Skip to content
PERINGER Data Solutions, back to home

Back

← All articles

Private AI for law firms: a risk-based architecture

Published · updated

By early July 2026, Damien Charlotin’s database listed more than 1,600 decisions in which a court established that a party had relied on references an AI had invented. A year earlier the database held about a hundred.

These cases combine two failures: the model produced something false and the human checks didn’t catch it. Checking shouldn’t depend on individual discipline alone. The system can push people to check, record that they checked and block certain uses outright. Showing a source passage makes an error easier to spot, but it doesn’t prove that the authority exists, that it’s current, that it’s relevant or that anyone has read it correctly. The lawyer stays responsible for the conclusion.

I’m an engineer, not a lawyer. What follows is a proposal for an architecture, and the firm has to check it against its actual matters, its providers and its duties.

Art. 321 SCC does not prescribe a machine; it requires control

Law firms misread this often, and the misreading is expensive. Art. 321 SCC punishes revealing a secret to an unauthorised third party. Nowhere does it say a lawyer has to do all the processing personally.

The Swiss Bar Association commissioned a university opinion and drew on it for its guidance on cloud services. The guidance accepts that a firm can use a cloud service when the provider is properly integrated as an auxiliary and the risks are controlled. That classification isn’t automatic. Four questions structure the analysis:

  1. the provider is selected with care;
  2. it is contractually bound to professional secrecy;
  3. it uses the data only to perform the contract;
  4. the outsourcing survives a case-by-case risk assessment.

Read the four as a specification, technical and contractual at the same time. A Swiss provider and a Swiss data location reduce some risks, but they don’t settle the matter. The firm still has to examine who has administrative access, which subprocessors sit behind the provider, who holds the keys, what gets retained, and how you leave at the end. Hosting abroad, or access from abroad, calls for its own assessment. Informing the client and getting the client’s agreement are further safeguards; depending on the circumstances the agreement may be implied, but it has to be demonstrable.

Follow that through. A firm that switches on a built-in assistant without mapping the data flow, without checking the contract, without informing clients where necessary and without writing the risk down can’t demonstrate control over the outsourcing.

The Bar Association’s AI guidelines stress confidentiality, competence, verification and accountability. An internal installation and a properly governed external provider are both options. A hybrid design may also be defensible when its risks are written down.

A three-tier model

TierWhat it isPrudent default placement
1Nothing from a matterAny model, public ones included
2Matter content stripped of direct identifiers but potentially still covered by secrecyA controlled Swiss service or another environment approved after risk and contract review
3The matter itself: pleadings, correspondence, exhibits and the firm’s archiveA dedicated, tightly controlled environment, internal or outsourced where the legal and technical analysis permits

The tiers are a risk model, not the wording of Art. 321 SCC. Tier 3 deserves the strongest controls, but the law doesn’t require tier 3 to stay on a machine the firm owns. A historical archive can create real research value; to use the archive you also need matter-level permissions, retention controls and a lawyer’s validation of every output.

The firm’s server

For a practice of five to twenty lawyers, a first service may fit on one machine in the server room. But that machine alone isn’t a production architecture: the firm has to decide what happens during a failure, during maintenance and during a restore.

  • One machine, one GPU: a 48 GB card serves a 30B-class open model to the whole firm. See three machines for running AI in-house.
  • vLLM to serve the model: a web interface on the firm’s own domain, behind the directory and sign-on the firm already has.
  • The archive index, on the same machine: twenty years of pleadings become searchable by meaning rather than by filename. See intelligent search.
  • The evidence behind each answer: the assistant shows the source passage and the reference, and controls verify that the document exists and that the quotation matches. A lawyer still checks authority, currency, relevance and reasoning.
  • Backups restored on purpose: a server that holds the firm’s archive without a proven restore is a professional-conduct risk. See the restore test.
  • Separate operational controls: encryption, patching, privileged accounts, logs, monitoring, proportionate redundancy and a fallback procedure matter as much as the GPU.

As an order of magnitude, a configuration like this may reach CHF 10,000–20,000 once you include the machine, the disks, the UPS and the commissioning. That’s not a quotation, and it may leave out integration, security, redundancy, backup, maintenance, energy, replacement and support. Compare it with a subscription only when you compare the full cost and the full service on both sides.

Tier 2 runs on a Swiss host serving open models under Swiss law. I described that full stack in internal AI without a US cloud, and a secure AI assistant plugs into it without tier 3 moving at all.

The checklist

A firm can establish where it stands before calling anyone.

  1. Where are my files right now? The network share, the mail and the office suite all count.
  2. Do my people have an internal tool? If they don’t, they’re using the public one.
  3. Do my access, my secrets, my mail hold the standard a review expects? See identity and access and the collaboration tenant.

One negative answer proves nothing on its own. Two or more suggest that the real issue is wider infrastructure and governance, and that AI merely makes the gap visible.

The points the engagement letter should reflect

A generic clause doesn’t, by itself, satisfy professional secrecy or establish valid consent. The engagement letter has to describe the firm’s actual design, and the firm should draft the letter after its analysis. It should cover at least:

  • the categories and purposes of service providers;
  • processing locations and access from abroad;
  • subprocessors and material changes;
  • confidentiality, security, retention and deletion;
  • any use of AI and a no-training commitment where one genuinely applies;
  • circumstances requiring client information or agreement;
  • restrictions specific to a matter or client.

The wording has to match reality. A firm shouldn’t promise exclusively Swiss processing, no public service or sole control of the encryption keys unless its infrastructure proves those claims. An overbroad clause turns an organisational gap into a breached contract.

The order matters: map the flows, select the controls, test the evidence, and only then state what the system genuinely allows the firm to promise.

The professional rules cited

The three tiers are a proposed risk model. They don’t replace analysis under Art. 321 SCC, the professional rules or the restrictions specific to a client and matter. The firm has to approve its own engagement terms.

Rules and case law consulted on 14 August 2026.

A first conversation, no commitment

A few lines about your project or your question are enough: I reply directly, usually within one working day.

Get in touch