Choosing legal AI tools: the questions the guide says to ask.

The longest section of the Law Society of NSW guide is a procurement checklist, and it reads like it was written by someone who has seen the contracts. Before adopting any generative AI tool, the guide expects a firm to define the use case and how success will be measured, review the contract in full, understand where data goes, test the tool, and only then let it near client work. This page distils the pre-adoption questions and adds the one the guide flags that most firms miss: whether clients require onshore data hosting.

General information only. This guide summarises published regulatory guidance and is not legal advice. Read the primary sources linked throughout, and take professional advice on your firm’s specific position.

The questions before any purchase

What is the use case, and how is success measured

A specific scenario, a desired output, and benchmarks for effectiveness. Tools adopted without a defined job tend to drift into unsupervised ones.

What does the contract actually say

The guide expects a full review covering copyright, intellectual property, data ownership, data sharing, and access to data provided to the tool, including how prompts and queries are stored.

Where does the data go

Storage, processing and access are three different answers. Whether prompts are used for training, who at the vendor can see them, and where inference runs all bear on confidentiality, and on clients with onshore data requirements.

What was it trained on

The guide advises checking training data sources, which bear on accuracy, bias and intellectual property risk in outputs.

Least privilege

If the tool will access internal documents and systems, it should receive only the data it needs to operate and nothing more.

Who can use it

Access controls so only authorised users can reach the tool, which is also the enforcement mechanism for the firm AI policy.

Does it show its sources

The guide recommends preferring tools whose outputs can be interrogated back to sources, because verification is the standing duty.

Did it pass testing

Thorough testing before adoption, with outputs that are expected, determinable, impartial and fit for purpose, and client awareness where AI will be used in their matters.

The onshore hosting question

The guide tells practitioners to consider the implications a tool has for a client’s potential requirement for onshore data hosting. Government, defence-adjacent, health and financial clients increasingly impose exactly that requirement in engagement terms, and a firm whose AI stack routes offshore can find itself unable to use its tools on its most sensitive matters. Asking every vendor where inference happens, rather than where data is stored, is the version of the question that gets the true answer; our Privacy Act guide covers why the distinction matters under APP 8.

Where deployment posture fits

Several of the guide’s questions answer themselves when processing happens on hardware inside the practice: prompts are not stored with a vendor, no third party can access client material, nothing routes offshore, and the onshore requirement is met by the floor the unit stands on. The remaining questions still deserve real answers from any on-premise vendor, ours included: what the support arrangement can access, how updates arrive, what was used to train the underlying models, and what happens at end of term. Our law firm page and deployment comparison set out how we answer them.

Common questions

What should a law firm ask an AI vendor about data?
Where prompts and outputs are stored, who can access them including support staff and legal process, whether they are used to train models, where inference actually runs as distinct from where data rests, and what happens to firm data at termination. The Law Society guide expects a full contract review covering ownership, sharing and access before adoption.
Is onshore data hosting required for Australian law firms?
There is no blanket rule, but the Law Society guide directs firms to consider clients' potential onshore hosting requirements, and government, health and financial clients increasingly impose them contractually. Cross-border disclosure obligations under APP 8 of the Privacy Act apply in parallel whenever personal information routes offshore.
Do the procurement questions apply to on-premise AI too?
Yes, with a shorter list. Transmission, vendor access and offshore routing questions largely fall away when processing stays inside the practice, but training data provenance, support access, update mechanisms, testing and exit arrangements deserve the same scrutiny for any vendor.

See Dominion answering from your own documents.

A demonstration takes 30 minutes, uses no client data, and comes with no obligation.

Book a demo