Insights · Tools
Build vs. Buy Legal AI: When a Small Firm Should Build Its Own
Buy the mature commercial tools for research and contract review, and build only where your firm holds a defensible private asset no vendor can sell.
Most small and mid-sized firms do not need to build their own AI. They need to buy the right tools, govern them well, and reserve building for the one place where the firm holds something a vendor cannot sell it: its own accumulated work product. This piece offers a decision framework for the build vs buy legal AI question, with the cost and risk considerations that should drive it.
Start with the asset, not the technology
The mistake firms make is treating AI as a technology purchase. It is better understood as a question about assets. Commercial vendors compete on assets they can scale across thousands of customers: comprehensive caselaw databases, statutory and regulatory corpora, contract clause libraries, and large model providers. A 12-lawyer firm cannot out-invest Thomson Reuters or LexisNexis on a caselaw database, and there is no reason to try.
What a vendor cannot sell you is your own firm. Your closed files, your motion bank, your negotiated agreements, your internal memoranda, your deposition outlines, and the institutional judgment encoded in twenty years of edits are a defensible private asset. No competitor has them. A general-purpose tool, however capable, does not know how your firm structures an indemnification provision or which arguments persuade the judges in your venue.
So the framework reduces to a single question. For any given task, ask whether the value comes from a public or licensable corpus, or from your firm's private work product:
- If the value lives in a public or licensable corpus (caselaw, statutes, public filings, general contract standards), buy.
- If the value lives in your firm's private precedent and judgment, and only there, building or configuring on top of your own data may be worth it.
Everything else in this article is about applying that test honestly and pricing it.
Buy the mature categories: research and contract review
Two categories are mature enough that building your own is hard to justify.
The first is legal research. The leading platforms layer retrieval and generative summarization over licensed caselaw and secondary sources that took decades and enormous capital to assemble. You cannot replicate the underlying corpus, and the license terms generally forbid you from extracting it to train your own system. Buy here, and buy with eyes open about reliability, which the next section addresses.
The second is first-pass contract review and due diligence. Commercial tools trained on broad clause libraries are competent at the commodity layer of transactional work: spotting a missing limitation of liability, flagging an unusual governing-law clause, surfacing change-of-control provisions across a data room, and producing a first markup against general market standards. This is genuine leverage, and rebuilding it in-house would mean recreating a clause corpus you do not have.
A useful instinct: if a capable competitor down the street could buy the identical capability off the shelf next week, it is not a source of durable advantage, and you should buy it rather than build it. Treat these tools as commodities to be procured well, not as differentiators to be engineered.
The risk that survives the purchase: verification
Buying does not transfer the duty of verification. It remains squarely on the lawyer, and the authorities are explicit.
In Mata v. Avianca, 678 F. Supp. 3d 443 (S.D.N.Y. June 22, 2023), Judge P. Kevin Castel sanctioned two attorneys and their firm after they filed a brief citing six fabricated decisions that ChatGPT had generated. The court imposed a $5,000 penalty jointly and severally under Rule 11, finding the lawyers had acted in subjective bad faith by continuing to stand behind the fake citations after their authenticity was questioned. The lesson is not "ChatGPT is dangerous." It is that an unverified machine output filed under a lawyer's signature is the lawyer's responsibility, whatever the source.
And this is not unique to consumer chatbots. A 2024 Stanford RegLab and HAI study, "Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools," tested purpose-built legal research products and still found meaningful error rates: roughly 17% of queries for Lexis+ AI and about 33% for Westlaw's AI-Assisted Research produced hallucinated or misgrounded content, across more than 200 hand-scored queries. The marketing term for these systems is "hallucination-free." The data did not support it. Buying a specialized tool reduces risk; it does not eliminate the obligation to check.
The ethical frame is now settled. ABA Formal Opinion 512 (July 29, 2024), the ABA Standing Committee's first comprehensive guidance on generative AI, ties this directly to the duty of competence under Model Rule 1.1 and its Comment 8 on technology, and stresses that the degree of independent verification required depends on the tool and the task. Verification cost belongs in every build-or-buy calculation, because it does not disappear no matter which side you choose.
When building (or configuring) is defensible
Building rarely means training a model from scratch. For almost every firm it means configuring retrieval over your own documents: a system that, when you ask a question or draft a clause, pulls from your closed matters, your prior briefs, and your negotiated agreements, and grounds its output in those specific sources. This is often called retrieval-augmented generation, and it sits on top of bought components (a commercial model, a vector database, a document platform). You are not rebuilding the engine; you are pointing it at your private library.
Build or configure when several of these are true:
- The task depends on your firm's precedent and house style, not general law (for example, generating a first draft of a recurring agreement the way your partners actually negotiate it).
- You have a clean, reasonably organized body of work product to ground the system. Garbage in is the dominant failure mode; if your document management is chaotic, fix that first.
- The workflow is high-volume and repeatable, so configuration cost amortizes (a litigation shop that files the same motion types weekly, an immigration or estates practice with standardized packages).
- No off-the-shelf product captures the advantage, because the advantage is your data.
A custom AI law firm capability is most defensible when it turns institutional memory into leverage: a brief-bank assistant that surfaces the firm's own winning arguments, a clause generator tuned to the firm's negotiated positions, an intake summarizer that follows the firm's matter taxonomy. These compound in value as the firm's work product grows, and a competitor cannot buy them because they are made of your files.
Counting the real cost of building
The build side of the ledger is routinely underestimated because the obvious cost, software, is the smallest part.
- Build is not a one-time spend. A configured system needs monitoring, evaluation, updating as models change underneath you, and a named owner. Without maintenance, quality silently degrades. Budget for the year, not the launch.
- Data preparation dominates. Cleaning, de-duplicating, permissioning, and structuring your documents is most of the work and most of the cost. It is also unglamorous and easy to defer.
- You still pay the verification tax. A homegrown tool grounded in your own files can still produce a wrong or out-of-date answer, so lawyer review time persists.
- Evaluation is non-optional. You need a way to measure whether the system is right often enough to rely on, which means building test sets and grading outputs. Few small firms staff for this.
- Vendor risk shifts to you. When you buy, the vendor carries security, uptime, and model maintenance. When you build, those become your responsibilities, including breach exposure over a repository of client confidences.
Set against this, buying converts a large uncertain capital project into a predictable per-seat subscription with the maintenance burden on someone else. For most firms most of the time, that trade favors buying. Building earns its keep only where the private-asset advantage is real and the volume is high enough to repay the overhead.
Confidentiality, supervision, and fees: the governance that applies either way
Whichever path you choose, three obligations attach.
Confidentiality (Model Rule 1.6). Putting client information into an AI tool implicates the duty of confidentiality. Formal Opinion 512 advises that lawyers evaluate where data goes, whether inputs are used to train the provider's models, and who can access them, and it cautions that boilerplate consent buried in an engagement letter is generally not adequate when client confidences will be fed into a self-learning tool. The diligence required when you build on your own infrastructure is no lighter; the data is now inside systems you must secure yourself.
Supervision (Model Rules 5.1 and 5.3). Opinion 512 frames AI oversight through the supervision rules. Managing and supervisory lawyers should establish clear policies on which tools may be used, for what, and with what verification, and should ensure that lawyers and staff are trained on them. A tool used without a policy is a supervision gap.
Fees (Model Rules 1.5). Opinion 512 also addresses billing. If a tool lets you complete a task in less time, you generally may not bill the hours you would have spent without it, and you may not charge a client to learn a technology for general use, though you may bill time learning a specific tool a client has asked you to use on the matter. Efficiency gains, in general, belong to the client, not the timesheet.
State authorities reinforce all of this, including guidance from the State Bar of California, the Florida Bar (Ethics Opinion 24-1, issued in 2024), and others; consult the rules and opinions of every jurisdiction in which you practice, since they vary.
A short decision checklist
Before you build anything, work through this:
- Does the value come from a public or licensable corpus? If yes, buy.
- Does it depend on your firm's private work product and judgment? If yes, building or configuring may pay off.
- Is your underlying data clean and well-organized enough to ground a system? If no, fix that first.
- Is the workflow high-volume and repeatable enough to amortize maintenance?
- Have you budgeted for data prep, evaluation, monitoring, security, and ongoing lawyer verification, not just software?
- Do you have a written policy covering confidentiality, supervision, and billing for the tool, under Opinion 512 and your state's rules?
The honest answer for most firms of 3 to 30 lawyers is: buy the mature tools for research and contract review, govern them rigorously, and build narrowly, where your own precedent is the product and no vendor can sell what you already own.
This is general information for lawyers and law-firm leaders, not legal advice, and it does not create an attorney-client relationship. The authorities are cited so you can read them yourself.
The longer argument continues in AI in the Defender’s Office, a national field guide now in production.
Read about the book →