Shadow AI in Legal Firms: What You Don't Know Is Happening | NSP
Dayna-Jean Broeders
21 July 2026
12 min
ReadShadow AI in Legal Firms: What Your Staff Are Using - And What You Don't Know About It
Seventy-nine percent of legal professionals say they use AI in their work. Only thirty percent of law firms have an AI policy in place.
Between how much AI is already being used and how much governance exists around it - is where most NZ law firms currently sit. Not because they've made a deliberate decision to allow unsanctioned AI use. Because the tools arrived faster than the policies, one useful application at a time, until AI became part of how the work gets done without anyone formally deciding it should.
This is shadow AI. And in the legal sector, the consequences of getting it wrong sit alongside professional conduct obligations that most other industries simply don't face.
Why Legal Professionals Are Turning to AI - With or Without Approval
Legal work is under more pressure than it has been in a generation. Client expectations have shifted. The volume and complexity of matters has increased. The economic model of billing for research, drafting, and document review is being disrupted by tools that compress those timelines dramatically.
Lawyers and legal support staff are turning to AI for the same reason any professional does: it makes work that used to take hours take minutes. A paralegal who discovers that a research task can be completed in twenty minutes instead of two hours isn't going to stop using the tool that made that possible. A lawyer who finds that a first-draft contract clause can be generated and refined in the time it used to take to find the precedent is going to keep using that workflow.
The problem isn't the instinct. The problem is that these individual decisions - each entirely reasonable in isolation - add up to something leadership has no visibility into: a distributed AI adoption pattern that nobody mapped, nobody assessed, and nobody approved.
What Shadow AI Looks Like in a Law Firm
Shadow AI in legal firms doesn't look like a rogue technology project or a deliberate policy breach. It looks like this:
A senior associate summarising a lengthy discovery document using ChatGPT to pull out key themes and dates - saving two hours on a billing day that's already overcommitted. The document contains client names, transaction details, and commercially sensitive information. The associate isn't trying to breach confidentiality. They're trying to get through their workload.
A paralegal drafting a first-pass employment agreement using a free AI tool to generate the structure and key clauses, then editing it into shape. The final document will go through partner review. But the initial generation happened on a platform with no data processing agreement with the firm.
A legal secretary using an AI meeting summariser - one that was added to Teams by someone in the firm months ago - to produce notes from a client call. The full transcript of that call, including privileged legal advice, is now stored on a third-party server the firm has no oversight of.
A lawyer using Copilot features inside Microsoft 365 that were activated by a recent update - without realising those features were now processing information from their inbox and documents as part of the summarisation functionality.
A partner experimenting with a legal research AI tool on a free trial, connected to their work email, to run searches on a contested matter. The tool's terms of service permit using search queries to train the model.
None of these people intended to create a compliance problem. All of them did.
The common thread across all of these scenarios is that leadership has no visibility into any of it. The firm's IT function, if it has one, hasn't been asked to approve these tools. No data processing assessment has been done. No staff training on safe AI use has been delivered. And the information governance frameworks the firm spent years building have a category of activity they simply don't account for.
Where AI Is Genuinely Creating Value in Legal Work
Before discussing the risks further, it's worth being clear: the staff using AI aren't wrong to see value in it. The tools are genuinely useful. The question isn't whether law firms should use AI - they should, and the firms that use it well will be more competitive than those that don't. The question is whether that use is happening in a way the firm can stand behind.
Here's what well-governed AI use looks like in a legal context:
Legal research - AI tools trained on case law, statutes, and commentary can significantly compress the time required for preliminary research. Used with appropriate scepticism - AI hallucination in legal research is a documented and serious problem - and with human review before any output is relied upon, the productivity gain is real.
Document review and due diligence - AI-assisted review of large document sets for contract analysis, disclosure review, and due diligence can compress timelines that previously required significant associate time. For NZ firms handling complex commercial transactions or litigation matters, this is one of the most significant operational opportunities AI presents.
Contract drafting and precedent management - Using Microsoft Copilot within a firm's existing Microsoft 365 environment - where data governance controls are already applied - allows lawyers to generate first drafts from precedents without that data leaving the firm's managed environment. This is meaningfully different from using a public AI tool for the same purpose.
Client communication drafting - Drafting and refining correspondence, particularly for routine matters, is a legitimate time-saving application. The key distinction is that the communication still goes through the lawyer's professional judgement before it's sent.
Matter summaries and status reports - AI-assisted summarisation of matter history for internal use - preparing for a call, briefing a colleague, or producing a status update - is a low-risk, high-value application when done within a governed environment.
Administrative and billing support - Time entry drafting, invoice narrative generation, and administrative correspondence are areas where AI can recover significant time without touching privileged matter content.
The distinction that matters across all of these is not whether AI is used - it's whether the data that AI processes is staying within the firm's governed environment, and whether the output is being reviewed by a professional before it's acted on.
The Specific Risks for NZ Law Firms
Most industries face shadow AI as primarily a data security and governance concern. Law firms face that - and then the professional conduct layer on top of it.
Client confidentiality - The lawyer-client relationship is built on confidentiality. When client matter content is entered into a public AI tool, that information leaves the firm's control and enters a third-party system with its own data handling practices. Most public AI tools' terms of service permit using input data in ways that are incompatible with legal professional obligations. The fact that no breach has been discovered yet doesn't mean one hasn't occurred.
Professional privilege - Privileged communications and advice that passes through an unapproved AI platform raises genuine questions about whether privilege has been inadvertently waived. This is not a hypothetical risk in the NZ legal context - it's an issue that surfaces in discovery and in professional conduct complaints.
The New Zealand Law Society's position - The NZLS has published guidance on the use of AI in legal practice, and the direction of travel is clear: lawyers are responsible for the work product they deliver regardless of how it was generated, and obligations of confidentiality and competence apply equally to AI-assisted work. "My staff member used AI without my knowledge" is not a defence that the NZLS will find compelling.
AI hallucination in legal work - AI tools generate confident, plausible-sounding output that is sometimes factually wrong. In legal drafting, a hallucinated case citation, a misquoted statute, or an inaccurate statement of legal principle that isn't caught in review becomes the firm's professional liability. Several jurisdictions have already seen courts impose sanctions on lawyers who submitted AI-generated filings without adequate review. NZ courts are watching these cases.
Inconsistent AI usage across the firm - Different lawyers using different AI tools for similar tasks produces inconsistent outputs, inconsistent quality controls, and inconsistent data governance. A firm that has inadvertently created five different AI workflows - each with different data handling, different review processes, and different quality standards - has a quality assurance problem as much as a governance one.
Privacy Act 2020 obligations - If client personal information is processed through AI tools without adequate data governance, the firm's Privacy Act obligations are relevant. The Privacy Commissioner has signalled increasing attention to how professional services firms handle the personal information of clients and third parties.
Contractual obligations to clients - Many commercial client engagements include confidentiality and data handling clauses that govern how the firm may process client information. Using AI tools without considering whether those clauses permit it creates contractual exposure the firm may not be aware of.
The Visibility Problem
Here's the fundamental challenge: before a law firm can govern AI use, it needs to understand what AI use is actually happening.
Most NZ law firms that have thought seriously about AI governance have focused on policy - drafting an acceptable use policy, setting out what staff should and shouldn't do. Policy is the right direction but policy without visibility has a significant gap: it governs what you've told people to do, not what they're actually doing.
The realistic picture across most NZ law firms right now is that AI tools are in use across the organisation - some sanctioned, some not, some embedded in tools that were already approved before the AI features were added - and leadership doesn't have a complete picture of any of it. That's not a failure of intent. It's the natural result of tools that move faster than governance.
Visibility comes before policy in a genuinely effective approach. Understand what's happening, then make informed decisions about what should and shouldn't be permitted, what controls need to be in place, and what staff need to understand.
This includes visibility into Microsoft 365 itself. The Microsoft 365 environment most NZ law firms run on has AI features that have been progressively enabled through product updates - Copilot features, AI-assisted summarisation in Teams, and AI capabilities embedded in Outlook and Word. Whether these features are active, what data they're processing, and how they're configured is part of the visibility picture that an AI governance programme needs to include.
What Mature Governance Looks Like for Legal Firms
Law firms that have approached AI governance well share a common pattern: they started with understanding before they started with policy.
They found out what AI tools were in use across the firm - not by asking staff to self-report, but by gaining technical visibility into the applications and services connecting to their environment. They assessed which tools had appropriate data processing arrangements and which didn't. They identified where Microsoft 365's built-in AI capabilities were active and whether the firm's data governance settings were appropriate for those capabilities.
From that foundation, they built something practical:
An approved tool list - a clear register of AI tools that have been assessed and approved for use, with guidance on what types of work they're appropriate for and what data can and can't be used with them.
A simple AI policy - not a lengthy legal document, but a clear, readable statement of what the firm expects from staff when they use AI. What can be entered into AI tools. What requires human review. What requires approval before use. What's not permitted.
Staff training - not a one-off session, but ongoing, practical guidance that reflects how the tools are actually being used. Staff who understand why the governance exists are more likely to follow it than staff who see it as bureaucratic overhead.
Microsoft Copilot as the governed alternative - for firms on Microsoft 365 Business Premium, Microsoft Copilot provides AI capability within the firm's existing data governance environment. It doesn't send data to external models. It works within the firm's existing permissions structure. It's the difference between staff using public AI tools because there's no approved alternative, and staff having a governed, capable tool that meets their needs without the data governance risk.
Executive oversight - someone in the firm is accountable for AI governance, reviews the approved tool list regularly, and has visibility into how AI is being used. This doesn't require a dedicated AI function. It requires that someone owns the question.
Gaining Visibility Before Building Policy
If your firm hasn't yet taken a structured approach to AI governance, the starting point isn't policy - it's visibility.
Understanding what AI tools are already in use across your Microsoft 365 environment, what data those tools are processing, and where the governance gaps sit gives you the foundation for decisions that are informed rather than aspirational. It's also the honest starting point for a conversation with your partners about what responsible AI adoption in your firm actually looks like.
NSP's approach to this starts with exactly that visibility - mapping the current state of AI adoption, identifying shadow AI exposure, and reviewing Microsoft 365 configuration and AI governance posture before any policy or programme work begins. For law firms specifically, that visibility exercise also surfaces the professional conduct and Privacy Act implications that generic AI governance frameworks don't account for.
For firms ready to go further, NSP's Secure AI Accelerator provides a structured programme that moves from that initial visibility assessment through AI enablement, security, governance, and ongoing optimisation - with executive reporting that gives firm leadership a documented, evidenced picture of their AI governance maturity over time.
The firms that will use AI most effectively over the next five years won't be the ones that banned it. They'll be the ones that got ahead of it - understood what was already happening, built the governance that made safe use possible, and gave their staff the tools and guidance to use AI as a genuine competitive advantage rather than a professional liability.
If you're not sure how much AI is already in use across your firm's Microsoft 365 environment, that's the question worth starting with. NSP can help you understand your current shadow AI exposure and governance readiness before you begin building policies or wider AI initiatives.
Talk to NSP about AI for your firm →
Or call us: 0508 010 101
Frequently Asked Questions
What is shadow AI in a law firm? Shadow AI refers to the use of artificial intelligence tools by lawyers and legal staff without formal approval, oversight, or governance from the firm's IT or management function. It typically includes public AI tools like ChatGPT being used for research, drafting, or document review, as well as AI features embedded in existing software that were enabled without a formal review. Shadow AI is particularly significant in law firms because of the professional conduct, confidentiality, and privacy obligations that apply to client information.
Is shadow AI a real risk for NZ law firms? Yes. The primary risks include client confidentiality breaches - when matter content is entered into public AI tools with permissive data handling terms - AI hallucination producing inaccurate legal output, inconsistent quality standards across the firm, and potential professional conduct issues under the NZLS's AI guidance. The Privacy Act 2020 is also relevant where client personal information is processed through unapproved tools without adequate data governance.
What should a NZ law firm do about shadow AI? The first step is gaining visibility - understanding what AI tools are actually in use across the firm, including AI features embedded in existing software and Microsoft 365 tools. From that foundation, firms can develop a practical AI policy, build an approved tool list, deliver staff training, and implement Microsoft Copilot as a governed AI capability within the firm's existing environment.
Can law firms use AI tools safely? Yes - with appropriate governance. The key distinctions are whether client and matter data stays within the firm's governed environment, whether AI-generated output is reviewed by a qualified professional before it's relied upon, and whether the tools in use have been assessed for compatibility with the firm's confidentiality and data protection obligations. Microsoft Copilot within a properly configured Microsoft 365 environment is the most common example of governed AI use in a legal context.
What is Microsoft Copilot and is it safe for law firms? Microsoft Copilot is Microsoft's AI assistant integrated into Microsoft 365 applications including Outlook, Word, Teams, and SharePoint. When properly configured, Copilot operates within the firm's existing Microsoft 365 data governance environment - it doesn't send data to external AI models, and it respects the firm's existing permissions and access controls. This makes it a fundamentally different proposition from public AI tools in terms of data governance risk, though appropriate configuration and staff training are still required.
Suggested Internal Links
- Why Law Firms Are One of the Most Targeted Industries in NZ Right Now
- Cloud Drift Management: Why Security Doesn't Stay Fixed in the Cloud
- What Is Microsoft Entra ID and Why Does Every NZ Business Need to Understand It?
- NSP Secure AI Accelerator
- AI Governance - NSP
- Cybersecurity Assessments - NSP
- Managed IT - NSP
CATEGORY
- Cybersecurity (84)
- Digital transformation (31)
- Managed services (30)
- Awareness and education (23)
- Cloud (23)
- Breach (16)
- IT Risk (16)
- AI (12)
- modern workplace (12)
- Collaboration (11)
- Cyber Smart Week (11)
- Business strategy (9)
- Culture (9)
- Backup (8)
- Remote Workers (8)
- microsoft (8)
- copilot (7)
- Cyber Insurance (6)
- Future of work (6)
- Managed Detection & Response (MDR) (6)
- network performance (6)
- Vulnerability Assessment (5)
- Microsoft Teams (4)
- vCISO (4)
- 0365 (3)
- IT budget (3)
- Legal Industry (3)
- Best Practice (2)
- Construction Industry (2)
- Governance (2)
- Penetration Testing (2)
- Tabletop Exercise (2)
- health IT consultant (2)
- Healthcare (1)
RECENT POST
Let’s stay in touch!
Enter your details below to stay up-to-date with the latest IT solutions and security measures.