Nick Hallam
19 August 2026
Before connecting an AI assistant to your firm's matter files, establish four things: where inference runs, whether your data trains a model, whether the assistant can only read or can also change records, and who approves each action. MatterFirst, a legal practice management platform for Australian law firms, publishes an MCP endpoint that stays off until an administrator enables it.
This is not the same question as "should we use AI"
Most firms have already settled the first question. Someone is summarising a lease in a chatbot, someone else is drafting a letter of advice with it, and the firm has a policy about it that is either honoured or quietly ignored.
Connecting an assistant to the matter files is a different decision, and a larger one. Pasting a clause into a chat window exposes one clause. Giving an assistant a live connection to the system of record exposes every matter that the connecting user can see, continuously, without anyone choosing which document goes across each time. The convenience is real: asking "which matters settle in the next fortnight and what is outstanding on each" and getting an answer from your own file is genuinely faster than running three reports. The exposure is real too, and it is not the same exposure your AI policy was written for.
The questions below are the ones worth resolving before the connection is made, not after. Most of them have a checkable answer, which is the point: a vendor either publishes the answer or does not.
The Supreme Court has already told you what to establish
If you practise in New South Wales, the shape of this analysis is not a matter of taste. Practice Note SC Gen 23, issued 28 January 2025 and commencing 3 February 2025, sets conditions on entering certain material into a generative AI program at all.
Paragraph 9A applies to information subject to non-publication or suppression orders, material produced on subpoena, material covered by the implied Harman undertaking, and anything subject to a statutory prohibition on publication. That material must not be entered into any GenAI program unless the practitioner is satisfied that the information:
- will remain within the controlled environment of the platform being used, and the platform is subject to confidentiality restrictions on the supplier ensuring the data is not made publicly available and is not used to train any large language models;
- is used only in connection with that proceeding, unless disclosure is otherwise required or permitted by law; and
- is not used to train the GenAI program or any large language model.
Paragraph 9B then confirms that, subject to 9A, a GenAI program may be used to generate chronologies, indexes and witness lists, to prepare briefs, to summarise or review documents and transcripts, and to prepare written submissions. Paragraph 10 prohibits its use in generating the content of affidavits, witness statements and character references. Paragraphs 16 and 17 require the author of written submissions to verify that every citation and legislative reference exists, is accurate and is relevant, and say that verification must not be carried out solely with a GenAI tool. Paragraph 20 prohibits using GenAI to draft an expert report, or any part of one, without prior leave of the Court.
Read paragraph 9A as a procurement specification rather than a litigation rule and it becomes a short vendor questionnaire. A connected assistant reaches subpoenaed material by default, because subpoenaed material sits on the matter with everything else. The three conditions in 9A are exactly the three things a vendor should be able to answer in writing.
Queensland practitioners should also read QLS Guidance Statement No. 37, which frames the ethical duties that survive any use of AI, and touches on when an AI cost can sit with the client as a disbursement rather than as practice overhead.
The questions, and what a good answer sounds like
| Question | A weak answer | A checkable answer |
|---|---|---|
| Where does inference run? | "Your data is hosted in Australia." | The named region for storage, and the named region for each model call, listed separately |
| Is our data used for training? | "We take privacy seriously." | A contractual statement of no training, extending to the model vendor, not only the platform |
| Can the assistant change anything? | "It has full access to your matters." | A list of read tools and a list of write tools, with the write path described |
| Who approves an action? | "Users are responsible for output." | A named person at the firm approves each request in the system before it takes effect |
| Which user's permissions apply? | "The integration has its own access." | The connection inherits a real person's role-based access, and the audit trail names them |
| How do we turn it off? | "Contact support." | An administrator switch in the product, effective immediately |
| What is recorded? | "We log everything." | Per call: which client, which user, what was asked, whether it was answered or refused |
| What does it cost to run? | "AI is included." | A published rate per unit of work, or an explicit statement that it is included and rate limited |
The distinction that matters most, and the one most commonly skipped, is between storage and inference. A vendor that stores your documents in Sydney may still send the text of those documents to a model endpoint in another country, and the two answers are frequently different. Ask the second question explicitly, in writing.
The second most important distinction is read versus write. An assistant that can only read is a research tool and the failure mode is a wrong answer, which a lawyer catches. An assistant that can send an email, close a matter or record a fact has a failure mode that reaches a client before anyone reads it. The safe default is that every write is a request that a person at the firm approves, not an action.
How the major Australian platforms describe AI access today
Verified against each vendor's own public pages in August 2026. "Not published" means the vendor does not state it on the pages checked, not that the capability is absent. Ask them directly and get the answer in writing.
| Platform | Built-in AI features | Connect your own assistant | How AI is charged | Published position on where AI processing runs |
|---|---|---|---|---|
| MatterFirst | AI assistant, Document AI extraction, bulk review projects | MCP endpoint documented, off until an administrator enables it, per-tool approval | Monthly balance in Australian dollars with published per-item rates | Firm's chosen AWS region, Sydney by default; the document reading step runs on Azure Australia East |
| LEAP | Matter AI, LawY, AI Prompts, Generator, AutoTime | Not published | "Nothing extra. Matter AI, LawY, AI Prompts, Generator and AutoTime are all included in every LEAP subscription." | Not published; states AI operates within LEAP under the same security standards as the platform |
| Clio | Manage AI, the evolution of Clio Duo | Not published | Not published | Clio's help centre states that, depending on where your firm is located, Manage AI may process queries on servers outside your home jurisdiction, with resulting data stored in your region |
| Smokeball | Archie, Archie Apps, LawY integration | Not published | Not published | States Archie operates in Smokeball's secured environment under zero data retention agreements; no region named |
| Actionstep | Actionstep Intelligence, Trace, Acumen | Not published | Not published | States firm data is not used to train AI models; no region named |
The Clio row is worth dwelling on, because it is the only one of the four that answers the inference question directly, and the answer is a qualified one. That is not a criticism of Clio. Publishing a nuanced answer is more useful to a buyer than publishing nothing, and a firm that reads it can decide whether it matters for its practice. It is a reminder that "hosted in Australia" and "processed in Australia" are two claims, and the second one is the one your professional obligations turn on.
How MatterFirst handles this
MatterFirst is a legal practice management platform for Australian law firms, built by North Cape Technology in Melbourne. It speaks the Model Context Protocol, so a firm can point an approved assistant such as Claude or ChatGPT at its own workspace rather than adopting a second assistant.
The connection is off until an administrator switches it on in Settings, MCP. Nothing is installed and nothing is published: the firm adds MatterFirst inside whatever assistant it already uses, and nobody outside the firm sees it. ChatGPT and Claude authorise by signing in to MatterFirst through OAuth 2.1 with PKCE, so there is no key to paste or lose. Assistants that read a configuration file use a bearer key issued in the app, and the guidance is to issue a separate key per machine so that a lost laptop means revoking one key.
Read tools answer from your own records and cite the document and page the answer came from. Every tool that would change something submits a request instead: sending an email, creating a task, closing a matter and recording a fact each appear in MatterFirst for a person at the firm to read and approve, and nothing happens until they do. That is the setting every tool arrives with. A firm can waive approval for one specific tool it has decided is safe, and the request is still recorded either way, against the person whose access was used. Tools can also be refused to outside clients while the firm's own people keep using them.
Every call is recorded against the firm, with the client that made it and whether it was answered or refused. The default rate limit is 120 calls a minute per key, set by the firm. Access can be withdrawn at any time, which closes the door.
On the two questions above: matter data, documents, extraction and matter questions all stay in the AWS region the firm chooses, Sydney by default. The one step that runs elsewhere is reading the document itself, on Azure AI Document Intelligence in Azure's Australia East region. Both regions are in Australia, and the security page sets out which is which so you can verify it during a trial rather than take it on trust.
Who this suits, and who it does not
Connecting an assistant to matter files suits firms that already have a house assistant their lawyers use daily and are tired of copying context into it, and firms whose questions span matters rather than sitting inside one. It suits practices where a principal will actually read the approval queue.
It does not suit a firm that has no AI policy yet, because the connection will outrun the policy. It does not suit a firm that wants the assistant to act unattended: if the appeal is that AI will send the client emails without anyone reading them, no permission model makes that safe, and the professional obligation to supervise does not move.
More broadly, MatterFirst suits Australian firms of roughly two to twenty fee earners that need onshore hosting, state-based trust accounting and document generation that is deterministic by default. Its trust compliance review workflow covers NSW, VIC, QLD and WA, so a firm operating a trust account in SA, TAS, ACT or NT should confirm that gap before shortlisting, even though matters can be recorded in all eight jurisdictions. Firms that need a connected PEXA or InfoTrack workflow today should note that both are listed as coming soon rather than available: the four integrations that connect self-serve now are Xero, Stripe, Microsoft 365 and Google Workspace, with a documented REST API and webhooks for anything else.
Frequently asked questions
Can I connect Claude or ChatGPT to my practice management system? With MatterFirst, yes, through its MCP endpoint, once an administrator enables it. Custom connectors sit on Claude's paid plans and behind a developer setting in ChatGPT. For the other Australian platforms in the table above, an equivalent capability is not published on their public pages as at August 2026, so ask them.
Does connecting an AI assistant to matter files breach client confidentiality? Not inherently, but it is the practitioner's judgement to make, not the vendor's. NSW Practice Note SC Gen 23 paragraph 9A sets out the conditions for suppressed, subpoenaed and Harman-protected material, and those conditions are about the platform's controlled environment, use limited to the proceeding, and no training on your data. Get all three in writing before you connect.
Where does MatterFirst process AI requests? Extraction, analysis and matter questions run in your chosen AWS region, Sydney by default for Australian firms. The initial document reading step runs on Azure AI Document Intelligence in Azure's Australia East region. Both are in Australia.
Can a connected assistant send an email to my client without anyone checking? Not by default. Every tool that would change something submits a request that a person at the firm approves in MatterFirst first. A firm can waive approval for a specific tool it has assessed, and the request is still recorded against the person whose access was used.
What does the AI cost, and can I bill it to the client? MatterFirst plans start at $199 AUD per month per workspace with users included, and each plan carries a monthly AI balance in Australian dollars rather than credits: A$100 on Solo, A$280 on Practice, A$600 on Firm. Rates are published on the AI pricing page, and each charge records its matter so you can export a per matter statement. Whether that is recoverable is between you, your costs agreement and your client. QLS Guidance Statement No. 37 is the starting point in Queensland.
Does the assistant see everything in the firm? It sees what the connecting person's role allows, and each tool can be enabled or refused separately, including refusing a tool to outside clients while the firm's own staff keep it.
Before you connect
Put the eight questions to your current vendor first, in writing, before you evaluate anyone else. If the answers are good, you have saved yourself a migration. If they are not published, that is information too, and it is the same information a professional indemnity insurer would want.
The evaluation checklist has the fuller set of questions worth putting to any vendor, including the ones about data residency and export that have nothing to do with AI and matter just as much.
Related posts
Legal software data residency in Australia: where your firm's matter data actually lives
Data residency for Australian law firms is not one question but six: database, documents, backups, AI processing, subprocessors and support access can each sit in a different country. What to ask, how to verify it, and what LEAP, Clio, Smokeball, Actionstep and MatterFirst publish today.
Legal TechAI document extraction in a legal workflow: how a contract becomes matter data
Extraction reads what is in a document. Generation writes what is not. A five step walkthrough of what happens between an upload and a filled matter field, what to test in a trial, where the inference actually runs, and how MatterFirst, LEAP, Clio, Smokeball and Actionstep describe their own document AI.