Attorney Practice Guide
Can Lawyers Use AI With Confidential Client Data?
A practical data-flow review for law firms evaluating AI access, transmission, retention, training, permissions, deletion, auditability, and attorney supervision.
Reviewed
Resource record
A practical data-flow review for law firms evaluating AI access, transmission, retention, training, permissions, deletion, auditability, and attorney supervision.
- Reviewed
- Aug 12, 2026
- Evidence
- ABA ethics guidance and vendor data terms
- Useful artifact
- Client-data decision checklist
Review note: Sources, workflow, and professional limits reviewed for the current edition.
There is no responsible universal answer to whether a lawyer can put client information into “AI.” The answer depends on the information, the product, the account and contract, the workflow, the people with access, the jurisdiction, and the safeguards the firm actually uses.
The practical mistake is treating every AI system as interchangeable. A public chat account, a business workspace, an embedded practice-management feature, a private API workflow, and a browser-local document check can have materially different data paths.
Before client information enters a system, trace what happens to it.
Start with the actual data flow
Ask the vendor to describe one representative matter from input through deletion.
1. What enters the system?
Inventory the information, not merely the file type:
- Client and prospective-client names
- Financial account numbers and statements
- Medical and disability records
- Immigration identifiers and family information
- Children’s information
- Privileged communications and attorney work product
- Court filings and public records
- Metadata such as file names, matter names, and user activity
A workflow may need only a document period and account suffix. Sending the complete file can expose more information than the job requires.
2. Where is information processed?
Determine whether processing occurs:
- Inside the user’s browser
- On the vendor’s infrastructure
- Through a third-party model provider
- Through optical-character-recognition or transcription subcontractors
- In another country or region
- In logs, monitoring systems, backups, or support tools
“Encrypted” does not answer who receives the plaintext during processing.
3. Is the information retained?
Ask about separate retention periods for:
- Original files
- Extracted text
- Prompts and responses
- Embeddings or indexes
- Operational logs
- Abuse-monitoring logs
- Backups
- Support copies
The useful answer includes a time period, deletion method, exceptions, and the contract or policy that controls.
4. Is the information used for training or improvement?
Separate several questions:
- Is customer content used to train a shared model?
- Is it used to fine-tune a customer-specific model?
- Is it used for human review, quality evaluation, or product improvement?
- Can the setting change by plan, administrator choice, or product feature?
- Do downstream model providers follow the same restriction?
“We do not train on your data” is important, but it is not a complete data-handling description.
5. Who can access each matter?
Confirm role-based access, firm isolation, administrator powers, support access, permission inheritance, and behavior after a user leaves the firm.
An AI feature should not allow a user to retrieve matter information they could not otherwise access.
6. Can the firm see what the system did?
A useful audit record may include:
- User and matter
- Source material used
- Machine action performed
- Output presented
- Approval, correction, or rejection
- Client-facing or filed result
- Version and timestamp
Auditability should preserve accountability without retaining more confidential content than necessary.
7. What happens when the system is wrong?
The workflow should define:
- Which outputs require attorney review
- What low confidence looks like
- When automation stops
- How a correction is recorded
- Whether the original source remains visible
- How an incident is reported and investigated
8. Can the firm leave?
Ask how to export matter records, audit history, prompts or work product the firm needs, and how deletion is confirmed after termination.
Professional responsibility belongs in the design
ABA Formal Opinion 512 discusses competence, confidentiality, communication, supervision, candor, and reasonable fees in connection with generative AI. Its confidentiality analysis makes vendor terms and the nature of the disclosure part of the lawyer’s evaluation.
The NIST Generative AI Profile provides a broader risk-management framework for generative AI. It is not a law-firm ethics opinion, but its govern, map, measure, and manage structure is useful when turning vendor claims into an operating review.
Firms should also check applicable state guidance, court rules, client instructions, protective orders, engagement terms, and contractual obligations. A national article cannot resolve a firm’s jurisdiction-specific duties.
Redaction helps, but it does not solve every problem
Removing names and account numbers can reduce exposure. It may not remove:
- A distinctive fact pattern
- Medical details
- Business names or transaction terms
- Dates, locations, or family relationships
- Metadata and file names
- Information that can be reidentified when combined
Use data minimization first: send only what the bounded job requires. Then consider redaction, access controls, contractual restrictions, review, and retention together.
Compare three common architectures
Browser-local processing
The file is read inside the browser tab and does not leave the device for the public check. This can be an excellent proof or narrow utility, though capability is limited by the browser and the code delivered to it.
DocketBuddy’s public one-file proof runs locally in the browser and excludes the file, file name, and extracted text from analytics.
Embedded platform AI
The feature operates inside an existing practice platform and can use the matter’s permissions and context. The firm should still examine downstream processors, feature-level retention, user controls, and the action history.
Connected workflow AI
A defined event sends a limited source packet to a model or processing service, then returns a result to the matter. This can minimize data and create precise controls, but the firm must understand every system in the chain.
What DocketBuddy publishes about its own boundary
DocketBuddy describes firm isolation, encryption, AI training posture, access controls, and product boundaries on its Security and Data Handling page. Product marketing should not substitute for the firm’s own review of current terms, workflow, and client requirements.
A concise vendor request
Before a live pilot, ask the vendor to provide:
- A current data-flow diagram for the feature
- The list of subprocessors involved in AI processing
- Retention periods by data type
- Training and human-review restrictions
- Permission and firm-isolation behavior
- Audit and administrator controls
- Export and deletion procedures
- Incident notification terms
- The product documentation and contract provisions supporting each answer
If the vendor cannot answer at the feature and account-plan level, the firm does not yet have enough information to evaluate that workflow.
Common Questions
Does using AI waive attorney-client privilege? That question depends on the circumstances, applicable law, the information disclosed, the recipient, and the safeguards and agreements involved. Firms should obtain jurisdiction-specific advice rather than relying on a categorical internet answer.
Is a business AI account automatically safe for client files? No account label resolves the full review. Examine the specific product, feature, settings, contract, subprocessors, retention, permissions, and workflow.
Is “not used for training” enough? No. It is an important control, but the firm should also evaluate transmission, retention, human access, logs, permissions, security, deletion, and downstream providers.
Should a law firm use local AI instead of cloud AI? Local processing can reduce some data-transfer risks, but it creates its own security, maintenance, access, update, and quality responsibilities. Architecture should be evaluated against the actual workflow and firm capabilities.
Method and scope
This checklist draws from ABA Formal Opinion 512, the NIST Generative AI Profile, and common software data-flow review practices. It is operational information, not a legal opinion about privilege, confidentiality, professional responsibility, or a particular vendor.
Article feedback
Was this helpful?
What should we improve?
Thanks for telling us
We’ll use this to improve the guide.