By Steve Whiter, Appurity
When did your firm last audit what its lawyers are doing in the browser? Which AI tools they’re accessing, what data they’re uploading, what legacy applications are running entirely outside your security controls?
Most firms have invested seriously in the right places: authentication hardening, email and mobile phishing protection, device management, BYOD profiles, staff awareness training. What few have applied the same rigour to is the environment where almost all of that investment can be undone in thirty seconds: the browser. It is where legal work happens now. And yet browser-level security – DLP controls, AI governance, access policies enforced at the session – often gets missed.
The shadow AI problem is already inside your firm
Shadow AI is not primarily a behavioural problem. It is an architectural one. Across every professional services sector, the path of least resistance when approved tools are unavailable or slower than a public alternative is a personal AI account. Legal is not an exception. Thomson Reuters’ 2025 Generative AI in Professional Services report found that only 30% of law firms currently have a specific AI policy in place. The firms without one are not necessarily uninformed about the risk, they are simply without the technical infrastructure to enforce anything, even if a policy existed.
When client facts, strategy, identifiers, or personally identifiable information find their way into prompts for public AI models, this can result in a confidentiality violation. Many providers retain and use prompts for model training and route traffic through third countries. This is an active compliance exposure every time a lawyer opens a browser tab without governance in place.
Without browser-level controls, a law firm has no way to prevent this from happening, no way to know when it has happened, and no audit trail to demonstrate to the ICO or the SRA that appropriate measures were in place. Nearly half of people using generative AI platforms are doing so through personal accounts their organisations are not overseeing.
The legacy application blind spot
There’s a second, less-discussed vulnerability in law firms’ endpoint architectures. It sits directly alongside the AI governance problem and compounds it.
Most firms remain significantly dependent on legacy applications. Matter management systems, time recording platforms, specialist compliance tools, and bespoke case management software are frequently client-server applications built for a different era of IT.
The standard modernisation pathway to maintain these apps is virtual desktop infrastructure – delivering those applications to remote users through a virtualised environment. VDI solves a real problem, but it also creates one.
Most firms running VDI have invested in session-level security within that environment, but it often does not address the broader browser session running alongside it. A lawyer accessing a matter management system via a virtual desktop while simultaneously using a public AI tool in their regular browser is operating across two separate security contexts. One is governed. The other is not. And the data moving between them – copied from a file, pasted into an AI prompt – falls into neither firm’s audit trail.
Solving the browser security challenge
Working with law firms across the UK, we see that the browser is increasingly where legal work happens, and it is often the least governed part of most firms’ security architecture. It is precisely why we recommend Chrome Enterprise Premium to legal sector clients. Google’s enterprise security platform has a fundamentally different architecture to most of the tools firms are currently using: rather than working outward from the network or the device, it works from within the browser session itself; the environment where the actual risk now lives.
Chrome Enterprise Premium operates at the browser level, within the Chrome session itself. Granular DLP controls prevent uploads to unsanctioned AI tools, restrict copy and paste of sensitive content, apply watermarks to confidential documents, and enforce print controls across every website and SaaS application a user accesses through their managed Chrome profile, regardless of whether they are on a corporate device, working remotely, or connecting from an unmanaged machine. The controls travel with the browser, not with the device.
The shadow AI problem also has a specific technical answer within this architecture. Security insights provide visibility into which AI tools are being accessed across the firm’s browser estate, flag data transfers to unsanctioned platforms, and, critically, give security teams the ability to act on that intelligence rather than simply observe it. With Chrome Enterprise Premium, firms can sanction specific tools, block others, configure policy messages that explain to users precisely why an action has been restricted, and maintain the evidence locker that regulators will look for if a breach is investigated.
Cameyo by Google addresses the legacy application problem at the architectural level. Rather than streaming a full virtual desktop — which, as discussed, operates as a separate security context — Cameyo delivers individual Windows and Linux applications directly into the managed Chrome browser as progressive web apps or in-browser sessions. Because those applications now run within Chrome’s security perimeter rather than alongside it, Chrome Enterprise Premium’s DLP controls, URL filtering, and access governance apply to the data moving through them. Those legacy applications, which previously lived outside any browser security context, come under the same governance framework as every other application the user has open. The fragmentation between the governed browser session and the ungoverned virtual desktop is directly addressed here.
The security case for browser-level governance is clear. What is less often recognised is that the same architecture – moving legacy applications into a managed browser environment – also eliminates the infrastructure overhead that makes VDI so expensive to maintain. The CISO and the IT director rarely want the same thing from the same solution. Here, they do.
Appurity, in partnership with Google, is offering eligible UK law firms with 200 or more endpoints the opportunity to run a fully funded Proof of Value in their own environment – with their own applications, their own users – at zero or close to zero cost.









