Data That Never Leaves the Firm: Compliance Considerations Behind the Second-Largest U.S. Law Firm's Self-Built AI Infrastructure
Latham & Watkins, the second-largest U.S. law firm by revenue, was recently reported to have taken a move rarely seen in the legal industry: it has directly purchased Nvidia GPU servers and begun building and fine-tuning its own internal artificial intelligence system. The news was first disclosed by the UK's Financial Times, subsequently confirmed by Bloomberg Law, Law360, and other media outlets, and Latham itself confirmed the fact to the press. Unlike most coverage that focuses on the technological spectacle of "law firms buying chips too," this article aims to discuss another thread driving this decision—data security compliance.
Beneath the Hardware Lies a Compliance Consideration
According to reports, Latham has been continuously purchasing servers equipped with multiple Nvidia GPUs over the past three years. It has now deployed several Nvidia H200 GPUs and is evaluating the newer-generation Blackwell and Vera Rubin architecture products. This hardware is housed in a third-party data center, but access is restricted to Latham's own employees. On the software side, Latham's engineering team is fine-tuning Nvidia's open-weight model Nemotron 3 to run on infrastructure controlled by the firm itself, rather than relying on closed-source cloud models provided by companies such as OpenAI and Anthropic.
The explanation given by Latham's Chief Information Officer Rene Mendoza to the Financial Times was straightforward: the sensitivity of certain client information makes the firm unwilling to hand it over to any cloud service provider. Behind this statement is actually a whole set of lawyer professional conduct rules imposing requirements for "reasonable measures to safeguard confidentiality"—and this is precisely the real driving logic behind this infrastructure investment.
Rule 1.6: Responsibility Not Transferred by Outsourcing Technology
American Bar Association (ABA) Model Rule of Professional Conduct 1.6(c) requires lawyers to make reasonable efforts to prevent information relating to the representation from being disclosed or accessed inadvertently or without authorization. The key feature of this rule is that its standard of judgment is "fact-specific"—the rule itself does not enumerate specific technical controls, but requires lawyers to comprehensively determine where the boundary of "reasonableness" lies based on factors such as information sensitivity, likelihood of disclosure, and feasibility of technical safeguards.
This raises a practical problem: when lawyers input client materials into a commercial AI tool, the data's flow path, retention period, and whether it is used for model training depend largely on the AI vendor's terms of service, not the firm's own control. The ABA's Formal Opinion 512 issued in 2024 on the use of generative AI explicitly states that lawyers have a responsibility to understand how generative AI tools process data and to implement adequate safeguards to ensure that data processing is secure and will not be inadvertently or without authorization disclosed to third parties. More importantly, this opinion, along with subsequent interpretations by bar associations in multiple states, emphasizes one point: even if a law firm signs a service agreement with an AI vendor, the ultimate responsibility for confidentiality obligations remains with the lawyer and is not transferred by delegating to a vendor. In other words, if the vendor breaches the contract or data is leaked, the risk of disciplinary action and professional liability still falls on the law firm itself.
Placing models and computing power within one's own controlled boundary is equivalent to replacing a compliance model of "relying on vendor promises" with one of "relying on one's own technical controls." This does not make confidentiality obligations disappear, but it does shorten the chain of trust required for third parties—if data never leaves the firm's network, then in theory there is no disclosure risk triggered by improper vendor data handling.
What Self-Built Infrastructure Solves and What It Does Not
It should be clarified that self-built GPU infrastructure is not a "once-and-for-all" compliance solution; it merely partially shifts the risk exposure from the "vendor side" to "one's own side." Several real compliance tasks will not be reduced as a result:
Vendor due diligence remains necessary. Latham has not completely abandoned commercial AI tools; reports show the firm still uses third-party legal AI services such as Harvey. For the parts that continue to use external tools, the set of vendor review frameworks already established in the industry—including reviewing SOC 2 Type II audit reports, clarifying clauses in data processing agreements (DPAs) prohibiting retention and secondary use, and understanding subprocessor lists—still applies and is not exempted just because the firm has built part of its infrastructure in-house.
The importance of internal access controls is equal or even greater. Data not leaving the firm does not mean data is not at risk. When models and data both run on the firm's own servers, who can access this system, how logs are retained, and how internal personnel permissions are tiered become new risk points. In other words, self-built infrastructure replaces the problem of "trusting external vendors" with the problem of "managing internal permissions well," and the latter equally requires institutional and technical measures to implement and is not inherently safer.
The workload of documenting responsibility will not decrease. Whether it is the requirements for incident response plans in ABA Formal Opinion 483 or the specific interpretations of the "reasonable efforts" standard by state bar associations, regulators expect not only that "a more secure architecture has been deployed" but also that the firm can demonstrate institutionalized records of risk assessment, access control, and emergency response. If self-built infrastructure lacks accompanying governance documentation, it may equally be difficult to prove compliance in a compliance review or dispute.
A signal that may be overlooked: peer review pressure
Kirkland & Ellis, another major U.S. law firm, posted a job listing in May this year seeking an AI infrastructure director responsible for managing a "locally deployed GPU cluster," indicating that at least a second leading law firm is simultaneously evaluating a similar path. This trend may have spillover effects on the industry's compliance baseline: when leading law firms begin to treat "whether data leaves the firm" as a differentiating capability they can showcase externally, clients—especially financial institutions and publicly listed company clients highly sensitive to information security—are likely to include the deployment method of AI infrastructure in their due diligence checklists when selecting external counsel, similar to the process by which reviews of law firm cybersecurity capabilities and SOC 2 certification gradually became standard. This means that "whether to build self-owned AI infrastructure" may in the future evolve from a technical selection issue into an indicator in client trust assessments.