← All issues

The AI Legal Index Brief

September 6 to 19, 2026 · Published September 19, 2026

The week in one line

OpenAI launched Astra for Law on September 17, and within two days fourteen vendors on this index had plugged their products in. That is convenient for lawyers, and it raises the question that matters now: do a firm’s ethical walls still hold once client material leaves the system built to protect it? Harvey, meanwhile, spent the fortnight on agents that ask permission before they act.

This issue covers two weeks, September 6 to 19, with 24 changes across 19 vendors. Two thirds were verified directly at the source. Sixteen of the changes landed on September 17 or 18, which in a change log is the equivalent of everyone in the room standing up at once.

Fourteen plugs, one socket

On September 17 OpenAI launched Astra for Law, a version of its latest model set up for legal work. It comes with its own legal search index, and selected firms get it first, inside ChatGPT and Codex.

OpenAI launched it alongside 26 plugins built by partners. Its pitch is that firms should get more out of the tools they already use, not replace them.

For this log, the story is who turned up. Within two days, fourteen vendors on this index had plugged their products into ChatGPT or Codex. Epiq took a broader route the same day, opening its applications to outside AI assistants in general.

The list reads like a tour of a law firm. It starts with the document systems, iManage and NetDocuments, and the eDiscovery platforms, Everlaw and Relativity. Then come the firm's records and knowledge tools from Intapp, Litera and DeepJudge, with Ironclad for contracts and Patlytics for patents.

Research arrives through Descrybe, UniCourt and Clio's Vincent, which went into Codex rather than ChatGPT. Legora and LegalZoom round out the list.

Two weeks ago this Brief argued that legal AI had stopped trying to be the place where the work happens and started reaching into the systems that hold it. It took twelve days for that sentence to need a sequel.

This fortnight the direction flipped. The systems that hold the work reached back, all at once, into the same assistant. A lawyer can now ask one question and reach the matter file, the evidence, the time entry and the docket without leaving the chat.

That is plainly convenient. It also means each system's access controls now have to keep working inside the assistant, which is not where any of them were designed to work.

Our read

A plugin announcement tells a firm that a connection exists. It does not say whose permissions the connection uses, what it can change, or where the text goes once it is in the conversation. Those answers are the real product, and this fortnight's releases give them unevenly.

Read, write or administer

Put the releases side by side and they describe very different things. That difference is what a firm is actually buying.

Some plugins read. Everlaw's works on the substance of the case evidence, not just its metadata, and it runs on the data already in Everlaw, permissions intact, rather than on a copy.

DeepJudge pulls source material from the firm's own documents. Litera answers questions about the firm's experience, relationships and people. Ironclad searches the contract repository, and Patlytics runs patent searches against the firm's own patent data.

Some write. iManage lets a lawyer draft in ChatGPT and save straight to the matter file. Intapp's plugin can create and update records, and can flag work that may need a time entry.

One stays out of the documents on purpose. Relativity's connection handles administration, such as setting up matters and managing access, and leaves the actual review inside Relativity aiR. It made the same choice when it connected to Google's Gemini Enterprise for Legal on August 25, so this looks like a policy rather than a one off.

And one says very little. NetDocuments describes its plugin as a way to find and switch on NetDocuments inside ChatGPT. That leaves firms to work out for themselves whether it reads documents or only locates them.

The pair worth studying is the eDiscovery one. Everlaw and Relativity sit in the same category and launched on the same day, yet they drew opposite lines. One took the assistant into the evidence. The other kept it at the front desk.

Neither is wrong. They are two answers to how much of a privileged production a general assistant should see, and a litigation team will want to know which one it bought before a protective order asks.

Our read

Soon every vendor comparison in this market will note whether a tool has a ChatGPT plugin, and on its own that tells a buyer nothing. What matters is whether the plugin reads, writes or only administers, whose permissions it uses, and what it logs. Four vendors can make the same announcement and carry four very different risks.

The walls arrived a week early

This was not Intapp's first ChatGPT plugin. On September 10 it released one for ChatGPT for Financial Services, built on DealCloud, that enforces the firm's information barriers on every answer. A user sees only what they could already see in DealCloud.

A week later the same promise arrived for law firms. Intapp says its new plugin respects the ethical walls and need to know rules a firm already has. Intapp sells the walls product most large firms run, so for its plugin the wall is the product, not a feature.

DeepJudge and iManage make similar promises from the document side. DeepJudge's search already respects a firm's permissions and walls, and the open question is whether that still holds once results sit in ChatGPT. iManage writes back into the matter file, which keeps the records system intact. What the launch does not spell out is whether iManage's matter security also controls what the plugin can read.

Underneath all three sits the same problem. A wall is enforced by the system that holds the matter. Once text leaves that system and lands in a conversation, the conversation becomes the new container.

Its retention, sharing and training settings are now part of the firm's confidentiality posture, whether anyone decided that or not. OpenAI's own launch makes the point for us, since it says it is expanding its privacy and governance controls for confidential client work. That is the right instinct, and a fair signal of where the risk now sits.

Buyer question

Before switching on a plugin that touches privileged or walled material, ask three things. What does it return to a user on the wrong side of a wall? Does it retrieve as that user or as a shared service account? And which retention settings apply once the text is in the conversation? A plugin that answers the first question but not the last has moved the wall rather than kept it.

Research got a default, and a rival rebuilt the citator

Astra for Law comes with its own index of case law, statutes, regulations and court rules. OpenAI also published how well it performs. On its own testing, it passed 54 percent of 200 legal research questions, against 38.7 percent for the same model using ordinary web search.

That is not a number a marketing team would have picked. Publishing it anyway is exactly the kind of disclosure this index grades vendors on.

It also changes things for three research vendors that plugged in the same week. Descrybe brought what it calls structured, verifiable US primary law into ChatGPT Enterprise, on the very day ChatGPT gained a legal index of its own. UniCourt brought in dockets from more than 5,000 state and federal courts. Clio took Vincent's research, sources attached, into Codex.

A research plugin used to fill a gap. Now it has to beat a built in default. Docket data has the easier case, because dockets are structured and easy to check. Primary law has to win on coverage and citation accuracy, tested on the buyer's own questions rather than anyone's press release.

Legora made the opposite bet three days earlier. On September 14 it said it is rebuilding its research tools on an ontology of the law, in effect a map of how legal authorities relate, plus an AI native citator. Both use technology from two companies it acquired, Qura and Wexler.

The map covers amendments, holdings versus dissents, and whether a rule still applies. Attorney editors who used to work at legal publishers set and audit the citator. It is in limited beta now, with general release planned for Q4.

A citator tells you whether a case is still good law. It is the part of AI research that buyers have had to take on faith, and it is where the sanctions cases came from. Legora also says it has catalogued more than 50 distinct ways AI fails at legal research.

That list is the most useful thing in the announcement, because any buyer can test any research tool against it, Legora's included. Nobody publishes fifty ways their category fails unless they expect to be graded on it.

Legora also shipped a ChatGPT Enterprise plugin that week, and OpenAI named it as one of the companies that will build on Astra for Law. It is on both sides of the socket, which in this market is starting to look like the normal place to stand.

Agents that ask first

Harvey logged four changes in the fortnight, and all four are about what an agent is allowed to do once it is inside a firm.

On September 8, Agentic Vault Search became generally available. It works only within the user's own Vault permissions and ethical walls, and it logs every file it touches.

A companion feature, Agentic Vault Organization, is in early access. It shows its full plan of renames, moves and tags before changing anything, waits for confirmation, can undo its last set of changes, and never edits what is inside a file.

On September 9, Memory arrived for individual users across the Assistant, the Word add in and Playbooks. Nothing is saved until the user confirms it, and every memory can be viewed and deleted. Admins decide who gets the feature, Harvey shows which memory it used the way it cites a source, and it says memories are never used to train models.

On September 10 came Contract Review Agents, in early access. A team builds one from its signed contracts and playbooks. The agent then compares each counterparty proposal with what the team has actually accepted before, and flags when recent deals have drifted from the team's own standards.

And on September 17, Harvey let its agent take over actions in Review Tables. Its example is a privilege review: reclassifying the privilege column, pulling in custodian data from a Relativity export and routing flagged rows to a named reviewer.

Put together, this is a design for oversight rather than a list of features. The agent uses the user's own permissions, shows its plan before acting, asks before remembering anything, logs what it touches and never quietly changes content. Those are the questions a risk committee would otherwise raise in a meeting, answered in the product.

The drift detection deserves its own paragraph. Every in house team negotiates from what it has actually accepted, while writing down what it says it accepts, and nobody owns the gap. An agent that tells a team its playbook is six months out of date is doing a job nobody currently has. That will be either very useful or quite awkward at the next team meeting, and probably both.

LinkSquares reached the same idea from the contract management side. Its Workflow Builder Agent turns a process described in plain English into the steps and routing needed to run it. Every workflow stays in a controlled space where the team reviews and edits it before anything goes live.

Our read

The plugin wave settled where an assistant can reach. Harvey and LinkSquares spent the same fortnight on what an agent should do once it gets there, and that is the question that decides whether a rollout survives its first incident. Memory is the next test. Harvey's is limited to the individual user today, and the version it says is coming next, shared across a matter or a whole organisation, is the one that will need a written policy.

Market notes

Lexroom made its first two acquisitions: Query Juriste, a French legal research company, and Praven Intelekt, a Bulgarian legal AI assistant. It now operates in Italy, Germany, Spain, France and Bulgaria.

Lexroom's argument is that each civil law country needs its own source base, rather than one model trained on everything. Buying local companies with local legal libraries is that argument in action. Customers of the acquired products should expect names, and possibly the products themselves, to change as the brands fold into Lexroom.

Patlytics brought patent search into ChatGPT. That puts one of the most sensitive documents a client ever hands over, the unfiled invention disclosure, one question away from a general assistant. The firm's training and human review settings are the whole answer there.

Epiq's connection raises a different question, because much of its work runs as a managed service. The person on the other end could be the client, an Epiq reviewer or both, and the matter record should say which.

LegalZoom's plugin is aimed at attorneys, but the company sells to small businesses as much as to lawyers. The line between legal information and legal advice now runs through a general assistant, and that line is where unauthorised practice risk sits.

CUBE now feeds its regulatory intelligence into IBM watsonx.governance. A new horizon scanning feature matches changes in AI regulation to the AI systems a company actually runs, and keeps a record of each assessment. Governance teams have been doing that matching by hand. The catch is that it only helps companies already on IBM's product.

What the fortnight says about the category

Two weeks ago the story was legal AI reaching into the systems where the work lives. This fortnight those systems reached back, all at once, into one assistant. Relativity has now done the same with a second assistant from a different company.

That changes what a legal AI vendor is selling. When fourteen vendors connect to the same assistant in the same two days, access to a strong model stops setting anyone apart. What still does is what a plugin cannot borrow from the socket: data only that vendor holds, a citator that knows whether the law is still good, and an agent that shows its work before it acts.

For buyers, the question is no longer which assistant to pick. It is which of the firm's systems trust which assistant, on whose permissions, and what happens to a privileged paragraph once it crosses over. A handful of vendors have answered that in writing. The count is below.

Index Answer

Which legal AI tools respect a firm's ethical walls when they connect to its systems?

Few, going by what vendors publish. The AI Legal Index records how every vendor it grades handles ethical walls and matter segregation, 282 vendors at the time of reading.

Only 8 of them show in writing that the tool checks each user's own access rights in the source system every time it retrieves something. That is the kind of wall that keeps holding when the tool is connected to something else.

Another 87 run a permission model of their own and explain it. That works, but it leaves the firm keeping two sets of access rules in step. A further 72 say they keep matters separate without explaining how, and the remaining 115 say nothing about walls at all.

Now look at the 15 vendors that connected to an outside assistant on September 17 and 18. DeepJudge, iManage and NetDocuments document that per user check. Descrybe, Ironclad and Relativity run their own permission models and explain them. Of the rest, 5 say they keep matters separate without explaining how, and 4 say nothing about walls.

These records describe each vendor's own product, and most were written before this week's plugins existed. A plugin could turn out better or worse than its record. But the record is still the place to start, because a plugin inherits whatever permission model sits underneath it.

A vendor that already documents per user checks has answered half the plugin question in writing. A vendor that has never explained how its walls work is asking firms to trust the plugin's walls on the same faith.

For the full picture, the document system integration page sets how deeply each vendor connects against how it enforces walls, and the privilege protection page has the confidentiality record for every vendor.

The AI Legal Index Brief is published by AI Legal Index, an independent reference for evaluating the AI software used in legal work. No vendor pays for inclusion, placement, or rating. Grades and signals for every vendor named here are on the vendor directory, and the grading method is on the methodology page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 18, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746