The duty of confidentiality is unchanged. What is new is how easily it is engaged by an action that feels like using a search box.
Start a conversation with the AI Adoption Concierge, already scoped to confidentiality & security. Choose the question closest to yours, or describe your situation directly.
Of all the duties generative AI touches, confidentiality is the one most directly and most easily engaged. Putting a client document into a tool is a disclosure to a third party, and whether that is permissible turns on terms most people never read — whether inputs are retained, whether they may be used to train models, who the subprocessors are, and where the data sits. ABA Formal Opinion 512 addresses confidentiality among the duties generative AI engages, and a common reading is that client information should not be placed into tools whose terms permit training on it. That single question eliminates a large number of products before capability is even discussed, which is why it belongs at the start of an evaluation rather than the end.
What the terms permit, how to diligence the vendor, and the privilege questions that remain genuinely open.
The one question that eliminates products before capability is even discussed.
investigateThe questions that separate a serious provider from a thin wrapper over somebody else’s model.
investigateThe genuinely unsettled area — and the reason most firms manage it conservatively.
investigateHow the Institute approaches confidentiality — the questions to ask, not answers about your obligations.
It depends entirely on the tool's terms and on the firm's obligations, which is why the terms question comes first. The concern the guidance identifies most directly is tools whose terms permit inputs to be retained or used to train models — a common reading of the confidentiality discussion in ABA Formal Opinion 512 is that client information should not go into those. Enterprise tiers of many products contract differently from their consumer equivalents on exactly this point, which is why "we use the same product at home" is not an answer to the question.
It can be part of the answer and it is not a universal solvent. Informed client consent is relevant to confidentiality obligations in many circumstances, and firms increasingly address AI use in engagement letters partly for this reason. But consent obtained without the client understanding what happens to their material is thin, consent does not address obligations owed to third parties whose information appears in the documents, and it does not resolve the privilege questions. Consent is a component of a position, not a substitute for having one.
This is genuinely unsettled and firms should be wary of anyone who says otherwise. Disclosure to a third party can bear on privilege, and whether processing a document through a vendor's system constitutes the kind of disclosure that matters — and how that interacts with existing doctrine covering vendors and agents — has not been comprehensively resolved. Most firms manage it conservatively: enterprise terms with no training rights, contractual confidentiality commitments, and restraint about what goes into any tool. That posture reflects uncertainty rather than a settled answer.
Usually materially so, and it is worth verifying rather than assuming. Enterprise and business agreements commonly differ from consumer terms on training rights, retention periods, data residency and audit — which is the whole reason they exist. What matters is reading the agreement that will actually govern the firm's use, not the marketing page describing the tier, and getting the material commitments in the contract rather than in a support article the vendor can revise unilaterally.
Describe the tools in use. The Institute will help you work out what questions to ask.