Does a lawyer need sovereign AI?

The year 2026 brought lawyers three signals at once: the Polish Bar Council added Section 23e on technological tools to its Code of Ethics, the Act on Artificial Intelligence Systems entered into force, and recommendations issued by the judges’ association Iustitia ruled out processing case data in commercial chatbots. The question about AI in a law firm stopped being “whether” and became “how”.
In our new blog article, we analyze what these requirements mean in practice. We start with three questions every law firm using AI must be able to answer: where clients’ data are physically located and which law governs them; who can access them and whether they are used to train third-party models; and whether the firm can demonstrate which tool processed them, when and for what purpose. A lawyer using a publicly available chatbot through a consumer account cannot reliably answer any of these questions — and this is not a criticism of model quality, but a structural characteristic of the service itself.
We also explain why, in practice, the line between a safe general question and case data runs “through the middle of a sentence” — and why neither an internal policy nor manual anonymization can reliably police it. The answer lies in architecture: a known jurisdiction, a routing layer that separates sensitive data from public models, an operations log, and a contractual exclusion of training. AI deployed in this way enables firms to use the best models on the market without losing control over data protected by professional secrecy. It also addresses two problems that emerge only when AI is rolled out across an entire law firm: rising costs and the portability of accumulated work context.
- Read the full article