Index · The training question

Do legal AI vendors train their models on client data?

There is no single answer, and that is the finding. Of the 108 legal AI vendors recorded on the Client Data in Training signal by the AI Legal Index, 8 prohibit training on customer content in the published agreement itself, 28 state it in a policy or trust page without a matching contract term, 3 train only where a customer affirmatively enables it, 1 train unless the customer turns it off, and 8 reserve the right to train in a published policy or agreement. The largest group, 60 vendors, publish no located term or policy addressing the question either way. Silence is a statement about disclosure rather than about the product, and it is also the one posture a firm cannot hold a vendor to.

This is the first question a general counsel asks and the one most often answered in a sales call rather than in a contract. The AI Legal Index records it on every vendor as the Client Data in Training signal, from published terms and policies, with a source and a verification date on each record. What decides the value is not whether the vendor says it respects confidentiality, it is where the commitment sits and whether a client can hold the firm to it.

Never, in the contract

Never, in the contract

The published agreement itself prohibits training on customer content. Not a policy page, the terms. This is the posture a firm can enforce, and it is the honest answer to which tools keep client data out of model training by default.

CloudLexPlaintiff & Claims AI
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
FilevinePlaintiff & Claims AI
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
IPRallyIP & Patents
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
JuroContract Review & Drafting
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
MyCaseIntake & Client Development
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
StenoLitigation & eDiscovery
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
TranscendRegulatory & Compliance Counsel
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.
XLSCOUTIP & Patents
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Never, in policy only

Never, in policy only

A public policy or trust page states no training on customer content, with no matching term located in the published agreement. A real commitment, revisable unilaterally.

The other side of the ledger

Jhana.ai record an opt out posture, meaning training occurs unless the customer turns it off. On 7 vendors the recorded value is Permitted, in the contract, meaning the published agreement expressly reserves a right to train on customer content with no opt out located: Clio, Genie AI, Neos, Securiti, Sirion, SmartAdvocate and Unity ELM. LegalVIEW BillAnalyzer records Permitted, in policy only. Any de identification or aggregation qualifier a vendor attaches is recorded in the summary on its profile, because a qualified reservation is still a reservation.

And then the largest group: 60 of 108 vendors publish no located term or policy addressing the question either way. A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product. For a buyer the practical consequence of silence is simple. There is nothing to enforce, so the answer arrives in a sales call and leaves no artifact behind.

Why the contract versus policy distinction decides this

A contractual prohibition sits in the terms a client can hold the firm to, so breaching it has a remedy. A policy statement is a public commitment the vendor can revise unilaterally. A marketing page that says your data is secure while the terms reserve a licence is a third thing again, and the gap between the three is where this risk actually lives. That is why the index records seven distinct values on this signal rather than a yes or a no, and why the tiers above are ordered by enforceability rather than by the warmth of the language.

The adjacent question, how long the product keeps what a lawyer typed, is recorded as Prompt and Output Retention on every vendor, and the full definition of every value on the training signal is on the signals reference.

Method and adjacent reads

Every record behind this page carries a source basis and a verification date, and a vendor that publishes a term tomorrow is redated the day it does. Standards and limits are on the methodology page. The accuracy side of the same diligence question is answered on which AI legal research tools publish their hallucination or accuracy rates, and the complete vendor set is in the directory.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 1, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746