Why law firms need to rethink identity security as AI tools join the workforce
5 min read.
There is a quiet shift happening inside law firms and most identity strategies have not caught up with it.
Document review tools that read, classify and summarise without human oversight. Intake assistants that pull information from client emails into matter records. Discovery platforms that scan terabytes and surface what's relevant. Agents that act on case management systems, document stores and email for fee earners.
Every one of these tools holds an identity and every one of them has access to client-confidential material. And every one of them is governed, in most firms, by the same control that governs anyone within the company logging in on a Monday morning: a username, a password and a multi-factor prompt.
That is the gap. And it is the gap that SentinelOne, in a recent piece of analysis, called the difference between authorisation and execution.
Authentication is not the finish line
For most of the last decade, identity security in professional services has been a story about getting the front door right. Stronger passwords, MFA everywhere, single sign-on, conditional access policies, as well as privileged access management for the partners and IT admins who hold the keys to everything.
This is all necessary but none of it is sufficient anymore.
The reason is straightforward. Once a user, or an AI agent, is authenticated, traditional identity systems stop watching. The assumption is that if you got through the gate, your behaviour from that point on is legitimate. That assumption was already strained when the only actors in the system were human but it breaks down completely when a meaningful share of the activity inside your firm is being executed by software that can act in milliseconds, at scale, without supervision.
SentinelOne distinguishes between continuous verification of who is acting, which applies to human users, and continuous validation of intent, which applies to non-human identities like service accounts and AI agents. A compromised AI agent does not need to fail a login challenge to do damage, it already has valid credentials. What changes is what it does with them.
Why this matters more for law firms than most
Three pressures stack up at once for the legal sector.
The first is regulatory. The SRA has been increasingly explicit about firms' obligations around AI governance, client confidentiality and data handling. When an AI agent touches privileged material, the firm carries the same duty of care it would for a human handling that file. Demonstrating that duty of care requires more than a record of who logged in. It requires evidence of what the agent did, with what data, and whether that behaviour was within its authorised scope.
The next is commercial. Clients are starting to ask and cyber due diligence questionnaires from corporate clients now routinely include questions about AI tool governance and non-human identity controls. Firms that can answer those questions with specificity will win work. Firms that cannot, will be quietly removed from panels.
Finally, it is operational. The pace at which AI tooling is being adopted inside firms, often by individual practice groups rather than through a central IT strategy, means that the inventory problem is real. Most firms do not know how many AI agents, integrations or service accounts have access to their data right now and you cannot govern what you have not catalogued.
What continuous validation looks like in practice
The shift SentinelOne describes and the one we are increasingly building into client environments, is from a model of access control to a model of behavioural validation. In practical terms, that also means three things.
First, a real inventory of non-human identities. Service accounts, API keys, workload identities, integrations, AI agents. Not a spreadsheet maintained by one person who left two years ago. A live, queryable record of every machine actor with access to firm data, what it is permitted to do and what it is actually doing.
Second, behavioural baselines for those identities. An AI agent that ordinarily summarises documents inside one matter folder, suddenly accessing the entire document management system, is a signal. Not because it has done anything technically unauthorised, but because its behaviour has changed shape. Continuous validation means treating that change as a question worth asking, in real time.
Third, the ability to revoke access mid-session. If an authenticated identity, human or otherwise, starts behaving in a way that suggests compromise or drift, the response cannot wait for the next login cycle. Access has to be withdrawable at the moment the behaviour is detected, with the evidence preserved for review.
Where to start
Most firms are not going to rebuild their identity stack overnight and they should not need to. The useful starting point is a structured conversation about what you have, what it can see and what would happen if one of those non-human identities behaved badly.
That conversation does not require a procurement decision. It requires honesty about the current state and a willingness to ask whether the controls that worked when the only users were people are still doing the job they were designed for.
Network and identity infrastructure is no longer a back-office concern. For a law firm, it is the substance on which client trust runs. As the number of things acting inside your systems grows, the question is no longer who is allowed in. It is what they are doing once they are.
Netprotocol is a SentinelOne partner, helping legal sector clients across the UK secure both human and non-human identities across their environments.