Legal technology experts are challenging the assumption that expensive, legal-specific AI platforms offer meaningfully superior security for attorneys handling confidential client information.
Attorney and e-discovery expert Craig Ball argues that courts are beginning to impose so-called “enterprise-grade” AI requirements that sound protective but may do little more than exclude solo practitioners and small firms from the technology.
The core problem, Ball explains, is that costly legal AI platforms generally rely on the same small group of foundation models from OpenAI, Anthropic, or Google as lower-cost mainstream tools.
These platforms share the same cloud infrastructure as more affordable alternatives, meaning the underlying security architecture at the model level is not fundamentally different.
As Ball puts it: “The model doesn’t know whether it’s being called by a BigLaw firm’s bespoke platform or by little ol’ me. The bytes don’t care about the price tag on the Application Programming Interface (API) wrapper.”
Ball draws a careful distinction between technical security measures and contractual enhancements, arguing the two are frequently conflated in court requirements and regulatory guidance.
A negotiated data-processing agreement may provide audit rights, breach-notification timelines, and deletion deadlines, but those provisions do not change how the underlying model actually processes data.
In Ball’s view, courts should not treat a lengthy and expensive contract as a substitute for examining the actual security settings and practices that matter in practice.
Rather than dismissing security concerns entirely, Ball proposes a set of practical safeguards that lawyers can implement regardless of which tool they use or how much they spend.
His recommendations include disabling training, requiring authenticated and non-public access, isolating each matter in a separate project or workspace, deleting material when a matter concludes, and documenting the tool, configuration, and contractual terms being used.
Ball’s broader argument is that courts should focus on actual protections rather than labels such as “enterprise-grade,” the existence of a bespoke data-processing agreement, or the price of the platform.
Without that focus, AI protective orders risk becoming another form of technology gatekeeping that imposes substantial costs on smaller practices without delivering any meaningful improvement in security.
That outcome would be particularly damaging because AI is one of the few technologies capable of narrowing the resource gap between large firms and solo practitioners or small practices.
A solo lawyer using a properly configured mainstream tool may be able to analyze documents, prepare for depositions, and conduct research at a scale that previously required an entire team of lawyers and support staff.
Ball’s credibility on this issue stems from decades of experience in the legal technology space, and he has no commercial affiliation with any purpose-built legal AI platform that might benefit from steering lawyers toward expensive products.
His conclusion that security should be measured by what a tool actually does, how it is configured, and how the lawyer uses it deserves serious attention from courts and regulators setting AI standards.

