Every week brings another tool promising to transform legal work, and for a small firm the danger is buying the demonstration rather than the product. The sample looks perfect because it was chosen to. What sits behind it, meaning where your client data travels, who the supplier depends on and what you get back when you leave, comes out only when somebody asks. These are the questions to put to a supplier first.
Why due diligence on AI suppliers is a regulatory duty rather than a procurement nicety
Buying software moves no part of your regulatory position. The SRA Code of Conduct for Firms requires you to keep effective governance over the services your firm provides, and sourcing part of that work from a third party leaves you answerable for it. Client information sitting inside a supplier's system is still client information you are responsible for, and the Code of Conduct for Solicitors reads as strictly as you remember.
Data protection reaches the same tools from another side. The moment client information goes into an AI product you are processing personal data, and often special category data as well. You stay the controller, the supplier is your processor, and you need a contract meeting Article 28 that sets out what it can do with the data and the security it has to keep. The ICO's guidance on AI and data protection expects a data protection impact assessment before processing starts where that processing is likely to pose a high risk to individuals, and the exercise is much the same one the SRA expects before a firm adopts new technology. The answers you obtain are the evidence, and a firm that watched a demonstration and signed has a subscription instead.
How to run the process
Start from your requirements rather than the supplier's feature list. Write down the few tasks where time is genuinely lost, whether that is research, drafting, document review or client correspondence, and rank them. A tool that solves your second problem brilliantly and your first not at all is the wrong tool.
Two people should own the exercise, being the partner who will live with the tool and the person who owns compliance in the firm. Send the questions in writing ahead of the commercial conversation, because a supplier answers differently on paper than across a table, and where an answer matters enough, ask for the same words in the contract.
Alongside the paper, run a short trial on your own closed matters with the people who would use the tool daily, and judge the output as you would a trainee's work. Count the corrections, because a licence that is cheap to buy and expensive to supervise can cost more than it returns. Then reduce the exercise to one page per tool, holding what it does, what data it touches, when the contract ends and who owns the company today, and review that register twice a year.
The company and its stability
Who owns the company today, and what happens to our contract if that changes?
Legal AI suppliers are buying each other. When the Swedish supplier Legora agreed on 29 July to buy Wexler, a British start-up whose software pulls facts out of large litigation document sets, it was Legora's fifth acquisition of 2026. Little changes on the day of a deal, which is what lulls firms into ignoring it. Pricing gets rebased, support moves to another country, and the roadmap you were promised is absorbed into somebody else's. Ask for a notice obligation in the agreement.
Which other companies does this product depend on to run, and will you name them?
Your engagement is with the supplier whose invoice you pay, and that supplier buys hosting, screening data, model capacity and search from companies your contract never names. When LexisNexis took three of its Nexis products offline between Wednesday 5 August 2026 and the following Monday, after identifying what it called unusual activity on servers hosted and managed by a third-party vendor, the failure sat in neither your firm nor your supplier and it still stopped the work. A supplier that cannot produce a sub-processor list has not thought about its own dependencies.
Which model sits behind each feature, and what happens when that changes?
Most legal AI products have been a layer of software over somebody else's model, which matters because the promises about accuracy and data handling then run through your supplier to a company you have no contract with. Some suppliers now own the model instead. Thomson Reuters announced on 24 August 2026 that it had trained a model named Thomson on the content behind Westlaw, Practical Law, Checkpoint and Reuters. Ask for written notice when a model is swapped or retrained, because your supervision arrangements were built around the behaviour of the old one.
Where your data goes and who sees it
Where is our data processed and stored, and which countries does it pass through?
A tool can sound local and still send data abroad, to a provider's servers or to a sub-processor elsewhere, and the answer is rarely on the marketing page. When you send a prompt to a hosted model you disclose its contents to the company running it, and if that operator falls under a legal regime that can compel access to data held on its systems, your client's information sits within that reach. A bad answer describes the encryption and hopes that satisfies you.
Which lawful transfer route covers data that leaves the United Kingdom?
Where data leaves the country you need a lawful basis for the transfer, such as a UK adequacy finding or the UK addendum to the standard contractual clauses, and the provider's contract should set it out. The ICO's guidance on international transfers holds the mechanics. If the supplier cannot identify the route it relies on, the tool is not ready for client data.
Who inside your company can reach our data, and under what controls?
Access is the question firms skip because it feels rude, and it decides whether a privileged document on a supplier's infrastructure is protected by anything beyond good intentions. Ask which roles can read customer content, what authorisation a support engineer needs before opening a matter, and whether that access is logged. An answer that says only that staff are trained has described a policy rather than a control.
Training on your data and confidentiality
Does our data train your models, and will you put that in the contract?
For client data the answer needs to be no, and it needs to sit in the agreement rather than in a sales email. The gap between a free consumer version and a paid business tier is often the gap between a breach and a safe workflow, because consumer products store what you type and use it to train future models. Paid products are not automatically different, and the only way to know is to read the clause.
Is there a data processing agreement that meets the UK GDPR?
The provider processes data on your instructions, which makes an Article 28 contract a requirement rather than a preference, and the ICO's UK GDPR guidance explains what one has to contain. Read it rather than file it, because an agreement that says nothing about sub-processor notice, deletion on termination or assistance with a subject access request has met the form and missed the point.
What do you retain, for how long, and can we have it deleted?
Many tools retain prompts, uploads and outputs, sometimes indefinitely, which sits awkwardly with the duty to keep personal data no longer than necessary. Your retention schedule has to reach the supplier's systems as well as your own, and a tool that cannot delete on request is a reason to think again. Ask too what happens when a client makes a subject access request.
Security and incident response
What will you tell us when something goes wrong inside your systems, and within what period?
Almost no supplier agreement promises to tell the customer when the software goes wrong, which is why this is the question you will miss most keenly if you skip it. Ask what the supplier undertakes to tell you, within what period, and whether that duty survives the supplier deciding the matter was minor. One that offers its published safety commitments instead has told you that the detail you would need after an incident is the detail it prefers not to give you before one.
What can the tool reach without a person approving the step, and what do you record when it acts?
Agentic tools act inside your systems, and the scope of that action is a written question rather than a demonstration question. On 9 September 2026 Senator Josh Hawley put sixteen questions to OpenAI about the incident in July when the company's own experimental models left the environment they were being tested in and reached the internal systems of Hugging Face. Establish what the tool can reach without approval, what the supplier records when it acts, and whether you can obtain those records.
Accuracy, verification and limits
What evidence do you have for accuracy on the work we do?
Performance claims in this market are usually the supplier's own early evaluations, which is a fair thing for a vendor to say about its own work and a weak thing for a buyer to rely on. Tabular analysis across a bundle of leases is a different task from finding the authority that decides a point, and a model scoring well on one tells you little about the other. A supplier that claims no weaknesses at all has either not tested the product on difficult work or has decided not to tell you what it found. The SRA's research on AI in the legal market checks the arithmetic a supplier offers you.
Contract terms and pricing
Is our pricing moving to a consumption basis, and what happens when the allowance runs out?
The flat subscription that let a fee earner use a tool as often as they liked is giving way to billing by how much work the tool does. Legal IT Insider set the position out on 21 August 2026 in an interview with Rudy DeFelice of the consultancy Harbor, whose summary is blunt, that the token subsidy era has ended. Ask what the unit is and what happens at the limit. Work that stops mid matter is a service failure you plan around, and work that carries on at a rate nobody approved is a bill you will be explaining to a client.
What do you disclaim, and what will you stand behind?
Read how the supplier handles errors, downtime and changes to the service. Many AI contracts disclaim a great deal, and knowing what you are carrying yourself is part of the decision. The regulatory half is settled already, because the work that leaves your firm is yours whether or not software produced it. The commercial half stays open until somebody reads the agreement.
Exit, continuity and outages
Can we export our data and our prompt history in a usable format?
Check what happens to your data if you leave, whether you can export it, and how long the provider keeps it after you go. A usable format means something your next system can read rather than a screen dump, and prompt history matters because it records how the work was done. Exit assistance is a clause suppliers concede before signature and resist afterwards.
What do you owe us when the service is unavailable, and how quickly are we told?
A tool that goes dark for four working days does not stop the work arriving. Completions keep their dates, and the risk in a small practice is what somebody does at four o'clock on the Friday when the check will not run and the file has to move. Ask what the supplier owes you, and how fast you are told.
Then write down, for each tool touching a regulated step, what your firm does while it is unavailable, naming the second source and who authorises the switch. When Fable 5 and Mythos 5 went dark for about nineteen days under United States export controls, the firms that felt it were the ones that had routed drafting or document review through a single tool without anybody deciding that the firm now depended on it.
Regulation
Does the Cyber Resilience Act reporting duty catch you, and what will you tell us when you file?
The Cyber Resilience Act started asking something of your software suppliers on 11 September 2026. Regulation (EU) 2024/2847 gives a manufacturer of a product with digital elements a duty to move once it becomes aware that a vulnerability in that product is being actively exploited or that a severe security incident has affected it. An early warning goes in within 24 hours, a fuller notification inside 72 hours, and the final report no later than 14 days after a fix is available. The duty sits on whoever places the product on the European market, which catches many of the companies selling into the legal sector here.
Ask each supplier that matters whether the duty catches it, and one that says no should be able to explain why. Then ask what the regulation leaves open, being what the supplier undertakes to tell you, its paying customer, and within what period, when it files. The European Commission's page on the reporting obligations sets out the deadlines. A business keeping a 24 hour duty to a state authority can reach its customers inside the same day.
Will you tell us before you add or change a sub-processor?
A new owner brings a new set of sub-processors, and a supplier that changes infrastructure changes the security regime your client data sits under and the list of people who can read it. None of that is improper. Under the UK GDPR the new owner becomes your processor, so your record of processing activities and your privacy notice need updating to name the right company.
Red flags that end the conversation
Vague answers are an answer in themselves. A supplier that will not say where data is stored, that cannot identify the transfer route it relies on, or that describes its encryption when you asked about access, has told you the tool is not ready for client work.
Watch for the substitutions. Published safety commitments offered in place of a disclosure undertaking, a demonstration offered in place of an evaluation on your kind of work, an assurance in an email offered in place of the clause you asked for. Each is a supplier choosing what it will be held to.
Two more are worth naming. A tool that cannot delete client data on request cannot live inside your retention schedule, and a long contract signed before the firm has proof of value is the lock-in that makes every later problem harder to leave.
Common questions
Who should run AI supplier due diligence in a small firm?
One partner who will own the tool if it is bought, sitting with the person who owns compliance in the firm. The partner knows the work the tool has to do and the compliance officer knows the duties it has to fit. The people who would use the product daily belong in the trial rather than in the contract reading. Nobody needs to be technical to ask what a supplier does with client data and what happens when the service stops.
Is a data processing agreement enough on its own?
No. An Article 28 contract sets out what the processor does with the data and the security it keeps, and you need one before client information goes anywhere near the tool. It does not tell you whether your data trains the supplier's models, what the supplier retains, who it depends on to run the service, or what you get back when you leave. Those answers sit in other parts of the agreement or in nothing at all until you ask.
What should we do if a supplier will not answer in writing?
Treat the refusal as the answer. A supplier that answers plainly is one you can supervise, and one that offers published commitments instead has told you that the detail you would need after an incident is the detail it prefers not to give you before one. You have leverage before signature and almost none afterwards, so the questions that matter are worth asking while you still have a signature to withhold.
Do we need to do this for a tool the firm already uses?
Yes, and the renewal is the moment to do it. Your duties run to the tools in use rather than to the ones you assessed, and suppliers change hands, change sub-processors and change pricing between one term and the next. Work through the same questions on every tool that touches client work, record the answers on a single page per tool, and review that register twice a year.
Where to go next
If a shortlist is forming and every demonstration looks convincing, the AI Vendor Selection package builds the requirements brief, the evaluation framework that tests each claim against your duties and your budget, and a negotiation note covering the terms that decide who carries the risk when a tool gets it wrong. Where the firm is not yet sure what its people already use, the AI Readiness Audit answers that first, and the guide to writing an AI use policy turns an approved supplier into rules your people follow. To talk it through, start with a conversation.
