The legal-AI market grew up, and split in two
Harvey, Legora, Spellbook and the rest are genuinely good now. That is precisely why the build-vs-buy decision matters more, not less.
Before the Reset, legal AI was a demo. After it, the vendors are real products and the in-house option, a sovereign model over your own privileged corpus, is also real. General Counsels no longer choose between AI and no-AI; they choose, matter type by matter type, between a vendor, a frontier model, and sovereign infrastructure. That is a portfolio decision, and most firms are making it by accident.
The deciding variable is not capability, assume capability everywhere, but privilege and confidentiality. The question for every workload is simple and brutal: if this content leaked, or was used to train someone else's model, what would it cost us? The answer sorts the portfolio.
Where each matter type belongs
Privilege and strategic sensitivity put a clear ceiling on what can leave the firm.
At the sovereign end sit privileged litigation strategy, live M&A due diligence, and sensitive contract review, anything whose exposure would waive privilege, breach an NDA, or hand an adversary your hand. These belong on in-house retrieval over your own corpus, on local compute, where the privileged material never leaves your control. At the other end, public-law research and regulatory horizon-scanning run happily on a frontier model: the inputs are public and the capability premium is real.
The interesting middle, template and clause drafting, internal policy work, is where a vendor or a hybrid pattern earns its place: capable, convenient, and acceptable because the confidentiality stakes are bounded. Vendor due diligence here is not optional; where a tool sends your data, and whether it trains on it, is the whole question.
A Rindogatan-modelled index (0–100): higher = stronger case for in-house/sovereign deployment, driven mainly by privilege and confidentiality. Directional, not a survey.
The privilege test that decides it all
One question, applied honestly to every workload, builds the entire placement map.
Ask of each matter: would exposure of this content waive privilege or cause material harm? If yes, it has one safe home, sovereign, in-house, auditable. If no, the convenience and capability of a vendor or frontier model can win. The discipline is to apply the test by matter, not by department: the legal team is not a category, but an unredacted M&A data room is.
This is also where the EU AI Act and professional-conduct duties converge with sovereignty: the obligations to supervise, to maintain confidentiality, and to be able to explain are all easier to honour on infrastructure you govern. For a GC, sovereign legal AI is not the cautious option; it is the defensible one.
“The build-vs-buy question in legal is really a privilege question: anything that would waive privilege if it leaked has only one safe home.”
Building the legal-AI portfolio
Four moves to a deliberate build-vs-buy map instead of an accidental one.
Classify your matter types by privilege and confidentiality exposure, not by practice area, and place each on the sovereign-to-frontier spectrum. Run real vendor due diligence on Harvey, Legora, Spellbook and Robin AI: data residency, training use, audit rights, exit.
Stand up one sovereign workload, privileged-document retrieval on local compute is the canonical first build, to prove the in-house option works, then route each matter type to its right home under a standing governance policy.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.