Does a lawyer need sovereign AI?
In 2026, lawyers received three signals at once: the Polish Bar Council added § 23e on technological tools to its code of ethics, the Act on Artificial Intelligence Systems entered into force, and recommendations from the judges' association Iustitia ruled out processing case data in commercial chatbots. The question of AI in a law firm changed from “whether” to “how”
In a new article on our blog, we analyse what these requirements mean in practice. We start with three questions every law firm using AI must be able to answer:
- Where client data is physically located and which law governs it
- Who can access it and whether it trains someone else's models
- Whether it is possible to demonstrate which tool processed it, when and why
A lawyer using a publicly available chatbot through a consumer account cannot reliably answer any of these questions — not because of model quality, but because of how the service is designed
The boundary “in the middle of a sentence”
We also show why the boundary between a safe general question and case data often falls “in the middle of a sentence” — and why neither an internal policy nor manual anonymisation can reliably enforce it
Architecture provides the answer
- Known jurisdiction
- A routing layer separating sensitive data from public models
- An operations register
- Contractual exclusion of training
AI implemented this way allows the use of leading models without losing control of data covered by professional secrecy. It also solves two problems that only emerge when deploying across an entire law firm: growing costs and portability of accumulated working context
The full article is on the allclouds.pl blog