Every AI product wants to improve with use. The honest question is how it does that — and whose data pays for the improvement.
The usual answer is that your content is the fuel. You use the tool, your documents flow to the vendor's servers "to improve the service", and the improvement is extracted from work you did on your clients' matters. The opt-out, if there is one, is buried three clicks deep in terms you didn't read.
We built the learning layer the other way round.
Off by default, and it means off
The self-learning layer does not run unless a firm turns it on. Not off-ish, not opt-out — off. When the layer is disabled, the recording code is a hard no-op; nothing is captured, because there is nothing to capture until the firm decides otherwise.
Turning it on takes an explicit confirmation in the firm's own settings, under the compliance section. It is a deliberate act by someone at the firm, not a default someone at the firm has to notice and undo.
What it learns, and where that stays
When a firm does opt in, the layer keeps a local journal of how the product's AI agents were used — which agent handled what, how a matter was routed, where a red flag fired, how often content was redacted. That journal lives on the firm's side. It is a record the firm can read, in a viewer that shows recent entries, and wipe on demand.
Before anything is written to that journal, a redaction pass strips personal identifiers — the national-insurance and tax numbers, passport numbers, postcodes, emails, phone numbers, amounts — the identifiers that make a record about a person rather than a pattern. That stripping happens on the firm's side, before the write, not on the way out to somewhere else.
The line we will not cross: matter content never leaves the firm boundary. What the layer was originally designed to share, had the firm opted in, was pseudonymised behaviour — the shape of how the tool was used, not the substance of what it was used on. We decided not to ship that sharing at all, so no shape and no substance leaves your firm: the learning stays local, and the product's prompts improve from our own work rather than from your usage.
Why we shipped the disclosure with the switch
A compliance officer cannot sign off on a feature they can't describe. So the layer ships with the paperwork a firm needs to fold it into its own privacy notice, its data-processing agreement, and its sub-processor list — drafted natively to the duties of each market, ready for the person responsible to review and sign. No external counsel required to work out what the switch does.
Where it is today, honestly
The opt-in toggle is live. The local journal captures on the firm's side when enabled. The redaction pass runs on every AI call. The parts that would carry pseudonymised behaviour to a central learner were built as a proof-of-concept and then DECLINED. We are not building them. There is no federation service, no upload endpoint, and none is planned — a firm's self-learning stays on the firm's own disk, and that is the finished shape rather than a stage on the way to something. We say so rather than leave you expecting a loop that is coming.
This is the same principle as the rest of the product: built by solicitors, for solicitors. A firm's data plane belongs to the firm. Learning is something you offer, with the paperwork attached — never something you take.
← All posts