Tell it what you need
Write the brief in your own words. AILA attaches the matter file, your playbook, and the precedents that fit.
Legal AI for South African law firms
Chatbots answer questions. AILA runs matters — from first instruction to final signature. It drafts in Word on your firm's own precedents. It knows who may see what. And it keeps the record to prove it.
What is AILA?
AILA is legal AI software for South African law firms. One system covers matters, drafting in Microsoft Word, a searchable knowledge repository, contract review and e-signing. It works from your firm's own precedents — not the internet's. Your data stays in South Africa, in line with POPIA and Legal Practice Council rules.
It is built by two admitted attorneys, on an engineering team that has been shipping South African software since 2012. Read our story →
Why AILA?
You know the matter file. AILA is what it should have become. Instruction, research, drafting, review, signature and archive hang off one spine — instead of getting lost in inboxes and shared drives. Nothing goes missing. Nothing walks out the door.
Drafting happens in Word. Email happens in Outlook. AILA lives inside both as a side panel. No new tool to learn. No copying between systems. And no privileged client text pasted into a browser.
POPIA duties, Legal Practice Council rules and ethical walls are built into the data itself — not into a policy nobody reads. Your data stays in South Africa. Every access is logged. Every log can be produced.
What AILA does
One file per matter: parties, documents, emails, transcripts, tasks and versions. Privacy levels decide who sees what — and enforce it.
Write a brief in plain words. AILA drafts on your templates and your precedents. Hard clauses come back to you as decisions, not surprises.
Ask the firm what it already knows. Every template, clause, opinion and signed agreement — searchable, with its source attached.
Findings ranked by risk, checked against your firm's own positions. Each one jumps to the clause it came from.
AILA watches the eTenders portal, pulls out the requirements, and builds the compliance pack from documents you already hold.
Send, track and file signed agreements without leaving the matter. The signed version goes straight into the repository.
How drafting works
Write the brief in your own words. AILA attaches the matter file, your playbook, and the precedents that fit.
Contested clauses return as decision cards: the wording, a recommendation, the reasons, and other options from your clause library. Usually five to fifteen per agreement.
AILA populates the document inside Word, with every decision recorded against the matter. Ready for your review — not instead of it.
Bring one template and one live matter. Forty-five minutes with the founders. No slides.
Frequently Asked Questions
Security and compliance
A firm cannot use a tool that makes confidentiality unclear. AILA is built so the question "who can see this?" always has a clear answer — and so the answer is enforced in the data itself, not just on the screen.
This page is the security brief. It is written so your firm's information officer can hold us to it.
Every matter records its lawful basis when it opens. A subject access request is answered from the audit log, not from memory: what was held, who accessed it, when, and on what basis.
Retention rules apply to documents, drafts and transcripts alike. When a retention period ends, the derived material goes with the source.
Conflict checks run when a matter opens, against the parties already in the system — not a manual register.
File-retention periods follow the applicable rules by default. Trust-account material is kept apart from general matter content by design.
In the data itself, so it holds everywhere at once: repository search, drafting, Outlook summaries, transcripts. An excluded user does not see a redacted result. They see nothing — not even a title.
The wall event itself is logged: who raised it, and when. A wall you can defend in an audit is a wall that leaves evidence.
MeetingBot transcribes on the machine in the room. Audio is not uploaded and does not pass through a third-party service.
The transcript takes on the matter's privacy level the moment it attaches.
Documents and matter data are stored in South Africa. The AI provider is contracted not to train on your content. No document leaves the tenant for any reason other than answering the request that asked for it.
Our sub-processor list is published below and updated when it changes.
INSERT · SUB-PROCESSOR LIST — REQUIRED BEFORE THIS PAGE SHIPS
Every view, edit, export, wall change and AI generation — with the user, the matter and the time. The log is exportable.
When a client, an insurer or the LPC asks what happened on a matter, the answer is a query, not an investigation.
Pricing
We do not publish a rate card. Here is why, plainly: firms differ in size, in how much data needs to move over, and in what they need built. A founding-firm arrangement is priced as one. What we can tell you is exactly how the model works.
Every seat includes all four tools: the web app, the Word add-in, the Outlook add-in and MeetingBot. It includes the Knowledge Repository, matters, contract review and e-signing. Onboarding is part of the deal, not a fee that shows up later. There are no per-document fees. A firm that drafts more does not pay more.
Three things. How many users. How much data comes in at onboarding — templates, precedents and past matters. And whether your firm needs something built that does not exist yet. That last one is a conversation, not a surcharge.
The honest comparison is not other software. It is the hours your firm spends finding its own knowledge: the precedent hunt before a draft, the re-drafting of clauses the firm already perfected, the version digging before a signature. AILA's cost sits against that time, at your charge-out rates. We will do that arithmetic with you — with your numbers, not ours.
Early firms shape the roadmap and work directly with the founders. Founding-firm terms reflect that.
Already using ChatGPT or Copilot?
ChatGPT, Copilot and Claude are good general tools, and we say so. What they do not have: a matter file, privacy levels, your precedents, or a record of who saw what.
So let's start with what the general tools get right. For learning a new area, for research you will verify, for internal drafts that are not privileged — they are useful. Your associates are already using them, policy or not.
The question is not whether general AI is good. It is whether a general tool is a place to do client work. It is not. Here are five reasons.
This is the sharpest version of the question, because Copilot lives in Word — exactly where AILA drafts. The difference is not location. It is architecture. Copilot can see your firm's documents through Microsoft 365. It does not know they are matters.
There is no matter file, no privacy level beyond file permissions, no playbook, no clause library, no conflict checks, no decision cards. Copilot knows your files exist. AILA knows what they are, which matter they belong to, who may see them, and which clause in them survived scrutiny last time. Same building. Only one has a legal system in it.
To be precise, because you will check: the paid business tiers — ChatGPT's business plans, Claude's commercial plans, Copilot for Microsoft 365 — do not train on customer data by default. They are much better than a free personal account.
If your comparison is "free ChatGPT vs AILA", you are comparing the wrong things. Even at their best, the general tools have no matter model, no privilege architecture, no South African legal grounding, no citation discipline, and no audit trail built for a firm's duties. The gap is not the privacy tier. It is everything above.
Everything above is about capability. This last part is about duty, and it is the reason a general tool can never be the answer for client work.
POPIA by design. Ethical walls enforced in the data, not just on the screen. Every access logged, and every log producible. Your documents stored in South Africa, with an AI provider contracted not to train on your content.
The full security brief is written so your firm's information officer can hold us to it. Read the security brief →
Keep the general tools for what they do well: learning, exploring, non-client work. Bring client work to a system built for it. If you would rather see the difference than read about it, bring a template and a live matter.
Book a demoOur story
AILA is built by attorneys who lived the problem, on top of an engineering team that has been shipping South African software for fourteen years. Here is where both halves come from.
HashTopic (Pty) Ltd has been building software in South Africa since 2012. Web platforms, intranets, document systems and AI tools — for universities, science councils and public institutions. Fourteen years of shipping systems that people rely on every day. See HashTopic's work →
This matters more than it might seem. Plenty of legal AI is sold by companies younger than the problem they claim to solve. AILA is a new product, but not a new company: the engineering behind it has a track record you can go and check.
HashTopic is based in Cape Town. AILA is built there, hosted in South Africa, and supported by the people who wrote it.
Both founders are admitted attorneys who practised at Big 5 firms. They did not research the problems AILA solves. They lived them, from articles onward: the precedent nobody could find, the clause re-drafted for the fourth time, the institutional knowledge that left with a colleague.
When they started articles, AI was not part of legal practice at all. They watched it arrive. They watched what it did to firms abroad, what it got right, and where it went badly wrong. That is a useful seat to have had: they know what the international tools do well, and they know exactly where those tools stop making sense inside a South African firm.
AILA is built to close that gap — international standards, South African realities. POPIA. Legal Practice Council rules. The eTenders portal. Citation discipline against South African authority. The things a global product will never prioritise, because it does not have to.
Serious legal AI has been priced and packaged for the largest firms. Everyone else has been offered a chatbot and told to make do. We think that is the wrong split.
A twelve-attorney firm in Durban carries the same duty of confidentiality, the same POPIA obligations and the same client expectations as a firm of three hundred. It just does not have an innovation department to fund the tools.
We build for small and medium South African practices — the firms that do most of the country's legal work. Excellent tools should be within their reach. That is the whole point.
AILA is new, and we say so. We are onboarding our founding firms now. They work directly with the founders, and what they need next is what gets built next — a workflow, an integration, a document type. No ticket queue. No committee.
Firms that work with us work with the people who build the product. That is a deliberate constraint, and it is the reason founding firms get the access they do.
Cape Town, South Africa
INSERT · COMPANY REGISTRATION NUMBER
INSERT · COMPANY LINKEDIN URL (WHEN LIVE)
INSERT · CONTACT EMAIL
Blog
Written by admitted attorneys. No hype, no jargon — what the law and the tools actually require of a South African firm.
AILA · WRITTEN BY ADMITTED ATTORNEYS · 4 AUGUST 2026 · AI Risk & Professional Duty
Read time · 6 minutes
If a judge asked your firm tomorrow where a particular citation came from, could anyone answer?
For two sets of South African practitioners, that question has already been asked in open court, and the answer was that the authority came from an AI tool and nobody had checked it. Both matters were referred to the Legal Practice Council. Neither firm intended to mislead anyone. That did not help them.
AILA is built by admitted attorneys, and this is the first thing we say to any firm considering AI: the risk is real, it is local, and it is manageable — but only if you understand precisely what went wrong in these matters and why the usual answer, "we'll just be careful", is not a control.
For two years the fabricated-citation problem was something that happened to American lawyers. Firms here read about it, winced, and carried on. That gap has closed. South African courts have now dealt with the same conduct under our rules, in our divisions, with referrals to our regulator.
The practical consequence is that a practitioner can no longer plead novelty. The risk is on the record, it has been reported on extensively by the profession, and a court is entitled to assume you knew about it.
In January 2025 the KwaZulu-Natal Division sat with an appeal in which the heads of argument cited nine authorities. When the judge went looking for them, seven did not exist, and one of the two that did was cited incorrectly. The court described the conduct as irresponsible and unprofessional, and referred the practitioners to the Legal Practice Council.
Two details matter more than the outcome. The fabrications were found by the judge, not by the firm. And when the junior involved was questioned, the account given to the court was unsatisfactory — which turned a research failure into a candour problem.
In June 2025 the Gauteng Division dealt with the same problem in an urgent application. Two authorities in the heads of argument did not exist. Counsel accepted responsibility immediately, apologised without reservation, and made clear there was no intention to mislead. The court accepted all of that — and still referred the matter to the Legal Practice Council.
Here is the detail every firm shopping for legal AI should sit with. The fabricated authorities in that matter did not come from a general chatbot. They came from a paid subscription research tool marketed as being trained on South African law.
Buying something described as "legal AI" is not, by itself, a control. What protects a firm is whether the tool shows you the source it relied on, and what it does when it has none.
There was a South African matter involving AI-generated authorities as early as 2023. The court took a more forgiving view then, finding no intention to mislead. Read the three matters together and the trajectory is obvious: the same conduct, treated more seriously each time. A firm relying on the tolerance shown in 2023 is relying on a position the courts have since moved away from.
General AI models are built to produce plausible text. That is the whole function. Ask one for authority on a point of law and it produces something that looks exactly like authority — a case name, a citation, a persuasive summary. Whether that case exists is a separate question, and the model does not ask it.
This is not a defect awaiting a patch. It is what the technology is. A model with no source to draw on will produce something anyway, because producing something is what it does. The word "hallucination" makes it sound like a malfunction. It is closer to the opposite: the system working exactly as designed, on a task it was never designed for.
No court has accepted, or will accept, that the tool said so. The practitioner who puts their name to the papers answers for what is in them. This holds whether the research was done by a candidate attorney, a subscription service, or a model. Delegation moves the work; it does not move the duty.
Every authority that comes out of any AI tool is checked against the actual report before it goes near a court or a client. Not the summary the tool produced — the report. In both of the 2025 matters, the fabrications would have been caught by one person spending ten minutes on SAFLII.
This is where the choice of tool does real work. A tool that shows you the passage it relied on, with a link to the source, can be verified in seconds — which means verification actually happens. A tool that produces confident prose with no visible source makes verification a separate research project, which means it gets skipped at 11pm on the night before filing.
Firms tend to treat this as a features question. It is a compliance question. The design of the tool determines whether your verification policy survives contact with a deadline.
Two tests, and they are not difficult to apply in a demo:
The second test is the one most tools fail. Admitting ignorance is not what a general language model is built to do. It is what a legal tool must do, and you can check it in five minutes: ask about something narrow and South African that you already know is unsettled, and watch what comes back.
AILA is grounded in your firm's own documents and cites what it draws on, so verification is a click rather than a search. Where it has no basis for an answer, it says so. We would rather return less and have you trust what comes back.
We are not going to tell you this removes the duty to check. It does not, and any vendor who implies otherwise is selling you a problem. What it does is make checking cheap enough that it actually gets done.
Bring your own hard question to a demo — ideally a narrow South African point you already know the answer to. The founders run the calls themselves.
Book a demo Compare with ChatGPT and CopilotFOUNDER REVIEW REQUIRED BEFORE PUBLISH · CASE FACTS VERIFIED AGAINST PUBLISHED REPORTING — CONFIRM AGAINST THE JUDGMENTS AND DECIDE WHETHER TO NAME PARTIES, CITATIONS AND THE THIRD-PARTY TOOL
AILA · WRITTEN BY ADMITTED ATTORNEYS · 11 AUGUST 2026 · POPIA & Compliance
Read time · 6 minutes
Most firms know POPIA applies to them. Fewer have worked out what it requires once AI tools are in the building.
The gap is not usually negligence. It is that AI adoption in law firms rarely goes through procurement. Nobody signs anything. An associate opens a browser tab, and a set of obligations that took the firm two years to build a compliance programme around is quietly in play.
This piece sets out what your firm has to be able to answer, in plain language, and what to get in writing before anyone uses a tool on client work.
Nothing about POPIA changes. What changes is the number of places client information can travel to without a decision being made about it.
A firm's compliance programme is generally built around known systems: the practice management platform, the document store, the email tenant. Each was chosen, contracted for, and documented. A consumer AI tool is none of those things, and it can process the same information within thirty seconds of somebody deciding to try it.
Client files hold personal information by definition, and a substantial part of it falls into POPIA's special categories: health, biometrics, religious or philosophical beliefs, trade union membership, race, sexual orientation, and criminal behaviour. Family law, employment, medical negligence and criminal defence practices work with special personal information constantly.
The processing conditions are stricter for that category, and the consequences of getting it wrong are correspondingly heavier.
The firm decides why and how client information is processed. That makes the firm the responsible party. A vendor that processes on the firm's behalf is an operator, and an operator relationship has to be governed by a written agreement with specific terms in it.
What a firm cannot do is treat the vendor relationship as a way of moving the obligation. The Information Regulator asks the firm. The client asks the firm. The obligation stays where it started.
Three things happen, usually without anybody deciding them.
Once submitted, the firm cannot say with certainty what was retained, for how long, or who inside the provider could see it. The firm has also lost the ability to answer a client who asks where their information went.
Most major AI providers process outside South Africa. Section 72 sets conditions for transferring personal information across borders, and those conditions have to be satisfied before the transfer, not reconstructed afterwards.
Consumer AI products are governed by standard terms of service, not by an operator agreement negotiated with your firm. There is no processing instruction, no confidentiality undertaking to the firm, and no security commitment your information officer can point to.
With consumer tools, the honest answer to all three is either "we don't know" or "we have nothing in place". Neither is a position a responsible party wants to be in when the question is put formally.
If a provider cannot answer these in writing, the firm cannot answer them either. And the firm is the one POPIA asks.
Answering the four questions once is not a control. Making them a gate is. In practice that means a short, boring set of steps that a firm of any size can run:
Firms that do this find the decision gets easier, not harder. Most vendors fail at the first step, which shortens the shortlist considerably.
Matter data and documents are stored in South Africa. The AI provider is contracted not to train on your content. Every access is logged, so a subject access request is answered from the record rather than from memory. Our sub-processors are published, so your information officer can review the whole chain before you sign anything.
The full detail, including the parts a compliance review will want to interrogate, is in our security brief.
The security brief is written to be read by the person who has to sign off, not by the person who wants the tool.
Read the security brief Book a demoFOUNDER REVIEW REQUIRED BEFORE PUBLISH · THIS POST IS CLOSEST TO LEGAL ADVICE — CHECK EVERY CHARACTERISATION OF POPIA · SECTION 72 REFERENCE AND DATA RESIDENCY CLAIM BOTH REQUIRE SIGN-OFF
AILA · WRITTEN BY ADMITTED ATTORNEYS · 18 AUGUST 2026 · Knowledge Management
Read time · 5 minutes
Ask a firm what its most valuable asset is and you will hear "our people" or "our client relationships". Both true. There is a third that nobody lists.
It is the accumulated knowledge sitting in the firm's own documents. Every negotiated clause. Every opinion. Every agreement that survived scrutiny on the other side. Decades of judgement, already written down.
Then ask where that asset lives. The answer is usually a shared drive, organised by whoever set it up years ago, navigable by the three people who remember where things are.
A precedent bank is not valuable because it contains documents. It is valuable because it contains decisions — the particular wording that a specific counterparty accepted, the carve-out that made a deal close, the formulation that has never been litigated in fifteen years of use.
That value is fragile in a way that physical assets are not. Nothing on the drive degrades. What degrades is the firm's ability to find the right thing and know why it was right.
The senior associate who knew that the best restraint wording sits in a 2022 matter folder takes that knowledge with her. Nothing was lost from the drive. Everything was lost from the firm.
Six files with similar names, three of them marked final. Nobody is certain which one was signed. So the safest option becomes drafting from scratch, which produces a seventh.
Folders answer the question "where did we file it?". They have never answered the question a lawyer actually asks, which is "what have we used before for something like this?". Those are different questions, and a hierarchy can only serve the first.
A clause without its matter, author and outcome is just text. You cannot tell whether it survived scrutiny or caused the dispute. Reusing it is an act of faith.
None of this appears in the accounts. It appears in time:
Firms absorb these as the cost of practice. They are actually the cost of an unmanaged asset.
Three properties, whatever tool you use to get them.
Every document carries its own source: which matter, who drafted it, when, and what happened to it. Provenance is what turns a file into evidence of a decision.
Privacy attaches to the document and moves with it, including into anything derived from it. A restricted precedent must not surface for the wrong person because it was copied into a general folder two years ago.
The system answers the question you would put to a colleague — "what have we used for a restraint in a services sale?" — rather than requiring the filename you happen to remember. This is the property that folders structurally cannot provide, and it is the one that changes daily practice most.
Not with a two-year taxonomy project. Firms that begin by redesigning the folder structure generally end where they started, with a tidier version of the same problem. A more realistic sequence:
The point of starting narrow is that it produces evidence. If a partner stops being asked the same question three times a week, the model works and you can extend it. If not, you have learned that cheaply.
The repository holds the firm's own material with provenance attached, applies the firm's privacy levels to every result, and answers questions the way a colleague would rather than the way a search box does. A new associate can be handed the firm's memory on their first day instead of assembling it over a year.
We built it because we spent years being the search engine ourselves. Here is how it works.
Onboarding brings your templates and precedents in as they are. No taxonomy project, no re-filing exercise.
Book a demo See the repositoryAILA · WRITTEN BY ADMITTED ATTORNEYS · 25 AUGUST 2026 · Confidentiality & Ethics
Read time · 5 minutes
Every firm has raised an ethical wall. Very few have raised one that would survive being tested.
The usual version looks like this. An email goes out naming the walled matter and the excluded people. A folder has its permissions changed. Everyone undertakes not to discuss it in the corridor or the lift.
That is a policy. It is a reasonable and well-intentioned policy. It is not a wall, and the distinction becomes very sharp at the moment somebody asks you to prove the wall held.
The test is simple: if an excluded person wanted to see the walled material, or came across it by accident, what would stop them? If the answer is "they know they shouldn't", the firm has a rule rather than a control.
Rules depend on every person remembering, every time, under pressure. Controls do not depend on anything.
A policy asks people to behave. Enforcement makes the wrong behaviour impossible. The gap between the two is precisely where walls fail — and almost never through bad faith.
Every one of these is somebody doing their ordinary job. That is the point. A wall that only holds when people are paying attention is not a wall.
If a firm's AI tool can read the whole document store, it can disclose the whole document store — helpfully, in fluent summaries, to anyone who asks a well-framed question. It does not need to be asked about the walled matter directly. It only needs to be asked about something adjacent.
An AI assistant is the most efficient leak a firm has ever installed, because it synthesises across everything it can see and answers in confident prose rather than returning a file the reader might not open.
This is the reason ethical walls have moved from a housekeeping question to a procurement question. Any tool that reads across the firm's material inherits the firm's confidentiality obligations, and either enforces them or defeats them.
Search, drafting, document lists, email summaries, transcripts, reports, AI answers. A wall that covers the folder but not the search index is a wall with a door in it. The relevant question for any system is not "can we restrict the folder?" but "which surfaces read this data, and does the restriction apply to all of them?"
An excluded person should not see a redacted result or a locked file. They should see nothing at all. A title is information. So is the existence of a matter, its size, its team, and the fact that access was denied. "You do not have permission to view this document" tells the reader that the document exists — which, in a contested transaction, may be the only thing they needed to know.
Who raised it, when, over which matter, covering whom, and every attempted access since. When a court, a client or the Legal Practice Council asks whether the wall held, "we sent an email to the firm" is not an answer. A log is an answer. The absence of a log means the firm's position rests on the recollection of the people with the most to lose from remembering incorrectly.
A wall enforced in the interface is bypassed by anything that reads the data underneath — a report, an export, a search index, an integration, an AI assistant. In practice that is now most of the firm's software.
A wall enforced in the data itself holds everywhere by default, including against tools nobody thought about when the wall went up. This is the single most important architectural question to ask a vendor, and it is usually answered in the first thirty seconds: if the response involves file permissions or folder access, the wall is in the wrong layer.
Walls are raised per matter, enforced on every query rather than every folder, and logged from the moment they go up. Because the restriction lives with the matter, it applies to search, drafting, summaries and AI answers without anybody configuring each one. An excluded user sees nothing — not a locked item, not a title.
The architecture, including how privilege is modelled and what the audit log records, is set out in the security brief.
On a demo we will raise a wall and then let you try to find the matter from an excluded account. It is a more useful five minutes than any slide.
Book a demo Read the security briefAILA · WRITTEN BY ADMITTED ATTORNEYS · 1 SEPTEMBER 2026 · Firm Policy
Read time · 5 minutes
Here is the fact most firm AI policies are written to avoid: your people are already using it.
The associate drafting at eleven at night is using it. The candidate attorney summarising a judgment is using it. If the firm has banned it, they are using it on their phones, where the firm has no visibility at all.
So the useful question is not how to stop AI use. It is how to make the use that is already happening safe, visible and defensible.
Before writing anything, find out what people are doing. Not through a formal audit that guarantees defensive answers — through a conversation in which nobody is in trouble.
Firms that do this are usually surprised twice. First by how widespread the use is. Second by how sensible most of it is: understanding an unfamiliar area, restructuring an argument, tightening prose. The genuinely risky use is a narrow slice, and it is easier to address once you can see the whole picture.
A ban that nobody follows is worse than no policy at all. It drives use underground, where the firm cannot see it, guide it, or catch the mistakes before they reach a client. It also teaches people that firm policy is aspirational, which is an expensive lesson to teach.
A rule that only says "no" loses to the deadline every time. The deadline is real and immediate; the rule is neither.
There is a second cost. A ban tells your best juniors that the firm would rather not think about the thing they can see reshaping their profession. Some of them will draw conclusions about where to work.
Learning an unfamiliar area. General research the person will independently verify. Internal drafts containing no client information. Improving the structure and clarity of something the lawyer wrote.
General AI is genuinely good at these, and pretending otherwise costs the policy its credibility with the people who have to follow it. A policy that describes a tool your associates use daily as useless is a policy they will stop reading at paragraph two.
No client information, no matter content, no privileged material in any consumer AI tool. Not anonymised. Not "just this once". Not in a prompt that only quotes a paragraph.
One line, no exceptions, and explain why rather than simply asserting it: the firm cannot say where that information goes, cannot produce an operator agreement, and cannot answer the client who asks. People follow rules they understand.
If the firm provides a tool that is safe for client work, the consumer tools stop being the only option at eleven at night. This is the part most firms skip, and it is the part that determines whether the rest of the policy holds.
A policy with a prohibition and no alternative is not a policy. It is a statement of preference.
Every citation from any AI source is checked against the actual report before it goes to a court or a client. South African courts have already dealt with what happens otherwise, and referred the practitioners involved to the Legal Practice Council — we wrote about those judgments here.
And the policy itself gets revisited on a fixed date, at least twice a year. This field does not sit still, and a policy written eighteen months ago is describing a different set of tools.
Keep it to one page. Longer documents get filed rather than read.
Someone senior enough that the policy carries weight, and close enough to daily practice to notice when it stops matching reality. In most firms this is a partner working with the information officer.
What does not work is drafting it once, circulating it, and treating the matter as closed. The associate who finds a genuinely useful new tool in November needs somebody to ask, or they will simply decide for themselves.
The firms that handle this well will not be the ones with the strictest bans. They will be the ones that separated clearly what general AI is for from what client work requires — and then gave their people both.
The second half is what we build. Here is the comparison, including the parts where ChatGPT wins.
AILA is built for the client work that consumer tools cannot safely touch. Your people can keep using ChatGPT for everything else — and should.
Book a demo See the comparisonAILA · WRITTEN BY ADMITTED ATTORNEYS · 8 SEPTEMBER 2026 · Buyer's Guide
Read time · 6 minutes
Every legal AI vendor will tell you their product is secure, accurate and built for lawyers. These are the ten questions that test whether it is.
Ask them of every vendor you meet. Ask them of us. We have marked the two where our own answer is imperfect, because a checklist that flatters its author is not a checklist.
Two practical notes before you start. Ask for answers in writing, because a demo-room assurance is not a contractual term. And ask the same question twice, once to the salesperson and once to whoever built the thing.
Because the firms we want to work with are the ones that ask hard questions, and because a vendor's response to question nine tells you considerably more than its answer to question one. Anyone can prepare a good answer about data residency. Very few vendors will tell you what they cannot yet do.
The answer should be a place, in writing, in the contract. "The cloud" is not a place. A region name in a marketing page is not a commitment. Ask separately about storage and processing, because they are not always in the same country, and ask where backups sit.
A verbal assurance is not a data-processing term. Ask whether the vendor's own AI providers train on content passed through to them, because that is a different question with a different answer. Ask what happens to your data at the end of the engagement, and who confirms deletion.
A tool grounded in your precedents drafts your agreements. A tool grounded in the open internet drafts everybody's, in a house style that is not yours, with no way to tell whether the source survived scrutiny.
The only safe answer is that it says so. South African courts have already dealt with practitioners who filed authorities that did not exist — in one 2025 matter, the fabrications came from a paid subscription tool marketed as trained on South African law. Being sold as a legal product is not a guarantee of legal behaviour.
Test this rather than asking about it. Bring a narrow South African point you already know is unsettled, and see whether the tool admits the gap or fills it.
If the answer is "file permissions", privilege is not modelled. Privilege attaches to the matter and should travel with everything derived from it — summaries, extracts, drafts, search results.
A title is information. So is a permission error, which confirms the document exists. The right answer is that an excluded user sees nothing. Ask which surfaces the wall covers, and make the vendor list them.
Views, edits, exports and AI generations, each with user, matter and timestamp. If you cannot export it, it is not your record — and a record you cannot produce is no use in a regulatory enquiry.
A published list your information officer can review before signing. If the list is confidential, the compliance chain has a hole in it that your firm, not the vendor, will have to answer for.
Our honest answer: AILA is new, and we are onboarding our founding firms now. We will not invent references. You would check, you would catch us, and you would be right to. What we offer instead is the founders on the demo call, direct access during onboarding, and founding-firm terms that reflect the position.
Our honest answer: our ISO 27001 certification is not complete, and you will notice we do not display the badge. Ask every vendor to show you the certificate itself, with its scope and dates, rather than the logo. Scope is where certification claims usually fall apart — a certificate covering a corporate head office says nothing about the platform your matters sit in.
Bring it to ours. We would rather be tested on these ten questions than trusted on a claim, and we would rather lose a firm on question ten than win one by being vague about it.
Send the list ahead and we will answer it in writing before we demonstrate anything.
Book a demo Read the security briefFOUNDER REVIEW REQUIRED BEFORE PUBLISH · CONFIRM ISO 27001 AND FOUNDING-FIRM STATEMENTS REMAIN ACCURATE AT PUBLISH DATE
We're still building this. Please check back shortly.