Many law firms are understandably reluctant to adopt agentic AI because of its well-documented security risks, including prompt injection. Running open-weight AI models (usually free) on computers you own—but that are not connected to your business network—lets lawyers who want to experiment do so far more safely.

Isolation doesn’t guarantee there will never be

Prompt Injection is generally acknowledged as the most serious vulnerability in the deployment of AI apps, and AI agents in particular. The Open Worldwide Application Security Project (OWASP), considered by many the world’s leading authority on web-facing system security risks, lists prompt injection as Number One on their list of the top ten

Agentic AI Conventional software keeps code (instructions) strictly separate from data (the files being processed). Large language models collapse the distinction. To an agent, both are just natural language. A firm’s internal policy and an incoming email are structurally similar. The model cannot reliably tell a document it is meant to read from an order

The marketing promise for premium legal RAG-based models was a hallucination-free experience. The empirical reality is different. Why?

It is a structural problem, created by the way Large Language Models are created. The process includes inputting large amounts of information. This typically includes all the publicly available information on the Internet.

The next step is

She begged “Do not do that,” then “STOP OPENCLAW.” Neither worked.

That’s what happened to Summer Yue, Meta’s Director of Alignment at their superintelligence safety lab. By the time she reached her desktop to kill the process manually, the AI agent she’d created had already deleted hundreds of emails. You would expect someone with

Let’s stop blaming the hallucinations and focus on the real problem:

Lawyers who don’t do their job because they are too busy, too lazy, or too incompetent.

The lawyer who cites a hallucinated AI case and the lawyer who cites a real case without reading it have committed the same ethical failure. Today, it’s usually

The hype machine is working overtime on Agentic AI. Don’t fall for it.

AI chatbots merely respond to prompts. They only give you information. AI agents like Claude Cowork or Openclaw go beyond this. They are built on large language models, but can take action on your behalf.

That sounds great, but there is a

The promise has become a mantra: AI will free lawyers from drudgery so they can focus on higher-value work. Thomas Martin, writing for the Thomson Reuters Institute, points to research from UC-Berkeley that complicates that story considerably. The study tracked what actually happens when knowledge workers adopt generative AI. They don’t work less. They

When people think about malware, they often imagine someone clicking a suspicious attachment or downloading a shady file. In reality, one of the most dangerous forms of infection requires no obvious mistake at all. It’s called a drive-by download, and it remains a quiet but serious threat.

The Threat

A drive-by download occurs when