Keep the alpha. Rent only the capability.
A no-training clause solves privacy, not competition. Rent capability; never rent the layer that holds your judgment.
Legal AI is good enough now that the interesting question moved. It is no longer whether to adopt, it is what you hand over on the way in. Three moves:
Your positions, your fallbacks, your precedent, and the reasoning that produced them. That is the asset a vendor cannot sell you and a rival cannot buy. It stays on compute you control, by architecture rather than by clause.
Matter types, clause taxonomy, party roles, risk severity, escalation thresholds, written once, versioned, and readable. These are the deterministic levers: they bind every model, every vendor, and every replacement for both, and they survive the tool that is fashionable this year.
A routing gateway with a hard floor: privileged work sealed to local inference, anonymised lanes for the hard non-privileged minority, citations verified character by character, every call in an append-only log. Harvey, Legora, and the frontier labs plug in behind it, and can be swapped out on a Tuesday.
Public-law research and bounded, anonymised drafting. The classifier decides, not the person in a hurry, and a privileged matter is refused rather than warned about.
Reviewed by counsel, logged against the matter, citations verified character by character before anyone relies on a word of it.
The point is not that vendors are bad. It is that they should be replaceable. When the ontology, the routing rules, and the log belong to you, a supplier is a supplier, and your GC can still tell a court exactly where every privileged document went.
The disruption is not theoretical. Named, current evidence, cited, not claimed.
Harvey reached an $11B valuation with customers running more than 25,000 custom agents that, in its words, “run workflows from start to finish.”
Harvey →European-built Legora (Stockholm) raised to a reported $5.6B valuation as “the AI operating system for the legal industry”, agents running end-to-end legal workflows.
Legora →OpenAI's Hebbia case study is titled, plainly, “Automating 90% of finance and legal work with agents.”
OpenAI →The LegalQuants community maintains an open-source engine and assistant that run against models you choose, seal privileged matters to local inference by architecture, and verify every citation character by character.
LegalQuants →Legal AI works, so the question has moved. It is no longer whether to adopt, but what a legal department gives away when it does. We help General Counsel and Legal Ops separate the capability that can safely be rented from the judgment that cannot, then build the two things that keep them in control of both: a legal ontology of their own, and a harness that decides where every matter is allowed to run.
On what third-party vetting became once anyone could generate the paperwork, and on why the deterministic scaffolding is the part that holds its value.
Certificates used to stand in for substance. Automation now strips the padding off a vendor answer in seconds, and rewards the organisations that meant it.
Convergence makes model capability a commodity, which puts the value back where it always was: in the boring, deterministic scaffolding.
Where agentic AI and a curated, lawyer-directed skeleton meet, and the two kinds of law firm that come out of it.
A legal department runs a privacy programme, an AI register, a vendor file, and a negotiation queue, and every one of them is a place where your positions get encoded. We build and operate these as todo.law: self-hostable, deterministic by default, with the Donna assistant only where you switch it on. Read the code, run it on your own infrastructure, or have us run it for you.
Open source (AGPL for the practice apps, Apache-2.0 for the assistant). Read the code before you trust it, run it yourself, or have us run it.
A function-by-function map of which AI use cases are prohibited, high-risk, or limited-risk under the Act, and the exact governance, documentation, and human-oversight controls needed for each.
A weighted scoring model for General Counsels deciding which matter types to outsource to legal-AI vendors and which to keep on sovereign infrastructure, including TCO and privilege-risk analysis.
In one 90-minute working session we map it across the frontier-sovereign axis, cost, risk, and strategic value. Then we tell you what we'd do.