Skip to content
Daily AI Intel

AI in Law & Legal Services · AI and Attorney Professional Responsibility & Ethics

Can using AI violate a lawyer's duty of confidentiality?

Yes — entering client information into an AI tool that stores, retains, or trains on that data without adequate safeguards can violate an attorney's duty of confidentiality.

Legal disclaimer

This page provides general information only and is not legal advice. Laws vary by jurisdiction and change over time. Consult a licensed attorney in your jurisdiction before making decisions based on this content.

Key takeaways

  • The duty of confidentiality generally requires attorneys to protect client information from unauthorized disclosure, including disclosure to third-party technology providers.
  • Entering confidential client details into a consumer AI tool without understanding its data handling practices creates meaningful risk of an ethical violation.
  • Bar guidance generally advises attorneys to understand how an AI tool stores, uses, and potentially shares uploaded information before entering client data.
  • Enterprise legal AI tools with contractual data protections are generally viewed as lower-risk than free, general-purpose consumer AI products.

Confidentiality obligations extend to third-party tools

An attorney’s duty of confidentiality has long extended beyond simply not gossiping about a client’s matter — it also covers how information is handled when shared with third parties, including vendors and service providers a lawyer relies on to do their work. Generative AI tools fall squarely into this category. When an attorney types client information into an AI tool, that information is being transmitted to and processed by a third-party system, which raises the same category of confidentiality concern that has long applied to using any outside vendor or service.

Where the real risk lies

The risk isn’t inherent to AI as a concept — it depends heavily on what a specific tool does with the data it receives. A consumer-facing AI chatbot with a general terms of service that permits using submitted content to improve its models presents meaningfully more risk than an enterprise legal AI product with a contractual commitment not to use client data for training and with defined data retention and security practices. An attorney who pastes details of a confidential matter into a general-purpose AI tool without understanding its data policies could be found to have failed in their duty to protect that information, depending on what the tool actually does with it.

What bar guidance generally recommends

Rather than telling attorneys to avoid AI altogether, bar association guidance on this topic generally focuses on due diligence: understanding, at least at a general level, how a given AI tool handles submitted data before using it with confidential client information, and favoring tools with clear, verifiable data protection commitments for sensitive work. Some attorneys also take the added step of anonymizing or redacting identifying details before using an AI tool for research or drafting assistance, though care is still needed to ensure that context alone doesn’t reveal who the client is.

Bottom line

Yes, using AI can violate an attorney’s duty of confidentiality if client information is shared with a tool that doesn’t adequately protect it — which is why bar guidance emphasizes vetting a tool’s data handling practices before entering any confidential details.

Go deeper

Important caveats

  • Specific confidentiality obligations and how they apply can vary somewhat by state, and this is a fast-evolving area of ethics guidance.
  • This is general information, not legal advice about a specific attorney's confidentiality obligations or a specific tool.

Frequently asked questions

Is it ever acceptable to use client information with an AI tool?

It can be, if the attorney has taken reasonable steps to understand the tool's data handling practices and has appropriate safeguards or client consent in place, consistent with existing confidentiality obligations.

Do bar associations recommend avoiding AI tools altogether for confidential matters?

Generally no — most guidance focuses on understanding and vetting a given tool's data practices rather than avoiding AI use altogether.

Does anonymizing client data before using AI eliminate the risk?

Removing identifying details can reduce risk, but attorneys still need to ensure that what remains doesn't inadvertently reveal confidential information through context.

ET

Written by Editorial Team

Last updated July 28, 2026

Get one well-sourced answer a week

No spam. Unsubscribe anytime.