In early August, Onit brought together legal operations leaders for a customer-exclusive focus group on Model Context Protocol (MCP). The discussion explored where MCP fits in contrast to APIs and what legal teams need from the next generation of AI integration.
Collectively, customers represented billions of dollars in legal spend. One point became clear during the discussion: legal teams are not waiting for one AI platform to win.
They’re already working across Copilot, Claude, Harvey, Glean, Wordsmith and other tools. Some are even testing the same use cases across multiple platforms to compare quality, productivity and cost.
Add those tools to in-house solutions and an already crowded legal technology stack, and the cost of fragmentation rises. Legal teams may have to find the same information repeatedly, reconcile answers drawn from different sources and determine whether each AI tool is respecting the same permissions and underlying data.
The challenge is not simply connecting more technology. It is connecting it without losing context, control or trust. MCP offers one possible approach.
What Model Context Protocol means for legal teams
Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external systems. It gives AI applications a consistent way to access available data, tools and workflows. For legal teams, that could allow AI agents to retrieve permitted information from systems such as matter management or document management and, where authorized, use available tools to complete an action.
For legal teams, the practical value may appear in requests such as:
- Show me my active matters.
- Which deadlines are coming up?
- Summarize this matter.
- Pull the key dates from this document.
Instead of opening multiple systems, finding records and assembling context manually, users can start with the work they need to get done.
MCP does not replace APIs. APIs define how software systems exchange information, while MCP provides a standard way for AI applications to discover and use the data and tools those systems make available. In many implementations, an MCP connection may rely on existing APIs behind the scenes.
The focus group saw greater value in connected legal intelligence
Participants spent less time discussing individual MCP use cases than a broader problem: how to connect the legal stack without creating another set of isolated AI experiments.
One participant described a legal knowledge layer connecting systems such as Onit and iManage with AI tools like Copilot, Harvey and Claude. Another participant had a name for where their organization is headed: a “legal brain” capable of making sense of information across siloed SaaS applications.
The opportunity is not another AI destination. It is a way for the tools legal teams choose to access trusted context already sitting across their technology ecosystem.
Better connections expose bad data
Greater connectivity also makes data quality harder to ignore.
Years of legal technology configuration can leave behind outdated fields, inconsistent naming and backend information that was never designed to provide context to an AI agent.
As one participant observed, what gets called an AI “hallucination” may actually be an agent pulling bad underlying data.
That makes data hygiene an operational requirement rather than a background maintenance task. Fields, descriptions and configurations that may have been easy to ignore become much more important when AI can use them to interpret and act on legal information.
Data quality is becoming AI infrastructure.
Governance must travel with the data
Participants also emphasized that greater connectivity cannot come at the expense of control.
MCP can standardize a connection, but it does not by itself determine who should have access or which actions should be allowed. Those controls must be enforced by the applications and underlying systems involved.
Permissions need to follow the user. Someone shouldn’t be able to access information through an AI agent that they couldn’t access in the underlying system. And as agents progress from retrieving information to creating or updating records, organizations need to know who initiated an action, what changed and how it happened.
The focus group did not advocate connecting every available system as quickly as possible.
Participants instead emphasized making legal AI more useful without sacrificing the permissions, approvals and audit trails required for governed execution.
Questions legal teams should ask before adopting MCP
Legal teams do not need to connect every system at once. Before moving forward with MCP, they should ask:
- Which systems contain the trusted matter, contract, spend and document data our AI tools need?
- Is that information accurate and consistently structured?
- Will existing user permissions apply when information is accessed through an AI application?
- Which actions should require review or approval before they are completed?
- Will the organization have a reliable record of what the AI accessed, changed or created?
- Which connections would benefit from MCP, and which are already well served by existing integrations?
Answering those questions can help legal teams identify where MCP may add value and where data, access or governance work needs to come first.
At Onit, we believe the long-term value of legal AI will depend less on any single model or interface and more on the trusted systems, workflows and controls surrounding it. MCP is promising because it may make those connections easier to establish. But connection alone is not the goal. The goal is to give legal teams useful, governed access to context wherever their work happens.
As AI moves from answering questions to taking action, permissions, approvals and auditability become even more important. Read Beyond Legal AI Assistants: Why Governed Execution Matters to explore what governed execution should look like for legal teams.