The same week two AmLaw firms were confirming client data had been compromised in fresh breaches, the largest personal injury firm in the country was explaining why it had spent years quietly building something most of its peers were still trying to buy off a shelf.
On a Monday in late September, Morgan & Morgan -- with roughly 1,000 attorneys across all 50 states and a case volume that dwarfs most AmLaw 200 firms -- disclosed that it has been running a proprietary, in-house AI platform for years, and is now committing at least $1 billion to AI and technology investment over the next decade. No press tour. No product launch. Just a firm revealing, almost in passing, that it had already made the decision every general counsel and managing partner is currently agonizing over in a pilot committee meeting.
That timing is not a coincidence worth ignoring. It's a data point.
The Announcement That Wasn't Really News -- To Morgan & Morgan
What makes the disclosure notable isn't that Morgan & Morgan is investing in AI. Every firm above a certain size is investing in AI in 2026. What's notable is the tense: has been running, not is launching. The firm wasn't announcing a pilot. It was confirming that a build decision made years ago -- before "agentic AI" was a term anyone used in legal marketing -- had already paid for itself enough to justify a ten-figure, decade-long follow-on commitment.
A few things about that commitment are worth sitting with:
- $1 billion over 10 years is not a legal-AI-tooling budget. It's an infrastructure budget on the scale of a mid-size enterprise software company.
- The platform predates the current wave of legal AI vendors by years, meaning the build decision was made when the available alternative wasn't "a slightly worse Harvey" -- it was nothing, or a shared consumer chatbot with no legal-specific controls at all.
- Morgan & Morgan is a plaintiff's firm operating at extraordinary volume -- hundreds of thousands of active matters, a caseload that turns document review, intake triage, and case valuation into genuine data-engineering problems, not boutique use cases.
When a firm with that much operating leverage and that much to lose still chose to build rather than license, it's a signal about where the serious end of the market is actually headed, regardless of how the vendor conference circuit frames it.
The Same Week, Two Firms Confirmed the Alternative Risk
Context matters here. In the same news cycle, Greenberg Traurig and Eckert Seamans both publicly confirmed new data breaches. Neither breach was about AI specifically -- but both landed at the exact moment a major firm was explaining why it had spent years building infrastructure specifically to avoid depending on third-party systems for anything touching client data.
The juxtaposition is the story. Two firms confirming they'd been exposed via infrastructure they didn't fully control, in the same week a third firm confirmed it had spent a decade -- and was about to spend a billion dollars more -- making sure it wasn't in that position.
This isn't an indictment of Greenberg Traurig or Eckert Seamans specifically; breach disclosures are becoming a routine feature of the legal sector's threat landscape, not an outlier. That's precisely the point. Law firms sit on some of the most sensitive, highest-value data in the economy -- privileged communications, litigation strategy, M&A terms, personal injury medical records -- and they are increasingly being treated as a soft target precisely because so much of that data still flows through shared, third-party infrastructure with inconsistent controls.
Why the Largest Litigation Firm in America Didn't Buy a Chatbot
The strategic logic for building rather than buying scales with exposure, and few firms have more raw data exposure than Morgan & Morgan. Consider what's actually flowing through a personal injury practice at that scale: medical records, settlement valuations, intake data on potentially hundreds of thousands of individuals, litigation strategy across every state jury pool in the country. That's not a dataset you want sitting inside a shared multi-tenant system where your prompts, your document uploads, and your retrieval patterns are adjacent to every other customer's.
The firm's $1B commitment reads less like a marketing flex and more like a rational response to three pressures every large firm now faces:
- Volume economics. At Morgan & Morgan's case volume, even marginal per-seat SaaS pricing across a 1,000-attorney org compounds into tens of millions annually -- often for tools that still require the firm to send privileged content externally for every query.
- Model risk. Public commercial LLMs hallucinate, and hallucinated case citations have already produced sanctions in multiple jurisdictions over the past two years. A firm processing hundreds of thousands of matters cannot absorb that error rate at scale.
- Data exposure. Every document sent through a third-party interface is a document the firm no longer fully controls the lifecycle of -- retention, logging, training-data policy, breach surface.
Building in-house solves all three, at a cost. And that cost is the part of this story that doesn't generalize.
"Proprietary" at BigLaw Scale Still Isn't Private AI for Everyone Else
Here's the uncomfortable truth the Morgan & Morgan announcement surfaces: most firms cannot replicate this. A $1 billion, decade-long infrastructure commitment requires an engineering organization, a data science team, ongoing model evaluation capacity, and security operations most firms -- even sophisticated AmLaw 200 firms -- do not have and have no interest in building. Morgan & Morgan can do this because its case volume and marketing-driven client acquisition model generate the kind of revenue scale that makes a nine-figure tech budget rational. A 300-lawyer regional firm, or even a 1,500-lawyer national firm without Morgan & Morgan's volume economics, does not have that option.
That leaves most firms choosing between two paths that both have real problems:
| Approach | Data control | Build cost | Time to deploy | Who it fits |
|---|---|---|---|---|
| Shared-cloud legal SaaS (per-seat commercial tools) | Low -- documents and prompts routed through vendor's multi-tenant infrastructure | Low upfront, high recurring per-seat cost | Weeks | Firms prioritizing speed over control |
| Full proprietary in-house build (Morgan & Morgan model) | Full | $100M-$1B+, multi-year engineering org | Years | Firms with enterprise-scale volume and existing engineering capacity |
| Private AI infrastructure deployment | Full corpus, index, and workflow layer under firm control | Fraction of a build, no engineering org required | Weeks to months | Firms wanting Morgan & Morgan-level control without Morgan & Morgan-level capital |
The first column matters most. Shared-cloud tools optimize for fast adoption at the cost of data control. Full proprietary builds optimize for control at a cost of capital and time that prices out nearly everyone. The gap between those two options is exactly where private AI infrastructure sits -- and it's the option Morgan & Morgan simply didn't need because it had the balance sheet to build instead.
The Architecture That Actually Matters: Corpus Control vs. Model Access
The most common misunderstanding in this debate is treating "uses a commercial LLM" and "exposes client data" as the same thing. They're not, and conflating them leads firms to either over-invest in unnecessary full builds or under-invest in the controls that actually matter.
The distinction that matters is architectural, not brand-based:
- What should stay on firm infrastructure: the full document corpus, the retrieval and indexing layer, vector stores, permissioning, audit logs, and the agentic workflows that orchestrate multi-step legal tasks. This is the layer where privilege lives, where matter-level access controls are enforced, and where a breach would actually be catastrophic.
- What can legitimately leave the firm's environment: the minimal, retrieved text chunks needed to answer a specific query, sent to a selected LLM provider under the firm's own API terms -- not the underlying documents, not the index, not the client relationship data.
That's the model RAGbase Legal is built around: firms can still use frontier LLM providers when it makes sense, but the retrieval layer, the document store, the permissions, and the workflow scaffolding never leave the firm's own infrastructure. It's the architectural equivalent of what Morgan & Morgan spent years and a nine-figure budget building for itself -- minimized data movement, full corpus control, no dependence on a shared multi-tenant vendor environment -- made available as private AI deployment rather than a from-scratch engineering project.
This matters for practical workflows too. A litigation team running case search across tens of thousands of internal matters needs the retrieval index built on the firm's own precedent, not a generic public corpus -- and it needs that index to stay inside the firm's security perimeter, not distributed across a vendor's shared infrastructure serving hundreds of other customers simultaneously.
What Firms Without $1 Billion Can Actually Do
Most firms reading the Morgan & Morgan announcement will draw the wrong conclusion if they stop at "we should build our own platform too." Very few firms have the case volume, revenue model, or existing engineering bench to make that math work. The more useful conclusion is narrower: the specific things Morgan & Morgan's build was solving for -- data control, hallucination risk, breach exposure -- are solvable without replicating the ten-figure capital commitment.
That means asking different questions during procurement than most firms currently ask:
- Does the vendor's architecture keep the document corpus and retrieval index on infrastructure the firm controls, or does it live inside the vendor's multi-tenant cloud by default?
- When a query is answered, exactly what data leaves the firm's environment -- full documents, or minimized retrieved chunks?
- Can the firm choose or change its underlying LLM provider without re-architecting its entire deployment, or is it locked into one model provider's infrastructure and terms?
- Are permissioning, logging, and audit trails native to the firm's own systems, or dependent on the vendor's own security posture -- the same posture that failed at Greenberg Traurig and Eckert Seamans this month?
Firms evaluating this properly are increasingly running the comparison covered in our AI for law firms guide, where the real cost comparison isn't build-vs-buy in the abstract -- it's full proprietary build vs. shared-cloud SaaS vs. private deployment, mapped against actual data sensitivity and matter volume.
Where This Goes Next
Morgan & Morgan's disclosure is going to get read by other large firms as permission -- proof that a serious, scaled legal organization looked at the commercial AI vendor landscape and decided the exposure wasn't worth it. That reading is correct. What won't generalize is the assumption that the answer is always "build it yourself." Most firms don't have Morgan & Morgan's volume economics, and trying to replicate a billion-dollar, decade-long infrastructure program to solve a data control problem is its own kind of risk -- capital risk, talent risk, multi-year execution risk, with no guarantee of catching up to where commercial AI capability will be by the time the build is finished.
The more durable lesson is about architecture, not capital. The firms that come out ahead over the next several years won't necessarily be the ones with the biggest tech budgets -- they'll be the ones that got the corpus-control question right early, whether they answered it with a billion-dollar build or a private deployment that gets them the same guarantees in months instead of years.
If your firm is weighing that same question -- shared-cloud convenience versus genuine data control -- the Morgan & Morgan disclosure is worth treating as a data point, not a template. Map your own matter volume, data sensitivity, and existing infrastructure against the build-vs-private-deployment tradeoff before assuming either extreme is the right answer for your firm.
Frequently Asked Questions
Why did Morgan & Morgan build its own AI platform instead of licensing a commercial legal AI tool?
What is the difference between a firm's proprietary AI and a private AI deployment like RAGbase Legal?
Does using an LLM provider like OpenAI or Anthropic automatically mean a law firm's data is exposed?
Related Articles
Your AI Vendor's Moat Is Your Data. Here's How to Take It Back.
How SaaS AI vendors build competitive moats from your firm's usage data — the shared learning paradox, the dilution problem, and why proprietary AI keeps the compounding advantage with you.
98% of AmLaw 200 Firms Use AI — But Most Still Can't Search Their Own Files
98% AI adoption, but most law firms still can't search their own institutional knowledge. The gap between external AI tools and internal document access — and how to close it.
The True Cost of Legal AI: SaaS Subscriptions, Hidden Fees, and the Ownership Alternative
The hidden costs of legal AI in 2026 — SaaS subscription economics, the efficiency penalty on billable hours, data sovereignty risks, and why proprietary AI changes the math.
RAGbase builds private AI systems for law firms: deployed on the firm's own infrastructure, zero data retention, full ownership.
See How RAGbase Works on Your Data
30-minute call. We scope your use case and show the system live.