AI and Client Confidentiality: What Attorneys Need to Know Before Using ChatGPT or Copilot

Tools like ChatGPT and Microsoft Copilot have become part of the daily routine in many law offices, often without much thought about what happens to the information typed into them. For an attorney, that's a confidentiality question first and a convenience question second — and the two don't always point in the same direction.

The Question Most Staff Never Ask

When text is entered into a general-purpose AI tool, where does it go? For many consumer-grade AI products, the answer is that submitted content may be retained and used to improve the underlying model, unless the specific plan or agreement says otherwise. That is fundamentally different from a document staying inside a firm's own systems.

This distinction is not always obvious from the interface. A chat window looks the same whether or not the vendor is retaining what's typed into it, which is exactly why firms can't rely on staff intuition to manage this risk.

Free vs. Business-Tier Tools Are Not the Same Product

Many AI vendors offer separate consumer and business or enterprise tiers, and the confidentiality terms often differ meaningfully between them — some enterprise agreements include commitments not to train on submitted data. The free or consumer version of a tool and its enterprise counterpart can carry very different data-handling terms, even when the interface looks nearly identical. A firm that has approved an enterprise AI tool for staff use has not necessarily approved the free consumer version of the same product, and staff frequently don't realize there's a difference.

A Simple Test Before Anything Goes Into an AI Tool

Before pasting anything into an AI tool, ask whether the same information could be emailed to an unknown third party without concern. If the answer is no, it likely shouldn't go into a general-purpose AI tool the firm hasn't specifically vetted for that purpose either. Client names, case facts, and privileged communications generally fail this test with consumer-grade tools.

What a Reasonable Policy Looks Like

  • Name the specific AI tools staff are approved to use, including which tier or plan
  • State plainly what categories of information may never be entered into an unapproved tool
  • Require attorney review of any AI-assisted work product before it leaves the firm
  • Review the policy when a new tool is adopted, not just once a year

Frequently Asked Questions

Is Microsoft Copilot safer than ChatGPT for handling client information?

It depends on which version and licensing tier is in use, and how it's configured within the firm's existing Microsoft environment. The specific agreement and configuration matter more than which vendor's name is on the product.

Should firms just ban AI tools altogether to avoid the risk?

For most firms, an outright ban isn't realistic — staff will use these tools with or without approval. A workable policy paired with technical controls tends to manage the risk better than a ban that's difficult to enforce.

What's the risk if a paralegal pastes a client's case summary into a free AI tool without asking?

The concern is that the information may leave the firm's control in a way that's difficult to reverse, potentially implicating the duty of confidentiality — independent of whether anything visibly goes wrong afterward.

How does IT fit into managing this, versus it being a legal ethics matter?

The ethical obligation sits with the attorneys and the firm's policy; the technical side — controlling which AI tools are reachable from firm devices and how data can move in and out of them — is where IT support comes in.

Next Step

If you'd like a plain, specific answer about where your firm actually stands — rather than an assumption — we offer a 15-minute call to see if we're a fit. No pitch, no obligation.

Managing partners and office administrators can reach us at 325-643-8184 or through the contact form at apollocomputers.com.