What keeps mid-size law firms up at night about AI

The most common AI concern at mid-size law firms is not data leakage or hallucinations. It is picking the wrong tool, with no credible way to evaluate before committing. 44% of firms named tool selection as their dominant fear, ahead of billing model disruption, data security, and the gap between deploying AI and actually getting attorneys to use it. The anxiety is rational. The evaluation criteria for AI tools are still being written by the same firms that have to live with the decision.

What mid-size firms reportShare
Top concern: picking the wrong AI tool44%
Concerned about billing disruption from AI efficiency28%
Report attorneys not using deployed AI tools33%
Worried about data leakage or confidentiality22%

How we know this

Sidebar puts one question a week to legal management professionals at firms of 10 to 200 attorneys. Members are verified by title, employer, and firm size before they are admitted, and every reply is private. This page draws on every Sidebar cycle that has touched this question, and it is updated as new replies come in. We publish patterns across the group, never individual firms, and only once at least five members have replied to that question. Full methodology at gosidebar.ai/methodology.

Paralysis is the rational response to a broken evaluation market

Tool selection is the number-one concern, and the reason is structural. AI tools in legal technology are changing faster than any firm evaluation cycle. By the time a committee finishes due diligence, the vendor has released two updates and a competitor has entered the same category. Waiting for the market to settle has a logic to it. The cost is that firms moving forward, even imperfectly, are building operational advantages while the committee reconvenes. There is no version of this evaluation that resolves cleanly. A firm that waits for certainty is waiting for a moving target to stop moving, and the tools that looked strongest a year ago are not the ones anyone would pick today.

The guardrail nobody built: a reviewer who can catch the error

Most firm AI policies rest on an assumption nobody states out loud: that a competent human will review the output and catch what the tool gets wrong. That assumption holds for a senior partner working inside a practice area they have run for twenty years. It holds much less well for the associate doing the reviewing day to day, who may not yet have the substantive depth to recognize a wrong answer that reads fluently. A policy that says AI output must be reviewed by an attorney is not the same as a policy that says the reviewer is qualified to catch the specific kind of error the tool tends to make. No checklist closes that gap. Only judgment does, and judgment is exactly the thing a junior reviewer is still building.

Billing model disruption is the fear with no vendor solution

The billing model is the one AI risk that no software can fix. When AI compresses work, the hourly math changes. A client who learns that a research task took half the time and sees no adjustment on the invoice has a reasonable grievance. Unlike hallucinations or data leakage, there is no patch for a client pricing expectation. Firms working through this are doing it through engagement letter language and internal billing policy, not through technology, and the ones who have not started are the ones most likely to face the question from a client before they have an answer ready.

Data security anxiety is real, and almost nobody can define it precisely

About 22% of firms name data leakage or confidentiality as a top concern, and the concern is genuine even though it is rarely specific. Some are worried about employees pasting client information into consumer tools with no enterprise agreement behind them. Others are simply unsure whether the enterprise AI vendors they already pay are honoring their own training-data promises, and have no reliable way to verify it. A fear this vague is hard to act on, because the fix for "an employee uses an unvetted tool" and the fix for "our vendor might be lying about training data" are not the same fix, and most firms have not separated the two problems long enough to solve either one. The vagueness is not a failure of imagination. Vendor contracts on data handling are dense, inconsistently worded across providers, and rarely reviewed by anyone with the technical background to catch a meaningful gap. A firm can be genuinely careful about consumer-tool usage and still have no real answer to whether its enterprise vendor is doing what its contract says, because verifying that requires an audit most firms have neither the staff nor the leverage to run.

Deployment and adoption are two different problems

33% of firms flagged the gap between deploying AI tools and actually getting attorneys to use them. Task forces and rollout plans mark the deployment. Attorneys reverting to prior workflows within weeks mark the failure. The firms naming this as a concern have already run at least one deployment with the same result: strong initial uptake, gradual reversion, and continued subscription costs. The launch event is not the behavior change.

The junior-reviewer gap has a number attached to it now

The review-gap concern is not abstract. A 2024 Stanford RegLab and HAI study, later published in the Journal of Empirical Legal Studies, tested the leading AI legal research tools against real queries and found that the tools made by LexisNexis and Thomson Reuters each hallucinate between 17% and 33% of the time. That is the error rate a reviewer is being asked to catch, on every single query, without a reliable signal for which answers are the wrong ones. A partner with twenty years in a practice area will often sense when an answer feels off. A reviewer still building that instinct has a meaningfully higher chance of missing it, which is precisely the exposure our members are naming when they say a policy alone does not solve this. The study also found that the vendors' own marketing had outrun what their tools could support: one legal AI provider had publicly claimed its product did not hallucinate at all, a claim it quietly walked back after the research was published, clarifying that the promise covered only linked citations rather than the substance of an answer. Firms evaluating tools on vendor demos alone are evaluating the version of the product the vendor wants shown, not the failure rate a reviewer will encounter on a real matter.

Source: Stanford RegLab, Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools

What to do with this

Stop debating tools long enough to name the actual stakes to whoever is stuck in the evaluation. It is not a features conversation. It is three specific risks: a wrong platform choice that is nearly impossible to unwind once attorneys build habits around it, a review gap where the person checking the output may not be equipped to catch what it gets wrong, and a billing expectation clients will eventually raise whether or not the firm has an answer ready. Naming those three separately, instead of letting them blur into a general unease about AI, is what unsticks a committee. Paralysis is what happens when the fear stays vague enough that no specific action addresses it. Once the fear has a name, it has an owner and a next step. Assign each of the three risks to a different person if the firm has the bench for it. A single committee trying to hold all three at once is a large part of why the evaluation stalls in the first place, since the person who can judge platform fit is rarely the same person who should be writing billing policy or setting review standards for junior staff.

We don't know what to do about AI, so instead of one person who doesn't know what to do, we put six people who don't know what to do in a room. We're trying to decide about something that's changing as we're talking about it, and time is not on our side.

Debbie Foster, The perils of just turning it on.

Members get more. The breakdown by firm size, practice area, and tech stack. A new question every Tuesday, the outlier answers that cut against the pattern, and most weeks an expert take with one clear next step.

Frequently asked questions

What is the biggest AI concern for mid-size law firm leaders?
Picking the wrong tool, not data leakage or hallucinations. About 44% of firms name tool selection as their dominant fear, ahead of billing model disruption, data security, and the gap between deploying a tool and getting attorneys to use it in real matters.
Can a review policy alone catch AI errors in legal work?
Not reliably. A review policy assumes the reviewer has the substantive depth to recognize a wrong answer that reads fluently, which holds for an experienced partner far more than for a newer associate. Independent testing has found the leading AI legal research tools hallucinate between 17% and 33% of the time.
Why are law firms worried about AI and client billing?
Because AI compresses the time a task takes, and clients notice. A client who learns a research task took half the time and sees no change on the invoice has a reasonable objection, and there is no software fix for that, only engagement letter language and a clear internal billing policy.
Why do AI tools get deployed at law firms but not adopted?
Deployment and adoption are different problems. A task force and a rollout plan mark the deployment. Attorneys quietly reverting to their old workflows within weeks marks the failure, and firms keep paying subscription costs for tools that never became a habit.