Build vs Buy Legal AI: The Decision Mid-Size Firms Keep Getting Stuck On
At a Glance
- Who this is for: Heads of IT and COOs at mid-size firms who've trialled legal AI platforms and are now being asked whether the firm should build its own.
- The problem: Most trials are decided by what happens around the output: documents moving in and out of the DMS, work passing between lawyers, and who maintains the tool in year 2.
- What decides it: Which systems the AI has to connect to, and who owns the tool when it breaks.
- The takeaway: Test every option against your own hardest matters, design governance first, and price year 2 before you price year 1.

What does build vs buy legal AI mean? Build vs buy legal AI is the choice between licensing an off-the-shelf legal AI platform and developing a tool in-house on top of a hosted model. Buying gets a firm a finished product quickly. Building gets it a tool shaped around its own systems, along with the job of maintaining it.
What One Firm's Trial Showed
The Head of Technology at a US litigation firm of around 30 lawyers recently set out, on a public practitioner forum, how the firm tested 3 well-known legal AI platforms. Each ran the same work for about 3 weeks: a disclosure exercise, a motion and an advice memo.
The firm's own lawyers reviewed every output. The drafts were decent.
The firm decided to build its own tool anyway. More than 100 replies followed, arguing about whether that was brave or reckless, and both sides had a point.
Why Buying Legal AI Stalls at the Document Management System
Every task in the trial started with the same routine. Check the document out of the DMS, download it, upload it to the platform, do the work, download the result, file it back.
For one draft, that's a few minutes. Across a team of associates on a full disclosure exercise, it's hours of unbilled administration and a steady risk that someone files the wrong version.
The review step was the second gap. The firm runs most of its work from task templates, where an associate finishes a draft and passes it to a senior lawyer. None of the platforms could mark the task complete, check the document back in and notify the reviewer in 1 step.
Then there was the budget. The platforms would have sat on top of the firm's existing research subscription, and business development would have needed a separate system again to work on the same material.
What Building Legal AI In-House Actually Costs
Building fixes the connection problem, because the firm controls both ends. The firm in the post had 2 engineers who could write integrations, including their own connector to the DMS, and it limited the first build to a single area of work.
Few mid-size UK firms have that bench. Fewer can protect it from other IT priorities for a full year.
The cost that catches firms out arrives in year 2. A prototype that works most of the time comes together quickly. Getting from most of the time to every time takes sustained testing, security review, re-work after model changes, and user support.
Several practitioners in the thread made the same point about accountability. When a bought platform fails, the vendor answers for it. When the firm's own tool fails, the Head of IT does.
We covered the same trade-off for a single use case in build or buy an AI billing assistant. The pattern holds across the wider build vs buy legal AI decision: licence price is the smallest number in the comparison.
What a Build vs Buy Legal AI Trial Should Test
The most useful detail in the post was a failure. The intake notes for one test matter held a single line that should have disqualified the prospective client. Every platform in the trial missed it.
When the firm pointed it out, each system agreed straight away. A missed fact like that changes the legal answer, which makes it far more dangerous than a clumsy sentence in a draft.
The firm's trial method is worth copying:
- Pick 3 or 4 real pieces of work and run every option through the same set
- Have the lawyers who do that work review the outputs
- Build a firm-owned evaluation set from your most awkward matters: disqualifying facts buried in notes, conflicting dates, missing exhibits, poor scans and privileged material
- Re-run the set every time the model or the prompts change
Measure adoption alongside accuracy. A tool that tests well and then sits unopened has still cost the licence fee and the partner time spent choosing it.
Legal AI Governance Comes Before the Model
Whichever route a firm takes, design the governance first. The firm in the post authenticated its tool through its existing Microsoft identity platform. That let it inherit the ethical screens already set up in its DMS, so users could only reach what they could already reach.
Client data needs the same attention. Anything sent to a model should be checked for personal data and privileged material first, with each redaction logged so the firm can show its working if a client or court asks.
For UK firms, the ICO's guidance on AI and data protection is the reference point. It expects data protection by design, and an impact assessment before high-risk AI processing begins.
Professional duties don't move either. The Law Society's Generative AI: the essentials, written with small and medium-sized firms in mind, is clear that a solicitor's duties to the court and the client apply to the work whether or not AI helped produce it.
Our piece on AI governance for law firms sets out the 4 controls we'd build first.
A Third Route: Build Legal AI with a Partner and Keep the Assets
The thread split into 2 camps, and the split hid a third option. Buying gets a polished product that stops at the edge of the firm's systems. Building gets the connections, along with every future bug.
The third route puts the build inside the firm's own tenant and the delivery risk with a partner. That's the model behind Cognitive Outsourcing™.
3Rive takes operational ownership of a defined function, funds its AI redesign across the term, shares the savings from Year 2, and hands the AI assets back to the firm when the term ends. The tooling is built around the firm's DMS and task management, because that's where the work runs.
It also answers a question the forum post left open. Under the billable hour, time saved by AI doesn't reach the firm's cost base on its own. Gain-share ties the result to a baseline both sides have signed off, as we set out in Cognitive Outsourcing™ vs managed services.
It only fits if the firm would consider handing over a whole function. If not, the questions below still apply.
5 Guestions to Settle Build vs Buy Legal AI
- Which 2 systems must the AI read from and write to on day 1? If the DMS and task management are on the list, test those connections before anything else.
- Who maintains it, and who answers for it, in year 2? Name a person or a contract, and budget for the work.
- What's in the evaluation set, and who scores it? Real matters, scored by the fee earners who run them.
- Where does client data go, and can you prove it afterwards? Look for redaction, logging and deployment inside your own tenant.
- How will the saving reach the firm's economics? If the billable hour absorbs it, the business case needs a different pricing or delivery model.
Common Pitfalls
- Judging a trial on draft quality and finding the DMS friction after signing.
- Starting an in-house build without naming who maintains it in year 2.
- Testing on the vendor's demo matters instead of the firm's own.
- Choosing the model before designing authentication, ethical screens and redaction.
- Letting scope creep in once partners see a working prototype.
How 3Rive Approaches This
We start with the systems the AI has to live inside and the matters it has to get right, and choose the model after. Where a firm hasn't decided which route to take, that's a Tech Advisory conversation first, starting with AI Readiness in Five Days, which ends with a costed 90-day plan.
Where the firm is building, our AI service line delivers the tooling inside the firm's own tenant, with redaction, audit logging and a review step built in. Our Colombo delivery centre is ISO/IEC 27001 certified.