Private AI in law: the deployment guide
Everything we have learned designing private AI for law firms, written for the person who has to decide rather than the person selling it: the three deployment archetypes compared, what private actually costs to run, retrieval that respects ethical walls, how to evaluate a model on your own matters, governance that survives an insurer's questions, a 90-day rollout plan and the ten failure modes we keep seeing.
3 archetypes · cost model
The complete AML audit report — all 14 pages of it
The document every pitch in our market dances around, published in full so you can judge the deliverable instead of the deck. Overall assurance rating, findings by severity, the file-level matrix, the firm-level control matrix, a remediation plan with owners and dates, the board page — and the methodology appendix with the findings the tooling got wrong, because those exist and we keep them.
credibility to give away
The 20-point file self-check
Run one live file against the seven control areas and the twenty checks a reviewer will apply to it — with answer notes, honestly worded, on page three.
AI tool register
The first artefact enterprise buyers ask for: tool, owner, data location, DPIA status, review cadence — import-ready, one synthetic example row marked for deletion.
The shadow-AI one-pager
Eight rules on a page: what may and may not go into AI tools. Free to circulate in your firm — ask for the print-ready version any time.
DPIA skeleton for legal AI
A UK GDPR art-35 DPIA pre-loaded with the questions that recur for legal tooling: client data, training use, retention, subprocessors, human oversight.
AI vendor assessment questionnaire
The questions to send any AI supplier — with the answers that should end the conversation, marked as such.
“What a reg 21 auditor asks” briefing
The independence test, the proportionality question, the evidence pack — two pages your partnership can read before it reads anything else on this.
Five Fridays: your AML file, defended.
One short lesson each week — the obligation, the seven control areas, the findings that cluster, the remediation plan that survives Monday, and the evidence pack you'll be glad exists. Unsubscribe mid-course and the lessons are yours to keep. No upsell sequence, no webinar bait: the fifth email genuinely ends.
§ your email, plainly What happens to the address you just typed.
- What you typed is what we use — the address goes on the list and nowhere else. No click-to-confirm loop, no "are you still interested" sequence, no third party validating your existence.
- Then one email a month, the Reg 21 Brief, until you say stop. Unsubscribe is one click and means one click.
- No sales sequences, no third-party sharing, no CRM enrichment from this page. The list is the business's memory, not its inventory.
- Delete on request — email diin@probativeco.com and the record is gone, same day, with a note saying it was.
Read the specimen.
Then send three files.
Twenty minutes, £0, ~48 hours, findings yours either way. Most firms find at least one issue they did not know they had — and by then you'll have read our report format, so you'll know exactly what "finding" means here.
Prefer writing? diin@probativeco.com