ibl.ai Agentic AI Blog

Insights on building and deploying agentic AI systems. Our blog covers AI agent architectures, LLM infrastructure, MCP servers, enterprise deployment strategies, and real-world implementation guides. Whether you are a developer building AI agents, a CTO evaluating agentic platforms, or a technical leader driving AI adoption, you will find practical guidance here.

Topics We Cover

Featured Research and Reports

We analyze key research from leading institutions and labs including Google DeepMind, Anthropic, OpenAI, Meta AI, McKinsey, and the World Economic Forum. Our content includes detailed analysis of reports on AI agents, foundation models, and enterprise AI strategy.

For Technical Leaders

CTOs, engineering leads, and AI architects turn to our blog for guidance on agent orchestration, model evaluation, infrastructure planning, and building production-ready AI systems. We provide frameworks for responsible AI deployment that balance capability with safety and reliability.

Back to Blog

ABA Model Rule 1.6 Compliant AI: Privileged Work Product Stays Behind the Firewall

Mikel AmigotJune 1, 2026
Premium

ABA Model Rule 1.6 obligates lawyers to make 'reasonable efforts to prevent the inadvertent or unauthorized disclosure of' client information. State bars are converging on the view that this is incompatible with sending privileged work product to managed AI vendors. Self-hosted AI inside the firm's network is the architecture that satisfies the rule by deployment.

The Short Answer

ABA Model Rule 1.6 compliant AI means privileged work product stays inside the firm's network β€” not in a managed AI vendor's cloud. On ibl.ai you own all the code and the data β€” self-hosted inside your own perimeter, model-agnostic across any LLM, and priced by usage with no per-seat pricing. ibl.ai's self-hosted architecture aligns directly with Rule 1.6's "reasonable efforts" standard: the runtime, the model, and the privileged data all sit inside the firm's existing perimeter, where the firm's existing confidentiality controls already operate.

What Rule 1.6 Actually Requires of AI Use

ABA Model Rule 1.6(c) reads: "A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."

Three structural questions every firm's general counsel asks of any AI deployment:

1. Where does privileged work product live during the inference call? A managed AI vendor's cloud is β€” at minimum β€” transit. Even with a DPA, the privileged information has been processed by a third party.

2. Who has access to logs and intermediate state? The vendor's engineers, sub-processors, and (under subpoena to the vendor) third parties have potential access. The firm's confidentiality controls don't extend to the vendor's environment.

3. What contractual + technical controls prevent the vendor from using client data for training, evaluation, or quality improvement? A strong DPA addresses this contractually. The technical controls live in the vendor's environment, not the firm's.

State bars are increasingly answering: "reasonable efforts" requires the firm's confidentiality controls to extend to the AI processing path β€” which is hard when a managed vendor controls that path.

Recent state-bar opinions (NY, CA, FL, IL, and others) have not banned managed AI vendors outright, but have raised the bar on disclosure, supervision, and informed consent. The architectural shortcut: keep the privileged data inside the firm's network.

How ibl.ai's Architecture Satisfies Rule 1.6 by Deployment

Self-hosted runtime inside the firm's network. The runtime executes in the firm's existing VPC or on-prem environment β€” same network as iManage / NetDocuments / SharePoint. Privileged documents are processed inside the firm's existing confidentiality perimeter.

Model-agnostic with firm-controlled routing. Open-weight models (Llama 4 / DeepSeek-R1) run on firm GPU β€” no data ever leaves. For frontier-lab models (Claude / GPT-5 / Gemini), cloud API calls route through a firm-controlled proxy that enforces data-residency policy + logs every call to the firm's SIEM. The firm decides which models are permitted for which matters.

Open-source platform. OpenClaw is MIT-licensed; the platform license is perpetual. The firm can audit the code, document it in the firm's AI governance policy, and operate independently.

Audit logs in the firm's SIEM. Every AI call, every model output, every tool invocation logs into the firm's existing SIEM with matter ID, user ID, model version, and timestamp. The firm's normal supervision processes apply.

Conflicts checking + DMS integration inside the firm. Connectors to iManage / NetDocuments / SharePoint / firm's matter-management system run inside the firm's network. Documents never leave the perimeter to be reviewed.

For the broader policy framework: AI Policies for Law Firms: A Practical 2026 Guide.

Why Managed AI Vendors Struggle With Rule 1.6 at Scale

Three structural problems for managed legal AI vendors (Harvey, Co:Counsel, Spellbook, Ironclad AI):

1. Vendor-side third-party access. The vendor's engineers, the vendor's sub-processors, and (under compelled disclosure) third parties have potential access to privileged content during processing. A DPA contractually limits this; it doesn't structurally prevent it.

2. Vendor-controlled model lifecycle. When the vendor updates the model, the firm's prior validation may not apply. The firm's supervision obligation (Rule 5.3 for non-lawyer assistance) becomes hard to discharge.

3. Subpoena reach. A subpoena to the firm reaches what the firm controls. A subpoena to the vendor reaches what the vendor controls β€” including privileged work product the firm sent through the vendor's system. The firm's privilege claim becomes harder.

Self-hosted on the firm's network removes the third-party custodian entirely.

Workloads Where Rule 1.6 Matters Most

Any AI use that touches privileged work product. In practice:

  • Contract review + redlining β€” every contract under review is potentially privileged
  • Due diligence document review β€” deal-room content is highly sensitive
  • Brief-writing assistance β€” draft work product is privileged
  • Deposition preparation β€” witness prep, theory of the case
  • Legal research with case-specific context β€” research tied to a specific matter
  • Internal know-how + playbooks β€” firm IP that lawyers reference during privileged work
  • Litigation strategy β€” even more sensitive than normal privileged work product
  • eDiscovery review β€” privilege-log work + relevance determinations

The Cost Math

A 200-lawyer firm running ~30,000 first-pass contract reviews/month + general legal AI use:

ApproachMonthly costPrivilege posture
Harvey ($400/lawyer Γ— 200)$80,000Vendor cloud (DPA)
Co:Counsel ($300/lawyer Γ— 200)$60,000Vendor cloud (DPA)
Spellbook / Ironclad AI / LinkSquares (~$2/contract Γ— 30K)~$60,000Vendor cloud (DPA)
Direct Claude Sonnet API (token-priced)~$630Anthropic cloud (DPA)
ibl.ai self-hosted (Llama 4 / DeepSeek-R1)~$5,000–8,000Inside the firm's network

ibl.ai self-hosted is ~10Γ— cheaper than Co:Counsel AND structurally aligned with Rule 1.6.

For per-contract math: What AI Contract Review Actually Costs in 2026.

Run the Numbers

Why Family-Owned and New York Matters Here

A law firm's AI vendor relationship for workloads touching privileged work product is a multi-year commitment that touches the firm's core ethical obligations. ibl.ai is family-owned and operated from New York, NY β€” a long-term partner with a perpetual platform license and no investor exit pressure. The runtime is open source. Privileged work product stays inside the firm's network. The math works at a 5-lawyer boutique or a 2,000-lawyer global firm.

ABA Model Rule 1.6 compliant AI isn't a vendor checkbox. It's the firm's confidentiality controls extending to the AI processing path β€” which only works when the AI processing runs inside the firm's perimeter.

Related: When Compliance AI Hallucinates, Who Audits the Filing? β€” the four artifacts an auditable AI filing requires, and which of them a hosted API decides for you.

Why does owning the AI stack matter?

ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β€” so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.

  • You own all the code and the data

    Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform β€” the stack itself is yours.

  • Model-agnostic

    Run any LLM β€” Claude, GPT, Gemini, Llama, Command, or your own fine-tune β€” and switch providers without rewriting the platform.

  • No per-seat pricing

    Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.

  • Deploy anywhere

    Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY β€” a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

See the ibl.ai AI Operating System in Action

Discover how leading universities and organizations are transforming education with the ibl.ai AI Operating System. Explore real-world implementations from Harvard, MIT, Stanford, and users from 400+ institutions worldwide.

View Case Studies
Work with our team

Pilots, deployment, and full ownership

Most enterprise engagements are one-time, not subscriptions. You integrate ibl.ai with your own data, deploy it on your own infrastructure, and the engineering hours scale with the work β€” so the price tracks the scope, not your headcount.

Start here

Pilot

from $15K

fixed scope Β· fixed timeline

A time-boxed proof of value on your real data β€” not a slide deck.

Best for: Teams that want to see ibl.ai working before committing.

  • Deployed on your infrastructure or our cloud
  • 1–2 production agents wired to a slice of your data
  • One integration (LMS / SIS / SSO / data source)
  • Weekly working sessions with our engineers
  • Pilot fee credits toward a full engagement
Scope a pilot
Most common

Integration & Deployment

$25K – $80K

one-time Β· not a subscription

Full deployment integrated with your data and systems. Engineering hours scale with scope.

Best for: Organizations rolling ibl.ai out across a department, campus, or business unit.

  • Platform deployed in your VPC, on-prem, or air-gapped
  • Integrated with your data + identity (SSO / SAML)
  • Multiple custom agents built to your workflows
  • Engineering hours proportional to scope
  • You own the data Β· run any LLM you choose
Plan a deployment
Full ownership

Codebase Transfer + Custom AI Engineering

Six figures

perpetual license Β· you own the stack

We transfer the full source code. You own and self-host the entire platform β€” outright.

Best for: Government, defense, and enterprises that require perpetual ownership and sovereignty.

  • Complete source-code transfer + perpetual license
  • Dedicated AI engineering team on your roadmap
  • Custom agents, models, and integrations to spec
  • Air-gapped capable Β· zero vendor lock-in
  • Family-owned, New York–based long-term partner
Talk about ownership
You own the code and data Run any LLM β€” Claude, GPT, Gemini, Llama Family-owned & operated from New York, NY