AI for lawyers: what to buy, what to build, what to skip
AI for lawyers, from an operator who ships builds: the honest capability map, the buy-vs-build decision, the ethics rules, and a 90-day way in.

Most "AI for lawyers" guides are tool catalogs. The question under the catalog is the one nobody ranks for: do you buy a tool, or build a system around how your firm actually works?
TL;DR
- "AI for lawyers" splits into three real choices: run a raw model like ChatGPT or Claude, buy a legal-tuned SaaS tool (CoCounsel, Spellbook, Lexis+ AI, Paxton), or build a custom intelligence layer around your own data. The tool listicles only cover the middle option.
- AI ships real value at drafting, summarization, research-with-verification, and intake. It sinks at citation accuracy, client-data confidentiality, and audit trail, but those are gaps a build closes, not permanent limits.
- The ethics rules are settled enough to act on: ABA Formal Opinion 512 (2024) says verify outputs and protect client data, and the Mata v. Avianca sanctions (2023) show the cost of skipping the review step.
- What decides buy-vs-build isn't headcount. It's whether you want an AI hire that builds systems around your own data and keeps them current, or a static tool you operate by hand. A solo practice that wants the former gets more from a build than a 50-attorney firm that just wants a chat window.
- Start with one workflow and a 90-day pilot. It is a paid quarter with a working build at the end, and you can fire me anytime if the value isn't there.
This is the article we'd write for a managing partner deciding where to spend on AI this year, and wanting to spend it on the thing that compounds. It covers what AI actually does in a firm today, the buy-vs-build decision, the ethics constraints, what a custom legal system looks like, and how to test it before you commit. The legal-specific facts here are public and cited. The build experience behind the recommendations comes from shipping custom intelligence layers inside live mid-market companies.
What can AI actually do for lawyers right now?
AI in 2026 is spiky. It has become extraordinary at language work and ordinary at everything else, which is exactly the shape of most legal work. So the honest map has two columns. AI ships real value at first-pass drafting (correspondence, memos, demand-letter shells), document summarization (depositions, discovery sets, long contracts), research with a verification step, and non-billable admin (intake routing, scheduling, training material). All of those share one trait: the failure mode is wasted time, not malpractice.
It sinks, sometimes badly, at three things in raw form: citation accuracy, where a public model will invent cases that read perfectly; client-data confidentiality, where the consumer tool retains what you paste in; and audit trail, where you cannot reconstruct who reviewed what. The tool listicles treat those as reasons to buy their product. They are better understood as the exact gaps a custom build is for. The mental model most lawyers start with, a chat window that is good at writing but hallucinates, is the 1995 version of the internet: technically accurate, and about to be made small by everyone who builds the business around it instead.
Buy a tool or build a system? The decision that actually matters
Once you get past "is AI good for lawyers," the real fork appears, and it has three tines. The strategy question sits upstream of the tool question, and the playbook for working it out does not change much between a software company and a law firm.
The three options most firms compare:
| option | what it is | the catch | best fit |
|---|---|---|---|
| Raw model (ChatGPT Business, Claude) | The general tool, ~$25–30/seat/mo | You enforce every guardrail by hand: review step, citation checks, keeping client data out of the public model | You want the raw capability for drafting and summarization and you will run your own review step. The entry point at any size. Covered in depth for the ChatGPT case here. |
| Legal SaaS (CoCounsel, Spellbook, Lexis+ AI, Paxton) | Foundation models wrapped with legal tuning and controls, roughly $50–$850/seat/mo | Lock-in, a workflow shaped to the vendor's defaults, and each tool stops at the edge of its one job, so the research memo still does not flow into drafting or intake on its own | A genuinely standard workflow (legal research, contract review) a tuned tool already fits |
| Custom intelligence layer (fractional CAIO retainer, builds included) | Systems built around your own data and maintained over time. Priced like a hire, not a software seat: roughly $15K–$25K/mo, with a solo build at the low end | Onboarding time and senior-partner attention to shape what gets built | You want an AI hire that builds around your data and keeps it current, not a tool you run by hand. Fits a solo practice or a large firm. |
The mistake is reading those tiers as a budget ladder. They are a fit question. Every firm has repetitive, high-value work, so "do you have work worth automating" is not the dividing line. The dividing line is what you want done with it. The SaaS pitch leans on legal tuning, confidentiality, and an audit trail as if those were unique to it. They are not. A custom build delivers the same, shaped to your firm, and keeps improving, while the SaaS option adds lock-in and a vendor-shaped flow. What makes the build the durable choice is the part no subscription offers: it is software built and maintained with AI, so it compounds instead of freezing the day it ships. You are getting an AI team's capability at the cost of one strong hire, and the reason firing it rarely makes sense is that you would be firing the firm's accumulating AI capability, not a vendor.
What does AI used safely in a law firm look like?
The ethics questions are more settled than the vendor fear-marketing suggests, and the rules point at workflow design, not tool choice. ABA Formal Opinion 512, issued in 2024, applied the existing Model Rules to generative AI: competence (Rule 1.1) means understanding what your tool can and cannot do, confidentiality (Rule 1.6) means keeping client data out of tools with unclear retention, and supervision (Rules 5.1 and 5.3) means a lawyer owns the output. None of that requires a legal-specific product. It requires a review step on every AI workflow before output leaves the building, client data isolated from any public model, and a documented chain of who checked what.
The cost of skipping that step is on the record. In 2023, in Mata v. Avianca in the Southern District of New York, a lawyer filed a brief citing cases ChatGPT had fabricated; the court imposed a $5,000 sanction and ordered him to notify his client and the judges whose names had been attached to invented opinions. Every vendor tells that story as a reason to buy. The accurate reading is narrower: it was a process failure, a missing verification a paralegal would have done in 1995, and the workflow did not catch it. A raw chat window cannot ground its citations against real case law; a system built around it can, which is the whole point of building one. The confidentiality risk runs the same way, and a 2026 ruling made it concrete. In United States v. Heppner (Southern District of New York, February 2026), the court held that defense materials a client generated by feeding case details into a public consumer AI tool were not protected by attorney-client privilege or work-product, because there is no attorney-client relationship with the platform and its terms permit use and disclosure of inputs, so there was no reasonable expectation of confidentiality. It is one district-court decision, not nationwide law, but the reasoning is the warning: a public chat window is a third party, and the same work done inside a counsel-directed, controlled system stays protected.
How accurate is legal AI, and how long until it pays off?
No AI system is accurate on day one, whatever a vendor promises, and any honest answer starts there. A realistic curve on a firm-specific workflow runs around 60% on day one, roughly 85% by the third quarter as the team feeds it corrections, and past 95% on the workflows people use daily. The 95% is the number that matters and the day-one number is sales theater. The reason a build gets there and a static tool does not is that the build is maintained: someone keeps the models underneath it current and folds the team's corrections back in.
Payoff runs on quarters, not weeks. The first 30 days is integration and a first dashboard; the first real workflow usually lands inside the first quarter; adoption, the part that actually produces results, can take until the end of the second quarter before it accelerates. A small, fast-moving firm on a focused workflow can see payoff inside the first month; a larger or slower one should plan for up to two quarters. The build is quick. How fast the firm changes how it works sets the pace. On return, I will not hand you a number I have not measured: what I am confident about is the mechanism, which is putting attorney hours on the highest-value work instead of the busywork a system can carry.
What a custom legal intelligence layer actually looks like
Concretely, it is usually four or five firm-specific agents wired into one system, not a single chatbot. A representative shape for a litigation-heavy boutique:
- An intake agent that classifies inbound matters by type, runs an initial conflict check, drafts the engagement letter, and routes the file to the right paralegal.
- A drafting agent trained on the firm's own templates and prior winning briefs, so a partner edits a first pass in 20 minutes instead of starting cold.
- A research agent that works against the firm's existing Westlaw or Lexis subscription and returns citation-verified memos with the quotes inline, so the citations are grounded instead of invented.
- A discovery summarization agent for long document sets that returns a paragraph per document with key-passage links.
- A secure document agent for anything touching privileged data, running on a hardened instance with no public-model exposure. In client environments I would not point a public agent framework at sensitive data; I would use a more secure variant and have the trade-off conversation up front.
Five components, one authentication layer, one data layer, one interface. A paralegal texts the intake agent like a colleague; a partner asks the research agent for a memo. When a better foundation model ships next quarter, you swap the component; the system around it stays. This is the thing the listicles cannot sell you, because it is not a product on a shelf. It is the connective tissue around whichever model is ahead this quarter, built around your firm and kept current, and it is what an AI consultant who actually ships builds delivers instead of a tool recommendation.
How to start without betting the firm
Pick one workflow and run a 90-day pilot. It is a paid quarter, not a free trial and not a demo the team only watches: a working build at the end, a quarter of risk instead of a year, and an easy walk-away if the value is not clear.
The workflow has to be specific. "AI for our firm" is too vague to act on. "Draft demand letters from intake forms in our personal injury practice" or "summarize incoming discovery PDFs into one-page case-fact briefs" is one workflow, one output, one team. The first working version comes fast, rough but real enough that a partner can judge whether the value is there. The test is the trajectory, not the demo: trustworthy output, a flow that fits how the firm actually works, and the people who touch it starting to reach for it.
And the engagement that follows is built to be fireable. I run it quarter by quarter, so a firm leaves simply by not renewing at the end of any quarter. The value is not the first build. It is a fractional Chief AI Officer, an outside consultant who works like a hire without anyone joining the payroll: he keeps the workflows you already have current as the models and the firm change, and ships new ones as new bottlenecks appear.
Start with one workflow. Run a 90-day pilot. Fire me anytime. Book a 30-minute call and we will walk through one of the live builds.
Frequently asked questions
Which AI is best for lawyers? There is no single best AI for lawyers, because the choice is between three different things. A raw model (ChatGPT or Claude) is best when you want general drafting and summarization and will run your own review step. A legal-tuned SaaS tool (CoCounsel, Spellbook, Lexis+ AI, Paxton) is best for a standard workflow it already fits. A custom intelligence layer is best when you want systems built and maintained around your own data. The right answer depends on which of those you want, not on which product markets hardest.
Is Claude or ChatGPT better for lawyers? For most firm work the difference between frontier models matters less than the system you put around them. Both hallucinate citations without a grounding step, and both lack confidentiality and audit guarantees in their public versions. A custom build treats the model as a replaceable component: you use whichever is ahead this quarter and swap it later without rebuilding the workflow. Pick on the system, not the logo.
Is it ethical for lawyers to use AI? Yes, within the existing rules. ABA Formal Opinion 512 (2024) applies the duties of competence, confidentiality, and supervision to generative AI: understand the tool, keep client data out of systems with unclear retention, and verify outputs the way you would a junior associate's. The Mata v. Avianca sanctions in 2023 show the cost of skipping that verification. Used with a review step and isolated client data, AI is a tool like any other.
David Reo
Founder, Pinecrest AI
Former spacecraft engineer turned AI automation expert. Helping businesses leverage AI strategy, training, and custom systems.
Ready to explore what AI can do for your business?
Book a free strategy call and we'll map out the opportunities together.
Book a Strategy Call