Mobile AI Legal Assistant: RAG Search and Risk Detection
Over 30% of inquiries to legal firms are routine questions that can be automated. A properly built RAG system reduces lawyer workload by 40% and cuts response time by 3x. Imagine a user asking in chat: "What is the statute of limitations for a loan agreement?" If your AI assistant answers incorrectly, the consequences can be fatal. We develop such systems from scratch, starting not with a model but with the jurisdiction and constraints. Our experience: 5+ years in LegalTech, 20+ implementations for iOS and Android. We guarantee that answers always include references to specific articles of law.
How an AI Assistant Finds the Right Legal Norms?
Three fundamental distinctions you cannot ignore when designing. Jurisdiction matters. An article of the Russian Civil Code and a similar norm in Kazakhstan may give directly opposite answers to the same question. Before any answer, the system must know the user's jurisdiction — either from a profile or explicit selection. RAG, not fine-tuning. An LLM fine-tuned on previous editions of legislation will confidently cite norms that have already been repealed. The correct approach is Retrieval-Augmented Generation with an up-to-date database of regulatory acts. The document is split into chunks, indexed via a vector store (pgvector, Pinecone, or Weaviate), and on query, relevant fragments are retrieved and passed into the LLM context. The source is always indicated in the answer: According to Art. 196 of the Civil Code of the Russian Federation (current version). Disclaimer is part of UX, not a footnote. Before the first query, explicit confirmation that the user understands this is not legal advice and does not replace a lawyer. Without this confirmation, the interface does not open.
Why We Choose RAG Over Fine-Tuning?
| Approach |
Advantages |
Disadvantages |
| Fine-tuning |
Faster inference |
Becomes outdated when laws change; expensive to retrain |
| RAG + vector store |
Always up-to-date base; transparent sources |
Dependent on indexing quality |
RAG wins on safety and currency — that's why we use it in every project. Inference speed is compensated by query optimization. Additionally, we reduce infrastructure costs by using a shared base for multiple clients.
How Is High-Risk Query Detection Implemented?
Criminal questions, questions about specific criminal cases, medical-legal intersections — a separate class. A classifier (fine-tuned BERT or keyword-based for MVP) determines the category before the LLM call:
| Risk Level |
Example Query |
Action |
| informational |
what is statute of limitations |
AI answer |
| moderate |
how to draft a claim |
AI answer + disclaimer |
| high |
how to avoid criminal liability |
AI answer + lawyer recommendation |
| criticalRedirect |
active criminal case, arrest |
Only redirect to a lawyer |
At criticalRedirect — only emergency redirect to a live lawyer, no AI answer.
What Data Is Encrypted and How?
Legal consultations are sensitive data. They must not be stored in cleartext. On iOS, chat history is encrypted via AES-GCM (CryptoKit) before writing to Core Data. The key is in Keychain, tied to biometric authentication. On Android, similarly via EncryptedSharedPreferences or Room with SQLCipher. Server side: all requests to LLM are logged without user identifiers (only session hash), data in vector store — public regulatory acts, no personal data.
Mobile App Structure
On iOS — MVVM with Combine, on Android — ViewModel + StateFlow. The chat is implemented as a message list with support for rich content: quotes from regulatory acts, links to sources, buttons with a call to "Consult with a lawyer". When suggestsProfessional == true, a card with a button to contact a lawyer appears in the UI. This monetizes through partnerships with legal services and simultaneously reduces legal risks for the app owner.
What's Included in the Work and Timeline Estimates
- Architectural documentation (diagrams, API specification)
- Integration with a partner legal service (on request)
- Setup of disclaimer flow and risk detection
- Admin instructions for updating the act database
- 14 days of post-deployment support
MVP with RAG on a single jurisdiction, basic chat, and disclaimer flow — 3–4 weeks. Full system with multi-jurisdictional base (RU/BY/KZ), automatic legislative base update, risk classifier, integration with partner legal service, history encryption, and iOS + Android support — 2–3 months. Timelines depend on the volume of the regulatory base being indexed.
Get a consultation from an engineer — we will select the optimal configuration for your project. Order a free demo access to evaluate the assistant's performance on your data.
Machine Learning in Mobile Apps: CoreML, TFLite, and On-Device Models
We distinguish two fundamentally different approaches: an app with on-device AI and an app that simply calls a cloud API. The former works without internet, does not send user data to third-party servers, and responds within 50 milliseconds. The latter depends on network latency and pricing plans. Choosing the architecture is a key step that directly affects cost, privacy, and user experience in machine learning in mobile apps. Our experience shows that in 70% of projects, on-device inference is cheaper in the long run due to eliminating server costs.
How to Choose Between CoreML and TFLite for On-Device Inference?
CoreML — Apple's native framework for running ML models on device. Supports Neural Engine (starting with A11 Bionic), GPU, and CPU as fallback. Models are converted to .mlmodel format via coremltools from PyTorch, ONNX, or TensorFlow. Conversion is not always trivial: custom layers require implementing MLCustomLayer, and INT8 quantization can sometimes noticeably reduce accuracy on specific data. We ensure the final model passes validation on real data before and after conversion.
TensorFlow Lite — cross-platform alternative for Android and Flutter. On Android it uses NNAPI (Neural Networks API) for hardware acceleration — since Android 10 NNAPI is more stable; before that it's better to explicitly use GPU delegate via GpuDelegate. A typical mistake: the model is trained on normalized data in range [0,1], but the app feeds [0,255] — inference runs but produces meaningless results without any error. We include an automatic input data validation module in the SDK.
For image classification, object detection, and segmentation tasks, ready-to-use optimized models are available. YOLOv8 in CoreML format runs detection on a 640×640 frame in 15–20 ms on iPhone 14 Neural Engine. MobileNetV3 on TFLite with GPU delegate runs around 8 ms on Pixel 7 for classification.
| Parameter |
CoreML |
TFLite |
| Platforms |
iOS, macOS, watchOS |
Android, iOS, Linux, embedded |
| Hardware acceleration |
Neural Engine, GPU, CPU |
NNAPI, GPU (OpenCL/OpenGL), CPU |
| Quantization support |
FP16, INT8 (with coremltools) |
FP16, INT8, dynamic range |
| Custom operations |
Via MLCustomLayer (Swift) |
Via delegates (Java/Kotlin) |
| Model bundle size |
~3–5 MB (MobileNetV2 quantized) |
~2–4 MB |
What If You Need Text Generation On-Device?
Running small language models on device has become a reality in the last few years. Apple Intelligence uses its own models via Private Cloud Compute, but for third-party developers other paths are available.
llama.cpp with Metal backend on iOS is a working approach for phi-3-mini (3.8B parameters, 4-bit quantization, ~2.3 GB). Inference: 15–25 tokens/second on iPhone 15 Pro. For integration in Swift, use the Swift Package llama.swift or a wrapper via C interface llama.h. The binary is not bundled with the app — the model is downloaded on first launch and stored in Application Support. Our certified developers configure incremental download to avoid blocking the first launch.
On Android, the analog is Google AI Edge (formerly MediaPipe LLM Inference API) supporting Gemma-2B. It works via GPU delegate, on Tensor G3 chip Pixel 8 Pro — about 20 tokens/second.
Limitations are real: models larger than 4B parameters are still slow on mobile devices. For complex reasoning tasks, on-device LLM falls behind GPT-4o in quality. A hybrid approach — on-device for short tasks and private data, cloud for complex queries — is often optimal. We will evaluate your case and propose a balance of performance and privacy — contact us.
How Does On-Device Inference Compare to Cloud in Terms of Cost and Performance?
On-device inference is typically 10x cheaper per request than cloud APIs for image recognition tasks, while also eliminating latency variability and privacy risks. The table below summarizes the trade-offs.
| Criteria |
On-Device Inference |
Cloud API |
| Latency |
<50ms |
200–500ms (including network) |
| Cost per 1M requests |
$0 (no server) |
$10–50 (AWS Rekognition, Google Vision) |
| Privacy |
Data stays on device |
Data sent to server |
| Offline |
Yes |
No |
| Scalability |
No server scaling issues |
Need to provision API capacity |
For an app with 100k MAU running 10 image recognitions per user per month, on-device inference can save up to $5,000 monthly compared to cloud API. Get a free consultation on your ML architecture today.
Integrating OpenAI API and Other Cloud Models
For scenarios where cloud inference is acceptable, integrating OpenAI, Anthropic, or Google Gemini is an HTTP client + streaming SSE. In Swift, AsyncThrowingStream is convenient for streaming responses. In Kotlin, use Flow.
Critically: API keys must never be stored in the app bundle. Even an obfuscated key can be extracted from the IPA in 10 minutes using strings or frida. Correct architecture: mobile app → your own backend → OpenAI API. The backend controls rate limiting, logs requests, and protects the key.
What Is Included in the Work (Deliverables)
- Trained and quantized model for the target device (documentation with metrics)
- SDK for integration (Swift/Kotlin/Flutter) with call examples
- Performance tests on 3–5 real devices
- Instructions for OTA model updates
- Support during App Store / Google Play moderation (compliance with Guidelines 4.2, 5.1)
- 2 weeks of technical support after release
Typical Project Pipeline
-
Task analysis — measure latency, privacy, size, supported devices.
-
Model prototyping — in Python, evaluate accuracy on target data.
-
Conversion and quantization — for CoreML/TFLite with validation.
-
Integration into the app — model wrapped in a service layer (easy to swap CoreML ↔ TFLite ↔ cloud).
-
Testing — on real devices, measure FPS, RAM, battery.
-
Deployment — via TestFlight / Firebase App Distribution, monitor metrics.
Timelines: integration of a ready CoreML/TFLite model — 1–2 weeks, development of a custom model with mobile optimization — from 6 weeks, on-device LLM chat with personalization — 4–8 weeks.
Why We Take on Complex Cases?
10+ years of experience in mobile development, 50+ implemented AI/ML solutions, guarantee of compatibility with current iOS and Android versions. All projects undergo code review and load testing. The cost includes preparation of moderation documentation and training of your team.
Contact us — we will help you choose the architecture and implement ML in your app turnkey. Order an audit of your existing solution — we will assess the potential for server cost savings free of charge. In some projects, savings can reach significant amounts per month.