Every tool in your stack — including AI — inventoried, risk-rated, and covered by written data-handling agreements.
Your security perimeter is only as strong as the sloppiest vendor inside it — and since ABA Opinion 512, 'we didn't know the tool did that' is not a defense. We maintain a living inventory of every application, service, and AI tool that touches firm or client data, each one risk-rated and covered by a written data-handling agreement.
AI gets its own lane: an approved-tool catalog, a firm AI-use policy your attorneys can actually follow, and technical controls that keep client data out of tools that train on it. Shadow IT gets found, assessed, and either sanctioned or shut off.
When a client asks 'what AI tools touch our matters?', the answer is a report, not a scramble.