Three things legal professionals told us at ILTACON 2026: why data protection reads as a solved problem, what actually blocks encryption, and how outside counsel guidelines are shaping AI use.
During ILTACON 2026, two subjects came up at our booth without us raising them: on-prem file shares and the archives firms are required to retain. Neither is new. Neither has anything to do with AI. They came up from people who had already told us their data protection was handled.
That combination is what we took home from ILTACON 2026. Below are the three patterns we heard most often across a week of conversations. They are impressions from a booth, not survey findings, and where we've drawn a conclusion from them we say so.
Data protection reads as a solved problem
What we heard
Firms have mapped data protection onto tools they already run, and the reasoning holds together. Document management is covered by iManage or NetDocuments, and both offer protection comparable to that of other enterprise file storage solutions. E-discovery is covered by Relativity and its peers, which ship native PII identifiers and workflow-driven redaction that the teams using them are satisfied with. Ethical walls are covered by Intapp, restricting matters at the folder and file level. Each product covers a slice, the slices add up, and the category closes.
Reframing the conversation around exposure did not open it either. Raising risk in general terms ended conversations politely and quickly. However, raising a specific location — this kind of data, in this system, that no one has looked at — kept them going. That distinction held all week, which is reasonable in a profession that deals in specifics.
The exception that came up was consistent. Dark archive data, or material a firm must retain but no longer uses, and legacy on-prem systems came up repeatedly, unprompted, from the same people who described everything else as handled.
Our read
Those two examples sit outside the systems firms had in mind, even after they concluded they were covered. It's not because of a gap in systems or tools; rather, it's the nature of the work.
With archive data, it accumulates because firms are required to let it. ABA Model Rule 1.15 sets a five-year floor for client property after a representation ends, and states go further: New York requires seven years and Alabama six, while practical guidance for client files generally lands between five and ten. Criminal matters sit further out again: California's Formal Opinion 2001-157 advises against destroying a criminal file without the former client's consent while the client is alive. A firm with several offices and a mixed practice is holding material under several retention clocks at once, some of them effectively open-ended. Deletion is not the remedy, which means the only remaining question is whether the retained material is protected where it sits.
The consequences are not theoretical. In March 2026, LexisNexis disclosed that an unauthorized party had accessed a limited number of servers containing what the company described as mostly legacy, deprecated data from prior to 2020, including customer names, user IDs, and business contact information. Products and operational services were unaffected. A legal information provider is not a law firm, and we'd caution against reading it as more than an illustration. But the shape is the one worth noting: the live systems held, and the exposure came from data that had been kept.
The tooling explains part of it. Across the 200+ firms in our 2026 legal data protection research, iManage and NetDocuments account for effectively the entire market, at 75% and 24%, respectively. Both were built to manage documents inside a controlled environment. When a document is downloaded and emailed to opposing counsel, uploaded to a deal portal, or handed to a third-party platform, access controls, retention rules, and IRM classification no longer apply to it. The coverage firms describe is real. It also ends at the download.
That distinction is worth separating from a related one. Detection controls and protection controls fail differently: DLP inspects a file at an egress point and returns a verdict, and when the verdict is wrong, the file leaves readable. Protection applied to the content inside the file doesn't depend on the verdict.
None of which is an argument for replacing any of it. Firms are satisfied with these systems because they work at what they were built for, and no firm is going to displace a working stack for a marginal improvement over what it already has. The opening is narrower: protection that extends past where the existing controls stop. A layer that sits underneath what a firm already runs, reads the classifications it has already applied, and covers the ground after the download is not a replacement decision. It's our opinion that firms should view this addition as the next mile of protection, rather than a marginal improvement. Even with ethical walls and DLP or DSPM in place, a firm following every one of its own rules can still leave data exposed.
Where we fit
Discover locates and classifies sensitive content in the places document management systems were never pointed at: on-prem shares, local drives, archives. Shield protects it where it sits, without moving it and without disturbing retention obligations.
What blocks encryption is workflow, not cryptography
What we heard
When encryption came up, the objection was rarely about the technology, and it was not an argument against protecting data. It was about workflow, and specifically the workflows a firm does not control. A firm filing in federal court sends documents to clerks, judges, and opposing counsel it cannot support, and several people described the same concern: a protected document that does not open on the other end becomes a filing problem rather than a security one. A filing treated as not received, a deadline missed, an exposure in front of a court. Set against a breach that may not happen, that is a trade most firms decline.
The same people wanted their sensitive data found and classified. The appetite there was real, and it was the most receptive subject we raised all week. What they would not accept was protection that put the document's usability at risk. The line was not between protecting data and leaving it exposed. It was between protection that survives the workflow and protection that does not.
Our read
This is the most useful thing we learned, and the concern is firmer than the people raising it described. Federal CM/ECF systems reject encrypted or password-protected PDFs outright. Districts publish a prohibited-content list, and password protection sits on it alongside JavaScript and embedded attachments. The Central District of California states plainly that a PDF with any password protection will not be accepted. Several districts also require filed documents to be text-searchable, which rules out anything that would render a document opaque to text extraction.
So the concern we heard as a caution about recipients is a published technical constraint. A whole-file-encrypted filing does not arrive and go unopened. It does not arrive at all. Firms declining encryption in that context are describing their filing rules accurately, and any vendor who treats it as reluctance has misread the problem.
What is selective encryption?
Selective encryption protects only the sensitive content within a document, rather than the entire file. Identified material, such as names, account numbers, or privileged passages, is encrypted, tokenized, or redacted, while the surrounding document stays readable, searchable, and indexable. The file opens normally in Office, Google Workspace, and PDF readers. Only the protected content requires authorization.
Where we fit
Selective encryption is the version of this that survives the filing rules. The file is not encrypted; the sensitive spans inside it are. It stays a standard, text-searchable PDF that opens in any reader, and the protected content stays unreadable to anyone without authorization. Nobody on the receiving end needs an account, a license, or a support call.
Outside counsel guidelines are setting AI policy, less strictly than advertised
What we heard
The prevailing account of outside counsel guidelines is that clients are tightening them sharply. This could include requiring pre-approval before client data touches any third-party AI tool, plus documentation to prove which tool was used or who reviewed the output. The legal-tech solution Intapp has made that case directly, and it is where the market is heading.
It was not what we heard. Firms described conditions rather than prohibitions, varying by client and by matter. Where hard exclusions do exist, several described applying the strictest version across the board because a blanket rule is easier to administer than a conditional one. This means the firm absorbs the cost of the client's caution.
Our read
Two things follow. The first is that client guidelines, not internal policy frameworks, are the practical driver of AI governance in firms right now. The second is that most firms cannot enforce a conditional rule even when the guideline permits one, which is why the blanket restriction wins.
There is a reason for that beyond administrative convenience, and it is the same reason the first pattern above exists. Governance configured inside a platform governs that platform. Client data does not stay in one platform — it moves from the document management system to email, to co-counsel, to an e-discovery vendor, to whatever tool the client asks the firm to work in next. A conditional rule has no single place to live, so the firm enforces it at the only point it fully controls: the decision to allow the tool at all.
That gap between having a policy and having a control is where the risk sits. IBM's 2026 Cost of a Data Breach research found that 92% of organizations suffering an AI-related breach had no AI access controls in place, and that shadow AI has risen fourfold as a non-malicious insider event, now the third most common. Intapp puts the same point well: a policy describes intent, and documentation proves execution.
The courts have started to weigh in. In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York held on February 10, 2026, that documents a criminal defendant generated with a publicly available AI tool were protected by neither attorney-client privilege nor the work product doctrine. The holding is narrow and confined to its facts: the defendant acted on his own initiative before retaining counsel and used a consumer version of the tool. It does not establish that a lawyer's use of AI waives privilege. What it does establish is that the confidentiality assumption behind AI use is now something a court will examine rather than presume.
Where we fit
AI Guard enforces those conditions on the content itself, before it enters a model, a retrieval index, or a fine-tuning set. A firm can take a different approach for each client without holding the strictest line for all of them.
What we got wrong
Ahead of the conference, we wrote about five sessions we were watching, and two of our predictions did not survive the week.
We argued that ethical walls would come under pressure from AI reading across an entire repository. Firms use walls, consider them handled, and were not asking that question. The concern stands on the merits — a wall enforced by one system reaches as far as that system does — but it was not on anyone's mind.
We were further off on the Trust Premium, where we expected firms to be treating provable security as a way to win client work. Our own research found that 87% of corporate clients say security posture influences their selection of outside counsel and 75% now require security questionnaires during procurement. On the floor, firms told us they were secure enough and wanted to discuss productivity.
The client-side demand is documented. What we misjudged was where it would surface. A firm using security posture to win work does that in pitches and RFP responses, not at a booth, and the firms furthest along have no incentive to describe their advantage publicly. Our read is that the Trust Premium is already operating in client pursuits and simply isn't a conference conversation. What we heard on the floor was that the middle of the market is still answering questionnaires rather than leading with the answers.
Where this goes
The pattern from ILTACON 2025 held: client data lives and moves well beyond the firm, and controls stop at the edge of whichever system implemented them. What changed is the number of destinations. Third-party involvement in breaches has gone from 15% two years ago to 30% last year to 48% in Verizon's 2026 reporting, and every AI tool a firm adopts is another place privileged content goes.
Last year's takeaway was that nobody wants a bigger tech stack. That held. What we'd add after this year is that nobody's stack will be a single product, either. Detection, document management, ethical walls, and data-layer protection each answer a different question, and a firm's data is protected to the extent those answers complement rather than duplicate one another.
Firms are right that they have layers. The question is what those layers answer. Most of the stack answers whether someone gets in. Protection at the data layer answers what they can read once they do, and it holds after the file leaves. It is also where the migration to post-quantum cryptography has to land, following the standards NIST finalized in 2024 — a problem the profession will inherit whether or not it reaches next year's agenda.
If you spoke with us on the floor and want to continue the conversation, or if dark archive data and legacy on-prem systems are on your list, point us at one data source, and we'll show you what's sitting unprotected in it.