Client Confidentiality and AI Tools: Questions to Ask Before You Upload

Before client information goes into any AI tool, you need clear answers about storage, training, access and retention. Here are the questions to ask.

· 5 min read · eLaw Platform

Black and white photo of a woman looking at padlocks and graffiti in Cologne
Photo by Christian Gertenbach on Unsplash

Pasting a contract into an AI tool feels no different from pasting it into a word processor. Legally and ethically, it can be very different. Depending on the tool, that text may be stored on a vendor's servers, reviewed by its staff, retained for months or used to improve a model that other customers query. Client confidentiality obligations do not pause because the software is convenient.

This guide sets out the questions to ask any AI vendor before client information goes in, the kinds of data that call for extra caution and the practical safeguards firms are adopting. It is meant for partners, IT leads and anyone choosing or approving tools for a legal team.

This article is general information, not legal advice. Confidentiality rules and data protection laws vary by jurisdiction.

The duty behind the questions

In most US jurisdictions, the professional conduct rule modelled on ABA Model Rule 1.6 requires lawyers to make reasonable efforts to prevent unauthorised disclosure of, or access to, information relating to a client's representation. What counts as reasonable depends on the sensitivity of the information, the likelihood of disclosure and the cost of safeguards.

The duty is broader than privileged material. It covers information relating to the representation, whatever its source. That includes the fact that a client has consulted you at all.

Ten questions to ask any AI vendor

Get written answers, ideally in the contract or data processing terms rather than a marketing page.

Data use

  1. Is our input used to train or improve models? If yes, can it be switched off contractually, not just in a settings toggle?
  2. Is our data shared with any third parties, including underlying model providers? Under what terms?

Storage and retention

  1. Where is data stored, and in which countries? Cross-border transfers can raise data protection issues.
  2. How long are prompts, uploads and outputs retained? Can we set retention ourselves or delete on demand?
  3. What happens to our data if we end the contract?

Access and isolation

  1. Who at the vendor can access our data, and under what circumstances?
  2. Is our data logically separated from other customers' data?
  3. Can we restrict access within the firm by matter or team, to respect ethical walls?

Security and incidents

  1. What security controls are in place, such as encryption at rest and in transit and access logging? Ask for documentation rather than assurances.
  2. How and when will we be told about a breach?

If a vendor cannot answer clearly, that is itself an answer.

Information that deserves extra caution

Even with a well-vetted tool, some categories warrant a second thought or a specific client conversation:

  • Health information, especially if HIPAA or similar rules may apply.
  • Personal data of individuals in jurisdictions with strict privacy laws, such as the GDPR.
  • Trade secrets and unreleased financial information.
  • Material subject to a protective order or court seal.
  • Information about minors or criminal matters.

Some protective orders restrict where documents may be stored or who may view them. Check before uploading discovery material to any outside service.

Practical safeguards firms are adopting

Safeguard What it looks like
Approved tool list Staff may use only tools that passed review for client data
Tiered use rules Public or anonymised material in general tools; client material only in approved ones
Redaction before upload Removing names and identifiers where the task allows it
Engagement letter language Explaining that the firm may use vetted AI tools and how data is protected
Periodic re-review Rechecking vendor terms, which can change after signing

Consumer accounts on general chatbots are a common weak point. A staff member using a personal account for client work may be agreeing to terms the firm never reviewed.

Talking to clients about it

Some corporate clients now include AI clauses in outside counsel guidelines, ranging from notice requirements to outright bans on certain tools. Read those guidelines before using AI on their matters. For other clients, a short explanation in the engagement letter, with an invitation to ask questions, is often enough. Where sensitive information or unusual uses are involved, informed consent may be appropriate.

Where purpose-built tools fit

Tools designed for legal teams often address these questions upfront. eLaw, for example, describes its platform as keeping firm data isolated while it handles document analysis and legal research with cited answers. Treat any vendor statement as a starting point and confirm the detail in the contract and data processing terms.

Your first confidentiality review

  1. List every AI tool anyone in the firm currently uses, including personal accounts.
  2. Send the ten questions to each vendor and file the answers.
  3. Publish an approved-tools list with tiered use rules.
  4. Update your engagement letter template and diary a re-review in six months.

FAQ

Does uploading a document to an AI tool waive attorney-client privilege?

Not automatically, but it can create risk if the tool's terms allow the vendor or others to access the content, much as careless disclosure to any third party might. Courts look at the circumstances, including reasonable expectations of confidentiality. Using tools with strong contractual confidentiality protections reduces that risk.

Is anonymising data enough to protect client confidentiality?

It helps, but it is not always sufficient. Facts can identify a client even without names, especially in small markets or high-profile matters. Treat anonymisation as one safeguard among several, and consider whether the remaining details could still reveal who is involved.

Can staff use free AI chatbots for client work?

Many firms prohibit it because free consumer tiers often have broader data use and retention terms than enterprise versions. If the firm has not reviewed the terms, staff cannot easily judge whether use meets confidentiality duties. A clear policy on approved tools avoids guesswork.

It depends on the jurisdiction, the tool, the information involved and any client guidelines. Some bar opinions suggest informed consent may be needed before inputting confidential information into certain tools. Check the opinions in your jurisdiction and the client's outside counsel guidelines.

← All articles