AI Vendor Due Diligence for Law Firms: What to Check Before You Sign
8/17/20264 min read


AI Vendor Due Diligence for Law Firms: What to Check Before You Sign
Every AI tool your firm adopts is a decision about client confidentiality. The moment client data flows into a vendor's system, that vendor becomes a partner in your ethical obligations — whether or not you vetted them like one. For attorneys, due diligence isn't a procurement formality. It's a professional-responsibility duty.
This is general information, not legal advice.
Why this is an ethics question, not just an IT question
Three California duties converge the instant you evaluate an AI vendor:
Competence (Rule 1.1) — you must understand a tool well enough to use it properly and to recognize when its output needs independent verification. You can't assess a tool you haven't examined.
Confidentiality (Rule 1.6 and Business & Professions Code § 6068(e)) — you must take reasonable steps to prevent unauthorized disclosure of client information, which applies directly to any tool routing client data to third-party infrastructure.
Supervision (Rules 5.1 and 5.3) — managerial lawyers are responsible for firm-wide policies governing these tools, and for supervising the staff who use them.
The ABA reinforced this at the national level. ABA Formal Opinion 512 (2024) treats reviewing a vendor's terms as a professional obligation, and takes the position that using generative AI without understanding how it handles client data can violate the confidentiality rule. Meaningful vendor due diligence isn't optional; it's the standard of care.
There's also a privilege dimension that's easy to overlook: if a tool's terms of service permit the vendor to retain your inputs, train on them, or share them with third parties, the choice of tool itself can create attorney-client-privilege risk — before any breach ever happens. What the contract allows matters as much as what the vendor promises.
The vendor due-diligence checklist
Run every AI tool that could touch client data through these questions before you commit. Document your answers — a demonstrable review process is part of the point.
Data handling
Does the vendor train its models on your inputs? (You want: no.)
What is the data-retention period, and can you get zero data retention?
Is client data shared with, or processed by, third parties or subprocessors?
Who owns the inputs and outputs under the contract?
Are there data-residency options if your matters require them?
Security posture
Does the vendor hold SOC 2 Type 2 certification? (This is the practical benchmark for legal AI. ISO 27001 is a plus.)
Is data encrypted in transit and at rest?
Is multi-factor authentication available and enforceable?
What is the vendor's breach-notification commitment and history?
Are audit logs available so you can reconstruct who accessed what?
Terms of service
Read them — actually read them. Pay closest attention to clauses on data ownership, retention, third-party sharing, and any rights the vendor claims over your inputs.
Can you negotiate a data-processing agreement (DPA) or a contractual no-training commitment?
Fit with your obligations
Does the tool let you keep a human verification step before anything is filed or sent to a client?
If the vendor's system generates public-facing media, does it carry the provenance/disclosure features California's newer transparency statutes anticipate?
Does the vendor supply documentation (e.g., training-data disclosures) you can fold into your confidentiality analysis?
For solos and small firms without dedicated IT
You don't need a security team to do this competently. The State Bar's guidance calls for reasonable care, not perfection. In practice, a small firm can satisfy the duty by documenting a review of the vendor's SOC 2 report, reading and saving the terms of service, confirming a no-training / retention position in writing, and keeping that record on file. Being a diligent, questioning consumer is the bar — not becoming a cybersecurity expert.
Build it into a repeatable process
Due diligence isn't a one-time gate. Tools change their terms; new features route data in new ways. Treat vendor review as a recurring step: re-verify at renewal, log each tool you approve (with its permitted uses and data limits), and pair the review with a written AI-use policy and the human verification habits that keep filings and client work sound. (See our related pieces on attorney confidentiality with public AI tools and supervising agentic AI.)
Frequently asked questions
Do I really have to review a vendor's terms of service myself?
Effectively, yes. ABA Formal Opinion 512 treats reviewing vendor terms as a professional obligation, because you can't protect client confidentiality without knowing how the tool handles data.
What security certification should a legal AI tool have?
SOC 2 Type 2 is the working benchmark, ideally alongside encryption in transit and at rest, MFA, and — where possible — a contractual zero-data-retention commitment.
Can using a consumer AI tool waive attorney-client privilege?
It can. If the terms permit retention, model training, or third-party disclosure, the choice of tool can independently create privilege risk, separate from any data breach. Vet the terms before client data goes in.
Is a "no-training" promise in marketing enough?
No. Get it in the contract or terms, not just the sales page, and keep a record.
This article is general information, not legal advice. Confirm the current State Bar guidance and any applicable rule before relying on specifics.
Sources
California Rules of Professional Conduct 1.1 (competence), 1.6 (confidential information), 5.1 and 5.3 (supervision)
California Business & Professions Code § 6068(e)
ABA Formal Opinion 512 (2024) — Generative Artificial Intelligence and the Model Rules
State Bar of California, Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law (2023; updated 2026)