Deploying AI for Practicing Lawyers: Local De-identification and Case Work with Large Language Models

Client Profile

Our clients are practicing lawyers in multiple countries and regions, now numbering several dozen. Their practices span litigation and non-contentious work, and the mix of their work often shifts with the matters they take on.

The service is deployed for each lawyer individually rather than through a centralized system deployed across a law firm, for two reasons:

(a) Confidentiality. A centralized system brings the whole firm’s case materials together on a single platform, widening access to them. Deploying independently for each lawyer limits the system and its data to that lawyer and the matters they handle, in line with the need-to-know principle and with the common practice of information barriers within law firms.

(b) Accumulated expertise. Each lawyer’s practice mix, drafting conventions and client requirements differ. The scenarios, document templates and terminology configured for each lawyer are updated as their matters evolve, building up into the lawyer’s own working methods and drafting standards.

Law firms can take the same approach, deploying separately for each lawyer according to their needs, with each deployment running independently.

Original Problems

The problems lawyers commonly face fall into four areas.

(a) Confidentiality. Case materials contain parties’ identities, identification documents, accounts and amounts, and lawyers owe their clients a duty of confidentiality. Uploading unprocessed materials to cloud AI risks disclosure and the loss of legal professional privilege. The American Bar Association’s Formal Opinion 512, issued in July 2024, states that lawyers must understand how generative AI uses data and put appropriate safeguards in place, and that before inputting confidential client information into AI, they should generally obtain the client’s informed consent. The Law Society of Hong Kong’s position paper of January 2024 likewise notes that using AI through cloud services raises issues of client data privacy and legal professional privilege.

(b) Reliability. AI can fabricate facts and sources, while responsibility for a document always rests with the lawyer. A 2024 Stanford University study found that specialized legal AI tools produced incorrect results more than 17% of the time.

(c) Document workload. Reviewing case files, organizing evidence, responding to contract redlines and mapping out case facts take up a great deal of time, crowding out the time lawyers need for legal judgment and client communication.

(d) Adoption. General-purpose AI tools require users to work out prompts and workflows on their own, and their output formatting is inconsistent, making it hard to apply directly to a lawyer’s document templates.

How We Worked

The engagement proceeded in four stages.

(a) Initial Diagnostic. Through a diagnostic workshop, we reviewed the document work that takes up most of the lawyer’s time and identified where AI should begin. A lawyer’s work falls into two categories: work closely tied to legal judgment, including the legal basis, the purpose for which evidence is offered, views on evidence and litigation strategy; and work unrelated to legal judgment, including understanding long documents, structured drafting, responding to redlines, building chronologies and indexing materials. AI handles only the latter; the former always remains with the lawyer.

(b) Full Diagnostic & Proposal. Because a lawyer’s work shifts with the matters they take on, the stable way to classify it is by document type rather than area of law, so scenarios are selected by document type. Each lawyer selects three scenarios from the scenario library; a common combination is organizing evidence, responding to contract redlines and compiling case chronologies. For each scenario, a document template confirmed by the lawyer serves as the standard for the output and the basis for acceptance, and rules are set for using materials according to their sensitivity.

(c) Implementation. We deployed the de-identification tool on the lawyer’s own computer and configured it for their practice, configured working instructions and document templates for each selected scenario and tested them on de-identified materials from past matters. The lawyer then completed acceptance by operating the system independently.

(d) Operations & Maintenance. We follow up quarterly to update document templates, scenario instructions and de-identification settings as the lawyer’s matters and client requirements change; after model and tool upgrades, we carry out compatibility adjustments and regression testing.

AI Architecture

The system is designed around three requirements: lawyers need not learn any technology; data remains secure and under control; and every output is a draft for the lawyer to review and revise.

(a) Local de-identification. Highly sensitive case materials are de-identified on the lawyer’s own computer before being processed by a cloud-based large language model, and the output is restored on the same computer once returned. The original, identifiable data never leaves the lawyer’s computer.

(b) Trade-offs between local open-weight models and cloud frontier models. Open-weight models can be deployed locally, so data need not leave the premises, but this involves trade-offs among quality, speed and cost. Models that can run on personal devices must be quantized, which lowers quality and lengthens waiting times on long case files; deploying near-frontier models on a law firm’s own servers requires substantial hardware investment and dedicated technical staff to maintain them. Cloud frontier models offer full capability and fast responses, but materials must leave the premises. This project bridges the two through de-identification: identifying and replacing sensitive information is done on the lawyer’s own computer, and the subsequent work is handled by a cloud frontier model. The original, identifiable data never leaves the lawyer’s computer, while the lawyer still has the full capability of frontier models.

(c) Tiered use. Lawyers handle materials according to their sensitivity. Only highly sensitive materials must be de-identified, so security measures do not add to everyday workload.

(d) Scope of capability. The system deals only with “what is there,” not “what it means”:

Table 1 — Scope of capability
What the system handlesWhat the lawyer decides
What a document is, when it was created, what it says and on which pageWhether it proves the claim
Where document A and document B disagreeWhose account is credible and how to weigh them
Who admitted what in a transcriptThe legal consequences of that admission
Whether a document’s structure, format and required sections are completeWhether its arguments hold

The purpose for which evidence is offered, views on evidence and litigation strategy are completed by the lawyer.

(e) Verifiability. Factual statements in the output can be traced to the source materials, and points of uncertainty are flagged; where materials are incomplete, the system identifies what is missing rather than filling the gaps. Each scenario is released for use only after multiple rounds of testing confirm stable results.

Results

(a) Case materials can be used safely with cloud frontier models. Highly sensitive materials are used after local de-identification, and the original, identifiable data never leaves the lawyer’s computer.

(b) Lawyers operate the scenarios on their own, and the output applies the lawyer’s confirmed document templates directly, presented as tracked changes in Word. Lawyers review and revise rather than rewrite.

(c) Output is verifiable. Factual statements can be traced to the source materials, points of uncertainty are flagged and the system identifies missing items when materials are incomplete.

(d) Lawyers’ time has shifted from organizing materials and drafting documents to review and legal judgment.

(e) Responsibilities are clearly divided. The purpose for which evidence is offered, views on evidence and litigation strategy are completed by the lawyer, who always remains responsible for the document.

(f) The service has been delivered to dozens of lawyers in multiple countries and regions.

Representative Deliverables

Table 2 — Representative deliverables
CategoryDeliverables
Data securityLocal de-identification tool; rules for using materials according to their sensitivity
ScenariosWorking instructions and document templates for each scenario
UseDesktop workspace and user manual

Data sources: American Bar Association, Formal Opinion 512 (July 2024); The Law Society of Hong Kong, position paper on artificial intelligence (January 2024); Stanford RegLab and Stanford HAI, AI on Trial: Legal Models Hallucinate in 1 out of 6 (or More) Benchmarking Queries (May 2024).

Back to all case studies