Most of the AI risk conversation inside law firms has pointed inward. Which tools are people using? What are they pasting into them? Does anyone check the output before it goes to a client? Those are the right questions, and we have spent a fair amount of time on them here.

New survey data adds a second set. The people trying to get into your firm have the same tools as your attorneys.

The International Legal Technology Association released its 2026 Technology Survey this month, drawing on responses from 508 firms. The headline number is what everybody expected: 94% of responding firms are now using or exploring generative AI, up 14 points in a single year. A second finding got less coverage and matters more for security planning. This year, for the first time in the survey’s history, generative AI appeared on the tracked list of security challenges. It went straight to second place, ahead of malware and compliance, behind only user behavior.

What firms said they are worried about

The Executive Summary is specific about where that concern sits. At the top of the list: AI-powered social engineering. Deepfake calls, synthetic phishing, impersonation at scale.

If that has a familiar ring to it, it should. We wrote in August about fake IT support calls targeting law firms, in which someone calls the help desk, sounds like someone who belongs there, and talks their way into a password reset. Voice synthesis makes that call cheaper to run and much harder to hear coming. Firms that trained their staff to listen for a bad accent or an odd turn of phrase are now training against something that has neither.

Beyond social engineering, firms face risks that live within their own environments: spotting AI behaving in ways it should not, preventing AI agents from being misused, managing AI features that arrive in third-party software the firm already licenses, and defending against prompt injection and data poisoning. That last cluster connects to something we have covered before: AI is showing up through systems firms already own, rather than through a purchase decision someone signed off on.

Then there is the defense side, where the survey found a real split. Six in ten firms have put AI-powered tools to work defending the organization, most often for around-the-clock monitoring and endpoint defense. Four in ten are not using AI defensively at all. ILTA’s authors call that a readiness gap, and they are right to do so. Attack tooling is not waiting for the other four in ten to catch up.

The gap that follows firm size

Buried in the policy tables is the finding that speaks most directly to anyone running operations at a smaller or mid-sized firm: A formal generative AI policy is in place at 98% of firms with 350 to 699 lawyers. At firms under 50 lawyers, it is 57%. Required training before anyone gets access runs at 72% at the largest firms and 11% at the smallest. Mandatory human review of AI-assisted work product: 79% versus 31%.

None of that reflects how seriously smaller firms take the problem. It reflects who is available to work on it. At a 40-lawyer firm, the person expected to write the AI policy is usually the same person who handles the phone system, new-hire onboarding, malpractice insurance renewal, and the partner whose laptop will not connect to the conference room display. The threat arrives at the same scale either way. The staffing does not.

ILTA’s authors put it plainly: “The platform migration is largely complete, but the governance migration has yet to begin.”

What we do about it

This is the part of the problem Innovative Computing Systems is built to absorb, and the survey points to the same answer firms are already reaching for. Outsourced security operations remain one of the industry’s top practices, which the authors describe as a structural shift from internal operations to a purchased-capability model.

Here is how that works in practice for the firms we support.

We run monitoring and response around the clock, so an anomaly at two in the morning is somebody’s job at two in the morning, not a discovery on Monday. Endpoint detection, managed detection and response, and log correlation are part of the Innovative Managed Solution, meaning the defensive tooling the survey found missing at four in ten firms is already in place and tuned.

We build identity verification into support procedures, because a deepfake call succeeds or fails at the help desk. Our support team is 100% U.S.-based and staffed 24/7/365, and verification steps for password resets and MFA changes are built into how we respond, so a convincing voice still has to clear a bar it cannot talk past.

We keep security awareness training current with what is actually being attempted, including synthetic voice and video, and we handle backups the way the survey describes as best practice: immutable copies, point-in-time snapshots, and air-gapped retention, tested rather than assumed.

On governance, our Managed Intelligence work covers the ground the policy tables show smaller firms carrying alone. We assess what AI is already in use, write the acceptable use policy, define the approved tool list, stand up the approval workflow, and run the training, then review it as the tools change. It connects to the verification question we wrote about recently, since somebody has to own checking the citations, and a policy is where that assignment becomes real. We’ve got your back on the parts of this that do not belong on your desk.

Where that leaves you

You should not be the person expected to out-argue a synthetic voice on a Tuesday afternoon, and you should not be the one held responsible when nobody had time to write the policy. These are preventable problems, and you deserve better than having to absorb them personally.

Innovative Computing Systems has worked exclusively with law firms since 1989, and more than 100 firms nationwide rely on us to keep their environments safe, secure, and reliable. When monitoring, verification procedures, backups, and AI governance are in place, the survey’s readiness gap is no longer your problem to solve after hours. You get the time back for the work that actually needs you.

If you want to know where your firm stands relative to what this survey found, request a consultation. A Solutions Consultant will follow up to discuss your current setup and identify any gaps.