Skip to content
Predictive Systems

Case study · Legal drafting and research

It never leaves the building

A 120-lawyer firm wanted AI and could not let a single client file leave the office. What it got runs on the firm’s own hardware, grounds its answers in Supreme Court decisions, and shows the source behind every line.

Allan Tan · Founder and Chief AI Scientist


A hundred and twenty lawyers. Two hundred documents a day. And a requirement that ruled out most of the market before the first conversation.

Data remains on premise. The client wanted full confidentiality.

For a law firm this is not a preference to be negotiated down. Client files are covered by privilege, and privilege does not have a clause about vendor infrastructure. A tool that sends a draft contract to somebody else’s cloud for processing is a tool the firm cannot use, however good it is.

That constraint came first, and everything else was built inside it.

The work that was worth automating

The firm’s complaint was not that its lawyers were bad at drafting. It was that too much of what they did was repetitive, and that research was slow.

Those are different problems. The first is volume: the same clause, the same structure, the same twelve variations, drafted again. The second is retrieval: knowing that the firm has argued this point before, and finding where.

The system addresses both, and the results are lopsided.

4 hours 30 minutes

Drafting from a template, before and after. Bespoke drafting moved far less.

That qualifier is not modesty. The saving is not uniform across all drafting, and a firm evaluating this should expect the bulk of it where the work was most patterned. The document that took an afternoon is the one that now takes half an hour.

The part that is not a time saving

The more interesting outcome does not show up in a productivity figure at all.

Because the system can be asked to argue a position, it can also be asked to argue against one. A lawyer preparing a submission can put the counterfactual to it. What would the other side say, what does the strongest version of their case look like? It answers before committing to a line.

That is not automation of anything. It is a sparring partner available at 11pm, and the firm reports it produces better arguments rather than merely faster ones. It is also, of the two outcomes, the one that would be hardest to buy elsewhere.

The citation problem

Everything above is worthless if the system invents a case.

A hallucinated citation in legal work is not a quality issue. It is the kind of thing that ends up in a judgment with the lawyer’s name attached, and it has happened often enough elsewhere to make every general counsel rightly nervous.

The system attacks it from two directions at once. Answers must surviveconsensus across different agents and across different source documents: several independent readers, working from more than one source, arriving at the same claim.

And retrieval is anchored where a lawyer would anchor it. The strongest grounding is Supreme Court decisions: published, citable, and the authority that actually settles a point rather than merely supporting one. The firm’s own past papers and previous arguments sit alongside that as an additional source, not as the foundation. Institutional memory is useful. It is not authority, and a system that confused the two would produce confident work a court would not accept.

It is worth being precise about what that buys. Agreement is not proof. What it is, is a hostile environment for a fabrication: a hallucination is unlikely to be reproduced by a different agent reading a different document, so a claim that survives independent corroboration is far less likely to be invented. That is a strong signal, and it is not a guarantee, and in a system built to stop invented citations, overstating the safeguard would be its own version of the same mistake.

Show the source, then let them argue with it

Which is why the last line of defence is a human being with the evidence in front of them.

Every statement the system produces carries its source. Not a bibliography at the end, not a footnote to chase. The provenance travels with the claim, so a lawyer reading a suggested clause can see immediately what it was drawn from.

And they can push back. The lawyer can question the system about any statement, ask where it came from, ask what else supports it, ask what would undermine it. The output is a position to be interrogated rather than an answer to be accepted, which is roughly how a partner treats a junior’s memo, and exactly the relationship the work requires.

Why on-premise decided the design

It would be easy to file the deployment model as a procurement detail. It is closer to the opposite.

The case law the system reasons from is public. Everything else about the work is not. The matter being drafted, the client it belongs to, the position the firm is considering and has not yet taken. That is the material moving through the system all day, and it is exactly what privilege covers. The firm’s own past papers, brought in as a supplementary source, are privileged too.

A hosted tool would have meant all of it crossing a boundary on every query. Running inside the firm’s own walls is what makes it usable on live matters rather than on sanitised examples, which is the difference between a system lawyers work with and one they demonstrate.

The confidentiality requirement did not limit what could be built. It is the reason the useful version could be built at all.


Data that cannot leave your network?

Let’s Talk AI