
Confidentiality is one of a lawyer’s most fundamental duties. Clients trust you with sensitive information, and protecting it is sacrosanct. AI tools create a serious, often underappreciated risk here: putting client or confidential information into them can breach confidentiality and create data risks. Every lawyer using AI must understand and manage this. Let me explain the confidentiality and data risks of using AI, and how to protect against them.
Quick answer
Using AI can create serious confidentiality and data risks because putting confidential or client information into AI tools may expose or mishandle that information, potentially breaching your fundamental duty of confidentiality, as well as privilege and data-protection obligations.
The core risk is that when you input information into an AI tool, you may not control where that data goes, how it is stored, processed or used. So inputting confidential or client information can risk exposing it or breaching confidentiality.
To protect against this:
- Do not input confidential or client information into AI tools without proper safeguards and confidence that it is handled appropriately and compliantly.
- Understand how any tool handles data before using it with sensitive information, including where the data goes, how it is stored and used, and whether the tool is appropriate for confidential material.
- Use appropriate, compliant tools and safeguards for any sensitive work.
- Comply with your confidentiality, privilege and data-protection obligations.
- When in doubt, do not input sensitive information.
Protecting client confidentiality and data is a fundamental duty that AI use must never compromise. The keys are: never input confidential or client data without proper safeguards, understand how tools handle data, use compliant tools and safeguards, comply with your duties, and protect confidentiality when you are unsure. This is general guidance, not legal or professional advice. Verify your obligations and any tool’s data handling.
Why this is a serious risk
Confidentiality is fundamental to the lawyer-client relationship and your professional duties, and often involves legal privilege. Clients’ data may also be subject to data-protection obligations.
The risk with AI is that when you input information into a tool, you may not control what happens to it, where it goes, how it is stored, processed or used, or whether it could be exposed. So inputting confidential or client information into AI tools can risk breaching confidentiality, privilege and data-protection duties.
Because this duty is so fundamental and the risk so real, this is one of the most important things to get right when using AI as a lawyer.
How to protect against it
- Don’t input confidential or client data without proper safeguards. The simplest, safest rule is: do not put confidential or client information into AI tools unless you have proper safeguards and confidence that it will be handled appropriately and compliantly. When unsure, do not input it.
- Understand how a tool handles data. Before using any tool with sensitive information, understand how it handles data, where it goes, how it is stored, processed and used, and whether it is appropriate for confidential material. Do not assume it is safe.
- Use appropriate, compliant tools and safeguards. For any work involving sensitive information, use tools and arrangements that are appropriate and compliant for confidential data, with proper safeguards.
- Comply with your duties. Ensure your use complies with your confidentiality, privilege and data-protection obligations, as well as any applicable rules and firm policies.
- Protect confidentiality when in doubt. When you are unsure, do not input sensitive information. The convenience of using AI should never take priority over protecting client confidentiality.
YLCC ACTION STEP: Adopt a firm rule: never input confidential or client information into AI tools without proper safeguards and confidence that it is handled appropriately and compliantly. Before using any tool with sensitive material, understand how it handles data. Comply with your confidentiality, privilege and data-protection duties, and when in doubt, do not input the information. Protecting client confidentiality and data is a fundamental duty that AI must never compromise.
If this is you
If you have pasted client information into AI tools: Stop and reconsider. This can risk confidentiality. Going forward, do not input confidential or client information without proper safeguards, and understand how any tool handles data.
If you assume AI tools are safe for confidential data: Don’t assume. Understand how a specific tool handles data before using it with sensitive information, and use only appropriate, compliant tools with proper safeguards. When unsure, do not input it.
If you are unsure about your obligations: Take confidentiality, privilege and data protection seriously, verify your duties and any firm policies, and comply. Protecting client data is fundamental.
PLEASE DON’T DO THIS: Please don’t input confidential or client information into AI tools without proper safeguards and confidence that it is handled appropriately. This can breach your fundamental duty of confidentiality, as well as privilege and data-protection obligations. Please don’t assume tools are safe for sensitive data without understanding how they handle it. When in doubt, do not input sensitive information. Protect client confidentiality and data above convenience, always.
FAQs
- What are the confidentiality risks of using AI? Inputting confidential or client information into AI tools can risk exposing or mishandling it, potentially breaching your fundamental duty of confidentiality, as well as privilege and data-protection obligations, because you may not control where that data goes or how it is used.
- Can I put client information into AI tools? Not without proper safeguards and confidence that it is handled appropriately and compliantly. When in doubt, do not input it. Protecting confidentiality is fundamental.
- How do I protect confidentiality when using AI? Don’t input confidential or client data without safeguards, understand how any tool handles data before using it with sensitive material, use appropriate and compliant tools and safeguards, comply with your duties, and protect confidentiality when you are unsure.
- Why is this so important? Because confidentiality, and often privilege and data protection, is a fundamental duty, and a breach can seriously harm clients and your professional standing. AI use must never compromise it.
- What if I’m unsure whether a tool is safe? Do not input sensitive information. Understand the tool’s data handling first and, when in doubt, protect confidentiality by not inputting it.



