Michael Alabi
← All case files

Case file · October 2025 to March 2026

A confidentiality clause decided which AI tool lawyers got.

Picking an AI tool for lawyers isn't a vendor demo, it's a confidentiality decision. Here is how I evaluated Legora AI and Harvey AI, chose the one contractually barred from training on client data, and built the governance and training that took it firm-wide.

Organization
Jackson Etti & Edu (law firm), Lagos, Nigeria
Role
Head, Information Technology & Data Management
Adoption journey
October 2025 to March 2026: sourcing, first trial batch, official adoption
Evaluated
Legora AI and Harvey AI, with lawyers on live matters
Selected
Legora AI, contractually barred from training on client data (§8.3.3)
Impact
Work that took 2-5 days or 3-10 hours turned around in 5-20 minutes, per Partner and Senior Associate feedback
The problem

Lawyers needed an AI tool built for legal work: drafting, reviewing, and comparing documents across jurisdictions, not a generic assistant repurposed for a law firm. Picking one meant testing real tools against real legal work before committing the firm to either, and getting the confidentiality question right before anyone's client matter touched either platform.

The pilot

I ran a pilot of Legora AI and Harvey AI with lawyers across the firm, both built specifically for legal work, using them on live matters including a merger-control comparison across seven jurisdictions. Legora's own terms state plainly that it will not use a subscriber's confidential information to train or fine-tune its models, and won't let its subcontractors do so either, a guarantee the firm needed and didn't find the same way in Harvey. That, and how much faster it let the firm move, decided it. Microsoft Copilot was rolled out separately for non-lawyer staff.

The verification

Legora's own terms weren't the only check I relied on. Legora has been audited by an independent firm and confirmed to meet the ISO 27001:2022 requirements, and will provide the certificate on request (legora.com/legal/security). The Data Protection team and I went further ourselves: we fed the tool a canary string, a highly identifiable but entirely fictional project code name paired with synthetic financial figures, a marker of our own that we could watch for if it ever surfaced somewhere it shouldn't.

The governance

Adoption came with limits, not just access. I drafted an AI usage policy and put it in place, restricted what users could do on the platform, set permissions by role, and worked with the Data Protection unit to put data-privacy controls around it before it reached lawyers' live matters.

The training

I ran in-house training with practical use cases and live demonstrations across Intellectual Property; Regulatory, Governance & Compliance; Litigation; and Corporate Commercial, including a dedicated session for the Corporate Mergers & Acquisitions team. I also co-anchored a further session the Legora AI team led. When a Senior Partner found the platform's processes too complex, I ran a dedicated, simplified training for her rather than leaving her to work it out. Every user was trained, and I followed up with repeated firm-wide emails reminding people to anonymize confidential information before it went into the tool.

The feedback loop

Training didn't end with a session. I gathered feedback from participants and took it back to Legora AI for product improvement, keeping the tool moving toward how the firm actually worked rather than treating the rollout as a one-time install.

The result

The real measure wasn't how many people had logged in, it was what a lawyer could now do that used to take days. Partners and Senior Associates reported that work which used to take junior lawyers 2 to 5 days, or 3 to 10 hours depending on the type, came back from Legora AI in about 5 to 20 minutes, a cut in review time of roughly 85% to well over 99% depending on the task; it's their assessment, not something I measured myself, since I'm not the one drafting the briefs. What I learned running that program is what led me to build JEEves afterward: a personal initiative to give the firm its own in-house AI experience, this time for HR, on Claude and Retrieval-Augmented Generation.

Legora will not use Subscriber's Confidential Information to train or fine-tune AI models, nor will it allow its subcontractors to do so.
Legora AI, U.S. General Terms and Conditions, §8.3.3

What it shows

AI adoption run as a vendor evaluation, a governance rollout, and a training program, not a single purchase decision: two legal-AI tools evaluated against a real contractual guarantee on client confidentiality, that guarantee checked rather than taken on faith, a written usage policy and data-privacy controls before general access, and training that adapted to a partner who found it too complex rather than leaving her behind.

  • Legora AI
  • Client Confidentiality
  • ISO 27001:2022
  • Canary Data Testing
  • Microsoft Copilot
  • AI Usage Policy
  • Role-Based Permissions
  • Data Privacy
  • Enterprise Training

Open to Head of IT / CIO and AI Adoption & Governance roles.

Start a conversation