allclouds.pl

Does a lawyer need sovereign AI?

A lawyer reviewing sovereign AI architecture and client data protection

Sovereign AI architecture enables legal teams to use AI while maintaining control over client data, professional secrecy and case context.

Several pending matters, each with a different factual background, procedural deadlines and client expectations, and dozens of decisions to be made between them — usually under time pressure. This is the everyday reality of legal work, and it is exactly where AI has the most to offer. Used well, artificial intelligence shortens the path from problem to decision: it helps run research faster and verify it immediately, prepare alternative ways to solve the problem, and finally draft a pleading, article or note for a court session. An AI assistant that knows the case file, chronology and prior correspondence does not start with a blank page, but with a draft for human verification. Answers based on the organisation's knowledge, rather than on model guesswork, reduce the risk of hallucinations, while the context stored in the tool accumulates with each new matter.

![A lawyer reviewing sovereign AI architecture and client data protection](image:cover)

This is where the problem begins. The material on which AI could work most effectively is also the most strictly protected: clients' personal data, trade secrets and case information covered by professional secrecy. The question is therefore not whether to use AI, but how to use its full benefit — appropriate models and real acceleration of work — without losing control over data that lawyers are obliged to protect. This is exactly why lawyers need sovereign AI. Before the solution, however, the legal requirements must be faced honestly.

Three questions that must be answered

Before choosing an AI solution for legal work, three questions must be asked: (1) where will the clients' data physically reside and under the law of which state will it fall? (2) who outside the law firm may gain access to the data entered into the tool and is that data used to train models? (3) can I demonstrate which tool processed client data, when and for what purpose?

A lawyer using a publicly available chatbot on a consumer account cannot reliably answer any of these questions. Data goes to infrastructure whose location the lawyer does not control, under a legal regime that allows access by authorities of a third country — in the case of US providers, primarily under the CLOUD Act and Section 702 FISA. The provider may change the terms of service unilaterally, and chat history is not an auditable register of operations. This is not a criticism of model quality; it is a structural feature of a consumer service. Meanwhile, ethical rules require a competent assessment of the tool's limitations and risks, and readiness to tell the client which tools work on their matter and for what purpose. It is difficult to assess the risk of a tool whose data-processing architecture is unknown; it is even harder to tell a client where their data went if the lawyer does not know it themselves.

The boundary runs through the middle of a sentence

Not every use of AI in a law firm touches case data. Research on general legal issues, work on fully anonymised materials or drafting one's own texts can comply with bar requirements even when public tools are used, provided they are used consciously. The problem is that the boundary between a general question and case data often runs, in practice, through the middle of a sentence. Imagine a question about whether a contractual penalty was justified: after two clarifications it may already contain the contractor's name, amounts from an accounting note and the dispute chronology. Guarding that boundary by internal rules means trusting that every person in the team will recognise it every time. Anonymisation remains — but a lawyer forced to anonymise materials each time is not accelerating work, but adding another stage to it, and an assistant deprived of the realities of the case will not prepare a useful document. There are two ways out of this problem: prohibit AI for case data, or create conditions in which AI can legally work with it.

Professional bodies have already answered, although not directly

By a resolution adopted at a plenary session on 12-13 June 2026, the Polish Bar Council amended the Code of Bar Ethics and Dignity of the Profession, adding, among other provisions, a new § 23e. Under the new rules, an advocate may use technological tools, including those based on artificial intelligence, only as auxiliary tools. Their use may not lead to a breach of professional secrecy, entrust technology with activities in a way that violates the advocate's independence, or replace the advocate's own verification of results. The advocate should also have the competence to assess the limitations of tools and the risks associated with their use, and, at the client's request, indicate the tools used in the client's matter and the purpose of their use. Use of technology does not release the advocate from personal responsibility for the content and form of professional activities. Importantly, using technological tools generally does not require separate notification to the client unless such an obligation results from generally applicable law. The duty to identify tools arises only at the client's request — that is, precisely when the lawyer must already be able to answer.

The National Chamber of Legal Advisers, in its recommendations on the use of artificial-intelligence-based tools by legal advisers, formulates similar principles: human oversight of AI, a ban on entering information covered by legal adviser secrecy into external tools without appropriate safeguards, a ban on testing unverified solutions on client matters, and full responsibility of the legal adviser for content provided to the client — regardless of AI's involvement in its preparation. The same direction is set at European level by the CCBE guidelines, which list confidentiality and professional competence among the core principles for using generative AI.

It is also worth noting where other legal professions are heading. The recommendations of the Polish Judges' Association Iustitia go further than the professional bodies of representatives and exclude processing any court-proceeding-related data in commercial, publicly available AI models. Defence secrecy requires separate emphasis (Article 178 point 1 of the Polish Code of Criminal Procedure): it is absolute and the client cannot release the lawyer from it. Neither client consent nor internal rules work within its scope — only control over where the data may go at all remains. The direction is therefore consistent: the closer AI gets to case data, the less room there is for tools outside the organisation's control.

Regulations complete the picture

A requirement affecting every law firm using AI is the obligation under Article 4 of the AI Act to ensure an appropriate level of AI literacy among people operating these systems. This cannot be transferred to a chatbot provider. The third element, alongside professional ethics and the AI Act, is the GDPR. A lawyer is generally the controller of personal data contained in case files, while the AI tool provider is a processor. This requires a data processing agreement meeting Article 28 GDPR requirements — a consumer service does not provide such an agreement. Use of infrastructure belonging to providers subject to US jurisdiction also means a transfer of data to a third country within the meaning of Chapter V GDPR, currently based on the adequacy decision for the Data Privacy Framework. Legal scholarship has also long identified a structural conflict between Article 48 GDPR and the US CLOUD Act (Christakis 2019; Schwartz, Peifer 2019). A law firm that bases client-data handling solely on these grounds builds on ground whose stability does not depend on it.

These requirements also have a practical dimension. The new provisions of the Bar Ethics Code and the KIRP recommendations define a standard of care that disciplinary officers will use in the first AI-related cases. Legal scholarship also signals that mandatory professional liability insurance was not designed for damage involving AI systems and that coverage gaps may arise (Szpyt 2025; Bana 2026). A law firm that can demonstrate which tool processed case data, when and for what purpose is in a significantly better position than one that can only state that it "uses AI carefully".

The solution: sovereign AI architecture

The systemic solution is not to trust that the team will sense the boundary, but to use an architecture in which crossing the boundary is controlled technically, not only by internal rules. Sovereign AI understood in this way does not mean a worse model at a higher price. It is an implementation model in which models, including the best ones on the market, operate in an environment controlled by the organisation: the organisation decides which data may go to which model and under what conditions. In practice, this consists of four elements: (1) infrastructure in a known jurisdiction; (2) a routing layer separating sensitive data from public models; (3) operation logging that makes it possible to answer who processed what, when and for what purpose; and (4) a contract guaranteeing that the data is not used to train models. The best models remain available, but they work behind the organisation's gate. The routing layer decides which elements of a query, and under what conditions, may reach them (deployment in the EU region, contractual ban on retention and training), while the most sensitive material is routed to a model running in the organisation's own infrastructure or pseudonymised before it leaves the law firm's environment. Returning to the contractual penalty example: the general legal question may go to a public model, but the contractor's name, note amounts and dispute chronology may not. Such an architecture directly answers the three questions set out above and the requirements of professional bodies: the lawyer keeps the full benefit of AI — access to appropriate models and real acceleration of work — while client data remains under demonstrable protection.

Implementation at law-firm scale: costs and context

A decision to implement AI comprehensively reveals two more issues that are rarely discussed before the start. The first is cost. Free team access to tools, organised processes and acquired practice mean rapidly increasing consumption; the company card limit can then surprise the organisation faster than expected.

When AI tools are used comprehensively, cost control should be approached systemically. This means matching the right model to a specific task or process — simple administrative processes can be handled by a cheaper model than drafting a several-hundred-page pleading — and setting a token-consumption limit that allows employees to work freely with tools that improve their work while giving the organisation cost predictability.

The second issue is context. Working with AI tools gives something no previous technological progress offered in the same way: work with context. An AI tool remembers the user's way of working, writing style, the multi-threaded nature of issues under consideration and decisions already made. Alongside time savings and increased work efficiency, the accumulated context of the entire organisation becomes another asset that a law firm gains by implementing AI.

Enterprise accounts and offers labelled as "sovereign cloud" reduce risk compared with consumer services, but they remain entirely a contractual promise by the provider, enforceable at most after the fact. A sovereign architecture also includes a contract — the fourth element, the ban on training — but it applies only to the part of the data that, after passing through the gateway, actually reaches a model. The rest is decided by technology: routing, operation logs and infrastructure jurisdiction, which the organisation verifies itself, not after the fact. The environment of a large foreign AI provider ties the law firm to one provider's models and technology stack, while sovereign architecture preserves the freedom to choose models and the conditions of their use. Literature also notes that offerings labelled as "sovereign cloud" differ significantly in the scope of sovereignty — from purely operational sovereignty to full data sovereignty (Klare, Lechner, Fritzsche 2025). The organisation's know-how should therefore be placed in a tool that allows the context to be freely moved and used in another tool or model.

The answer

So does a lawyer need sovereign AI? If artificial intelligence is to actually shorten the path from problem to decision — that is, to work on case files, not only on general questions — the answer is yes. Professional ethics, advocate secrecy, legal adviser secrecy, defence secrecy, GDPR and the AI Act do not prohibit lawyers from using AI. They do, however, impose conditions that a consumer service by definition does not meet. Sovereign architecture — known jurisdiction, data routing, operation register and contractual exclusion of training — makes it possible to meet those conditions in a verifiable way, while also addressing problems that appear only when AI is implemented across an entire law firm: it enables cost control by matching the model to the task and protects the accumulated work context, which remains a portable organisational asset rather than hostage to one provider. The full benefit of AI and protection of client data are therefore no longer mutually exclusive — provided the implementation architecture is sovereign.

At allclouds.pl, this is exactly how we design AI work environments (saie.allclouds.pl). If your law firm or legal department is considering how to fully use AI without professional risk, we invite you to contact us.

Sources

Selected literature