Skip to content
For Australian law firms

How we build AI for a law firm.

These decisions are settled before a single system is designed: what stays inside your control, who signs before anything leaves, and the obligations each build is measured against.

The six things we settle first

Settled before anything is designed, so they are not traded away later when a deadline arrives.

Your systems stay the source of truth

A build reads from and writes back to the systems you already control, so no second copy of your client data lives anywhere else.

The least data that will do the job

Each build carries a written rule for what is sent and what is withheld. Where a job does not need to know who the client is, it is not told.

Where it is processed is a design decision

Australian processing where your matters require it, settled and priced at the start. If a client contract, a government matter or your insurer imposes a location requirement, that requirement governs the build.

A named person signs before anything leaves

Every build stops and presents its work for approval. On screen, as a step that cannot be skipped.

The AI sees only what that person sees

Access is bounded by the user's existing permissions. It cannot open a matter they could not open themselves. Every action is logged with a time and a name against it.

A written rule for how long things are kept

Retention and destruction are decided in writing per build, because that is the half of the security obligation most often left undone.

The obligations we build against

Named plainly, because the wrong instrument is still in wide circulation and it changes the answer.

Privacy Act 1988 (Cth)
The 13 Australian Privacy Principles are the live instrument, in force since 12 March 2014 and amended in December 2024. The older Information Privacy Principles and National Privacy Principles were repealed on that date, and the IPPs never applied to a private law firm at any point.
Solicitors' Conduct Rules
Rule 9 on confidentiality and Rule 4 on competence and diligence make human verification of AI output a professional obligation. That is why the sign-off gate above is built in.
Legal professional privilege
Disclosure to a service provider under a duty of confidence, for the dominant purpose of providing the legal service, should not waive privilege. We document that position per build.
Notifiable Data Breaches
Any new processing path is a new breach surface, so every build gets a named escalation route before it goes live.
AI risk standards
Before we build, every step of your process is scored for how safe it is to let AI do it and how well AI can do it. Those bands are anchored to NIST AI RMF 1.0, ISO/IEC 42001:2023 and ISO/IEC 23894, together with the human-in-the-loop oversight taxonomy. Any step where AI would act irreversibly on its own is gated behind a named person, or dropped.

The plain-English version is on How we govern AI: what AI handles, what your people keep, and how every agent is tested to stop.

This is the first half hour of an AI Scan.

In a two-hour session we walk your own process step by step and score it the same way: what AI can take on, what a person must check, and what it should never go near. You leave with the one thing worth doing first, costed against your own numbers.

Book your AI Scan
Common questions

Questions about AI in a law firm

Is AI safe to use with law firm client data?

It depends entirely on how the system is built. Six controls decide it: your existing systems stay the source of truth so no second copy of client data is created; only the minimum data needed leaves them; where processing happens is a design decision settled at the start; a named person approves anything before it reaches a client; the AI can only see what that user could already open; and retention and destruction are written down per build.

Which parts of legal work should AI never touch?

Any step where AI would perform an irreversible act itself, or make the final legal decision. Witnessing or signing a document, assessing testamentary capacity, authorising a release of trust funds, and the compliance sign-off itself. Every step of a process is scored before a build, and any step where AI would act irreversibly on its own is gated behind a named human who authorises each instance, or dropped from the build.

Which privacy law applies to an Australian law firm using AI?

The 13 Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth) are the live instrument, in force since 12 March 2014 and amended in December 2024. The older Information Privacy Principles and National Privacy Principles were repealed on that date, and the IPPs never applied to a private law firm at any point. Alongside the Act sit obligations it does not cover: the Solicitors' Conduct Rules, legal professional privilege, and the Notifiable Data Breaches scheme.

Where is our data processed if we use AI?

Australian processing where the firm's matters require it, settled and priced at the start rather than assumed afterwards. Where a client contract, a government or defence-linked matter, or the firm's insurer imposes a location requirement, that requirement governs the design. Where a job does not need to know who the client is, the data is de-identified before it leaves the firm's own systems.

Can a supplier guarantee an AI build is compliant?

No. The obligations attach to the firm, not to the supplier, and they depend on facts only the firm holds, annual turnover, the terms of its client engagements, its insurer's position and its own risk appetite. A supplier can describe its engineering controls and the reasoning behind them so the firm can form its own view. That is not legal advice and it is not a certification.