
Across the legal industry, attorneys are quietly adopting AI tools faster than their firms can write policies for them. A paralegal drafts a summary in ChatGPT. An associate uses Copilot to clean up a memo. A partner pastes a contract into an AI tool to “see what it thinks.” Each of these feels like a small productivity win. Each one may also be a confidentiality problem your firm hasn’t accounted for.
For law firms, this isn’t just an IT question — it’s an ethics question. And it’s one that bar associations, malpractice insurers, and clients are starting to ask directly.
The Problem: Convenience vs. Confidentiality
Generative AI tools work by processing whatever text you give them. Depending on the tool and its settings, that text may be:
- Stored on the provider’s servers
- Used to improve or train future versions of the model
- Accessible to the provider’s staff for review or troubleshooting
- Retained well beyond the session in which it was entered
When an attorney pastes a client’s contract, deposition notes, or settlement details into a free, consumer-facing AI tool, none of that may be obvious to them in the moment. But the underlying data has now left the firm’s control — and potentially the protections of attorney-client privilege along with it.
Why This Is an Ethics Issue, Not Just a Tech Issue
Model Rule of Professional Conduct 1.6 requires attorneys to make reasonable efforts to prevent unauthorized disclosure of client information. Several state bar associations have issued guidance in the past two years specifically addressing generative AI, and the common thread is consistent: attorneys are expected to understand how a given AI tool handles data before using it for client work, the same way they’re expected to vet a cloud storage vendor or an e-discovery platform.
The risk isn’t theoretical. If client information is exposed, used inappropriately, or surfaces in another user’s AI output, the firm could face a bar complaint, a malpractice claim, or both — separate from any breach notification obligations that might apply.
Not All AI Tools Carry the Same Risk
This isn’t an argument against AI in legal work. The technology is genuinely useful, and firms that use it well are gaining a real efficiency advantage. The distinction that matters is between tools built with confidentiality in mind and tools that aren’t.
Higher risk: Free, consumer versions of general-purpose AI chatbots, browser extensions with vague data policies, and any tool where the firm hasn’t reviewed the terms of service or data handling practices.
Lower risk: Enterprise-tier AI products with contractual data protections (no training on your inputs, defined retention periods, audit logs), legal-specific AI platforms built for law firms (many integrate directly with practice management software and are designed around privilege requirements), and AI features within tools the firm already vets and controls, like Microsoft 365 Copilot under an enterprise agreement.
The gap between these two categories is large, and it’s usually invisible to the attorney using the tool day to day.
What a Law Firm Should Actually Do About This
A blanket ban on AI tools rarely works in practice — attorneys will use them anyway, just without telling anyone. A more realistic approach:
- Find out what’s already being used. Most firms are surprised by how many AI tools are already in use informally. A short, non-punitive survey of staff is often more revealing than any policy document.
- Set a clear, simple rule about client data. Something as direct as: “No client-identifying information goes into any AI tool that hasn’t been approved by [IT/managing partner].” Simple rules get followed; complicated ones get ignored.
- Vet and approve a short list of tools. Rather than trying to evaluate every AI product on the market, pick one or two enterprise-grade options with appropriate data protections, and make those the firm’s sanctioned choice.
- Put it in writing. An AI use policy, even a one-page version, gives the firm something to point to for insurance questionnaires, client audits, and bar inquiries — and gives attorneys clear guardrails instead of guesswork.
- Review vendor contracts before rolling anything out. This is where firms benefit from involving their IT partner. Data retention terms, training-data opt-outs, and breach notification clauses are easy to miss in a vendor’s terms of service, but they’re exactly what would matter in a bar inquiry or claim.
The Bottom Line
AI tools aren’t going away from legal practice, and firms that use them thoughtfully stand to gain real efficiency. But “thoughtfully” has to include knowing where client information goes once it’s typed into a chat window. A firm that can show it evaluated its AI tools, set a clear policy, and chose options with real data protections is in a fundamentally different position — with regulators, insurers, and clients — than a firm that finds out after the fact that an associate was pasting deposition transcripts into a free chatbot.
