TrustArc

TrustArc is a privacy management platform for privacy, legal and compliance teams, sold as a suite of applications: PrivacyCentral for running a privacy programme against laws and regulations, Data Mapping and Risk Manager and a Data Inventory Hub, Assessment Manager for privacy and AI risk assessments, Cookie Consent Manager, a customer-facing Trust Center product, and Nymity Research, a subscription library of regulatory summaries and operational templates updated daily. Its AI layer, branded Arc Intelligence and Nymity AI, adds a research chatbot over the Nymity library, an assistant inside PrivacyCentral, similarity lookup and autofill of records and assessments, bulk record creation in the data inventory, an evidence analyser, translations, cookie-purpose research and executive summary reports, with every AI feature optional and off until a customer uses it. The company also operates TRUSTe assurance and certification programmes. The company is TrustArc Inc., a Delaware corporation headquartered in Walnut Creek, California, and it publishes a full legal centre: a subscription and services agreement, end-user terms for partner channels, a data processing addendum, technical and organisational measures, a government request policy committing to advance notice of demands for customer data, a sub-processor disclosure with locations and transfer mechanisms, and a dedicated terms of use for AI features that maps each AI feature to its technology and provider, states that customer data is not used for model training or improvement, and commits to thirty days' notice before any adverse change to a provider relationship. It states annual SOC 2 Type II assessment by an external auditor, and names the New England Journal of Medicine among its customers.

Vendor siteWalnut Creek, California, United States
Last verifiedSeptember 6, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Artificial intelligence is present and peripheral by the vendor's own construction. The Terms of Use for AI Features state that use of any AI-enabled feature is strictly optional, that no customer data is processed by AI technologies unless the customer uses such a feature, and that the customer may discontinue them at any time; Table 1 lists the features as assistants, lookups, autofill, similarity search, bulk record creation, translations and summaries layered onto PrivacyCentral, Data Mapping, Assessment Manager, Cookie Consent Manager, Trust Center and Nymity Research, each of which functions as a privacy management, assessment or research product without them. Arc Intelligence reached general availability in December 2025 on a platform in operation for decades. This is the legacy-platform case the brief asks the axis to discriminate, and it does. AI Terms, legal centre index and product navigation read 6 September 2026.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is disclaimed without measurement, and grounding is to a subscription corpus the reader cannot open. The AI Terms state that TrustArc takes measures designed to ensure accuracy but is not responsible for the quality, accuracy or effectiveness of AI-generated output and that every output must be reviewed, with a subject-matter expert if needed, before use; the NymityAI research chatbot answers over the Nymity library of regulatory summaries and templates, which is licensed content rather than primary law a reader can verify without a subscription. No accuracy figure, test set, evaluation or description of how answers cite their sources is published on the surfaces read. AI Terms, product navigation and trust centre privacy notice read 6 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A written commitment to human oversight with real review surfaces, short of the full control structure. AI Terms section 2.1 requires the customer to review and validate AI outputs and not rely on them for decision-making without human oversight, section 1.1 requires notice before any AI technology processes customer data and makes every AI feature optional and revocable on request, and the features themselves are assistive, with suggestions, lookups, autofill and an evidence analyser that a user accepts into an assessment or record. What is not published is any threshold at which the system acts without a person, any description of what executes automatically, or a stated route back after an output is wrong beyond the customer's own review. AI Terms and product navigation read 6 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

A named customer without figures, and figures without a named customer. A published case study names the New England Journal of Medicine and its data protection officer, Sean McInnis, describing a migration of a cookie consent tool and the support received, with no measured outcome; a second case study attributes figures to an unnamed Fortune 500 consumer products company: time to compliance cut by up to fifteen per cent, privacy programme operating expenses reduced by sixteen to thirty per cent, and more than three quarters of privacy processes automated, with no method stated. Nothing joins a named customer to a figure, and the AI features are not the subject of either study. Two case study PDFs read 6 September 2026; the customers index was not opened.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments on training use, third-party providers and deletion, short of the full picture on segregation and privilege. No training: AI Terms section 1.1(b), incorporated into the customer agreement, states that customer data will not be used for AI model training, model improvement or any similar purpose, and 1.1(d) that the third-party AI technologies are explicitly opted out of LLM training and used solely to generate responses for authenticated users within the TrustArc environment. Third-party providers: Table 1 names them feature by feature. Retention and deletion: the subscription agreement gives a thirty-day retrieval window after termination followed by deletion, and the AI Terms commit to ceasing AI processing promptly on request. Not located: any statement on segregation between customers or matters, since the technical and organisational measures document was not opened, and any treatment of privilege or work product. AI Terms, subscription agreement fragments and trust centre privacy notice read 6 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real position on tooling versus expertise, short of a drawn advice line and jurisdiction limits. AI Terms section 1.2(b) requires the customer to review all AI output before use, suggesting consultation with an internal or external subject-matter expert, and section 2.1 bars relying on outputs for decision-making without human oversight; the buyer is stated as privacy and compliance teams. The Nymity library publishes legal summaries and the research chatbot answers from them, and no located surface states whether those outputs are or are not legal advice; the subscription agreement, which a third-party summary describes as stating that use of the solutions does not guarantee compliance, could not be fetched in full because the site blocks automated retrieval, so that line is not credited. No jurisdiction limit is named. AI Terms and subscription agreement fragments read 6 September 2026.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Published AI-use commitments without a governance mechanism, testing regime or accountable owner. The AI Terms are substantive on data use, provider transparency, opt-out and change notice, but they say nothing about who inside TrustArc is accountable for the AI features, what is tested before a feature ships, or what has been found about uneven output; no responsible AI page, ISO 42001 or equivalent certification, or model evaluation is published on the surfaces read. The Assessment Manager product sells AI risk assessment to customers, which is governance of the customer's AI rather than TrustArc's own. AI Terms, product navigation and trust centre read 6 September 2026.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published policy covering most of the ground, with access control not read. Retention: the subscription agreement retains customer data for thirty days after termination for retrieval, then permits deletion except for legally required copies; the trust centre privacy notice retains personal information only as long as necessary and places data about individuals named in customer assessments under customer control. Deletion: the AI Terms commit to ceasing AI processing on request. Sub-processors: a public disclosure lists each with location, purpose and transfer mechanism, with emailed notice thirty days before any addition and a subscription to receive it, plus a separate affiliate list. Incident practice: AI Terms section 1.3 commits to prompt notice of any security incident involving AI-related processing under the agreement or DPA. Access control: the technical and organisational measures document and DPA of February 2024 exist in the legal centre and were not opened; the trust centre security page states TLS 1.2 in transit and AES-256 at rest with intrusion detection and logging. Surfaces read 6 September 2026.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

A real published position on liability, short of the full picture because the subscription agreement could not be read end to end. Recovered through the search index from the subscription agreement: section 8.1 gives a TrustArc defence and indemnity for third-party claims stated to be its entire liability and the customer's exclusive remedy for such claims, with exclusions for modifications, combinations and non-compliant use; section 8.2 has the customer indemnify TrustArc for customer data and other matters; section 7.2 warrants core functionality against documentation, no material decrease during the term, malicious-code measures and diligent services. The end-user terms for partner channels cap either party's liability at fees paid for the applicable solution in the preceding twelve months. AI Terms section 2.1 provides the AI features with the same warranties and exclusions as the solutions and section 1.2(b) disclaims responsibility for the quality and accuracy of AI output. The agreement's own cap, consequential-loss exclusions and carve-outs were not readable because the site returned bot detection on fetch on 6 September 2026; that is a limit on this reading and the agreement is the rebuttal route.

Source: Vendor Published
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integrations are referred to without documentation an implementer could use on the surfaces read. The subscription agreement contemplates customer-enabled Third-Party Applications with data exchange on the customer's behalf, and the Trust Center product page describes pushing documents from content systems, notifying Slack and creating ServiceNow tasks through TrustArc Integrations. No integrations page or documentation was opened, no practice, document or matter system is named in the material read, and nothing describes what syncs or in which direction for the privacy applications. Subscription agreement fragments and Trust Center product page read 6 September 2026; the integrations surface is the rebuttal route.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is stated with partial residency detail and the tenancy model is not addressed. The sub-processor disclosure gives a location for each processor, including Microsoft in Washington and Canada Central for logging and messaging and Mailgun in Texas for research alerts, and the AI Terms place one feature, Ask Arc, on Anthropic in the United States or Bedrock in the EU, which is a region choice stated for that feature alone; the trust centre security page names an enterprise-grade cloud hosting provider without naming it. Nothing states whether customers share infrastructure or where the platform's primary data store sits, and no residency option is described for the platform as a whole. Sub-processor disclosure, AI Terms and trust centre security page read 6 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real and stated on a trust centre that renders, short of a report reachable without asking. The trust centre security page states an annual assessment by a qualified external third-party auditor against the AICPA SOC 2 Type II standard, alongside TLS 1.2 in transit, AES-256 at rest, intrusion detection, logging and incident response plans; the trust centre carries privacy, security, availability and legal sections. No auditor is named, no coverage period is stated, and the report itself sits behind the trust centre's permissions, which the vendor's own Trust Center product page describes as keeping SOC 2 reports behind confidentiality requirements; no request was submitted. No ISO certification is stated on the surfaces read. Trust centre security page and Trust Center product page read 6 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The most granular provider disclosure in the pull, held off A because the models themselves are not named. Table 1 of the AI Terms maps every AI-enabled feature to its AI technology and third-party provider: the Azure AI Platform from Microsoft for the Nymity research chatbot and lookups, the OpenAI API for autofill, similarity search, bulk record creation, evidence analysis, summaries and cookie research, the Gemini API from Google Cloud for translations and assisted upload, and for Ask Arc either Anthropic in the United States and Bedrock from Amazon in the EU or the OpenAI API, depending on which of the two versions of the table the page renders. Section 2.2(b) commits to thirty days' notice and a right to object before any modification that materially and adversely affects the customer, including changes to provider relationships, and section 1.1(d) states the providers are opted out of LLM training. The page carries two versions of Table 1 with different entries for Ask Arc, which is recorded as an inconsistency a buyer will see. The technology column names platforms and APIs rather than models. AI Terms read 6 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information was located on any surface read, at any level. The legal centre lists agreements and policies with no pricing document, the subscription agreement refers fees to the order, the AI Terms refer to usage limits such as daily query caps without a charge, and the supplier's pre-screen recorded no pricing page. The home page navigation was read only in excerpt, so the existence of a pricing page was not established by inventory, and this row is rebuttable on that page if one exists. Legal centre index, AI Terms, subscription agreement fragments and end-user terms fragments read 6 September 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment and coverage described with substance; the boundaries are left open. The buyer is stated as privacy, legal, security and compliance teams in enterprises, with the Nymity library covering privacy regulations, legal summaries and operational templates globally and product navigation naming the EU AI Act, India's data protection law and the EU-US Data Privacy Framework among covered regimes; case studies span healthcare and publishing and consumer products, and the TRUSTe assurance programmes serve a separate certification market. What is not stated is where the product stops: no jurisdiction or regulation is named as unsupported and no law firm use is described. Product navigation, case studies and AI Terms read 6 September 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in the contract

The published terms prohibit training on customer content. Not a policy page, the agreement.

The commitment is in the agreement. The Terms of Use for AI Features, last updated November 2025 and incorporated into the customer's agreement, state at section 1.1(b) that TrustArc will not use customer data for AI model training, model improvement or any similar purpose beyond the authorised use of the AI-enabled features, and at 1.1(d) that the third-party AI technologies reached through API calls are explicitly opted out of large language model training and used solely to generate responses for authenticated users inside the TrustArc environment; the trust centre privacy notice repeats that AI services are opted out of LLM training by default. No aggregation or de-identification qualifier appears. Surfaces checked 6 September 2026.

Source: Vendor PublishedTrustArc will not use your Customer Data for AI model training, model improvementAs of Sep 6, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed fixed window

A specific retention period is published and the customer cannot change it.

A specific period is published and the customer cannot change it during the term. Subscription agreement section 11.5 keeps customer data available for retrieval for thirty days after termination, after which TrustArc has no obligation to maintain it and may delete or destroy all copies except any it must retain for legal purposes; the AI Terms add that AI processing under any disabled feature ceases promptly on request and that AI services process data only to generate responses, and the trust centre privacy notice retains personal information only as long as necessary. Nothing states a configurable window for prompts and outputs during the term. The subscription agreement was recovered in fragments through the search index because the site blocks automated fetching. Surfaces checked 6 September 2026.

Source: Vendor Publishedfor thirty (30) days following the termination of this AgreementAs of Sep 6, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

No located public material addresses segregation between customers or matters. The AI Terms state that AI services generate responses only for authenticated users within the TrustArc environment, which is an access statement rather than a description of how one customer's data is walled from another's, and the technical and organisational measures document and DPA of February 2024 in the legal centre, where such a description would sit, were not opened on 6 September 2026 and are the rebuttal route. AI Terms, trust centre privacy notice and security page checked.

Source: Operator VerifiedAs of Sep 6, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

A published Government Request Policy for Customer Data in the legal centre commits to notice: TrustArc will not disclose customer data to government authorities unless required by law or to prevent serious injury or death, will alert customers with as much advance notice as possible so they may object unless prohibited, will give notice as soon as permissible where advance notice is not possible, and will typically ask a government to submit requests for customer-controlled personal data to the customer directly. Whether the DPA of February 2024 carries a matching contractual term was not established, since that document was not opened. No transparency report is published. Surfaces checked 6 September 2026.

Source: Vendor Publishedalert Customers with as much advance notice as possibleAs of Sep 6, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The source behind the research answers is identified without a stated rights basis. The NymityAI research chatbot answers over the Nymity Research library, described by the vendor as more than fifty thousand expert privacy references, legal summaries and operational templates updated daily; the library is TrustArc's own subscription content, so the corpus is named, but nothing states the primary-law sources it summarises, the licence or public-domain basis for them, or the update method beyond the daily claim. Product navigation and AI Terms read 6 September 2026.

Source: Vendor PublishedAs of Sep 6, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history. The research product summarises regulations and guidance rather than citing case law, and no citator or treatment signal is described. Recorded as the honest value for a product without that function. Surfaces checked 6 September 2026.

Source: Operator VerifiedAs of Sep 6, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the AI features do when they cannot ground an answer. The AI Terms warn that outputs may contain errors and require review, and impose usage limits such as daily query caps, but describe no abstention path or confidence signal. Surfaces checked 6 September 2026.

Source: Operator VerifiedAs of Sep 6, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming TrustArc, Nymity or TrustArc Inc. was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both product names together with a general search for court findings; results returned sanctions involving general-purpose chatbots, none of which is this product. This is a statement about the public record, not a finding about the product.

Source: Operator VerifiedAs of Sep 6, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. The AI Terms require human oversight and expert review of outputs and the product content engages extensively with privacy statutes, but no ethics opinion, bar rule or professional responsibility framework is named on any surface read. AI Terms, legal centre and product navigation checked 6 September 2026.

Source: Operator VerifiedAs of Sep 6, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The buyer is an in-house privacy, legal or compliance function that bills no client, so the product sits outside a lawyer-to-client fee relationship. The published savings claims are operational and attributed to an unnamed Fortune 500 customer, privacy programme operating expenses reduced by sixteen to thirty per cent and more than three quarters of processes automated; nothing addresses how AI-assisted work is recorded or disclosed on any bill, and no law firm is a named buyer segment. Surfaces checked 6 September 2026.

Source: Vendor PublishedAs of Sep 6, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

A sub-processor list, a model provider list and client-facing disclosure material are all published without an agreement in place. The sub-processor disclosure lists each processor with location, purpose and transfer mechanism, with thirty days' emailed notice of additions and a subscription for it; Table 1 of the AI Terms maps every AI feature to its provider, Microsoft, OpenAI, Google Cloud and, for one feature in one version of the table, Anthropic and Amazon; and the AI Terms, the government request policy and the DPA are published in the legal centre in a form a firm could forward. Surfaces checked 6 September 2026.

Source: Vendor PublishedTable 1: AI-Enabled Features ... AI Technologies ... Third-Party ProviderAs of Sep 6, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses court disclosure or verification certification of AI-assisted work. The product produces privacy assessments, records and research summaries rather than court-facing work product, and nothing describes a per-document record of model used, sources retrieved and human verification. Surfaces checked 6 September 2026.

Source: Operator VerifiedAs of Sep 6, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 6, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746