SecurityTechInsider AI security & governance
EN/ NL
Governance

Vetting an AI intake engine at a law firm: five checks before you connect it

Paravo launched an AI engine for intake and client communication at law firms in August 2026. How to vet such a system before you deploy it.

4 September 2026 4 min
Illustration for this article: Vetting an AI intake engine at a law firm. Oxidised copper and patinated brass sheet, corrosion blooming across the surface.
Law firms deploying AI intake engines must log every client interaction and demonstrate control over data handling before going live. Image: SecurityTechInsider — original editorial illustration

You must be able to demonstrate per client interaction what data the AI system saw, which messages it sent, how it handled confidentiality, and where human review occurred. Without that evidence you cannot account to clients or regulators for what the system did on your behalf.

An analysis of 4 September 2026 of vetting an AI intake engine before deployment argues that law firms must treat client-facing AI systems as governance problems, not just technology choices. The case in point is an engagement engine launched in August 2026 that combines lead generation, AI-driven intake, follow-up and re-engagement of former clients, integrated with widely used firm tools such as Clio, Google and Outlook. In our assessment, the position of such a system in the client communication workflow—handling first contact and recording what follows—makes auditability non-negotiable. A firm that operationalises AI without a control layer widens the gap between what it deploys and what it can later explain.

Why intake automation raises governance questions

Intake automation is emerging as a revenue lever because the gap between client expectation and firm capacity has widened. Firms respond to roughly one third of emails from potential clients, whilst consumers expect near-immediate answers. At the same time, generative and agentic AI use within legal organisations has nearly doubled in a year, with client-facing applications such as intake becoming a more important focus. Clients increasingly expect firms to use AI, yet their awareness of actual AI use remains low. That tension—between expectation, deployment and transparency—is where governance enters.

When an AI system communicates with potential clients on behalf of the law firm, it makes statements and collects data under that firm's responsibility. The system is not a standalone chatbot answering questions; it is a layer connected to the channels where first client contact arrives, and it independently handles the initial exchange. That places AI in the revenue-critical workflow, not in internal research or drafting where the stakes are different.

What can go wrong without controls

  • Undocumented client communication — no record of what the AI said to whom, when, or on what basis.
  • Uncontrolled data collection — personal information gathered and retained without explicit consent or audit trail.
  • Confidentiality breach — client information or legal advice reproduced or inferred in AI outputs without safeguard.
  • Silent AI use — clients unaware that an AI system handled their initial contact, preventing informed consent.
  • Unverifiable hallucination — the AI makes false statements about the firm's services or legal position without human review before sending.
  • Training data contamination — client data used to improve the AI model without contractual prohibition.

Which controls must you be able to demonstrate

  1. Log all client interactions — record every message the AI sent, every data input it received, and every decision point where human review occurred.
  2. Enforce confidentiality contractually — require the AI vendor to confirm in writing that client data is not used for model training or improvement.
  3. Segregate client data — ensure client information is stored and processed separately from the vendor's other data and systems.
  4. Mandate staff training — require all users to complete training on hallucination risk, professional secrecy obligations, and the limits of the AI system.
  5. Implement fail-closed privacy checks — configure the system so that when a privacy or confidentiality check fails, the message is not sent and a human is alerted.
  6. Audit the audit layer — invest in logging and inspection infrastructure so you can reconstruct what the system did and did not do.

How should you test an engagement engine before deployment

A concrete benchmark is provided by how one major firm treats client intake as an AI workflow rather than a forms project. That firm enforces mandatory training on hallucinations and confidentiality, bans consumer tools such as the public version of commercial AI services for client matters, secures contractual agreements that data is not used for training, segregates client data, and invests in audit and log infrastructure. Use those five elements as your test: can the engagement engine you are considering meet each one? If the vendor cannot demonstrate logging, data segregation, contractual safeguards and fail-closed privacy checks, the revenue promise does not outweigh the governance risk.

What tooling can and cannot do

A verification layer can make the steps an AI system takes visible for inspection and can replace sensitive document values with synthetic equivalents before AI processing occurs. It can show you what the AI chain did and did not see. What it cannot do is confirm the correctness of the anonymisation or make the final professional judgement for you. The lawyer remains accountable for the decision to deploy, the choice of data to feed the system, and the review of what it produces. Tooling supports that accountability; it does not replace it.

Sources: This article draws on reporting and guidance from LawNext, Law.com Legaltech News, Thomson Reuters Institute and Perspective AI.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.