Founding clients · 2026 Free 2026 guide: private AI in law — deployment, costs, evaluation and a 90-day plan. Read it → Ask about a founding place
the AI practice · September 2026

Your firm has an AI strategy. It lives in your fee-earners' browser history.

We are not here to sell you a model. We are here for the three jobs firms keep asking us to do: find out what is actually in use, build something private for the work that cannot leave, and prove to an insurer, a client or a regulator that the whole thing is under control.

3services
private · training · audit
One weekcheapest way in
the DPIA & policy pack
0vendor payments
no reselling, no referrals
01what changed in 2026

Three things happened this year, and they changed the question.

The vendors moved

Legal AI's biggest players started building their own models.

In August 2026 Thomson Reuters announced a proprietary legal model rather than continuing to sit on third-party foundations. Whatever you buy, the signal matters: if model ownership is part of the biggest vendor's confidentiality story, it belongs in your build-or-buy decision too.

The regulator spoke

The SRA's August 2026 warning notice is about supervision, not technology.

The themes are the ones we find in audits: outputs trusted without verification, supervision assumed rather than evidenced, files that do not show what anyone checked. A better model does not fix that. Logging, verification and file-note discipline do.

The clients asked

AI governance joined the diligence questionnaire.

Enterprise clients and public bodies now ask what tools process their data, where it rests and who reviewed the output. The AI register has joined the AML review as a document you are expected to produce.

The staff didn't wait

Fourteen undeclared tools across nine firms.

That is our 2026 audit average. Free tiers, browser extensions, personal accounts. None of it procured, all of it processing client content.

The honest position

Private is not automatically right.

For plenty of firms the answer is a policy pack and governed commercial tools. We will tell you that plainly — it is cheaper for you and better for our reputation.

Sources for the two claims above are linked in our 2026 private AI guide. We cite what we read rather than restating it as fact.

02the three engagements

Private AI, training, audit — in that order, usually.

Firms arrive at one of these three depending on what has just gone wrong: a client questionnaire, a blocked pilot, or a partner asking why nobody can produce a register. Here is what each actually involves.

01

Private AI deployment

For firms whose client base rules out third-party processing, or who are tired of paying per seat for capability they could own. We design, pilot and deploy AI that runs inside your perimeter — and we will tell you if your firm is too small for it to make sense.

Readiness assessment

Ten working days. What is in use, what a private layer would replace, which hosting pattern fits your size, and what it costs to run. Credited against a pilot if you proceed.

Pilot · from agreed in writing

Four to six weeks. Model chosen, retrieval wired over a scoped document set with DMS permissions inherited, evaluation run with your own fee-earners on your own matters.

Deployment

Six to ten weeks. Production scope, access controls, logging, governance pack, training and an internal owner so the capability outlives us.

Managed cover

Model updates with regression evaluation, quarterly re-testing, register upkeep, incident support and a quarterly governance note for the board.

What "private" means here, in one picture
Your firmFee-earner asks a question in the tool they already use, authenticated as themselves. Ethical walls applied before anything is retrieved.
Your perimeterModel runs on your hardware or your private tenancy. Retrieval reads your own precedents and matters. Nothing traverses a supplier.
Your evidenceQuery, sources, model version, output and the human decision recorded against the matter — which is the reason to do this at all.
Not in the pictureClient content leaving the building, third-party training on your data, or a vendor demo standing in for an evaluation.
02

AI training

Because the risk is not the model — it is what someone pastes into it at 6pm on a Thursday. Four sessions covering the people who use AI, the people who supervise it, and the people who have to answer for it.

Fee-earner essentials

Half a day, up to twenty people. The three prohibitions, how to verify an output in three minutes, and the file-note language that evidences the check.

Role-based programme

Three sessions: fee-earners, supervisors and partners, then COLP, MLRO and IT. Competency checklist per role and a training record pack for the insurer file.

COLP / MLRO oversight

How to evidence oversight of a model you did not build: what to read, a 30-minute quarterly sampling routine, what to log, what to escalate.

Board briefing

Ninety minutes for the people who decide, with the three deployment routes costed and a one-page decision memo left behind.

Training is built around the tools your firm actually uses. Send us the list and the drills use your stack rather than generic examples.
03

AI audit

The independent check on your AI control environment, mirroring what you already do for AML. Three audits, taken alone or as an annual cycle, each ending with findings, ratings, owners and dates.

AI use audit

Discovery across declared and undeclared tools, data-flow assessment per tool, risk tiering with an action each, and a register formatted for tender questionnaires. Amnesty is the method: findings by pattern, never by name.

Output quality audit

A sample of AI-assisted work products tested for correctness and verification, plus a review of file notes and supervision trails. Failure modes reported by task type.

Annual governance audit

Control testing against your own policy and ISO/IEC 42001 ambitions: register, DPIAs, oversight logs, sample matters, findings and a remediation plan.

Vendor diligence pack

For AI companies selling into law firms: the security, governance and evidential answers their procurement teams ask for, assembled before they ask.

03how this fits with the compliance work

One practice, two desks, one evidence pack.

The AI work and the AML work are not separate businesses with separate calendars. Firms that run both with us get one assurance cycle: the AML review in one quarter, the AI audit in the next, one board pack a year, and one place to send the client questionnaire that asks about both.

compliance desk

AML, DPIA and 42001

Independent file review under regulation 21, DPIA and AI policy packs, ISO/IEC 42001 readiness, and the retainers that keep the evidence current.

All services, and how quotes work →
AI desk

Deployment, training and audit

Architecture for the work that cannot leave, training that changes behaviour, and the independent audit that tells you whether any of it worked.

Costs and quotes, and how quotes work →
04the questions we get

Straight answers about the AI work.

Q1Is private AI overkill for a 20-fee-earner firm?+
Sometimes. If your client base has no objection to enterprise-tier commercial tools and you have a policy everyone follows, the policy pack may be all you need. Private becomes the right answer when a client contract, a matter type or an insurer's question rules out the transfer — which happens more often than firms expect.
Q2Will an open-weight model be good enough?+
For focused tasks with good retrieval — summarising a bundle, extracting terms, drafting from precedent — yes, close enough to be genuinely useful. For open-ended reasoning it is behind the frontier models. That is why we run a pilot on your own matters before anyone commits to a deployment.
Q3Do you resell hardware, models or licences?+
No. No reseller margin, no referral fees, no vendor sponsorship — not in our audits, not in the AI tools index. It means our recommendation is free to be that you need less than you were quoted.
Q4Can you make us ISO/IEC 42001 certified?+
No, and nobody advising you can. Certification comes from a UKAS-accredited body that must be independent of your consultant (ISO/IEC 17021-1). We prepare the management system and evidence pack; they certify. We do not sit in the audit.
Q5Where do we start if we have done nothing yet?+
Three options, in ascending order of commitment: the DPIA & AI policy pack (agreed in writing, one week) if you need documents fast; the AI use audit (agreed in writing, two weeks) if you suspect nobody knows the real inventory; the readiness assessment (agreed in writing, ten days) if a private deployment is on the table and you want the cost model before the board asks.
Q6Is any of this legal advice?+
No. We are a compliance and AI governance consultancy, not a law firm, and none of this is a reserved legal activity. Where something needs a lawyer we say so and step back.
// start here

Send three files.
We'll tell you what a reviewer would flag.

  • No charge and no obligation — you keep the findings either way
  • Turned around in ~48 hours, encrypted transfer only
  • Most firms find at least one issue they did not know they had
Book the free 3-file check → Talk to us about cost Or write to — replies usually the same day.