confidentiality

When the Leak Is the Contract: What Legal AI Fiction Tells Us About Real Confidentiality Risk

Adira EditorialLegal AI desk4 min read
Editorial illustration for When the Leak Is the Contract: What Legal AI Fiction Tells Us About Real Confidentiality Risk

The Fiction That Feels Familiar

Artificial Lawyer's serialised story 'The Innovators' is running a plotline built around a leak, and the opening line of Part 4, 'We have a leak,' is the kind of sentence that lands differently when your day job involves contracts containing trade secrets, pricing schedules and unreleased product roadmaps.

Good legal fiction works precisely because it compresses anxieties that practitioners carry around but rarely articulate in board reports. The 'civil war' framing of this instalment, pitting factions within a legal technology organisation against one another, mirrors a tension that in-house teams and law firms are quietly navigating right now: who controls the data that flows through AI legal tools, and what happens when that control breaks down?

The question is no longer hypothetical. It deserves a serious answer.

Confidentiality Is a System, Not a Policy

Most organisations treat confidentiality as a document. There is a policy, there is an NDA, there is a clause in the employment contract. What they frequently underestimate is that confidentiality is actually a system, one made up of people, processes, permissions and, increasingly, the AI tools that sit between a lawyer and a counterparty's signed agreement.

When an AI model is trained on, or merely processes, a corpus of your contracts, several questions immediately arise. Where does the data reside? Who can query it? Does the model retain anything between sessions? Can outputs be reconstructed to reveal inputs? These are not paranoid questions. They are the questions a careful general counsel should be asking before any AI CLM is deployed at scale.

The risk is not only external. Internal leaks, whether accidental or deliberate, are statistically more common than external breaches in professional services environments. An AI system that surfaces the wrong contract to the wrong team member, or that allows a junior associate to run a query that returns commercially sensitive terms from a counterparty's file, is a confidentiality failure even if no data ever leaves the building.

What 'Reading from Your Side' Actually Means

Adira is built around a principle we call reading contracts from your side. This is not a marketing formulation. It reflects a genuine architectural choice about whose interests the system serves and whose data it is trained to protect.

Many AI legal tools are positioned as neutral intermediaries, platforms that sit above the fray and serve whoever is using them at a given moment. The problem with neutrality in contract work is that contracts are inherently adversarial instruments. Every clause allocation, every definition, every notice period is a negotiated outcome between parties with competing interests. A tool that is genuinely neutral is, in practice, a tool that serves no one's interests particularly well.

Reading from your side means the system understands your standard positions, your risk tolerances, your jurisdiction-specific obligations and your historical negotiation outcomes. It means the data architecture is designed so that your counterparty's information does not bleed into your organisation's institutional knowledge base, and vice versa. Confidentiality is baked into the structure, not bolted on as a feature.

The In-House Team's Due Diligence Checklist

If the fictional leak in 'The Innovators' prompts anything useful, it should prompt in-house legal teams to run a short but serious audit of their AI legal tooling. The following questions are a reasonable starting point.

First, data residency: where are your contracts stored when they are being processed by an AI, and in which jurisdiction does that storage sit? This matters both for data protection compliance and for any sector-specific confidentiality obligations, particularly in financial services, healthcare and defence.

Second, model training boundaries: is your contract data used to train or fine-tune any underlying model, and if so, is that model shared with other customers of the same vendor? Shared model training is a known vector for inadvertent information transfer.

Third, access controls: can the AI system enforce the same role-based access permissions that your existing document management systems apply? If a paralegal cannot open a particular matter file in your DMS, can they nonetheless extract information from it by querying the AI layer?

Fourth, audit trails: does every AI-assisted contract interaction generate a log that your team can review? In the event of a dispute or a regulatory inquiry, you need to be able to demonstrate what the system was asked and what it returned.

The Larger Lesson From Legal Fiction

The value of serialised legal fiction like 'The Innovators' is not that it predicts specific events. It is that it forces practitioners to consider scenarios they would otherwise defer thinking about until those scenarios arrive as live problems.

The civil war metaphor is apt not because legal AI organisations are necessarily riven by internal conflict, but because the deployment of AI in legal work genuinely does create competing loyalties: between efficiency and caution, between openness and confidentiality, between the vendor's product roadmap and the client's risk profile.

Clarity about whose side the AI is on, structurally, contractually and technically, is not a soft consideration. It is the foundation on which trustworthy legal AI must be built.

Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom