New research from Harmonic Security, reported this month by Law.com, should change how general counsel think about the tools their departments already use. Across 1.9 million classified AI-session minutes in enterprise organizations, legal and governance teams turned out to be the single heaviest users of artificial intelligence, at 19.5 percent of all activity. They out-used sales at 17.7 percent, product and engineering at 13.3 percent, strategy at 11.9 percent, and HR at 10.4 percent. For a profession with a reputation for moving slowly, that is a real shift. It is also the part of the finding that deserves the least celebration.
Consider what actually passes through a legal team's prompts. Contracts under negotiation. Privileged communications. Regulatory exposure. Litigation strategy. The valuation of a patent portfolio. Harmonic's own conclusion is blunt: because lawyers handle the most confidential categories of information a company holds, and because they now use AI more than anyone else, legal represents the largest single concentration of sensitive data entering AI systems inside the enterprise. High volume meeting high sensitivity is not a milestone to applaud. It is a risk surface to manage.
Enterprise-approved is not the same as safe
To their credit, lawyers are disciplined about which door they walk through. Legal accounts for roughly a third of sanctioned enterprise AI usage but only about four percent of activity on free, personal accounts, the mirror image of the go-to-market teams that generate most of their AI activity on whatever chatbot happens to be open in a browser tab. That discipline matters for IT. It does not make the work safe. It answers a narrow question, which account, and leaves the harder one untouched: is a general-purpose assistant the right instrument for legal work at all?
The tools in question are commodities. ChatGPT alone accounts for 67 percent of legal's AI hours in the study, the largest concentration of any department on any single tool, with Copilot and Gemini making up much of the rest. These are capable, general systems. None of them was designed to understand privilege, to check a citation against a real reporter, or to treat an incoming document as potentially hostile. A junior staffer pasting a draft indemnification clause into Copilot to tighten the language is not doing anything his employer forbade. He is also not exercising the caution the work demands, because the tool gives him no way to.
Three failures the commodity tools cannot see coming
Start with privilege, because it is the protection most easily lost and least easily recovered. Attorney-client privilege and work-product protection depend on confidentiality. Disclose protected material to the wrong third party and you can waive that protection, sometimes without realizing it has happened. General AI services vary widely in what they retain, where it is stored, who can reach it, and whether prompts are used to train the model further. A lawyer who feeds privileged content into a tool whose data handling they cannot fully account for is making a bet on all of those questions at once. Harmonic's chief executive, Alastair Paterson, put the irony plainly: lawyers risk breaking the very data-protection laws they are paid to uphold the moment they use the wrong tool.
Then there is the exposure lawyers are least likely to anticipate. Legal documents arrive from adversaries. Opposing counsel drafts them, counterparties send them. We examined one example at length in a recent analysis: a filing in a Brazilian labor court was found to contain hidden text, white letters invisible to a human reader, instructing any AI that processed the document to review it superficially and raise no objections. That is a prompt-injection attack, aimed directly at the general tools opposing lawyers might use to analyze the filing. A commodity model has no reason to flag it. It was built to be helpful, not suspicious.
And then there is fabrication, which is no longer a hypothetical. In 2023, two attorneys in Mata v. Avianca were sanctioned in federal court after filing a brief built on six decisions ChatGPT had invented, with fabricated citations and quotations. When one of them grew uneasy and asked ChatGPT whether the cases were real, the model assured him they were. They were not. Courts have disciplined lawyers for the same error more than once since. General models produce fluent, confident prose whether or not the authority behind it exists, and Harmonic found that legal AI sessions average 6.4 minutes. Six minutes is long enough to get an answer. It is not long enough to verify one, and nothing in a general chatbot verifies it for you.
The profession already has a word for this
None of this is exotic. The ABA's Model Rules require competence, and since 2012 that duty has expressly included the technology a lawyer uses. Rule 1.6 requires reasonable efforts to prevent the disclosure of client information. In July 2024, the ABA issued Formal Opinion 512, its first formal ethics guidance on generative AI, which tells lawyers in effect that reaching for these tools suspends none of their existing duties of confidentiality, competence, supervision, or candor. Running privileged work through a system you do not understand, without safeguards, is not a neutral act of efficiency. It is closer to diagnosing a serious condition from a search engine, or to representing yourself in a matter that plainly calls for counsel. The output looks authoritative. The person relying on it has no way to know where it is wrong.
Partnering with Adjuria addresses these risks and positions legal teams to capture the benefits
None of this is an argument against AI in legal work. The adoption numbers make the opposite case. Legal reached for these tools faster than any other department because the need is genuine: the volume of contracts, the regulatory surface, the research, the drafting. The argument is against doing that work with instruments that were never built for it, in the hands of people given no way to check them. That is the gap Adjuria closes.
AI Associate is a private, department-trained platform rather than a public chatbot. Your data stays in your environment and is never used to train anyone else's model, which is the starting condition for protecting privilege rather than gambling with it. Every output runs through a quality layer the commodity tools do not have. Citations are checked against real authority through a deterministic, AI-free process, so you are never asking one model to vouch for another model's work, and every check is transparent to the human reviewer, who can see exactly which authority was confirmed and how. Drafts pass through multi-model quality checks and hallucination detection that cross-references your own source documents instead of trusting the model's confidence. The platform treats incoming documents as untrusted, so an injected instruction is something it watches for rather than something it obeys. And because Adjuria pairs the platform with consulting, the governance and safeguards are designed around how your team actually practices, not bolted on after a problem surfaces.
The threats will not hold still, and neither do we. Prompt injection was a curiosity a year ago and a documented courtroom tactic today. Adjuria monitors the legal and security landscape continuously and updates the platform's safeguards as new attack methods and failure modes emerge, so your protection keeps pace with the risk rather than trailing a breach behind it. That is the real distinction between a tool you license and a partner accountable for keeping you safe.
The Harmonic study is a portrait of a profession that has embraced AI ahead of almost everyone else, and for the most part without the tooling its own duties of confidentiality and competence require. That combination will not hold. The departments that come through this period intact will be the ones that treated legal AI as a legal instrument, held to legal standards, rather than as a convenience that happened to be open in the next tab. If your team is already this far in, the safeguards are not a future project. They are overdue.

