Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

A recent AI security breach shows why law firms need access controls on their AI tools before scaling automation across client matters.

The Hugging Face Breach Is a Warning for Law Firms
Insight ai

The Hugging Face Breach Is a Warning for Law Firms

Sam McKay

A security researcher recently found that an AI agent running inside Hugging Face’s infrastructure had access it should never have had. No malicious actor. No sophisticated exploit. Just an agent with permissions nobody had bothered to scope down, sitting quietly with reach into systems far beyond its job description. The incident made the rounds in security circles for a simple reason. It’s the clearest proof yet that AI agents need the same access discipline you’d apply to a new paralegal on day one, not the blanket trust you’d give a senior partner who’s been with the firm for fifteen years.

If you run a law firm and you’ve started using AI tools for intake, document review, or matter triage, this should get your attention. Not because your AI vendor is reckless. Because most firms have no idea what data their AI tools can actually see, and that’s a privilege problem hiding behind a productivity win.

The access question nobody’s asking

Here’s what usually happens. A firm adopts an AI tool to speed up intake or first-pass document review. It works well. Someone connects it to the case management system so it can pull matter details automatically. Someone else gives it calendar access so it can book consultations. Within a few months, that tool has read access to client files, conflict data, billing records, and communication history, because connecting everything felt easier than scoping it carefully.

Nobody sat down and asked: what does this agent actually need to see to do its job? That question is exactly what privileged access management has always been about for human employees. A junior associate doesn’t get partner-level access to every matter in the firm. A paralegal doesn’t see billing rates for clients they’ve never worked on. Yet most firms hand their AI tools broad access by default, because scoping permissions takes more setup time than clicking “connect all.”

The Hugging Face incident is a preview of what happens when that habit meets scale. An agent with too much reach becomes a single point of failure for your entire client data set, not just the task it was built for.

What this actually costs a firm like yours

This isn’t just a security abstraction. It’s tied to the same manual work that’s already draining margin at firms doing $1M to $25M in revenue. We typically see three problems stacked on top of each other, and each one gets worse when automation is added without access controls.

Billable-hour leakage. Attorneys at firms this size lose somewhere in the range of 4 to 6 hours a week to document review, intake admin, and matter housekeeping that never shows up on an invoice. Firms try to fix this with AI tools, which is the right instinct, but if those tools are bolted on without a clear permission structure, you’ve traded an efficiency problem for a data governance problem.

Intake delays that cost you the client. A call comes in at 7pm on a Thursday. Nobody picks up. By the time someone calls back Friday morning, that person has already spoken with two other firms. Industry ranges suggest 30-40% of after-hours intake never converts, and that’s before you even build an AI intake agent. Once you do build one, if it isn’t conflict-checking properly or if it has access to matters it shouldn’t, you’ve created a new liability inside a fix for an old one.

Discovery and document review. Junior associate time on first-pass review runs $200-400 an hour depending on your market and seniority mix. Multiply that across a mid-size discovery batch and it’s real money, which is why so many firms are looking at document review agents right now. The catch is the same one running through everything else here. A review agent needs access to the documents in a matter. It does not need standing access to every matter the firm has ever touched.

Firms in the $1M-$25M range typically leak somewhere between $80,000 and $250,000 a year in unbilled time, missed intake, and review inefficiency. That's the band we see most often when we run a structured audit, before any AI access risk is even factored in.

What role-based AI access actually looks like

You don’t need a security team to fix this. You need the same discipline you already apply to staff access, applied to your AI tools before you scale them further.

Start by mapping what each agent can actually reach. If you’re running an intake tool, does it need read access to every closed matter from the last decade, or just enough conflict data to clear a new caller? If you’re running a document review tool, is it scoped to the matter it’s working on, or does it have a standing connection to your entire document management system?

This is the exact audit we run when a firm engages us. We look at every AI tool touching client data, map what it can access against what it needs to access, and rebuild the permission structure around the job, not the vendor’s default settings. It’s the same principle behind role-based access for staff, just applied to software that’s now doing staff-level work.

A well-built Intake Voice Agent is a good example of doing this right. It answers every call, including after-hours, lunch, and weekends, runs a conflict check against the matters it’s scoped to see, captures the details of the new matter, and books a consultation directly into the calendar. It doesn’t need to see every client file the firm has ever opened. It needs conflict data and calendar access, and that’s it. Scoped correctly, it closes the intake gap without becoming a liability.

A Matter Triage Agent works the same way. It reviews incoming forms and emails, classifies the practice area, scores fit against your intake criteria, and routes the file to the right partner with a short brief attached. It touches new inbound information, not your entire historical archive. When it’s built with that boundary in mind, it speeds up routing without turning into a backdoor into every case the firm has run.

Compare that to a firm that connects an off-the-shelf AI assistant to its whole practice management platform because it was the fastest way to get started. That firm now has an agent with reach into privileged client communications, billing, and matter strategy across every practice group, doing a job that only needed a fraction of that access. That’s the exact pattern the Hugging Face incident exposed, just moved from a tech company’s infrastructure into a law firm’s client files.

Document review deserves its own scrutiny

Discovery work is where access sprawl gets especially risky, because the documents themselves often contain privileged material, opposing counsel correspondence, and sensitive client information that has nothing to do with the matter at hand if the tool wasn’t scoped properly.

A Document Review Agent built the right way runs first-pass review on a specific batch, flags relevant clauses, summarizes positions, and produces an associate-grade memo, all inside the boundary of the matter it was assigned. It should not carry access into unrelated files, other clients’ discovery sets, or firm financials. If your current review tool has broader access than that, you’ve got exposure sitting quietly in a system nobody’s reviewed since it was set up.

This is worth walking through with your team, or with us. If you want a structured way to think about what your intake process should look like once access controls are in place, our AI Client Intake Checklist for Law Firms is a practical worksheet built for exactly this. It walks through what a properly scoped intake flow should capture, check, and hand off, so you’re not guessing at what “correct access” looks like when you sit down with a vendor. You can grab the direct checklist download if you want to work through it before your next tool decision.

Why this matters more as you scale automation

The firms most exposed to this problem aren’t the ones avoiding AI. They’re the ones who moved fast, connected everything, and never went back to tighten it up. That’s a normal pattern. Nobody builds a new intake process and immediately audits its permission structure on day one. But at $1M to $25M in revenue, you’re at exactly the size where a single access misstep touches enough client matters to matter, without the compliance headcount of a firm ten times your size to catch it.

If you’re weighing whether to expand your use of AI agents across intake, triage, or review, the access question needs to come before the rollout, not after. That’s a different sequence than most vendors will walk you through, because most vendors are selling the feature, not the governance around it. We built our advisory work specifically to sit in that gap. If you want to see how this fits into a broader operating model, our advisory service walks through how firms structure AI adoption around access and accountability rather than just speed.

This is also where a lot of firms realize their intake and voice tools need the same review. Our voice agent platform and ops automation tools are both built with scoped access as a starting assumption, not an afterthought bolted on later. That’s a deliberate choice, because we’ve seen what happens when it isn’t.

What an Omni Audit actually does

We run a 60-minute audit specifically built for firms in your position. No deck, no sales pitch dressed up as a workshop. We look at three things: what manual work is costing you the most right now, what AI tools you’re already running and what they can access, and where the two overlap in ways that create risk instead of efficiency.

You walk away with three outputs. A map of where your billable-hour leakage, intake delays, and review bottlenecks are actually costing you money, in the $80,000 to $250,000 range we typically see at this size. A clear picture of what your current AI tools can access versus what they need to access. And a short list of what to fix first, in order, with rough cost and time estimates attached.

If you want to see how this looks for firms like yours specifically, see Omni for law firms walks through the audit format in more detail. We also keep a running set of breakdowns on our insights page if you want more context before booking anything.

The Hugging Face incident is a wake-up call for anyone running AI agents at scale, and law firms have more to lose than most industries if they get this wrong. Client privilege, conflict data, and matter strategy are not the kind of information you want sitting inside a tool nobody’s scoped properly. Book a 60-min Omni Audit and we’ll walk through exactly what your current tools can see, what they should see, and what that gap is costing you.

Where to start this week

You don’t need to rip out your current tools to fix this. Start by listing every AI tool touching client data right now and writing down what system access each one has. Most firms are surprised by what they find just from that exercise alone. Then compare it against what the tool actually needs to do its job, the same way you’d review access for a new hire during onboarding.

If that exercise raises more questions than it answers, that’s normal, and it’s exactly what the audit is built to resolve. You can browse our resource library for more on how AI agents should be structured around access before you scale further, or go straight to the AI audit for law firms and get a specific answer for your firm instead of a general framework.

The firms that get ahead of this now won’t be scrambling to explain an access failure to a client eighteen months from now. Book my Omni Audit and let’s find out what your AI tools can actually see, before it becomes a problem you’re explaining to a client instead of preventing for one.