Trust and Security to Demand From Legal AI Software
What a personal injury firm must demand before AI touches client files: data ownership, audit trails, escalation, and honest claims. A trust checklist for legal AI.
Before you let any AI touch a client's file, demand four things: it must protect the data, log every action it takes, escalate when it is unsure, and never claim more than it can do. If a legal AI vendor cannot give you a straight answer on all four, the product is not ready for a personal injury firm. You are the custodian of privileged medical and financial records for injured people. That duty does not bend because the software is impressive.
I build AI products, including for legal, and I refuse to ship one that fails this bar. Here is the standard, and why each part is non-negotiable.
Who owns and can see the data?
Start with the boring question that decides everything. Where does client data live, who can access it, and does the vendor train models on your clients' information?
A PI case file holds medical history, injury details, insurance information, and financial facts about a vulnerable person. That is not data you hand to a black box. Demand to know the storage location, the access controls, and the training policy in plain language. "It's secure" is not an answer. A serious vendor names its controls without flinching.
Then check the exit. If you cannot export every case cleanly, you do not really own your files, and a vendor that holds your data hostage has leverage over you forever. Portability is part of security, not separate from it.
Does it log what it did?
For legal work, an action without a record is a liability. Every automated step on a case, every message sent, every status changed, every document requested, must leave a trail you can inspect later.
This is not paranoia. It is how you defend a decision when it gets questioned, and how you catch a mistake before it reaches a client. "The AI handled it" is worthless unless the AI wrote down what it handled and why. I make audit trails a hard requirement across my products, and I explained the reasoning in how to add audit trails to AI systems. In legal, that requirement is not optional. It is the whole point of trusting software with sensitive work.
What does it do when it is not sure?
The most dangerous AI is the one that guesses confidently. A trustworthy system knows the edge of its competence and escalates to a human at that edge. A dangerous one fills the gap with a fabricated answer and moves on.
Ask the vendor directly: what happens when the model is not confident? The right answer is that it flags the case for a person. The wrong answer is a shrug or a claim that it is "always accurate." Nothing is always accurate. A product that pretends otherwise is lying to you, and that lie will eventually land on a client's file. Building the guardrails that make escalation reliable is real engineering work, which I covered in how to build guardrails into an AI product.
Does the vendor overclaim?
The last demand is about honesty in marketing, which sounds soft but is the tell that predicts everything else. A vendor that overstates what its AI does in the sales deck will cut the same corners in the product.
Watch for claims with no limits attached. Real capability comes with boundaries, and an honest vendor states them. I hold my own products to what I call claims discipline, which I wrote up in claims discipline for AI products: say only what the software can actually do, and say where it stops. In legal, an overclaim is not just bad marketing. It is a firm relying on a capability that was never real, on a real client's case.
The trust checklist
Before AI touches a single file, get clear answers to these:
- Where does the data live, who sees it, and can I export it all?
- Is every automated action logged and inspectable?
- Does the system escalate to a human when it is uncertain?
- Does the vendor state the limits of what its AI can do?
Four questions. Any vendor worth trusting answers all four without hedging. This connects to a bigger truth about selling AI into serious industries: the product is not the capability, it is the assurance around it. I made that argument in why I sell assurance, not capability, and it applies double to law.
We built CaseSolo to pass this checklist, because I would not put a legal product into a firm otherwise. If a vendor cannot clear the same bar, keep them away from your clients' files.