Skip to content
For Australian law firms

How we build AI for a law firm.

Everyone will tell you which parts of your practice AI can do. Almost nobody will tell you which parts it must not touch. These are the decisions we settle before a single system is designed - what stays inside your control, who signs before anything leaves, and the obligations every build is measured against.

The six things we settle first

Six things are true of every system we put into a firm. They are settled before anything is designed, so they are never traded away later when a deadline arrives.

Your systems stay the source of truth

A build reads from and writes back to the systems you already control. We do not create a second copy of your client data living somewhere else.

The least data that will do the job

Each build carries a written rule for what is sent and what is withheld. Where a job does not need to know who the client is, it is not told.

Where it is processed is a design decision

Australian processing where your matters require it, settled and priced at the start. If a client contract, a government matter or your insurer imposes a location requirement, that requirement wins and we build to it.

A named person signs before anything leaves

Every build stops and presents its work for approval. On screen, as a step that cannot be skipped.

The AI sees only what that person sees

Access is bounded by the user's existing permissions. It cannot open a matter they could not open themselves. Every action is logged with a time and a name against it.

A written rule for how long things are kept

Retention and destruction are decided in writing per build, because that is the half of the security obligation most often left undone.

The obligations we build against

Named plainly, because the wrong instrument is still in wide circulation and it changes the answer.

Privacy Act 1988 (Cth)
The 13 Australian Privacy Principles are the live instrument, in force since 12 March 2014 and amended in December 2024. The older Information Privacy Principles and National Privacy Principles were repealed on that date, and the IPPs never applied to a private law firm at any point.
Solicitors' Conduct Rules
Rule 9 on confidentiality and Rule 4 on competence and diligence make human verification of AI output a professional obligation. That is why the sign-off gate above is built in.
Legal professional privilege
Disclosure to a service provider under a duty of confidence, for the dominant purpose of providing the legal service, should not waive privilege. We document that position per build.
Notifiable Data Breaches
Any new processing path is a new breach surface, so every build gets a named escalation route before it goes live.
AI risk standards
Before we build, every step of your process is scored for how safe it is to let AI do it and how well AI can actually do it. Those bands are anchored to NIST AI RMF 1.0, ISO/IEC 42001:2023 and ISO/IEC 23894, together with the human-in-the-loop oversight taxonomy. Any step where AI would act irreversibly on its own is gated behind a named person, or dropped.

This is the first half hour of an AI Scan.

In a two-hour session we walk your own process step by step and score it the same way - what AI can take on, what a person must check, and what it should never go near. You leave with the one thing worth doing first, costed against your own numbers.

Book your AI Scan