The gap in the file
Associates draft in Copilot, summarise threads in Outlook, and paste facts into public ChatGPT. Knowledge tools and practice systems are growing their own AI surfaces. None of that lands in the matter file as a single, attributable record.
When a client asks what AI touched the advice, the usual reconstruction is mailbox search, browser history, and hope. Firms do not treat time, conflicts, or privilege that way. They should not treat AI that way.
Confidentiality is the constraint
The trail has to live where the matter lives. Observation stays inside a customer-owned, hermetic boundary. Matter content is not the vendor’s to own.
Shadow AI is already in the building
Acceptable-use PDFs do not stop a public assistant at 11pm. Detection and attribution belong on the same row as sanctioned Copilot so a partner sees the exception next to the work, not in a detached security ticket after discovery.
Multi-tool is the default
Microsoft 365 Copilot in Word and Outlook. Slack AI. Research and KM assistants. Finance AI in the back office. A firm that only logs the sanctioned ChatGPT Enterprise workspace still has no proof, and cannot see Copilot in the matter document.
What partners need on the row
- Proof: who used which AI system, on what, under which policy.
- Sanctioned or shadow.
- A hash-chain export when a client or insurer asks for evidence of control.
- A live trail for operators.
Questions
Related
