Artificial intelligence is becoming more useful to law firms because it is moving closer to the information attorneys already work with every day.

Instead of manually copying text from a document into an AI tool, newer integrations can allow AI systems to search, summarize, and work with content stored inside document repositories and productivity platforms.

That shift creates a new governance question for law firms:

If AI can reach the matter file, are your permissions ready for it?

In September 2026, iManage announced an integration with ChatGPT Enterprise that allows authorized users to work with governed iManage content directly from ChatGPT while preserving existing permissions, ethical walls, and audit trails. Read the iManage announcement

That is a useful example of where legal AI is heading.

The issue is no longer only whether lawyers are copying confidential information into a public AI tool.

Now firms also need to think about what AI can retrieve from systems users already have permission to access.

Why Permissions Matter More When AI Can Search Firm Data

A traditional permissions model answers a familiar question:

Which files can this user access?

An AI-enabled environment adds another:

What can the AI retrieve on that user's behalf?

That distinction matters because AI can make large amounts of information much easier to search and surface.

The American Bar Association recently highlighted this exact issue in guidance on Microsoft Copilot. The ABA article explains that Copilot can work across Microsoft 365 sources such as email, Teams, OneDrive, and SharePoint based on the permissions the user already has. The article recommends that firms review those permissions before deployment. Read the ABA guidance on Copilot deployment

That means an old access-control problem can become an AI governance problem.

If a lawyer has access to information that is broader than their current role requires, AI may be able to surface that information more quickly and conveniently than a person browsing folders manually.

The underlying permission did not necessarily change.

The way the information can be accessed did.

AI Does Not Create Every Data Governance Problem

It is important not to blame AI for weaknesses that already existed.

A law firm may already have:

  • Outdated SharePoint permissions
  • Old Teams memberships
  • Access to closed matters that was never removed
  • Broad OneDrive sharing
  • Legacy document permissions
  • Inconsistent sensitivity labels
  • Users with access to internal administrative or financial information they no longer need

Those issues existed before AI.

AI can make them more visible.

The ABA's Copilot guidance makes this point directly: permissions set years earlier may become much more consequential when an AI tool can use the user's full authorized data landscape to answer questions. (americanbar.org)

That is why firms should treat AI readiness as an extension of information governance and cybersecurity rather than a completely separate technology project.

AvTek makes a similar point in our guide to questions every business should answer before expanding AI use: organizations should understand what data they hold, where it lives, who can access it, which AI systems are approved, and what controls are in place before expanding AI use.

Start With the Data Sources AI Can Reach

Before enabling an AI tool across the firm, leadership and IT should understand its scope.

Questions should include:

  • Can it access Outlook?
  • Can it search Teams?
  • Can it reach OneDrive?
  • Can it search SharePoint?
  • Can it connect to the document management system?
  • Can it reach matter-specific repositories?
  • Can it access internal administrative data?
  • Can it search archived or closed-matter information?

The ABA recommends documenting the data sources that fall within the scope of a Copilot deployment before the tool is turned on. (americanbar.org)

That is a practical first step.

Before asking whether the AI is secure, ask:

What exactly can it see?

Review Permissions Before Expanding AI Access

Once the firm understands which systems the AI can reach, the next question is whether the existing permissions still make sense.

That review should not begin with AI.

It should begin with users and roles.

Ask:

  • Does each attorney still need access to every matter currently available to them?
  • Have attorneys moved between practice groups?
  • Have old matters closed?
  • Do former team members still retain access to related workspaces?
  • Are Teams and SharePoint permissions aligned with current responsibilities?
  • Do administrative users have access beyond what their job now requires?
  • Are internal leadership or compensation documents appropriately restricted?

The goal is not to remove access arbitrarily.

It is to make sure the firm's access model reflects how the firm operates today.

AI can then work within those boundaries.

Ethical Walls Become Even More Important

Law firms often rely on ethical walls or information barriers to restrict access between matters, clients, or groups of attorneys.

If an AI tool connects to the firm's document environment, those controls need to remain effective.

The iManage ChatGPT Enterprise integration is notable because iManage says existing permissions, ethical walls, and audit trails remain in place when users work with governed content through the AI integration. (imanage.com)

That is the kind of architecture firms should understand before integrating AI into legal workflows.

The important question is not simply:

"Can this AI connect to our document system?"

It is:

"Does the AI respect the same access boundaries our lawyers already depend on?"

Confidentiality Still Applies When AI Makes Access Easier

Law firms handle information that may include:

  • Client communications
  • Matter documents
  • Litigation strategy
  • Work product
  • Financial information
  • Personally identifiable information
  • Internal firm information
  • Partner or leadership materials

AI does not change the firm's responsibility to handle that information appropriately.

ABA guidance on AI use stresses that lawyers should understand how AI platforms handle information, including data retention, training practices, vendor terms, and security controls before using them with confidential information. Read ABA guidance on avoiding accidental disclosure with AI

The key point is not that every AI tool handles data the same way.

They do not.

Firms need to evaluate the specific platform, configuration, and use case rather than make assumptions based on the word "AI."

Paying for an AI Tool Does Not Automatically Answer the Security Question

A common mistake is assuming that an enterprise or paid version of an AI product automatically makes every configuration appropriate for confidential legal work.

The ABA has cautioned law firms to understand how the product handles data, whether information may be used for training, and whether permissions are configured correctly. (americanbar.org)

Those questions should be part of vendor review.

Law firms should understand:

  • Whether firm data is used to train models
  • Whether data is retained
  • Where data is processed
  • Which administrators can configure access
  • Which third parties or subprocessors are involved
  • What audit logging is available
  • What security certifications or documentation the vendor provides
  • How the platform integrates with existing firm systems
  • Whether existing permissions are enforced

The goal is not to label a product secure or insecure based only on its brand name.

The goal is to understand what the specific service does with the firm's information.

Sensitivity Labels Can Add Another Layer of Control

Permissions answer the question:

Who may access this information?

Data classification can answer another:

How should this information be handled?

The ABA's Copilot deployment guidance specifically discusses Microsoft 365 sensitivity labels as a way to apply additional protections to highly sensitive documents. (americanbar.org)

That distinction can matter for documents such as:

  • Leadership deliberations
  • Compensation materials
  • Sensitive HR information
  • Particularly restricted client information
  • Confidential internal planning
  • Other information that requires stronger controls

A user may have legitimate access to a document while the firm still decides that the document should not be surfaced through an AI interaction.

That is where information classification and AI governance begin to overlap.

AI Governance Should Cover More Than Approved Tools

An AI policy is useful, but it should not stop at a list of approved applications.

A practical law firm AI governance program should consider:

Approved Applications

Which AI platforms may employees use for firm work?

Approved Use Cases

What activities are appropriate for each tool?

Restricted Information

What types of client, matter, employee, or firm information should not be entered into particular systems?

Permissions

What existing systems can the AI access?

Data Classification

Which information requires additional protection?

Vendor Review

How does the AI provider process, retain, and protect firm data?

Human Review

Where must attorneys verify AI-generated output before use?

Logging and Monitoring

What evidence exists showing how AI is being used?

Ongoing Review

What happens when the vendor changes its product or introduces new capabilities?

This makes AI governance part of the firm's broader security program rather than a standalone policy exercise.

AI Output Still Requires Legal Judgment

Better permissions do not make AI output automatically reliable.

AI may help summarize, organize, draft, and retrieve information, but lawyers still need to evaluate the result.

ABA guidance on Microsoft Copilot stresses that attorneys remain responsible for reviewing output, protecting confidential information, and using appropriate legal research methods where accuracy and authority matter. Read the ABA guide to using Microsoft Copilot

That matters because there are really two different governance problems:

Can the AI access information appropriately?

and

Can the firm rely on what the AI produces?

Solving one does not solve the other.

Human Oversight Needs to Happen Throughout the Workflow

As AI tools become more capable, simply having an attorney review the final output may not always be enough.

Recent ABA commentary argues that professional oversight should include how the tool was selected, what task it was given, what information it used, what sources it relied on, and what limits apply to the system, not just whether someone looked at the final response. (americanbar.org)

That is an important shift.

The question becomes:

Where does human judgment belong in the process?

For low-risk administrative tasks, the answer may be simple.

For work involving legal analysis, client strategy, confidential matter data, or actions that affect a client, the review process may need to be more deliberate.

AI governance should reflect the significance of the task.

Microsoft 365 Security Is Part of AI Readiness

For firms considering Copilot or other AI systems that work inside Microsoft 365, AI readiness and Microsoft 365 security increasingly overlap.

If AI can interact with:

  • Email
  • Teams
  • SharePoint
  • OneDrive
  • Documents
  • Internal collaboration spaces

then existing Microsoft 365 controls matter.

AvTek's Co-Managed IT Services include Microsoft 365 security protection, auditing, policy management, threat monitoring, privileged access management, multi-factor authentication, Microsoft Intune, device compliance, configuration profiles, and Conditional Access.

For firms without a full internal technology team, AvTek's Managed IT Services include Microsoft 365 and Azure management, cybersecurity, risk assessments, backup and disaster recovery, and strategic IT planning for legal and professional services organizations.

The objective is not to "secure AI" as a separate island.

It is to make sure the environment AI is entering already has sensible identity, access, data, endpoint, and security controls.

Law Firms Should Review AI and Permissions Together

A useful readiness process should answer both sides of the equation.

AI Questions

  • Which AI systems are approved?
  • What information can they process?
  • How does the vendor handle firm data?
  • What use cases are allowed?
  • Where is human review required?
  • What logging is available?

Access Questions

  • What systems can the AI reach?
  • Which users can access which matters?
  • Are permissions still current?
  • Are ethical walls functioning as intended?
  • Is highly sensitive information classified?
  • Are inactive access rights being removed?
  • Are administrative privileges appropriately limited?

Looking at only one side can leave a gap.

The AI system may have strong enterprise security controls while the firm's internal permissions remain too broad.

Or the firm's permissions may be well managed while employees use unapproved external AI tools with client information.

Governance needs to cover both.

Cybersecurity Governance Can Help Firm Leadership Make Better AI Decisions

AI is not purely an IT decision.

Managing partners, firm administrators, operations leaders, legal leadership, IT, and cybersecurity teams may all have a role in determining:

  • Which AI tools the firm approves
  • Which data they can access
  • What risks are acceptable
  • Which safeguards are required
  • How vendors are evaluated
  • Who owns policy decisions
  • How exceptions are handled
  • How controls are reviewed over time

For firms that need additional cybersecurity leadership, AvTek's vCISO Services include cybersecurity risk assessments, remediation planning, policy development, governance, vendor and third-party risk discussions, security technology recommendations, and executive-level guidance.

That type of governance can help firms evaluate AI within the broader context of cybersecurity and business risk rather than treating each new AI product as a standalone purchasing decision.

Frequently Asked Questions About AI Permissions for Law Firms

Can Microsoft Copilot access law firm documents?

Microsoft Copilot can work with Microsoft 365 information that the user has permission to access, including sources such as email, Teams, OneDrive, and SharePoint, depending on the deployment and configuration.

The ABA recommends that firms understand exactly which data sources fall within scope before deploying Copilot. (americanbar.org)


Can AI search a law firm's document management system?

Some AI platforms can integrate directly with document management systems.

For example, iManage announced a ChatGPT Enterprise integration in September 2026 that allows authorized users to search and work with governed iManage content while preserving existing permissions, ethical walls, and audit trails. (imanage.com)

Whether a particular AI can access a firm's document system depends on the product, integration, permissions, and configuration.


Should law firms review permissions before deploying AI?

Yes.

ABA guidance recommends reviewing the data sources and permissions that an AI system such as Microsoft Copilot can access before deployment. (americanbar.org)

The goal is to ensure access rights still reflect current roles, matters, and responsibilities.


What are ethical walls in legal AI systems?

Ethical walls, or information barriers, restrict access to certain clients, matters, or information within a firm.

If an AI system integrates with a law firm's document environment, the firm should understand whether and how those existing restrictions are enforced.


Can law firms use ChatGPT with client information?

The answer depends on the specific product, configuration, client information involved, applicable ethical obligations, firm policy, and how the service handles data.

ABA guidance recommends that lawyers evaluate data retention, training practices, vendor terms, and confidentiality risks before using AI platforms with client information. (americanbar.org)

Firms should not assume all versions or configurations of a product handle data the same way.


Does an enterprise AI product automatically make a law firm AI-ready?

No.

An enterprise AI platform may provide stronger administrative and security capabilities than a consumer version, but firms still need to consider permissions, identity, information classification, vendor configuration, employee policies, data governance, and human oversight.


What should law firms do before enabling Copilot?

A useful starting point is to:

  1. Identify the data sources Copilot can access.
  2. Review current user and group permissions.
  3. Review highly sensitive information and classification controls.
  4. Define approved use cases.
  5. Establish AI policies and review requirements.
  6. Evaluate security and administrative settings.
  7. Determine how activity will be governed over time.

The appropriate process will depend on the firm's environment and risk profile.

Before AI Can Search the Matter File, Make Sure the Right People Can

Legal AI is becoming more integrated with the systems attorneys already use.

That can make AI far more useful.

It also makes the quality of the firm's existing information governance more important.

The central question is no longer simply:

"Are our attorneys allowed to use AI?"

It is increasingly:

"What can AI access on their behalf?"

Before expanding AI across your law firm, understand the environment it is entering.

Review the permissions.

Review the data.

Review the vendor.

Review the Microsoft 365 environment.

Confirm that ethical walls and access boundaries are working as intended.

Then decide what AI should be allowed to do inside those boundaries.

AvTek Solutions helps legal and professional services organizations strengthen that foundation through Managed IT Services, Co-Managed IT Services, Cybersecurity Services, and vCISO Services.

If your firm is preparing to expand Microsoft Copilot, connect AI to a document repository, or allow AI to work with matter data, review the access environment before you expand the AI environment.

Talk with AvTek about your law firm's AI and cybersecurity risk