- Legal Futures - https://www.legalfutures.co.uk -

AI risk: What law firms must now demand from vendors

Guest post by Eleonora Dimitrova [1], who holds an LLB and LLM in corporate and commercial law from Queen Mary University, London

Dimitrova: Risks are moving upstream

Debate about AI in legal practice has largely focused on how solicitors use these systems – whether reliance affects competence, how outputs should be verified, and what safeguards are required around confidential information. Those questions matter.

But they are increasingly downstream of where regulatory risk is actually created. In many cases, a firm’s exposure is fixed much earlier: at procurement.

This is not a novel regulatory concept. The profession already treats decisions about outsourcing, cloud hosting, and third-party data processing as matters of regulatory significance rather than commercial convenience.

AI procurement belongs squarely in that category. What is different is the extent to which system architecture now determines whether compliance with professional obligations is possible at all.

Under the outcomes-focused framework applied by the Solicitors Regulation Authority (SRA), firms remain responsible for the systems through which legal services are delivered. Competence, due diligence, and confidentiality are non-delegable duties.

Each presupposes that the firm understands how its systems function, where information flows and how outputs are generated. Where those conditions are absent, compliance becomes largely theoretical.

That same pattern of uncertainty has already emerged in firm approaches to AI-assisted competence and due diligence. Procurement explains why.

The question firms should already be able to answer

A single question exposes the problem.

If required to justify its position tomorrow, could the firm explain – clearly and with evidence – where a privileged document goes, who can access it, and what persists after it is processed by the AI system it has procured?

For many firms, the answer is no. That is not a failure of training or supervision. It is a failure of procurement, and precisely the kind of failure regulators have historically treated as systemic.

Procurement as the regulatory choke point

Every material AI-related professional risk can be traced upstream.

If a firm cannot explain how an AI system generates outputs, that is not simply a usage problem. If it cannot identify where client data is processed or who has access to it, internal policies cannot cure that gap. And if it cannot assess whether privileged material is disclosed to third parties, downstream caution will do little to reverse the exposure.

Despite this, AI procurement in many firms remains fragmented. IT teams assess security. Innovation functions assess capability. Practice leadership evaluates usefulness. Risk and compliance teams are often consulted late, if at all.

Decisions with direct regulatory consequences are therefore taken without a coherent governance framework. This is not an implementation glitch. It is a governance defect.

Why conventional procurement frameworks now fail

Traditional procurement models in law firms tend to rest on three assumptions, namely that:

In the AI context, all three assumptions are unstable.

Vendors may be unable – or unwilling – to explain how models behave in legally sensitive scenarios. Indemnities offer little comfort where the risk concerns regulatory breach, privilege waiver or reputational harm. And architecture is no longer neutral. It can determine whether professional obligations can be satisfied at all.

AI systems ingest, transform, infer and generate. Treating them as equivalent to document storage or workflow tools is a category error. From a regulatory perspective, that assumption is becoming increasingly difficult to sustain.

What firms must now demand from AI vendors

If firms are serious about compliance, procurement standards will need to become more rigorous. Certain safeguards are likely to become baseline expectations where AI systems interact with confidential or privileged information.

Verifiable data-flow transparency. Firms should require documented explanations of how data is ingested, processed, logged, accessed and deleted. High-level assurances that information is “not used for training” are insufficient.

If data flows cannot be mapped, control cannot be demonstrated.

Contractual restrictions with regulatory force. Restrictions on secondary use, subcontractor access, cross-border transfers and unnecessary retention should be embedded in enforceable contractual terms supported by audit rights.

Reliance on evolving privacy policies alone rarely provides sufficient assurance.

Jurisdictional control. Where privileged or confidential material is involved, uncontrolled cross-border processing may be difficult to reconcile with professional duties. Procurement decisions should therefore reflect where data is processed and under which legal regime.

Model-level risk explanations. Vendors should be able to explain, in intelligible terms, how outputs are generated, how errors arise and how updates are governed. Competence cannot be assessed where system behaviour remains an opaque ‘black box’.

Exit and deletion certainty. Procurement must assume that vendor relationships may end. Firms therefore require assurance that data can be extracted, deleted and independently verified. Inability to exit cleanly may itself create regulatory exposure.

These expectations are not onerous. They reflect the level of operational discipline already applied when other third-party systems interact with core professional obligations.

Where procurement failures crystallise: confidentiality and privilege

Weak procurement becomes most dangerous where confidentiality and privilege are engaged.

AI systems frequently rely on layered vendor ecosystems involving hosting providers, subcontractors and internal review processes. Even where raw inputs are deleted, derivative information may persist in ways that are difficult to audit.

Once a system has been procured without adequate controls, internal policies and training can only mitigate risk at the margins.

This reinforces a broader pattern already visible across AI competence and confidentiality debates: governance failures upstream cannot be cured downstream.

Regulatory silence is becoming increasingly difficult to sustain

The SRA has emphasised principles and outcomes in its public commentary on AI. That approach is familiar. In the procurement context, however, firms may increasingly require clearer operational expectations.

Without greater clarity around what constitutes adequate AI procurement due diligence – what questions should be asked, what contractual safeguards are expected, and how firms should evidence compliance – practice will continue to diverge.

Some firms will avoid AI tools entirely. Others will adopt them rapidly, relying on informal assurances rather than structured governance. Neither approach reflects informed risk management.

Conclusion: procurement is where accountability now sits

AI does not dilute professional responsibility – it concentrates it.

A firm that cannot explain why it selected a particular AI system, what risks were identified at procurement stage, and how those risks were controlled may struggle to defend that decision when challenged. Procurement records may matter as much as usage policies, and possibly more.

The profession has already seen how uncertainty develops when operational standards lag behind technological adoption. Procurement may be the next fault line.

Firms that continue to treat AI procurement primarily as a commercial exercise rather than a regulatory decision are not simply innovating. They may be accumulating unmanaged risk – risk that will ultimately be judged by a familiar standard: whether solicitors took reasonable, informed and defensible steps to protect their clients.