Due diligence data rooms and AI: privilege is the constraint
Law firms can use modern AI on a due diligence data room without endangering privilege only when the review runs on their own hardware, air gapped, with every action sealed to a verifiable record.

Law firms cannot defensibly send a due diligence data room to a cloud AI service, because privilege and client confidentiality depend on control that ends the moment a document leaves the firm's estate. The route that works is to bring the AI to the documents rather than the documents to the AI: review that runs on hardware the firm owns, on premise and air gapped, where no file and no prompt ever leaves the building and every action is sealed to a tamper evident record. We build for exactly this constraint, and the oldest rule in legal practice explains why.
Why is privilege the real constraint on AI in due diligence?
Because privilege rests on confidentiality, and confidentiality is precisely what a third party processing arrangement puts in question. Under English law a communication attracts privilege only while it remains confidential, and the courts have treated careless disclosure to third parties as a risk to that protection. A data room concentrates the most sensitive material both sides possess: the client's instructions and advice, the target's contracts, disputes, regulatory correspondence and employee records, held under confidentiality obligations and usually a non disclosure agreement. Introducing an external AI service introduces a new recipient, and every new recipient is a question the firm may one day have to answer.
What has the SRA said about confidentiality and AI tools?
The Solicitors Regulation Authority has been clear that the duty of confidentiality does not bend for new technology. The SRA Code of Conduct requires solicitors to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents, and the regulator's published research on artificial intelligence in the legal market presses firms on confidentiality and data protection as risks they must actively manage when adopting AI. None of this prohibits the technology. It demands that firms adopt it on terms they control, with the same discipline applied to anyone else given access to client material.
Why does cloud AI create a disclosure question at all?
Because a cloud service must receive and process documents on infrastructure the firm neither owns nor supervises. From the moment of upload, the firm relies on the provider's promises about staff access, sub processors, retention, security and training use, in every jurisdiction that infrastructure touches. Even with well drafted terms, the firm has moved from a position where no third party ever held the material to one where it must argue that the disclosure did not compromise confidentiality. In a privilege dispute that is an argument to be won. On premise, it is not even a question.
What does sovereign review of a data room look like?
It looks like the review running inside the firm, on the firm's own hardware, with the outside world physically unable to see it. Mickai is a Sovereign Intelligence Operating System, a SIOS, installed on the customer's own machines, on premise and air gapped. Applied to a data room, our document review capability reads the package the way a diligent first pass team would, then goes further than billable time usually allows.
- Reads every document in the room and builds the cross references a manual first pass rarely completes, linking contracts to amendments, disclosures to schedules and correspondence to the matters it concerns
- Flags anomalies, gaps and inconsistencies, such as a missing counterpart signature or terms that change between versions, and holds them for a lawyer rather than deciding anything itself
- Drafts first pass summaries and issue lists for the deal team to review, amend and own
- Keeps every prompt, document and output inside the building, because there is no connection over which they could leave
- Seals every action to the Open Audit Record before it runs, a cryptographically signed, tamper evident account of what was reviewed, when and under whose clearance
The last point matters more in legal work than almost anywhere else. If a client, an opponent or a regulator asks how AI touched a matter, the answer is not a policy statement. It is a sealed, verifiable record.
“A firm should never have to argue that its use of AI did not breach confidentiality. The architecture should make the question impossible to ask, because nothing ever left the building.”
What stays with the lawyers?
Everything that matters. Judgement, advice, negotiation and disposition remain with the qualified people who owe the duties. The system does the patient work, the reading, the cross referencing, the flagging, and it stops at the point of consequence. Consequential actions wait for a person's clearance, and access to the review can be gated by voice biometrics so only those entitled to a matter can open it. A machine should extend a lawyer's reach, never replace a lawyer's responsibility, and the Open Audit Record makes the human chain of responsibility provable years later.
Where does this leave deal teams next?
The direction of travel is visible on both sides. Regulators, led in England and Wales by the SRA, will keep sharpening expectations of how firms supervise technology, and clients in regulated and sensitive sectors are already asking their advisers where documents go. Firms that can answer that the review runs on their own hardware, with every action sealed to a record they can prove, will find that answer becoming a competitive asset in pitches as well as a compliance position. We expect sovereign, on premise review to move from an unusual choice to the default posture for privileged work, because it is the only posture that leaves nothing to argue about.
Frequently asked questions
Does using a cloud AI tool waive privilege?
Privilege depends on confidentiality, and disclosure to third parties is the classic way confidentiality is lost. Whether a particular arrangement compromises privilege is a legal question on its own facts, and firms should take their own advice. The structural point is simpler: a review that never discloses material to any third party never raises the question.
Is a provider promising not to train on our data enough?
A contractual promise reduces one risk among many, but client material still sits on infrastructure the firm does not control, subject to the provider's staff access, sub processors and security. The confidentiality duty is the firm's and cannot be outsourced along with the documents. Keeping material on the firm's own hardware removes the dependency entirely.
Can an air gapped system still be useful on a live deal?
Yes. The data room is loaded onto the firm's own hardware and the review runs entirely locally, so speed and depth do not depend on any connection. Air gapped means the documents cannot leave, not that the work slows down.
What is the Open Audit Record?
It is our evidence layer: a cryptographically signed, post quantum, tamper evident record of every action the system takes, sealed before the action runs and verifiable offline. For a law firm it means the history of what was reviewed, what was flagged and who cleared each step can be proved later without trusting anyone's recollection.
Does the system give legal advice?
No. It reads, cross references, flags and drafts, and it holds anything consequential for a person. Advice, judgement and sign off remain with the qualified lawyers on the matter.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on premise and air gapped, so no document or prompt ever leaves the building. Every action is sealed to the Open Audit Record, a cryptographically signed, tamper evident record that is verifiable offline and sealed before an action runs. MICKAI comprises 87 studios, with ten production ready at launch and 77 in development, and its architecture is covered by 104 filed UK patent applications across 2,340 claims, filed rather than granted, owned by Mickai LTD.