home  /  confidentiality & security
department of confidentiality & security

What happens to the client’s material.

The duty of confidentiality is unchanged. What is new is how easily it is engaged by an action that feels like using a search box.

begin here

Where is your firm?

Start a conversation with the AI Adoption Concierge, already scoped to confidentiality & security. Choose the question closest to yours, or describe your situation directly.

AI Adoption Conciergeconfidentiality & security · orientation, not legal or ethics advice
Tell me which tools are in use and what material is going into them. I'll help you scope the questions worth asking. I can't advise on your confidentiality obligations — that is for your own counsel.

Of all the duties generative AI touches, confidentiality is the one most directly and most easily engaged. Putting a client document into a tool is a disclosure to a third party, and whether that is permissible turns on terms most people never read — whether inputs are retained, whether they may be used to train models, who the subprocessors are, and where the data sits. ABA Formal Opinion 512 addresses confidentiality among the duties generative AI engages, and a common reading is that client information should not be placed into tools whose terms permit training on it. That single question eliminates a large number of products before capability is even discussed, which is why it belongs at the start of an evaluation rather than the end.

specialization areas

Areas in this part of the practice.

What the terms permit, how to diligence the vendor, and the privilege questions that remain genuinely open.

methodology

How this department investigates.

How the Institute approaches confidentiality — the questions to ask, not answers about your obligations.

Terms reviewRetention, training rights, subprocessors, jurisdiction and termination — read before the demo, not after.
Vendor diligenceThe questions that separate a serious provider from a wrapper, and the answers worth getting in writing.
Tiering by sensitivityWhich material may go into which tool, stated concretely enough to apply without a judgement call.
Client obligations auditOutside counsel guidelines that already impose terms, frequently stricter than the firm's own position.
Privilege considerationsThe open questions, framed honestly rather than resolved, because they are not settled.
Exposure assessmentWhat to do when material has already gone somewhere it should not have.
common questions

Confidentiality — the questions firms ask.

Can client material go into an AI tool at all?

It depends entirely on the tool's terms and on the firm's obligations, which is why the terms question comes first. The concern the guidance identifies most directly is tools whose terms permit inputs to be retained or used to train models — a common reading of the confidentiality discussion in ABA Formal Opinion 512 is that client information should not go into those. Enterprise tiers of many products contract differently from their consumer equivalents on exactly this point, which is why "we use the same product at home" is not an answer to the question.

Does consent solve it?

It can be part of the answer and it is not a universal solvent. Informed client consent is relevant to confidentiality obligations in many circumstances, and firms increasingly address AI use in engagement letters partly for this reason. But consent obtained without the client understanding what happens to their material is thin, consent does not address obligations owed to third parties whose information appears in the documents, and it does not resolve the privilege questions. Consent is a component of a position, not a substitute for having one.

What about privilege?

This is genuinely unsettled and firms should be wary of anyone who says otherwise. Disclosure to a third party can bear on privilege, and whether processing a document through a vendor's system constitutes the kind of disclosure that matters — and how that interacts with existing doctrine covering vendors and agents — has not been comprehensively resolved. Most firms manage it conservatively: enterprise terms with no training rights, contractual confidentiality commitments, and restraint about what goes into any tool. That posture reflects uncertainty rather than a settled answer.

Are the enterprise tiers actually different?

Usually materially so, and it is worth verifying rather than assuming. Enterprise and business agreements commonly differ from consumer terms on training rights, retention periods, data residency and audit — which is the whole reason they exist. What matters is reading the agreement that will actually govern the firm's use, not the marketing page describing the tier, and getting the material commitments in the contract rather than in a support article the vendor can revise unilaterally.

Do you know what the terms permit?

Describe the tools in use. The Institute will help you work out what questions to ask.

AI adoption conciergeorientation · not legal or ethics advice
Tell me which tools are in use and what material is going into them. I'll help you scope the questions worth asking. I can't advise on your confidentiality obligations — that is for your own counsel.