Confidentiality is a duty, not a preference

A lawyer’s obligation to protect client information does not have a “but the vendor’s terms of service seemed fine” exception. Most cloud AI tools require shipping client data to someone else’s servers, under terms that can change, be breached, or be swept up in an acquisition. On-premises AI answers the confidentiality question a different way.

What does “on-premises” actually mean?

It means the AI models run on hardware the firm owns, inside its own network, behind its own firewall. Client documents are processed locally. Nothing is uploaded to an outside service, retained by a vendor, or used to train someone else’s product. Confidentiality is satisfied by architecture — the data physically cannot leave — rather than by a promise that it won’t.

Promises expire; architecture doesn’t

This is the whole argument in one line. A vendor’s privacy policy is a commitment that can be revised, and a security posture is a target that can be missed. If client data never leaves the building in the first place, no policy change, breach notice, or corporate transaction on a vendor’s side can put it at risk. For the most sensitive matters, that structural guarantee is worth more than any assurance.

For some clients, it’s the only option

This matters double for firms whose clients require it: trade-secret litigation, deals under NDA, and any client whose outside-counsel guidelines already prohibit cloud processing. For those matters, AI that runs entirely in-house is not a preference — it is the only version the client can lawfully allow the firm to use at all. A firm that can offer air-gapped AI can take work a cloud-only competitor cannot touch.

The surprise: it’s now affordable

On-prem used to be the expensive option. It isn’t anymore. Open-weights models have become good enough, and capable hardware cheap enough, that a small firm can own its stack outright. Much of PLI Labs’ public research is precisely about serving strong models on accessible, even older, GPUs — the recipes that make ownership economical.

None of this means every task belongs on a local box. A well-designed practice uses the right tool for each job. But the question “where does the data go?” deserves a real answer, and for a lawyer, “nowhere” is often the only one that fits the duty.

This article is general information from a technology consultancy, not legal advice, and does not create an attorney-client relationship. Figures describing the founder’s own practice are illustrative, not a promise of results.

Back to the research hub