Morillo Hudson
Infrastructure +
Services +
Selected Work +
Research +
The Firm +
Client PortalSecure access →Private Client Office
Note · Data Governance · July 2026

Prohibition relocates exposure

Financial services already ran this experiment. It cost the industry more than $3.5 billion. Law firms are running it again with AI.

In December 2021, JPMorgan agreed to pay $200 million to the SEC and CFTC. The violation was not insider trading, market manipulation, or client harm. It was that its bankers had been conducting business over WhatsApp and personal text messages, and the firm could not produce the records.

What followed was one of the most systematic enforcement campaigns in modern regulatory history. Since that first action, the SEC has charged more than 100 firms over off-channel communications. Combined penalties across the SEC, CFTC and FINRA now exceed $3.5 billion.

Here is the part the legal profession should sit with.

100+ Firms charged. Nearly all had a written policy prohibiting the very conduct they were fined for.

The policies were not missing. They were ignored, and they were ignored at every level of the organisation. Regulators noted repeatedly that the violators included supervisors, managing directors and senior executives.

This is worth stating plainly: it was not a failure of character or of training. It was what happens when a written rule is asked to hold back a real workflow pressure, and the rule is the only thing standing there.

The prohibition did not stop the behaviour. It moved the behaviour onto personal devices, where the firm could no longer see it, log it, produce it or defend it. That migration, not the underlying conversations, is what the penalties were for.

The same experiment, running now

Walk into most law firms today and you will find a version of the following sequence.

Someone runs an audit, or an associate mentions something in passing, and the firm discovers that people have been using public AI tools on client work. Deposition summaries. Diligence review. First-pass drafts. The material going in is often unredacted.

The firm's response is almost always the same: a policy, circulated by email, prohibiting the use of generative AI on client matters. Management then considers the problem closed.

It is not closed. It has been relocated. The associate facing a client deadline that manual review cannot meet now has three options rather than two: do the work slowly and miss the deadline, do the work slowly and eat the hours, or open the same tool on a personal laptop where nobody is watching. The pressure that produced the behaviour has not changed by a single degree. Only the firm's visibility into it has changed, and it has changed for the worse.

Before the policy, the firm had a governance problem it could see. After the policy, it has the same problem conducted on unmanaged devices, with no logs, and a written prohibition that now serves as evidence the firm knew.

Why law firms have the harder version

A bank that loses an off-channel enforcement action pays a fine and hires a compliance consultant. It is expensive and embarrassing, and then it is over. A law firm faces something structurally worse, for three reasons.

The exposure is adversarial, not regulatory

A recordkeeping violation is raised by a regulator on a predictable timetable. A privilege waiver is raised by opposing counsel, in the middle of a matter, at the moment of maximum leverage. Once a court accepts that confidential client material was disclosed to a third-party system without adequate safeguards, the remedy is not a fine. It is the loss of protection over the material itself. There is no settlement that puts that back.

The duty runs to the partner, not only the firm

Professional conduct rules place supervisory responsibility for lawyers and non-lawyer assistants on partners and managers directly. A policy nobody enforces is not supervision. It is documentation of the standard the firm failed to meet.

The governing guidance already anticipates this

Current professional guidance on generative AI is explicit that a lawyer must understand how a tool handles client data before putting confidential information into it, and must evaluate the risk of disclosure. Read carefully, it does not tell firms to prohibit AI. It tells them to know where the data goes. Those are very different instructions, and only one of them is achievable.

Convenience is a security control

The uncomfortable premise underneath all of this is that people given an impossible workload will find the tool that makes it possible, and no policy has ever successfully competed with that.

Information security learned this twenty years ago and keeps having to relearn it. Ban Dropbox and people email themselves attachments. Ban personal email and people use USB drives. Ban USB drives and people photograph the screen. Every prohibition of a convenient tool produces a less convenient, less visible substitute, and the security posture gets worse each time.

The only intervention that has ever worked is to make the sanctioned path faster than the unsanctioned one. Not equally fast. Faster. When the approved tool is the path of least resistance, compliance stops depending on anyone's virtue.

So the question worth asking is not should our people use these tools, because they already are. It is: can we give them a tool good enough that they have no reason to reach for anything else, running somewhere the client data never leaves our control?

That is an architecture question, not a policy question.


The distinction that matters

There is a meaningful difference between data defence that is promised and data defence that is structural.

A vendor's terms of service is a promise. An acceptable use policy circulated to associates is a promise. A partner's assurance to a client that the firm does not use AI on their matter is, increasingly, a promise that the partner is not in a position to verify.

Architecture is not a promise. If client material is processed inside an environment the firm already controls and never persists outside it, the confidentiality obligation is satisfied by the shape of the system rather than by anyone's adherence to a memo.

Financial services spent $3.5 billion learning that a policy is not a control. The legal profession is now standing at the same fork, holding the same memo, and expecting a different result.

Prohibition does not reduce exposure. It relocates it somewhere you cannot see, cannot govern, and cannot defend.

Morillo Hudson builds private AI infrastructure for regulated firms. Systems are deployed inside the firm's own environment; client material does not leave it.

Where does your firm actually stand?

We run a short assessment mapping where client material currently travels, and what the firm could demonstrate if a client asked. Twenty minutes. The findings are yours to keep.

Request an assessment
← Return to Notes