Lawgistics
How Lawgistics found 1,000 hours of unapproved AI use in its clients' browsers
A law-firm-focused MSP turned browser-layer visibility into hard numbers on shadow AI and unapproved file sharing, then built and deployed a full policy set through Intune in 45 minutes.
A single user at one client firm was logging 112 hours a month on ChatGPT, a platform Lawgistics had not approved.
Visible across the client environments Lawgistics manages, turning an abstract AI risk into a specific number.
Configured once and rolled out to clients through the Intune tenant Lawgistics already ran across all clients.
"Atakama's platform is easy to roll out and manage. The browser security insights are both useful and terrifying."

About
Lawgistics is a managed service provider focused on law firms that range from 40 to 400 endpoints each. Sean Anderson, the firm's Technical Innovation Manager, owns new technology evaluation: testing platforms, building the policies that govern them, and deciding what reaches client environments.
That role has shifted almost entirely toward AI. Anderson's work now centers on configuring, restricting, and testing AI tooling so that law firm clients can use the tools without putting confidential data at risk. Atakama joined the Lawgistics stack three months ago to supplement existing endpoint security, MFA, and platform hardening.
Challenge
The browser was the one layer Lawgistics could set policy on but could not watch.
Lawgistics had worked methodically down its security stack. Endpoint protection was locked down, MFA was enforced across platforms, and the SaaS tools its client firms depend on were hardened. Intune handled browser policy and Microsoft Defender covered basic DNS filtering. What none of that provided was an active view of what was actually happening in the browser, where all users spend the overwhelming majority of their time.
That gap became increasingly consequential as more SaaS applications moved into the browser.
"After we had locked down all the endpoint security and MFA and all the platforms, browser security is sort of the next biggest thing. You spend 100% of your day on your computer, and you spend 90% of your day on the browser. And as we continue to push clients towards SaaS products, they're putting more and more of their data into the internet, and they're doing more and more of their work on a browser."
For law firms, the risk of unmonitored browser activity is concrete rather than theoretical. A user pasting case material into a personal AI account is not an abstract policy violation. It is client information sitting in a third party's system, on a matter with an opposing party, a likely violation of the attorney-client privilege.
"If you use a personal AI account, then everything you put in there trains the model. And if you put sensitive case data in there, opposing legal counsel could ask questions about your inputs and get a real answer."
Solution
A policy set built in 45 minutes and deployed through tooling Lawgistics already ran.
Anderson came across Atakama, a browser security platform, in a hallway conversation at a conference in Denver, then sat in on the demo running at the event.
Deployment went through Intune, the same path Lawgistics uses for everything else it rolls out. Most of the effort was decision-making rather than implementation: reviewing the available controls and deciding which ones belonged in a law firm environment. The initial policy set took about 45 minutes to build and deploy and covered sensitive-page watermarking, malicious content blocking, and warnings for weak, compromised, and reused passwords.
"A little bit of time to review all the options and decide what we wanted. That was maybe 45 minutes of building out our initial policies. And then we just deployed all through Intune."
Anderson has since expanded his original policy set to cover upload and paste blocking, a capability that was still on the roadmap when Lawgistics first deployed and quickly shipped after they joined.
Extension management that reads in plain English.
Extension management in Intune presents extensions as long alphanumeric identifiers, which makes reviewing them slow. Atakama lists them by name with immediately recognizable icons.
"The extension management in Intune is based on whatever 40-character alphanumeric codes, and that's all you see in there is all the codes. Whereas when I look at Atakama's dashboard, it's like Acrobat and Google Docs are allowed, and you go, oh, okay, I know those."
Results
Shadow AI found, unapproved file sharing surfaced, and client conversations that start from data.
Shadow AI, quantified. Lawgistics found one client with a single user logging 112 hours a month on ChatGPT, which Lawgistics had not approved. Across the environments Anderson manages, browser data showed 38 users accounting for roughly 1,000 hours of ChatGPT in a single month.
Unapproved sharing tools identified. Activity data surfaced ShareFile in use at a client, despite not being on the approved list of sharing platforms.
A baseline of normal. For most clients, the data confirmed what Anderson expected to see: case management software, Zoom, and a smaller group in QuickBooks. That baseline is what makes the exceptions stand out.
AI conversations grounded in numbers. Anderson can now open a licensing and governance conversation with a client using real usage data instead of a general warning about risk.
"Right now I can say 38 users have done a thousand hours of ChatGPT this month, and then that is the conversation. There's no, 'I'm not sure how big of an issue it is,' or 'Do we really need to do this?' It's just your people are doing this, they're doing it all the time, and you're not in control of it."
Those findings are shaping what comes next. Anderson has written an expanded AI policy that limits access to the platforms Lawgistics has configured for clients and allows ChatGPT for research while blocking uploads and pastes to it, and browser data is being brought into the account management team's quarterly reviews with clients.
"A big part of the job has been setting up fences to prevent law firms from becoming news headlines."

Stay ahead of browser threats
Get monthly security insights, product updates, and expert guides delivered to your inbox.
No spam. Unsubscribe anytime.