
Three Nexis products went dark on Wednesday the fifth and stayed dark into the weekend. The problem was not at LexisNexis. It sat on servers owned and run by a company LexisNexis pays, whose name you still do not know.
THE LEAD PLAY
Your Vendor Has Vendors

Nexis Diligence, Nexis Newsdesk, and the Nexis Metabase API all went offline in the middle of last week. Diligence came back first, with Newsdesk and the Metabase API restoring progressively as of Monday. LexisNexis named only those three products and has said nothing about Lexis+ or Protégé, so if legal research is the only Lexis product your firm touches, you likely had a normal week.
The company identified what it called “unusual activity on servers that are hosted and managed by a third-party vendor,” disconnected from those systems, brought in a forensics firm, and rebuilt in a new environment before turning anything back on. Todd Larsen, who runs Nexis Solutions, put it this way: “While this decision resulted in those applications going offline, it was the right step to take to ensure the integrity of our own environment and protect our customers and data while our investigation continues.”
That is the correct call, and worth saying out loud, because plenty of vendors would have left the lights on and hoped. No breach has been declared. No data has been confirmed accessed and no threat actor has been named. The vendor has not been named either.
The failure did not live on infrastructure LexisNexis owns or in code LexisNexis wrote. It lived on servers a supplier hosts and manages, one layer past the edge of the contract you signed.
Your vendor security questionnaire almost certainly stops at that edge. You ask LexisNexis about its SOC 2, its encryption, its incident response plan, its breach notification timeline. LexisNexis answers, accurately, about LexisNexis. Then it hands part of the job to somebody else, and that somebody else is the one who has the bad week.
Nexis Diligence is not a research toy. LexisNexis sells it for due diligence, adverse media screening, and know-your-customer work, which at a firm means the checks that run before a new matter opens. When it goes dark on a Wednesday, intake stops moving, and anybody who has run an intake operation knows what most of a week of that costs. It does not show up as a security incident in anyone's reporting. It shows up as a backlog.
The AI version of this problem is worse, because the stack is longer and nobody draws it for you. The legal AI tool you bought runs inference on a model somebody else trained, hosted in a cloud region somebody else operates, with a retrieval layer that may or may not be the vendor's own code. Ask most legal AI vendors to name every company that touches your data on the way to an answer and you will get a good-faith list that is shorter than the truth.
The instrument for this already exists and legal ops already knows how to read it. It is the subprocessor clause, and almost nobody checks whether theirs does anything.
The Play this week: Pull the DPA or the master agreement for your ten highest-risk AI and data vendors. Read for three things, in this order.
First, does the contract obligate the vendor to maintain a current list of subprocessors, and are you entitled to see it on request? If the answer is no, you cannot name the companies holding your data, and neither can your general counsel.
Second, does your breach notification clause trigger on an incident at a subprocessor, or only on the vendor's own systems? Most are drafted the narrow way. That is the clause that decides whether you get a phone call or find out because a product stopped loading.
Third, does your SLA count downtime caused by a subprocessor as downtime? If it carves that out, your service credits are decorative.
Where the answers come back wrong, the fix goes in at renewal and it is three sentences, not a redline war. Ask for the subprocessor list as a contractual right rather than a courtesy, and ask for notification to run on any incident affecting your data regardless of whose hardware it sat on.
SECOND CHAIR
Your notetaker does not know who is on the call

The New York City Bar issued Formal Opinion 2026-2 on August 5, extending its earlier guidance on recording client conversations to everyone else a lawyer talks to. Co-counsel, prospective clients, opposing counsel, witnesses, and the firm's own employees and agents. It reads Rules 1.1, 1.18, 3.4, 4.2, 4.3, and 8.4 together, and the holding is blunter than most ethics opinions manage: “as the default practice (that is, absent a good reason to record a conversation in a particular instance) an attorney should avoid recording conversations.”
Consent from every party, every time. No surreptitious recording, and the intention to record has to be disclosed. On witnesses, the committee warns that recordings are potentially discoverable and that preserving, transcribing, and summarizing them can “create unfavorable evidence out of context” and put work product at risk. On opposing counsel, the exposure narrows to settlement discussions and mediation, where the evidentiary privileges need special care. And competence under Rule 1.1 now includes a skill nobody lists on a resume. From the opinion: “The duty of competence includes knowing how to turn off the recording function, so that conversations are not inadvertently recorded.”
The prospective client problem is the one worth sitting with, and the opinion calls it a paradox outright. A recording proves you took only the minimum information needed to decide whether to take the matter. The same recording is what carries that information into a Rule 1.18 conflicts analysis and out to everyone the disqualification imputes to.
The read: Almost every firm notetaker policy I have seen is scoped to client meetings. Intake is where the tool is switched on by default, running on calls with people who will never become clients, and it is where 1.18 does the most damage. Scope the policy by who is on the call, not by whether it is billable.
The model providers are selling the implementation now

Harbor launched an offering called Deploy on August 10, embedding specialist teams and forward-deployed engineers inside client organizations to actually stand up legal AI. Harbor says it works with more than 80 percent of the Global 200 and close to 600 corporate law departments, supported by over 900 professionals. It did not disclose pricing.
The pitch is legal-native expertise against generalists. Rudy DeFelice, Harbor's global head of AI strategy: “Legal doesn't work like the rest of the economy... a general-purpose deployment arm... can't get inside them the way a legal-native team can. That's the gap Harbor Deploy exists to close.”
The read: The interesting sentence in that announcement is not Harbor's pitch. It is the premise Harbor puts underneath it: “OpenAI, Anthropic, and Microsoft have each launched dedicated businesses built to embed engineers inside client organizations.” Harbor has an obvious interest in you believing that, and it is also true. The company selling you the model now also sells the people who install it and the assessment that tells you what to install. When the vendor scopes the project, benchmarks the result, and books the services revenue, you have lost your independent read on whether any of it worked.
STILL WATCHING
California SB 574 went onto the Assembly Appropriations suspense file on August 5, with a hearing set for August 13. The operative language amends Code of Civil Procedure section 128.7. A paper filed in any court “shall not contain any citations that the attorney responsible for submitting the pleading has not personally read and verified, including any citation provided by generative artificial intelligence.” Read that twice. The duty runs to the signing attorney personally, and it does not depend on anybody having used AI. Fiscal bills have to clear Appropriations by August 14 and the session ends August 31.
Thomson Reuters v. ROSS Intelligence, No. 25-2153, was argued in the Third Circuit on June 11. Ten weeks, no opinion.
The Copilot for Word prompt injection. Microsoft shipped its August updates on Tuesday. Nothing in the published rundowns touches the chain Håkon Måløy disclosed. That is 160 days since he reported it and 16 since he published it.
In Cole v. Hobby Town Unlimited (C.D. Ill.), the response to Judge Darrow's show cause order came due August 7. No ruling has been reported.
The Otter.ai privacy litigation. The motion to dismiss has been under submission in the Northern District of California since May 20.
QUICK HITS
If a lawyer at your firm personally connected SharePoint to ChatGPT, that connection dies Friday. OpenAI stopped issuing individually authorized sync connections in ChatGPT Enterprise on August 10. On August 14 the existing ones are disabled and deletion of the synced data begins. Google Drive, SharePoint, GitHub, GitLab Issues, Azure Boards, Basecamp, Help Scout, Zoho Desk, Teamwork, Aha!, Zoho CRM, and Pipedrive are all named. Administrator-managed sync is unaffected, which is the whole point. Whoever files a ticket on Friday complaining that their documents disappeared is your shadow AI inventory, delivered free.
Harvey is reportedly raising again, four months after the last one. The Information reported on August 7 that the company is in talks for at least $500 million at a $15.5 billion valuation, with Lightspeed keen to lead, against more than $350 million in annualized revenue, up from $190 million in January. In March it raised $200 million at $11 billion. Talks are not a round, the revenue figures are not audited, and Harvey's own newsroom says nothing about any of it.
BigHand bought Ayora on August 4, terms undisclosed. Ayora is an AI pricing and matter cost platform, and phase one folds it into BigHand's Matter Pricing Cloud. Both founders stay, with CEO Stefan Ciesla-Grain taking over AI and data product strategy. Worth noticing what got bought. Not a drafting tool, not a research tool. Software that tells a firm what its own work costs and what to charge for it.
Two firms spent last week hiring for governance rather than tools. Akerman named Michael Adler, previously head of global data privacy and AI at Highspot, as director of AI governance and data protection inside Akerman Intelligence. Bird & Bird brought in legal transformation partner Shahin Baghaei and three colleagues from EY. Nobody announced a product.
Nobody at your firm signed a contract with the company that had the bad week. Find out its name before you need it.
See you in the next one.
