
The 30-second version: Palantir's CEO went on CNBC and bluntly described on live TV the exact trap your firm is walking into with AI. Not "AI is scary." Sharper: you can pay a fortune, get modest value back, and quietly hand a vendor the three things that make your firm your firm: your client data, your work product, and your method.
Below is the translation and the questions to ask before you sign anything else.
THE FULL BRIEF
Who is this guy, and why should a lawyer care?

If you've seen Karp on TV, your first read was probably: this man is having a nervous breakdown. Wild hair, restless hands, sentences that sprint and swerve. But there is more to it as that's not a man losing it; it's a man who doesn’t succumb to theatrics and playing it safe and just tells you the truth at speed. He holds a PhD in social theory and a law degree, and Palantir builds the software running on genuine critical infrastructure like the battlefield, intelligence, hospitals, energy. When he talks about data security, he means it in life-and-death terms, not marketing terms. His persona is the packaging and may be distracting. His argument is the reason to listen. Here is why.
Before reading, you might want to take 7ish mins to watch and listen. If you get what he is saying, then no reason to keep reading my words. If you need some guidance, read on after.
Ok allow me to call out a few things:
Each one is his quote, then plain English, then what it means for your firm.
1. "It's safe because it doesn't touch your underlying data… it doesn't transfer your IP."
What he said (1:36):
"It takes a large language model, it makes it safe and useful and precise. Safe because it doesn't touch your underlying data… safe because it prevents the large language model from caching your data and replicating your business… safe because it doesn't transfer your IP."
Translation: He talking about what Palantir does. And what every enterpsie user of AI should be aware of. A raw AI model is horsepower with no steering wheel. To make it safe in a serious setting you need an application layer which is software that sits between the model and your data, enforcing rules so the model reasons over your information without swallowing it. Karp names three distinct failures a pure deployment creates: the model touches your data, it caches and can reproduce your data, and it absorbs your method; the actual know-how behind what you do.
Why it matters: A firm's crown jewels are exactly those three things: confidential client data, the work product built on it, and the firm's method (how you structure a deal, argue a motion, price a matter). Drop a brief into a chatbot and you may hand over all three at once. That gives you a clean vendor checklist: does it touch our data, retain our data, or learn our methods? Three yeses is malpractice waiting to happen. Now you may think that your license protects you from all three. Perhaps.
Watch that third leg. It's the sneaky one. As your lawyers build reusable prompts, skills, and workflows on a vendor's platform, the system may never ingest a single client document and still absorb your logic: the sequence of moves and the judgment calls that make your work yours. "We don't train on your data" and "we don't learn your methods" are two different promises. Vendors make the first one loudly. Make them answer the second.
2. "They want to know they own the means of production."
What he said (3:53):
"They want to know they own the means of production. It's not being transferred to someone else. They're not interested in some fake deploy code that… transfers the alpha to a third party and the jig is up."
Translation: Karp says that many CEO’s, behind closed doors want to own the compute, the model, the data, and their "alpha": their proprietary competitive edge. What they fear is a slick deployment that looks like it runs in-house but quietly pipes their advantage out the back door. Owning the "weights" which are the internal settings that define a customized model's behavior is how you keep control instead of renting it back. So “we do not train on your data is fundamentally different from we tell you how the model operates and “thinks.”
Why it matters: For a firm, "alpha" is your reputation, relationships, and accumulated judgment; basically the reasons a client picks you. If your AI stack is built so that edge accrues to a vendor's model instead of to your firm, you're financing your own commoditization. Ownership and control of the stack isn't an IT preference. It's a survival question. Put another way, your vendor may not use or train on your ingredients, but they may be learning your method that they will look to productized later. See Claude Legal Skills and OpenAI’s recently released finance agent.
3. "Are we really going to outsource the battlefield to the consensus view in Silicon Valley?"
What he said (6:14):
"Do they get to control the weights to do it, or do you get to control the weights? Are we really going to outsource the battlefield of this country to the consensus view in Silicon Valley? That is effing insane."
Translation: Weights are the internal settings that define a model's behavior. Control the weights and you control what the system does and how it decides. Karp's alarm: if a handful of labs control the weights, they quietly control the judgment baked into every system running on top of them. Handing that off means outsourcing your most consequential decisions to a small, unaccountable group's "consensus view," to values and risk tolerances you never chose and can't see.
Why it matters: This is the one that should stop a managing partner cold, because it isn't about data or dollars. It's about defensibility. A regular user asks a model for something and moves on. A lawyer can't. You carry a heightened obligation to explain and stand behind what the tool did and how you used it, whether to a client, a partner, a court, a regulator, or a malpractice carrier. And you cannot defend what you do not understand. So Karp's question, sized for a firm, isn't only "do we control the weights?" It's "do we understand how this system reaches its output well enough to put our name on it?" If the reasoning is an opaque box you can't inspect or explain, you haven't adopted a tool. You've outsourced judgment you're still on the hook for. You may not need to own the weights. You do need to understand the system well enough to defend it. That's the line between using AI and being unable to account for your own work product.
"But Harvey and Legora already do this." Maybe. Read the sentence they don't finish.
The moment you raise any of this, a vendor reassures you fast: "We don't train on your data. It's isolated, encrypted, SOC 2, safe and secure." Every one of those statements can be completely true, and to their credit, legal specific tools have met a lot of this head on. Harvey, for one, states it doesn't train on customer data and requires the same of its model providers, and offers zero data retention, matter level isolation, and SOC 2, ISO 27001, GDPR, and CCPA compliance. That's real, and it's why these tools have earned genuine traction. Credit where due.
The point isn't that the reassurances are false. It's that they're bounded, and the boundary is where your attention belongs. "We don't train on your data" answers caching. It does not answer who controls the weights, whether your prompts and methods shape the system in the moment, or whether the vendor's roadmap gets smarter by watching how thousands of firms work. "It's in a secure vault" protects the documents, not necessarily the method. And no policy erases custody risk: anything that leaves your premises still carries breach, subpoena, and terms change exposure. A promise about use is not a guarantee about custody.
Here's what makes it urgent rather than academic: it's changing under your feet. Those assurances were written for a world of drafting and retrieval. As these platforms turn on agentic capabilities, tools that don't just draft but act, opening your systems and taking steps across your matters, your DMS, and your billing, the surface area explodes, and the security page you read at signup was written for the previous product. The true things they tell you aren't the same as the things you need to know, and the gap widens every time they ship a new feature. Keep asking. Get it in writing. Paper it again at every renewal.
One honest caveat: Karp has skin in the game. Palantir sells the exact solution his critique points toward, so read him as an interested party, not a referee. But you can discount the salesman and still keep the questions. The questions are legitimate.
What to actually do this week
Start by reframing the whole thing. This is not an "AI governance" problem, or a training problem, or a workflow problem. Those framings are exactly how firms sleepwalk into the trap. This is a defensibility and explainability problem, and that is a different discipline with a different standard.
Here is why it's urgent and not theoretical. Courts, jurisdictions, and regulatory bodies are getting savvy fast. They already understand that a lot of lawyers are quietly outsourcing their judgment, embedding it into a workflow, and losing sight of the hundreds of small decisions a lawyer makes in a given context to reach an output. The output may look sound. But when it was generated by AI and you cannot reconstruct how you got there or why each call was right, "it looked sound" is not a defense. That gap is where a great many lawyers and firms are about to find themselves exposed. This is the whole point Karp is making: there is the easy way, and there is the right way, and they are not the same path.
So before your firm's next AI decision, ask better questions:
1. The data test. For every tool in use or under review: does it touch our client data, retain it, or learn our methods? Get answers in writing.
2. The trust questions. Who owns the data? Where is it cached? Are our prompts secure? Is anything transferred to the vendor? A dodge is your answer.
3. The defensibility question. Can we explain and stand behind what this tool did, whether to a client, a court, or our carrier? You can't defend what you can't understand, and you can't outsource what you can't defend.
4. The renewal rule. Ask all of the above again the moment a vendor ships agentic features. The assurance you accepted was written for the product you bought, not the one you're now using.
Print those four. Bring them to your technology committee. But bring the reframe first, because the questions only matter once everyone in the room agrees on what you are actually protecting. It was never the workflow. It was the judgment.
Print those five. Bring them to your technology committee. That's the whole assignment.
Happy Independence Day to my fellow Americans.
Fitting time to ask who really owns what.
Talk soon again, Josh

To read previous editions, click here.
Was this newsletter useful? Help me to improve!
Who is the author, Josh Kubicki?
Josh Kubicki teaches AI and the business of law at Indiana University Maurer School of Law and has trained over 3,000 lawyers on generative AI. He is the author of Brainyacts, read by nearly 10,000 legal professionals worldwide.
AI training, courses, and resources: kubicki.ai
Strategic advisory for firm leadership: joshkubicki.com
DISCLAIMER: None of this is legal advice. This newsletter is strictly educational and is not legal advice or a solicitation to buy or sell any assets or to make any legal decisions. Please /be careful and do your own research.
