Legal Regulatory Compliance
The question for Australian law firms in 2026 is not whether to use AI. It is which tools to approve, how to assess them against your professional obligations, and how to make sure staff use only those tools with client data.
Banning AI does not work. Firms that attempt a blanket prohibition find that fee earners and support staff continue using AI tools anyway, but now covertly rather than openly. The governance problem does not go away. It goes underground.
The practical objective is a governed AI environment: a defined set of approved tools assessed for compliance with your professional obligations, clear guidance for staff on what they can and cannot do, and technical controls that enforce the policy without relying on individuals to self-police.
This article covers how to assess and select AI platforms appropriate for legal practice, how the leading options compare on the criteria that matter for Australian law firms, and how browser-level controls complete the governance picture by restricting everything you have not approved.
- FREE GUIDE -
AI Governance Checklist for Australian Businesses
Not sure if your organisation's AI use is putting sensitive data, compliance obligations, or client trust at risk?
Download our free AI Governance Checklist and assess your readiness across governance, data protection, staff behaviour, compliance, and incident response. Score your organisation in minutes and identify the gaps that need attention.
✅ 30 practical assessment questions
✅ Board and leadership team friendly
✅ Identify Shadow AI and compliance risks
✅ Instant self-assessment scoring framework
The Assessment Criteria That Matter for Law Firms
Before comparing specific platforms, the assessment framework needs to be clear. General enterprise software evaluation criteria are not sufficient for a legal practice. The criteria that matter are determined by your obligations under the ASCR, the Privacy Act, and the expectations of the VLSB+C and LPLC.
For a full account of what each of those regulators requires, see AI Governance for Law Firms: What VLSB+C, LPLC and OAIC Actually Require.
The five questions every AI platform must answer before it is approved for use with client data in a law firm are:
Where is data processed and stored? Australian law firms handling client personal information have obligations under APP 8 of the Privacy Act governing cross-border disclosure. A platform that processes data on overseas infrastructure without a compliant data processing agreement in place does not meet this requirement.
Is client data used to train the AI model? Consumer-tier and free accounts on most platforms use data entered by users to train or improve their models. That means client information entered into a free-tier account is used to train a model operated by a third party. This is incompatible with ASCR confidentiality obligations and APP 6. Enterprise licensing tiers typically offer contractual opt-outs from training data use. This must be confirmed in writing before approval.
Does the vendor provide a data processing agreement? A data processing agreement (DPA) sets out how the vendor handles data on behalf of the firm, including security obligations, breach notification requirements, and data deletion terms. Without a DPA, the firm has no contractual basis for the vendor’s handling of client data.
What are the data residency commitments? Even where a DPA is in place, the firm should confirm where data is stored at rest and in transit, and whether Australian data residency can be confirmed or contractually committed.
Has the platform been assessed against the firm’s specific workflows? A platform that is technically compliant may still create risk if it is deployed in a workflow that involves particularly sensitive data categories – trust account records, PEXA transaction data, or legally privileged communications. Approval should be workflow-specific, not blanket.
How the Leading Platforms Compare
Three categories of platform are most commonly evaluated by Australian law firms: enterprise productivity suites with embedded AI, practice management platforms with AI features, and legal-specific AI research tools.
Microsoft 365 Copilot
Microsoft 365 Copilot is the AI layer built into the Microsoft 365 suite, available on commercial licensing tiers. For law firms already operating on Microsoft 365, it is typically the first platform assessed.
At the appropriate commercial licensing tier, Microsoft provides a DPA, commits that customer data is not used to train foundation models, and offers data residency controls including Australian data centre options. Copilot operates within the firm’s existing Microsoft 365 tenant, which means it is subject to the firm’s existing identity, access, and permissions controls.
The governance requirement is configuration. Copilot inherits whatever permissions and access controls are already in place within the tenant. A firm with poorly configured document permissions, overly broad sharing settings, or ungoverned SharePoint environments will find that Copilot surfaces and synthesises information that individual staff should not have access to. Before deploying Copilot, the firm’s Microsoft 365 environment needs to be assessed and tightened.
Copilot is an appropriate platform for Australian law firms to approve for use with client data, subject to correct licensing, configured data residency, a reviewed DPA, and a pre-deployment permissions audit. For a detailed platform assessment including data handling terms, see Enterprise AI Tools Comparison 2026.
Clio AI
Clio is a practice management platform used widely by Australian law firms, and its AI features are built into the Clio environment. Because Clio AI operates within the firm’s Clio instance, client data processed by Clio AI stays within a platform the firm already has a data processing relationship with.
The assessment question for Clio AI is whether the firm’s existing Clio agreement covers AI feature use to the standard required — specifically, whether the DPA addresses AI processing, whether Clio commits that matter data is not used for model training, and whether the firm’s data residency requirements are met under the Clio agreement.
For firms already using Clio as their primary practice management platform, Clio AI is typically the lowest-friction path to approved AI use in matter-related workflows. The assessment is largely a DPA review and a conversation with the Clio account team rather than a full vendor evaluation.
Legal-Specific AI Research Platforms
A growing number of AI-assisted legal research platforms operate in the Australian market, including tools integrated into existing legal research subscriptions. These platforms are trained on legal data and designed for legal workflows, which makes them more contextually reliable than general-purpose AI for research tasks.
The assessment criteria are the same: DPA, data residency, training data use, and workflow suitability. Legal-specific platforms generally perform better on these criteria than general-purpose tools because their business model depends on law firm trust, but each must still be assessed individually rather than assumed to be compliant.
Consumer and Free-Tier Platforms
Free-tier accounts on ChatGPT, Claude, Gemini, Copilot, and comparable platforms do not meet the assessment criteria for approval with client data. They do not provide DPAs for free-tier users, they typically use input data for model training, and they offer no data residency controls.
This does not mean staff will not use them. It means the firm needs to make clear that client data must not be entered into these tools, and it needs technical controls in place to enforce that position.
Why Policy Alone Is Not Enough
A written AI governance policy that staff are asked to follow voluntarily is a starting position, not a control. Research on technology governance consistently shows that self-compliance with technology policies is unreliable, particularly where the tool in question is easy to access, widely used outside work, and perceived as making the job easier.
Browser-level and network-level controls address this gap. They enforce the policy technically rather than relying on individual decision-making.
In practice, this means the firm’s IT environment is configured to:
Allow access to approved AI platforms for the appropriate staff and workflows.
Block access to unapproved AI platforms, including consumer AI tools, at the browser or network layer.
Prevent file uploads to unapproved external platforms, including AI tools accessed through a browser.
Log and alert on attempts to access blocked AI platforms, giving the firm visibility into where staff are attempting to use unapproved tools — which is itself useful information for governance.
This technical layer converts the firm’s written AI governance policy into an enforceable framework. It removes the reliance on staff reading and remembering the policy at the moment they are about to do something the policy prohibits.
For firms without in-house IT capability to implement and maintain these controls, a managed service delivers this as an ongoing function rather than a one-time project. Book a Shadow AI Demo to see how KMTech implements browser-level AI governance controls for Australian law firms.
The Governance Position This Creates
A law firm that has completed this process has a defensible governance position across all three regulatory frameworks relevant to AI in legal practice.
It can demonstrate to the VLSB+C that it has adequate systems and controls over AI tool use by staff. It can demonstrate to the LPLC at PI renewal that it has assessed which tools are in use, approved those that meet the required standard, and implemented controls to enforce the policy. It can demonstrate to the OAIC that it has taken reasonable steps under APP 11 to protect client personal information from unauthorised access and processing.
The objective is not compliance for its own sake. It is a practice environment where AI makes the firm more productive and competitive, without creating the confidentiality, regulatory, and insurance exposures that come from unmanaged AI use.
For the regulatory foundations underpinning this framework, see AI Governance for Law Firms: What VLSB+C, LPLC and OAIC Actually Require. For a detailed comparison of how leading enterprise AI platforms handle these criteria, see Enterprise AI Tools Comparison 2026.
Frequently Asked Questions
What AI tools are appropriate for Australian law firms?
AI tools appropriate for use with client data in an Australian law firm are those that provide a signed data processing agreement, commit contractually that client data is not used for model training, offer confirmed data residency controls, and can be configured to operate within the firm’s existing access and permissions controls. Microsoft 365 Copilot at the appropriate commercial licensing tier, practice management platforms with AI features such as Clio, and legal-specific AI research platforms generally meet these criteria. Consumer and free-tier accounts on general-purpose AI platforms do not.
Is Microsoft Copilot safe to use in a law firm?
Microsoft 365 Copilot can be used compliantly in a law firm at the appropriate commercial licensing tier, with correct configuration. The key requirements are: a reviewed and current data processing agreement with Microsoft, confirmed Australian data residency settings, a pre-deployment review of the firm’s Microsoft 365 permissions environment to ensure Copilot does not surface information beyond appropriate access controls, and staff guidance on what client data can be processed through Copilot. Copilot is not appropriate on consumer or personal Microsoft accounts, which do not provide the governance controls required.
Can law firms use ChatGPT for legal work?
Free-tier ChatGPT accounts are not appropriate for use with client matter data in an Australian law firm. They do not provide a data processing agreement, they use input data for model training by default, and they offer no data residency controls. ChatGPT Enterprise, at the appropriate licensing tier with a confirmed DPA and training data opt-out, may be assessed for approval, but most law firms evaluating enterprise AI options will find Microsoft 365 Copilot a more integrated and lower-friction path given existing Microsoft 365 infrastructure.
How do browser-level controls restrict unapproved AI tools in a law firm?
Browser-level and network-level controls work by configuring the firm’s IT environment to allow access to approved AI platforms and block access to all others at the network or browser layer. This means staff attempting to access an unapproved AI platform are blocked before they can enter any data, regardless of which device or browser they are using on the firm’s network. File upload prevention adds a further control layer, blocking the upload of documents to unapproved external platforms including AI tools accessed through a browser. These controls enforce the firm’s AI governance policy technically rather than relying on individual staff compliance.
What is the first step for a law firm wanting to approve AI tools?
The first step is an assessment of which AI tools staff are currently using, approved or otherwise. This baseline establishes the scope of the governance task. From there, the firm can develop a written AI governance policy, assess the tools it wants to formally approve against the five criteria covering DPA, data residency, training data use, and workflow suitability, and implement technical controls to block unapproved tools. A Shadow AI discovery assessment is the fastest way to establish the baseline. Contact KMTech to arrange one for your firm.
Shadow AI & AI Governance Protection
For executives and technical leaders who need visibility and control
Your workforce is already using AI tools. The question is whether you can see it, govern it, and prevent data leakage.
If you're concerned about Shadow AI risk, AI governance gaps, or enabling AI safely without blocking innovation, we'll show you exactly what's happening in your organisation and how to protect it.
Request a demo to view real‑time visibility, protection, and governance controls
Request a Demo Today
Author: Bradley Kaine, CEO and Co-Founder, Kaine Mathrick Tech · Reading time: approximately 9 minutes
Bradley Kaine is CEO and co-founder of Kaine Mathrick Tech, a cyber-first managed IT services provider with offices across Melbourne, Sydney, Brisbane, and Hobart. He works with managing partners and firm principals to implement AI governance frameworks that protect client confidentiality and meet Australian professional obligations.
More on Web Filtering and Shadow AI from KMTech
Everything on this topic, in one place.
ARTICLES
KMTech publishes Shadow AI content tailored to the regulatory pressures each industry actually faces. Start with the foundational guide, then go to the piece that matches your sector:
Legal
Financial services
Last updated:





