The last two weeks of August brought five significant legal AI announcements. Most were integrations rather than products, which is why they may not have registered as news inside your firm.
On August 19, NetDocuments added AI features that turn document collections into reviewable tables and extract case citations from uploaded files. On August 21, Harvey announced a partnership with PacerPro that pipes live docket activity from federal and state courts into its platform, with new filings arriving within a minute or two of posting. On August 24, Thomson Reuters launched its own large language model, trained on Westlaw, Practical Law, and other Thomson Reuters content, and first deployed in Tabular Analysis within CoCounsel Legal. That same day, LexisNexis expanded the agentic capabilities in Lexis+ with Protégé, which can now carry context from research through drafting and reach a firm’s own work product through a connected document management system. On August 25, Google Cloud put Gemini Enterprise for Legal into preview with connectors into iManage, NetDocuments, Microsoft 365, DocuSign, RelativityOne and more.
Five announcements. Almost none of them ask your firm to buy a new application. They ask your firm to connect something.
Why this time is different
For the past two years, AI adoption has arrived through procurement. A practice group wanted a tool, someone requested a license, and the purchase order triggered a security review. Imperfect, but it had a natural checkpoint: money had to move before anything got installed.
That checkpoint is disappearing. When AI capability ships inside Westlaw, Lexis+, your document management system, or a Google or Microsoft subscription the firm already pays for, there is no purchase order to catch it. Instead, there is a toggle, a connector, or an admin consent screen. Frequently, the request that reaches you sounds small: “Can you turn this on for the litigation group?”
We wrote in July about AI showing up in firms through unmanaged accounts and unsanctioned tools. This is the same governance problem approaching from the opposite direction. The tools are sanctioned, the vendors are ones your firm has trusted for years, and the risk sits in what those tools are now permitted to reach.
What a connection actually grants
The vendors themselves are reasonably clear about this, and their answers are not identical.
Google states that client data, firm playbooks, and model outputs remain private to the organization, are never used to train or fine-tune its foundation models, and that access remains bound by the role-based and document-level permissions inherited from the document management and e-discovery systems it connects to. Thomson Reuters says it does not use customer data to train its model without explicit consent. NetDocuments notes that analysis happens inside its own platform, so documents remain governed by the firm’s existing security controls and ethical walls. The Harvey and PacerPro announcement, by contrast, describes the data flow without addressing permissions or storage at all.
Those differences are why a blanket policy on “AI tools” no longer works. Three questions decide whether a given connection is safe for your firm:
What can it reach? A connector that inherits your existing permissions is only as good as those permissions are today. If ethical walls in the document system have drifted, or if a legacy security group still grants a paralegal access to a matter she closed in 2023, an AI assistant will surface that content faster and more thoroughly than any person ever browsed for it. Inheritance carries forward whatever the underlying permission model actually says today, accurate or otherwise.
Where does firm content travel, and who can train on it? Written commitments differ between vendors and sometimes between tiers of the same product. This belongs in contract review, not in a marketing FAQ.
Who authenticates, and what gets logged? Every new connector is another credential path into client data. The FBI’s May 2026 FLASH alert on criminals impersonating IT staff at law firms, which we covered last week, recommended phishing-resistant multi-factor authentication and tighter control over remote access to sensitive systems. That guidance applies squarely here. It is also worth remembering that agents now execute work rather than just answer questions, so drafting, redaction and review need a named human reviewer and a record of what the agent did. The same question we raised about AI notetakers keeping a record you may not control applies to every agent given write access.
What we do about it
Innovative Computing Systems treats connection approval as part of Managed Intelligence, so decisions about what touches client data are made deliberately rather than one help-desk ticket at a time.
The inventory comes first: what is already connected across your document system, email tenant and research platforms, which means you have a single accurate list instead of a partial one. From there, we build an approval path that specifies who signs off on a new integration and what evidence they require, so that a request from a practice group has a clear path to approval or denial.
Vendor data handling gets reviewed against your client obligations before anything is enabled. Pilots run in a controlled group, where we check that inherited permissions match reality and catch the drift in ethical walls that nobody has time to audit. Then the approved connections become firm policy, and we train the people who use them.
We work alongside your IT staff on all of it. You keep the authority; we carry the operational load.
None of this is an argument against these tools. Legal-specific AI running within platforms your firm already governs is a considerable improvement over attorneys pasting client material into a consumer chatbot, and firms that build an adoption strategy now will be steadier than those that react later. The point is that the decision should be made on purpose. As we noted when new research asked who is actually managing firm AI, the gap is rarely enthusiasm. It is ownership.
You should not have to absorb five vendor announcements in a week and work out on your own what each one means for client confidentiality. That is our job. We keep your environment safe, secure, and reliable so you can spend your day on the work that actually needs you. We’ve got your back.
Ready to get a handle on what is connected to your firm’s systems? Request a free Legal IT consultation. Tell us what you are running, and one of our Solutions Consultants will follow up to talk through your AI integrations, document management and security.
