Can a Law Firm Use ChatGPT Without Breaching Confidentiality?
The question is not whether your firm uses AI. Somebody there already has. The question is whether the way they are using it survives a look from the Bar.
Can a law firm use ChatGPT without breaching confidentiality?
Only with the right account and clear rules. Entering client names, case facts or privileged communications into a consumer AI tool discloses that information to a third party, which risks waiving privilege and breaching the duty of confidentiality. General legal questions with no client facts in them are a different matter and are broadly fine.
Three duties, not one
Most discussion of AI in law firms stops at confidentiality. The rules reach further than that.
Confidentiality — Model Rule 1.6
The duty covers current, former and prospective clients. Putting identifying facts into a third-party system is a disclosure. The exposure is not only the tool’s operator seeing it — it is that the material may sit outside the protection of privilege and be discoverable later.
Competence — Model Rule 1.1
Competence now includes understanding the tools you use. A lawyer who cannot say where a tool sends data, whether it trains on inputs, or who can see the output is not in a strong position if asked.
Supervision — Model Rule 5.3
This is the one firms overlook. You are responsible for the non-lawyer assistance you use, and an AI tool sits squarely in that category. Output has to be reviewed before it reaches a client or a court, and someone has to own that.
The account matters more than the tool
This is the practical heart of it. The same product behaves very differently depending on how it was signed into.
A personal account, signed up with a personal email, gives the firm no visibility, no retention terms in its favour, and no administrative control. A business or enterprise tier gives you data-handling terms, administrative oversight and inputs excluded from training. The tool did not change; the contract did.
So a firm that bans AI outright usually ends up worse off than one that approves a business tier — because the ban does not stop the behaviour, it just moves it onto personal accounts and personal phones where nothing is visible.
What is safe, what is not
Reasonably safe
Research questions with no client facts. Drafting a template or a general clause. Improving the clarity of writing that contains nothing identifying. Summarising a public document.
Not safe on a consumer account
Case facts, client names, discovery material, correspondence, anything from a matter file. Uploading a document. Connecting a tool to the firm’s email or document management system.
The category nobody thinks about
Meeting note-takers. An assistant that joins a call and records it is capturing exactly the conversations most likely to be privileged — and in Florida, recording without consent from every participant is a third-degree felony quite apart from the ethics question. We wrote that up separately.
Five things worth doing this month
- Find out what is already connected. Permissions granted to an AI tool do not expire and do not surface in any dashboard. When we ran this check on our own tenant we found ChatGPT holding read access to every file we owned, granted months earlier by one person clicking Accept. The full account is here.
- Approve one tool, on a business tier. Then remove the others rather than leaving them connected and unused.
- Write the one-page rule. Approved tools, what may never go into a prompt, who to ask about anything new. Our template is free to copy.
- Decide your position on client disclosure. Whether you tell clients you use AI is a judgement for the firm, but it should be a decision rather than an omission.
- Name someone. Rule 5.3 responsibility needs an owner. Without a name it is nobody’s job.
Where we fit
We are a small IT company in Haines City that looks after professional practices across Polk and Osceola. We do not advise on ethics rules — that is your Bar and your own judgement. What we can do is tell you, factually, which AI tools currently hold access to your firm’s email, files and calendars, what each one can reach, and who approved it. It takes about ninety seconds to run and rather longer to talk through.
If it comes back clean we will say so. Get in touch — (321) 221-7117, Monday to Friday, 8am to 6pm. Related: what a law firm should ask an IT provider.
General information, not legal advice. Consult your own Bar’s rules and opinions.
More on using AI without creating a problem
- Can employees use ChatGPT with company data?
- Is it legal to use an AI note-taker in Florida?
- Does AI on client tax data trigger section 7216?
- Can front desk staff use AI to write patient emails?
- Does AI estimating actually work for a contractor?
The practical starting point: a free one-page AI acceptable use policy you can copy and issue this week, and how we approach AI consulting.

