Does a lawyer need sovereign AI?
A new article on sovereign AI architecture for law firms and legal departments
The year 2026 brought lawyers three signals at once: the Polish Bar Council added § 23e on technological tools to the ethics code, the Act on artificial intelligence systems entered into force, and the judges’ association Iustitia recommended excluding case data from processing in commercial chatbots. The question about AI in a law firm is no longer “whether”, but “how”.
In the new article on our blog, we analyse what these requirements mean in practice. The starting point is three questions every law firm using AI must be able to answer: where client data is physically located and which law applies to it, who has access to it and whether it is used to train third-party models, and whether it is possible to demonstrate which tool processed the data, when and for what purpose. A lawyer working with a publicly available chatbot on a consumer account cannot reliably answer any of them — and this is not a criticism of model quality, but a structural feature of the service itself.
We also show why the boundary between a safe general question and case data often runs, in practice, “through the middle of a sentence” — and why it cannot be reliably protected either by internal rules or by manual anonymisation. The answer is architecture: known jurisdiction, a routing layer separating sensitive data from public models, an operation register and a contractual exclusion of training. AI implemented in this way allows legal teams to use the best models available without losing control over data covered by professional secrecy — while also solving two problems that appear only when AI is deployed across an entire law firm: rising costs and portability of accumulated work context.
Read the full article: Does a lawyer need sovereign AI?