# When Your Legal AI Vendor Is Breached or Shuts Down

> Your duties do not move when the vendor fails. What ABA Opinion 483 requires after a vendor breach, and what one day's shutdown notice actually costs a firm.

[Home](https://rankshieldlegal.com/) / [Blog](https://rankshieldlegal.com/blog/) / Firm Security Vendor failure
# Your Legal AI Vendor Gets Breached or Shuts Down: Whose Problem Is It?
Every vendor-diligence guide, including ours, is written for the moment before you sign. Almost none is written for the moment the vendor fails. On June 30, 2022, the litigation analytics company Gavelytics shut down with one day's notice to its customers and employees. That is the scenario worth planning for, because when a third party holding your privileged material is breached or goes dark, your professional obligations do not transfer to them. They stay with you.

By [Jamie Kloncz](https://rankshieldlegal.com/about/), Founder, RankShield ** 20 min read ** Published September 8, 2026

There are two vendor failures a firm should have a plan for, and they look nothing alike. In the first, the vendor is breached and your client's confidential material is exposed by someone else's security failure. In the second, the vendor simply stops: it shuts down, gets acquired, or is bought and folded into something that no longer does what you needed.
The first has a clear ethical framework and most firms have never read it. ABA Formal Opinion 483, "Lawyers' Obligations after an Electronic Data Breach or Cyberattack," issued in October 2018, addresses what a lawyer must do after a breach, and it reaches breaches that occur at or through a third-party service provider [[1]](#ref-1) [[2]](#ref-2).
Its most uncomfortable holding is about safe harbors: there are none. On the IAPP's reading of the opinion, a lawyer's post-breach notification obligations are independent of any assessment of how reasonable the lawyer's efforts to avoid the breach were [[2]](#ref-2). Doing the diligence properly does not discharge the duty to tell the client when it fails anyway.
The second failure has almost no ethical literature and a great deal of history. Gavelytics closed on June 30, 2022 with a single day's notice; its platform and data were acquired by another company six months later. ROSS Intelligence shut down in December 2020 after litigation with Thomson Reuters left it unable to secure financing. LexisNexis Firm Manager, by contrast, was discontinued with an orderly wind-down planned well in advance, closing on October 31, 2017 [[3]](#ref-3).
The difference between one day's notice and a planned wind-down is not something a firm controls after the fact. It is decided in a contract signed years earlier, or not decided at all. This article is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. Opinion 483 is an ABA ethics opinion rather than binding law, jurisdictions vary, and breach-notification statutes apply independently. Confirm your own obligations with counsel.

## Opinion 483 reaches breaches that happen at the vendor
The duty does not stop at your own perimeter. Opinion 483 addresses lawyers' obligations after an electronic data breach, and its framework extends to breaches occurring at or through a third-party service provider, with vendor oversight running through the Rule 5.3 duty regarding nonlawyer assistance [[1]](#ref-1) [[2]](#ref-2).
Firms tend to read breach obligations as being about their own systems. The relevant question is not whose server was compromised, it is whose client confidential information was in it.
The structural route is Rule 5.3, which governs a lawyer's responsibilities regarding nonlawyer assistance. A vendor processing client material is performing work the lawyer is responsible for supervising, and the opinion's framework treats vendors as subject to that oversight obligation rather than as a boundary where the lawyer's duty ends [[2]](#ref-2).
That has an obvious implication most vendor evaluations miss. The diligence you perform before signing is not only about choosing well. It is the evidence that you exercised the supervision the rule requires, which is a different purpose and a different audience. Our guide to [reading a SOC 2 report](https://rankshieldlegal.com/blog/read-soc-2-report-legal-ai-tool) covers how to assess the controls; this is the reason the assessment itself is worth documenting.
It also means the firm cannot treat a vendor incident as the vendor's announcement to make. The vendor will notify the firm. The firm owes its own communication to its own clients, on its own timeline, and the vendor's public statement does not discharge it.

## There is no safe harbor for having done the diligence
The holding that surprises careful firms most: on the IAPP's reading, a lawyer's post-breach notification obligations are independent of a reasonableness assessment of the lawyer's efforts to avoid the breach [[2]](#ref-2). Having chosen a well-audited vendor does not reduce the duty to tell the client when that vendor is compromised.
This is the ethical analogue of a finding this site has covered from the litigation side. In Johnson v. Dunn the court treated a firm's existing AI policies as aggravating rather than mitigating, noting the lawyers had benefitted from repeated warnings and internal controls before the failure happened anyway. Opinion 483 does something structurally similar for breaches: good prior conduct does not buy relief from the post-incident duty [[2]](#ref-2).
The two propositions are worth holding together because firms tend to assume the opposite. Diligence feels like insurance. It is not insurance against the disclosure obligation; it is evidence of supervision, which is a separate benefit.
What diligence does affect is everything downstream of the notification: whether the firm can tell the client what happened, whether contractual remedies exist, whether the vendor is obliged to help, and whether the firm looks like an organization that was paying attention. Those are substantial. They are not the duty.
The practical reframing is that the diligence file and the incident file serve different masters. The first answers whether the firm supervised. The second answers what the firm did when supervision was not enough. A firm that has only the first is missing the one that gets used.

Source: ABA Formal Op. 483 (Oct 2018) via IAPP; LawSites legal tech failures Download SVG

## Current clients and former clients are not the same question
Opinion 483 draws a line most summaries blur. An obligation exists to communicate with current clients about a data breach. On former clients the committee declined to impose an ethical notice requirement, stating it was unwilling to require notice to a former client in the absence of a black letter provision, and pointing instead to Rule 1.16(d) and to agreements about information handling and record retention [[2]](#ref-2).
This distinction is worth stating carefully because it is frequently reported the other way, including in summaries that assert Opinion 483 requires notifying both. It does not.
For current clients the position is straightforward: an obligation exists to communicate about a breach, triggered where client interests have a reasonable possibility of being negatively impacted, including where confidential information has been misappropriated, destroyed or compromised, or where the lawyer's ability to provide legal services is substantially impaired [[2]](#ref-2).
For former clients the committee declined to create an ethical duty, reasoning that the Model Rules contain no black letter provision requiring it. It pointed to Rule 1.16(d), which concerns a lawyer's obligations on termination of a representation, and encouraged firms to reach agreements with clients about how information will be handled and to adopt record-retention schedules [[2]](#ref-2).
Two consequences follow, and they cut in opposite directions. The first is that a firm holding years of former-client material in a vendor system has less ethical clarity about notification than it probably assumes. The second is more useful: the committee's suggestion is that the answer belongs in the engagement letter and the retention schedule rather than in an ethics opinion. That is a document a firm can change this quarter.
⚠️ Note also that ethics rules are not the only layer. State breach-notification statutes apply to personal information regardless of what the Model Rules say about former clients, and those obligations run on their own triggers and timelines. Nothing in Opinion 483 displaces them.
Because the ABA site blocks automated retrieval of the opinion PDF, the characterizations above are drawn from the IAPP's analysis of Opinion 483 rather than quoted from the opinion text, and are attributed accordingly. The opinion itself is the authoritative statement; read it before relying on any summary, including this one.

## The second failure: the vendor that simply stops
Shutdowns do not come with a standard notice period. Gavelytics closed on June 30, 2022 with one day's notice to customers and employees. LexisNexis Firm Manager was discontinued with an orderly wind-down planned in advance, closing October 31, 2017. Both are normal outcomes. Which one you get is decided by your contract [[3]](#ref-3).
The legal technology graveyard is not hypothetical and it is not confined to marginal products. ROSS Intelligence, an AI legal research company, shut down in December 2020 after litigation with Thomson Reuters left it unable to secure financing. Atrium closed in 2020 having raised $75 million [[3]](#ref-3).
Gavelytics is the instructive one for planning purposes. A litigation analytics company closed on June 30, 2022, giving customers and employees a single day's notice. Its platform and data were acquired by another company roughly six months later, which is a reasonable outcome and also entirely outside the customers' control during the intervening period [[3]](#ref-3).
Set that against LexisNexis Firm Manager. Sales were discontinued in January 2017, the shutdown was planned in advance, and the service closed on October 31, 2017 [[3]](#ref-3). Same category of event, completely different experience for a firm that had matters running on it.
The variable is not the vendor's decency. It is whether anything in the agreement obliged them to give notice, provide an export, or maintain access during a wind-down. Absent a term, a company in financial distress owes its customers whatever its remaining resources and goodwill allow, which in Gavelytics's case was one day.
Acquisition is the version firms plan for least, because nothing appears to break. The product continues, the login works, and the terms, the retention schedule, the sub-processor list and the data location may all change under a new owner. A firm that verified those things at signing and never again has verified a state of affairs that no longer obtains, which is the argument our [RFP guide](https://rankshieldlegal.com/blog/legal-ai-rfp-security-requirements) makes for annual re-checks.

## The duty you cannot discharge without the data
Rule 1.16(d) requires a lawyer to surrender papers and property to which the client is entitled on termination of a representation. That is a duty you cannot perform if the material sits in a vendor system you can no longer reach. The vendor's failure becomes your inability to meet an obligation the client is owed.
This is the point at which a vendor problem stops being procurement's and becomes professional responsibility's.
A client whose representation ends is entitled to their file. If a meaningful part of the work product, correspondence, or analysis lives inside a platform that has gone dark, been repossessed by a creditor, or been folded into an acquirer's stack under different terms, the firm owes something it may not be able to produce.
The exposure is quiet because it is deferred. Nothing goes wrong on the day the vendor closes. It goes wrong months later when a client asks for their file, or a matter is transferred, or a malpractice claim requires reconstructing what was done and when.
The verification record has the same shape and the same vulnerability. This site argues consistently that a firm should be able to show which authorities were checked and by whom, and our guide on [proving verification to a court](https://rankshieldlegal.com/blog/prove-you-verified-ai-citations-to-court) works through why. A verification log that exists only inside a vendor's system is a record you do not actually hold.
That is the practical test for any legal AI tool: if this vendor disappeared tomorrow, what would the firm still have. If the honest answer is a login that no longer works, the firm has been renting its own evidence.
1 day notice Gavelytics gave customers and employees before shutting down on June 30, 2022 [3]

## What to negotiate before you need it
Five terms decide how a vendor failure lands: notice on discontinuation, export format and retrieval window, what happens on acquisition or insolvency, breach-notification timing to you, and cooperation obligations during your own client notification. All of them are cheap at signing and unobtainable afterwards.
None of these terms is exotic and all of them are easier to obtain during a competitive procurement than during a crisis. The reason firms lack them is that vendor evaluation focuses almost entirely on capability and security posture, both of which describe the vendor working rather than the vendor failing.
The export term deserves the most attention and gets the least. "You can export your data" is not a commitment worth much unless it specifies the format, whether it includes metadata and audit logs, how long access persists after termination, and whether export remains available if the account lapses for non-payment. A CSV of document titles is technically an export.
The insolvency and acquisition provisions are the ones a vendor may resist and the ones that matter most in exactly the scenarios this article describes. A company that is being wound down has limited ability to honour any obligation, which is an argument for escrow or for retaining your own copy rather than for a stronger promise.

- **Notice period on discontinuation** A defined minimum, in writing. The distance between Gavelytics and LexisNexis Firm Manager is the distance between one day and a planned wind-down, and only a contract term makes that predictable [[3]](#ref-3).
- **Export: format, scope, and window** Specify the format, that it includes metadata and audit or verification logs, how long retrieval remains available after termination, and that it survives non-payment. Test the export once while the vendor is healthy.
- **Acquisition and insolvency** What happens to your data, your retention windows, and your negotiated terms if the vendor is acquired or enters insolvency. Consider escrow, and prefer keeping your own copy over relying on a promise from an entity that may not exist.
- **Breach notification to you, with a clock** You cannot meet your own obligation to a client until the vendor tells you. Set a defined maximum notification period to the firm, and require enough detail to identify which clients' material was involved.
- **Cooperation during your notification** Opinion 483's framework leaves the client communication with you [[1]](#ref-1) [[2]](#ref-2). Require the vendor to provide the facts you need to make it accurate, rather than a press statement.
- **Keep your own copy of anything evidentiary** Verification records, audit logs, and anything you might need to reconstruct what was done should exist somewhere the firm controls. A record held only by a vendor is a record you can lose without doing anything wrong.

## The incident plan needs a vendor branch
Most firm AI incident plans assume the incident happens inside the firm. A vendor breach inverts the sequence: the firm learns late, from someone else, with facts it cannot independently verify, and still owes its clients a communication it must make on its own judgment.
Our guide to [the law firm AI incident response plan](https://rankshieldlegal.com/blog/law-firm-ai-incident-response-plan) covers the internal case. The vendor case differs in three ways worth writing into the plan explicitly.
First, discovery is external and delayed. The firm finds out when the vendor decides to say so, which may be well after the fact and may arrive as a general customer notice rather than a specific account finding. The first task is usually establishing whether your data was in scope at all, and the vendor is the only source.
Second, the facts are someone else's. A firm investigating its own incident can look. A firm receiving a vendor notification is dependent on the vendor's characterization, which is being drafted with the vendor's own liability in view. That is a reason to have contractual detail obligations, and a reason to be careful about repeating a vendor's framing to a client as though the firm had verified it.
Third, the notification duty is still the firm's. The client's relationship is with the lawyer. On the Opinion 483 framework, the obligation to communicate with a current client about a breach affecting their confidential information belongs to the firm regardless of whose system failed [[1]](#ref-1) [[2]](#ref-2).
Naming the vendor branch in the plan costs nothing and changes the first hour. Who contacts the vendor, who decides scope, who drafts the client communication, and who decides whether the vendor's account is sufficient to rely on are all questions better answered before a notice arrives on a Friday afternoon.

## What a firm should actually do this quarter
Four things, none of which require a vendor's cooperation: inventory which vendors hold client material, test one export, add the vendor branch to the incident plan, and put information handling and retention into the engagement letter, which is where Opinion 483's committee pointed for the former-client question [[2]](#ref-2).
The recommendations in this article are unusually cheap, which is the main argument for doing them now rather than after a notification.
Start with the inventory, because most firms cannot currently answer the question. Which vendors hold client confidential material, what categories, for which clients, and under what retention. That single document is the prerequisite for every other step, and it is the thing a firm most wishes it had on the day a vendor notice arrives.
Then test one export. Not read the clause, perform the export, on a real matter, and look at what comes out. This is the step that reliably surprises people, and it is far better to be surprised while the vendor is healthy and answering support tickets.
Add the vendor branch to the incident plan, and put the engagement-letter language in place. On the former-client question the committee's own suggestion was agreements with clients about information handling and record-retention schedules, which is to say the answer is contractual rather than ethical [[2]](#ref-2). That is within the firm's control and does not require anyone's permission.
None of this makes a vendor failure less likely. It changes what the failure costs, which is the only variable a firm actually holds.

Test yourself
## Test yourself on vendor failure
Five questions on what happens when the third party holding your client's material fails.

- 1 Your vendor is breached. Does thorough prior diligence reduce your notification duty? Yes, reasonable security is a defense No, the duty is independent of your pre-breach efforts Only if you hold a current SOC 2 **Answer:** No, the duty is independent of your pre-breach efforts On the IAPP's reading of Opinion 483, post-breach notification obligations are independent of a reasonableness assessment of the lawyer's efforts to avoid the breach. Diligence is evidence of supervision, not insurance against the disclosure duty.
- 2 Does Opinion 483 require notifying former clients? Yes, current and former alike No, the committee declined absent a black letter provision Only where the matter is under 7 years old **Answer:** No, the committee declined absent a black letter provision This is frequently reported the wrong way. The committee was unwilling to require notice to a former client absent a black letter rule, pointing instead to Rule 1.16(d) and to agreements on information handling and retention. State breach statutes still apply independently.
- 3 How much notice did Gavelytics give before shutting down? Ninety days One day Six months **Answer:** One day It closed on June 30, 2022 with one day's notice to customers and employees; its platform and data were acquired roughly six months later. LexisNexis Firm Manager, by contrast, ran an orderly wind-down planned in advance.
- 4 Why is an acquisition easy to miss? Vendors are not required to disclose it Nothing visibly breaks while terms, retention and data location can all change It voids your SOC 2 automatically **Answer:** Nothing visibly breaks while terms, retention and data location can all change The login still works and the product continues, so a firm that verified terms at signing and never revisited them has verified a state of affairs that may no longer hold. Treat acquisition as its own trigger event, not a matter for the next annual review.
- 5 Which contract term is usually weakest and matters most? Uptime SLA The export term Governing law **Answer:** The export term "You can export your data" commits to little. Specify format, whether metadata and audit logs are included, how long retrieval survives termination and non-payment, then test it once while the vendor is healthy. A CSV of document titles is technically an export.
Honest self-check. There is no sign-up, and nothing is stored.

Questions answered
## Straight answers to the common questions
The questions readers ask about this topic, answered directly. **No forms, no sales pitch.**

JAMIE KLONCZ · SEO AGENCY NAPLES ************** ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

← PREV NEXT → [REQUEST ACCESS →](https://rankshieldlegal.com/contact/)

- **If our AI vendor is breached, do we have to tell our clients?** On the framework of ABA Formal Opinion 483, an obligation exists to communicate with current clients about a data breach, and that framework reaches breaches occurring at or through a third-party service provider, with vendor oversight running through Rule 5.3. The trigger is generally that client interests have a reasonable possibility of being negatively impacted, including where confidential information has been misappropriated, destroyed or compromised, or where the lawyer's ability to provide legal services is substantially impaired. The vendor notifying the public, or notifying you, does not discharge your communication to your own client, because the client's relationship is with the lawyer rather than the vendor. Opinion 483 is an ABA ethics opinion rather than binding law and jurisdictions vary; state breach-notification statutes also apply independently on their own triggers. Confirm your obligations with counsel.
- **Does having done thorough vendor diligence reduce the obligation?** No. This is the holding that most surprises well-governed firms. On the IAPP's reading of Opinion 483, a lawyer's post-breach notification obligations are independent of any assessment of how reasonable the lawyer's pre-breach efforts were. Choosing a well-audited vendor, reading the SOC 2, and negotiating good terms do not reduce the duty to tell the client when that vendor is compromised anyway. What diligence does affect is everything downstream: whether you can explain what happened, whether contractual remedies exist, whether the vendor must help, and whether the firm appears to have been paying attention. Those matter, but they are not the duty. It is worth noting the structural parallel with Johnson v. Dunn on the litigation side, where a court treated a firm's existing AI policies as aggravating rather than mitigating.
- **Do we have to notify former clients?** Opinion 483 declines to impose that as an ethical duty, and this is frequently reported incorrectly. The committee stated it was unwilling to require notice to a former client in the absence of a black letter provision requiring it, reasoning that the Model Rules contain no such provision. It pointed instead to Rule 1.16(d), which concerns obligations on termination of a representation, and encouraged firms to reach agreements with clients about how information will be handled and to adopt record-retention schedules. Two things follow. A firm holding years of former-client material in a vendor system has less ethical clarity than it likely assumes. And the committee's own suggestion locates the answer in the engagement letter and retention schedule rather than in an ethics opinion, which is a document the firm can change now. Separately, state breach-notification statutes apply to personal information regardless of the Model Rules position.
- **What happens to our data if the vendor shuts down?** Whatever the contract says, and if it says nothing, whatever the vendor's remaining resources and goodwill allow. The range is real and documented. Gavelytics, a litigation analytics company, shut down on June 30, 2022 with one day's notice to customers and employees; its platform and data were acquired by another company roughly six months later, entirely outside customers' control in the interim. LexisNexis Firm Manager, by contrast, discontinued sales in January 2017 and closed on October 31, 2017 with an orderly wind-down planned in advance. ROSS Intelligence shut down in December 2020 after litigation left it unable to secure financing, and Atrium closed in 2020 having raised $75 million. The variable is not the vendor's decency but whether any term obliged them to give notice, provide an export, or maintain access during a wind-down.
- **Why does an acquisition matter if the product keeps working?** Because nothing visible breaks, which is exactly why it goes unexamined. The login still works and the product continues, while the terms, the retention schedule, the sub-processor list, the data location, and the security posture can all change under a new owner. A firm that verified those things at signing and never revisited them has verified a state of affairs that may no longer exist. The practical protection is twofold: a contractual provision addressing what happens to your data, retention windows, and negotiated terms on acquisition, and a scheduled annual re-check of the artifacts, since an audit report covers a defined window and asserts nothing about the period after it. Acquisition is also worth treating as a trigger event in its own right rather than waiting for the next annual review.
- **What single contract term matters most?** The export term, and it is usually the weakest. "You can export your data" commits to very little on its own. Specify the format, whether the export includes metadata and audit or verification logs rather than just documents, how long retrieval remains available after termination, and whether it survives an account lapsing for non-payment. Then test it once while the vendor is healthy and answering support tickets, on a real matter, and look at what actually comes out. That step reliably surprises people, and a CSV of document titles is technically an export. Close behind it are the insolvency and acquisition provisions, which matter most in precisely the scenarios where a distressed company has the least capacity to honour any promise, which is an argument for escrow or for keeping your own copy rather than for stronger contractual language.
- **How is a vendor incident different from our own?** Three ways, all of which belong in the incident plan explicitly. Discovery is external and delayed: you find out when the vendor decides to say so, often as a general customer notice rather than a specific account finding, so the first task is establishing whether your data was in scope at all. The facts are someone else's: a firm investigating its own incident can look, while a firm receiving a vendor notification depends on a characterization drafted with the vendor's liability in view, which is a reason to have contractual detail obligations and to be careful about repeating a vendor's framing to a client as though you had verified it. And the notification duty is still yours, because the client's relationship is with the lawyer regardless of whose system failed. Decide in advance who contacts the vendor, who decides scope, who drafts the client communication, and who judges whether the vendor's account can be relied on.

## References

- American Bar Association, Standing Committee on Ethics and Professional Responsibility. Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack. October 2018. [https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-op-483.pdf](https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-op-483.pdf)
- International Association of Privacy Professionals. American Bar Association issues ethics opinion on client-data breaches (analysis of Formal Opinion 483). 2018. [https://iapp.org/news/a/american-bar-association-issues-ethics-opinion-on-client-data-breaches](https://iapp.org/news/a/american-bar-association-issues-ethics-opinion-on-client-data-breaches)
- LawSites (Robert Ambrogi). The Five Most Momentous Legal Tech Fails. April 2024. [https://www.lawnext.com/2024/04/the-five-most-momentous-legal-tech-fails.html](https://www.lawnext.com/2024/04/the-five-most-momentous-legal-tech-fails.html)

Written by
## [Jamie Kloncz](https://rankshieldlegal.com/about/)
Founder, RankShield
Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.
[More about Jamie →](https://rankshieldlegal.com/about/)

Try it · Free
## Check a citation against live case-law
Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.
[Try the citation checker](https://rankshieldlegal.com/ai-legal-citation-checker/)

Keep reading
## Related guides
[Firm Security How to Read a SOC 2 Report for a Legal AI Tool Read guide →](https://rankshieldlegal.com/blog/read-soc-2-report-legal-ai-tool/)[Firm Security The Law Firm AI Incident Response Plan Your Cyber Insurer Now Expects Read guide →](https://rankshieldlegal.com/blog/law-firm-ai-incident-response-plan/)[Firm Security The Legal AI RFP: Security and Verification Requirements Every Request for Proposal Needs Read guide →](https://rankshieldlegal.com/blog/legal-ai-rfp-security-requirements/)
