What General Counsel Should Ask About AI in Legal Vendor RFPs
AI Summary
AI in legal RFPs creates exposure that most technology sections weren't drafted to find. General counsel updating outside counsel AI guidelines should expand the RFP technology section to cover three exposures beyond data security. The first is AI hallucination risk under ABA Model Rules 1.1, 1.6, 3.3, and 5.3. The second is privilege and confidentiality loss when vendor AI processes matter content. The third is regulatory compliance under the EU AI Act, Texas TRAIGA, and federal procurement standards. This guide gives legal ops leaders the disclosure questions, evaluation criteria, and Legal AI governance framework needed to update outside counsel AI guidelines for the new reality.
TL;DR
- 99% of in-house legal teams use AI, but 47% have no AI policy and most RFP technology sections miss AI-specific vendor risk
- GCs need to address three Legal AI exposures in vendor RFPs: AI hallucination liability, privilege loss when vendor AI processes matter content, and new regulatory compliance obligations
- Update outside counsel AI guidelines and expand the RFP technology section with AI disclosure, data handling, accuracy, and governance questions
In This Article
- Why AI Belongs in Your Legal Vendor RFP
- What AI Risks Should Be in a Legal Vendor RFP?
- How Are GCs Updating Outside Counsel AI Guidelines?
- What to Ask Outside Counsel About AI Use in Vendor RFPs
- What Does Legal-Grade AI Look Like for In-House Teams?
- Frequently Asked Questions
Why AI Belongs in Your Legal Vendor RFP
AI belongs in your legal vendor RFP because outside counsel are using it on your matters, with or without your visibility, and the RFP technology section AI questions you're asking today weren't written for that reality. When vendor risk meant data security posture, uptime guarantees, and SaaS architecture, the questions did their job. AI changes the threat model, and the questions don't follow. A modern RFP technology section needs answers to four questions the older version doesn't ask:
- Where does our matter content go during processing, and in which jurisdictions does it sit at rest?
- Do vendor AI models train, fine-tune, or evaluate on our data at any stage?
- How are hallucinations caught before they reach a client deliverable or court filing?
- Who at the firm is accountable when AI output is wrong, and what's the remediation path?
The adoption numbers explain why this gap matters now. Generative AI in legal departments has scaled fast: ACC survey data shows in-house AI adoption more than doubled in a single year, from 23% in 2024 to 52% in 2025. Individual legal professional AI use rose from 31% in 2025 to 69% in 2026, according to an 8am report covering more than 1,300 legal professionals. Thomson Reuters found that 45% of law firms either use AI or plan to make it central to their workflow within a year.
The governance gap underneath those numbers is the part that should make a GC pause. Axiom's 2024 survey found that 99% of in-house legal teams use AI for work, while 47% of organizations have no formal AI policy, 83% report using AI tools their company didn't provide, and 81% acknowledge using unapproved tools. ACC found that 59% of in-house counsel don't know whether their outside counsel uses GenAI on their matters, and 80% are neither requiring nor encouraging it.
That's the position an outdated RFP technology section puts you in. Adoption inside the legal department and across outside counsel is widespread, while written governance trails behind. The questions written for a pre-AI vendor relationship can't capture risks they were never drafted to address. Legal vendor AI governance needs to be embedded in the RFP itself, with explicit questions, documented answers, and rejection criteria for the responses that don't measure up. Without that, legal vendor AI governance lives only in the engagement letter, not in the procurement decision.
What AI Risks Should Be in a Legal Vendor RFP?
Three categories of Legal AI risk need separate treatment in your legal vendor RFP technology section. The first is output accuracy and professional responsibility, also known as AI hallucination legal risk. The second is confidentiality and privilege, or AI privilege waiver risk. The third is regulatory compliance under new frameworks like the EU AI Act and Texas TRAIGA. Each one demands its own vendor questions and rejection criteria, and conflating them is how RFPs end up technically complete and practically exposed.
What Are the Professional Responsibility Risks of AI Hallucinations?
AI hallucinations are one of the professional responsibility risks of AI in legal work, and the ABA Model Rules treat them seriously. They create four exposures: competence (Rule 1.1), confidentiality (Rule 1.6), candor to the tribunal (Rule 3.3), and supervision of nonlawyer assistance (Rule 5.3). When an attorney files a brief containing AI-fabricated citations, every one of those rules can be triggered at once, along with potential sanctions, disqualification, and bar referrals. The AI competence professional responsibility analysis runs through all four.
The pace of hallucination cases changed faster than most outside counsel guidelines did. French researcher Damien Charlotin, who maintains a global database of AI hallucination incidents, tracked the rate, which rose from roughly two cases per week before spring 2025 to two or three cases per day by late 2025. Charlotin puts the running total above 700 court cases involving AI-generated content, implicating 128 lawyers, including attorneys at top-tier firms.
The disciplinary record now reflects that standard. Three federal courts sanctioned lawyers for AI hallucinations in the first two weeks of August 2025 alone. One of those attorneys was using a well-known legal research database. In Johnson v. Dunn, a federal court in Alabama disqualified a nationally recognized firm. The court also referred attorneys to the state bar and required them to file the sanctions order in every pending case where they were counsel of record.
For a corporate legal department, the question has shifted from whether outside counsel can use AI responsibly to whether the vendor tools they've chosen make responsible use possible at all.
How Does Outside Counsel AI Use Affect Attorney-Client Privilege?
The privilege analysis went from theoretical to litigated in early 2026. In United States v. Heppner (S.D.N.Y., Feb. 2026), a court ordered AI-generated documents produced and rejected both privilege and work-product protection. A client used the consumer version of Claude to analyze legal exposure. Consumer terms disclaimed confidentiality. The materials weren't prepared at counsel's direction.
The current pattern in outside counsel guidelines AI provisions reflects what Heppner exposed. Guidelines from financial services, healthcare, and government clients now require explicit approval before client data is processed by any third-party tool, AI included. A firm using a commercial AI drafting assistant on M&A documentation without that approval has breached the engagement. The output's quality is beside the point. The client data AI risk law firms create through casual AI tool use is no longer theoretical.
Three questions decide whether vendor AI preserves or breaks privilege:
- Can vendor personnel access matter content?
- Is content used to train, fine-tune, or evaluate AI models at any stage?
- Is there a confidentiality agreement adequate to preserve privilege between the firm and its AI vendors?
Privilege analysis answers all three. A standard IT security review only answers the first, which is why an RFP that relies on IT security questions alone leaves the privilege analysis incomplete.
A modern legal vendor RFP should explicitly ask all three questions, with AI disclosure outside counsel built into the documented response.
Which AI Regulations Affect Legal Vendor Governance?
Four regulatory developments now reach into legal vendor governance: the EU AI Act's GPAI obligations (effective August 2025), Texas TRAIGA (effective January 1, 2026), AI governance regimes in Utah and Colorado, and federal procurement requirements for LLM vendors. Each creates a documentation or disclosure obligation that flows from the AI vendor to the law firm to the corporate legal department that is buying that firm's services.
The EU AI Act's GPAI model obligations now require foundation model providers to publish detailed training data summaries, and require downstream users, including the law firms you hire, to confirm their AI systems don't fall into prohibited categories. That pulls vendor model provenance directly into the compliance conversation, whether outside counsel raised it or not.
State frameworks are arriving on a similar timeline. Texas TRAIGA takes effect January 1, 2026. Utah and Colorado have enacted or are implementing their own AI governance regimes. Corporate legal departments now sit at the center of a patchwork of state, federal, and international obligations that touch vendor relationships directly.
Federal procurement has set the early precedent. LLM vendors selling into government contracts must provide model cards, evaluation artifacts, and acceptable use policies, and enterprise buyers are starting to mirror those requirements in their own RFPs. What's standard in federal procurement in 2026 will be standard in AI in legal RFPs by 2027.
ACC has published sample AI guidelines for outside counsel covering disclosure, data security, accuracy, and performance, and corporate legal departments are starting to embed those same requirements into their outside counsel guidelines and RFPs. The shift from informal expectation to written requirement is well underway.
How Are GCs Updating Outside Counsel AI Guidelines?
Corporate legal departments are embedding AI provisions directly into outside counsel AI guidelines, covering data security, AI use restrictions, and confidentiality of matter information. AI moved from a footnote in the engagement letter to a separate schedule with its own approval workflow, disclosure requirements, and rejection criteria for noncompliant responses.
The procurement conversation has shifted along with it. Efficiency was the standard test for a vendor tool. Now the test is whether the tool can withstand scrutiny if a matter is challenged, a regulator audits, or a privilege dispute lands in front of a judge. Recognizing that shift means funding legal ops AI vendor evaluation as a defined function, with AI governance playbooks built into the vendor lifecycle from RFP through renewal.
The exposure gap shows up in departments that update expectations without updating governance. Saying yes to AI without defining how it will be used, where data will sit, and who will be accountable is how a legal department absorbs the risk without capturing the benefit. Law firm AI disclosure requirements close that gap, starting with the questions your RFP asks and the AI disclosure outside counsel commits to in writing.
What to Ask Outside Counsel About AI Use in Vendor RFPs
Four clusters of AI RFP questions for law firms belong in your updated RFP technology section, each one tied to an exposure point above. These RFP technology section AI questions function as a starting framework for Legal AI vendor assessment. Add jurisdiction-specific or matter-specific items as your practice areas require.
Disclosure questions
- Will you disclose AI use on our matters, and through what mechanism?
- Which matter types or task categories will involve AI?
- Who at your firm is accountable for AI disclosure decisions on our account?
Reject answers that rely on attorney discretion alone without a documented disclosure standard.
Data handling questions
- Where does our matter content go when processed by an AI tool, and in which jurisdictions does it sit at rest?
- Can vendor personnel, including subprocessors, access our content?
- Is our content used to train, fine-tune, or evaluate AI models at any stage?
- What contractual confidentiality protections sit between your AI vendors and our matters?
Reject answers that treat IT security posture and confidentiality preservation as the same analysis.
Accuracy and supervision questions
- What verification protocols apply when AI output goes into a filing, contract, or advice memorandum?
- How are hallucinations detected, remediated, and reported to clients?
- What's your supervisory structure under ABA Model Rule 5.3 for AI tools your attorneys use?
Reject answers that treat AI output as equivalent to junior attorney work product without independent verification.
Governance questions
- Do you have a documented firm-wide AI policy, current as of 2026?
- Is AI training required for attorneys before they use approved tools?
- What's the incident response procedure if AI output causes client harm?
- Will you provide annual reporting on AI use across our matters?
Reject answers that describe governance in aspirational terms without artifacts. Policies, training logs, and incident response procedures should exist as documents you can review. This is the operational core of legal department AI vendor due diligence.
The answers should be specific, current, and auditable, with documentation that a member of your team can request and review on demand. A vague answer tells you what kind of partner the firm will be.
What Does Legal-Grade AI Look Like for In-House Teams?
Legal-grade AI for an in-house team means accuracy you can stake professional judgment on, governance the business can defend, and data handling auditable enough to withstand outside scrutiny. Those three criteria define RoAI for a corporate legal department, with hours saved as the downstream benefit. The standard you ask outside counsel to meet through your RFP is the standard your own AI choices should meet too.
Litera is the Legal AI platform built to unify the practice and business of law for in-house legal teams. More than 30 years of legal-specific expertise sits behind every workflow. Rules-based engines handle deterministic accuracy on high-stakes work, and intelligent automation handles routine volume.
AI-first entrants look compelling in demos but underdeliver in deployment when the matter involves real privilege exposure and real liability. Probabilistic LLMs can't match deterministic accuracy on the work that ends up in front of a judge.
Enterprise security is built into the platform: ISO 27001, SOC II Type 2, GDPR, NIS 2, and DORA certifications. Through Lito, Litera's award-winning Legal AI agent, that capability sits inside Microsoft Word, Outlook, Teams, and SharePoint, with no new platforms or logins required and no compromise on the accuracy and governance standards your team stakes its judgment on.
Chances are, outside counsel have been running on Litera for years. The bar your RFP sets for them is the bar Litera spent decades engineering into legal work. See how Litera builds Legal AI your team can stand behind.
Learn more about Legal AI you can trust
Frequently Asked Questions
What questions should general counsel ask about AI in vendor RFPs?
Add four question clusters to the RFP technology section. Disclosure questions ask whether outside counsel will tell you about AI use, on which matters, and through what mechanism. Data handling questions address where content goes, who can access it, and whether content trains AI models. Accuracy and supervision questions cover verification protocols, hallucination response, and Rule 5.3 structure. Governance questions address firm-wide AI policy, attorney training, incident response, and annual reporting. Vague or aspirational answers should be rejection criteria.
How does outside counsel's AI use affect attorney-client privilege?
Outside counsel's AI use can expose privilege when matter content is processed by a tool whose terms disclaim confidentiality, when vendor personnel can access content, or when content is used for model training. In United States v. Heppner (S.D.N.Y., Feb. 2026), a court rejected privilege and work-product protection over materials a client analyzed using consumer-grade AI.
Does outside counsel AI use waive privilege?
Not in every case. Privilege depends on whether materials were prepared at counsel's direction and whether adequate confidentiality protections were in place. Consumer AI tools without legally binding contractual terms create the waiver risk. Enterprise Legal AI with proper confidentiality agreements, restricted vendor access, and no training-data use preserves privilege when properly engaged.
Which ABA model rules apply to AI-assisted legal work?
ABA Formal Opinion 512 confirms that Rule 1.1 (Competence), Rule 1.6 (Confidentiality), Rule 3.3 (Candor toward the tribunal), and Rule 5.3 (Supervision of nonlawyer assistance) apply to AI-assisted legal work. More than 600 hallucination cases now implicate 128 lawyers, including attorneys at top-tier firms.
How should legal departments evaluate law firm AI policies?
Knowing how to evaluate law firm AI policies starts with looking for documented policies current as of 2026, mandatory attorney AI training before tool use, written incident response procedures, and a commitment to annual reporting on AI use across matters. Aspirational language without artifacts (policies, training logs, response procedures you can review) should be a rejection signal during Legal AI vendor assessment.
What is the risk of AI hallucinations in legal filings?
Hallucination cases moved from roughly two per week in early 2025 to two or three per day by late 2025, per Damien Charlotin's database. Stanford RegLab found legal-specific tools hallucinated between 17% and 34% of the time. In Johnson v. Dunn, a federal court in Alabama disqualified the firm, referred attorneys to state bars across multiple jurisdictions, and required the filing of the sanctions order in every pending case.
How do you update outside counsel guidelines for AI?
Knowing how to update outside counsel guidelines for AI starts with adding provisions covering AI disclosure on matters, restrictions on data handling and processing locations, accuracy and supervision protocols tied to ABA Model Rules 1.1 and 5.3, and governance requirements including documented policies and incident response. ACC's sample AI guidelines for outside counsel provide a starting framework that corporate legal departments can adapt to their jurisdictions and matter mix.
What is ABA Model Rule 1.6 AI confidentiality, and how does it apply?
ABA Model Rule 1.6 AI confidentiality protects client information. Under Formal Opinion 512, the rule applies to AI tools the same way it applies to any third party with potential access to client information. Using consumer AI without confidentiality protections, or vendor tools that train on input data, can trigger Rule 1.6 obligations that weren't met at the time of use.
See how in-house legal teams are already moving at the speed of business. Meet with us →