Keeping Client Data Safe: 3 Alarming AI Risks Law Firms Can’t Ignore

Keeping client data safe in the age of AI webinar banner featuring speakers Rick Thompson, Steven R. Combs, and moderator Dan Safran.

If you registered for our September 3rd webinar and life got in the way — or you heard about it after the fact and wished you’d caught it live — good news. The full recording is right here, and honestly, I don’t think you will miss much by watching it after rather than during. Sixty minutes, no sales pitch, just a genuinely useful conversation about keeping client data safe in a legal industry that’s adopting AI a lot faster than most firms are governing it.

Watch the Full Webinar Recording

Who Joined the Conversation

Dan Safran, President and CEO of Unbiased Consulting, moderated the session. I, Steve Combs, sat alongside Rick Thompson, who spent more than 25 years as a CIO inside law firms, including an AmLaw 200 firm — so when he talks about the gap between policy and what’s really happening on lawyers’ desktops, it’s coming from firsthand experience, not a slide deck. As Co-Founder & Principal of Cocha Technology, I brought the security and business-strategy side to the table, along with a stack of current statistics that, frankly, surprised even the two people sitting next to me.

Why This Conversation Hit a Nerve

Here’s the number that opened the whole discussion: research from earlier this year found that almost 60 percent of legal professionals surveyed in the UK admitted to using unsanctioned, “shadow” AI tools at work — tools nobody in IT approved, vetted, or even necessarily knows about. Zoom out further, and roughly 90 percent of legal professionals are using AI in some form. Zoom in on the other side of that equation, and only about 23 percent of organizations have AI runtime controls in place to govern any of it.

I said it plainly during the session: with that many people using AI and so few technical controls in place, the gap isn’t a hypothetical risk anymore. It’s already happened, quietly, inside most firms.

The "Whack-a-Mole" Problem

Rick offered an analogy midway through the session that I think is going to stick with a lot of people who watch this: shadow AI isn’t like one whack-a-mole game anymore. It’s an entire arcade full of them, running simultaneously, and nobody’s fast enough to hammer them all down. Every unsanctioned tool a well-meaning associate or partner adopts inherits whatever access that person already has — which means confidential client data can end up somewhere nobody intended, without anyone doing anything they’d consider reckless in the moment.

That’s really the uncomfortable core of this whole topic. Most of this risk doesn’t come from bad actors. It comes from smart, busy people trying to work faster, using tools that quietly create exposure nobody’s tracking.

Confidentiality, Privilege, and the Discoverability Problem

One thread that ran through the discussion deserves its own callout: AI-generated drafts are discoverable, and courts are already grappling with what that means for privilege. Combs referenced a growing body of case law — including a well-known public database maintained by French legal researcher Damien Charlotin, which tracks court decisions worldwide involving AI-related issues in litigation — as evidence that this isn’t a future problem. It’s an active, growing one, with real sanctions and real consequences already on the record.

What a Real Framework Looks Like

The part of the conversation I found most useful wasn’t the alarming stats — it was the practical model I laid out for addressing this. I broke it into three pieces: governing and managing the AI tools themselves (identity, device trust, and browser-level controls), getting a genuine handle on permissions and data labeling, and building in real accountability through auditability and defensibility. That last piece matters more than it might sound — Rick and I both agreed that over the next 6 to 24 months, courts, regulators, and even cyber insurance carriers are going to expect firms to demonstrate exactly how their AI use is being tracked and governed, not just assume it’s fine.

If You Want to Go Deeper

I also mentioned a resource during the closing minutes of the webinar: a readiness snapshot offered through Cocha Technology and Unbiased Consulting that maps a firm’s current exposure — shadow AI usage, access monitoring, and overall security score — as a starting point before diving into a full remediation plan. If that’s something you’d like more information on, reach out and I can point you in the right direction.

Thanks again to everyone who registered, attended live, or is catching this recording after the fact. If keeping client data safe in the middle of this AI shift feels like a moving target right now, you’re not imagining it — and you’re not alone in trying to figure it out.

Recent Posts

Have Any Question?

Call or email Cocha.  We can help with your cybersecurity needs!

About the Author:

Picture of Steve Combs

Steve Combs

Co-Founder & Managing Director, Cocha Technology

Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.