plainly because these labels get attached to legal pages indiscriminately. The regime that governs your data is the Rules of Professional Conduct, your clients’ outside counsel guidelines, and whatever contractual security obligations you have signed up to — which are frequently stricter and more specific than the certifications vendors advertise. Where a firm genuinely handles protected health information for a client matter, HIPAA may apply to that engagement, and that is a real conversation with a real answer rather than a badge on a web page. We would rather scope the actual requirement than decorate the page.
Not for client material, and that is the whole reason this page exists. Consumer and general-purpose tools are a poor fit for confidential matter content because of where the data goes and what may be retained. What works is an enterprise model instance running inside your own Azure or AWS environment, where inputs are not used for training, logging is under your control, and the data never leaves the boundary your firm is responsible for. The models themselves are largely the same; the difference is entirely in where they run and what surrounds them.
Regulatory and filing monitoring, almost always. It produces something genuinely useful within weeks, it engages no client confidentiality because the sources are public, and it lets your risk people watch the system behave before anything touches a matter. From there the natural second step is retrieval over the firm’s own documents, which is more valuable and requires the permission work to be done properly. Starting with drafting is the common instinct and usually the wrong order, because it is the highest-scrutiny use with the least trust established.
It depends on which environment you run, which systems have to be connected and how much of the permission model is already clean, so there is no list price. The first step is a short assessment: where confidential material actually lives today including the copies nobody talks about, what your security team will and will not approve, and which use case gives you something useful fastest. That produces a scope, an acceptance definition and a fixed price in writing before any build starts.