Is legal AI safe for client confidentiality?
It can be, but the model you pick was never the risk. The terms it runs under and who else can see the data are.
Answered in short
5 things that decide this
- 01Legal AI can be safe for client confidentiality. The safety sits in the architecture and the contract, not in which model does the work.
- 02In United States v. Heppner (S.D.N.Y., 10 February 2026), a federal court held that a defendant's chats with a consumer AI tool were not privileged. The tool's own privacy policy allowed it to use and train on the inputs.
- 03ABA Formal Opinion 512 requires you to vet a vendor's security, avoid uncritical reliance on AI output, and get informed consent that is not a boilerplate clause buried in an engagement letter.
- 04California's 2026 guidance goes further for agentic systems. You must not let an AI system send communications, transfer data, or file documents on its own, without a human review gate.
- 05Five things have to be true before client data touches a model: scoped access, written no-training terms, every vendor named, direction of counsel on the record, and private deployment where your clients' own obligations require it.
What Heppner actually held, and what it left open
Bradley Heppner used the consumer version of an AI chatbot to research his own criminal case after retaining counsel. He fed it facts he'd learned from his lawyers and generated reports on defence strategy, then shared those reports with his attorneys. Prosecutors seized roughly 31 AI-generated documents from his devices. Judge Jed Rakoff had to decide whether any of it was privileged.
It wasn't. No privilege existed, because the chats weren't confidential in the first place. Anthropic's own published terms allowed disclosure of and training on user inputs, so nothing Heppner typed had a reasonable expectation of secrecy. Work-product protection failed too, on a separate ground. Nobody had prepared the reports at counsel's direction, and they didn't reflect anyone's legal strategy. Documents Heppner wrote before he had a lawyer couldn't be cloaked in privilege later just by forwarding them.
Here's what matters when you're evaluating a vendor: the ruling turned on the terms of that specific tool, not on AI use in general. Legal commentators reading the opinion think an enterprise tool with real no-training terms and confidentiality guarantees should come out differently. Nobody decided that case, though. "Probably fine" is reasoning, not a holding, so treat it as the open question it still is.
What ABA Opinion 512 and California actually require
ABA Formal Opinion 512 (29 July 2024) is still the baseline rule. You need a client's consent before you feed their facts into a self-learning tool. And a boilerplate clause isn't enough. Consent needs your own words on the risk, not a line buried in an engagement letter nobody reads twice. It also bars leaning on AI output with no check. Vetting a vendor's security becomes your own job now, under the same rules that already cover supervising a paralegal.
California's 2026 rewrite is the sharpest guidance out there, because it was written for agents, not chat tools. You must not let an agent send client data on its own. No emails, no filings, no data transfers, unless a person checks first. It goes further still. An AI system must not file papers, talk to the court, or speak for you. The more the system can do alone, the more you have to watch it.
Read together, both rules point at the same place. This isn't really about whether an AI vendor seems trustworthy. It's about whether you built the system so a lawyer can watch it, prove what happened, and stop it before it acts alone.
- Scoped accessLimited to the matter, not the whole DMS or mailbox
- No-training termsIn writing, and you can produce the contract on request
- Every vendor namedThe model provider, the logging layer, the eval pipeline — all of them
- Direction of counselOn the record, ideally in the prompt or task itself
- Private deploymentWhere a client's own obligations require it
Skip one, and a court or a regulator has an opening. Satisfy all five, and the model choice stops mattering as much as the vendor's promises suggest.
Where does the data travel? Ask any vendor this, including us
You don't need to read a privacy policy end to end. Six questions cover it, and a vendor who can't answer them plainly hasn't built the thing you're being asked to buy.
- 01Which model provider processes this data, and under which contract terms — can you show me the clause?
- 02Does that provider train on our inputs, by default or by opt-out, and who confirmed that in writing?
- 03What other vendors touch the data on the way through: logging, observability, prompt caching, eval pipelines?
- 04Is access scoped to the matter, or does the system see everything in the DMS and mailbox once it's connected?
- 05Can the system take an action on its own — send an email, file a document, transfer data — without a person approving it first?
- 06If we needed to prove in a privilege log where this data went, could you produce that log today?
What a lawyer still has to do
None of this is delegable, and no vendor's architecture changes that. You still review output before it reaches a filing or a client. Explaining the actual risk to a client is still yours to do, not a clause to point at. And you still supervise associates and staff the way Rule 5.3 already requires, so your system needs a supervisor's view, not only a user's. Software can make the compliant path the default and the violation visible. It can't make the judgement for you. California's guidance says exactly that: a lawyer's professional judgment cannot be delegated to AI, and it remains the lawyer's responsibility at all times.
Related questions
01Is it safe to put client information into ChatGPT?+
Not the consumer version. That's close to the exact fact pattern that lost in Heppner: a consumer AI tool whose published terms allow disclosure and training on inputs. An enterprise tier with written no-training terms is a different question. Even then, you still need the same vendor vetting Opinion 512 requires before client data goes near it.
02Does using AI on a case waive privilege?+
It can, and Heppner is the proof. Privilege isn't lost by storing data badly. You lose it by disclosing data to a third party under terms that don't protect it. So the question that matters is who else received the data and under what contract, not whether the file was encrypted.
03Does a consent clause in our engagement letter cover us?+
No. ABA Opinion 512 says explicitly that boilerplate provisions in an engagement letter are not informed consent. You have to explain the actual risk yourself, and your system should record what was disclosed to which client and when.
04What's different about agentic AI here?+
California's 2026 guidance treats it as a separate risk. Give an agent standing access to email, a DMS, or a calendar, and it reaches every matter you have open, not only the one it's working on. The state's rule bars letting such a system send, file, or transfer anything without a human approving it first.
05Do we need a private deployment, or is a major vendor's enterprise tier enough?+
Check your clients' own contracts first; they often decide it for you. Some corporate clients' outside-counsel guidelines already specify where data may be processed and by whom. That pushes the answer toward private deployment, regardless of what a vendor's standard enterprise terms offer everyone else.
06Who is actually liable if the AI gets something wrong?+
You are, against your own licence, not the vendor. That's why Opinion 512 bars uncritical reliance and why a review step before anything filed or sent isn't optional. A system can flag and route; the accountability stays with the person holding the bar card.
Related
- Legal hub →AI, automation and custom software for law firms, built around the system you already run.
- Legal document automation →Drafting pipelines built with the same five rules, privilege kept.
- AI intake for law firms →Where the intake line has to route, not advise, and why that boundary matters.
- Is AI intake safe for a law firm? →The same architecture question, applied to the first call.
- Legal AI should route, not advise →The boundary between logistics and legal advice, argued in full.

