By David Levy
California just sent a bill to Governor Gavin Newsom’s desk and it’s worth paying attention to.
Senate Bill 574 isn’t a law yet. But once enacted, it will set requirements for attorneys using generative AI, including restrictions on entering confidential or nonpublic information into AI systems.
With AI playing an increasingly important role in how businesses operate, this rule makes sense. But it also points to something bigger than AI.
It raises a broader question about how law firms understand and control the sensitive information moving through their operations, especially as technology gets more deeply embedded in their workflows.
And what if that information is shared with staff working on the other side of the world?
Where Law Firm Security Actually Stands
Law firms regularly handle some of their clients’ most sensitive information, including confidential communications, case files, financial details, and personal information. More of it is managed across cloud platforms, digital tools, and connected workflows every year, so firms need to be clear about how that information is protected, who can access it, and what controls are in place.
The ABA’s 2024 Legal Technology Survey found that only 60% of law firms had formal cybersecurity policies established. That leaves a significant share of firms whose data is potentially at risk.
This gap matters because formal policies give firms a consistent framework for handling sensitive information and defining security responsibilities. Without that framework, security requirements can be harder to enforce consistently across teams.
AI Is Just One Part of the Information Security Conversation
California is the first state to pass legislation specifically regulating how attorneys use generative AI. Other states have addressed the same concerns through ethics opinions and professional guidance.
The approaches differ, but the underlying concern is the same. They all trace back to protecting confidential client information when attorneys use AI. But that’s only one part of the security picture.
The same questions apply whenever sensitive information gets handled, whether by a person, a digital system, or an outside partner. Who can access it? How do they access it? What safeguards actually stand behind it? Who’s responsible for keeping those security measures in place?
Those controls matter whether the person handling the information works in the firm’s office, from a home office in another state, or from another country.
The Security Question for Virtual Staffing
I see this concern comes up regularly with clients considering virtual staffing. Many clients I’ve talked to ask how they can be confident that highly confidential legal information remains secure when their people are working from different locations.
It’s a reasonable question. Location tends to dominate conversations about hiring global teams. But I think the real conversation should be centered on the controls surrounding the information someone is authorized to access, rather than where they happen to work.
Think of it this way: someone working inside a law firm’s office can have excessive permissions, use an unapproved application, or retain access they no longer need. A person working from another location can face the same risks but can also operate within a controlled environment with defined permissions, approved systems, security training, active monitoring, and clear procedures.
Location tells you something about the operating environment, but it doesn’t tell you, by itself, how secure the information actually is.
Evaluate the Controls More Than the Location
For firms considering a virtual team, security due diligence should begin with the same questions they would ask of any person or organization handling sensitive information.
What can they access? Access should match the work the person is responsible for. A support professional who needs one system or workflow shouldn’t automatically have access to everything else the firm uses.
How do they access it? Firms should understand the systems, authentication methods, devices, and applications involved, along with which tools are approved for handling firm and client information.
How are they prepared to handle sensitive information? Technology controls are only part of the equation. People need to understand confidentiality expectations, acceptable technology use, and the procedures they are expected to follow.
What happens when circumstances change? Roles change, responsibilities expand, and people leave. Firms should understand how permissions are reviewed, updated, and removed throughout the relationship.
What evidence can the provider offer? Instead of accepting a general assurance that a provider takes security seriously, firms should ask about certifications, policies, infrastructure, access controls, training, monitoring, and incident response.
These questions give firms something real to evaluate. They pull the conversation away from concerns about where a team sits and put the focus back where it belongs: on the actual controls governing how sensitive information gets handled. They also help ensure that security expectations are built into the relationship from the start, rather than addressed only after a team has been established.
How We Approach Security
At Cloudstaff, security is built into how we support dedicated teams. Our environment includes PCI-DSS, ISO 27001:2022, and ISO 9001:2015 certifications, GDPR and HIPAA compliance, managed devices, access controls, and continuous monitoring, among other safeguards.
Certifications show that a company meets recognized standards, while its security mechanisms show how those standards are implemented in daily operations.
The combination of people and technology matters. Technology creates the environment and the controls, while the people working inside that environment need to understand their responsibilities and follow the processes built around it. Both have to work together for these security measures to be effective.
A Better Way to Think About Virtual Staffing for Law Firms
Generative AI is raising new questions about how legal professionals handle information, and SB 574 addresses specific parts of that for attorneys and other professionals covered by its provisions.
For firm leaders, there’s a broader operational question that goes well beyond AI. Are we evaluating security based on where people work, or based on the controls that actually govern how they work?
Security isn’t determined by geography alone, but by the controls you put around your information.
About the Author
David Levy is the Vertical Lead for Legal & Law Firms, North America at Cloudstaff, where he helps U.S. law firms build remote teams that extend their capacity for intake, document review, contract handling, legal research, and paralegal support. He brings two decades of experience across legal operations, outsourcing, and client partnerships, including as a founding team member at Accedo Technologies and in an operations role at a U.S. law firm. David works directly with firms looking to scale their teams without compromising accuracy or client trust.
How much trust could your firm build with a team backed by legal-grade security?
Visit Virtual Staffing for Legal to find out.

