Written by: Wiktor Stefański, Head of People & Operations, Digital Colliers
Anthropic disclosed this week that Claude breached systems belonging to three unnamed organisations during red-team exercises. Earlier this year, OpenAI and Hugging Face both dealt with their own model and token exposure incidents. If you're outside counsel, the question your general counsel is about to ask you is very specific. "Which AI vendors touched our matter, and did any of them have an incident in the last 90 days?" Most firms cannot answer that today.
The question is not hypothetical anymore
Clients have watched the fabricated-citation story metastasise. Court cases involving AI-hallucinated citations went from 87 to over 1,300 in eleven months last year. That number scared risk committees at every serious client. What comes next is the second wave of scrutiny, which is not about hallucinations at all. It's about the vendor stack itself, and whether your firm knows what's inside it on a per-matter basis.
The ABA already put a marker down. Formal Opinion 512 makes it clear that lawyers cannot bill hours that AI actually saved. The SRA issued its own AI guidance back in November 2023. Regulators have said, in effect, "you own the tool's behaviour." Clients are now saying the same thing out loud. If Claude is quietly used inside a discovery vendor, and that vendor's provider had an incident, your client wants to know before they read about it in a filing.
What the data model actually looks like
There are two artefacts you need. Neither is exotic. Both are usually missing.
The first is a per-matter AI vendor log. For every matter, a lightweight record that captures:
- Which AI-enabled tools were used, at what phase, and by which fee-earner
- The underlying model provider behind each tool, not just the vendor brand
- What data category went in (privileged, personal, financial, public)
- Whether outputs were reviewed by a human before leaving the firm
- The vendor's data-retention posture for that matter
The hard part is the second row. Your e-discovery platform might say "AI-assisted review." You need to know if that's Claude, GPT-4, an open-weights model, or a mix. Vendors resist this question. Ask it anyway, in writing, and log the answer.
The second artefact is a live incident register. One page, updated when a provider in your stack discloses anything material. Anthropic's red-team disclosure, OpenAI outages, token leaks, model behaviour changes, jailbreak reports. You want the entry to include the date, the provider, the affected products, whether your firm uses any of them, and the client-notification decision.
Most firms are running this in someone's head or in a Slack channel. That doesn't survive contact with a serious client questionnaire.
The patch-latency reality
Here is the uncomfortable part. Only about 3 to 5 percent of publicly disclosed security vulnerabilities get patched within 30 days. AI vendors are not magically better at this than the rest of the software industry. If your incident register is populated only when a vendor decides to notify you, you are already behind. The winning approach is to subscribe to the vendors' own security advisories, mirror them into your register, and then decide per-matter whether client notification is triggered.
Think of it as conflicts-checking, but for AI supply-chain events. The muscle already exists in every firm. It just hasn't been pointed at this yet.
The hard deadline
EU AI Act Article 50 transparency obligations apply from 2 August 2026. That is the date by which any client with EU exposure will expect you to disclose AI use in the work product itself. High-risk obligations follow on 2 December 2027. Fines for high-risk violations reach up to 15 million euros or 3 percent of global turnover, and that is before you factor in client-relationship damage.
2 August 2026 is roughly the time it takes a mid-sized firm to procure a tool, roll it out, train fee-earners, and get through one full audit cycle. If you start building the per-matter log and incident register in Q1, you have a chance of walking into that deadline with something real. If you start in Q4, you'll be doing it under client pressure with a live incident on the register. That is a much worse conversation.
The firms that answer the question calmly next quarter are the ones building the ledger now.

