Confidentiality decision · approve a route, not a provider

Can Lawyers Use AI With Confidential or Privileged Data?

A provider logo cannot answer whether confidential or privileged matter data belongs in an AI workflow. The decision turns on the client, task, surface, contract, data path and controls.

Direct answer

Lawyers can evaluate AI uses involving confidential information only at the workflow level. Start with client instructions and applicable professional duties, then record matter sensitivity, the exact product and account, contract and data use, retention and access, connected tools, final destination and qualified review. Do not describe a product as privilege-safe or assume privilege is preserved; that legal conclusion depends on the facts and jurisdiction.

Matter-data decision gates for client instruction, sensitivity, product surface, contract, data path and reviewer
Decision map. No provider name by itself makes confidential or privileged legal work appropriate.

The six-part decision test

GateQuestionRequired record
Client instructionWhat has the client authorized, prohibited or required?Engagement terms, outside-counsel guideline and matter direction.
Matter sensitivityWhat information and harm are in scope?Data class, purpose and consequence.
Product surfaceWhich account, model, feature and route will receive it?Exact product and configuration.
ContractWhat are the data-use, retention, access and subprocessor terms?Executed terms and current incorporated pages.
Data pathWhere do prompts, files, logs, tools and outputs go?Copy-by-copy map and deletion path.
ReviewerWho is accountable for the final work and exceptions?Named role, approval and stop conditions.

Start with applicable professional guidance

ABA Formal Opinion 512 discusses competence, confidentiality, communication, supervision, candor and fees under the Model Rules. It is useful guidance, not controlling law in every jurisdiction. The State Bar of California’s practical guidance addresses duties for California lawyers. Use the sources that govern or inform the lawyer and matter; preserve the checked date and any client-specific requirements.

Do not collapse confidentiality and privilege. Contract terms, encryption, no-training language and retention controls can contribute to a confidentiality record. They do not automatically determine attorney-client privilege or work-product treatment.

Approve a surface, not a logo

A consumer chat, managed business workspace, API project, embedded legal product and cloud marketplace can use related models while creating different contracts, administrators, retention, regions, logs and features. Record the exact organization, project or tenant and prohibit personal accounts for approved matter workflows.

Check whether files, feedback, browsing, connectors, retrieval, code execution, memory, support or safety review change the path. Product-level statements can be accurate and still fail to cover a feature that sends content elsewhere. Unknown routes should not receive confidential material.

Read the contract beside the architecture

Attach the executed order form, service agreement, DPA where applicable, data-use terms, retention documentation, subprocessor list, security evidence and change-notice path. Public OpenAI, Anthropic and Google terms are starting points; the purchased agreement and product documentation control the buyer’s actual record.

Map customer content, account data, feedback, telemetry, safety or abuse logs, files, caches and outputs separately. “Not used to train” does not answer retention, human access, subprocessors, customer-side logging or deletion. Keep each claim attached to its source and product.

Minimize before routing

Ask whether the task needs names, identifiers, complete documents or the most sensitive fields. Redact or pseudonymize where that preserves the legal job. Use controlled references when the model needs structure but not identity. Keep source documents and approved work in the firm’s system of record.

Minimization is not a reason to call personal data anonymous or confidential information harmless. Record what was removed, who can reconnect the data and whether the remaining context can still identify a person or reveal a matter.

Run a canary before live matter use

  1. Create the intended managed account and least-privilege roles.
  2. Use non-sensitive test content through every required feature.
  3. Capture the observable prompt, file, tool, log, output and export copies.
  4. Test access removal, deletion, disabled features and a denied destination.
  5. Confirm the final human review and matter-record path.
  6. List provider-side facts that remain Unknown.

Maintain the decision after approval

Set review triggers for a new model, endpoint, connector, region, contract, retention rule, client instruction or external action. Compare the changed field and affected workflows instead of re-approving the provider from memory. Pause the route when a material requirement becomes Unknown.

Measure approved-workflow coverage, expired reviews, permission drift, deletion tests, incidents and attempted use of unapproved surfaces. Those measures show control operation; they do not prove privilege preservation or the absence of disclosure.

Ask risk questions the operating team can answer

Start with the possible failure, not an abstract low, medium or high score. Could content reach an unintended provider or tool? Could a person outside the approved team retrieve it? Could the system act on an inaccurate output? Could a record be retained beyond the matter’s requirement? Could the firm fail to reconstruct what happened? Name the consequence, affected people and existing control.

Then ask whether the proposed route reduces, transfers or merely hides the risk. Encryption can protect data in transit or at rest while authorized processing still exposes plaintext. A DPA can define duties while a connector adds another recipient. Human review can catch substantive mistakes while doing little about an earlier disclosure. Keep controls attached to the failure they address.

Build the privilege question as a factual file

Where privilege or work-product protection matters, preserve the purpose of the communication, participants, legal relationship, expected confidentiality, disclosures, vendor role, terms and safeguards. Identify whether the tool is acting inside a controlled professional workflow or through a personal account with broader reuse and access. Give this factual file to the responsible lawyer.

Do not publish a reusable yes-or-no answer for every jurisdiction or matter. The same service can sit in materially different facts depending on the account, client direction, feature and downstream sharing. A narrow approval can require counsel review before a new client, jurisdiction or disclosure pattern enters the route.

Treat every enabled tool as another route

Browsing, search, email, cloud storage, document management, code execution and external actions can send content beyond the base model provider. Record the recipient, payload, purpose, authentication, retention, logs and permitted destinations for each tool. Disable tools the workflow does not need.

For agentic actions, require explicit authority, preview and approval for material writes or sends. Verify the destination and preserve the final human decision. A model with strong enterprise data terms can still create an uncontrolled disclosure through a third-party tool.

Find the routes already in use

Inventory managed and unmanaged AI use across web accounts, browser extensions, transcription, document tools, research products, mobile apps, APIs and embedded features. Ask practice groups which task they are trying to complete and which data enters the route. A software inventory alone can miss a newly enabled feature or a personal account used for work.

Give one owner authority to maintain the inventory, request evidence, pause an unapproved route and schedule rechecks. Ownership should not become a central bottleneck: publish short route cards for approved uses and send only exceptions, new surfaces and material changes back through review.

Use decision states instead of a universal score

StateMeaning
ApproveThe named workflow, account, data class and review path have sufficient current evidence.
RestrictUse is allowed only with narrower data, users, tools or destinations.
Non-confidential onlyThe route may support public or synthetic work but not client or matter information.
Remediate and retestA contract, configuration, logging or deletion gap has an owner and test.
ProhibitA material boundary fails or the provider cannot support the required route.
UnknownRequired evidence is missing; absence of evidence is not approval.

Give users a short incident path

Users need to know how to stop the workflow, preserve the event identifier, identify affected content and contact the response owner. The incident team needs the account, model, tool, destination, user, timestamps, logs, deletion options and provider support path. Test this with a non-sensitive event.

A mistake should not disappear into a general helpdesk ticket. Define when counsel, privacy, security, the client or an insurer may need to be involved, without making a universal notification conclusion in the product guide. Preserve decisions and their basis.

What the decision can and cannot say

A defensible record can say that a named reviewer approved a specific workflow, account, feature set, data class and period based on cited terms and tested controls. It cannot say the provider is universally safe, compliant or privilege-preserving. Keep Observed facts, Supported inferences and Unknowns separate, and route the legal conclusion to the responsible lawyer.

FAQ

Can a lawyer paste confidential information into a business AI account?

The account label alone is not enough. Check client instructions, applicable duties, the exact surface and contract, retention and access, features, data path and review before approving a defined workflow. Official source · checked 2026-09-03

Does no-training language preserve privilege?

No automatic conclusion follows. No-training addresses one use of data; privilege depends on the facts and applicable law.

Should law firms ban every AI use involving matter information?

A risk-based decision can approve, restrict or reject specific routes. The useful unit is one workflow and data class, not an undifferentiated provider-wide rule.

Sources checked

Operational information, not legal advice. Verify current terms, account configuration and applicable professional duties before use.

Decision frame · source-linked

Lawyers can evaluate AI uses involving confidential information only at the workflow level.

Why now. A compact, source-linked frame makes the next decision portable without replacing the full analysis.

  • Client instruction
  • Matter sensitivity
  • Product surface

Take this frame with you

Share the decision, not a generic object. The full sources and limits stay on the canonical page.