Three years ago most lawyers wanted nothing to do with AI. The stated objection was accuracy: three quarters of respondents to the American Bar Association's 2024 technology survey named hallucinations as the reason they held back. The unstated objection was status. You spend a decade earning the right to be the person who knows, and a machine that answers instantly is not a tool, it is a comment on your value. Then adoption went from 11% to 30% in a single year, and by Clio's 2026 read three quarters of small firms were using it. What changed was not the technology. It was the firm across town quoting a lower fee.
The reluctance was real, and it is over
A ten-person firm is not running a pilot programme. There is no innovation committee, no IT department, and nobody whose job is to read a vendor's security whitepaper. There are partners, associates, a paralegal or two, an office manager, and roughly four hundred things that matter more this week than an AI policy.
So adoption at that size never arrives as a decision. It arrives as an associate at 9pm with a forty-page settlement agreement and a summary due in the morning. That associate is not being reckless. They are being efficient, with the same tool opposing counsel is using, and the firm's position on it is whatever nobody has said out loud.
Clio's number for the consequence is the one to sit with. Fewer than a third of solo and small firms report any revenue increase from AI, against nearly 60% of enterprise firms. The work got faster and the billing did not change. The efficiency went to the client. The risk stayed in the building.
Nobody wrote the policy down
Here is the gap that should bother a managing partner more than the adoption rate. Three quarters of small firms use AI. Fifty-five percent have no policy governing it. And profession-wide, asked how many have a written policy that is genuinely enforced rather than filed, the answer is 9%.
That is not a training problem. A policy living in a PDF on the shared drive is not a control, it is a document you can produce after something has gone wrong, which is a different and far less useful thing. Ask the honest question about your own firm: if an associate pasted a client's medical records into a chatbot last Tuesday, by what mechanism would you find out?
At most firms this size, you would find out when the client did. Everything below is about closing the distance between the rule and the evidence.
A file, not a text box
Start with the shape of the work, because this is where privacy tooling quietly fails a law firm. What a lawyer has is a file. A scanned lease, a PDF bundle from opposing counsel, a DOCX the client emailed. Almost every tool that claims to strip personal data takes a string of text, so somebody has to turn the document into text first, and that somebody is you.
promptShield takes the file. You add PDFs, Word documents, spreadsheets, decks and images to the Library, and detection runs across four layers: patterns for things with a shape (account numbers, national IDs, emails), entities for things without one (names, employers, addresses), your own expressions for the matter-specific terms no general model has heard of, and an optional deep pass for the edge cases. Text recognition for scans happens inside that pipeline, not as a chore you run first. We wrote up why that distinction matters in why nobody built a redaction tool for you.
Then a human signs off. Findings land in a review panel, and the file cannot be downloaded until somebody has verified them. That gate is deliberate, and it is the part that survives a professional-negligence conversation: the software proposed, a named person confirmed, the confirmation was recorded. On download you pick the destination folder and can set it as the default, so protected copies collect in one place instead of scattering through Downloads.
Out to the model and back again
Now the round trip, which firms usually assume is impossible. Two ways to protect a file, answering different questions.
Redact removes the text permanently. Right for anything leaving the firm: an exhibit, a filing, a document going to the other side. Encode swaps each value for a short reversible code and keeps the mapping in a registry on your own machine. The same client gets the same code in every document, every time, which is what keeps an encoded bundle readable as a case rather than as alphabet soup. The model can follow that the party in the lease is the party in the correspondence, because the code says so. That consistency is load-bearing enough to have its own article.
So the associate encodes the agreement, drops the protected copy into whichever assistant the firm uses, and gets back a summary full of codes. That response goes into the Decode tab, as a file or as pasted text, and the real names come back locally from the registry on their machine. Nothing in the loop required the client's name to reach the model. And for the copy-paste habit nobody is going to give up, Clipboard Guard swaps known terms for their codes as you copy, before the paste happens.
What the managing partner actually gets
Ten people means ten machines, and machines are how this goes wrong. The license manager in the browser dashboard is where you assign a license to an email address, set someone as owner, admin or member, and tag licenses by team, matter type or cost centre so an export reconciles against how the firm bills. When somebody leaves, revoking their license deactivates their device.
Details that matter at this size: two personal device slots are always included, so the partner with a desktop and a laptop is not paying twice; licenses bulk-assign from a pasted spreadsheet; and renewal management shows what is renewing against what is expiring, which is how you avoid learning in August that three people lost access in July.
Note the deliberate asymmetry. The people holding seats see none of this. The dashboard, the audit log and the compliance monitor belong to the owner. Your associates get an app that protects documents. They do not get a console for looking at each other.
The Compliance Monitor, and what it will not tell you
This is the instrument that turns a policy into something observable. It lists every seat with what that person did in a window you choose: documents exported, pages processed, values detected, encoded and redacted, and when they were last seen. It totals seats against how many are compliant and how many are policy gaps, on a threshold you set, so a seat idle for 30 days surfaces instead of sitting quietly in a list. The whole thing exports as a compliance report.
Now the important part, which is the product's own disclaimer rather than a caveat we are volunteering to look balanced. The Compliance Monitor surfaces signals of potential non-compliance based on activity through promptShield. It cannot tell you whether somebody handled a sensitive document outside the tool. A member whose machine is offline-activated is flagged as air-gapped precisely because their activity cannot be verified at all.
So what you have bought is not surveillance, and any vendor selling certainty here is selling something they do not have. What you have is the difference between an assertion and a record. "We have an AI policy" is an assertion. "Here is a report showing nine of ten seats protecting documents every week, and here is the tenth, which I followed up on" is a record, and it reads very differently to an insurer, a client's procurement team, or a regulator.
Common questions
Do the documents leave our office?
No. Detection, text recognition and redaction run on the machine the file is already on, and the code registry is local too. What reaches our servers is license validation and the activity counts behind the compliance report: counts and timestamps, never document content. On the Pro plan a machine can be offline-activated and make no outbound request at all, with the trade-off named above, that it can no longer be verified in the monitor.
Isn't it easier to ban AI at the firm?
You can write that rule. You will not enforce it, and the numbers say so: adoption reached three quarters of small firms while most had no policy either way. A ban does not remove the 9pm associate with a deadline. It removes your visibility into what they did. Making the protected route the quickest route is the only version of this that survives a busy week.
Which plan covers a ten-person firm?
The license manager, the audit log and the Compliance Monitor are Pro features, so the firm needs Pro for the owner who manages seats. The lawyers using the app day to day only need a license assigned to them. Basic covers the desktop app without the management layer, but you give up the reporting, which for a firm trying to prove a policy is the point. What "safe" has to mean here is covered in is it safe to upload my contract to ChatGPT.
The bottom line
The profession spent three years arguing about whether AI belonged in legal work, and the argument ended the way these always do: not with a consensus, but with a competitor charging less. Adoption is settled. Governance is not, and the distance between 75% using it and 9% enforcing a policy about it is where the next few years of professional-liability claims will come from.
A ten-person firm cannot close that with a committee. It can make the careful path the path of least resistance and keep a record that it was taken. Smaller ambition than a policy framework, worth considerably more.
Every lawyer reading this has had the conversation where a client hands over something they are frightened of, and trusts you with it because there is nowhere else to put it. That trust is the actual product. Everything else is billing. Try promptShield on a real matter this week, and watch whether the associate at 9pm takes the safe route once it is also the fast one.