A private LLM for law firms - because your associates are already pasting client contracts into ChatGPT.
Public assistants send every prompt to a third party's servers - outside your firm's control and hard to square with GDPR and attorney-client privilege. The alternative is a self-hosted LLM for law firms: the model, your documents, and every query stay inside your own infrastructure, with no third party in the loop. Built for firms that can't put privilege on a vendor's servers.
Shadow AI is already inside most law firms.
law firms already run generative AI in active workflows - much of it on public tools nobody signed off on.
of global turnover - the ceiling for a GDPR fine under Article 83.
privilege can turn on who has had access to a document - including a foreign server.
What a self-hosted, GDPR-aligned LLM means in practice.
Public assistants route every prompt through a third party's servers - a risk most firms accept without reading the data-processing agreement. Private LLM deployment removes the third party entirely.
Why public assistants are the wrong tool
Pasting a client contract into a consumer chatbot sends that text to a foreign server the firm does not control. That is difficult to reconcile with:
- Attorney-client privilege - privilege can turn on who has had access to a document.
- GDPR Articles 28 & 32 - processor obligations and security-of-processing duties most consumer AI terms do not satisfy.
- Reputational exposure - a client finding out their file passed through a public model is a conversation no partner wants to have.
What changes with a private LLM
The model is deployed on infrastructure inside the firm - on premises or in a private, dedicated environment the firm controls. In practice:
- Data never leaves the perimeter - no request is sent to OpenAI, Anthropic, or any other provider.
- Vendor independence - the model is open-weight; the firm is not locked into one vendor's pricing or policy changes.
- Air-gap configuration is possible - the system can run with no internet connection at all.
AI contract review
Clause extraction, redline comparison, and risk flagging on drafts that stay on firm infrastructure throughout.
Private case-archive search
A private RAG system indexes the firm’s own case files, so associates search precedent without a document ever being uploaded anywhere.
Drafting support
First-pass memos, correspondence, and filings drafted from firm precedent and templates - reviewed and finalised by counsel.
Built around Articles 28 and 32, not around a marketing claim.
Compliance is ultimately the firm's and its counsel's judgment. What a private LLM deployment provides is the technical foundation that judgment rests on.
GDPR-aligned
Architecture supports the processor obligations of Article 28 and the security-of-processing duties of Article 32.
Data residency
The model and its data reside physically in the EU, or on the firm’s own premises - never a jurisdiction the firm did not choose.
Access control
Role-based access, tied to the firm’s existing identity provider. After handoff, no outside party retains access.
No lock-in
Open-weight models the firm owns outright. Swapping providers is a configuration change, not a migration.
A live deployment - private RAG for contract review.
Private RAG for contract review at a Dubai/London firm.
A self-hosted retrieval system indexed a 12,000-document contract archive so associates could search precedent and flag deviations without a single file leaving the office network - cutting first-pass review time by 73%.
Read the case studyA predictable process, start to handover.
Qualification call
A short conversation to confirm fit and scope. No proposal without it.
Paid assessment
Infrastructure and document review, with a fixed-price deployment plan at the end.
Deployment
Typically 2–6 weeks, depending on the size of the document archive, on the firm’s own infrastructure.
Handover + SLA
Written runbook, training, and an ongoing support agreement if the firm wants one.
Questions law firms ask before signing.
Is it possible to run client data through public assistants like ChatGPT?
Technically yes, and many firms already do without realising it. The document leaves the firm's network and is processed on a third party's servers under that provider's terms - not the firm's. This is the exposure a private LLM removes entirely.
Is ChatGPT GDPR-compliant for a law firm?
It is difficult to reconcile with GDPR. Prompts sent to a public assistant are processed on a third party's servers under that provider's terms - the firm cannot guarantee the Article 28 processor obligations or the Article 32 security-of-processing duties it is bound by, and client data may leave the EU. A self-hosted LLM keeps processing inside the firm's own perimeter, where those duties are the firm's to control rather than a vendor's to promise.
Does using a public AI chatbot risk waiving attorney-client privilege?
It can. Privilege can turn on who has had access to a document, and pasting a client file into a consumer chatbot hands it to a third party the firm does not control. Keeping every query and document on infrastructure the firm owns removes that exposure - no outside party ever sees the material.
Is "on-premises" just a cloud service without the internet?
No. The model, the vector database of firm documents, and the interface all run on hardware the firm controls - in the office or in a dedicated private environment. The system can be disconnected from the internet entirely and continues to function at full quality.
How quickly can it be deployed?
Typically 2–6 weeks after a paid assessment, depending on the size of the document archive. Most of that time goes into ingesting and tuning retrieval over the firm’s own corpus, not the model itself - the Dubai/London deployment in the case study took six weeks over roughly 12,000 binding documents.
Is there vendor lock-in?
No. The models deployed are open-weight and owned outright by the firm. Changing models or providers later is a configuration change, not a migration project.
How is the cost calculated?
Fixed price per engagement, scoped after the discovery call and a paid assessment. Pricing is not published here because it depends on firm size, infrastructure, and integrations - the call exists to work that out honestly.
Who has access to our documents after deployment?
Only the users the firm provisions, through role-based access tied to its existing identity provider. No outside party - including the deployment team - retains standing access after handover.
Book a confidential discovery call.
Thirty minutes, no deck. You describe the firm's document workflows; the response is an honest read on fit, timeline, and whether a private LLM is the right tool at all.
Built and deployed by Nikita Chetverikov, a private-AI & fullstack engineer who ships on-premises LLM and private-RAG systems for regulated teams - LinkedIn · GitHub.
Prefer email? contact@zedbyl.tech
Read next
Shadow AI and the corporate data leak
Why staff pasting documents into public assistants is already happening at most firms.
Case studyPrivate RAG for contract review
How a 30-lawyer firm searches its own archive without a document leaving the building.
ReferenceFull FAQ on on-premises AI
Hardware, models, security, and pricing - plain answers.