Article
Claude in law firms: the tool is brilliant, but is the provider ready for regulated professions?
Mamadou Waggeh
Founder of Leaid
Introduction
Generative artificial intelligence is reaching a turning point in the legal sector. After an initial phase dominated by curiosity, individual testing and sometimes spectacular demonstrations, providers are now seeking to enter professionals’ daily workflows. Anthropic has understood this perfectly with Claude Cowork and its variants aimed at legal teams. The use cases put forward are those that genuinely take up a significant part of a lawyer’s or in-house counsel’s week: contract review, clause extraction, document comparison, redlining, summarising, preparing a first draft, organising a case file.
At first sight, the offering is highly coherent. Claude has a reputation as a serious, cautious model, less sloppy than some competitors and particularly comfortable with long texts. In a law firm, this quality of document-based reasoning is obviously attractive. It fits a transformation already described for the legal professions: the gradual shift from the triptych of analysis, production and delivery to a triptych of verification, validation and delivery. In this new paradigm, the tool produces more raw material, but the professional remains responsible for qualification, judgement and delivery to the client.
Yet it is precisely because Claude performs well that one must be demanding. The more useful a tool is, the more it shapes the way work is done. The more it enters daily use, the more critical an outage, an access restriction, cost drift or a confidentiality problem becomes. The mistake would therefore be to treat Claude as mere productivity software. For a lawyer, it is potentially a strategic supplier, in other words a link in the legal production chain, with everything that implies in terms of professional secrecy, business continuity, data protection, security and liability.
1. An appealing value proposition for legal use cases
It would be unfair to reduce Claude to its risks. Legal professionals need tools capable of processing large volumes of information, spotting inconsistencies, redrafting clauses and helping to prepare deliverables. Business law firms, in-house legal departments and legaltechs have already been working on these use cases for several years. Claude is therefore part of a genuine trend, not a purely media-driven phenomenon.
The promise is particularly strong across four families of tasks. First, reading and summarising large corpora: contracts, schedules, exhibits, case law, email exchanges, internal reports. Second, document comparison, useful in contractual, litigation or regulatory matters. Third, producing first drafts, whether of a memo, an email, a clause or an outline of arguments. Finally, organising work, with agents able to chain several steps together and draw on different files or applications.
In a sector subject to deadline pressure, the growing complexity of rules and clients’ demands for productivity, these uses have an obvious appeal. They can reduce the time spent on certain repetitive tasks and free up part of lawyers’ attention for the areas where their added value is greatest: strategy, negotiation, risk assessment, client relationships, judgement and responsibility.
But this appeal must not obscure a simple reality: a tool suited to general-purpose use is not automatically suited to a law firm. Law is not merely a documentary discipline. It is also a liability regime, a relationship of trust, a body of professional ethics rules and a system of evidence. That is why the model’s performance cannot be the sole criterion for adoption.
2. Operational risk: continuity of access becomes a professional ethics issue
The first area of concern is service continuity. A law firm cannot depend on a tool to which access can be interrupted without clear mechanisms for notice, appeal, escalation or contractually guaranteed support. Suspended accounts, an inaccessible service, a restriction linked to a usage policy or a geographical area, even a temporary one, do not have the same effects for a private individual as for a professional who must file pleadings, close a transaction or be ready for a client meeting.
Anthropic documents the existence of warning, suspension and appeal procedures in the event of a breach or suspected breach of its usage policies. That is legitimate from the standpoint of an AI provider, which must control dangerous or unlawful uses of its models. But from a law firm’s standpoint, this logic must be built into the risk plan. What happens if an account is suspended during a sensitive transaction? Who can challenge it? What is the response time? Is there an identified human contact? Does the contract provide for a notification obligation?
The question of support is equally central. Anthropic’s documentation indicates that support varies by plan, that telephone support and human live chat are not always available, and that some users first go through an automated support agent. For individual use, that may be acceptable. For a professional organisation, particularly one handling client data and high-stakes matters, it is insufficient unless the offering is supplemented by precise commitments: support level, response times, dedicated contact, emergency procedure, exit clause.
A law firm must therefore ask a simple question before any deployment: is Claude a supplementary tool or a critical one? In the first case, use can remain limited and controlled, without any interruption bringing work to a halt. In the second, a genuine supplier audit is required. Access to the tool cannot rest on the same guarantees as a consumer subscription.
3. Confidentiality risk: professional secrecy cannot be delegated
The second point concerns confidentiality. Lawyers are bound by professional secrecy. This obligation is not limited to avoiding the publication of a document. It means controlling the information life cycle: collection, entry into the tool, storage, access by the provider, logging, subcontracting, transfer outside the European Union, retention, deletion, incident handling and the ability to audit.
The major AI providers have strengthened their guarantees, particularly for enterprise offerings. Anthropic highlights security measures, control mechanisms, limited-retention options and, for some customers, agreements not to retain inputs and outputs on eligible APIs. But these guarantees are neither general, nor automatic, nor equivalent across plans. The devil is in the detail: eligibility conditions, exclusions, required configurations and how teams actually use the tool.
The issue is all the more sensitive because agentic tools are designed to access files, manipulate documents, connect to applications and execute tasks. This development is powerful, but it widens the risk surface. A misconfiguration, an overly permissive connector, confusion between personal and professional environments, a misunderstood retention policy or a prompt containing sensitive information can be enough to cause an incident.
The analysis must be conducted against several requirements: the GDPR, bar rules, the firm’s security policy, contractual obligations towards clients, any sector-specific restrictions and, for international matters, data transfer rules. A lawyer’s use of Claude cannot be decided by the end user alone. It must be treated as a governance decision.
4. Usage monitoring: a tension with confidentiality expectations
Another point deserves particular attention: usage control mechanisms. AI providers monitor interactions with their models to prevent uses that are unlawful, dangerous or contrary to their policies. Anthropic indicates in particular that certain content may be flagged by its safety classifiers and that data associated with these flags may be retained for specific periods. This logic is understandable from the standpoint of the overall security of the service. It is far less so when a user believes they are interacting in a perfectly confidential environment.
For lawyers, an exchange with an AI may contain facts covered by professional secrecy, litigation strategies, identifying details, health data, financial information or documents provided by a client. Even when a provider does not use this data to train its models, there may be logs, scores, metadata, compliance systems or review mechanisms in the event of suspected prohibited use.
This is not to say that these systems are illegitimate. It is to say that they must be fully understood before any professional use. A law firm must know what is monitored, what is retained, who can access it, for how long, under what conditions and with what remedies. In practice, this means distinguishing between non-sensitive uses, internal uses, anonymised client work and uses involving confidential or identifying data.
5. The real cost: the subscription is only the visible part
The third issue is economic. Many users assess Claude on the basis of the advertised price of a subscription or an API cost per million tokens. This approach is insufficient for a law firm. The real cost depends on the volume of documents processed, the length of prompts, the size of outputs, the model tier used, the tools enabled, the connectors, caching, any agents and the way users work day to day.
Legal uses are precisely the ones that can send consumption soaring. A lawyer does not merely submit a short question. They add contracts, schedules, exhibits, successive versions, style instructions, client constraints, and sometimes request several iterations. The cost is then less comparable to a Google search than to a document production line.
Use in French must also be measured. Depending on the model and tokeniser, the same text can generate a markedly different number of tokens from one language to another. Tests carried out on French-language matters can show significant differences, sometimes close to double the figure for certain English-language equivalents. The consequence is simple: a French law firm cannot extrapolate its cost from English-language benchmarks. It must test on its own documents, its own uses, its own templates, factoring in corrections, iterations and long outputs.
The full cost must therefore be built up: subscription cost, API cost, governance cost, training cost, integration cost, human oversight cost, risk cost and exit cost. An AI that is cheaper on paper may be more expensive in production if it consumes more, requires more checking or creates more operational uncertainty.
6. What a law firm should require before deploying Claude
The right answer is not to ban Claude on principle. It is to treat its adoption with the same rigour a law firm would apply to a critical supplier. The model’s performance may justify experimentation. It does not justify ungoverned adoption.
Seven conditions to meet before deploying Claude in a law firm
- Restrict consumer-grade use to non-sensitive tasks and prohibit the entry of identifying client data without an approved framework.
- Carry out a contractual audit: data retention, subcontractors, transfers, confidentiality, support, SLAs, exit arrangements and liability.
- Document authorised uses: internal summaries, translation, rewording, document review, extraction, clause analysis, template generation.
- Provide for a systematic human validation process for every client deliverable and every procedural document.
- Test token consumption on real French-language matters to avoid unpleasant financial surprises.
- Provide for a fallback solution and a multi-provider strategy to avoid excessive dependency.
- Train lawyers and staff on the critical assessment of outputs, on hallucinations and the limits of reasoning, and on confidentiality rules.
Claude can be an excellent support tool. It must not become a central black box in legal production without contractual, technical and economic guarantees. Responsible adoption means starting from the profession’s needs, then choosing the tool. The opposite approach creates a dangerous dependency.
Conclusion
The question Claude raises is not whether lawyers are modern. It is whether AI providers are mature enough for regulated professions. A tool can be technologically remarkable and operationally fragile. It can be useful, yet poorly governed. It can deliver time savings while creating new confidentiality, cost and dependency risks.
For French lawyers, the challenge is therefore to resist two excesses: conservative rejection and naive adoption. Claude deserves to be tested. It does not deserve to be adopted unconditionally. The profession must retain control of its data, its methods, its responsibilities and its business model. Only on that condition can AI become a genuine assistant to the law, rather than a new source of vulnerability for those whose very mission is to protect others.
© Leaid — Mamadou Waggeh, Founder of Leaid · leaid.ai