Blogs
The Governance Gap: Why Connecting to AI Isn't the Same as Owning It

In the span of a single week, three major legal technology vendors announced new AI partnerships, each promising to bring the power of generative AI to litigation, investigations, and compliance workflows. The energy is real. The capability is genuine. And the questions these announcements leave unanswered are the ones that matter most.
Building a connection to a third-party AI system is not the same as owning, integrating, or governing that AI. In legal and investigative contexts, where evidence integrity, privilege, and defensibility aren't optional, that distinction is important.
The Taxonomy That Matters
Every legal and investigative organisation should be asking a deceptively simple question before adopting any AI-powered tool: Who actually owns the model your evidence depends on, and what happens when that changes?
The answer typically falls into one of three categories, and they are not equivalent:
Owned AI: Technology a vendor has built, trained, and maintains outright. The vendor controls the model architecture, the training data, the update cycle, and the performance guarantees. When something goes wrong, there's a single point of accountability.
Responsibly Integrated AI: Open-source or third-party models that a vendor has deliberately selected, validated against bias and performance standards, embedded into their platform, and fully supports. The vendor stands behind these models as if they were their own, because operationally, they are.
Connected AI (Framework): Access to external AI platforms via API connections or partnerships. Genuinely useful. Gives customers fast access to leading-edge capability. But architecturally and contractually different from the first two categories.
Most of this week's announcements fall into that third category. That's not a criticism, merely a classification. And classifications matter when your workflows depend on them.
The Questions Worth Asking
When AI is accessed via a third-party connection rather than owned or properly integrated, organizations should understand:
1. Governance and continuity: What oversight exists over that model? Who decides when it's updated, retrained, or deprecated? And what happens to your workflows if the upstream provider changes pricing, availability, or data-handling terms?
2. Audit trail: Can you demonstrate exactly what model was used, what prompt was submitted, what response was received, and when? Can you reproduce that result six months from now during a regulatory inquiry or at trial?
3. Data sovereignty and regulatory accountability: Where does your evidence go when it's sent to a third-party model? Can you guarantee that privileged material isn't used to train someone else's model? Under frameworks like the EU AI Act, the deployer bears specific obligations for high-risk AI systems. When AI is accessed via third-party connections, the question of who bears the compliance burden becomes legally consequential.
These aren't hypothetical concerns. They're the questions that general counsel, CISOs, and compliance officers are already asking.
Why This Matters More Here
Litigation evidence, privileged material, and sensitive investigations carry a different set of risks than general business use cases. A marketing team experimenting with AI-generated content operates quite differently than a legal team using AI to review documents that may determine the outcome of a billion-dollar case or a criminal prosecution.
In these contexts, governance and control serve as the foundation of true defensibility. Every AI-assisted decision in a legal workflow must be explainable, reproducible, and auditable, both today, and years from now when that decision is challenged.
A Responsible Framework, By Design
At Nuix, we've spent considerable time thinking about all of this, not as a marketing exercise, but as a core principle. Our approach is built around distinct, deliberate categories:
Technology we own outright: Our proprietary Cognitive AI core, combining machine learning, natural language processing, private language models, and patented mathematical optimizations, has been continuously developed for over 13 years. We built it. We train it. We control it. It delivers deterministic, explainable, auditable results.
Technology we responsibly integrate and fully support: The AI models we use for features like Semantic Search (text and image search), transcription, face recognition are deliberately selected, rigorously validated against our Responsible AI standards, embedded into our platform, and run entirely within customer environments. No data leaves the customer's environment.
A governed framework for connecting to leading external AI platforms: Our BYO-AI framework supports connections to OpenAI, Anthropic Claude, Google Gemini, AWS Bedrock, and Azure AI Services, with complete audit trails logging every interaction (model name, timestamp, prompt, response).
On-premises and air-gapped deployment: For organizations handling the most sensitive matters, defense, law enforcement, national security, and classified investigations, we offer something that cloud-only connector architectures simply cannot: the ability to run AI entirely on-premises. Customers can deploy local models via Ollama or VLLM in fully air-gapped configurations where zero data leaves the network. No API calls to external providers. No data traversing third-party infrastructure. Complete operational sovereignty. This isn't a roadmap item. It's shipping today.
The point is not that third-party AI connections are bad. We offer them ourselves. The point is that customers deserve clarity on which category they're getting, flexible options that meet their unique requirements, and accountability across the stack.
The Governance Difference
What underpins all of this is governance as an operational reality. Our AI Governance and Responsible Use Policy is informed by the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, and the Australian AI Ethics Framework. It's adopted by our Board of Directors, with standing oversight through the Audit & Risk Committee. It's reviewed at minimum annually and independently assessed under our ISO/IEC 42001 certification program.
This isn't a slide deck. It's an integrated management system where AI governance operates within our Information Security and AI Management Systems under a joint committee, with one risk method, one incident process, one audit cycle.
Every AI system we ship is registered, classified by impact level, and approved through escalating authority that culminates at Board level for the highest-impact capabilities. Impact, risk, conformity, and bias assessments are completed before deployment and again upon material change. When something goes wrong, formal AI incident management activates through trained personnel and defined channels, with escalation to the Board and disclosure obligations to regulators and customers as required.
Connecting to a leading AI platform is a valid and useful starting point. Many organizations will benefit from it. But the organizations handling the most sensitive matters need to go further: Who governs the model? Who audits the interaction? Who's accountable when something changes? We built our framework to answer those questions before they're asked.
The Bigger Point
The market conversation has become overly fixated on generative AI, as if the only question that matters is which large language model you're connected to. A more thoughtful view is that different problems call for different AI approaches.
Some problems demand owned, deterministic AI that delivers consistent, auditable results at scale. Some benefit from responsibly integrated models that extend capability without sacrificing control. And some are genuinely well-served by connections to leading external platforms, provided the governance framework exists to make that connection defensible.
The organisations that navigate this moment successfully won't be defined by which partnerships they've announced. They'll be the ones that can answer: Do I understand what I'm getting? Do I know who's accountable? Can I audit every step? And can I defend this decision when it matters most?
Those are the questions worth asking. And the answers should be clear before you entrust your most sensitive matters to any AI-powered workflow.
Christopher Stephenson is Head of AI Strategy & Governance at Nuix, where he leads the company's Responsible AI program and holistic AI strategy.