Your firm is already running on AI. Some of it you approved — a research tool, a drafting assistant, the features now baked into the software your team opens every morning. A lot of it you didn’t. Attorneys and staff are pasting work into free chatbots, running browser extensions that read what’s on the screen, and connecting assistants to their inboxes and calendars. Most of that activity happens outside anything IT can see.

That gap is quietly becoming one of the more serious risks a law firm carries right now. And a newer class of AI is widening it.

From tools that answer to tools that act

The AI most people picture answers a question and stops. The AI showing up now does things: it reads an inbox, moves files, fills forms, and takes the next step on its own. These are often called AI agents, and they change the security math.

Forrester’s 2026 threat research placed AI agents near the top of the risks businesses should plan for this year. The point worth sitting with is where the danger comes from. It isn’t only outside attackers wielding AI. A large share of the exposure stems from what organizations create for themselves by allowing AI agents to operate without controls. Personal agents slip into a firm through a browser add-on or an inbox connection, then reach data at machine speed with no one watching — a helper nobody approved, working outside every policy the firm has.

For a law firm, the risk is specific. When an unapproved tool sends client data to an outside service, that’s a confidentiality problem — whether or not anyone meant to create one.

The numbers behind the gap

The scale of unmonitored AI use is easy to underestimate. Netskope’s Cloud and Threat Report for 2026 found that 47% of generative AI users still access those tools through personal, unmanaged accounts — a path that skirts company data controls entirely. Clio’s 2025 Legal Trends Report tells a similar story within the profession: 79% of legal professionals now use AI, yet more than half say their firm has no AI policy in place or they aren’t aware of one. Adoption has outrun the rules meant to guide it.

The cost of leaving that gap open is measurable. IBM’s 2025 Cost of a Data Breach Report found that “shadow AI” — employees using unapproved AI tools — added roughly $670,000 to the average breach. Among organizations that suffered an AI-related breach, 63% either had no AI governance policy or were still developing one, and 97% lacked proper AI access controls. The same report points the other way, too: organizations that used AI and automation extensively in their security operations saved an average of $1.9 million per breach and contained incidents about 80 days faster. Governance and the security to back it up don’t just reduce risk — they lower the bill when something does go wrong.

Set that against a sector already under pressure. Threat researchers tracked more than 200 ransomware incidents targeting law firms and legal services organizations between 2025 and early 2026. Firms hold exactly what attackers want — sensitive client information, under deadline pressure — and unmonitored AI hands them one more way in.

The fix isn’t a ban. It’s governance.

The instinct to ban AI is understandable, and it doesn’t work. Tell a firm full of smart, busy people they can’t use a tool that saves them an hour a day, and they’ll use it anyway — just on personal accounts, out of sight, where the risk is highest. A blanket ban doesn’t remove the exposure. It relocates it somewhere you can’t manage.

The workable answer is structure. Adopt AI on purpose, with guardrails, so your team gets the benefit without the firm carrying invisible risk. In practice, that means a few connected moves:

  • See what’s actually in use. You can’t govern what you can’t find. That starts with an honest inventory of the AI touching your firm — tools you deployed, agents running through browsers and inboxes, and the personal accounts staff use on the side.
  • Set clear rules people can follow. A practical acceptable-use policy draws bright lines: what’s fine for everyday work, what needs review, and what never happens— such as putting confidential client data into a public tool.
  • Approve the tools and keep a human in the loop. Vet what the firm sanctions, and require that a person verify AI output before it reaches a client or a court.
  • Put controls and monitoring around it. Access limits, logging, and detection turn AI from a blind spot into something you can watch and manage.
  • Train the people using it. Guardrails only hold when everyone understands them.

This is the work Innovative Computing Systems handles through Managed Intelligence, part of the Innovative Managed Solution. We help firms adopt and operationalize AI in a structured, secure, and practical way — the policy, the tool approvals, the governance framework — and we pair it with the security side, so the same firm watching for AI misuse is also watching for the ransomware crews that treat law firms as easy marks. We work alongside your team, not over the top of them. You get the upside of AI without inheriting a risk nobody signed off on.

The bar is moving in the same direction

Governance isn’t only a security measure anymore; it’s becoming a professional expectation. The American Bar Association’s Formal Opinion 512 set the national baseline for lawyers’ use of generative AI, and as of 2026, 11 states plus the District of Columbia have issued their own formal ethics opinions on the subject. California is going further still: proposed rule amendments would require managing lawyers to establish internal policies governing the use of AI, placing it alongside long-standing duties like conflict screening. The direction is clear. Firms that build governance now are getting ahead of where the rules are already heading.

You can have both

Adopting AI and staying secure are not opposing choices. You don’t have to freeze while competitors move, and you don’t have to gamble with client trust to keep up. With the right structure — and a partner handling both the governance and the security behind it — your firm can put AI to work while your systems stay safe, secure, and reliable.

That’s the whole idea. You focus on practicing law and taking care of your clients. We’ve got your back on the technology that makes it possible.

Ready to put structure around the AI your firm already uses? Talk with Innovative Computing Systems about Managed Intelligence — and let’s make AI a safe, secure, and reliable part of how your firm works.