data sovereignty

The 2028 Cloud Mandate: Who Really Controls Your Matter Data?

Relativity's 2028 cloud deadline routes privileged eDiscovery data through frontier AI APIs. Here's why law firms now need private AI infrastructure.

RAGbase Legal Research TeamOctober 10, 2026 9 min read

When the company that hosts the privileged documents for a majority of the Am Law 200 tells its own customers "we're going to run through you," it's worth pausing on what, exactly, is being run through — and where it's going.

That's the line Relativity CEO Phil Saunders used to describe what happens to firms that don't comply with the company's January 1, 2028 deadline requiring all new matters to be hosted in RelativityOne's cloud. It wasn't a hedge or a soft suggestion. It was a statement of market power from a vendor that, by its own marketing claims, sits inside the document review workflow of nearly every large law firm in the country. And in the same conversation, Saunders added a second data point that deserves equal scrutiny: Relativity intends to build its AI roadmap by partnering with frontier model labs — OpenAI, Anthropic, Google — rather than with legal-specific AI vendors like Harvey or Legora.

Taken together, these two statements describe a future in which the dominant eDiscovery infrastructure layer for the legal industry pushes matter data onto public cloud, then routes AI processing of that data through general-purpose consumer-facing model APIs. That's not a hypothetical. It's the stated strategy of the company that already holds an estimated 84% of its ARR on cloud, with a hard deadline three years out for the rest.

The Deadline That Isn't Moving

Relativity's server product — the on-premise deployment that let firms host matters on infrastructure they controlled — has been on borrowed time for years. Saunders' recent comments close the door on any ambiguity. The January 1, 2028 cutoff for new matters stands. Firms running on-prem today aren't being asked to migrate; they're being told the migration is the only path that remains supported.

The business logic is straightforward. Cloud hosting is Relativity's higher-margin, easier-to-service product line, and with 84% of ARR already there, the remaining on-prem base represents operational overhead the company has every incentive to eliminate. From a vendor's P&L, this is a rational move. From a general counsel's or managing partner's risk register, it's a different calculation entirely — because it forces a decision about where privileged, work-product, and client-confidential material physically lives, on a timeline set by someone else's roadmap.

For the roughly 16% of ARR still tied to legacy or hybrid deployments — which, across Relativity's customer base, almost certainly includes firms handling the most sensitive matter types (national security-adjacent work, cross-border investigations, regulated-industry litigation) — this is no longer a conversation about convenience. It's a forced migration of the matter data most firms are least willing to migrate.

From Legal AI to Frontier Labs: A Strategic Pivot With Data Consequences

The second half of Saunders' comments is, in some ways, more consequential than the deadline itself. Relativity has signaled it will prioritize deep technical integration with frontier labs — OpenAI, Anthropic, Google — over partnerships with legal-specific AI vendors built specifically to handle privileged legal content, such as Harvey and Legora.

This is a meaningful architectural choice, not a branding preference. Legal-specific AI vendors were built, at least in marketing terms, around legal workflows: citation-checking, privilege-aware redaction logic, matter-specific retrieval tuned to litigation and transactional document types. Frontier labs build general-purpose foundation models designed to serve every industry simultaneously — healthcare, finance, consumer apps, and, now, legal document review, all running through the same underlying API infrastructure and commercial terms.

By choosing frontier labs over legal AI specialists, Relativity is optimizing for model capability and pace of innovation — GPT and Claude model families iterate faster than most vertical legal AI products can match. But it also means that when a reviewer inside RelativityOne runs an AI-powered privilege check, a deposition summary, or a document classification pass, that request is increasingly likely to be served by a general-purpose model endpoint operated by a company whose primary customer base has nothing to do with law.

That's not inherently reckless. OpenAI, Anthropic, and Google all offer enterprise API terms with data-handling commitments. But it does mean the data governance question shifts from "is my eDiscovery vendor handling my documents responsibly" to "whose API terms govern my privileged data, and did my firm actually negotiate them, or did they come bundled inside a platform decision made for us?"

The Hidden Data Path: Where Documents Actually Go

Most conversations about "the cloud" conflate two very different things: storage and processing. A matter hosted in RelativityOne's cloud means the full document set — natively, with metadata — sits on Relativity's cloud infrastructure. When AI features are layered on top, a second data path opens: content from those documents gets sent to whichever model provider is powering the AI feature, as a processing step.

This is the architecture point firms need to understand before 2028, not after. There are two fundamentally different models for how an AI system touches a document corpus:

Shared-cloud SaaS model (the Relativity + frontier lab path): The full matter — documents, metadata, review tags, workflows — lives on the vendor's cloud. AI features call out to a third-party model API (OpenAI, Anthropic, or Google) to process content on demand. The firm's relationship with the underlying model provider is mediated entirely by the eDiscovery vendor's contract, not the firm's own agreement.

Private AI architecture (the on-prem/hybrid path): The full corpus, the retrieval index, the vector stores, the permissions layer, and the audit logs stay on infrastructure the firm controls. When a question requires model reasoning, only the minimal retrieved text chunks needed to answer that specific query — not the full document, not the full matter — are sent to an LLM provider, under API terms the firm itself selects and can audit. The firm still gets frontier-model reasoning quality. What changes is custody: the corpus never leaves, and what does leave is deliberately minimized.

This distinction matters more than the oversimplified "cloud bad, on-prem good" framing that dominates vendor marketing on both sides. The honest version of the argument isn't that private AI never touches a frontier model API — it's that what leaves the firm's infrastructure is scoped, minimal, and governed by the firm's own terms, rather than bundled into a platform vendor's broader cloud and AI roadmap.

Comparison: Data Custody Under Each Model

DimensionShared-cloud eDiscovery + frontier AIPrivate AI architecture
Full document corpus locationVendor's public cloud (e.g., RelativityOne/Azure)Firm's own infrastructure (on-prem or firm-controlled private cloud)
What's sent to the LLM providerVaries by vendor implementation; can include substantial document contentMinimal retrieved chunks needed per query
Who negotiates LLM API termsThe eDiscovery vendor, on behalf of all its customersThe firm, directly with its chosen model provider(s)
Audit/permissions layerControlled by eDiscovery vendorControlled by the firm
Model choice flexibilitySet by vendor roadmap (frontier labs over legal AI specialists)Firm selects model(s) per matter sensitivity
Migration deadline exposureSubject to vendor timelines (e.g., Jan. 1, 2028)Not dependent on a third party's cloud transition schedule

Market Signal: Rivals Are Already Building the Alternative

Relativity's dominance has historically made alternatives feel theoretical. That's changing. Consilio's partnership with Reveal to launch a private-cloud eDiscovery alternative is a direct market response to the same pressure this article describes — and Consilio didn't frame it abstractly. The stated rationale was that clients want "more control over their costs than what traditional public-cloud models offer."

Read that carefully: a major eDiscovery competitor is building toward the 2028 deadline not by matching Relativity's cloud-only roadmap, but by offering the opposite — a private-cloud path specifically because enterprise clients are asking for it. That's not a niche request from a handful of security-obsessed GCs. It's a large eDiscovery provider making a strategic bet that sovereignty and cost control are a durable market segment, not a transitional phase firms will outgrow once they get comfortable with the cloud.

The Consilio/Reveal move is also a useful proof point for a broader thesis: when one dominant vendor in a category forces a binary choice (comply with our cloud mandate, or be left unsupported), competitors with a different thesis gain an opening. The same dynamic is playing out in legal AI more broadly, where firms are increasingly unwilling to accept that the only path to AI capability runs through a single vendor's cloud and a single set of frontier-model partnerships chosen on their behalf.

What This Means for AmLaw 200 Firms Between Now and 2028

Firms currently running Relativity Server deployments face a decision tree that collapses faster than most innovation committees are prepared for. Three broad paths exist:

  1. Full migration to RelativityOne cloud, accepting the bundled AI roadmap. This is the path of least immediate resistance. It also means accepting that AI processing of matter content will run through whichever frontier lab integrations Relativity prioritizes, on terms the firm doesn't directly negotiate.

  2. Migration to a private-cloud eDiscovery alternative (Consilio/Reveal being the clearest current example), preserving more infrastructure control while still meeting modern review and production requirements.

  3. Hybrid architecture: keep core document review on whatever platform makes sense operationally, but layer private AI deployment on top for the AI-driven work product — privilege review, deposition analysis, case search, matter intelligence — so the firm retains custody of its corpus and controls exactly what gets sent to any external model provider, regardless of which eDiscovery platform ultimately wins the hosting decision.

For firms with heavy regulated-industry, government, or cross-border caseloads, path three is increasingly the only one that satisfies both operational reality (you still need a review platform) and governance reality (your GC's data residency and privilege obligations don't change because a vendor moved its deadline up).

The Architecture Question Firms Should Be Asking Their Vendors

The 2028 deadline forces a conversation that should have been happening regardless of the date: not whether a firm uses frontier models, but who controls the layer between the firm's documents and those models.

Every firm evaluating AI tools right now — whether it's a consumer-facing assistant, a per-seat legal SaaS product, or an eDiscovery platform's bundled AI feature — should be able to answer three questions with specificity: Where does the full document corpus live? What exactly gets sent to the model provider, in what quantity, and under whose contract terms? And if the vendor changes its roadmap, cloud policy, or AI partnership strategy tomorrow, what happens to the firm's data the day after?

Relativity's answer, as of this announcement, is clear: documents live in its cloud, and AI processing will increasingly run through frontier labs chosen by Relativity, not by the firm. That's a legitimate strategic position for a platform vendor to take. It's also precisely the scenario that makes a parallel, firm-controlled AI layer — one where the corpus, retrieval index, and permissions stay in-house, and only the minimal necessary content reaches an external model — worth building before the deadline forces the decision. Our AI for law firms guide walks through how firms are structuring exactly this kind of hybrid architecture today, ahead of 2028.


The 2028 deadline isn't really about servers versus cloud. It's about who writes the terms governing privileged data once AI enters the workflow — the eDiscovery vendor, the frontier lab, or the firm. Firms that want a seat at that negotiation have roughly two years to build the architecture that keeps them in it.

Frequently Asked Questions

What is Relativity's 2028 cloud-only deadline?
Relativity CEO Phil Saunders confirmed that starting January 1, 2028, all new matters must be hosted in Relativity's cloud (RelativityOne), ending support for new on-premise server deployments. Roughly 84% of Relativity's ARR is already on cloud, and Saunders has told non-compliant firms bluntly, 'we're going to run through you.'
Does Relativity send law firm data to OpenAI, Anthropic, or Google?
Relativity has stated it will prioritize deep integration with frontier model labs (OpenAI, Anthropic, Google) over legal-specific AI vendors like Harvey and Legora for its AI features. This means AI-powered review and analysis inside a cloud-hosted matter is likely to route document content through general-purpose frontier model APIs rather than purpose-built legal AI infrastructure.
What's the alternative to cloud-only eDiscovery platforms for firms concerned about data sovereignty?
Firms can pair private/on-premise AI infrastructure with their review platform so that the full document corpus, indexes, and agent logic stay on firm-controlled infrastructure, while only minimal retrieved text chunks are sent to an LLM API under terms the firm selects. Competitors like Consilio, through its partnership with Reveal, have already launched private-cloud eDiscovery alternatives citing explicit client demand for more control.

Related Articles

R
RAGbase Legal Research Team
Research

RAGbase builds private AI systems for law firms: deployed on the firm's own infrastructure, zero data retention, full ownership.

See How RAGbase Works on Your Data

30-minute call. We scope your use case and show the system live.

We use audience and marketing cookies (Google Analytics, LinkedIn). No tracker loads without your consent. Learn more