Legal & professional services · case-study · May 2026

The contract summarizer was sending privileged clauses to the model

A firm's contract-summarization step was passing client-confidential and privileged language straight to the model. Here's what an Inspector caught in Watch mode — provenance a client could see.

The workflow you already run

Associates summarize contracts for hours, so a model does the first read: it takes the executed agreement and returns key terms, obligations, and dates. The output saves real time, and the habit spreads across the practice — NDAs, MSAs, side letters, all flowing through the same convenient step.

The risk you can't yet see

But a contract is not neutral text. It carries counterparty names, deal terms under NDA, and language that may be privileged. When that document goes to a model, the firm has, in effect, disclosed client-confidential material to a third system — and if a client asks "who and what saw our agreement, and can you prove it stayed inside the firm?", the honest answer today is that no one wrote it down. Confidentiality you can't demonstrate is confidentiality a client won't trust.

What an Inspector caught

Run in Watch mode, inside the firm's own environment, an Inspector observed the same summarization call:

an inspector · watch mode Executed contract → summarization model
inboundsummarize agreement · DMS → model
filtercounterparty names + NDA terms redacted · pre-model
reconstructclauses segmented · 14
detectprivileged language · flagged for review
outputkey terms · schema-valid · provenance attached

On record

Counterparty names and NDA terms it would have redacted before the model read them. Fourteen clauses segmented cleanly. One passage of likely-privileged language flagged for a human rather than summarized silently. And a provenance trail the firm could show a client — signed, on the firm's own stack, nothing run. Watch first: prove the confidentiality holds before an Inspector touches live matters.

Related

← All insights