Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Legal AI
    August 23, 2026
    34 min read

    Top 10 AI Agents for Law Firmsin 2026

    Four vendor renames in eighteen months, one billion-dollar acquisition and one dismemberment mean most legal AI rankings you will read this year are wrong about the roster before they get to the analysis. This one scores nothing a vendor published about itself — only ownership from public record, certifications on the vendor's own trust page, where the no-training clause is actually written, and whether a price exists at all. Every cell is a citation or the words “not publicly disclosed”.

    AI agents for law firms in 2026 — legal research, contract drafting, e-discovery and the lawyer supervision duties that bound all of it
    17%–33%
    Hallucination rate found in the two largest legal research tools, measured April 2024
    Magesh, Surani, Dahl, Suzgun, Manning & Ho, J. Empirical Legal Studies (2025), DOI 10.1111/jels.12413
    516
    US court decisions in which a lawyer relied on AI-hallucinated material
    AI Hallucination Cases database, Damien Charlotin, HEC Paris — data as of August 23, 2026
    Dec 2, 2027
    New date for EU Annex III high-risk obligations, deferred from August 2, 2026
    Regulation (EU) 2026/1744 (Digital Omnibus on AI), Recital 40, OJ L, 2026/1744, 24.7.2026
    3 of 15
    Verified legal AI vendors holding ISO/IEC 42001, the AI management system standard
    Vendor trust centres for Harvey, Legora and Definely, checked August 23, 2026

    Key Takeaways

    • Four vendor renames inside eighteen months — Casetext to CoCounsel, Leya to Legora, Callidus to StrongSuit, Lexis+ AI to Lexis+ with Protégé — plus Clio's $1 billion acquisition of vLex and the dismemberment of one well-known vendor mean a 2026 legal AI ranking written from memory is wrong in at least five places.
    • We scored only attributes a managing partner can re-check in an afternoon: ownership from public record, certifications on the vendor's own trust page, where the no-training commitment is written, whether a price is published, suite lock-in, and whether any independent evaluation exists. We scored no accuracy, hours-saved or ROI figure, because every one in this market is published by the seller about itself.
    • Not one of the fifteen vendors we verified publishes a price. Every pricing cell in our table reads not publicly disclosed, and the two widely circulated third-party figures are both refused — one is contradicted by the vendor's own page, and one of the most-cited sources for the other is a direct competitor.
    • Only three vendors hold ISO/IEC 42001, the AI management system standard: Harvey, Legora and Definely. Twelve do not, including several marketing agentic AI hardest.
    • No-training commitments are not equivalent and the differences are contractual. Harvey's is in the Platform Agreement, Spellbook's is in the Terms of Service, Ironclad prohibits third-party training but permits first-party training on opt-in, Legora's appears in marketing but not in its published Security Policy — and Luminance's published Master Hosted Agreement affirmatively reserves a perpetual right to learn from product usage.
    • The binding constraint is not technical. California's 2026 COPRAC guidance, issued at the California Supreme Court's request and addressing agentic AI directly, states that lawyers must not deploy agentic systems that make substantive legal determinations, communicate legal advice, prepare and file pleadings, or act in a representative capacity without meaningful lawyer supervision and review.
    • 516 US decisions involve a lawyer relying on AI-hallucinated material — 293 of them in 2026 through August 23, versus 207 in all of 2025. The widely quoted worldwide figure of 1,955 is not a lawyer statistic: 801 of the 1,344 US cases involve self-represented litigants.
    • EU high-risk obligations moved. Regulation (EU) 2026/1744, in force July 27, 2026, deferred Annex III standalone high-risk to December 2, 2027 and Annex I to August 2, 2028. Separately, Annex III(8)(a) binds systems used by a judicial authority — not a private firm's own drafting tools.
    • Frenchy Digital cost bands: discovery and workflow audit $9k–$22k; single-workflow agent $28k–$70k; multi-workflow platform with system integration $70k–$180k; enterprise, multi-site or regulated build $180k–$420k+.

    The Claim Under Test: Most 2026 Legal AI Rankings Are Already Wrong

    The single most useful thing to know about legal AI rankings in 2026 is that the roster changed faster than the writing did.Before any question of which product is better, there is a prior question a managing partner should ask of every list they read: does this list even name the products correctly? Four vendor renames landed inside eighteen months, alongside a billion-dollar acquisition and one company's dismemberment. A ranking written from memory rather than from the register is wrong in at least five places before it reaches a single judgement.

    Here is the corrected roster, each item checkable in a public source. Casetext no longer exists as a brand — Thomson Reuters completed its acquisition for $650 million in cash on August 17, 2023, and the 2026 product name is CoCounsel Legal, not CoCounsel 2.0. Leya became Legora in February 2025. Callidus Legal AI became StrongSuit on November 12, 2025 — and its Crunchbase and CB Insights entries still sit at a callidusai slug, which is how the dead name keeps getting copied. Lexis+ AI was replaced outright by Lexis+ with Protégé on February 24, 2026; LexisNexis now describes the older product as its first-generation AI experience. vLex was acquired by Clio for $1 billion in a deal that closed on November 10, 2025, with Vincent AI retained rather than retired. And Relativity is Silver Lake-controlled — visible in the board composition on Relativity's own leadership page rather than in any press release.

    None of that is a gotcha. It is the ordinary consequence of a market consolidating at speed, and it is exactly why a ranking has to be re-verified rather than inherited. The vendor-risk section below works through the sharpest case of all: a company that appears on virtually every 2026 legal AI listicle, whose engineering team is now at Microsoft and whose services arm is now at Scissero, and which Companies House nonetheless still lists as Active.

    The claim under test.Nearly every "best AI agents for law firms" article ranks on accuracy, hours saved, or return on investment. In this market those figures come almost entirely from the sellers. We do not rank on them. We rank on attributes you can re-check yourself in an afternoon — and we say in the text what we refused to score and why. That refusal is the product.

    The second thing worth knowing is that legal is unusual: it is one of the few markets where a genuinely independent, peer-reviewed evaluation of AI products exists at all. That evaluation is a decade of credibility in a single paper, and it is also narrower and older than the way it gets quoted. Handling it honestly — reporting what it found, what it covered, and the fact that one of the products it tested has since been retired — is the difference between a ranking a partner can rely on and one they will quietly discount.

    And the third: the constraint that decides whether any of this works in your firm is not technical. It is professional-responsibility law, and in California it has now been written specifically about agents. We get to that below, and we build the human-in-the-loop boundary table directly out of the regulator's own language rather than out of ours. If you want the wider cross-industry version of this argument, our survey of the top AI agents across every category in 2026 applies the same evidence standard outside legal.

    How We Ranked, and What We Refused to Rank On

    We scored eight attributes, every one of which you can verify from a public source, and we scored no performance metric of any kind. Here is the methodology in full, stated up front so you can disagree with it before you read the table rather than after.

    What we scored — and how you re-check each one

    • Documented public integrations: The vendor's own documentation or product page. If a partner confirms it independently, better. If only a marketing page names it, we say so.
    • Certifications actually published: The vendor's trust centre. SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001. Not the sales deck.
    • Where the no-training commitment lives: Contract, published policy, marketing page, or nowhere. These four are not the same thing, and the difference is enforceable.
    • Pricing transparency: The vendor's pricing page. Published figure, or the literal words not publicly disclosed. We never estimate a price.
    • Standalone or suite-locked: Product documentation. Whether the AI can be bought without also buying the content or platform subscription underneath it.
    • Ownership and funding from public record: SEC filings, Companies House, dated press releases. Not a Crunchbase summary.
    • Whether any independent evaluation exists: For eleven of the fifteen vendors we verified, the answer is none at all.
    • Data residency and retention commitments: The DPA, security addendum or trust page. Where it is unpublished we mark it unpublished.

    What we refused to score: accuracy, hallucination rate, hours returned, time saved, matter throughput, realisation lift and return on investment.Not because those things do not matter — they are the only things that matter to a P&L — but because in this market every published figure of that kind was produced by the party selling the product, on a private dataset, with an unpublished methodology. Scoring them would mean ranking vendors on the quality of their marketing departments.

    The independent-benchmark position, stated precisely. Legal is the rare vertical where an independent benchmark does exist — and that is precisely why we do not score accuracy. The one peer-reviewed evaluation, from Stanford's RegLab, covered three products, ran in April 2024, and found the two largest vendors hallucinating between 17% and 33% of the time; one of those products has since been replaced outright. The only ongoing benchmark is one vendors opt into task by task, and the two biggest declined its second round. For e-discovery there is nothing at all: NIST's TREC Legal Track, which gave technology-assisted review its evidentiary foundation, ran from 2006 to 2011 and has had no successor. As the Stanford authors put it, "no arbiter or trustworthy institutional mechanism has yet emerged in the legal AI space." So every accuracy figure you will read in this market is still published by the vendor about itself.

    That paragraph is worth unpacking, because it is the load-bearing claim of the whole article. The peer-reviewed study is Magesh, Surani, Dahl, Suzgun, Manning and Ho, "Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools", published in the Journal of Empirical Legal Studies (DOI 10.1111/jels.12413) and accepted March 14, 2025. Cite that version, not the 2024 preprint, whose Westlaw figure was superseded. It was preregistered, used 202 hand-constructed legal queries with manual expert coding of every response, and released its dataset with half withheld to guard against model memorisation.

    Its definition of a hallucination is the methodological crux and is worth quoting exactly, because vendors dispute it: "A response is considered hallucinated if it is either incorrect or misgrounded. In other words, if a model makes a false statement or falsely asserts that a source supports a statement, that constitutes a hallucination."That means a factually correct answer that cites a source which does not actually support it counts as a hallucination. For a lawyer preparing a brief, that is the right definition. For a vendor's marketing team, it is an unfair one. Both positions are coherent; you should know which one a number is using.

    "We demonstrate that the providers' claims are overstated. While hallucinations are reduced relative to general-purpose chatbots (GPT-4), we find that the AI research tools made by LexisNexis (Lexis+ AI) and Thomson Reuters (Westlaw AI-Assisted Research and Ask Practical Law AI) each hallucinate between 17% and 33% of the time."

    Magesh, Surani, Dahl, Suzgun, Manning & Ho, Journal of Empirical Legal Studies (2025)

    The claims being tested were not vague. The paper's own endnote reproduces them: LexisNexis marketed "100% hallucination-free linked legal citations"; Casetext said CoCounsel "does not make up facts, or 'hallucinate,' because we've implemented controls to limit CoCounsel to answering from known, reliable data sources"; Thomson Reuters said it avoided hallucinations by relying on trusted Westlaw content. Those are the sentences the study was designed to test, and it contradicted them.

    Now the fairness, in the same breath. LexisNexis's Chief Product Officer for North America and UK, Jeff Pfeifer, responded on May 24, 2024: "LexisNexis has not been contacted by Stanford's Daniel Ho, and our own data analysis suggests a much lower rate of hallucination." He also argued the criteria measured answer and citation quality rather than hallucination specifically. LexisNexis has never published the underlying data. Stanford's reply was that it had been denied access to the tools; the paper's endnote records that Thomson Reuters denied three access requests during the initial evaluation and provided access only after the results were released. Stanford then augmented the study, and the augmented results were nearly identical — Ask Practical Law's accuracy moved from 19% to 20%.

    And the caveat that matters most in 2026: the products tested no longer describe the products sold.The evaluation was completed in April 2024. The highest-performing system was Lexis+ AI, accurate on 65% of queries — and Lexis+ AI was replaced entirely by Lexis+ with Protégé on February 24, 2026. No successor evaluation of the replacement has been published by anyone. Presenting 17%–33% as a current performance figure for today's products would be exactly the error this article exists to refuse. Presenting it as the best independent measurement the profession has ever obtained, of products that have since moved on, is accurate.

    The other benchmark in this market is the Vals Legal AI Report, run by Vals AI with Legaltech Hub, using datasets from eight law firms and an independent-attorney baseline sourced through Cognia Law. It is genuinely useful and it is not equivalent to the Stanford work, because vendors choose which of the seven tasks to enter. In the February 2025 round Harvey entered six, Thomson Reuters entered four, vLex Vincent AI entered six, and LexisNexis withdrew from all but legal research and does not appear in the published report. When Vals separated legal research into its own October 2025 study, neither Thomson Reuters nor LexisNexis opted in, and Harvey, Legora, Luminance, Spellbook and Eve are all absent. Vals also discloses that it has a customer relationship with one or more participants.

    For e-discovery the position is starker and completely checkable. NIST's TREC Legal Track ran from 2006 to 2011 and stopped. The archive carries year pages through 2011 and nothing after. That reference corpus underpinned the technology-assisted-review validation literature courts leaned on when they approved predictive coding — and it has had no maintained successor for roughly fifteen years, over precisely the period in which the tools became generative. So when a vendor cites precision and recall, or documents per hour, or growth multiples, there is no neutral corpus those figures could have been measured against.

    Three numbers we refuse, named so you can refuse them too

    "AI will automate 44% of legal work." The number is real and the source is Goldman Sachs, March 26, 2023 — but it does not mean what it is quoted to mean. It measures task exposure to labour-saving automation, computed as an importance-weighted average over the O*NET task taxonomy for more than 900 occupations, aggregated to industry level. It is a desk exercise over a task list, not an observation of any law firm, and it is explicitly conditional on generative AI delivering on its promised capabilities. Goldman's own baseline for actual substitution is 7% of US employment, with 63% complemented and 30% unaffected, and the authors give a 15%–35% uncertainty band on exposure. Quote the 7% alongside the 44% or do not quote either.

    Utilisation and billable-hour-recovery statistics.The widely circulated figures on how little of a lawyer's day is billable derive from a vendor's own practice-management data — a vendor that is ranked in this very article. We could not obtain the methodology, and even if we could, its denominator is that vendor's customer base rather than a census of the profession. We print no utilisation figure and no "hours returned per lawyer per week" figure. Every one we encountered in this research was published by a seller, including one attributed to a vendor's own General Counsel.

    Per-seat prices for gated products.A per-seat figure circulates for Spellbook that Spellbook's own pricing page contradicts, and a range circulates for CoCounsel whose most-cited source is Spellbook — a direct competitor. Both are refused. The pricing cell in our table says "not publicly disclosed" for all ten products, because that is the truth.

    One more refusal, briefly, because it is the standard opening line of AI articles: the "95% of generative AI pilots fail" figure and the Gartner projection that a large share of agentic projects will be cancelled do not survive a citation check as evidence about your firm. The first rests on a small interview and conference-survey sample about custom-built tools; the second measured investment posture in a poll. Neither is a base rate you should plan against, and neither appears anywhere in our analysis.

    Everything below was checked on August 23, 2026.Re-check it yourself: open the vendor's trust centre, open its terms of service, open Companies House or SEC EDGAR, and open the pricing page. Those four tabs will confirm or refute every cell in the next section. If a cell has moved since publication, the vendor changed — not the method.

    The Comparison Table: Verifiable Attributes Only

    Every cell below is either a fact traceable to a public source or the literal words "not publicly disclosed". There is no accuracy column, no efficiency column and no score. Two patterns leap out of the table before you read any individual row, and both are more decision-useful than any performance claim would have been.

    Product (2026 name)Ownership, from public recordCertifications on the vendor's own trust pageNo-training commitment — where it is writtenPrice published?Independent evaluation?
    HarveyIndependent. USD 200M at an USD 11B valuation announced March 25, 2026, co-led by GIC and SequoiaSOC 2 Type 2, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001:2023, IRAP, AIUC-1, GDPR, CCPAIn the contract. Platform Agreement §11.8, effective January 9, 2026, binds Harvey and its subprocessorsNo — the pricing page returns 404Yes — VLAIR, February 2025, vendor-participatory; entered six of seven tasks
    CoCounsel LegalThomson Reuters. Casetext acquired for USD 650M cash, closed August 17, 2023Not publicly disclosed — we located no trust page evidencing SOC 2 or ISO for CoCounselNot found — no published contractual clause locatedNo — vendor publishes none; third-party figures refusedYes — VLAIR, February 2025; entered four of seven tasks, declined the October 2025 round
    LegoraIndependent. USD 550M Series D at USD 5.55B on March 10, 2026, led by Accel; USD 50M extension April 30, 2026 to USD 5.6B post-moneySOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001 (October 10, 2025, Prescient Security LLC), GDPRMarketing security page only — no equivalent clause in the published Security Policy effective September 1, 2025No — the pricing page returns 404None — absent from both VLAIR rounds
    Lexis+ with ProtégéLexisNexis Legal and Professional, a division of RELX. Never independentSOC 2 Type 1 and Type 2, SOC 3, ISO/IEC 27001 with SoA, ISO 9001, ISO 14001, ISO 22301, ISAE 3402, HIPAA, NIST CSF. No ISO 42001Published trust-centre statement; whether it is an MSA term could not be verifiedNo — vendor states pricing varies by organisation size, capabilities and content scopeYes — its predecessor Lexis+ AI was the Stanford study's highest scorer at 65% accuracy, April 2024
    LuminanceIndependent. USD 75M Series C on February 18, 2025, led by Point72 Private Investments. Companies House 09857705, Active, no insolvency filingsSOC 2 Type 2, ISO/IEC 27001:2022. No ISO 42001. Dedicated single-tenant instance per customerNone found — the published Master Hosted Agreement Cl. 10.1.3 reserves a perpetual right to use learnings from product usageNoNone
    SpellbookIndependent. Spellbook US Inc. (Delaware) and Dialog Enterprises Inc. (Canada). USD 50M Series B on October 9, 2025 led by Khosla; USD 40M RBCx debt facility March 4, 2026Self-asserted SOC 2 Type II, HIPAA, GDPR and “EU AI Act Compliant”. No ISO 27001, no ISO 42001In the contract. Terms of Service §4.1(b)(iv) and §4.2; customer owns Customer Data and OutputsNo — “custom pricing”; the circulating per-seat figure is contradicted by the vendor's own pageNone — absent from both VLAIR rounds
    Clio (with vLex Vincent AI)Independent and private. Acquired vLex for USD 1B, closed November 10, 2025; Series G USD 500M primary at USD 5B led by NEA, plus USD 350M debt led by Blackstone and Blue OwlSOC 1 Type 2, SOC 2 Type 2, GDPR, HIPAA, TX-RAMP. ISO 27001 not listed on Clio's own trust centre. No ISO 42001Not found — the trust centre's AI section carries no explicit no-training statementCould not verify — clio.com blocks programmatic fetch and secondary figures conflictYes — vLex Vincent AI in VLAIR February 2025, scoring 53.6%–72.7% and beating the lawyer baseline on three tasks
    EverlawEverlaw, Inc., a Delaware corporation. Private; no acquisition or ownership change found as of August 23, 2026. Series D USD 202M, November 2, 2021, led by TPGSOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, 27017, 27018, FedRAMP Moderate, GovRAMP Moderate, Cyber Essentials Plus, HIPAA. No ISO 42001In the contract, with a qualifier — no training “for general use”, alongside a broad licence to use case materials to improve the serviceNo — data-volume-based pricing described with no figuresNone — its only accuracy study is its own (7,737 documents, September 19, 2024)
    Relativity aiRRelativity ODA LLC, Chicago. Silver Lake-controlled, evidenced by board composition on Relativity's own leadership pageSOC 2 Type II, SOC 3, ISO/IEC 27001:2022, 27018, FedRAMP, IRAP PROTECTED, HIPAA, CSA CAIQ. No ISO 42001, no ISO 27701Principle only — the AI Principles page is explicitly a statement of principle, not a warrantyNo — and Relativity's own two pages disagree on whether aiR for Case Strategy is included or separately quotedNone — the frequently cited law-firm podcast is a discussion, not an evaluation
    DISCO (Cecilia)CS Disco, Inc., Delaware. Publicly traded, NYSE: LAW, Commission File No. 001-40624 — the only vendor here whose financials you can audit yourselfSOC 2 Type 2, ISO/IEC 27001, ISO/IEC 27701. No ISO 42001, no FedRAMPProcess commitment in the AI Principles; the Cecilia AI Platform product terms contain no training, retention or output warranty languageNo — DISCO publishes pricing pages containing no figuresNone — its published adoption study is vendor market research

    Corporate status, certifications, contract terms and pricing disclosure checked August 23, 2026. Cells marked as not found or not publicly disclosed record a gap in public disclosure, not evidence that a commitment does not exist privately.

    Pattern one: not one vendor publishes a price.All ten pricing cells read the same. Harvey's and Legora's pricing pages return 404. LexisNexis states in its own words that pricing varies by organisation size, capabilities required and content scope. Spellbook says custom pricing. DISCO publishes pricing pages that contain no figures at all. In a market where every seller gates price, the third-party numbers that fill the vacuum are worth exactly what their sourcing is worth — and for the two most-cited legal AI price points, that sourcing is a competitor and a contradicted blog.

    Pattern two: only three of fifteen hold ISO/IEC 42001. Harvey, Legora and Definely. That is the only certification in this market that speaks to how a vendor governs AI specifically, rather than how it governs information security generally. Twelve do not hold it — including LexisNexis, Relativity, DISCO, Everlaw, Clio, Ironclad and Spellbook, several of which market agentic AI hardest. Do not over-read the badge, though: Definely holds ISO 42001 and we could not find a no-training commitment anywhere in its published documents. A certification is a management-system attestation, not a confidentiality promise.

    The integration picture is the other half of the buying decision, and for a law firm it is frequently the deciding half. A tool that cannot see your document management system is a tool your associates will paste into, which is a confidentiality problem before it is a productivity one. Here the disclosure quality varies enormously — and the vendor with the best-documented list is not the one with the loudest agent marketing.

    ProductIntegrations named by the vendorPublic integration documentation?Standalone or suite-locked
    HarveyMicrosoft 365 including Word and Outlook; Intapp ethical-wall enforcement (July 23, 2026); LexisNexis content, evidenced by RELX Inc. appearing on Harvey's subprocessor listNo — no integrations documentation URL resolves. iManage and NetDocuments are not verifiable for HarveyStandalone; consumes LexisNexis content as a feature
    CoCounsel LegaliManage, NetDocuments, SharePoint, HighQ, DeepJudge, Smokeball, Box, Litify, Microsoft Word, Outlook, Teams, Claude, SupioYes — the deepest documented list in the set, on the vendor's own product pageSuite-locked; the value proposition is grounding in Westlaw and Practical Law
    LegoraWord and Outlook add-ins; MCP connectors; DeepJudge (August 18, 2026), Box (August 13, 2026) and Tinexta (July 20, 2026) named in newsroom itemsNo — no integration documentation URL and no Microsoft AppSource listing foundStandalone
    Lexis+ with ProtégéiManage, SharePoint, NetDocuments; Microsoft 365 via Lexis Create+; customer-held keys integrating AWS KMS, Azure Key Vault, Google Cloud KMS and HashiCorp VaultVendor-stated rather than documentedSuite-locked; inseparable from LexisNexis content licensing
    LuminanceWord plugin onlyNo — the homepage promises “a host of integrations” and names none. iManage, NetDocuments, SharePoint, Salesforce and DocuSign are unverified for LuminanceStandalone
    SpellbookiManage, OneDrive, Dropbox, SharePoint, Google Drive. iManage is confirmed by the partner, not only by the sellerYes — a published integrations page. Email, Slack and Salesforce appear on the homepage but not on that pageStandalone; runs inside Word and Google Docs
    Clio (with vLex Vincent AI)Clio Manage, Clio Grow, Clio Draft and Clio Work, paired with vLex Vincent AI. Disclosed subprocessors: Google Cloud, OpenAI, Anthropic, AWSCould not verify — clio.com blocks programmatic fetchSuite-locked; the AI layer requires a Clio Manage subscription
    EverlawAnthropic (Claude via MCP), Legora, Microsoft 365, Purview, OneDrive, SharePoint, Slack, Salesforce, Box, Dropbox, Google Drive and Vault, Asana, Jira, Zoom, Zendesk, ShareFileYes — a published integrations pagePlatform. No iManage, NetDocuments, Clio, Litify or Relativity connector documented
    Relativity aiRMicrosoft Azure OpenAI, Model Context Protocol, Relativity App Hub, native collection from Claude, ChatGPT and Gemini enterprise accountsPartial — DMS connector documentation could not be reached, so we print no DMS claimFully suite-locked; there is no standalone aiR
    DISCO (Cecilia)Microsoft 365, Google Workspace, Slack, Box, Dropbox, Code42; Active Directory, Google Directory, Workday, SAP SuccessFactors. Named LLM providers: OpenAI, L.L.C. and WriterYesPlatform. No iManage, NetDocuments, Clio or Litify connector documented

    Integration claims are recorded at the strength of their evidence: vendor documentation, vendor marketing page, or partner confirmation. Where we could not reach documentation, we print no claim rather than repeating one.

    Read those two tables together and the shape of the market is clear. The vendors with the deepest firm-side integration documentation — CoCounsel Legal, Spellbook, Definely — are not the vendors with the strongest AI-specific certification. The vendors with the strongest certification posture — Harvey, Legora — publish the least about how they connect to your DMS. And the two e-discovery platforms with the most mature security programmes, Everlaw and Relativity, document no law-firm DMS connector at all, because they were built as evidence platforms rather than as practice tools. There is no product here that is strong on every axis, which is a more honest finding than a ranked score would have produced.

    The Ten, 1–5: Harvey, CoCounsel, Legora, Protégé, Luminance

    Each entry below states what the product does, what is verifiable, what is not disclosed, who it fits, who it does not, and who owns it. The ordering reflects the verifiable-attribute picture, not a performance judgement — there is no performance judgement available to make.

    1. Harvey — the strongest disclosure position in the set

    What it does.Harvey is a standalone legal AI platform whose 2026 surface includes Harvey Agents, Vault, Knowledge, Spaces, Command Center, Contract Intelligence and Harvey Mobile, with Harvey II launched on August 18, 2026 and Harvey Tenet as an in-house post-trained legal model. Its own description of the agent model is delegated overnight batch work returning a first-pass review, inside Spaces where, in Harvey's words, tasks can be assigned to a lawyer or an agent. That is a delegated-task agent inside a structured review loop, which is a fair characterisation and a more modest one than several competitors make.

    What is verifiable. More than for any other vendor here. Ownership: independent, with $200 million raised at an $11 billion valuation announced March 25, 2026, co-led by GIC and Sequoia. Certifications on its trust centre: SOC 2 Type 2, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001:2023 (announced June 5, 2026), IRAP, AIUC-1, GDPR, CCPA, VPAT and WCAG. And the no-training commitment is contractualPlatform Agreement §11.8, effective January 9, 2026, reads: "Harvey will not train any AI models using Your Content or Customer Data. Subprocessors will not train any AI models using Your Content or Customer Data." That is the strongest no-training language in this roster, and it binds the subprocessors too. Data residency: EU/Switzerland or Australia processing is offered, with storage tied to the order-form region and audit-log retention of one to ten years.

    What is not disclosed. Price — the pricing page returns 404. Integration documentation — no integrations documentation URL resolves, so although Microsoft 365 including Word and Outlook is confirmed, Intapp ethical-wall enforcement was announced July 23, 2026, and RELX Inc. appears as a listed subprocessor for the Ask LexisNexis feature, iManage and NetDocuments are not verifiable for Harvey and we do not claim them. One residency detail worth surfacing for EU firms: all subprocessors span US, EU, Switzerland and Australia except Anthropic, PBC, which is US only. A further funding round was reported in August 2026 at a higher valuation; it is unconfirmed and we do not state it.

    Who it fits. Firms with a procurement function that will actually read the Platform Agreement, and with enough matter volume to justify a platform rather than an add-in. Who it does not. A twelve-lawyer firm whose entire knowledge base lives in iManage and who needs a documented connector on day one. On independent evaluation, Harvey entered six of seven VLAIR tasks in February 2025 and led on five, with Document Q&A at 94.8% against a 70.1% lawyer baseline — and it lost Redlining to the lawyer baseline, 65.0% to 79.7%. We report that number specifically because it is the most informative one in the report and the least likely to appear in a vendor deck.

    2. CoCounsel Legal (Thomson Reuters) — the best-documented integrations, the thinnest published assurances

    What it does.An assistant grounded in Westlaw and Practical Law, sold as CoCounsel Legal — not Casetext, which is dead as a brand, and not CoCounsel 2.0, which was the February 2025 name it entered VLAIR under. A next-generation version rebuilt on Anthropic's Claude Agent SDK entered early access in June 2026 with US general availability planned for August 2026; that is trade-press sourced and we could not confirm GA, so treat it as planned rather than shipped.

    What is verifiable.Ownership is settled and documented: Thomson Reuters closed its acquisition of Casetext, Inc. on August 17, 2023 for $650 million in cash, confirmed in the company's own release and in its SEC Form 6-K. Integrations are the deepest documented list in this set, published on the vendor's own product page: iManage, NetDocuments, SharePoint, HighQ, DeepJudge, Smokeball, Box, Litify, Microsoft Word, Outlook, Teams, Claude and Supio. For a firm whose work already lives in a DMS, that list is a genuine and checkable advantage.

    What is not disclosed. Two significant gaps. First, we could not locate a Thomson Reuters trust page evidencing SOC 2 Type II or ISO certification for CoCounsel. That is a gap in public disclosure rather than evidence of absence — a company of that size assuredly holds attestations — but a Rule 5.3 diligence file needs the document, not the inference, so ask for it. Second, no published contractual no-training clause could be found. Do not assume one exists; ask for it in the order form. Pricing is not published by the vendor, verified twice; the third-party range in circulation is refused, and it is worth knowing that one of its most-cited sources is a competing vendor.

    Who it fits. Firms already committed to Westlaw and Practical Law, for whom the grounding is the product. Who it does not.Firms trying to reduce content-suite dependence — this is the most suite-locked product in the set by design. On evaluation: CoCounsel entered four of seven VLAIR tasks in February 2025, took the top Summarization score at 77.2% and the highest four-task average at 79.5%, opted out of Redlining, Transcript Analysis and EDGAR Research, and declined the October 2025 legal research round. Thomson Reuters's own claims — a million users across 107 countries, 76% of surveyed users agreeing quality improved, a 33% average reduction in time spent — are self-reported and we do not treat them as neutral fact.

    3. Legora — the loudest agentic claim, and no independent evaluation at all

    What it does.Legora, renamed from Leya in February 2025, sells Legora aOS with Agent, Monitors, Lists, a Word add-in, an Outlook add-in, Editor, Tabular Review, Workflows, Legal Research and Portal. Its positioning is the most committedly agentic in the roster: the vendor describes end-to-end execution of complex legal work in which the Agent plans, executes, reviews and delivers, and its CEO has said the breakthrough is AI that does not just assist but executes autonomously. Architecturally that is a real agent design. The autonomy claim itself is the vendor's, and it has never been independently tested.

    What is verifiable.Independence and scale: a $550 million Series D at $5.55 billion on March 10, 2026 led by Accel, extended by $50 million on April 30, 2026 to a $600 million round at $5.6 billion post-money, adding Atlassian and NVIDIA's NVentures. Certifications: ISO/IEC 27001:2022, SOC 2 Type 2 and ISO/IEC 42001, achieved October 10, 2025 and certified by Prescient Security LLC. Data handling: Azure, region-bound per agreement, processing restricted to the EU or GDPR-compliant jurisdictions, AES-256 at rest, TLS 1.2+, 72-hour breach notification, and permanent deletion of all data and dedicated storage at contract end.

    What is not disclosed, and the one thing to fix in procurement. Price — the pricing page returns 404. Integration documentation — none; DMS integrations and MCP connectors are described generically, and DeepJudge, Box and Tinexta appear only in newsroom items. And the important one: Legora's marketing security page states plainly that it will not use your data to train or fine-tune any AI models, but the contractual Security Policy effective September 1, 2025 contains no equivalent clause. That is not an accusation of bad faith; it is a drafting gap, and the fix is one sentence in your order form. Ask for it.

    Who it fits. Firms that want the most aggressive agent architecture available and have the governance maturity to bound it. Who it does not. Anyone who needs third-party evidence before deploying autonomy — Legora appears in neither VLAIR round, and at a $5.6 billion valuation that absence is material and worth saying out loud.

    4. Lexis+ with Protégé (LexisNexis / RELX) — the naming fact most 2026 lists get wrong

    What it does. On February 24, 2026 LexisNexis made Lexis+ with Protégé generally available in the US, fully replacing Lexis+ AI. Protégé is the AI assistant layer embedded across LexisNexis solutions rather than a standalone product. A May 7, 2026 expansion added Protégé Work, Protégé Agentic Drafting, Protégé Workrooms, Protégé Vault, bring-your-own-key encryption and Shepard's Verify trust markers.

    What is verifiable, including the agent question. This is the clearest documented answer to "is it really an agent?" anywhere in the roster, and it is a nuanced one. At the February 2026 launch, trade press reported that Protégé did not feature autonomous agentic workflows. The May 2026 release routes a natural-language goal to a skill and presents a structured plan before executing; the product page describes approving the approach before agents carry out multi-step work. So: supervised agentic workflow, plan-then-approve. Marketing does use harder language — purpose-built drafting agents creating contracts, motions, briefs and deal documents — and that is the vendor's framing rather than a documented capability boundary. Certifications on the LexisNexis trust centre are extensive: SOC 2 Type 1 and 2, SOC 3, ISO/IEC 27001 with a Statement of Applicability, ISO 9001:2015, ISO 14001:2015, ISO 22301:2019, ISAE 3402, Cyber Essentials, HIPAA, NIST CSF, GDPR, CCPA, VPAT and WCAG — with coverage explicitly naming Lexis+ with Protégé. ISO/IEC 42001 is not listed, which is notable given the volume of agentic marketing.

    What is not disclosed.Price, in the vendor's own words: pricing varies based on factors such as the size of your organisation, specific capabilities required, and the scope of content access. Data residency and retention are not published. And the no-training position — the trust centre states plainly that LexisNexis never uses customer data to train its models — is a published policy whose contractual status we could not verify.

    Who it fits. Firms whose research spine is already LexisNexis, and especially those who want customer-held encryption keys, which is a genuinely differentiated 2026 feature. Who it does not.Firms trying to unbundle AI from content licensing — this is locked. On evaluation: its predecessor was the Stanford study's highest scorer at 65% accuracy in April 2024, LexisNexis withdrew from all but legal research in VLAIR's first round and does not appear in the published report, and it declined the October 2025 round. That is a consistent pattern of non-participation, stated neutrally.

    5. Luminance — the single most important procurement finding in the roster

    What it does. Six contract modules — Draft, Negotiate, Analyze, Comply, Investigate and Collaborate — plus the Ask Lumi assistant, following a January 27, 2026 platform update the company described as its largest in ten years. Honestly characterised, this is classic contract automation plus an LLM copilot, marketed with agent language. Luminance does say it uses agents to automate, expedite and enhance contract activity, but its own product pages describe augmentation and do not claim end-to-end autonomous execution. That makes it the weakest agentic claim among the ranked ten, which is worth knowing rather than holding against it.

    What is verifiable. Registry-confirmed: LUMINANCE TECHNOLOGIES LTD, company number 09857705, incorporated November 5, 2015 in Cambridge, status Active, with no insolvency filings. Funding: $75 million Series C on February 18, 2025 led by Point72 Private Investments; no valuation was stated and we do not infer one. Certifications: ISO/IEC 27001:2022 and SOC 2 Type 2 across security, availability and confidentiality, with each customer on a dedicated single-tenant instance and no co-mingling of data. Retention is specified: a 30-day post-termination retention period, after which Luminance deletes or destroys all copies of customer data including outputs, with nightly encrypted in-region backups kept at least fourteen days.

    Read this clause before you sign anything. Luminance's published Master Hosted Agreement, clause 10.1.3, states that "Luminance may retain and utilise on a perpetual basis the results of any usage or learnings of the Product to develop or improve the Product" — qualified only by an undertaking that no customer confidential information or personal data is contained in them. That is the opposite of a no-training commitment, and it is the single most consequential contractual difference in this roster. The necessary caveat: the published document is dated July 3, 2024 and may have been superseded. Treat this as as published, and confirm the current MSA with your rep before you draw a conclusion.

    What is not disclosed. Price. Integrations — the weakest disclosure in the set; the homepage promises a host of integrations and names none, and only the Word plugin is confirmed, so iManage, NetDocuments, SharePoint, Salesforce and DocuSign are all unverified for Luminance and we claim none of them. ISO/IEC 42001 is not claimed. There is one open corporate question we flag rather than answer: Companies House shows share allotments on May 12 and August 7, 2026, plus new Articles and allotment resolutions filed August 14, 2026 — consistent with a round closing, but no announcement exists and we do not assert one.

    Who it fits. Contract-heavy practices wanting deterministic automation with a single-tenant guarantee. Who it does not.Any firm whose clients impose outside-counsel guidelines with a no-training requirement, until the current MSA is confirmed. There is no independent evaluation, and the vendor's time-saving percentages — including one attributed to Luminance's own General Counsel — are self-reported and unaudited.

    The Ten, 6–10: Spellbook, Clio, Everlaw, Relativity, DISCO

    6. Spellbook — contractual confidentiality, and a compliance claim worth questioning

    What it does. A drafting and review copilot that lives inside Microsoft Word and Google Docs, with Spellbook Associate marketed as an AI agent for transactional legal work and Autonomous Contract Management in early access from June 2026. The base product is human-in-the-loop by design; the agentic layers are vendor-described and untested.

    What is verifiable. Two contracting entities are named in the terms — Spellbook US Inc., a Delaware corporation, for US customers, and Dialog Enterprises Inc., a Canadian federal corporation, for everyone else. Funding: a $50 million Series B on October 9, 2025 led by Khosla Ventures, plus a $40 million RBCx debt facility announced March 4, 2026 explicitly earmarked for acquisitions in a consolidating legal AI market. Integrations are published and one is partner-confirmed: iManage, OneDrive, Dropbox, SharePoint and Google Drive, with iManage listed on iManage's own technology-partner page rather than only on Spellbook's. And the confidentiality position is contractual: Terms of Service §4.1(b)(iv) states that customer data transmitted to third-party LLMs via the platform will not be used to train, improve or develop the AI models; §4.2(b) treats customer data as confidential information; §4.2(a) gives the customer ownership of both Customer Data and Outputs.

    What is not disclosed, and one claim to interrogate. Price is custom, and the widely repeated per-seat figure is contradicted by Spellbook's own page — do not use it. Retention period is not stated; data centres are in Canada and the US. Neither ISO 27001 nor ISO 42001 is claimed. And the security page asserts SOC 2 Type II, HIPAA, GDPR and "EU AI Act Compliant" — that last is a self-assertion with no certifying body behind it, because no such certification scheme exists. It is a useful example of a pattern rather than a reason to disqualify: when a vendor lists a regulation alongside genuine attestations, ask which auditor issued it.

    Who it fits. Transactional practices that want AI in the drafting surface without changing platforms, and firms whose outside-counsel guidelines require a written no-training term. Who it does not. Litigation-led firms — this is a contracts product. Note also that email, Slack and Salesforce appear on the homepage as data sources but not on the integrations page, and secondary sources claim NetDocuments that the vendor does not. There is no independent evaluation.

    7. Clio with vLex Vincent AI — the acquirer, not the acquired

    What it does.Practice management with an AI layer over the firm's own Clio data — summarising, drafting and answering with the user in the loop — now paired with vLex's Vincent AI for legal research alongside Clio Manage, Clio Grow, Clio Draft and Clio Work. No autonomous-agent claim appears in any Clio-owned source we could reach, which is itself a data point.

    What is verifiable. Clio acquired vLex for $1 billion in a deal that completed November 10, 2025, alongside a Series G of $500 million primary led by NEA at a $5 billion valuation and a $350 million debt facility led by Blackstone and Blue Owl. Correct a common error while you are here: some secondary sources date that $5 billion Series G to 2024. The primary source dates it to November 2025. Vincent AI was retained rather than shut down; vLex now operates as part of Clio. Certifications on Clio's trust centre: SOC 1 Type 2, SOC 2 Type 2, GDPR, HIPAA and TX-RAMP, with the 2025 SOC 2 Type II report covering June 1, 2024 to May 31, 2025. Disclosed subprocessors include Google Cloud, OpenAI, Anthropic and AWS.

    What is not disclosed. More than we would like, because clio.com blocks programmatic fetch. ISO 27001 is not listed on Clio's own trust centre despite secondary claims that it holds it; ISO 42001 is not listed either. No explicit no-training statement appears in the trust centre's AI section, and contractual terms were unreachable — a real gap relative to Harvey and Spellbook. Pricing could not be verified from the vendor and secondary figures conflict badly, so treat every Clio price you see as unverified. Even the AI product name is unsettled: one 2026 source reports the AI slot renamed on the pricing page while another still calls it Clio Duo, and we could not resolve it from Clio's own site.

    Who it fits. Small and midsize firms already running Clio, which is a very large population, and who want research and drafting adjacent to the matter record rather than in a separate tab. Who it does not. Firms not on Clio Manage — the AI layer requires the subscription underneath it. On evaluation, vLex Vincent AI is one of only four products in this entire market ever independently evaluated: in VLAIR February 2025 it scored 53.6%–72.7% and surpassed the lawyer baseline on three tasks. One relationship to disclose in the interests of the same standard we apply to vendors: Clio is an investor in Definely, which appears in the next section.

    8. Everlaw — the most interesting genuine agent story is not Everlaw's own

    What it does.An e-discovery and litigation platform whose AI suite, EverlawAI, covers Deep Dive, Coding Suggestions, Writing Assistant, Review Assistant, Predictive Coding, Clustering and AI Translations, with Storybuilder for narrative work. Predictive Coding and Clustering are classic machine learning, not agents, and Everlaw's product pages avoid the word agent — which is refreshing and accurate.

    The exception is worth its own sentence. On May 12, 2026 Everlaw shipped an Anthropic Model Context Protocol integration enabling multi-step work driven from Claude. The right way to describe that is precise: the agent is Claude; Everlaw is the tool surface.It is not an autonomous Everlaw agent. The permission model is the part that matters for a firm — Claude can access only the Everlaw data available to the user's authenticated environment and permissions, which is exactly the blast-radius posture a matter-scoped deployment needs.

    What is verifiable. Entity: Everlaw, Inc., a Delaware corporation, named in its own terms of service; headquartered in Oakland with offices in London, New York and Washington. Certifications are the broadest of the e-discovery three: SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, 27017 and 27018, FedRAMP Moderate, GovRAMP Moderate, Cyber Essentials Plus, HIPAA and GDPR/CCPA. Integrations are documented and include Anthropic via MCP and Legora, plus connectors for Microsoft 365, Purview, OneDrive, SharePoint, Slack, Salesforce, Box, Dropbox, Google Drive and Vault, Asana, Jira, Zoom, Zendesk and ShareFile.

    What is not disclosed, and the qualifier to read. Everlaw's no-training commitment is contractual but hedged: it will not use input or output to train or fine-tune a generative AI model for general use through the service, while separately retaining a broad licence to use case materials to support, manage and improve the service. That gap is real and it is not an unqualified no-training promise, though its published framework — working only with LLM providers committing to zero data retention — is a genuine control. Pricing is volume-based with no figures. Data residency and retention are not published. No iManage, NetDocuments, Clio, Litify or Relativity connector is documented. Ownership is private with no acquisition found as of August 23, 2026, which is absence of news rather than positive proof; the last round on record is a $202 million Series D on November 2, 2021 led by TPG. Its only accuracy study is its own, on 7,737 documents, and we do not treat a vendor marking its own homework as evidence.

    Who it fits. Litigation practices with government or regulated-client work where FedRAMP Moderate matters. Who it does not. Firms wanting AI inside their DMS-based drafting workflow.

    9. Relativity aiR — markets agentic, disclaims autonomy, and both halves are true

    What it does. aiR Assist, aiR for Review, aiR for Privilege, aiR for Case Strategy and aiR for Data Breach Response, plus Contract Review and Legal Hold, all inside RelativityOne. Relativity claiR — conversational command over legal data — was announced August 12, 2026 with general availability planned for early 2027, so it is not something you can buy today.

    The agent question, quoted from both sides. Relativity describes aiR as an agentic system that can eliminate repetitive, time-consuming cognitive tasks — and in the same voice states that humans are in the loop and that fully autonomous agents without human oversight do not belong in legal tech. Read together, that is a multi-step LLM pipeline with mandatory human review: a supervised copilot expressed in agent vocabulary. Its MCP layer is deliberately fenced — it can manage matters, workspaces, users and permissions, and excludes data exports and consequential AI decisions. That fencing is good design and worth asking every other vendor to match.

    What is verifiable. Entity: Relativity ODA LLC, Chicago. Ownership: Silver Lake-controlled, and we say that on structural evidence rather than press — Relativity's own leadership page lists Joe Osnoss as Chairman of the Board and a Managing Partner and Managing Director of Silver Lake, with multiple Silver Lake executives as directors. We print no date or valuation for that transaction, because Relativity's own announcement is undated and the figures in circulation are secondary only. Certifications: SOC 2 Type II, SOC 3, ISO/IEC 27001:2022 and 27018, FedRAMP as stated on that page, IRAP PROTECTED, HIPAA and CSA CAIQ. No ISO 42001 and no ISO 27701.

    What is not disclosed. The no-training position is a principle, not a warranty: the AI Principles page is explicitly a statement of principle, and the closest language describes data minimisation in the models Relativity trains — which describes howit trains, not a promise not to. That is materially weaker than Everlaw's, Ironclad's or Wordsmith's published positions. Pricing carries an inconsistency between Relativity's own two pages on whether aiR for Case Strategy is included in RelativityOne or separately quoted; base pricing is not published. Data residency and retention are not published. DMS connector documentation could not be reached, so we print no DMS claim at all. It is fully suite-locked — there is no standalone aiR — and there is no independent evaluation. The law-firm podcast frequently cited as validation is a discussion with no dataset, no metrics and no disclosed commercial relationship; it is not an evaluation and should not be cited as one.

    Who it fits. Firms already standardised on RelativityOne with large review populations. Who it does not. Anyone wanting to buy the AI without the platform, or needing a contractual training prohibition.

    10. DISCO (Cecilia) — the only vendor whose financials you can audit yourself

    What it does.DISCO Hold, DISCO Request, DISCO Ediscovery and DISCO Case Builder, plus the Cecilia AI platform and Auto Review. Cecilia's shipping capabilities are Q&A, Auto Review, document summaries, deposition summaries, single-document Q&A and definitions. Auto Review is a generative classifier, not an agent.

    Why it earns a place on verifiable grounds alone. CS Disco, Inc. is still publicly traded on the NYSE under the ticker LAW, verified against primary SEC filings rather than press: the Form 10-Q for the quarter ended June 30, 2026, filed August 5, 2026, Commission File No. 001-40624, with 64,919,765 shares outstanding as of July 31, 2026 and no going-private or change-of-control item in any 2026 8-K. Q2 2026 revenue was $43.1 million, up 13% year over year, with software revenue of $36.8 million, a GAAP net loss of $8.7 million, adjusted EBITDA of $(3.4) million, FY2026 guidance of $172.0–179.0 million and 354 customers above $100,000 of trailing-twelve-month revenue. Ongoing stockholder litigation is disclosed as an excluded expense. No other vendor in this roster can be checked that way, and for a firm signing a multi-year platform commitment, auditable solvency is a real ranking attribute rather than a trivia item.

    What is not disclosed, and one claim not to repeat. Agentic Cecilia AI was announced on February 9, 2026 as an autonomous multi-step reasoning engine available later in 2026 at no additional cost. We found no general-availability confirmation, so do not write that it is shipping— and note that DISCO's own AI Principles undercut the autonomy framing, stating that AI capabilities cannot replace lawyers and must be designed to support the exercise of legal judgement. The no-training position is a process commitment in those principles — a rigorous vendor selection process designed to prevent client data training a vendor's model for general use — and the Cecilia AI Platform product terms contain no training, retention or output warranty language at all. That is the weakest formulation among the e-discovery three. Named LLM providers are OpenAI, L.L.C. and Writer, alongside Pinecone, Snowflake, AWS and Azure. Certifications: SOC 2 Type 2, ISO 27001 and ISO 27701; no ISO 42001 and no FedRAMP. Pricing pages carry no figures. Retention is not published. There is no independent evaluation, and the DISCO adoption study frequently cited is vendor market research.

    Who it fits. Litigation teams wanting usage-based e-discovery with a publicly auditable counterparty. Who it does not. Transactional practices, and firms needing a law-firm DMS connector — none is documented.

    Five We Verified but Did Not Rank — and the One We Refused

    Fifteen vendors passed our corporate verification and one did not, so there was no need to pad the list — and no excuse to write any entry from memory. Five verified vendors sit outside the ten either because they solve a narrower problem or because they are built for in-house legal rather than for a firm. They are worth knowing about, and in two cases they are better answers than anything in the ten.

    Definely — the best standalone drafting add-in, and the least over-marketed vendor here

    Read, Proof, Cascade, Vault and Enhance, delivered entirely as a Microsoft Word add-in. It lives in the drafting surface rather than in a review platform: surface a defined term or cross-reference inline without leaving the page, proof automatically for broken cross-references and inconsistent defined terms, trace what a mark-up breaks, search precedent over the firm's own indexed bank, and interrogate a document in natural language with clause-level citations. Registry-verified as DEFEYENE LEGAL SOLUTIONS LIMITED, company number 10721979, Active, incorporated April 12, 2017. Its trust centre carries ISO/IEC 27001:2022, SOC 2 Type 2 re-certified October 28, 2025, Cyber Essentials and ISO/IEC 42001:2023, making it one of only three holders across the whole roster. It names Microsoft Word, iManage, NetDocuments and SharePoint — on paper the strongest law-firm DMS story of the newer entrants, though named on a marketing page with no technical documentation URL behind any of them.

    Two things stop it going higher, and one is a genuine caution. Its product pages describe Enhance as a legal AI assistant and never use the word agent — only its Series B release calls it a multi-agent system — so if you are shopping for agents, this is not one, and the company is admirably honest about that. More materially: despite ISO 42001, we could not find a no-training commitment anywhere — not in the trust centre, not in the privacy policy, not in the terms of use. And its published processing jurisdictions include Belarus alongside Lithuania, Sweden, the UK and the US, which any buyer with data-sovereignty constraints should surface early. Funding: $30 million Series B on June 9, 2025 led by Revaia, $40 million total, with Clio among the investors — a relationship we disclose because Clio is ranked above.

    Eve — the plaintiff-side specialist, with a compliance page weaker than its homepage

    Eve is a Butler Labs, Inc. company, independent, having raised a $103 million Series B on September 30, 2025 led by Spark Capital at a valuation over $1 billion. Its workflow is plaintiff-side end to end: intake and lead answering, medical records and bills extraction, medical chronologies, demand-letter drafting, discovery, deposition summarisation, settlement analysis and firm dashboards. In January 2026 it announced autonomous agents for task execution, an AI Auditor and an AI Analyst, including nightly caseload review. Structurally that is records ingestion, structured extraction and templated generation on a schedule, and there is no independent verification of autonomous operation.

    The reason it is a sidebar rather than a ranked entry is a disclosure inconsistency every buyer should be able to spot. The homepage claims SOC II Type 2 certification and HIPAA compliance; the security page says only that the information security programme follows the criteria set forth by the SOC 2 Framework — following criteria is not holding an attestation — and HIPAA is not mentioned on the security page at all. There is no trust portal, no ISO 27001 and no ISO 42001. The no-training claim is marketing-only and carries a hedge worth reading twice: data is never used to train shared models, which does not on its face preclude firm-specific tuning. Clio integration is documented on both sides; Filevine, Litify, SmartAdvocate and GrowPath are secondary. All data is hosted on AWS in the United States; retention is unspecified. If you are a plaintiff firm, Eve is genuinely the most workflow-complete option in its niche — go in with those questions written down.

    StrongSuit, Ironclad and Wordsmith — right tools, wrong buyer, or too little published

    StrongSuit is the vendor most likely to be miscited in 2026, because it was called Callidus Legal AI until November 12, 2025 and its Crunchbase and CB Insights slugs still say so. It is not shut down and not acquired: StrongSuit 2.0 launched July 9, 2026. The product is litigation-first — precedent research over a proprietary US case-law database of over 10 million cases, element-by-element outlines, automated validation that cited cases remain good law, and an oral-argument simulator. It is out of the ten for one reason: we could not verify its compliance posture, its pricing or even its legal entity name, because strongsuit.com returns 403 to programmatic fetch and no trust page could be found. Its only third-party recognition is an awards programme, which is submission-based and is not testing.

    Ironclad has the clearest genuine multi-agent architecture in this entire research set — Jurist drafts, redlines against a company playbook, scores risk and negotiates, now inside Microsoft Word, with routing and approval gates constraining what actually ships. Its AI Addendum, effective April 20, 2026, is the most precisely drafted document in the roster: Ironclad enables zero data retention where available and prohibits each AI subprocessor from training on customer data, but may itself train on customer data where the customer opts in, receiving a perpetual, irrevocable, royalty-free right to do so. So do not write that Ironclad does not train on customer data — write that third-party training is prohibited and first-party training is opt-in. It is out of the ten because of one verified absence: iManage, NetDocuments and SharePoint do not appear on its integrations page. Ironclad is built for in-house legal and procurement stacks, not for firm DMS stacks, and for a law-firm buyer that is decisive.

    Wordsmith is the same story with a sharper edge: it describes itself as the legal operations platform for in-house teams, structured Receive, Route, Resolve, Record, with requests arriving from the business by Slack, email and Teams. It is registry-verified as WORDSMITH AI LTD., company number 15250293, Active, Edinburgh-based and registered in England and Wales, with a $70 million Series B on June 3, 2026 and a $14 million extension on August 5, 2026. It has the most unambiguous no-training wording anywhere in this market — it does not train on your data, full stop, with a contractual zero-data-retention commitment with its AI providers — though the underlying DPA is not public, so that rests on the vendor's assertion. It holds SOC 2 Type II and GDPR; ISO 27001 is in progress, so do not report it as certified. Its EU data residency default is the best-published position of any vendor we reviewed. It is simply not a law-firm tool.

    The vendor most lists still include, and why it is not on ours. Robin AI appears on virtually every 2026 legal-AI listicle. We do not rank it, and the reason is the best illustration in this vertical of why a roster must be re-verified rather than copied.

    Here is what is uncontested and structural. In December 2025, Scissero acquired Robin AI's managed-services arm of roughly seventy-five people, price undisclosed. In January 2026, Microsoft acqui-hired the engineering team into its Word organisation, explicitly without buying the company or the product. The engineering team is at Microsoft and the services team is at Scissero. That alone tells a buyer that the product they would be sold today is not the product that team built.

    Trade press — Artificial Lawyer and Legal IT Insider in January 2026, with earlier reporting in Legal Cheek and The Lawyer — additionally reported a roughly $50 million round collapsing in October 2025, about a third of staff laid off, and an HMRC winding-up petition filed in early November 2025. We attribute all of that to those outlets rather than asserting it ourselves, and we note the status precision that matters here: a winding-up petition is a filed step, not an outcome.We are not in a position to characterise the company's financial condition and we do not.

    And now the detail that makes the whole argument. Companies House still lists ROBIN AI LIMITED, company number 11400135, as "Active" — no insolvency, liquidation, administration or strike-off filing, a share allotment filed March 11, 2026 and a confirmation statement on March 24, 2026. It also shows the registered office moved to the care of one of its own venture investors in December 2025, accounts overdue, and zero active persons with significant control. The website still loads and still markets the product; its footer copyright ends in 2025, its pricing page 404s, and its trust centre subdomain no longer resolves at all.

    The lesson for a managing partner is not about one company. A register said one thing, the trade press said another, and the product page said a third — and a listicle that checked only the product page would have ranked it. If your shortlist came from an article, open Companies House or SEC EDGAR for every name on it before you take a meeting. That takes about twenty minutes and it is the single highest-yield diligence step available to you.

    The Binding Constraint: Duties You Cannot Delegate

    An AI agent may draft, research, extract, summarise and queue; a licensed lawyer must review, verify and sign. That boundary is not a best practice — it is the rule, and in California it is now written specifically about agents. No product decision in this article matters as much as this section, because the constraint binds identically regardless of which vendor you choose.

    Start with the baseline. ABA Formal Opinion 512, issued by the Standing Committee on Ethics and Professional Responsibility on July 29, 2024, is the profession's reference text on generative AI. Its opening summary is the whole duty set in one sentence: lawyers using these tools must fully consider their obligations of competence, confidentiality, communication, supervision of employees and agents, advancing only meritorious contentions, candour toward the tribunal, and reasonable fees.

    "a lawyer's reliance on, or submission of, a GAI tool's output—without an appropriate degree of independent verification or review of its output—could violate the duty to provide competent legal representation as required by Model Rule 1.1."

    ABA Formal Opinion 512, “Generative Artificial Intelligence Tools” (July 29, 2024)

    Read the calibration alongside it, because 512 is more practical than its reputation suggests and this passage is the most operationally useful sentence in the opinion. It expressly contemplates sampling-based validation: if a lawyer uses a tool to review and summarise numerous lengthy contracts, the lawyer would not necessarily have to manually review the entire set to verify the results, if the lawyer had previously tested the tool's accuracy on a smaller subset by manually reviewing those documents, comparing them to the tool's summaries, and finding the summaries accurate. That is a workable protocol you can write into a firm policy — and it is the difference between a defensible deployment and a theatrical one.

    On confidentiality, 512 is stricter than most firms have yet operationalised: because many self-learning tools are designed so their output could lead directly or indirectly to disclosure of information relating to a client's representation, a client's informed consent is required before inputting such information — and merely adding general boiler-plate to engagement letters purporting to authorise GAI use is not sufficient. It also sets a baseline every lawyer should recognise as a work instruction: read and understand the terms of use, privacy policy and related contractual terms of any tool you use, or consult someone who has.

    And on supervision, Rules 5.1 and 5.3 turn vendor diligence into an ethical duty rather than a procurement preference. Managerial lawyers must establish clear policies on permissible use; supervisory lawyers must make reasonable efforts to ensure compliance. 512 then applies the cloud-and-outsourcing checklist to AI providers directly: reference checks and vendor credentials, understanding security policies and protocols, confidentiality agreements, understanding the vendor's conflicts-check system to screen for adversity among firm clients, and the availability of a legal forum for relief under the vendor agreement. That paragraph is, in effect, the specification for the comparison table above.

    Now the most on-point source that exists for an agents article. The State Bar of California's 2026 Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law states in its own words that it "replaces the 2023 version and, at the request of the California Supreme Court, addresses the unique challenges presented by the use of agentic AI." A state supreme court asked its bar to write about agents specifically. Nothing a vendor publishes carries that weight.

    Its definition of agentic AI is better than any vendor's: systems that can autonomously perform tasks or workflows without human prompting, built not just with multistep functionality but able to pursue goals, plan, select tools and execute tasks without immediate human intervention — with examples including pleading revisions across multiple iterations, preparing discovery responses, coordinating review of documents, and autonomously facilitating client intake. If you want a working definition to hold vendors against, use that one.

    "Lawyers must not deploy agentic systems in a manner that allows the system to make substantive legal determinations, communicate legal advice, prepare and file pleadings, or otherwise act in a representative capacity without meaningful lawyer supervision and review."

    State Bar of California, COPRAC — 2026 Practical Guidance

    The guidance adds three things a firm should build directly into policy. First, autonomy does not dilute duty: this autonomy does not satisfy a lawyer's duty to exercise independent judgment, nor does it alter existing ethical obligations, and professional judgment cannot be delegated to AI. Second — and this is the scaling principle the boundary table below is built on — the greater the degree of autonomy afforded to an AI system, the more important it is for a lawyer to implement supervisory controls and verification mechanisms.Oversight is not a fixed overhead; it scales with what you let the system do. Third, on filings specifically: where agentic AI is used in connection with court filings, no document may be transmitted to the court without lawyer review and approval, and lawyers must not permit AI systems to autonomously file documents, communicate with the court, or make representations on the lawyer's behalf.

    The confidentiality passage is the one that should change your architecture. Agentic systems may be configured with persistent or automated access to email, messaging platforms, document management systems, knowledge bases, client files and calendaring systems, raising acute confidentiality considerations — and unrestricted or poorly configured agentic systems may unintentionally disclose confidential information across different matters and even expose privileged material. The guidance then draws the hard line: a lawyer must not deploy an agentic system in a manner that permits autonomous external transmission of client information, including automated communications, filings or data transfers, without appropriate safeguards and human review.

    One sentence in that document justifies this entire article, and it is worth pinning above a procurement desk: "Reasonable efforts require more than reliance on generalized marketing assurances."

    There is a conflicts angle most rankings miss entirely. ABA 512 cites a joint Pennsylvania and Philadelphia bar opinion warning that because large language models continue to develop, some without safeguards similar to those already in use in law offices such as ethical walls, they may run afoul of Rules 1.7 and 1.9 by using information developed from one representation to inform another. That is precisely why Harvey's July 2026 Intapp integration for ethical-wall enforcement is a more interesting feature than most of the agent marketing around it.

    The record of what happens when the verification duty is skipped is now large, and it needs to be quoted carefully. The AI Hallucination Cases database, maintained by Damien Charlotin, a research fellow at HEC Paris's Smart Law Hub, records decisions where a court or tribunal has explicitly found or implied that a party relied on hallucinated content. It expressly does not track the wider universe of all fake citations in filings. As of August 23, 2026 it holds 1,955 cases worldwide and 1,344 in the United States.

    The honest arithmetic, which most articles get wrong. Of the 1,344 US cases, 801 involve self-represented litigants and only 516 involve lawyers. Quoting the 1,955 worldwide total as a lawyer statistic overstates it roughly fourfold. Use the lawyer figure — it is still large and still accelerating: 207 US lawyer cases in all of 2025, and 293 in 2026 through August 23. Of those US lawyer cases, 153 carry a monetary penalty and 108 a professional sanction. The originating case is Mata v. Avianca, decided in the Southern District of New York on June 22, 2023, where a submission included at least six non-existent decisions with fabricated quotations and internal citations, and the court imposed a $5,000 fine on the lawyers and their firm.

    The finding that makes this relevant to a product ranking is that twenty-five cases in the database name a commercial legal-research AI product rather than a consumer chatbot. Before you read that table, read the two caveats that must travel with it, because a ranking that cites the tracker against a vendor without carrying the vendor's dispute is not citable. First, the database's own disclaimer: the mention of a specific tool does not necessarily mean that tool was responsible for the hallucinations in question — the tool named is the tool the sanctioned party said they used. Second, Thomson Reuters investigated and states that the errors did not originate in either Westlaw or CoCounsel, and that dispute is recorded against every one of its entries.

    DateCaseCourtTool named by the sanctioned partyOutcomeVendor disputed the attribution?
    2025-05-06Lacey v. State Farm General InsuranceC.D. Cal.CoCounsel, Westlaw Precision, Google GeminiBriefs struck; $31,100 in sanctions jointly against two firmsYes
    2025-09-05Anthony C. Hill v. Workday, Inc. (1)N.D. Cal.CoCounselOrder to circulate the decision within the firm; CLEYes
    2026-01-26Lifetime Well LLC v. IBSpot.com Inc.E.D. Pa.Lexis+ AI; LexisNexis Protégé$4,000 sanction; order to share the opinionNo
    2026-03-10Cartagena v. Dixon, Blackburn & T.A. Blackburn Law (1)S.D.N.Y.Protégé (LexisNexis)Bar referralNo
    2026-03-31Heimkes v. Fairhope Motorcoach Resort COAS.D. Ala.CoCounsel (Westlaw)Reprimand; bar referral; adverse costs of roughly $55,597Yes
    2026-04-03United States v. Farris6th Cir.Westlaw CoCounselCounsel disqualified with no compensation; briefs locked; bar referralYes
    2026-04-28Anthony C. Hill v. Workday, Inc. (2)N.D. Cal.CoCounselAdmonishment; $1,001 fine; four hours of live CLEYes
    2026-04-28Tekoma Chaney v. Transdev ServicesC.D. Cal.LexisNexis+ (Protégé)Monetary sanction; reporting to other courtsNo
    2026-05-19Chakma v. Sushi Katsuei, Inc.S.D.N.Y.LexisNexis AIMonetary sanctionNo
    2026-07-14In re Rosslyn2016, LLCS.D. Tex. (Bankr.)Westlaw PrecisionCivil contempt; CLE; adverse costs of roughly $29,877Yes

    Selected US entries naming a commercial legal AI product, from the AI Hallucination Cases database as of August 23, 2026. Sanctioned, struck, disqualified, referred and warned are different outcomes; each is stated as the record shows it. Vendor dispute column records Thomson Reuters's stated position, which appears on twelve records in the database.

    Even with both caveats fully carried, the operational point stands and is worth stating plainly to your partnership: buying a professional-grade legal AI product does not discharge the verification duty, and courts have sanctioned lawyers who assumed it did.That is not an argument against these tools. It is an argument for treating the verification step as billable, staffed work rather than as something the subscription bought you. And it is the reason ABA 512's footnote citing the Stanford study — the profession's ethics regulator relying on the independent evaluation — is the most quotable pairing in this whole field.

    One procedural note with a status caveat, because standing orders are amended and withdrawn. The peer-reviewed Stanford paper records that as of May 2024, more than twenty-five federal judges had issued standing orders instructing attorneys to disclose or limit AI use in their courtrooms. We could not verify a current 2026 count and do not state one; nor could we confirm that one frequently cited certification order remains in force on its court's current requirements page. Both ABA 512 and the California guidance tell lawyers to check the applicable jurisdiction's rules and orders. That is the correct instruction, and it is a per-matter task rather than a firm-level one.

    What Actually Binds a Law Firm Under the EU AI Act

    If your firm has EU exposure, two facts govern your planning, and the version circulating in most 2026 articles is out of date on both.

    The first is the calendar. Regulation (EU) 2026/1744 of 8 July 2026 — the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026 — deferred the high-risk dates. Recital 40 sets the date of application of Sections 1, 2 and 3 of Chapter III to 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those classified under Article 6(1) and Annex I. Anyone still writing that high-risk obligations apply from 2 August 2026 is repeating the pre-Omnibus timeline, and that is the single likeliest regulatory error in this subject area.

    ObligationDateStatus as of August 23, 2026
    Prohibited practices; AI literacyFebruary 2, 2025In force
    General-purpose AI obligations, governance, penaltiesAugust 2, 2025In force
    Article 50 transparency obligationsAugust 2, 2026In force — as of three weeks ago. Systems placed on the market before that date get four months to adapt marking practices
    High-risk, Annex III (includes administration of justice)December 2, 2027Deferred from August 2, 2026 by Regulation (EU) 2026/1744
    High-risk, Annex I (product-embedded)August 2, 2028Deferred by Regulation (EU) 2026/1744

    The second fact is a classification point that is routinely conflated, and getting it right will save you an unnecessary compliance programme. Annex III point 8(a) covers "AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution."

    The precision point: Annex III(8)(a) binds systems used by a judicial authority or on its behalf — not a private firm's own research and drafting tools. A firm using a legal AI product for its own work product is generally not thereby deploying a high-risk AI system under that provision. This is an interpretation grounded in the quoted text rather than legal advice, and classification is fact-specific: a firm building a tool for a court, or an ADR provider deploying one, lands differently. What does reach an EU-facing firm sooner is Article 50 transparency, in force since 2 August 2026, together with GDPR and the firm's own professional rules.

    Two further details for anyone drafting an internal position. Providers who placed systems on the market before 2 August 2026 have four months to adapt their marking practices — a December 2026 checkpoint for content marking on pre-existing systems. And amended Article 50(7) now frames the Commission's role as encouraging and facilitating codes of practice at Union level for detection, marking and labelling of artificially generated or manipulated content, rather than exercising a lost implementing-act empowerment.

    On the US side, the relevant regulators are the state bars rather than a federal AI statute. California's 2026 guidance is the fullest treatment of agentic AI by any US regulator. The New York State Bar Association's AI Task Force, the State Bar of California in its earlier 2023 form and the Florida Bar had each published detailed guidance before it, and ABA 512 additionally cites opinions from Florida, a joint Pennsylvania and Philadelphia opinion, West Virginia and the District of Columbia. We could neither confirm nor exclude the existence of a 2025–26 ABA successor opinion to 512, so we assert neither — though 512 itself anticipates that updated guidance will follow as specific tools develop.

    One evidence-rules caution, stated with status precision because this is an area where confident wrong answers circulate. A proposed Federal Rule of Evidence dealing with machine-generated evidence is not listed among pending amendments as of August 23, 2026, and we do not write that it is coming into force. What is currently published for public comment is amendments to Evidence Rules 104 and 902, published 14 August 2026 with a comment deadline of 15 February 2027 and a projected effective date of 1 December 2028 — and we could not confirm whether those amendments concern machine-generated or AI evidence, so we characterise their subject matter no further.

    A Worked Scenario: 40 Research Memos a Month

    This is an illustrative scenario, not a client outcome. No firm described below exists. Every input is either a figure from a source cited in this article or an assumption labelled as one, and the arithmetic is shown so you can substitute your own numbers. We do not publish client results we cannot evidence, and we will not tell you that a firm saw a 40% reduction in anything.

    Consider a 24-lawyer litigation and commercial firm producing 40 research memos a month, each carrying roughly 12 citations. Assume, before any AI, that a memo takes a senior associate 3.0 hours end to end. That is 120 hours a month of memo production, and 480 citations a month leaving the building over a partner's signature.

    Step one: the verification load, computed from the only independent measurement available. The Stanford study found hallucination rates of 17%–33% across the products it tested in April 2024, where a hallucination means a statement that is either incorrect or misgrounded — including a factually correct statement citing a source that does not support it. Applied to a 12-citation memo, that range implies roughly two defective citations per memo at the low end and four at the high end. Across 40 memos, that is 82 to 158 defective citations a month if nobody checks.

    Two caveats have to travel with that arithmetic or it is dishonest. The measurement covered three products, one of which no longer exists, and it is a point-in-time result from April 2024 rather than a current performance figure for anything on sale today. And no successor evaluation has been published, so we cannot tell you the rate is lower now — only that we do not know. What the arithmetic legitimately demonstrates is the shape of the exposure: at any plausible rate, unverified AI-drafted memos put defective citations into your work product at a monthly volume, not an annual one. That is the mechanism behind the 293 US lawyer sanction cases recorded in 2026 through August 23.

    Step two: the time budget. Assume drafting time falls from 3.0 hours to 1.0 hour with a research assistant in the workflow. Now add the verification step that ABA Formal Opinion 512 requires — pulling each cited authority and confirming it says what the draft claims. At four minutes a citation, twelve citations is 48 minutes, or 0.8 hours. Total per memo: 1.8 hours against a 3.0-hour baseline. Across 40 memos, 72 hours instead of 120. 48 hours a month released.

    Note what the verification step does to the headline. Naive arithmetic on drafting alone would claim a 67% reduction. Honest arithmetic, with the ethics obligation priced in, gives 40%. If a vendor's business case does not contain a verification line, it is quoting the naive number — and 512 does not permit you to run the naive number.

    Step three, and the part that surprises most partnerships: who captures the 48 hours. On hourly matters, nobody at the firm does. ABA 512 states that lawyers who bill an hourly rate must bill for their actual time, and that where a tool makes work much faster it may be unreasonable under Model Rule 1.5 to charge the same flat fee as before. So on hourly work those 48 hours simply leave the invoice. The firm captures value only where the work is flat-fee, contingency, or where released capacity is redeployed onto matters the firm would otherwise have declined. That is a real and often substantial gain — but it is a capacity argument, not a margin-per-matter argument, and the two get conflated constantly in vendor decks.

    Step four: can you pass the subscription through?Ordinarily not. California's 2026 guidance says subscription fees for tools providing general office functionality — drafting assistance, research capabilities, document review — typically constitute overhead similar to library maintenance or general computer systems, and should be absorbed in the fee rather than charged separately. Where a charge is legitimate, it must reasonably reflect actual cost, with no markup or profit element absent the client's informed written consent. ABA 512 draws the same line differently: a grammar tool embedded in word processing is overhead, while a third-party service charging per use for one client's document review is ordinarily a billable out-of-pocket expense. The usage-based e-discovery platforms are the clearest case on the billable side of that line; a firmwide research seat is the clearest case on the overhead side.

    The scenario summarised, with every assumption visible

    1. 1.Baseline: 40 memos a month, 12 citations each, 3.0 hours per memo. 120 hours; 480 citations. All three are assumptions — substitute yours.
    2. 2.Exposure if unverified: 82–158 defective citations a month, applying the 17%–33% range from the April 2024 Stanford measurement. That range measured products, one of which has since been retired.
    3. 3.Verification cost: 0.8 hours per memo at four minutes a citation. 32 hours a month, firmwide, that did not exist before.
    4. 4.Net time released: 48 hours a month, after verification. A 40% reduction, not the 67% the drafting line alone would imply.
    5. 5.Where the value lands: Not on hourly matters, where Rule 1.5 requires billing actual time. On flat-fee and contingency work, and on redeployed capacity.
    6. 6.Tooling cost: Unknown — no vendor in this market publishes a price. Model it as a range from your own quotes, and treat a firmwide research seat as overhead.

    The honest conclusion from that arithmetic is not that legal AI does not pay. It is that the payback is a capacity and quality story on a defined subset of your matters, and the verification step is a permanent line item rather than a transitional one. A firm that budgets for the verification and targets flat-fee work will do well. A firm that buys on a 67% number and bills clients for the software will have two problems.

    What Breaks First, and How You Detect It

    In this market the first failure is almost never the model — it is the roster, the contract or the boundary. Here are the failure modes in rough order of likelihood, each with the signal that reveals it and the rollback that contains it.

    1. The vendor you bought is not the vendor you renew with

    Four renames and one billion-dollar acquisition inside eighteen months, plus one company whose engineering team left for Microsoft. Detection: a quarterly check of Companies House or SEC EDGAR for every vendor on your stack, plus a look at whether the trust centre still resolves and whether the copyright footer is current. Those two web signals were the earliest public indicators in the case discussed above. Rollback: an export clause you negotiated at signature and have actually tested, plus a documented alternative for each workflow. Never let a single vendor hold the only copy of a work product.

    2. Prompt injection, which is unsolved

    Any agent that reads untrusted input — opposing counsel's correspondence, an inbound contract, a produced document set, a client email — can have instructions smuggled into that input. There is no fix; there is only blast-radius reduction. Detection: log every tool call an agent makes and alert on any egress action, any cross-matter read, and any privilege-flagged document entering a context window. Rollback: split the reading identity from the writing identity so the component that ingests untrusted text holds no write credential, scope every agent to a single matter, and permit no autonomous external transmission at all. We work through the attack classes and the concrete controls in our guide to prompt injection and the OWASP LLM Top 10. Frame this to your partners as containment, never as solved — because it is not.

    3. Matter-boundary leakage and the conflicts problem

    California's guidance names this directly: unrestricted or poorly configured agentic systems may unintentionally disclose confidential information across different matters and even expose privileged material. The ethics-opinion version is sharper still — models without safeguards equivalent to an ethical wall may run afoul of Rules 1.7 and 1.9 by using information from one representation to inform another. Detection: audit what each agent identity can actually read, not what the configuration screen says it should. Rollback: matter-level isolation enforced at the identity layer, and ethical-wall enforcement integrated rather than promised.

    4. The gap between the marketing page and the contract

    This is the quiet one. One vendor publishes an unambiguous no-training statement on its security page that does not appear in its contractual security policy. Another's published master agreement reserves a perpetual right to use learnings from product usage. A third prohibits third-party training while permitting first-party training on opt-in. A fourth qualifies its commitment with the words for general use. Detection: read the executed contract, not the website — 512 says so in terms. Rollback: get the commitment into the order form before signature. After signature you have no leverage and a client-notification problem.

    5. Announced-but-unshipped capability

    Two examples from this roster alone: an agentic e-discovery engine announced in February 2026 for "later in 2026" with no general-availability confirmation, and a conversational layer announced in August 2026 with GA planned for early 2027. Neither is a criticism — roadmaps are roadmaps — but a business case built on an unshipped feature has a delivery risk nobody priced. Detection: ask for the GA date in writing and the current release notes. Rollback: contract only for what is generally available today, with the roadmap item as an amendment.

    6. The verification step quietly stops happening

    The most dangerous failure, because it is invisible until a court finds it. Verification decays under deadline pressure exactly when the stakes are highest. Detection: a sampling protocol with a recorded result — which is precisely the mechanism ABA 512 contemplates, and which doubles as your evidence of reasonable supervision under Rules 5.1 and 5.3. Pull a fixed percentage of citations from filed work each month and record the check. Rollback: a citation-verification gate that a human signs before filing, enforced as a workflow step rather than as a policy memo. Twenty-five decisions in the hallucination database name a commercial product, which tells you the professional-grade tools did not remove this failure mode.

    The Human-in-the-Loop Boundary

    Every row of this table is grounded in ABA Formal Opinion 512 or the State Bar of California's 2026 Practical Guidance, not in our opinion about good practice. It is written to be lifted straight into a firm AI policy, and the right-hand column is deliberately absolute.

    An agent may act aloneNeeds lawyer review before useMust never touch
    Retrieve and organise documents from the DMS inside a scoped, access-controlled single matterAny research result or citation that will be used in advice or a filing. ABA 512 requires an appropriate degree of independent verificationFiling anything with a court. California 2026: lawyers must not permit AI systems to autonomously file documents, communicate with the court, or make representations on the lawyer's behalf
    Draft a first-pass internal summary, chronology or issues list for a lawyer to readContract redlines produced against a playbook, before they go to the counterpartyCommunicating legal advice to a client. California 2026 bars agents from communicating legal advice without meaningful lawyer supervision and review
    Extract structured data from records into a reviewable tableDemand letters, discovery responses and pleadings — drafted by the agent, none sent by itMaking substantive legal determinations. That phrase is the California guidance's own
    Flag internal inconsistencies, broken cross-references and missing documentsAnything that crosses a matter boundary. California warns of unintended disclosure across different matters and exposure of privileged materialAutonomous external transmission of client information — not without appropriate safeguards and human review

    The organising principle behind the table is the California guidance's scaling rule, which is more useful than any fixed checklist: the greater the level of system autonomy, the greater the lawyer's obligation to implement oversight mechanisms sufficient to ensure that professional judgment remains with the lawyer. In practice that means the supervision budget is a function of the product you bought. A Word add-in that surfaces defined terms needs almost none. An agent with persistent DMS access that runs overnight batches needs a named owner, an audit log somebody reads, and a documented sampling protocol.

    Three further boundary rules from the same source belong in the policy. Training is a duty, not a perk: supervision includes providing appropriate training on the ethical and practical aspects, and pitfalls, of tools that perform tasks with limited or no real-time human direction. Juniors are not shielded by instruction: a subordinate lawyer must not use AI-enabled tools, including agentic systems, at a supervisor's direction in a manner that violates their own professional obligations. And competence is recurring: because these systems evolve through updates and model changes, the duty of competence includes periodic reassessment of capabilities and risks, including when deploying a system for a new legal task. That last one is why a firm AI policy needs a review date on it.

    One bias note worth carrying into any multi-agent design: the California guidance observes that this can be of particular concern when using agentic AI, as multiple agents can compound any underlying bias. If your architecture chains agents, the compounding is a design property rather than an edge case.

    Cost and Timeline If You Build Rather Than Buy

    For most small and midsize firms, the honest advice is to buy a product first and commission a build only where the workflow is specific to your practice and nobody sells it. The ranked products cover research, drafting, contract review and e-discovery competently. Where a custom build earns its keep is the connective tissue: intake triage against your own criteria, matter-specific extraction from a document type your practice sees constantly, or an integration between two systems neither vendor will build. We work through that decision in detail in our build-versus-buy analysis for AI agents, and the short version is that buying loses to building only when the workflow is a differentiator rather than a commodity.

    When a build is the right answer, these are Frenchy Digital's bands. They are the same bands we quote across every industry, and we publish them because nobody else in this market publishes a number at all.

    EngagementRangeTimeline
    Discovery + workflow audit$9k–$22k2–4 weeks
    Single-workflow agent$28k–$70k4–9 weeks
    Multi-workflow platform with system integration$70k–$180k9–16 weeks
    Enterprise / multi-site / regulated build$180k–$420k+14–24 weeks

    Senior-led work runs $150–$225 per hour; retainers run $2,500–$9,500 per month. Every engagement carries a 30-day post-launch warranty, and full source-code and IP ownership transfers to you — which for a law firm is not a nicety but a conflicts and confidentiality requirement. We return a fixed-price phased proposal within 5 business days. Frenchy Digital is a senior-led, Black-owned agency in Los Angeles, and you can book a discovery call at calendly.com/frenchydigital/discovery-call or reach us on +1 (424) 272-5601.

    A sequencing note specific to law firms. Start with the discovery and workflow audit, because the deliverable you need before anything else is a vendor diligence pack mapped to Rule 5.3 and a written human-in-the-loop boundary your ethics partner will sign. That artefact is useful whether you end up building or buying, it is the evidence of reasonable supervision the rules require, and it costs a fraction of the first phase of a build. Then take one workflow — not three — into a single-workflow agent, with the baseline measured before you start so the result is arguable rather than anecdotal.

    Red Flags When Evaluating a Legal AI Vendor

    Every item below is a pattern we observed in this specific roster while researching this article, not a generic warning list. None of them disqualifies a vendor on its own. All of them are questions you are entitled to ask in a procurement call.

    • A regulation listed as if it were a certification: One vendor's security page lists “EU AI Act Compliant” alongside SOC 2 and GDPR. No certification scheme issues that. Ask which body audited it and what the scope statement says.
    • An awards programme presented as independent testing: A submission-based industry award is marketing, not measurement. One ranked vendor's only third-party recognition is an award. That is worth knowing, and it is not a benchmark.
    • User-review platforms cited as benchmarks: Peer-review sites aggregate opinion from self-selecting users. They tell you about sales motion and support quality. They tell you nothing about accuracy.
    • A vendor-sponsored podcast or panel offered as validation: One frequently cited “independent validation” in e-discovery is a discussion with no dataset, no metrics, no methodology, speakers from a firm's own technology subsidiary, and no disclosure of a commercial relationship.
    • Marketing claiming a certification the security page does not: One vendor's homepage claims SOC 2 Type II certification while its security page says only that its programme follows the SOC 2 framework. Following criteria is not holding an attestation. Ask for the report and the observation period.
    • A no-training promise that lives only on a marketing page: Ask where it appears in the contract. In this roster, only two vendors put it in the binding document unqualified, one qualifies it, one permits first-party training on opt-in, and one published agreement reserves the opposite right entirely.
    • A price quoted to you from a third-party blog: No vendor in this market publishes pricing. If a comparison site shows you a per-seat figure, ask for its source — one widely circulated figure is contradicted by the vendor's own page, and a competing vendor is among the most-cited sources for another.
    • “Hallucination-free” or any absolute accuracy claim: The claim that leading tools deliver hallucination-free citations is the specific claim the one peer-reviewed independent study was designed to test, and contradicted. Treat any absolute as a reason to ask for the evaluation protocol.
    • Agent language the product documentation does not support: Several vendors market agents while their own product pages describe augmentation, plan-then-approve workflows, or explicitly disclaim autonomy. Read the documentation, then ask the rep to point at the autonomous execution loop.
    • A certification badge doing the work of a confidentiality commitment: One vendor holds ISO/IEC 42001 and publishes no no-training commitment anywhere. A management-system certification says how the vendor governs AI, not what it will do with your client's documents.
    • A trust centre or documentation URL that does not resolve: A de-provisioned trust subdomain, a 404 pricing page and a stale copyright footer were the earliest public signals in the one vendor we refused. They cost thirty seconds to check.
    • No answer on data residency or retention: Six of the vendors here publish nothing on retention. For a firm with EU clients or outside-counsel guidelines, that is a contract negotiation, not a footnote.

    The one question that does more work than all of the above: ask the vendor to name any independent evaluation of its product and to send you the protocol. Four vendors in this entire market can answer that at all, and two of those answers point to a benchmark the vendor chose which tasks to enter. Everyone else will send you a case study. That is not a reason to walk away — it is the state of the market — but it tells you exactly how much weight the performance conversation can carry, which is very little.

    What We Could Not Verify

    A ranking that reports only what it found is not a ranking you can audit. Here is what we chased and could not establish, stated plainly so you can weigh everything above accordingly.

    • Independence for two vendors rests on absence of news: Everlaw's and Ironclad's private status is supported by recently refreshed first-party documents and no acquisition reporting — not by a registry, because no filing exists for a private US company. We write “no acquisition found as of August 23, 2026”, never a flat statement of independence.
    • Whether an ABA successor opinion to Formal Opinion 512 exists: americanbar.org blocks programmatic fetch. We could neither confirm nor exclude a 2025–26 successor, so we assert neither. 512 itself anticipates that updated guidance will follow.
    • The exact 2026 issue date of the California COPRAC guidance: We read the document in full; only its day and month are missing, because the bar's own index paths were unreachable. We cite it as the 2026 Practical Guidance without a precise date.
    • Thomson Reuters's compliance posture for CoCounsel: No trust page evidencing SOC 2 Type II or ISO certification for the product could be located. That is a disclosure gap, not evidence of absence — and it is a question for your procurement call, not a mark against the product.
    • Clio's no-training commitment and current pricing: clio.com returns 403 to programmatic fetch, so both cells are unverified rather than negative. Secondary pricing figures conflict badly and we print none.
    • StrongSuit's compliance posture, pricing and legal entity name: strongsuit.com returns 403. We can confirm the November 2025 rename and the July 2026 product launch from press releases, and nothing further.
    • The date and terms of the Silver Lake–Relativity transaction: Relativity's own announcement page is undated and Silver Lake's page returned a server error. The figures in circulation are secondary only, so we print no date and no valuation — only the board composition, which is verifiable.
    • Whether Luminance's published Master Hosted Agreement is still current: It is dated July 3, 2024. Clause 10.1.3 is quoted as published, and any buyer should confirm the current MSA before relying on it either way. We also could not establish whether the August 2026 share allotments represent a new round.
    • Definely's cloud provider and no-training position: Its trust centre says AWS and its privacy policy says Azure, so we state neither. And we found no no-training commitment in any published document despite its ISO 42001 certification.
    • General availability of DISCO's agentic Cecilia: Announced February 9, 2026 for “later in 2026”, with no GA confirmation found. We do not write that it is shipping.
    • Any DMS connector claim for Relativity: Documentation paths could not be reached, so we print no iManage or NetDocuments claim for Relativity at all, in either direction.
    • A current count of federal judges with AI standing orders: The only figure we can source is “more than 25”, as of May 2024, via the peer-reviewed Stanford paper citing a legal-press tracker. We do not present a 2024 count as a 2026 count, and we could not confirm that one widely cited certification order remains in force.
    • Whether the pending amendments to Federal Rules of Evidence 104 and 902 concern AI evidence: Published for comment on August 14, 2026 with a February 15, 2027 deadline and a projected December 1, 2028 effective date. We did not read the preliminary draft and characterise their subject matter no further. A proposed rule on machine-generated evidence is not on the pending list.
    • Any utilisation, realisation or hours-recovered figure: Every one we encountered was published by a seller, including one attributed to a vendor's own General Counsel. We could not obtain the methodology behind the most-cited utilisation series, whose publisher is itself ranked in this article, and we print none of them.
    • Independent evaluation for eleven of the fifteen verified vendors: None exists at all for Legora, Luminance, Spellbook, Eve, StrongSuit, Everlaw, Relativity, DISCO, Ironclad, Definely or Wordsmith. Only Harvey, CoCounsel, vLex Vincent AI and the retired Lexis+ AI have ever been evaluated by anyone outside the vendor.
    • Any neutral accuracy corpus for e-discovery AI: There is none. NIST's TREC Legal Track ran 2006–2011 and has no successor, and the one benchmark-shaped exercise we found in 2026 was run by an e-discovery vendor with undisclosed funding. Every accuracy figure in that market is self-reported on a private dataset.

    None of this argues against adopting AI in a law firm. It argues for adopting it the way the constraints actually permit: one workflow at a time, with the diligence file assembled before the pilot rather than after, with the verification step budgeted as permanent work, and with the boundary written down in the regulator's language rather than the vendor's.

    And it argues for holding the line that makes the whole exercise defensible. An agent may research, draft, extract, summarise, chase and queue — which is a great deal of real work, honestly done. What it may never do is make the substantive legal determination, communicate the advice, or put a document in front of a court. A lawyer does that, personally, every time. That is not a limitation of the current generation of tools. It is the job.

    Evaluating Legal AI for Your Firm?

    Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. You leave with a vendor diligence pack mapped to ABA Model Rule 5.3, a human-in-the-loop boundary your ethics partner can sign, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.

    Scoping an AI Agent for Your Firm?

    Book a free 60-minute discovery call. You leave with a vendor diligence pack mapped to Rule 5.3, a human-in-the-loop boundary your ethics partner can sign, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1ABA Standing Committee on Ethics and Professional Responsibility — Formal Opinion 512, “Generative Artificial Intelligence Tools” (July 29, 2024)
    2. 2State Bar of California, COPRAC — “Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law” (2026 edition)
    3. 3Magesh, Surani, Dahl, Suzgun, Manning & Ho — “Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools”, Journal of Empirical Legal Studies (2025), DOI 10.1111/jels.12413
    4. 4Stanford RegLab — publication page for the peer-reviewed hallucination study
    5. 5AI Hallucination Cases database — Damien Charlotin, HEC Paris Smart Law Hub
    6. 6Vals AI and Legaltech Hub — Vals Legal AI Report (VLAIR), February 27, 2025
    7. 7Vals AI — VLAIR legal research study, October 14, 2025
    8. 8LawSites (LawNext) — “Vals AI's Latest Benchmark Finds Legal and General AI Now Outperform Lawyers in Legal Research Accuracy” (October 2025)
    9. 9NIST — TREC Legal Track archive (ran 2006–2011; no successor)
    10. 10Mata v. Avianca, Inc. — S.D.N.Y. opinion and order of June 22, 2023 (CourtListener)
    11. 11Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026 — consolidated text
    12. 12EU AI Act — Annex III (high-risk classification, including point 8 on the administration of justice)
    13. 13EU AI Act — Article 50 (transparency obligations, in force August 2, 2026)
    14. 14Hatzius, Briggs, Kodnani & Pierdomenico — “The Potentially Large Effects of Artificial Intelligence on Economic Growth”, Goldman Sachs Global Economics Analyst (March 26, 2023)
    15. 15Thomson Reuters — “Thomson Reuters completes acquisition of Casetext, Inc.” (August 17, 2023)
    16. 16Clio — “Clio Completes Landmark $1B vLex Acquisition; Series G at $5B Valuation” (November 10, 2025)
    17. 17LawSites (LawNext) — “LexisNexis Launches Lexis+ with Protégé, Replacing Lexis+ AI” (February 2026)
    18. 18UK Companies House — ROBIN AI LIMITED (company no. 11400135), filing history
    19. 19Artificial Lawyer — “Microsoft To Acqui-Hire Robin AI Tech Team” (January 9, 2026)
    20. 20Legal IT Insider (legaltechnology.com) — Scissero's acquisition of the Robin AI managed services arm
    21. 21UK Companies House — LUMINANCE TECHNOLOGIES LTD (company no. 09857705)
    22. 22CS Disco, Inc. — Form 10-Q for the quarter ended June 30, 2026, filed August 5, 2026 (NYSE: LAW)
    23. 23Harvey — Platform Agreement, section 11.8 (no-training clause), effective January 9, 2026
    24. 24Spellbook — Terms of Service, sections 4.1(b)(iv) and 4.2
    25. 25Luminance — Master Hosted Agreement, clause 10.1.3 (published July 3, 2024)
    Chris Machetto - CEO & Founder, Frenchy Digital of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital. Building apps and digital products since 2019 for startups and enterprises across LA, San Francisco, Paris, Geneva, and more globally.