Which legal AI vendors disclose which AI models they use?
Fewer than a buyer would assume, and the gap between naming a model and disclosing a supply chain is where most of the market sits. The AI Legal Index grades every vendor on Model Supply Chain Disclosure, which asks four things together: which models sit underneath the product, whose they are, where inference runs, and whether the vendor commits to telling customers when any of that changes. Of 148 legal AI vendors recorded, 7 answer all four, 43 name models or providers without completing the set, 57 gesture at the underlying technology without identifying anything a buyer could verify, and 41 publish nothing about the model supply chain a customer inherits. The complete disclosure tier is DecoverAI, GC AI, IPRally, Jimini AI, Noxtua, Spellbook and Vesence. A vendor saying it is powered by leading large language models has named nothing. A vendor saying which model, from which provider, running in which region, with notice on change, has told a firm what it is actually buying.
A model supply chain is the set of dependencies a customer inherits without choosing them: the model itself, the company that owns it, the infrastructure it runs on, and the terms attached to each. In most industries that is a procurement detail. In legal work it is a confidentiality question, because a firm cannot tell a client which companies see privileged material if the vendor has not said. The index grades this on Model Supply Chain Disclosure and records the law side of the same question as a separate signal. Both records are on every vendor profile with a source basis and a date.
- 7 of 148 vendors publish a complete model supply chain: models named, providers identified, inference location stated, and change notice committed.
- 41 publish nothing at all about what sits underneath the product.
- 4 of 149 name their primary law sources together with the licence basis for each, so most buyers cannot say where the law in the answer came from.
- 1 publish both halves. That number is the one worth watching, because the two questions are usually answered by different teams and almost never answered together.
The vendors that name the whole stack
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.An A on this axis is not a judgement about the models chosen. It records that a buyer can read, without a sales call, which models are in use, whose they are, where they run and what happens when that changes.
Named in part, short of the full set
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.These 43 vendors name models or providers and stop short of the complete picture. The most common missing piece is the change commitment, which matters more than it reads: a model swap is a routine engineering decision, and a disclosure with no notice attached is accurate on the day it is written and unverifiable every day after.
- AnkarIP & Patents
- AttiFin AIGeneral Legal Assistants
- AugustGeneral Legal Assistants
- Bloomberg LawLegal Research
- Blue JLegal Research
- CaseMineLegal Research
- CasepointLitigation & eDiscovery
- ChamelioContract Review & Drafting
- CheckboxLegal Ops & Spend
- ClioIntake & Client Development
- CoCounsel LegalGeneral Legal Assistants
- CUBERegulatory & Compliance Counsel
- DarrowPlaintiff & Claims AI
- DeepJudgeLegal Research
- DodonaiLitigation & eDiscovery
- EudiaGeneral Legal Assistants
- Genie AIGeneral Legal Assistants
- HarveyGeneral Legal Assistants
- JuroContract Review & Drafting
- LeahContract Review & Drafting
- LegalOnContract Review & Drafting
- LexroomLegal Research
- LitifyPlaintiff & Claims AI
- LuminanceContract Review & Drafting
- MalbekContract Review & Drafting
- MyCaseIntake & Client Development
- NeosPlaintiff & Claims AI
- NextpointLitigation & eDiscovery
- OmnilexLegal Research
- OnspringRegulatory & Compliance Counsel
- OntraLegal Ops & Spend
- ParambilPlaintiff & Claims AI
- QuestelIP & Patents
- RelativityLitigation & eDiscovery
- SmartAdvocatePlaintiff & Claims AI
- SmartDepoLitigation & eDiscovery
- Solve IntelligenceIP & Patents
- StenoLitigation & eDiscovery
- Streamline AILegal Ops & Spend
- SummizeContract Review & Drafting
- TradespaceIP & Patents
- WordsmithGeneral Legal Assistants
- XLSCOUTIP & Patents
The whole field, on one axis
| Grade | What it records | Vendors |
|---|---|---|
| A | Models, providers, location and change notice | 7 |
| B | Models or providers named, set incomplete | 43 |
| C | Technology described, nothing identifiable | 57 |
| D | Nothing published on the supply chain | 41 |
| Total | Vendors carrying a graded row | 148 |
50 of 148 vendors name something identifiable. The remaining 98 leave a buyer with a product description and no dependency list. Gated is not absent and is graded as its own tier: material a firm can pull from a trust portal without a sales conversation counts, material released only after a call does not.
Where did the law in this product come from?
Sources named and licensedNaming the model is half of what sits underneath a legal answer. The other half is the law itself, and the index records it separately as Primary Law Corpus Provenance. Of 149 vendors, 4 name their primary law sources together with the licence or public domain basis for each and an update cadence, 43 identify sources without stating the rights basis, 23 describe coverage by jurisdiction with no identification of the corpus underneath, and 79 publish nothing that identifies where the law in the product came from. Two separate risks sit on that one question. Coverage is the first: an answer drawn from a corpus that lags by months is confidently wrong in a way the reader cannot detect. Title is the second: legal publishing has already produced litigation over whether one company may build a research product on another company's editorial content, and a buyer who cannot say where the case law came from cannot price the risk that the corpus is enjoined.
Below that, 43 identify sources without stating the rights basis, 23 describe coverage by jurisdiction only, and 79 of 149 publish nothing located. A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Which vendors publish both halves?
1 of 148 vendors publish both halves: a complete model supply chain and a named, licensed primary law corpus. They are Noxtua. 6 disclose the full supply chain while leaving the corpus unidentified, which tells a firm who reads the question and not what was read to answer it. 3 name and licence the corpus without completing the supply chain, which is the reverse trade. Neither half substitutes for the other, and the reason this join is hard to find anywhere else is that no single vendor can publish it. It only exists across a market.
What the index cannot tell you
Whether an undisclosed stack is a good one. A vendor that publishes nothing about its models may be running a careful, well governed architecture, and the index records the silence rather than inferring anything behind it. The grade is a disclosure grade. It says what a buyer can find out without asking, which is the thing that matters when the person asking is a client and the answer is due this week.
These records also reach only as far as public material, and an absence is dated. It means not located in public sources on the date shown, and it is redated the day the vendor publishes. A vendor that walks a firm through its whole architecture in a procurement call and writes none of it down grades on what it wrote down, because a call leaves no artifact and an artifact is what gets forwarded to a client.
Every record behind this page carries a source basis and a verification date. Standards and limits are on the methodology page. The deployment half of the same architecture question is on which legal AI vendors offer on premise or private cloud deployment, the attestation half is on which legal AI vendors publish SOC 2 or ISO 27001 certification, what those models are permitted to learn from is on do legal AI vendors train their models on client data, what they get right when they answer is on which AI legal research tools publish their hallucination or accuracy rates, and the complete vendor set is in the directory.