Executive Summary

Jared sits down with Carly Savar, general counsel at Steno, to unpack what actually happens when a law firm signs up with an AI vendor. Carly explains why reading the fine print matters more than any feature list, and what separates a vendor you can trust from one that's just telling you what you want to hear.

Key Takeaways

  • Read the actual data processing agreement yourself. Don't assume a vendor's security is handled just because they signed a service level agreement.

  • Push for a zero-day retention agreement, and ask about the LLMs your vendor is built on, not just the vendor itself.

  • SOC 2 Type 2 certification means a company's controls held up over a full year. SOC 2 Type 1 only proves a single snapshot in time.

  • Not all training is created equal. Aggregated usage data is usually fine. Your client's confidential content should never go into a model.

  • New billing ethics guidance says you can only charge for the time you actually spent, not the time an AI tool saved you.

About the Guest

Carly Savar is general counsel at Steno, a litigation support and court reporting technology company. She spent years litigating before founding her own legal recruiting company and eventually moving in-house. Carly now negotiates AI and data agreements from both sides of the table, as counsel to a legal tech vendor and as a buyer evaluating other vendors herself.

Links and Resources

  • Steno: steno.com

  • Red Cave Law Firm Consulting: redcavelegal.com

Keywords

legal tech, legal technology, AI for lawyers, AI vendor vetting, legal AI vendor contracts, data security for law firms, zero-day retention agreement, SOC 2 Type 2, SOC 2 certification, ISO 27001, shadow AI, in-house counsel, legal tech general counsel, court reporting technology, Steno, AI training data, law firm AI policy, small law firm technology, technology competence rule, Red Cave Law Firm Consulting

Episode Chapters

  • 00:00:00 Cold open and show intro

  • 00:02:00 Meet Carly Savar and the vexing AI vendor problem

  • 00:03:00 Zero-day retention and why training on your data is the real risk

  • 00:06:00 What to actually ask vendors before you sign

  • 00:08:00 SOC 2 Type 1 vs Type 2 and other certifications

  • 00:10:00 Life as GC inside a legal tech vendor

  • 00:13:00 Clients who want cool tech vs clients who ask the right questions

  • 00:15:00 Not all training is created equal

  • 00:16:00 Keeping up with shifting ethics rules and regulations

  • 00:18:00 Tech competence and billing for time spent, not time saved

  • 00:22:00 Advice for lawyers going in-house at startups

  • 00:24:00 Carly's path into law and out of Big Law litigation

  • 00:27:00 Finding Steno and the frog-in-water approach to tech adoption

  • 00:33:00 Going to law school too soon and learning to fail

  • 00:37:00 Women in legal tech today

  • 00:39:00 Wrap-up and where to find Carly and Steno

 

Podden och tillhörande omslagsbild på den här sidan tillhör Jared Correia. Innehållet i podden är skapat av Jared Correia och inte av, eller tillsammans med, Poddtoppen.