Legal AI for South African law firms

Legal AI built as an operating system. Not another assistant.

Chatbots answer questions. AILA runs matters — from first instruction to final signature. It drafts in Word on your firm's own precedents. It knows who may see what. And it keeps the record to prove it.

Book a demo Hosted in South Africa. POPIA-aligned. Built by admitted attorneys.

Built by lawyers, for lawyers

What is AILA?

One system for the firm's legal work.

AILA is legal AI software for South African law firms. One system covers matters, drafting in Microsoft Word, a searchable knowledge repository, contract review and e-signing. It works from your firm's own precedents — not the internet's. Your data stays in South Africa, in line with POPIA and Legal Practice Council rules.

It is built by two admitted attorneys, on an engineering team that has been shipping South African software since 2012. Read our story →

Why AILA?

Three reasons firms move.

A physical matter file on an attorney's desk, with South African statutes and a to-do list

One system for the whole matter

You know the matter file. AILA is what it should have become. Instruction, research, drafting, review, signature and archive hang off one spine — instead of getting lost in inboxes and shared drives. Nothing goes missing. Nothing walks out the door.

AILA working inside Microsoft Word and Outlook

It works where your people already are

Drafting happens in Word. Email happens in Outlook. AILA lives inside both as a side panel. No new tool to learn. No copying between systems. And no privileged client text pasted into a browser.

The Constitutional Court of South Africa with the South African flag

South African law, built in

POPIA duties, Legal Practice Council rules and ethical walls are built into the data itself — not into a policy nobody reads. Your data stays in South Africa. Every access is logged. Every log can be produced.

What AILA does

Six jobs. One set of data.

Matters

One file per matter: parties, documents, emails, transcripts, tasks and versions. Privacy levels decide who sees what — and enforce it.

Drafting in Word

Write a brief in plain words. AILA drafts on your templates and your precedents. Hard clauses come back to you as decisions, not surprises.

Knowledge Repository

Ask the firm what it already knows. Every template, clause, opinion and signed agreement — searchable, with its source attached.

Contract review

Findings ranked by risk, checked against your firm's own positions. Each one jumps to the clause it came from.

Tenders

AILA watches the eTenders portal, pulls out the requirements, and builds the compliance pack from documents you already hold.

E-signing

Send, track and file signed agreements without leaving the matter. The signed version goes straight into the repository.

How drafting works

AILA drafts without guessing.

Watch it draft one of yours.

Bring one template and one live matter. Forty-five minutes with the founders. No slides.

Book a demo Read the security brief

Frequently Asked Questions

What firms ask first.

Security and compliance

Privilege is the product requirement.

A firm cannot use a tool that makes confidentiality unclear. AILA is built so the question "who can see this?" always has a clear answer — and so the answer is enforced in the data itself, not just on the screen.

This page is the security brief. It is written so your firm's information officer can hold us to it.

How does AILA handle POPIA?

Every matter records its lawful basis when it opens. A subject access request is answered from the audit log, not from memory: what was held, who accessed it, when, and on what basis.

Retention rules apply to documents, drafts and transcripts alike. When a retention period ends, the derived material goes with the source.

How does AILA fit Legal Practice Council rules?

Conflict checks run when a matter opens, against the parties already in the system — not a manual register.

File-retention periods follow the applicable rules by default. Trust-account material is kept apart from general matter content by design.

How is an ethical wall enforced?

In the data itself, so it holds everywhere at once: repository search, drafting, Outlook summaries, transcripts. An excluded user does not see a redacted result. They see nothing — not even a title.

The wall event itself is logged: who raised it, and when. A wall you can defend in an audit is a wall that leaves evidence.

How does meeting transcription stay private?

MeetingBot transcribes on the machine in the room. Audio is not uploaded and does not pass through a third-party service.

The transcript takes on the matter's privacy level the moment it attaches.

Where is our firm's data stored?

Documents and matter data are stored in South Africa. The AI provider is contracted not to train on your content. No document leaves the tenant for any reason other than answering the request that asked for it.

Our sub-processor list is published below and updated when it changes.

INSERT · SUB-PROCESSOR LIST — REQUIRED BEFORE THIS PAGE SHIPS

What does the audit log record?

Every view, edit, export, wall change and AI generation — with the user, the matter and the time. The log is exportable.

When a client, an insurer or the LPC asks what happened on a matter, the answer is a query, not an investigation.

POPIA LPC rules Microsoft Entra ID AES-256 at rest ISO 27001 APPEARS HERE ONLY ONCE CERTIFIED
Book a demo Send this page to your information officer

Pricing

Per user, per month. Quoted per firm.

We do not publish a rate card. Here is why, plainly: firms differ in size, in how much data needs to move over, and in what they need built. A founding-firm arrangement is priced as one. What we can tell you is exactly how the model works.

What does a subscription include?

Every seat includes all four tools: the web app, the Word add-in, the Outlook add-in and MeetingBot. It includes the Knowledge Repository, matters, contract review and e-signing. Onboarding is part of the deal, not a fee that shows up later. There are no per-document fees. A firm that drafts more does not pay more.

What shapes a quote?

Three things. How many users. How much data comes in at onboarding — templates, precedents and past matters. And whether your firm needs something built that does not exist yet. That last one is a conversation, not a surcharge.

What does it replace?

The honest comparison is not other software. It is the hours your firm spends finding its own knowledge: the precedent hunt before a draft, the re-drafting of clauses the firm already perfected, the version digging before a signature. AILA's cost sits against that time, at your charge-out rates. We will do that arithmetic with you — with your numbers, not ours.

Early firms shape the roadmap and work directly with the founders. Founding-firm terms reflect that.

Book a pricing conversation Fifteen minutes. Your firm's numbers. No slides.

Already using ChatGPT or Copilot?

Every firm has AI now. That is not the same as having a legal system.

ChatGPT, Copilot and Claude are good general tools, and we say so. What they do not have: a matter file, privacy levels, your precedents, or a record of who saw what.

So let's start with what the general tools get right. For learning a new area, for research you will verify, for internal drafts that are not privileged — they are useful. Your associates are already using them, policy or not.

The question is not whether general AI is good. It is whether a general tool is a place to do client work. It is not. Here are five reasons.

01

Privilege has no home there

A consumer chatbot has no idea what a matter, a client or a privacy level is. The moment matter content is pasted in, privileged material sits in a third-party service under consumer terms — outside every control the firm has. There is no ethical wall, because there is nothing to wall. In AILA, privilege belongs to the matter and travels with everything that comes from it. In a chat window, confidentiality is whatever the person typing remembered to leave out.

02

POPIA is the firm's problem, not the tool's

Under POPIA, your firm is the responsible party. Using a general AI service on personal information means cross-border processing, operator duties and transfer conditions the firm must assess and answer for. With consumer tools, there is no operator agreement to point to at all. AILA stores matter data in South Africa, contracts the AI provider not to train on your content, and publishes its sub-processors. The compliance question deserves a document, not a shrug.

03

Made-up citations are now a South African problem

This is no longer an overseas story. In 2025, the Gauteng High Court dealt with a matter where counsel had relied on an AI tool that produced made-up citations. General models produce plausible law, because plausible is what they are built for. A legal system has to do something different: cite what it actually relied on, and say so when it has no authority. That is how AILA is built. It is the sharpest difference between a language model and a legal tool. We wrote about the judgment here →

04

It has never read your precedents

A general model starts every draft from the internet's average agreement. It does not know your templates, your playbook, your negotiated positions — or that your firm settled its restraint wording three matters ago. AILA drafts on your precedents and hands the hard clauses back as decisions instead of guessing. The value of a firm is not that it can produce an agreement. It is that it produces its agreements.

05

No record, no defence

When a client audit, an insurer or the LPC asks who saw what and what the AI did, a chat history in a personal account is not an answer. AILA records every view, edit, export and generation: the user, the matter, the time. The work is defensible because the record exists.

The short version, side by side

What client work needs General AI tools AILA
Matter file and privacy levels No Yes
Grounded in your firm's precedents No Yes
Data stored in South Africa No Yes
Ethical walls, enforced in the data No Yes
Cites what it relied on; says when it has no authority No Yes
Audit log for every view, edit and generation No Yes
General knowledge, learning, exploration Excellent Not what it's for

But we have Microsoft Copilot

This is the sharpest version of the question, because Copilot lives in Word — exactly where AILA drafts. The difference is not location. It is architecture. Copilot can see your firm's documents through Microsoft 365. It does not know they are matters.

There is no matter file, no privacy level beyond file permissions, no playbook, no clause library, no conflict checks, no decision cards. Copilot knows your files exist. AILA knows what they are, which matter they belong to, who may see them, and which clause in them survived scrutiny last time. Same building. Only one has a legal system in it.

What about the paid, private versions?

To be precise, because you will check: the paid business tiers — ChatGPT's business plans, Claude's commercial plans, Copilot for Microsoft 365 — do not train on customer data by default. They are much better than a free personal account.

If your comparison is "free ChatGPT vs AILA", you are comparing the wrong things. Even at their best, the general tools have no matter model, no privilege architecture, no South African legal grounding, no citation discipline, and no audit trail built for a firm's duties. The gap is not the privacy tier. It is everything above.

And then there is privilege

Everything above is about capability. This last part is about duty, and it is the reason a general tool can never be the answer for client work.

POPIA by design. Ethical walls enforced in the data, not just on the screen. Every access logged, and every log producible. Your documents stored in South Africa, with an AI provider contracted not to train on your content.

The full security brief is written so your firm's information officer can hold us to it. Read the security brief →

What they're for, and what this is for

Keep the general tools for what they do well: learning, exploring, non-client work. Bring client work to a system built for it. If you would rather see the difference than read about it, bring a template and a live matter.

Book a demo

Our story

A new product. Not a new company.

AILA is built by attorneys who lived the problem, on top of an engineering team that has been shipping South African software for fourteen years. Here is where both halves come from.

AILA is a HashTopic product

Fourteen years of South African software

HashTopic (Pty) Ltd has been building software in South Africa since 2012. Web platforms, intranets, document systems and AI tools — for universities, science councils and public institutions. Fourteen years of shipping systems that people rely on every day. See HashTopic's work →

A new product, not a new company

This matters more than it might seem. Plenty of legal AI is sold by companies younger than the problem they claim to solve. AILA is a new product, but not a new company: the engineering behind it has a track record you can go and check.

Built, hosted and supported here

HashTopic is based in Cape Town. AILA is built there, hosted in South Africa, and supported by the people who wrote it.

The founders

Attorneys who lived the problem

Both founders are admitted attorneys who practised at Big 5 firms. They did not research the problems AILA solves. They lived them, from articles onward: the precedent nobody could find, the clause re-drafted for the fourth time, the institutional knowledge that left with a colleague.

They watched AI arrive

When they started articles, AI was not part of legal practice at all. They watched it arrive. They watched what it did to firms abroad, what it got right, and where it went badly wrong. That is a useful seat to have had: they know what the international tools do well, and they know exactly where those tools stop making sense inside a South African firm.

International standards, South African realities

AILA is built to close that gap — international standards, South African realities. POPIA. Legal Practice Council rules. The eTenders portal. Citation discipline against South African authority. The things a global product will never prioritise, because it does not have to.

Who we build for

The split we think is wrong

Serious legal AI has been priced and packaged for the largest firms. Everyone else has been offered a chatbot and told to make do. We think that is the wrong split.

The same duties, without the innovation budget

A twelve-attorney firm in Durban carries the same duty of confidentiality, the same POPIA obligations and the same client expectations as a firm of three hundred. It just does not have an innovation department to fund the tools.

Small and medium South African practices

We build for small and medium South African practices — the firms that do most of the country's legal work. Excellent tools should be within their reach. That is the whole point.

Where we are now

Onboarding founding firms

AILA is new, and we say so. We are onboarding our founding firms now. They work directly with the founders, and what they need next is what gets built next — a workflow, an integration, a document type. No ticket queue. No committee.

A small team, by design

Firms that work with us work with the people who build the product. That is a deliberate constraint, and it is the reason founding firms get the access they do.

Company details

HashTopic (Pty) Ltd

Cape Town, South Africa

INSERT · COMPANY REGISTRATION NUMBER

INSERT · COMPANY LINKEDIN URL (WHEN LIVE)

INSERT · CONTACT EMAIL

Book a demo Read the security brief

Blog

Plain answers to the AI questions firms are asking.

Written by admitted attorneys. No hype, no jargon — what the law and the tools actually require of a South African firm.

← BLOG

The judgment every South African firm should read before using AI

IMAGE SLOT 1/3 — FEATURE
SUGGESTED: SOUTH AFRICAN COURTROOM OR BENCH DETAIL, NEUTRAL, NO STOCK-PHOTO GAVELS
Table of contents
  1. Why this is no longer a story from abroad
  2. What the courts have actually decided
    1. The first referral to the Legal Practice Council
    2. The second judgment, and the uncomfortable detail
    3. The earlier warning nobody acted on
  3. Why AI invents cases
  4. What this means for your firm
    1. The duty stays with whoever signs
    2. Verification is not optional
    3. The tool changes what verification costs
  5. The standard to demand from any tool
  6. Where AILA stands on this

Read time · 6 minutes

If a judge asked your firm tomorrow where a particular citation came from, could anyone answer?

For two sets of South African practitioners, that question has already been asked in open court, and the answer was that the authority came from an AI tool and nobody had checked it. Both matters were referred to the Legal Practice Council. Neither firm intended to mislead anyone. That did not help them.

AILA is built by admitted attorneys, and this is the first thing we say to any firm considering AI: the risk is real, it is local, and it is manageable — but only if you understand precisely what went wrong in these matters and why the usual answer, "we'll just be careful", is not a control.

Why this is no longer a story from abroad

For two years the fabricated-citation problem was something that happened to American lawyers. Firms here read about it, winced, and carried on. That gap has closed. South African courts have now dealt with the same conduct under our rules, in our divisions, with referrals to our regulator.

The practical consequence is that a practitioner can no longer plead novelty. The risk is on the record, it has been reported on extensively by the profession, and a court is entitled to assume you knew about it.

What the courts have actually decided

IMAGE SLOT 2/3 — SECTION
SUGGESTED: BOUND LAW REPORTS OR SAFLII ON SCREEN, SHALLOW DEPTH OF FIELD

The first referral to the Legal Practice Council

In January 2025 the KwaZulu-Natal Division sat with an appeal in which the heads of argument cited nine authorities. When the judge went looking for them, seven did not exist, and one of the two that did was cited incorrectly. The court described the conduct as irresponsible and unprofessional, and referred the practitioners to the Legal Practice Council.

Two details matter more than the outcome. The fabrications were found by the judge, not by the firm. And when the junior involved was questioned, the account given to the court was unsatisfactory — which turned a research failure into a candour problem.

The second judgment, and the uncomfortable detail

In June 2025 the Gauteng Division dealt with the same problem in an urgent application. Two authorities in the heads of argument did not exist. Counsel accepted responsibility immediately, apologised without reservation, and made clear there was no intention to mislead. The court accepted all of that — and still referred the matter to the Legal Practice Council.

Here is the detail every firm shopping for legal AI should sit with. The fabricated authorities in that matter did not come from a general chatbot. They came from a paid subscription research tool marketed as being trained on South African law.

Buying something described as "legal AI" is not, by itself, a control. What protects a firm is whether the tool shows you the source it relied on, and what it does when it has none.

The earlier warning nobody acted on

There was a South African matter involving AI-generated authorities as early as 2023. The court took a more forgiving view then, finding no intention to mislead. Read the three matters together and the trajectory is obvious: the same conduct, treated more seriously each time. A firm relying on the tolerance shown in 2023 is relying on a position the courts have since moved away from.

Why AI invents cases

General AI models are built to produce plausible text. That is the whole function. Ask one for authority on a point of law and it produces something that looks exactly like authority — a case name, a citation, a persuasive summary. Whether that case exists is a separate question, and the model does not ask it.

This is not a defect awaiting a patch. It is what the technology is. A model with no source to draw on will produce something anyway, because producing something is what it does. The word "hallucination" makes it sound like a malfunction. It is closer to the opposite: the system working exactly as designed, on a task it was never designed for.

What this means for your firm

The duty stays with whoever signs

No court has accepted, or will accept, that the tool said so. The practitioner who puts their name to the papers answers for what is in them. This holds whether the research was done by a candidate attorney, a subscription service, or a model. Delegation moves the work; it does not move the duty.

Verification is not optional

Every authority that comes out of any AI tool is checked against the actual report before it goes near a court or a client. Not the summary the tool produced — the report. In both of the 2025 matters, the fabrications would have been caught by one person spending ten minutes on SAFLII.

The tool changes what verification costs

This is where the choice of tool does real work. A tool that shows you the passage it relied on, with a link to the source, can be verified in seconds — which means verification actually happens. A tool that produces confident prose with no visible source makes verification a separate research project, which means it gets skipped at 11pm on the night before filing.

Firms tend to treat this as a features question. It is a compliance question. The design of the tool determines whether your verification policy survives contact with a deadline.

The standard to demand from any tool

Two tests, and they are not difficult to apply in a demo:

  • It cites what it actually relied on. Not a plausible-looking citation attached after the fact — the specific source the answer was drawn from, visible and checkable.
  • It says when it does not know. When there is no authority for a point, the tool says so, rather than inventing a case or reaching for a foreign one that does not apply here.

The second test is the one most tools fail. Admitting ignorance is not what a general language model is built to do. It is what a legal tool must do, and you can check it in five minutes: ask about something narrow and South African that you already know is unsettled, and watch what comes back.

Where AILA stands on this

AILA is grounded in your firm's own documents and cites what it draws on, so verification is a click rather than a search. Where it has no basis for an answer, it says so. We would rather return less and have you trust what comes back.

We are not going to tell you this removes the duty to check. It does not, and any vendor who implies otherwise is selling you a problem. What it does is make checking cheap enough that it actually gets done.

See how it answers when it does not know

Bring your own hard question to a demo — ideally a narrow South African point you already know the answer to. The founders run the calls themselves.

Book a demo Compare with ChatGPT and Copilot

FOUNDER REVIEW REQUIRED BEFORE PUBLISH · CASE FACTS VERIFIED AGAINST PUBLISHED REPORTING — CONFIRM AGAINST THE JUDGMENTS AND DECIDE WHETHER TO NAME PARTIES, CITATIONS AND THE THIRD-PARTY TOOL

← BLOG

POPIA and AI: what a law firm actually has to answer for

IMAGE SLOT 1/3 — FEATURE
SUGGESTED: SERVER ROOM OR FILING DETAIL, SOUTH AFRICAN CONTEXT, NO PADLOCK CLICHÉS
Table of contents
  1. What changes when AI enters the workflow
  2. Your firm is the responsible party
    1. Most client information is special personal information
    2. The duty does not transfer to the vendor
  3. What happens when someone pastes client text into a consumer tool
    1. It leaves the firm's control
    2. It probably crosses a border
    3. There is no operator agreement
  4. The four questions to answer before adopting any tool
  5. Putting the answers into procurement
  6. How AILA answers them

Read time · 6 minutes

Most firms know POPIA applies to them. Fewer have worked out what it requires once AI tools are in the building.

The gap is not usually negligence. It is that AI adoption in law firms rarely goes through procurement. Nobody signs anything. An associate opens a browser tab, and a set of obligations that took the firm two years to build a compliance programme around is quietly in play.

This piece sets out what your firm has to be able to answer, in plain language, and what to get in writing before anyone uses a tool on client work.

What changes when AI enters the workflow

Nothing about POPIA changes. What changes is the number of places client information can travel to without a decision being made about it.

A firm's compliance programme is generally built around known systems: the practice management platform, the document store, the email tenant. Each was chosen, contracted for, and documented. A consumer AI tool is none of those things, and it can process the same information within thirty seconds of somebody deciding to try it.

Your firm is the responsible party

Most client information is special personal information

Client files hold personal information by definition, and a substantial part of it falls into POPIA's special categories: health, biometrics, religious or philosophical beliefs, trade union membership, race, sexual orientation, and criminal behaviour. Family law, employment, medical negligence and criminal defence practices work with special personal information constantly.

The processing conditions are stricter for that category, and the consequences of getting it wrong are correspondingly heavier.

The duty does not transfer to the vendor

The firm decides why and how client information is processed. That makes the firm the responsible party. A vendor that processes on the firm's behalf is an operator, and an operator relationship has to be governed by a written agreement with specific terms in it.

What a firm cannot do is treat the vendor relationship as a way of moving the obligation. The Information Regulator asks the firm. The client asks the firm. The obligation stays where it started.

What happens when someone pastes client text into a consumer tool

IMAGE SLOT 2/3 — SECTION
SUGGESTED: LAPTOP AT NIGHT, DOCUMENT ON SCREEN, DELIBERATELY ORDINARY

Three things happen, usually without anybody deciding them.

It leaves the firm's control

Once submitted, the firm cannot say with certainty what was retained, for how long, or who inside the provider could see it. The firm has also lost the ability to answer a client who asks where their information went.

It probably crosses a border

Most major AI providers process outside South Africa. Section 72 sets conditions for transferring personal information across borders, and those conditions have to be satisfied before the transfer, not reconstructed afterwards.

There is no operator agreement

Consumer AI products are governed by standard terms of service, not by an operator agreement negotiated with your firm. There is no processing instruction, no confidentiality undertaking to the firm, and no security commitment your information officer can point to.

With consumer tools, the honest answer to all three is either "we don't know" or "we have nothing in place". Neither is a position a responsible party wants to be in when the question is put formally.

The four questions to answer before adopting any tool

  • Where is the data processed and stored? A country, in writing. "The cloud" is not an answer, and neither is a region name with no contractual force.
  • Is there a written agreement covering processing and training? Specifically: does the provider use your content to train models, and is the answer in the contract rather than in a marketing page?
  • Can the firm serve a subject access request? If a data subject asks what you held, who accessed it and when, the answer has to come from a record, not from recollection.
  • What happens when the engagement ends? Deletion, export, retention periods — and who confirms it happened.

If a provider cannot answer these in writing, the firm cannot answer them either. And the firm is the one POPIA asks.

Putting the answers into procurement

Answering the four questions once is not a control. Making them a gate is. In practice that means a short, boring set of steps that a firm of any size can run:

  • No AI tool touches client work until the four answers exist in writing and are filed with the information officer.
  • The operator agreement is signed before the pilot, not after the roll-out.
  • The sub-processor list is reviewed, because your provider's providers are in your chain whether or not you have looked at them.
  • The tool appears on the firm's processing record alongside every other system.
  • Someone owns it — usually the information officer — and the review has a date on it.

Firms that do this find the decision gets easier, not harder. Most vendors fail at the first step, which shortens the shortlist considerably.

How AILA answers them

Matter data and documents are stored in South Africa. The AI provider is contracted not to train on your content. Every access is logged, so a subject access request is answered from the record rather than from memory. Our sub-processors are published, so your information officer can review the whole chain before you sign anything.

The full detail, including the parts a compliance review will want to interrogate, is in our security brief.

Give this to your information officer

The security brief is written to be read by the person who has to sign off, not by the person who wants the tool.

Read the security brief Book a demo

FOUNDER REVIEW REQUIRED BEFORE PUBLISH · THIS POST IS CLOSEST TO LEGAL ADVICE — CHECK EVERY CHARACTERISATION OF POPIA · SECTION 72 REFERENCE AND DATA RESIDENCY CLAIM BOTH REQUIRE SIGN-OFF

← BLOG

Your precedents are an asset. Your folder structure is not.

IMAGE SLOT 1/3 — FEATURE
SUGGESTED: ARCHIVE SHELVING OR LEVER-ARCH SPINES, EDITORIAL RATHER THAN CORPORATE
Table of contents
  1. The asset nobody puts on the balance sheet
  2. How knowledge value decays
    1. People leave and the map leaves with them
    2. Versions multiply
    3. Findability fails
    4. Context strips away
  3. What the decay costs, in hours
  4. What managed knowledge looks like
    1. Provenance
    2. Access control that travels
    3. Plain-language retrieval
  5. Where a firm should start
  6. How AILA's Knowledge Repository handles it

Read time · 5 minutes

Ask a firm what its most valuable asset is and you will hear "our people" or "our client relationships". Both true. There is a third that nobody lists.

It is the accumulated knowledge sitting in the firm's own documents. Every negotiated clause. Every opinion. Every agreement that survived scrutiny on the other side. Decades of judgement, already written down.

Then ask where that asset lives. The answer is usually a shared drive, organised by whoever set it up years ago, navigable by the three people who remember where things are.

The asset nobody puts on the balance sheet

A precedent bank is not valuable because it contains documents. It is valuable because it contains decisions — the particular wording that a specific counterparty accepted, the carve-out that made a deal close, the formulation that has never been litigated in fifteen years of use.

That value is fragile in a way that physical assets are not. Nothing on the drive degrades. What degrades is the firm's ability to find the right thing and know why it was right.

How knowledge value decays

IMAGE SLOT 2/3 — SECTION
SUGGESTED: NESTED FOLDER TREE ON SCREEN, DELIBERATELY UNGLAMOROUS

People leave and the map leaves with them

The senior associate who knew that the best restraint wording sits in a 2022 matter folder takes that knowledge with her. Nothing was lost from the drive. Everything was lost from the firm.

Versions multiply

Six files with similar names, three of them marked final. Nobody is certain which one was signed. So the safest option becomes drafting from scratch, which produces a seventh.

Findability fails

Folders answer the question "where did we file it?". They have never answered the question a lawyer actually asks, which is "what have we used before for something like this?". Those are different questions, and a hierarchy can only serve the first.

Context strips away

A clause without its matter, author and outcome is just text. You cannot tell whether it survived scrutiny or caused the dispute. Reusing it is an act of faith.

What the decay costs, in hours

None of this appears in the accounts. It appears in time:

  • The precedent hunt that precedes every substantial draft.
  • Re-drafting clauses the firm has already perfected, because nobody could find the perfected version.
  • The question asked down the corridor, because the system cannot answer it and a colleague can.
  • Partner time spent as a lookup service — the single most expensive search function a firm can operate.
  • Onboarding that takes a year, because a year is roughly how long it takes to learn where things are.

Firms absorb these as the cost of practice. They are actually the cost of an unmanaged asset.

What managed knowledge looks like

Three properties, whatever tool you use to get them.

Provenance

Every document carries its own source: which matter, who drafted it, when, and what happened to it. Provenance is what turns a file into evidence of a decision.

Access control that travels

Privacy attaches to the document and moves with it, including into anything derived from it. A restricted precedent must not surface for the wrong person because it was copied into a general folder two years ago.

Plain-language retrieval

The system answers the question you would put to a colleague — "what have we used for a restraint in a services sale?" — rather than requiring the filename you happen to remember. This is the property that folders structurally cannot provide, and it is the one that changes daily practice most.

Where a firm should start

Not with a two-year taxonomy project. Firms that begin by redesigning the folder structure generally end where they started, with a tidier version of the same problem. A more realistic sequence:

  • Pick one practice area and one document type — the one your people draft most often.
  • Identify the versions that are actually authoritative, and say so explicitly. This is judgement work and it needs a senior person.
  • Attach context to each: matter, author, date, outcome, and any known limitation.
  • Make the set searchable in plain language, and see whether people use it.
  • Only then widen the scope.

The point of starting narrow is that it produces evidence. If a partner stops being asked the same question three times a week, the model works and you can extend it. If not, you have learned that cheaply.

How AILA's Knowledge Repository handles it

The repository holds the firm's own material with provenance attached, applies the firm's privacy levels to every result, and answers questions the way a colleague would rather than the way a search box does. A new associate can be handed the firm's memory on their first day instead of assembling it over a year.

We built it because we spent years being the search engine ourselves. Here is how it works.

Start with one practice area

Onboarding brings your templates and precedents in as they are. No taxonomy project, no re-filing exercise.

Book a demo See the repository
← BLOG

What an ethical wall actually has to do

IMAGE SLOT 1/3 — FEATURE
SUGGESTED: PARTITION, GLASS DIVIDER OR OFFICE THRESHOLD — ARCHITECTURAL, NOT LITERAL
Table of contents
  1. What most firms raise is not a wall
  2. The difference between a policy and enforcement
    1. Where walls actually leak
    2. What AI changed
  3. Three tests for a real wall
    1. It holds on every surface at once
    2. Exclusion means invisibility
    3. The wall leaves evidence
  4. Why enforcement has to live in the data
  5. A checklist for your next conflict
  6. How AILA raises walls

Read time · 5 minutes

Every firm has raised an ethical wall. Very few have raised one that would survive being tested.

The usual version looks like this. An email goes out naming the walled matter and the excluded people. A folder has its permissions changed. Everyone undertakes not to discuss it in the corridor or the lift.

That is a policy. It is a reasonable and well-intentioned policy. It is not a wall, and the distinction becomes very sharp at the moment somebody asks you to prove the wall held.

What most firms raise is not a wall

The test is simple: if an excluded person wanted to see the walled material, or came across it by accident, what would stop them? If the answer is "they know they shouldn't", the firm has a rule rather than a control.

Rules depend on every person remembering, every time, under pressure. Controls do not depend on anything.

The difference between a policy and enforcement

A policy asks people to behave. Enforcement makes the wrong behaviour impossible. The gap between the two is precisely where walls fail — and almost never through bad faith.

Where walls actually leak

  • A document title appearing in a search result, because the search index was never told about the wall.
  • A matter name in a shared calendar entry or a time-recording narrative.
  • An email thread forwarded one hop further than the sender intended.
  • A firm-wide report, WIP list or billing summary that includes the walled matter without anyone considering it.
  • A document copied into a general precedent folder, stripped of the restriction that applied to it.

Every one of these is somebody doing their ordinary job. That is the point. A wall that only holds when people are paying attention is not a wall.

What AI changed

IMAGE SLOT 2/3 — SECTION
SUGGESTED: SEARCH RESULT LIST WITH TITLES BLURRED — TITLES-AS-INFORMATION POINT

If a firm's AI tool can read the whole document store, it can disclose the whole document store — helpfully, in fluent summaries, to anyone who asks a well-framed question. It does not need to be asked about the walled matter directly. It only needs to be asked about something adjacent.

An AI assistant is the most efficient leak a firm has ever installed, because it synthesises across everything it can see and answers in confident prose rather than returning a file the reader might not open.

This is the reason ethical walls have moved from a housekeeping question to a procurement question. Any tool that reads across the firm's material inherits the firm's confidentiality obligations, and either enforces them or defeats them.

Three tests for a real wall

It holds on every surface at once

Search, drafting, document lists, email summaries, transcripts, reports, AI answers. A wall that covers the folder but not the search index is a wall with a door in it. The relevant question for any system is not "can we restrict the folder?" but "which surfaces read this data, and does the restriction apply to all of them?"

Exclusion means invisibility

An excluded person should not see a redacted result or a locked file. They should see nothing at all. A title is information. So is the existence of a matter, its size, its team, and the fact that access was denied. "You do not have permission to view this document" tells the reader that the document exists — which, in a contested transaction, may be the only thing they needed to know.

The wall leaves evidence

Who raised it, when, over which matter, covering whom, and every attempted access since. When a court, a client or the Legal Practice Council asks whether the wall held, "we sent an email to the firm" is not an answer. A log is an answer. The absence of a log means the firm's position rests on the recollection of the people with the most to lose from remembering incorrectly.

Why enforcement has to live in the data

A wall enforced in the interface is bypassed by anything that reads the data underneath — a report, an export, a search index, an integration, an AI assistant. In practice that is now most of the firm's software.

A wall enforced in the data itself holds everywhere by default, including against tools nobody thought about when the wall went up. This is the single most important architectural question to ask a vendor, and it is usually answered in the first thirty seconds: if the response involves file permissions or folder access, the wall is in the wrong layer.

A checklist for your next conflict

  • The wall is raised in the system before the email goes out, not after.
  • Excluded users see no trace: no titles, no counts, no permission errors.
  • Every surface is covered, and someone has listed the surfaces rather than assuming.
  • AI and search are explicitly in scope, including anything derived from walled material.
  • The log is exportable, because a log you cannot produce is not evidence.
  • Removal is deliberate and recorded, with a date and a person attached.

How AILA raises walls

Walls are raised per matter, enforced on every query rather than every folder, and logged from the moment they go up. Because the restriction lives with the matter, it applies to search, drafting, summaries and AI answers without anybody configuring each one. An excluded user sees nothing — not a locked item, not a title.

The architecture, including how privilege is modelled and what the audit log records, is set out in the security brief.

Test the wall yourself

On a demo we will raise a wall and then let you try to find the matter from an excluded account. It is a more useful five minutes than any slide.

Book a demo Read the security brief
← BLOG

The associate is already using ChatGPT. Now what?

IMAGE SLOT 1/3 — FEATURE
SUGGESTED: LATE-NIGHT DESK, ONE LAMP, PHONE FACE-UP BESIDE LAPTOP
Table of contents
  1. Start from what is actually happening
  2. Why bans fail
  3. A policy people will actually follow
    1. One: name what is allowed, honestly
    2. Two: name the hard line
    3. Three: give people a sanctioned path
    4. Four: verify and review
  4. What to put in the document
  5. Who owns it
  6. The honest close

Read time · 5 minutes

Here is the fact most firm AI policies are written to avoid: your people are already using it.

The associate drafting at eleven at night is using it. The candidate attorney summarising a judgment is using it. If the firm has banned it, they are using it on their phones, where the firm has no visibility at all.

So the useful question is not how to stop AI use. It is how to make the use that is already happening safe, visible and defensible.

Start from what is actually happening

Before writing anything, find out what people are doing. Not through a formal audit that guarantees defensive answers — through a conversation in which nobody is in trouble.

Firms that do this are usually surprised twice. First by how widespread the use is. Second by how sensible most of it is: understanding an unfamiliar area, restructuring an argument, tightening prose. The genuinely risky use is a narrow slice, and it is easier to address once you can see the whole picture.

Why bans fail

A ban that nobody follows is worse than no policy at all. It drives use underground, where the firm cannot see it, guide it, or catch the mistakes before they reach a client. It also teaches people that firm policy is aspirational, which is an expensive lesson to teach.

A rule that only says "no" loses to the deadline every time. The deadline is real and immediate; the rule is neither.

There is a second cost. A ban tells your best juniors that the firm would rather not think about the thing they can see reshaping their profession. Some of them will draw conclusions about where to work.

A policy people will actually follow

IMAGE SLOT 2/3 — SECTION
SUGGESTED: SHORT PRINTED POLICY DOCUMENT ON A DESK — ONE PAGE, NOT A MANUAL

One: name what is allowed, honestly

Learning an unfamiliar area. General research the person will independently verify. Internal drafts containing no client information. Improving the structure and clarity of something the lawyer wrote.

General AI is genuinely good at these, and pretending otherwise costs the policy its credibility with the people who have to follow it. A policy that describes a tool your associates use daily as useless is a policy they will stop reading at paragraph two.

Two: name the hard line

No client information, no matter content, no privileged material in any consumer AI tool. Not anonymised. Not "just this once". Not in a prompt that only quotes a paragraph.

One line, no exceptions, and explain why rather than simply asserting it: the firm cannot say where that information goes, cannot produce an operator agreement, and cannot answer the client who asks. People follow rules they understand.

Three: give people a sanctioned path

If the firm provides a tool that is safe for client work, the consumer tools stop being the only option at eleven at night. This is the part most firms skip, and it is the part that determines whether the rest of the policy holds.

A policy with a prohibition and no alternative is not a policy. It is a statement of preference.

Four: verify and review

Every citation from any AI source is checked against the actual report before it goes to a court or a client. South African courts have already dealt with what happens otherwise, and referred the practitioners involved to the Legal Practice Council — we wrote about those judgments here.

And the policy itself gets revisited on a fixed date, at least twice a year. This field does not sit still, and a policy written eighteen months ago is describing a different set of tools.

What to put in the document

Keep it to one page. Longer documents get filed rather than read.

  • The permitted uses, listed plainly.
  • The prohibition, in a single sentence, with the reason attached.
  • The approved tool or tools, named, with a note on what each is for.
  • The verification rule, applying to every AI source without exception.
  • What to do after a mistake — reported, not concealed. A policy that punishes disclosure produces concealment.
  • Who to ask, by name.
  • The review date.

Who owns it

Someone senior enough that the policy carries weight, and close enough to daily practice to notice when it stops matching reality. In most firms this is a partner working with the information officer.

What does not work is drafting it once, circulating it, and treating the matter as closed. The associate who finds a genuinely useful new tool in November needs somebody to ask, or they will simply decide for themselves.

The honest close

The firms that handle this well will not be the ones with the strictest bans. They will be the ones that separated clearly what general AI is for from what client work requires — and then gave their people both.

The second half is what we build. Here is the comparison, including the parts where ChatGPT wins.

The sanctioned path

AILA is built for the client work that consumer tools cannot safely touch. Your people can keep using ChatGPT for everything else — and should.

Book a demo See the comparison
← BLOG

How to evaluate legal AI: ten questions to ask any vendor — including us

IMAGE SLOT 1/3 — FEATURE
SUGGESTED: TWO PEOPLE ACROSS A TABLE, ONE SCREEN, EVALUATION RATHER THAN SALES
Table of contents
  1. Why we published a checklist we do not score full marks on
  2. Data and contract
  3. Grounding and accuracy
  4. Confidentiality and privilege
  5. Evidence and supply chain
  6. The commercial questions
  7. How to run the evaluation
  8. Bring the list to the demo

Read time · 6 minutes

Every legal AI vendor will tell you their product is secure, accurate and built for lawyers. These are the ten questions that test whether it is.

Ask them of every vendor you meet. Ask them of us. We have marked the two where our own answer is imperfect, because a checklist that flatters its author is not a checklist.

Two practical notes before you start. Ask for answers in writing, because a demo-room assurance is not a contractual term. And ask the same question twice, once to the salesperson and once to whoever built the thing.

Why we published a checklist we do not score full marks on

Because the firms we want to work with are the ones that ask hard questions, and because a vendor's response to question nine tells you considerably more than its answer to question one. Anyone can prepare a good answer about data residency. Very few vendors will tell you what they cannot yet do.

Data and contract

1. Where is our data stored and processed?

The answer should be a place, in writing, in the contract. "The cloud" is not a place. A region name in a marketing page is not a commitment. Ask separately about storage and processing, because they are not always in the same country, and ask where backups sit.

2. Do you train on our content, and is that in the contract?

A verbal assurance is not a data-processing term. Ask whether the vendor's own AI providers train on content passed through to them, because that is a different question with a different answer. Ask what happens to your data at the end of the engagement, and who confirms deletion.

Grounding and accuracy

3. What grounds the answers — our documents or the internet?

A tool grounded in your precedents drafts your agreements. A tool grounded in the open internet drafts everybody's, in a house style that is not yours, with no way to tell whether the source survived scrutiny.

7. What does the tool do when it does not know?

The only safe answer is that it says so. South African courts have already dealt with practitioners who filed authorities that did not exist — in one 2025 matter, the fabrications came from a paid subscription tool marketed as trained on South African law. Being sold as a legal product is not a guarantee of legal behaviour.

Test this rather than asking about it. Bring a narrow South African point you already know is unsettled, and see whether the tool admits the gap or fills it.

Confidentiality and privilege

4. How is privilege modelled?

If the answer is "file permissions", privilege is not modelled. Privilege attaches to the matter and should travel with everything derived from it — summaries, extracts, drafts, search results.

5. How are ethical walls enforced, and can an excluded user see even a title?

A title is information. So is a permission error, which confirms the document exists. The right answer is that an excluded user sees nothing. Ask which surfaces the wall covers, and make the vendor list them.

Evidence and supply chain

6. What does the audit log record, and can we export it?

Views, edits, exports and AI generations, each with user, matter and timestamp. If you cannot export it, it is not your record — and a record you cannot produce is no use in a regulatory enquiry.

8. Who are your sub-processors?

A published list your information officer can review before signing. If the list is confidential, the compliance chain has a hole in it that your firm, not the vendor, will have to answer for.

The commercial questions

IMAGE SLOT 2/3 — SECTION
SUGGESTED: CONTRACT SIGNATURE PAGE, CROPPED — NO HANDSHAKES

9. How many firms use you, and can we speak to one?

Our honest answer: AILA is new, and we are onboarding our founding firms now. We will not invent references. You would check, you would catch us, and you would be right to. What we offer instead is the founders on the demo call, direct access during onboarding, and founding-firm terms that reflect the position.

10. What certifications do you hold?

Our honest answer: our ISO 27001 certification is not complete, and you will notice we do not display the badge. Ask every vendor to show you the certificate itself, with its scope and dates, rather than the logo. Scope is where certification claims usually fall apart — a certificate covering a corporate head office says nothing about the platform your matters sit in.

How to run the evaluation

  • Send the ten questions before the demo. What comes back in writing is the real answer.
  • Put your information officer in the room for questions one, two, six and eight.
  • Bring your own documents and your own hard question. A scripted demo tests the script.
  • Ask each vendor what their product is bad at. The ones with an answer are the ones to shortlist.
  • Compare the written answers side by side, not the demos. Demos are designed to be memorable; contracts are what you will actually live with.

Bring the list to the demo

Bring it to ours. We would rather be tested on these ten questions than trusted on a claim, and we would rather lose a firm on question ten than win one by being vague about it.

Ten questions, founders on the call

Send the list ahead and we will answer it in writing before we demonstrate anything.

Book a demo Read the security brief

FOUNDER REVIEW REQUIRED BEFORE PUBLISH · CONFIRM ISO 27001 AND FOUNDING-FIRM STATEMENTS REMAIN ACCURATE AT PUBLISH DATE