AI for law firms · Guide
Private AI vs ChatGPT for law firms: a fair comparison
Private AI vs ChatGPT for law firms is rarely an either-or choice. ChatGPT Business and Enterprise suit general drafting and research, under business terms that exclude training by default. A private assistant suits client material and precedent questions, where the firm needs control over where data is processed and who sees what. Many firms will use both.
- By
- Peter
- Published
- Last reviewed
- Reading time
- 7 min read
What exactly are we comparing?
This guide compares ChatGPT’s business plans with a private assistant built over the firm’s own documents. Personal ChatGPT plans are left out: Australian legal regulators have said public chatbots are not a safe place for confidential or privileged client information, and OpenAI may use content from personal plans to improve its models unless the user opts out (OpenAI). Our guide to whether AI is safe for law firms covers that guidance.
The three options, as at September 2026:
- ChatGPT Business. A self-serve workspace priced per user per month, with Standard and Premium seats, single sign-on and admin controls.
- ChatGPT Enterprise. Sold through OpenAI’s sales team, adding SCIM user provisioning, role-based access controls and data residency.
- A private assistant. An AI model deployed in a cloud region the firm chooses, connected to a curated set of its documents through retrieval-augmented generation, so answers come from, and cite, the firm’s own precedents.
How do ChatGPT Business, ChatGPT Enterprise and a private assistant compare?
ChatGPT is easier to start and does more out of the box, while a private assistant gives more control over location, scope and permissions. Neither is automatically the safer choice: each is only as good as its configuration. The table sets out the detail.
| ChatGPT Business | ChatGPT Enterprise | Private assistant over your documents | |
|---|---|---|---|
| Where content is stored | A region chosen at checkout, where that option has rolled out. With a non-US region, a copy of every prompt and response is still kept in the US for a limited time for abuse monitoring | New workspaces can store conversations, files, custom GPTs and memory at rest in Australia, at no extra cost | Wherever you deploy it, such as Microsoft Azure’s Australia East region or AWS’s Sydney and Melbourne regions |
| Where the model runs | No processing-region option, so no Australian processing | No Australian option; in-region processing is offered only in the US, Europe and the UAE | Can stay in Australia with a region-bound deployment, which narrows the choice of models |
| Training on your content | Not by default | Not by default | Not by default on Azure OpenAI or Amazon Bedrock; confirm for any other provider |
| Retention | Admins set it; deleted conversations removed within 30 days, with legal and safety exceptions | Admins set it; deleted conversations removed within 30 days unless legally required | You set it; some providers keep abuse-monitoring logs unless you are approved for an exemption |
| Access control | Single sign-on and MFA; admins can view, export and delete members’ conversations | Adds SCIM provisioning and role-based access controls | Designed around your existing permissions, so people only get answers from documents they can already open |
| Grounding in precedents | File uploads, projects, custom GPTs and connected apps that respect existing permissions | As for Business, with more admin control | The core purpose: a curated precedent bank, with answers that cite the passage used |
| Cost model | Per user per month | Per user, agreed with OpenAI’s sales team | Setup fee plus monthly fee, plus model usage billed by the cloud provider |
| Effort to run | Low: settings, policy and training | Low to moderate | Higher: hosting, monitoring, document updates and model changes need an owner |
Sources: OpenAI enterprise privacy, ChatGPT Business storage, ChatGPT data residency, ChatGPT Business, Azure data privacy, Amazon Bedrock FAQs.
Where does ChatGPT do better?
ChatGPT does better on breadth, capability and effort. A business workspace gives staff OpenAI’s current models, web search, data analysis, file handling and connected apps with no build at all, and administration is a settings page rather than a hosting project. For suggesting how to structure a letter of advice, summarising a published judgment or preparing a first cut of a client newsletter, a well-configured ChatGPT Business workspace is hard to beat on value.
Its business terms are also solid. OpenAI does not train on Business or Enterprise content by default, admins control retention, and new Enterprise workspaces can store content at rest in Australia; our guide to where ChatGPT stores your data sets out each plan. Our AI Setup service configures these workspaces properly: single sign-on, retention, allowed apps, a usage policy and staff onboarding.
Where does a private assistant do better?
A private assistant does better where the firm, not the vendor, needs to decide where data is processed, which documents are in scope and who can see each answer. Those are the questions that matter most for client files and precedents.
- Processing location. A Standard deployment of Azure OpenAI processes prompts within Microsoft’s Australian geography (Microsoft Learn), and Amazon Bedrock’s Australian inference profile for Claude Sonnet 5, called from Sydney or Melbourne, keeps data within Australia (AWS). Check each model you plan to use, because not every model has an Australian option. ChatGPT has no Australian processing option.
- Scope. You choose what goes in: the current version of the firm’s retainer, costs disclosure templates and practice-group checklists, with superseded drafts left out. Staff get the firm’s answer, not the internet’s.
- Permissions. Answers can respect matter-level restrictions and information barriers, so a lawyer walled off from a matter does not get answers drawn from its documents.
- Court-restricted material. NSW Supreme Court Practice Note SC Gen 23 allows material such as subpoenaed documents into a Gen AI program only if the practitioner is satisfied it stays in a controlled environment under the supplier’s confidentiality restrictions and is excluded from model training. A private deployment makes that assessment easier to document, though the practitioner still has to make it.
What are the limits of a private assistant?
A private assistant is more work and is not automatically safer. It moves responsibility from a large vendor to the firm and whoever runs the system for it, so the limits need to be understood before the build starts.
- Model lag. Microsoft says region-bound deployment types receive new models last, with no committed date (Microsoft Learn). An Australia-only assistant may run a model a generation behind ChatGPT.
- Hallucination remains. Grounding reduces invented answers but does not remove them. Lawyers still verify.
- Document quality. If the precedent bank holds three versions of the same retainer, the assistant can cite the wrong one. Curating the collection is real work.
- Someone must run it. Monitoring, permission changes, document refreshes and model retirements need an owner every month.
- Configuration risk. A poorly secured private deployment can be worse than a well-run business subscription.
The same trade-off applies beyond law firms; our guide to a private knowledge assistant vs a shared AI tool covers it for any professional firm.
How should a law firm decide between them?
Decide by the information involved, not by the tool. Sort the tasks staff want AI for by what information each one needs, then match each category to a tool.
| Information involved | Example task | Suggested tool |
|---|---|---|
| Public material or general know-how, no client identifiers | Structuring a letter, summarising a published judgment | ChatGPT Business or Enterprise |
| Client confidential | Summarising client correspondence, a first draft of advice | ChatGPT Enterprise after a terms review, or a private assistant |
| Court-restricted or contractually local | Subpoenaed documents, material under suppression orders | A private assistant with Australian processing, or no AI |
| The firm’s own precedents | “Which retainer do we use for a fixed-fee conveyance?” | A private assistant |
Then work through five steps:
- List the ten tasks staff most want AI for, by practice group.
- Classify each task using the table above.
- Check client contracts, panel terms and insurer requirements for data-location clauses.
- Pilot the private assistant on one collection, tested against questions whose answers staff already know.
- Write the result into the firm’s AI policy, so staff know which tool is for which information.
For example, a 30-person firm with property and litigation groups might give everyone ChatGPT Business for general drafting, and give the litigation team a private assistant for discovery summaries and the property team one for its precedent bank. The decision rests on the material, and it can be revisited as vendors add Australian processing.
How does Pylon Digital approach it?
We set up both, and recommend whichever fits the information. Our Private AI & Knowledge Assistants service builds a staff assistant and an “ask our documents” assistant that stores client data in fully GDPR-compliant data centres, answers from your precedents and cites its sources. It is priced as a setup fee plus a monthly fee, both quoted in writing after the free discovery call.
This is general information, not legal advice.
