The short answer
The question has two meanings, and both matter now.
One: should your firm connect its AI tools to its own systems, so the AI can finally reach your documents and matters? Two: should your firm expose its own services through an MCP, so AI agents can hire you directly?
The first is about working faster. The second is about being reachable in a market that is starting to run on agents.
For most firms the honest answer to both is the same: soon, deliberately, and not by accident.
Here is how to think about it.
Why this question can't wait
Most firms now have at least one AI tool in use. Many have several. In India, Harvey is already in use at Shardul Amarchand Mangaldas, AZB & Partners and S&A Law Offices. Cyril Amarchand Mangaldas has adopted Legora. The tools are here.
But there is a quiet problem underneath the adoption. The AI sits in one place. Your documents sit in your document management system. Your matter details sit somewhere else again. So the lawyer becomes a courier. You copy a clause here, paste a precedent there, and feed the AI context by hand.
That courier work eats the time the AI was supposed to save.
There is a second gap too. Even when the AI produces something good, it usually can't act. It can draft a status update but not post it to the deal room. It can spot a missing condition but not update the checklist. Again, the lawyer carries the message between systems.
This is the gap MCP is built to close. And the legal software market is now racing to enable it. iManage launched its MCP server in May 2026. NetDocuments is following. Harvey and Legora are both building toward agentic workflows that depend on exactly this kind of connection.
So MCP has stopped being plumbing. It is becoming a procurement question and a risk question at the same time. That is why it deserves a partner's attention, not just IT's.
What an MCP actually is
MCP stands for Model Context Protocol. It is an open standard, created by Anthropic in late 2024 and now backed by every major AI provider, including OpenAI, Google and Microsoft. Late in 2025 it was handed to a neutral foundation, so it no longer belongs to any single company. That matters: standards only become safe to build on once no one vendor controls them.
Think of it as a universal plug. Before MCP, connecting an AI tool to a system meant building a custom integration for every pair. One for the AI and your DMS. Another for the AI and your billing system. Each one was brittle and expensive.
MCP replaces that with a single common interface. Two roles do the work. An MCP server makes a system's data and actions available in a standard way. An MCP client is the AI application that uses them.
Notice those two roles. A firm can sit on either side of them. You can be the client, pointing your AI at your own systems. Or you can be the server, exposing your own services so other people's AI can use them. Those are very different strategic moves. Take them one at a time.
The first move: your firm as the client
This is the version most people mean. Instead of uploading copies of your documents into an AI tool, the AI reaches into your existing system, asks for what it needs, and the files never move.
iManage's pitch shows the upside clearly. With its MCP server, an AI tool can read governed content without bulk-exporting it. The documents stay in place. Access is permission-aware, so the AI only sees what that user is allowed to see. Ethical walls hold. Every query is logged and can be audited.
That solves a real fear among general counsel and security officers: AI tools quietly making copies of confidential files and scattering them across half a dozen vendors.
The use cases that firms find most credible fall into five buckets:
- Matter context — giving the AI the whole picture of a matter, not just the document on screen.
- Transaction coordination — letting the AI see live deal status and flag bottlenecks.
- Due diligence — connecting the AI to the data room so issues flow straight into the report.
- Knowledge and precedent — starting a draft from the firm's best prior work, not a generic template.
- Client reporting — pulling status, risk and numbers into an update without a partner assembling it by hand each week.
None of these work well through copy and paste. All of them work through a connection like MCP.
The part the demos skip: what could go wrong
Here is the catch. The moment an AI can read your files and act in your systems, you have widened your attack surface. Three risks matter most for a law firm.
Prompt injection. An AI follows instructions it reads. So an attacker can hide instructions inside content the AI processes — a document, an email, a web page. The AI can't always tell the difference between your instruction and a hidden one. Security teams call this indirect prompt injection. The danger rises when you combine three things: access to private data, exposure to untrusted input, and the ability to send data out. An MCP setup can create all three in one place.
Tool poisoning. Every MCP tool carries a description that tells the AI what it does. Attackers can hide malicious instructions inside that description — visible to the AI, invisible to you. One 2025 study of roughly 1,900 open-source MCP servers found that about 5.5% had this kind of flaw. So the source of your tools matters as much as the tools themselves.
The confused deputy. An MCP server often holds broad access so it can serve many users. If permissions are scoped loosely, an attacker can trick the server into using that broad access on their behalf. The fix is tight, per-user permissions — never one master key that can reach everyone's data.
There is a simpler way to hold all this in your head. The protocol standardises the plug. It does not make the plug safe. Safety lives in how you wire it and how you govern it. The same MCP connection can be locked down or wide open, depending on the choices behind it.
For a law firm, the stakes are not abstract. They are privilege, confidentiality, your ethical walls, and your duties to clients.
The bigger move: when your firm becomes the server
Until recently, MCP in law was about firms consuming AI. Then a firm flipped it.
In April 2026, General Legal — a Y Combinator-backed firm that calls itself "AI-native" — launched what it describes as the first MCP server run by an actual law firm. The idea is simple and slightly startling. An AI agent can upload a contract, track the review, and download an attorney-redlined version, all through plain conversation. No forms. No email. The agent handles the logistics. The firm does the law.
The crucial detail is what comes back. It is not AI-generated markup. Every contract is reviewed and redlined by a licensed attorney. The firm even makes the human step visible in the workflow: a contract moves from AI analysis, to the attorney queue, to attorney review, to delivered.
That is a real line crossed. A tech vendor that hands you AI suggestions is selling a tool. A law firm that hands you attorney redlines is selling legal services — with malpractice exposure and professional duties attached. General Legal put that service behind an open endpoint, so the "client" can be a piece of software acting for a human.
A few things make it more than a gimmick. It runs on flat fees, not the billable hour. It was built by the team behind Casetext, the legal-AI company Thomson Reuters acquired in 2023. And the firm says AI was built into its lawyers' workflow from day one, not bolted on afterwards.
One caveat for Indian readers: General Legal serves US clients for now. So this is not something you plug into from Bengaluru tomorrow. The model is the signal, not the product. The next competitive edge may not be having the best internal AI. It may be being the firm an AI agent can actually hire at two in the morning, without a single email.
The strategic question follows naturally. As clients start delegating routine legal tasks to their own agents, do you want to be discoverable and callable by those agents? Or invisible to them?
The India layer: DPDP and where your data lives
There is a local dimension to all of this. India's Digital Personal Data Protection rules were notified in November 2025 and are phasing in through May 2027. They require reasonable security safeguards and breach reporting, and they give people rights over their data.
An MCP that lets an AI read client matter data is, in plain terms, a new way of processing personal data. That brings it inside the DPDP conversation: consent, security, and breach readiness.
One piece is still unsettled. The rules on cross-border transfers and data localisation for the largest data handlers have not been finalised. So a sensible firm designs now for a world where certain data may need to stay in India. The "documents never leave the system" model fits that direction well. A model that ships your files to a vendor's overseas servers may not.
So, should you? A way to decide
Don't answer yes or no. And keep the two directions separate.
- Treat consumption as procurement. On every renewal, ask the vendor a plain question: are you MCP-enabled, and how do you secure it? The tools you buy over the next 18 months will either connect to your stack or they won't.
- Don't connect everything. Start with one high-value, lower-risk pattern. Knowledge and precedent, or matter context, are good first steps. Read-only before write access.
- Insist on a governed gateway. Route AI access through a permission-aware, fully logged server — the kind a serious DMS now offers — rather than ad hoc connections. Documents stay in place.
- Scope permissions tightly. Least privilege. No master key. Per-user, per-matter access only.
- Assume the AI reads hostile content. Require human sign-off before any action that sends, posts, or changes something.
- Map it to DPDP. Document your security safeguards. Plan for breaches. Watch the pending localisation rules.
- Give it an owner. Someone senior should own the firm's MCP posture and brief partners on what changes when the AI can finally do the work, not just describe it.
Then add one more, looking the other way. You probably will not expose your own services to agents this year. But decide who is watching that frontier. The firms that move first will shape how clients' agents find legal help — and being early to a new channel is hard to copy later.
The real takeaway
The firms that win the next phase of legal AI won't be the ones with the most tools. They will be the ones whose AI can safely reach the work that matters — and, increasingly, the ones an AI agent can reach directly.
General Legal is the early proof. An AI-native firm didn't wait for the market. It built the connection and put its lawyers behind it. That is not a software purchase. It is an engineering and governance decision dressed up as one — designing the connection, the permissions, and the guardrails on purpose.
So, should your firm have an MCP? As a consumer of AI: soon, if you can answer the seven questions above. As a provider to the agent economy: not yet for most — but start watching now, because someone in your market will move first. If you can't yet answer either honestly, the honest answer is not until you can.