Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Protect client data while using AI agents for intake, triage, and document review with clear access controls and human approval.

AI Agent Security for Law Firms
Insight ai

AI Agent Security for Law Firms

Sam McKay

The recent attention around AI security, including HiddenLayer’s reported $100M funding round, points to a practical issue law firm owners can’t ignore.

AI agents are becoming useful inside legal practices. They can answer a prospective client’s call at 9:40 pm, route a commercial dispute to the right partner, summarise an incoming discovery batch, and prepare a first-pass matter brief before a lawyer opens the file.

That capability is valuable. It also creates a new exposure point.

An AI agent isn’t just a chat window. Once connected to your phone system, email, document management platform, calendar, CRM, billing system, and matter files, it becomes an active participant in your operating environment. If it has broad permissions, poor instructions, or no approval checkpoints, it can access or alter information it should never touch.

For a law firm, the risk isn’t abstract. It can mean privileged documents appearing in the wrong workflow, a conflict check being performed against incomplete data, a consultation booked into the wrong lawyer’s calendar, or an agent sending an email that sounds plausible but creates a professional responsibility problem.

The right response isn’t to ban AI agents. It’s to control their access from day one.

For firms in the $1M to $25M range, this is the practical framework: inventory every system an agent can reach, give it only the permissions required for its task, and put a human approval step in front of every external send, filing, calendar change, or material record update.

That is how you get the upside of automation without treating client confidentiality as an experiment.

AI security starts with an access inventory

Most firms don’t have a single AI platform. They have a collection of tools that have accumulated over time.

There may be a legal practice management platform, Microsoft 365 or Google Workspace, a document management system, a cloud storage folder structure, intake forms, a VoIP platform, a CRM, accounting software, e-signature tools, and individual staff using AI assistants through browser tabs.

The first job is to map the access chain.

Ask a simple question for every AI agent or AI-enabled workflow: what can this system see, read, create, edit, send, download, or delete?

The answer should be specific enough that a partner can understand it without technical jargon.

For example, an Intake Voice Agent may need to:

  • Receive calls from your main number after hours
  • Read the firm’s appointment availability
  • Ask a defined set of intake questions
  • Search a restricted conflict-check dataset
  • Create a provisional intake record
  • Send an internal summary to the intake team

It does not need access to every matter note, every historical email, every document folder, or the ability to send engagement letters.

A Document Review Agent may need to read a selected folder containing a discovery batch, contract set, or matter export. It may need permission to create a draft review memo in a controlled workspace. It does not need access to trust accounting, the full client directory, or authority to overwrite source documents.

This distinction is where many firms get into trouble. They connect an agent using an administrator account because it is faster during setup. Then the agent has access far beyond the original use case.

That is not an AI problem. It is a permission design problem.

If you want a structured view of where AI should sit inside your practice, start with See Omni for law firms. The point is not to add another tool. It is to identify work that can be safely automated and the controls required before it touches client data.

Minimum access means minimum access

Law firms already understand the principle of least privilege in other contexts. A junior staff member doesn’t receive unrestricted access to every sensitive matter. An external consultant doesn’t get access to every shared drive. A departing employee’s permissions are removed.

AI agents should be treated the same way.

The agent should receive the narrowest possible set of permissions for the outcome you want. That means limiting both systems and actions.

A useful way to assess this is through four questions.

What data does the agent need to read?

Be precise. “Client files” is not precise enough.

An intake agent may need the prospective client’s name, contact details, opposing party name, practice area, brief matter description, and preferred consultation time. It usually does not need to read prior legal advice, full retainer records, or financial history.

A Matter Triage Agent may need access to new form submissions and designated intake inboxes. It can classify the practice area, score fit against the firm’s criteria, identify missing information, and route the lead to the appropriate partner. It doesn’t need access to existing case strategy notes to do that work.

What can it create?

Creating records is often lower risk than editing existing ones, if the new records are clearly marked as agent-generated drafts.

For example, let an agent create a draft intake record or a preliminary document-review memo in a dedicated folder. Don’t allow it to write directly into the final matter file without a lawyer or authorised staff member reviewing the output.

What can it change?

This is where firms need restraint.

Calendar changes, contact record edits, matter status changes, document renaming, filing deadlines, billing records, and client communications can all affect legal work. Any agent permission to alter these items should be reviewed one action at a time.

A sensible rule is this: if the change affects a client, a court deadline, a financial record, or the legal status of a matter, it should require human approval.

What can it send outside the firm?

External sending is one of the most important control points.

An agent may draft a client follow-up, request missing documents, or prepare a consultation confirmation. But it should not independently send those messages until your firm has a clear approved workflow for that exact communication type.

Early in deployment, use draft-only mode. The agent prepares the message, a human reviews it, then the human sends it. Over time, a firm may choose to automate a narrow set of low-risk confirmations, such as a standard appointment reminder. Even then, the language, recipient rules, and escalation path should be tested.

For a closer look at the operating workflows behind these controls, review Omni Ops. This is where agent work is designed around defined triggers, approvals, and handoffs, not vague prompts.

The human approval rule that protects your firm

A simple operating rule works well for most firms:

Agents can collect, classify, draft, and recommend. Humans approve, send, file, and decide.

That rule isn’t perfect for every action, but it creates the right default.

Your Intake Voice Agent can answer every call after hours, lunch breaks, and weekends. It can capture the caller’s details, ask screening questions, run a limited conflict check, and book a provisional consultation into the firm’s calendar.

Before a client receives a substantive response, before an engagement is created, and before sensitive documents are requested, an authorised staff member reviews the intake.

Your Matter Triage Agent can read incoming website forms and designated emails. It can determine that a lead appears to be an employment issue, a family law dispute, or a commercial litigation matter. It can score the fit, identify urgency, and provide the relevant partner with a one-paragraph brief.

The partner or intake manager still decides whether the firm will accept the matter, what conflict process is required, and what is communicated next.

Your Document Review Agent can process a defined batch of contracts, discovery files, or transaction materials. It can identify clauses, flag variations, summarise positions, and prepare an associate-grade memo for review.

It should not amend the underlying documents, make legal conclusions without review, or file anything with a court or third party.

This approach also makes adoption easier internally. Lawyers don’t have to trust an agent as a substitute for professional judgment. They can use it as a controlled first-pass operator that removes low-value admin and gives them a clearer starting point.

Where firms lose money when they don’t automate carefully

The pressure to deploy AI usually comes from a genuine commercial issue.

Law firm owners see attorneys spending time on work that doesn’t make it onto an invoice. Intake messages sit unanswered. Associates spend days moving through large document sets. Partners become the bottleneck because every process eventually lands on their desk.

The risk is moving too quickly because the pain is real.

Across firms of this size, we usually see 4 to 6 hours per attorney per week absorbed by document review, intake follow-up, status chasing, matter administration, and internal coordination that is never fully billed. At a team level, that can become a meaningful part of the $80K to $250K annual leakage band for a typical practice in this range.

Document review is often the clearest example. Associate time may sit in the $200 to $400 per hour range, depending on market and matter type. First-pass review is necessary work, but it doesn’t always need a lawyer to begin with a blank page.

A controlled Document Review Agent can take the first pass on a designated dataset. It can extract key clauses, identify missing provisions, compare language against an approved checklist, group documents by issue, and produce a memo that tells the associate where to focus.

The associate remains responsible for the legal analysis. The agent reduces the mechanical work.

Intake is another area where access design matters. Firms commonly lose good leads after hours because no one answers quickly. Industry ranges often put unconverted after-hours intake at 30% to 40% when a firm has no structured response process.

An Intake Voice Agent can change that. But it should only access the fields it needs, create provisional records, and escalate uncertainty to a person. A bad intake response isn’t just a lost opportunity. It can create confusion around conflicts, expectations, and confidentiality.

If you want to examine these trade-offs in your own firm, Book a 60-min Omni Audit. We map the manual work, identify the safest high-value agent use cases, and show where controls need to sit before anything goes live.

Don’t begin by connecting AI to everything. Begin with one contained workflow.

A good first workflow has three traits. It happens often, follows a recognisable process, and can be checked by a human before it creates an external consequence.

For many firms, that is intake triage or document review.

Start with a small, clear scope. For example, limit the Matter Triage Agent to submissions from one web form and one monitored inbox. Give it a fixed practice-area classification list. Tell it what qualifies as urgent. Require it to create a summary and route it internally, but not communicate acceptance or rejection to the prospect.

Then test 30 to 50 real examples. Review where the agent classified matters correctly, where it missed context, and where staff had to intervene. Update its instructions and escalation rules.

Do the same with a Document Review Agent. Start with a single document type, such as vendor contracts or a defined discovery production. Set out exactly what it should extract and what it must flag. Require it to cite the relevant source page or section in its memo so the reviewing lawyer can validate the output quickly.

Your technology team or implementation partner should also establish operational controls:

  • Use dedicated service accounts rather than a partner’s personal login
  • Turn on multi-factor authentication for all connected systems
  • Keep activity logs for agent actions and approvals
  • Separate test environments from live matter data where possible
  • Review access quarterly and immediately after role changes
  • Define an escalation process for conflicts, threats, deadlines, or uncertainty
  • Remove unused integrations rather than leaving them connected “just in case”

This doesn’t need to become a six-month security project. It does need to be intentional.

The Omni voice platform is built around practical front-office workflows, including controls for what an agent captures, what it hands off, and when a human takes over. The same thinking applies to operations work across your firm.

Use a checklist before you connect your next agent

If your firm is planning an intake automation project, download the AI Client Intake Checklist for Law Firms. It is a practical worksheet to use with your intake manager, managing partner, and technology lead before an agent receives access to phone, calendar, form, or client-data systems.

You can also access the direct worksheet here. Work through it before implementation, not after an avoidable mistake has exposed a gap.

The checklist won’t replace legal or cybersecurity advice specific to your jurisdiction and practice. It will help you ask better operational questions. What data is necessary? Who approves the next step? Where does the agent stop? What happens if it is uncertain?

Those questions are the foundation of a safe deployment.

AI security is an operating discipline

The firms that get value from AI won’t necessarily be the firms with the most tools. They will be the firms that build controlled workflows around actual work.

They will know which agents can access which systems. They will use minimum permissions. They will keep humans at decision points that affect clients, matters, money, and professional responsibility. They will review results instead of assuming an agent is right because it produces confident language.

That discipline protects client information and makes the firm more efficient.

A well-designed Intake Voice Agent can stop high-intent calls from disappearing into voicemail. A Matter Triage Agent can make sure the right partner sees the right opportunity with the context needed to act. A Document Review Agent can give associates a credible first-pass memo without granting broad access to every matter file.

The opportunity is significant, especially when your firm is already losing time to unbilled administration and slow response cycles. But the path is not unrestricted automation. It is purposeful, narrow, reviewed automation.

If you want to identify where that starts in your practice, see the AI audit for law firms. In 60 minutes, we work through three outputs: your biggest operational leakage points, the best initial agent workflows, and the access and approval controls needed to implement them. There is no deck and no generic technology pitch.

When you’re ready to turn that into a practical plan, Book my Omni Audit.