allclouds.pl

Does a lawyer need sovereign AI?

Does a lawyer need sovereign AI?

A dozen or so cases in progress, each with different facts, procedural deadlines and client expectations, and between them dozens of decisions to make — usually under time pressure. This is a lawyer’s everyday reality, and it is exactly where AI has the most to offer. Used well, artificial intelligence shortens the path from problem to decision: it lets you do research faster and verify it straight away, prepare alternative ways of solving a problem and, finally, a draft of a pleading, an article or a note for a court hearing. An AI assistant that knows the case files, the case timeline and the correspondence so far starts working with the lawyer not from a blank page but from a draft to be checked; answers based on the organisation’s knowledge rather than the model’s guesses also reduce the risk of hallucinations, and the context stored in the tool accumulates with each new case.

![Does a lawyer need sovereign AI?](image:cover)

This is where the problem begins, however. The material on which AI could work most effectively is also the most strictly protected: clients’ personal data, trade secrets, information about the case covered by professional secrecy. The question is therefore not whether to use AI, but how to use its full benefits — the right models and a real acceleration of work — without losing control over data we are obliged to protect. That is what sovereign AI is for, for a lawyer. Before we get to the solution, however, we need to face honestly the requirements set by the law.

Three questions you need to be able to answer

Before choosing the right AI solution for legal work, three questions need to be asked: (1) where will my firm’s client data physically end up, and which country’s law applies to it? (2) who outside the firm can gain access to the data entered into the tool, and is it used to train models? (3) can I show which tool processed client data, when and for what purpose?

A lawyer using a publicly available chatbot on a consumer account cannot reliably answer any of them. The data goes to infrastructure whose location they do not control, under a legal regime that allows access by the authorities of a third country — in the case of US providers, primarily under the CLOUD Act and Section 702 of FISA; the provider can change the terms of service unilaterally, and the conversation history is not an auditable record of operations. This is not a criticism of the quality of the models — it is a design feature of a consumer service. Meanwhile, the rules of professional ethics require a competent assessment of a tool’s limitations and risks, and readiness to tell the client which tools are being used in their case and for what purpose. It is hard to assess the risk of a tool whose data processing architecture you do not know; it is even harder to tell the client where their data went if you do not know yourself.

The boundary runs through the middle of a sentence

Not every use of AI in a law firm touches case data. Research on general legal issues, work on fully anonymised material or editing one’s own texts fall within the requirements of the professional bodies even with public tools, provided they are used consciously. The problem is that in practice the boundary between a general question and case data runs through the middle of a sentence — just imagine a question about whether a contractual penalty was charged correctly, which after two follow-ups already contains the counterparty’s name, the amounts from the accounting note and the timeline of the dispute. Guarding this boundary with internal rules means trusting that every person on the team will sense it every time. That leaves anonymisation — except that a lawyer forced to anonymise material every time does not speed up their work but adds another step to it, and an assistant deprived of the realities of the case will not prepare a useful document. A problem framed like this has two ways out: ban AI from case data, or create conditions in which it can work with that data lawfully.

The professional bodies have already answered, though not directly

By a resolution adopted at its plenary session on 12–13 June 2026, the Polish Bar Council (Naczelna Rada Adwokacka) amended the Code of Ethics for Advocates (Zbiór Zasad Etyki Adwokackiej i Godności Zawodu, hereinafter: ZZEA), adding, among other things, a new § 23e. Under the new provisions, an advocate may use technological tools, including those based on artificial intelligence, only in an auxiliary capacity, and their use may not lead to a breach of professional secrecy, to entrusting tasks to technology in a way that undermines the advocate’s independence, or to the advocate failing to verify the results personally. An advocate should also have the competence to assess the limitations of the tools and the risks associated with their use, and, at the client’s request, indicate the tools used in their case and the purpose of their use. The use of technology does not relieve the advocate of personal responsibility for the content and form of their professional activities. Importantly, the use of technological tools does not, as a rule, require separate notification of the client, unless such an obligation arises from generally applicable law — the obligation to indicate the tools arises only on request, that is, at the moment when one already needs to be able to answer.

The National Council of Legal Advisers (Krajowa Izba Radców Prawnych, KIRP), in its Recommendations on the use by legal advisers of tools based on artificial intelligence, sets out analogous principles: human oversight of AI, a ban on entering information covered by legal adviser privilege into external tools without appropriate safeguards, a ban on testing unproven solutions on client cases, and the legal adviser’s full responsibility for the content provided to the client — regardless of AI’s role in preparing it. The same direction is set at European level by the CCBE guidelines, which list confidentiality and professional competence among the fundamental principles for using generative AI.

It is also worth noting where the other legal professions are heading. The recommendations of the Polish Judges’ Association “Iustitia” go further than those of the professional bodies of attorneys and rule out processing any data related to court proceedings in commercial, publicly available AI models. Defence counsel privilege (Article 178(1) of the Polish Code of Criminal Procedure) deserves separate emphasis: it is absolute and the client cannot waive it, so within its scope neither the client’s consent nor internal rules apply — all that remains is control over where the data can go at all. The direction is therefore uniform: the closer you get to case data, the less room there is for tools that remain outside the organisation’s control.

Regulations complete the picture

A requirement that applies to every law firm using AI is the obligation under Article 4 of the AI Act to ensure an appropriate level of AI literacy among the people operating these systems — it cannot be passed on to the chatbot provider. The third element of the picture — alongside the rules of ethics and the AI Act — is the GDPR. A lawyer is, as a rule, the controller of the personal data contained in the files of the cases they handle, and the provider of the AI tool is a processor, which requires a data processing agreement meeting the conditions of Article 28 GDPR — a consumer service does not provide for such an agreement. Using the infrastructure of providers subject to US jurisdiction also means transferring data to a third country within the meaning of Chapter V GDPR, currently based on the adequacy decision for the Data Privacy Framework. Finally, legal scholarship has for years pointed to the structural conflict between Article 48 GDPR and the US CLOUD Act (Christakis 2019; Schwartz, Peifer 2019). A firm that bases the handling of client data solely on these foundations is building on ground whose stability does not depend on it.

These requirements also have a practical dimension. The new ZZEA provisions and the KIRP recommendations set the standard of due diligence that disciplinary officers will turn to in the first AI-related cases, and legal scholarship signals that compulsory professional liability insurance was not designed with damage involving AI systems in mind and that there may be gaps in cover (Szpyt 2025; Bana 2026). A firm that can show which tool processed case data, when and for what purpose is in a fundamentally better position in both contexts than one that can only give assurances that it “uses AI carefully”.

The solution: a sovereign AI architecture

The systemic solution is not to trust that the team will sense the boundary, but an architecture in which crossing the boundary is controlled technically, not by internal rules. Sovereign AI understood in this way does not mean a worse model at a higher price — it is a deployment model in which models, including the best on the market, work in an environment that remains under the organisation’s control: it is the organisation that decides which data goes to which model and on what terms. In practice this consists of four elements: (1) infrastructure in a known jurisdiction; (2) a routing layer that separates sensitive data from public models; (3) logging of operations that makes it possible to answer the question of who processed what, when and for what purpose; (4) a contract guaranteeing that the data is not used to train models. The best models on the market remain available — but they work behind the organisation’s gateway: it is the routing layer that decides which parts of a query may reach them and on what terms (deployment in the EU region, a contractual ban on retention and training), and it directs the most sensitive material to a model running in the firm’s own infrastructure or pseudonymises it before it leaves the firm’s environment. Going back to the contractual penalty example: the general question may go to a public model, but the counterparty’s name, the amounts from the note and the timeline of the dispute — no longer. An architecture built in this way answers directly the three questions posed above and the requirements of the professional bodies: the lawyer retains the full benefits of AI — what this was about from the start: access to the right models and a real acceleration of work — and client data remains under protection that can be demonstrated.

Deployment at the scale of a law firm: costs and context

A decision to deploy AI comprehensively reveals two more issues that are rarely discussed before the start. The first is cost: the team’s unrestricted access to tools, well-organised processes and acquired skill mean rapidly growing usage — and the limit on the company card can then come as a surprise sooner than planned.

When AI tools are used comprehensively, it is good to take a systemic approach to cost control. To do this, you need to match the right model to a specific task or process (simple administrative processes can be handled by a cheaper model than the drafting of a pleading running to several hundred pages) and set a token usage limit that lets employees carry out their tasks freely with tools that streamline their work, while giving the organisation predictable costs.

The second issue is context. Working with AI tools offers something that no earlier technological advance has offered — working with context. An AI tool remembers the user’s way of working, their writing style, the many threads of the issues under consideration and the decisions they make. Alongside saving time and increasing work efficiency, the accumulated context of the whole organisation is therefore another asset that a law firm gains by deploying AI.

Enterprise accounts and “sovereign cloud” offers reduce risk compared with a consumer service, but they remain entirely a contractual promise by the provider, enforceable at most after the fact. In a sovereign architecture a contract also appears — this is the fourth element, the ban on training — but it covers only the part of the data that actually reached the model after passing through the gateway; the rest is decided by technology: routing, the log of operations and the jurisdiction of the infrastructure, which the organisation verifies itself, rather than after the fact. The environment of a large foreign AI provider ties the firm to one provider’s models and technology stack, whereas a sovereign architecture preserves the freedom to choose models and the terms of their use. The literature also points out that offers labelled “sovereign cloud” differ significantly in the scope of sovereignty — from purely operational to full data sovereignty (Klare, Lechner, Fritzsche 2025). The organisation’s know-how should therefore be placed in a tool that allows this context to be moved freely and used in another tool or model.

The answer

So does a lawyer need sovereign AI? If artificial intelligence is really to shorten the path from problem to decision — that is, to work on case files and not only on general questions — the answer is: yes. The rules of professional ethics, advocate, legal adviser and defence counsel privilege, the GDPR and the AI Act do not prohibit lawyers from using AI, but they set conditions that a consumer service by design does not meet. A sovereign architecture — a known jurisdiction, data routing, a log of operations and a contractual exclusion of training — makes it possible to meet these conditions in a verifiable way, and at the same time addresses problems that only emerge when deploying across the whole firm: it gives cost control by matching the model to the task, and protects the accumulated work context, which remains a portable asset of the organisation rather than a hostage of a single provider. The full benefits of AI and the protection of client data are therefore not mutually exclusive today — provided that the deployment architecture is sovereign.

At allclouds.pl this is exactly how we design AI working environments (saie.allclouds.pl). If your law firm or legal department is wondering how to make full use of AI without professional risk — we invite you to get in touch.

Sources

Rzeczpospolita, NRA zmieniła kodeks etyki. Adwokat może korzystać z AI, ale tylko pomocniczo (16.06.2026): https://www.rp.pl/zawody-prawnicze/art44636171-nra-zmienila-kodeks-etyki-adwokat-moze-korzystac-z-ai-ale-tylko-pomocniczo

Naczelna Rada Adwokacka, Zmiany w Zbiorze Zasad Etyki Adwokackiej — nowe regulacje dotyczące korzystania ze sztucznej inteligencji (June 2026): https://www.adwokatura.pl/z-zycia-nra/zmiany-w-zbiorze-zasad-etyki-adwokackiej-naczelna-rada-adwokacka-przyjela-nowe-regulacje-dotyczace-korzystania-ze-sztucznej-inteligencji-w-wykonywaniu-zawodu-adwokata/

KIRP, Rekomendacje dotyczące korzystania przez radców prawnych z narzędzi opartych na sztucznej inteligencji: https://kirp.pl/rekomendacje-dotyczace-korzystania-z-ai/

CCBE, Guide on the use of generative AI by lawyers (10.2025): https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20251002_CCBE-guide-on-the-use-of-the-use-of-generative-AI-for-lawyers.pdf

Naczelna Rada Adwokacka, AI Act: od 2 sierpnia 2026 r. obowiązują nowe zasady transparentności: https://www.adwokatura.pl/ogolnoprawne/ai-act-od-2-sierpnia-2026-r-obowiazuja-nowe-zasady-transparentnosci/

Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji (Dz. U. poz. 1003) [Act of 3 July 2026 on artificial intelligence systems]: https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20260001003

SSP Iustitia, Rekomendacje dotyczące wykorzystywania narzędzi AI przez sędziów: https://iustitia.pl/wp-content/uploads/2026/03/Rekomendacje-1.pdf

allclouds.pl, SAIE — Sovereign Artificial Intelligence Ecosystem: https://www.allclouds.pl

Selected literature

K. Szpyt, Civil Liability for Damages Caused by the Use of Artificial Intelligence Systems by Lawyers in the Provision of Legal Services, Parts I–III, “Prawo Asekuracyjne” 2025, DOI: 10.5604/01.3001.0055.1127 (Part I), 10.5604/01.3001.0055.4804 (Part III)

Ch. Rennig, The Use of Artificial Intelligence and the Professional Duties of German Lawyers, “Studia Prawa Publicznego” 2025, no. 1(49), DOI: 10.14746/spp.2025.1.49.3

A. Perlman, The Legal Ethics of Generative AI, SSRN 2024, DOI: 10.2139/ssrn.4735389

K. Terzidou, Generative AI Systems in Legal Practice: Offering Quality Legal Services while Upholding Legal Ethics, SSRN 2025, DOI: 10.2139/ssrn.5197274

V. Janeček, T. Melham, Privilege and Confidentiality in Generative AI Workflows, 2026 (preprint)

T. Christakis, Transfer of EU Personal Data to U.S. Law Enforcement Authorities After the CLOUD Act: Is There a Conflict with the GDPR?, 2019

P.M. Schwartz, K.-N. Peifer, Data Localization Under the CLOUD Act and the GDPR, “Computer Law Review International” 2019, DOI: 10.9785/cri-2019-200102

M. Klare, U. Lechner, A. Fritzsche, Digital Sovereignty Through Sovereign Clouds?, IET Conference Proceedings 2025, DOI: 10.1049/icp.2025.2947

A. Bana, Artificial Intelligence, Legal Professional Negligence and the Rise of AI-Covered Indemnity Risk, SSRN 2026, DOI: 10.2139/ssrn.6443021

What else to explore

https://www.allclouds.pl/en/blog/czy-prawnik-potrzebuje-suwerennego-ai-2026