I’ve been writing about AI and security for almost a year and unlike many others in the legal industry, I have consistently taken the position that mainstream AI tools are safe for lawyers to use so long as training is turned off—or the lawyer uses a Teams, Business, or Enterprise version with appropriate privacy protections. (See Attorneys Can Safely use Chat GPT Without Redaction) I never believed that solos and small firms need to invest in pricey, legal-specific AI platforms simply to protect confidential information. Unfortunately, many in the industry dismissed my perspective.
Now, attorney/legal technologist/e-discovery expert Craig Ball agrees. In a recent MUST READ article, Ball argues that courts are beginning to impose “enterprise-grade” AI requirements that sound protective but may do little more than price solos and small firms out of using the technology.
The problem, Ball explains, is that the expensive legal AI platforms generally rely on the same small group of foundation models—OpenAI, Anthropic, or Google—and the same cloud infrastructure as lower-cost mainstream tools. Legal-specific platforms may add valuable workflows, integrations, citation checking, document-review features, and contractual protections. But those additions do not necessarily create a fundamentally different security architecture at the model or infrastructure level.
As Ball puts it:
“The model doesn’t know whether it’s being called by a BigLaw firm’s bespoke platform or by little ol’ me. The bytes don’t care about the price tag on the Application Programming Interface (API) wrapper.”
Ball also distinguishes between technical security and contractual enhancements. A negotiated data-processing agreement may provide audit rights, breach-notification timelines, deletion deadlines, and other assurances. Those provisions may be useful, but they do not themselves change how the underlying model processes data. In Ball’s view, courts should not treat a lengthy, expensive contract as a substitute for examining the actual security settings and practices that matter.
Ball does not argue that lawyers should ignore security. Instead, he proposes practical safeguards: disable training, require authenticated and nonpublic access, isolate each matter in a separate project or workspace, delete the material when the matter concludes, and document the tool, configuration, and contractual terms being used. These measures directly address the real risks of unauthorized access, reuse, and continuing exposure.
Ball’s broader point is that courts should focus on actual protections rather than labels such as “enterprise-grade,” the existence of a bespoke data-processing agreement, or the price of the platform. Otherwise, AI protective orders risk becoming another form of technology gatekeeping—imposing substantial costs on solos and small firms without delivering any meaningful improvement in security.
That matters because AI is one of the few technologies capable of narrowing the resource gap between large firms and smaller practices. A solo lawyer using a properly configured mainstream tool may be able to analyze documents, prepare for depositions, and conduct research at a scale that previously required a team. Requirements calibrated to BigLaw budgets could deprive the lawyers and clients who stand to benefit most from that capability.
Ball doesn’t have a dog in this fight. He’s not affiliated with a purpose-built legal AI platform that uses scare tactics with solos to drive sales. Nor is he one of many regulators captive to sponsorship dollars that VC-backed AI companies are eager to throw their way. Ball has credibility because of his decades of experience in the legal tech space. For that reason, Ball’s conclusion that security should be measured by what a tool actually does, how it is configured, and how the lawyer uses should be taken seriously.