Scott Nicholson, Senior Product Manager, iManage.com
As AI use accelerates across law firms, so does the concern over how to adopt it responsibly without risking confidentiality or compliance. According to a recent global research report surveying 3,000+ professional services organizations (including law firms), 85 percent of respondents are piloting AI in some form – while 36 percent have already experienced a data leak or compliance issue.
Ethical walls have a clear role to play in managing this tension between the promise of AI and the potential risk it presents to data.
Law firms have long relied on ethical wall solutions to protect their sensitive information by deploying information barriers at scale across client, department, or project levels.
However, as AI becomes more deeply embedded in the way that law firms work, this approach becomes more complicated. Today’s law firms want to reduce risk and prevent accidental data leaks but still enable their practitioners to tap into valuable institutional knowledge and work smarter with the latest tools and technologies.
How can law firms best address these competing objectives and effectively use ethical walls to safeguard legal data in the AI era?
The AI trajectory, from “assisted” to “integrated”
It’s helpful here to zoom in on how AI is being implemented at law firms – and how it both raises the stakes for governance of sensitive information and complicates the picture of what ethical walls should look like.
The AI adoption curve can be understood as five levels of delegation, each representing a deeper handoff of work from humans to AI.
Phase 1 is the “assisted” phase. The AI tool sits in its own browser tab. Think here of a lawyer going into their internet browser to use a tool like ChatGPT to do some legal research and either typing a question or copying and pasting some information. In this phase, the AI tool does not have access to content – the lawyer has to bring the content to the AI.
Phase 2 is the “augmented” phase. In this case, think of using Copilot within Microsoft Word to draft a contract. The AI (Copilot) only has access to the content of the tool it sits in (Word), and every output still goes through a human before it goes anywhere.
Phase 3 – the “orchestrated” phase – introduces a new level of complexity. The AI can link to different systems via MCP (model context protocol) or a standard API – and it can fetch content from all of them. The human becomes less in the loop now that the AI can access multiple systems. Ethical walls apply to these connections, but only in systems where they’re actually implemented.
Phase 4 is the “delegated” phase where people are building agents for basic, repetitive tasks – like pulling key terms or clauses from incoming agreements, for instance. The AI stays inside the user’s information barriers, and a human is still in the loop but primarily just at the beginning and the end of the task.
Finally, we move to phase 5, which is the “integrated” phase. At this stage, a human no longer triggers the AI tool. The AI acts almost like an employee: all it needs is a trigger and then it just starts to work – for example, automatically sending a contract off for signature and countersignature.
Taken together, these different phases show how quickly AI can move deeper into legal workflows – which brings us back to our key question: what should security policies and ethical walls look like at an AI-enabled law firm?
The walls must evolve
Clearly, safeguarding legal data today requires ethical wall solutions that are built for the new challenges AI introduces.
For starters, law firms need the ability to block AI tools for specific clients, matters, departments, or even entire offices. If a client says, “We do not want anyone using AI on our content,” the firm should be able to implement that ethical wall instantly.
There are also categories of content that should remain entirely outside AI systems. Certain matters – child protection cases, for example – carry data privacy implications that make AI involvement unacceptable regardless of governance controls. Ethical wall solutions must account for these cases.
Another governance challenge involves AI vaults: the workspaces that an AI tool creates to enable users to collaborate with their colleagues on a project or matter.
The problem is that a user can share a vault with someone who isn’t on the underlying ethical wall – and suddenly, content that was supposed to be restricted is visible to someone who should never have seen it. Any contemporary ethical wall solution must address this risk directly.
A third major concern is AI agents operating without adequate governance. For instance, an e-signature agent might automatically trigger when a document is marked ready for signature. If it pulls the wrong file and builds the signature package around that mistake, and the lawyer approves it without noticing, then the incorrect document is sent out. The human was technically in the loop, but the error slipped through – which means ethical walls must account for AI agents performing tasks with human-like autonomy.
Confidence without compromise
The need for ethical walls was present at law firms long before AI entered the picture – AI is simply creating new needs around how they must function. That means that law firms need to partner with vendors who are already thinking about these emerging governance challenges and evolving their solutions accordingly.
That’s the only way that law firms can embrace AI safely, securely, and with confidence – and without compromising the data in their care.

Scott Nicholson is Senior Product Manager at iManage. he has over 10 years’ experience working on legal technology issues, working with a global law firm, and enterprise SaaS providers.






