The Short Answer
OpenAI reports that weekly legal users of Codex grew 108x between February and June 2026, against 41x for sales and recruiting and 5x for engineering β indexed growth from a low base, not absolute counts. Adoption outran governance: privilege, confidentiality and retention obligations do not travel to a vendor's infrastructure. On ibl.ai you own all the code and the data, so the audit trail stays inside the firm.
The headline is genuinely surprising, and it is worth stating precisely before drawing conclusions from it.
What does the 108x number actually measure?
It measures weekly active legal users of OpenAI Codex, indexed against a February 2026 baseline, through June 2026. Reported alongside it: sales and recruiting at 41x, marketing at 26x, healthcare at 24x, and engineering β the function Codex was built for β at 5x.
Two limits belong on the number. First, these are multiples from a low base, not absolute user counts; a function starting from very few users produces a large multiple from modest absolute growth.
Second, OpenAI has not disclosed which legal tasks are driving it, which makes the figure directionally striking and substantively opaque.
For context on scale rather than growth rate: as of June 2026, Codex accounted for 64% of combined Codex and ChatGPT output tokens among OpenAI's enterprise customers.
So: treat 108x as a strong signal about direction and a weak one about magnitude.
Why is legal adopting faster than engineering?
Because legal work is unusually well-matched to what these tools became good at, and because the baseline was near zero.
Engineering had been using AI coding assistants for years by February 2026 β its growth is measured off an already-large base, which is exactly why 5x understates its absolute usage.
Legal started from almost nothing. And the work is document-dense, precedent-driven, and full of tasks that are high-volume but not high-judgment: first-pass review, clause extraction, summarizing a deposition, checking a definition's consistency across a 200-page agreement.
The profession everyone assumed would resist longest turned out to have the largest backlog of exactly the work these systems do well.
What obligations does legal AI use actually trigger?
More than most deployments were designed around, and this is where the growth rate becomes a risk statistic.
Privilege. Sending a privileged document to a third-party service raises a question about whether the privilege survives. The analysis is fact-specific and jurisdiction-specific. "The vendor says it does not train on our data" does not answer it.
Confidentiality. ABA Model Rule 1.6 obliges a lawyer to make reasonable efforts to prevent unauthorized disclosure. A tool that transmits client information to infrastructure the firm cannot inspect complicates what "reasonable efforts" means.
Competence. The duty of competence now extends to the technology being used, including its failure modes. A lawyer who cannot say what the tool does with the document has a competence problem before they have a privilege problem.
Retention and conflicts. If a vendor retains prompts for a period the firm did not choose, the firm's retention schedule is no longer the firm's. And a matter's conflict boundaries do not automatically map onto a shared workspace.
Can a vendor contract cover the privilege question?
It can help, and it cannot finish the job.
A DPA can commit to non-training, deletion windows and regional processing.
What it cannot provide is the firm's ability to verify those commitments, or to answer an opposing party's discovery question about where a privileged document was processed with anything other than a citation to someone else's policy.
The governance controls that actually answer these questions are the same ones the firm already holds for its document management system: the data stays in the firm's environment, the log is written to the firm's systems, and access is enforced by the firm's roles.
Those are properties of where the software runs, not of what the contract says.
What does the governance gap look like in practice?
| Question a GC will be asked | Managed AI assistant | Firm-owned deployment |
|---|---|---|
| Where did this privileged document go? | Vendor infrastructure, per policy | Inside the firm perimeter |
| Which model processed it? | Whichever the vendor routed to | The one the firm configured, logged |
| How long is the prompt retained? | Vendor's window | The firm's retention schedule |
| Cost as usage grows 108x | Per-seat, multiplied by headcount | Usage-based against a cap you set |
That last row deserves attention in a profession that bills by the hour. Per-seat legal AI pricing runs high β Harvey and Co:Counsel are commonly cited in the $200-500 per user per month range β and per-seat billing scales with headcount whether or not the seat is used.
Agent workloads do not track headcount at all.
How does ibl.ai approach legal AI governance?
ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.
For a firm, that means privileged material is processed on infrastructure the firm controls, every interaction is logged to the firm's own systems under its own retention rules, and matter-level access is enforced by role.
Because the platform is model-agnostic, the firm decides which model touches which category of document β a governance decision that stays with the firm rather than moving with a vendor's routing logic.
1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
Adoption is settled; the record-keeping is not
108x is not a prediction. It already happened, over five months, in the function with the most to lose from getting this wrong.
The useful question is no longer whether lawyers will use AI agents. It is whether the firm can produce a defensible answer about where the documents went β and that answer is determined by architecture chosen before the growth, not after it.
Related: ABA Model Rule 1.6 Compliant AI Β· Agent Sprawl Is a Board Issue. Most Cannot Count Theirs.