On July 20, 2026, Clifford Chance launched a custom AI-powered knowledge-management platform that gives its lawyers secure, natural-language access to more than 400,000 internal documents. Built with Microsoft and Epiq Advisory, the new system — called Knowledge Bank — embeds generative answers directly into Microsoft 365 workflows. But the most important innovation isn’t the chatbot. It’s a feature called Permissioned Search, which ties every AI-retrieved document to the same access controls that govern the firm’s client engagements, ethical walls, and matter-specific privileges.

What actually changed

The Knowledge Bank is not another off-the-shelf copilot bolted onto a document library. According to details first published by Artificial Lawyer and an Epiq case study, the platform was built over six months as a fully Microsoft-native application. The engineering stack includes SharePoint, Power Platform, Microsoft Graph API, and Azure AI Studio. It sits entirely within the firm’s existing tenant, drawing on the same identity and security model that already protects its emails, Teams conversations, and client files.

Key features include:

  • Permissioned Search – Epiq’s proprietary component enforces metadata-driven restrictions. A lawyer can query the entire repository but will only see documents they are authorized to access, based on client confidentiality rules, jurisdiction, and deal-team memberships.
  • Natural language queries and generative answers – Lawyers ask questions in everyday language and receive summaries, citations, and suggested precedents within Word, Outlook, and other Office apps.
  • Curated, AI-ready content – More than 400,000 documents were reclassified and summarised before being exposed to the AI. The firm intentionally built a “trusted internal material” corpus to reduce hallucinations and content drift.
  • Modular design – The architecture allows the firm to add practice-specific tools for mergers and acquisitions, litigation, regulatory advisory, and other areas without rebuilding the core.

Matt Taylor, Clifford Chance’s Global Head of Knowledge & Training, said the platform is “central to our strategy of delivering value to our clients” and underlined that AI is deployed “while respecting client confidentiality.”

What it means for you

For Microsoft 365 administrators and security teams
This project is a case study in AI governance. The takeaway is blunt: before you let generative AI loose on your SharePoint libraries, make sure your permissions are airtight. Years of accumulated “Everyone” or overly broad access groups turn a helpful search tool into a data-leakage nightmare. Clifford Chance’s approach shows that a successful enterprise AI deployment starts with information hygiene — Microsoft Entra ID group cleanup, SharePoint and Teams site permissions, sensitivity labels, and metadata consistency.

You don’t need to be a Magic Circle law firm to apply the same principle. Audit your existing permissions, classify your content, and decide explicitly what AI should never touch. The Knowledge Bank explicitly drew a hard boundary around its AI-eligible corpus. Your organization can do the same, even if it’s just a single document library for a department pilot.

For legal professionals and regulated industries
If you work in a firm that handles client-confidential information, this announcement signals a shift in what “AI-ready” really means. It’s not about flipping a Copilot switch; it’s about building a managed, governed, and continuously curated knowledge product. The Permissioned Search capability addresses the fundamental tension between “make all knowledge discoverable” and “never expose client data to unauthorized eyes.” Expect other legal technology providers to follow suit. In the meantime, pushing your leadership to invest in metadata and classification now will pay dividends when you eventually adopt a similar system.

For everyday Microsoft 365 users
You’re unlikely to build a 400,000-document knowledge bank, but you already experience the same friction at a smaller scale. Finding a reliable document in a shared library, Teams site, or OneDrive account often fails because nobody applied consistent tags or because the file you need is locked in a folder with broken permissions. Clifford Chance’s architecture is a reminder that even basic file properties (client name, matter ID, document type) and column-level metadata can transform retrieval. If your organization someday deploys an AI assistant, the quality of its answers will depend on the metadata you enter today.

How we got here

Microsoft has been deepening its legal-sector play for years. Clifford Chance was among the first global law firms to deploy Microsoft 365 Copilot, Paul Barlow, Microsoft’s technology strategist for legal services, noted in the announcement. That rollout gave lawyers a general-purpose productivity assistant. But the Knowledge Bank represents the next logical step: a specialized application that understands the constraints of legal work.

The timing is no coincidence. Since 2024, Microsoft has aggressively positioned Azure AI Studio and the Power Platform as the foundation for bespoke, industry-specific AI. Instead of forcing customers to adopt a separate knowledge-management vendor, the strategy is to make the existing Microsoft 365 tenant the control plane. Epiq’s implementation shows how a skilled partner can assemble a governed application from components many enterprises already license.

The reclassification of 400,000 documents also reflects a maturing understanding of AI risk. Early generative AI experiments often exposed organizations to hallucinations when grounding models on messy, untrusted internal data. By curating content first, Clifford Chance is trying to limit that exposure. The move mirrors broader enterprise trends: a 2025 survey by Gartner found that 63% of organizations planned to verify or clean their data before using it with generative models.

What to do now

Even if your organization isn’t ready for a full knowledge bank, you can begin the prerequisite work today. Here’s where to start:

  1. Audit Microsoft 365 permissions – Use the Microsoft 365 Admin Center or PowerShell scripts to review SharePoint and Teams permissions. Look for sites with “Everyone except external users” and groups that have expanded beyond their original purpose. Replace broad access with membership in Microsoft Entra security groups tied to real-world roles or projects.

  2. Deploy sensitivity labels – If you’re not already using Microsoft Purview Information Protection, start tagging documents with labels that matter for your business (e.g., “Client Confidential,” “Internal Only,” “Public”). These labels can later double as AI access controls.

  3. Build a content classification scheme – Decide what metadata matters for retrieval. For a law firm, it’s client, matter, and practice area. For other industries, it might be project code, document type, or regulatory chapter. Enforce these columns in document libraries and set default values to encourage adoption.

  4. Curate an AI-ready corpus – Identify a bounded set of authoritative documents for your first AI pilot. Don’t just point the model at “everything on the intranet.” Work with subject-matter experts to mark content as obsolete, duplicate, or outside the scope of the experiment. Clifford Chance’s multi-month reclassification effort shows the scale of work, but a departmental pilot might take weeks.

  5. Involve risk and compliance teams early – Before turning on AI search, have legal, privacy, and records-management stakeholders define what’s off-limits. Build their rules into your metadata and permission design from day one.

  6. Monitor and iterate – Once your system is live, track what users are asking and which documents are retrieved most. Adjust tags and access rules based on real usage, not just theory.

Outlook

Clifford Chance promises that the new platform is “modular and extensible,” so expect additional practice-specific tools to appear in the coming months. The firm’s early adoption of Microsoft 365 Copilot and now this custom build should be read as a single story: one of the world’s most risk-sensitive organizations is betting that the Microsoft ecosystem can handle AI governance at scale.

That bet will be tested. As documents are added, clients change, and regulations evolve, the team must prove that its metadata-driven approach remains accurate and maintainable. Other firms in legal, finance, and healthcare will watch closely. If the Knowledge Bank delivers without a confidentiality crisis, it will be cited as proof that a governed, permission-first AI model works.

Microsoft, meanwhile, is almost certain to productize more of these capabilities. Its work on a dedicated legal agent with the former Robin AI team, still in development, points to a future where industry-specific AI templates come pre-packaged. For now, though, the lesson from Clifford Chance is clear: the most important AI feature you can buy isn’t a better model — it’s better data hygiene.