Confidentiality, Privilege and Client Data in AI Tools
Putting client information into a cloud-based AI tool creates confidentiality and privilege risks that many practitioners underestimate. The rules are strict and the consequences for breach are serious.
Confidentiality is a foundational duty. You must not disclose client information to third parties without consent. Many AI tools are operated by vendors who have no confidentiality agreement with your firm or your client. When you input a contract, email thread or file into such a tool, you are disclosing the information. The vendor may log the interaction, use it for system improvement, store it for a period of time, or pass it to sub-processors. This is a breach of confidentiality unless the client has explicitly consented.
Legal professional privilege is more complex. Privilege protects communications between lawyer and client made for the purposes of obtaining legal advice. It also protects communications made in contemplation of legal proceedings. Privilege can be waived by disclosure to a third party. If you send a privileged email or a privileged document to an AI tool operated by a vendor, you may lose privilege if the disclosure was not necessary to the purpose for which privilege is claimed. A court might hold that privilege has been waived and order disclosure of the material.
There is no blanket exception for AI tools. The fact that the tool is used for efficiency or cost saving does not justify disclosure. The fact that the vendor has a privacy policy does not justify disclosure. The fact that the input is encrypted in transit does not eliminate the privilege issue. If you disclose information that would be privileged between you and the client to a third party, and that disclosure was not essential to the legal purpose, privilege is lost.
The safe approach is to assume that you cannot put client data into a public AI tool. Instead, obtain client consent before using any tool. A simple email saying “I plan to use an AI system to assist with the drafting of your contract. The vendor is XYZ Corp. Are you comfortable with this?” gives you protection. The client’s reply consenting to this use provides a defence if confidentiality is questioned later.

For privileged material, seek explicit consent and document it. Many clients will not understand the privilege implications and will assume that “using AI” means using a tool with the same privacy protections as your firm’s own systems. They do not. So explain the difference. State clearly that using a cloud AI tool means the vendor will see the material. Ask the client whether they consent to this disclosure for purposes of obtaining the legal advice you are providing. Document the consent in writing.
Some firms implement technical controls. They may use AI tools that run on their own secure servers rather than accessing public cloud services. They may use local language models that do not transmit data outside the firm’s network. These approaches are more expensive and slower but eliminate vendor-access risk. The trade-off is between convenience and confidentiality.
For client communications, err on the side of caution. Emails between you and your client about legal matters should not be sent to an AI tool without explicit consent. The same applies to internal file notes that discuss client information or legal strategy. If the information is not necessary for the AI task, do not include it. Redact sensitive details where possible.
The Law Society and Bar Standards Board expect that you understand the confidentiality risks of the tools you use. If you cannot explain to a client why it is safe to input their information into a tool, then it is not safe. If a complaint is later made about confidentiality breach, you will be asked to prove that you obtained informed consent. “The vendor has a privacy policy” is not proof. “The client agreed by email” is proof.
