Hashlogics
Answers

Is legal AI safe for client confidentiality?

It can be, but the model you pick was never the risk. The terms it runs under and who else can see the data are.

Answered in short

5 things that decide this

  1. 01Legal AI can be safe for client confidentiality. The safety sits in the architecture and the contract, not in which model does the work.
  2. 02In United States v. Heppner (S.D.N.Y., 10 February 2026), a federal court held that a defendant's chats with a consumer AI tool were not privileged. The tool's own privacy policy allowed it to use and train on the inputs.
  3. 03ABA Formal Opinion 512 requires you to vet a vendor's security, avoid uncritical reliance on AI output, and get informed consent that is not a boilerplate clause buried in an engagement letter.
  4. 04California's 2026 guidance goes further for agentic systems. You must not let an AI system send communications, transfer data, or file documents on its own, without a human review gate.
  5. 05Five things have to be true before client data touches a model: scoped access, written no-training terms, every vendor named, direction of counsel on the record, and private deployment where your clients' own obligations require it.
The case that changed the question

What Heppner actually held, and what it left open

Bradley Heppner used the consumer version of an AI chatbot to research his own criminal case after retaining counsel. He fed it facts he'd learned from his lawyers and generated reports on defence strategy, then shared those reports with his attorneys. Prosecutors seized roughly 31 AI-generated documents from his devices. Judge Jed Rakoff had to decide whether any of it was privileged.

It wasn't. No privilege existed, because the chats weren't confidential in the first place. Anthropic's own published terms allowed disclosure of and training on user inputs, so nothing Heppner typed had a reasonable expectation of secrecy. Work-product protection failed too, on a separate ground. Nobody had prepared the reports at counsel's direction, and they didn't reflect anyone's legal strategy. Documents Heppner wrote before he had a lawyer couldn't be cloaked in privilege later just by forwarding them.

Here's what matters when you're evaluating a vendor: the ruling turned on the terms of that specific tool, not on AI use in general. Legal commentators reading the opinion think an enterprise tool with real no-training terms and confidentiality guarantees should come out differently. Nobody decided that case, though. "Probably fine" is reasoning, not a holding, so treat it as the open question it still is.

The rules that now govern the answer

What ABA Opinion 512 and California actually require

ABA Formal Opinion 512 (29 July 2024) is still the baseline rule. You need a client's consent before you feed their facts into a self-learning tool. And a boilerplate clause isn't enough. Consent needs your own words on the risk, not a line buried in an engagement letter nobody reads twice. It also bars leaning on AI output with no check. Vetting a vendor's security becomes your own job now, under the same rules that already cover supervising a paralegal.

California's 2026 rewrite is the sharpest guidance out there, because it was written for agents, not chat tools. You must not let an agent send client data on its own. No emails, no filings, no data transfers, unless a person checks first. It goes further still. An AI system must not file papers, talk to the court, or speak for you. The more the system can do alone, the more you have to watch it.

Read together, both rules point at the same place. This isn't really about whether an AI vendor seems trustworthy. It's about whether you built the system so a lawyer can watch it, prove what happened, and stop it before it acts alone.

Five rules the architecture has to satisfyLive
  1. Scoped accessLimited to the matter, not the whole DMS or mailbox
  2. No-training termsIn writing, and you can produce the contract on request
  3. Every vendor namedThe model provider, the logging layer, the eval pipeline — all of them
  4. Direction of counselOn the record, ideally in the prompt or task itself
  5. Private deploymentWhere a client's own obligations require it

Skip one, and a court or a regulator has an opening. Satisfy all five, and the model choice stops mattering as much as the vendor's promises suggest.

Data travel checklist

Where does the data travel? Ask any vendor this, including us

You don't need to read a privacy policy end to end. Six questions cover it, and a vendor who can't answer them plainly hasn't built the thing you're being asked to buy.

  • 01Which model provider processes this data, and under which contract terms — can you show me the clause?
  • 02Does that provider train on our inputs, by default or by opt-out, and who confirmed that in writing?
  • 03What other vendors touch the data on the way through: logging, observability, prompt caching, eval pipelines?
  • 04Is access scoped to the matter, or does the system see everything in the DMS and mailbox once it's connected?
  • 05Can the system take an action on its own — send an email, file a document, transfer data — without a person approving it first?
  • 06If we needed to prove in a privilege log where this data went, could you produce that log today?
What doesn't change

What a lawyer still has to do

None of this is delegable, and no vendor's architecture changes that. You still review output before it reaches a filing or a client. Explaining the actual risk to a client is still yours to do, not a clause to point at. And you still supervise associates and staff the way Rule 5.3 already requires, so your system needs a supervisor's view, not only a user's. Software can make the compliant path the default and the violation visible. It can't make the judgement for you. California's guidance says exactly that: a lawyer's professional judgment cannot be delegated to AI, and it remains the lawyer's responsibility at all times.

Questions, answered
01Is it safe to put client information into ChatGPT?+

Not the consumer version. That's close to the exact fact pattern that lost in Heppner: a consumer AI tool whose published terms allow disclosure and training on inputs. An enterprise tier with written no-training terms is a different question. Even then, you still need the same vendor vetting Opinion 512 requires before client data goes near it.

02Does using AI on a case waive privilege?+

It can, and Heppner is the proof. Privilege isn't lost by storing data badly. You lose it by disclosing data to a third party under terms that don't protect it. So the question that matters is who else received the data and under what contract, not whether the file was encrypted.

03Does a consent clause in our engagement letter cover us?+

No. ABA Opinion 512 says explicitly that boilerplate provisions in an engagement letter are not informed consent. You have to explain the actual risk yourself, and your system should record what was disclosed to which client and when.

04What's different about agentic AI here?+

California's 2026 guidance treats it as a separate risk. Give an agent standing access to email, a DMS, or a calendar, and it reaches every matter you have open, not only the one it's working on. The state's rule bars letting such a system send, file, or transfer anything without a human approving it first.

05Do we need a private deployment, or is a major vendor's enterprise tier enough?+

Check your clients' own contracts first; they often decide it for you. Some corporate clients' outside-counsel guidelines already specify where data may be processed and by whom. That pushes the answer toward private deployment, regardless of what a vendor's standard enterprise terms offer everyone else.

06Who is actually liable if the AI gets something wrong?+

You are, against your own licence, not the vendor. That's why Opinion 512 bars uncritical reliance and why a review step before anything filed or sent isn't optional. A system can flag and route; the accountability stays with the person holding the bar card.

By Abdul Basit, CEO, HashlogicsUpdated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter