AI in Law & Legal Services · AI and Attorney Professional Responsibility & Ethics
Can using AI violate a lawyer's duty of confidentiality?
Yes — entering client information into an AI tool that stores, retains, or trains on that data without adequate safeguards can violate an attorney's duty of confidentiality.
Legal disclaimer
This page provides general information only and is not legal advice. Laws vary by jurisdiction and change over time. Consult a licensed attorney in your jurisdiction before making decisions based on this content.
Key takeaways
- The duty of confidentiality generally requires attorneys to protect client information from unauthorized disclosure, including disclosure to third-party technology providers.
- Entering confidential client details into a consumer AI tool without understanding its data handling practices creates meaningful risk of an ethical violation.
- Bar guidance generally advises attorneys to understand how an AI tool stores, uses, and potentially shares uploaded information before entering client data.
- Enterprise legal AI tools with contractual data protections are generally viewed as lower-risk than free, general-purpose consumer AI products.
Confidentiality obligations extend to third-party tools
An attorney’s duty of confidentiality has long extended beyond simply not gossiping about a client’s matter — it also covers how information is handled when shared with third parties, including vendors and service providers a lawyer relies on to do their work. Generative AI tools fall squarely into this category. When an attorney types client information into an AI tool, that information is being transmitted to and processed by a third-party system, which raises the same category of confidentiality concern that has long applied to using any outside vendor or service.
Where the real risk lies
The risk isn’t inherent to AI as a concept — it depends heavily on what a specific tool does with the data it receives. A consumer-facing AI chatbot with a general terms of service that permits using submitted content to improve its models presents meaningfully more risk than an enterprise legal AI product with a contractual commitment not to use client data for training and with defined data retention and security practices. An attorney who pastes details of a confidential matter into a general-purpose AI tool without understanding its data policies could be found to have failed in their duty to protect that information, depending on what the tool actually does with it.
What bar guidance generally recommends
Rather than telling attorneys to avoid AI altogether, bar association guidance on this topic generally focuses on due diligence: understanding, at least at a general level, how a given AI tool handles submitted data before using it with confidential client information, and favoring tools with clear, verifiable data protection commitments for sensitive work. Some attorneys also take the added step of anonymizing or redacting identifying details before using an AI tool for research or drafting assistance, though care is still needed to ensure that context alone doesn’t reveal who the client is.
Bottom line
Yes, using AI can violate an attorney’s duty of confidentiality if client information is shared with a tool that doesn’t adequately protect it — which is why bar guidance emphasizes vetting a tool’s data handling practices before entering any confidential details.
Go deeper
Important caveats
- Specific confidentiality obligations and how they apply can vary somewhat by state, and this is a fast-evolving area of ethics guidance.
- This is general information, not legal advice about a specific attorney's confidentiality obligations or a specific tool.
Frequently asked questions
Is it ever acceptable to use client information with an AI tool?
It can be, if the attorney has taken reasonable steps to understand the tool's data handling practices and has appropriate safeguards or client consent in place, consistent with existing confidentiality obligations.
Do bar associations recommend avoiding AI tools altogether for confidential matters?
Generally no — most guidance focuses on understanding and vetting a given tool's data practices rather than avoiding AI use altogether.
Does anonymizing client data before using AI eliminate the risk?
Removing identifying details can reduce risk, but attorneys still need to ensure that what remains doesn't inadvertently reveal confidential information through context.
Related questions
- Do Attorneys Have A Duty Of Technological Competence Regarding AI?
- Must Lawyers Disclose AI Use To Their Clients?
- What Ethical Rules Govern Attorneys' Use Of Generative AI?
- What Has The American Bar Association Said About AI In Legal Practice?
- Are AI Contract Review Tools Safe To Use With Confidential Agreements?
- Can a Lawyer Be Sued for Malpractice for Using AI-Generated Content?
Sources
- [1]Model Rules of Professional Conduct and ethics guidance — American Bar Association
- [2]Legal industry news and technology coverage — ABA Journal
Written by Editorial Team
Last updated July 28, 2026
Get one well-sourced answer a week
No spam. Unsubscribe anytime.