Skip to content
Oversight Newsroom

Insight · Legal AI · Vendor due diligence · Israel

Insight: 30 of 120 findings on legal AI tools have no public document — what cannot be checked remotely

Of 120 findings on AI tools for law firms, checked on 3 October 2026, 30 had no public document supporting the claim; another 39 hold only in a specific plan, region or configuration. What is missing online repeats itself: log export, an Israeli price quote, Hebrew support, a processing agreement for the specific plan. Absence of a document is not absence of capability — but it means the due diligence that section 47 of Israel Bar Resolution 60/24 and Regulation 15 require cannot be done from the website, only with the vendor.

What was checked, and what came out?

An internal market study dated 3 October 2026 collected 120 finding rows on AI tools available to Israeli law firms — vendor claims, capabilities, terms and prices — and classified each row by what was found online:

Status of the findings
StatusRows of 120
Documented51
Configuration-dependent39
Not shown30

"Independent check" is the evidence type in 32 rows: in most of them, the record is that no public document was found, not that a contradicting document was found.

What exactly is missing?

What is missing from public documents
What is missing from public documentsRows (of 30)
Log export / SIEM7
Price / quote7
Hebrew / Israeli law6
DPA / processing agreement5
Matter / client separation2
Human approval step1
Other2

The grouping into categories is a reading of the row contents, not a field in the source file. The two largest categories — logs and price — are unsurprising: global vendors publish log export only at the top enterprise plan, and prices in dollars without a local quote. The next three — Hebrew, a plan-level DPA, matter separation — are precisely what the Bar opinion asks about.

Why is "not shown" not "does not exist"?

Because the missing documents are usually the kind vendors provide in negotiation rather than on the website: a signed DPA, a current subprocessor list, log API documentation, a permissions demonstration in a trial account. All of these may exist. What the count says is that a firm cannot complete the check on its own — and that any classification of a system as "closed" under sections 10–11 and 40 must rest on a document received, not on a product page.

What do section 47 and Regulation 15 require?

Section 47 of the opinion (version of 18 September 2026) requires examining the vendor, its contractual commitments, information security, access, deletion and subprocessors — and monitoring changes (section 48). Regulation 15 of the Protection of Privacy Regulations (Data Security), as amended by Amendment 13, requires a risk assessment before engaging an external party and a written agreement defining the data, systems, processing type, term and return or destruction at the end; the Privacy Protection Authority's guide attaches a preliminary questionnaire (Annex A) and periodic oversight (Annex B). Both frameworks assume the documents will be obtained from the vendor — not found by search.

Checklist: what to ask, why, and what counts as an answer

Checklist: what to ask the vendor, why, and what counts as an answer
What to ask the vendorWhy (section)What counts as an answer
Processing agreement (DPA) for the plan purchased, not a marketing pagess. 41.4, 47 · Reg. 15(a)(2)Signed copy or final draft; plan name in the agreement body
Subprocessor list and processing regionss. 47 · Reg. 15Dated list; change-notification mechanism
No-training and no-transfer commitment — at the actual account levelss. 40.1–40.2A contract clause, not a general policy statement
Retention and deletion: periods, deletion at termination, written confirmations. 41.4 · Reg. 15(a)(2)Retention schedule; deletion procedure; deletion confirmation
Log export / SIEM connection at the plan purchasedss. 46.1, 53API or screen documentation; what is logged and for how long
Permission separation at matter level (not only user/organisation)s. 41Demonstration in a trial account; permission-model documentation
Human-approval step before an externally consequential actionss. 52–54Configuration setting; what counts as an 'external action'
Documented support for Hebrew and Israeli lawss. 19–24 (competence)Output samples; legal sources the system accesses
Price at the plan purchased, in NIS, including VAT and supports. 42.2 (fee transparency)Written quote; not a general dollar price list

The practical rule: any row answered with "yes, we have that" without a document stays "not shown". Any row answered with a document that refers to a plan other than the one purchased stays "configuration-dependent".

What to do with this in practice?

  1. Start from the plan, not the product. The same product name appears in the file under different statuses by plan and region.
  2. Ask for the nine documents before a demo. A vendor that cannot provide a plan-level DPA and a subprocessor list — a demo will not change the classification.
  3. Document the check. Section 46.1 expects documentation; Regulation 15 expects periodic oversight. A vendor that changes terms returns the row to "configuration-dependent".

Frequently asked questions

Is a vendor that does not publish a DPA on its website a problematic vendor?

Not necessarily. Many vendors provide a DPA only in negotiation. The question is not whether the document is on the website, but whether it is received, signed, and refers to the plan purchased. A vendor that does not provide it even on request — that is an answer.

Who in the firm should perform the check?

The opinion (sections 45–47) places responsibility on the firm and the lawyer responsible for the policy; Regulation 15 — on the database controller. In practice it requires a lawyer, an information-security function and whoever manages the engagement. The check can be assisted by an external adviser; the responsibility cannot.

How often is the check repeated?

Section 48 of the opinion requires monitoring of changes in terms, versions and connections; the Regulation 15 guide expects periodic oversight (Annex B). No fixed frequency is set by law; a change of plan, subprocessor or terms of use is a trigger for a repeat check.

Does the checklist replace legal advice?

No. It is a list of documents to request, not an opinion on vendor suitability. Whether the configuration passes the tests of the Bar opinion and Regulation 15 is assessed by matter, contract and specific configuration, and remains with the lawyer.