← Industries
Sector thesis · Counsel at work · quiet focus

Legal.

Privilege-safe AI for law firms of every size: an open, self-hosted stack we build, run, and support, on hardware you own.

The terrain

Legal AI settled fast into an easy default: rent seats on Harvey or Legora, accept the vendor cloud, call it a strategy. It buys real capability, and it buys the same capability for every rival at the same price. The quieter cost is what the firm hands over on the way in: its positions, its fallbacks, its precedent, its intake habits, poured into a platform it cannot inspect, on a per-seat meter, while its own clients adopt those very tools to stop needing outside counsel. A second path is now genuinely available, and it is not a research project. Open, self-hosted legal AI where privileged matters are pinned to sealed local inference by architecture, with the practice apps around it, runs today on a single machine in a small office, and scales to a firm-wide deployment.

Where the risk sits
  • R01Privilege and confidentiality riding on a contract rather than on architecture (a no-training clause solves privacy, not competition)
  • R02Firm know-how, playbooks, positions, precedent, encoded into a platform the firm does not own and cannot export
  • R03Professional duties on AI-assisted work: supervision, competence, and citations that must be verifiable, not plausible
  • R04Client audit questions the firm cannot answer: which system touched this matter, at which tier, on whose hardware
Forces reshaping legal

What's actually
reshaping the sector.

01 · The vendors set the ceiling, and the fees

Harvey reached an $11B valuation with clients running 25,000+ custom agents; Legora raised at a reported $5.6B as the AI operating system for the legal industry. Legal AI works, and every rival can rent exactly the same intelligence.

Harvey
02 · Your clients are arming themselves

OpenAI's case study on Hebbia is titled, plainly, Automating 90% of finance and legal work with agents. In-house teams are adopting the same platforms firms rent, to stop needing firms. Differentiation has to come from somewhere a vendor cannot sell twice.

OpenAI
03 · The sovereign engine already exists

The LegalQuants community, lawyer-builders across 17+ jurisdictions, maintains LQ.AI and Donna: open-source legal AI that runs against models you choose, including local open-weight ones, seals privileged matters to local inference by architecture, and verifies every citation character by character.

LegalQuants
04 · And so do the practice apps

The todo.law suite, DPO Central for privacy programmes, Dealroom for clause-by-clause negotiation, AI Sentinel for the EU AI Act, plus Clausemaster and VendorWatch, is open source and self-hostable, with attorney-authored skills licensed per deployment instead of per seat.

todo.law
Position

In legal, privilege decides the compute: the vendors are table stakes every rival can rent, and the firms that compound are the ones that own their harness, their playbooks, and their proof.

The business case

Own the harness. Rent capability only where it is safe.

The vendor platforms are good, and that is the problem. Capability every competitor can rent is a subscription, not an edge. Rent the layer that embodies your know-how and you are paying, per seat, to teach a system you will never own, in a cloud you cannot audit, while in-house teams buy the same thing to bring work back inside.

So we ship the other half. Donna on the LQ.AI engine gives a firm conversational research with character-verified citations, matter workspaces, knowledge bases, and a tool loop that asks before it reaches anywhere. Underneath it sits a five-tier inference gateway with a hard floor: a privileged matter at Tier 1 is sealed to local inference and the gateway refuses, outright, to route it outward. Around it runs the todo.law suite for the deterministic practice work, privacy programmes, contract negotiation, AI governance, vendor risk. On top of it we compile the firm's own clause libraries and positions into installable skills, in an open format, licensed per deployment rather than per seat.

You choose the posture, not the vendor: a hosted pilot in days, one script on an office computer, an isolated instance we run for you, or dedicated AI hardware in your own building that runs air-gapped. We deploy it, encode your knowledge into it, tune and support the models, and keep it current with backups first and migrations you can read. The proof is dual: the speed of AI-assisted delivery, and a routing log that shows a client exactly which systems touched their matter, at which tier. Clients have started asking. Be the firm with a good answer.

Workload placement

Where each AI workload
should live.

WorkloadPlacementRationale
Privileged review, drafting, and matter chatSovereignSealed local inference on firm hardware. The gateway refuses to route privileged work outward, so this is enforced by architecture, not by policy.
Firm playbooks, clause positions, and skillsSovereignThe moat. Your drafting judgment compiled into installable skills in an open format, running on a deployment you own.
Practice operations: privacy programmes, negotiation, AI governanceSovereignDeterministic apps that make no model calls at all until you switch one on. Self-hosted, one codebase, your database.
Bulk triage, classification, and summarisationSovereignA small local model runs these at near-zero marginal cost (this is the workload where self-hosting actually pays for itself).
Hard, non-privileged research and public-law draftingFrontierAnonymised, zero-retention, EU-region lanes. Rent top capability precisely where it is safe, and never on the consumer tier.
The first engagement

What is yours to encode,
and what you are renting by accident.

Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.

01
What know-how can be encoded?

Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.

02
How much of the stack comes in-house?

A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?

03
Which models should be yours?

Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.

What we would look for in legal
  • Clause libraries: standard language, the ladder of fallbacks, and the point of walking away
  • Positions and the reasoning behind them, per counterparty and per jurisdiction
  • Intake, conflicts, and matter-triage criteria that currently live in a partner's head
  • Review checklists and the severity rubric behind every finding
  • Precedent, and the judgment about when it actually applies
Models of your own

Privileged corpora cannot lawfully train anyone else's model, which makes a small model adapted on your own work, on your own hardware, the only version of this that can exist.

What you get back
  • +A register of encodable know-how, ranked by value and by how fast it decays
  • +A draft operating ontology in an open format, not inside a vendor's platform
  • +Two or three working skills, built and evaluated on your real work, not demonstrated on a slide
  • +A bring-it-in-house plan the CTO or CIO office can actually staff
  • +A model strategy: open weights, fine-tuning, purpose-built small models, and where the frontier stays
  • +An evaluation harness that shows it works, and keeps showing it after we leave

This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.

Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.

The stack we deploy

The firm's stack,
not a seat on someone else's.

Legal is the vertical where our application layer is already a finished product. It runs every day in an AI-native boutique practice, on a laptop, and every line of it is open source, so a firm can read it before it trusts it.

01 · Application layer
The practice suite

DPO Central for privacy programmes, Dealroom for clause-by-clause negotiation, AI Sentinel for the EU AI Act, with Clausemaster and VendorWatch alongside. Deterministic by default: out of the box these apps make no model calls at all, and a named administrator has to switch the assistant on before they ever do.

02 · Assistant
Donna on the LQ.AI engine

Matter workspaces, firm knowledge bases, and conversational research with citations verified character by character, inside a governed tool loop that asks for approval before it reaches for case law or any connected system. Built by the LegalQuants community, adopted, run, and supported by us.

03 · Knowledge & skills
Your judgment, compiled

We turn the firm's clause libraries, positions, and fallbacks into installable skills in an open format: standard language, the ladder of fallbacks, red flags, a severity rubric, jurisdiction notes. Premium skills carry a named lawyer's attestation and are licensed per deployment, never per seat.

04 · AI operating layer
The harness

A five-tier inference gateway with a hard floor. A privileged matter at Tier 1 is sealed to local inference and the gateway refuses, outright, to route it outward. Anything that does leave is pseudonymised first, and every call lands in an append-only audit log.

05 · Hardware & hosting
Where it runs

One script on an office computer, an isolated instance we operate, or dedicated AI hardware on a shelf in your own building (128 GB of unified memory, open-weight models up to 120B parameters, quiet enough for the front office, and able to work with the network unplugged).

Running today

The suite and the assistant are in daily use at an AI-native boutique practice, self-hosted, on local inference, with the firm's own review skills installed.

todo.law

Everything above is open source and public. The links go to the running product, not to a brochure.

How you run it

Four postures.
One codebase.

The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.

01 · We host it, briefly
Pilot

Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.

Teams that want proof before capital expenditure.

02 · One computer in your building
Self-hosted

The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.

Small teams, and anyone who wants to inspect the source before trusting it.

03 · We operate, you hold the keys
Managed

An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.

Organisations without an infrastructure team to spare.

04 · Your own hardware, air-gappable
Appliance

Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.

In legal we ship the appliance as a finished thing: the suite, the assistant, and the open-weight models you choose, installed and tested before the box leaves our hands.

Work that cannot leave the building, ever.

Around it
  • +Deployment and hardening, on your machines or ours
  • +Knowledge encoding: your playbooks and positions compiled into installable skills
  • +Model selection, tuning, and an evaluation harness built on your own work
  • +Remote maintenance and monitoring at a published monthly rate
  • +Updates as ordered, readable migrations, always after an encrypted backup
  • +Backup, restore, and continuity drills you can actually rehearse
  • +Enablement for the people who use it daily, not only for IT
  • +Governance evidence: routing logs, audit trail, and an attestation pack
What we can never do
  • Reach into your instance or see your work
  • Revoke your software or disable a licence remotely
  • Force an update on you

Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.

Where the software lives

Everything on this page is real, and you can go and read it.

We build and operate the suite under the todo.law name: the practice apps, the Donna assistant on the LQ.AI engine, the skills marketplace, and the appliance. Install it yourself on one office computer, let us run an isolated instance, or take the box. Firms of two partners and firms of two hundred start from the same page.

DPO CentralDealroomAI SentinelClausemasterVendorWatchDonna · LQ.AI
Open todo.law for law firms

Open source (AGPL for the practice apps, Apache-2.0 for the assistant). Read the code before you trust it, run it yourself, or have us run it.

Sector brief

Get the full
legal
placement map.

We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.

Request this research

Legal placement map