Local AI can address part of that concern by keeping model processing within a firm-controlled environment. Accuracy requires its own safeguards. A sound adoption plan deals with both, giving attorneys a defined way to use AI while retaining responsibility for the work.
The sanctions concern has a concrete basis
On February 9, 2026, the Tenth Circuit sanctioned an attorney representing herself in Amarsingh v. Frontier Airlines, Inc. Her brief contained seven fabricated case citations generated with ChatGPT, and she admitted that she had not verified them. The court ordered her to pay $1,000 to Frontier to offset fees and costs associated with the problems and directed that its order be sent to Maryland’s attorney-disciplinary authority. Read the court’s order, particularly pages 12-18.
The court identified a failure to check whether authorities existed, supported the propositions asserted, and contained the attributed quotations. Those are useful points around which to design a review process. A citation that looks plausible still needs to be opened and read.
The lesson extends beyond research. A summary can misstate testimony. A draft can add a fact that never appeared in the record. The person reviewing an AI-assisted document needs access to the underlying material, along with time to compare it.
Separate accuracy from confidentiality
These risks call for different questions:
| Concern | Question the firm must answer |
|---|---|
| Incorrect or fabricated output | How will we verify the facts, quotations, and authorities? |
| Exposure of client information | Where does the information go, and who can access it? |
| Uncontrolled use by staff | Which tools and tasks are approved, and who reviews the work? |
Moving a model into the office changes where it processes information. It does not make its output inherently reliable. NIST describes confidently generated false content as a risk arising from how generative models work. The practical implication is that a local deployment still needs factual verification. NIST’s Generative AI Profile, section 2.2.
That distinction makes the purchase decision clearer. Evaluate the system’s data handling and its performance on your actual tasks separately. Neither should serve as a substitute for evidence about the other.
What a local LLM can change
A locally deployed large language model can process prompts and documents on the firm’s own hardware. In a fully local workflow, that processing does not require sending the material to an external model provider.
For example, Ollama documents local processing and provides a setting to disable its cloud features. That illustrates the distinction between local and cloud operation; it does not establish how any particular legal product is configured.
For a law firm, the value is greater control over a specific part of the data path. The firm can decide which material enters the environment, which users receive access, and which connections are permitted.
Before relying on that arrangement, ask the provider to show the complete workflow. Document conversion, transcription, search indexes, backups, diagnostics, and remote support may involve additional systems. A local model inside an application that sends documents elsewhere is only one local component.
Also establish who maintains the hardware and software. Keeping processing in the office brings operational responsibilities with it, including updates, access management, and recovery when equipment fails.
Protecting privilege takes more than a deployment location
Confidentiality and attorney-client privilege are related, but distinct. The ABA’s commentary to Model Rule 1.6 distinguishes privilege and work-product protections from the broader ethical duty to protect information relating to a representation. See Model Rule 1.6, comment 3.
A server’s location cannot determine whether a communication is privileged or guarantee that protection will never be lost. Local processing can reduce a particular disclosure pathway. The firm must still assess applicable law, access, client instructions, and how information is used or shared.
ABA Formal Opinion 512 calls for evaluating potential disclosure both outside and inside the firm. It also addresses competence, supervision, and circumstances requiring informed consent. This is guidance based on the Model Rules; firms must apply their governing jurisdiction’s rules and relevant court requirements.
That makes matter-level access important. An employee’s ability to use the assistant should not automatically grant access to every client’s documents. Review who can retrieve material, who can see saved conversations, and how ethical walls are enforced.
Give attorneys a defined first use
A practical starting point is a limited internal task with source material the reviewer can inspect. Possible pilots include preparing a chronology from an approved document set, comparing two contract versions, or assembling a draft summary for attorney review.
Consider a hypothetical chronology project. The assistant proposes an event date, a short description, and a reference to the supporting page. The reviewing attorney checks the date against the source, confirms whose account it reflects, and decides whether the event matters. If the documents conflict, the chronology preserves the disagreement instead of quietly selecting an answer.
Use a small test set with known answers, including missing pages, conflicting dates, and an irrelevant document. That makes errors visible before the workflow expands. Judge the pilot on the accuracy of the reviewed result and the total time required, including corrections.
For legal research, retain a separate verification step: retrieve the actual authority from a trusted legal research source, read the relevant passage, and check its current status and applicability. Asking the same model whether its earlier answer was correct is not independent verification.
Where Onbox fits
Onbox is David AI Systems’ locally deployed AI system built specifically for attorneys. For firms concerned about sending sensitive material to an external model, it provides a local approach to discuss and evaluate against their requirements.
The most useful demonstration should use a workflow your firm understands, with nonconfidential sample documents. Ask to see where the material is processed, what the system retains, how access is restricted, and how a reviewer checks the output. Test the difficult examples as carefully as the straightforward ones.
This gives the firm a concrete basis for deciding where AI belongs in its practice. Attorneys can gain help with preparation and organization while keeping professional judgment and final review with the people responsible for the matter.
Talk with David AI Systems about Onbox using one workflow your attorneys want help with. Bring your data-handling requirements and review standards so the conversation starts with the way your firm actually practices.
← All articles