5 ILTACON 2026 Sessions Worth Your Time (and What They Mean for Your Data)
- Patrick Bryden
- Jul 6
- 6 min read
Last year, we wrote about the five ILTA sessions we had our eye on, including "Boring AI That Saves Time & Money," "Integrating IT Ops and Security," and "File Sharing & Collaboration Tools of Today and Tomorrow." The sessions and the conference both rose to expectations, addressing the same underlying challenge: firms don't want a bigger tech stack. They want one that keeps them secure while letting them operate as efficiently and effectively as possible.

A year on, that challenge hasn't gone anywhere. If anything, AI has sharpened it! Law firms are now under pressure to adopt and adapt quickly without losing track of where sensitive client data goes, and to govern new tools without grinding the work to a halt.
So at the risk of rehashing old ideas…we did the same exercise again!
Below are five sessions on the 2026 ILTACON agenda that highlight the challenges legal firms are facing now, including operational, ethical, and strategic challenges.
Break, Pivot, Exfiltrate: The Anatomy of a Breach
Law firms stay on the hacker target list for a simple reason: they hold concentrated, high-value client data. Drawing on real incident response work, this session traces how a firm breach actually unfolds, starting with initial access through phishing or credential compromise, then lateral movement into email and document repositories, and finally exfiltration from file shares where the sensitive material lives. It also examines why these attacks succeed, where controls commonly fail, and which indicators are missed, then closes with the operational, legal, and reputational fallout.
Confidencial's POV
The breach itself is rarely the part that costs a firm its clients. Rather, it's what becomes accessible afterward. A client hands a firm its most sensitive matters on the assumption that the firm can protect them better than it could itself. That's what we call the Trust Premium, and a breach that exposes readable client files spends it in a single news cycle.
Across our own research, law firms keep landing on the same distinction: perimeter controls decide whether an attacker gets in, but protection at the document level decides what they walk away with. In 2026, one of the most effective ways to neutralize this threat is to encrypt files at the data layer. This ensures exfiltration produces material no unauthorized party can open, and the question shifts from what was taken to what can actually be used (which is nothing).
Beyond the Charter: AI Governance Frameworks That Actually Work
This session examines how AmLaw firms are putting AI governance into practice, with case studies on ISO 42001, the NIST AI Risk Management Framework, and EU AI Act compliance programs. It covers the gap between executive vision and operational reality, including risk categorization that doesn't stall innovation, guardrails that keep firm data protected, and tactics for vetting new AI opportunities before ungoverned adoption takes hold.
Confidencial's POV
AI governance tends to fail in one of two directions. Too loose, and every AI solution under the sun spreads through the firm before anyone has mapped what it touches. Too rigid, and shadow AI quietly routes around the policy to get its work done. The firms that find the middle are the ones treating governance as something enforced, not something published.
That's the part worth pressure-testing at the data layer. A framework that lives in a policy document depends on everyone following it; a framework enforced on the file holds whether they do or not. When protection travels with the document itself, the guardrails the session describes survive contact with whatever tool, model, or workflow the file moves through next, which is the difference between a governance program a firm can describe and one it can prove.
AI Across the Client Boundary: The Architecture Firms Haven't Built Yet
This session makes the case that winning with AI takes more than tool selection. It takes an architecture that turns a firm's knowledge into something AI can use at scale across the boundary between the firm and its clients. It's set against real pressure: corporate legal teams pulling more run-rate work in-house without sacrificing quality or access to outside expertise, leaving firms and clients needing to collaborate seamlessly through AI-enabled workflows.
The session is organized around three building blocks:
Operationalizing firm IP by turning unstructured documents into governed, reusable knowledge assets
Using shared platforms like Microsoft 365 and Copilot as a common ground
Building a knowledge-centric operating model that supports firm–client interoperability, including through MCP
Confidencial's POV
The value this session wants to unlock is trapped in unstructured documents, such as contracts, memos, and work product. The moment that knowledge becomes a shared, AI-ready foundation, it also stops living inside the firm's four walls. It moves into a client's environment and into AI tools that can read across everything at once.
Every one of those moves is a place where "who or what can read this" needs an answer that travels with the document, not one that stays behind in the system it left. Protection applied at the file level, such as encryption or tokenization, enables a firm to operationalize its knowledge for AI without exposing sensitive information to unauthorized tools or individuals.
When AI Meets IG: Secure AI Integration with Knowledge Systems
Another governance session, and for good reason!
As firms adopt AI to draw insights from their knowledge repositories, this session examines the governance challenge of connecting AI to platforms such as iManage, NetDocuments, Intapp, and Outlook while maintaining compliance, security, and ethical standards. The session will look at real approaches firms are taking to balance innovation with information governance requirements, with takeaways covering:
Common integration patterns for AI with the DMS, Intapp Walls, and Outlook
Information governance considerations across security, compliance, and ethical AI use
Lessons from firms leading in AI-enabled knowledge management
Practical steps for building an AI integration roadmap under IG constraints
Confidencial's POV
Ethical walls are the clearest example of the governance problem. Intapp Walls exist to keep certain people away from certain matters, and an AI layer that reads across the entire repository can undo that separation, regardless of whether it should. The governance question is not whether the firm has a policy, but whether the policy can hold once an AI tool is doing the reading.
This is why protection should sit with the document rather than the system around it. When encryption and access control are bound to the file itself, the wall holds regardless of which tool, model, or integration touches it, and a firm can extend AI into its knowledge systems without quietly widening who can see what. Without this, the ethical walls will only hold for so long.
The Cybersecurity Evolution: From Legal Risk to Strategic Advantage
This session argues that cybersecurity in law firms has outgrown the IT department. As threat actors adopt AI, supply-chain attacks accelerate, and regulators raise the bar, security failures now carry direct business, ethical, and reputational consequences for law firms. The session will trace the shift from perimeter defense and compliance checklists to a leadership-driven, business-critical discipline, connecting cybersecurity to governance, risk management, vendor oversight, and incident readiness, with a focus on what firms can act on without slowing the business down.
Confidencial's POV
This is the Trust Premium in practical terms. When a firm can show a client that sensitive data stays protected even as it moves, such as being shared with co-counsel, sent to a client, or run through an AI workflow, security stops reading as overhead and starts reading as a reason to hand the firm the work. The firms that can prove it will win business from the firms that can only promise it. Getting there means protection that lives within the data itself rather than in the perimeter around it, which helps firms show clients, regulators, and insurers they are taking steps to strengthen their cybersecurity posture.
ILTACON is a reality check, not a showcase
The strongest sessions on the 2026 agenda aren't about the flashiest tool or the boldest prediction or hottest hot take. Rather, they are centered on problems legal firms face: how a breach actually unfolds, how to govern AI without stalling work, how to share knowledge across the client boundary without losing control, and how to turn security into something clients reward.
The thread running through all five is the same one running through all types of legal work: client data that increasingly lives, moves, and gets used beyond the firm's four walls. The teams asking how to keep it protected on that journey are the ones building the foundation for what comes next.
If you're at ILTACON and want to talk about AI readiness, governance, or protecting sensitive files after they leave the building, Confidencial will be on the floor. Come find us.
Frequently Asked Questions
Q: What are the key themes at ILTACON 2026? The 2026 agenda centers on law firm cybersecurity, practical AI governance, and secure AI integration with knowledge systems—reflecting firms' pressure to adopt AI quickly while protecting client data.
Q: Why are law firms frequent targets for data breaches? Law firms hold concentrated, high-value client data across many matters, which makes a single firm a high-yield target. The lasting damage usually comes not from the intrusion itself but from what becomes readable to an attacker afterward.
Q: How can law firms protect client data when using AI tools? Protecting data at the document level—encrypting or tokenizing sensitive content so it travels with the file—keeps information protected as it moves into AI tools, client environments, and collaboration platforms, rather than relying only on the perimeter around those systems.




Comments