Can Law Firms Use ChatGPT with Confidential Client Information?
A law firm can use generative AI tools — ChatGPT included — for client work, but the tier matters more than the brand, and no tool choice suspends the profession's two oldest protections. ABA Formal Opinion 512 (July 29, 2024) is the controlling ethics guidance: before inputting information relating to a representation, Model Rule 1.6 demands a fact-driven risk evaluation, and for self-learning tools, the client's informed consent. The part most competing summaries miss is that this entire analysis is the ethics duty only — evidentiary privilege is a separate doctrine with a separate failure mode, and choosing a tool settles nothing about it. As of 2026-08-28, this guide separates the two duties, states what Opinion 512 actually requires, and turns both into a review checklist.
This page is general information about published professional-conduct materials, not legal advice, and reading it creates no lawyer-client relationship. Decisions about confidentiality, client consent, and privilege in a specific matter belong with the firm's own counsel.
Two duties, not one
Confidentiality and privilege are two different duties with two different failure modes, and most pages on this question conflate them. The ethics duty is broad, binds the lawyer, and is what Opinion 512 analyzes. Privilege is narrow, belongs to the client, and is decided by courts under waiver doctrine — where disclosure to a third party is the classic failure. A tool that satisfies one analysis has said nothing about the other.
| Ethics confidentiality (Model Rule 1.6) | Evidentiary privilege (evidence law) | |
|---|---|---|
| Where it comes from | A professional-conduct rule: Model Rule 1.6 as adopted by the lawyer's licensing jurisdiction. The duty binds the lawyer. | A doctrine of evidence law — common law in federal practice, codified by statute in many states — developed case by case. The privilege belongs to the client. |
| What it covers | All information relating to the representation of a client, regardless of its source — a deliberately broad category. | Confidential communications between lawyer and client made for the purpose of seeking or giving legal advice — a much narrower set. |
| How it fails | Revealing the information without informed consent, implied authorization, or an exception — or failing to make reasonable efforts against inadvertent or unauthorized disclosure or access (Rule 1.6(c)). | Voluntary disclosure of the communication to a third party outside the protected relationship can waive it. Waiver is argued by a litigation opponent and decided on the specific facts. |
| Who decides | A disciplinary authority, applying the jurisdiction's version of the rule to the lawyer's conduct. | A court, in a discovery or evidentiary dispute, applying waiver doctrine to what actually happened with the specific communication. |
| What AI use has to do with it | Inputting representation information into a generative AI tool is exactly the act Opinion 512 analyzes: evaluate the risk of disclosure and access, read the tool's terms, and obtain informed consent where the opinion requires it. | Whether routing a communication through a third-party AI tool amounts to disclosure that waives privilege is a separate, fact-specific question. No tool selection answers it; the firm's own counsel does. |
On privilege, one thing can be said plainly and should be: no vendor architecture — ours included — can guarantee that privilege attaches or survives. Whether a particular use of a particular tool waives privilege for a particular communication is fact-specific and belongs with the firm's own counsel. Any vendor telling a firm that its deployment model settles the privilege question is answering a question that is not the vendor's to answer.
What Opinion 512 actually requires
The opinion creates no new rule. It walks the existing duties — competence, confidentiality, communication, candor, supervision, and fees — and states how each one reaches generative AI use. Cited here as the opinion states them, not as vendor paraphrase.
01Competence — Model Rule 1.1
- What the opinion says:
- Lawyers need not become generative AI experts, but must have a reasonable understanding of the capabilities and limitations of the specific tool they use — through self-study or the expertise of others — and the opinion is explicit that this is not a static undertaking. Uncritical reliance on a tool's output, without an appropriate degree of independent verification or review, could violate the duty.
- What that means in practice:
- Name the tool, the tier, and the tasks it is approved for; assign an owner to track how the tool changes; and set the review standard for outputs by task, not firm-wide.
02Confidentiality — Model Rule 1.6
- What the opinion says:
- Before inputting information relating to a representation, lawyers must evaluate the risk that it will be disclosed to or accessed by others outside the firm — and by others inside the firm who should not see it. The analysis is fact-driven: it depends on the client, the matter, the task, and the tool. For self-learning tools whose output could disclose representation information, the opinion requires the client's informed consent before inputting it — and boilerplate engagement-letter provisions are not sufficient. As a baseline, all lawyers should read and understand the Terms of Use, privacy policy, and related contractual terms of any tool they use, consulting IT or cybersecurity professionals where needed.
- What that means in practice:
- Run the risk evaluation per use case and write it down. Where the tool self-learns, treat informed consent as a gate, not a footnote in the engagement letter.
03Communication — Model Rule 1.4
- What the opinion says:
- Whether lawyers must disclose their use of generative AI to clients depends on the facts, and the opinion is explicit that its examples are not exhaustive. Disclosure is required when the client asks, when the engagement terms require it, and when informed consent is needed under Rule 1.6. Separately, the opinion identifies situations that call for consultation with the client: when the tool's use is relevant to the basis of the fee, and when its output will influence a significant decision in the representation.
- What that means in practice:
- Decide the disclosure posture in the engagement letter, where the opinion suggests such disclosures logically live — not matter by matter under pressure.
04Candor and meritorious claims — Model Rules 3.1, 3.3, 8.4(c)
- What the opinion says:
- Output must be reviewed before it reaches a court: the issues that have arisen include citations to nonexistent opinions, inaccurate analysis of authority, and misleading arguments. Even an unintentional misstatement to a court can involve a misrepresentation, and some courts now require lawyers to disclose their use of generative AI.
- What that means in practice:
- Make citation and authority verification a named step in any filing workflow that used a generative tool, and check the local court's standing orders.
05Supervision — Model Rules 5.1 and 5.3
- What the opinion says:
- Managerial lawyers must establish clear policies on the firm's permissible use of generative AI, and supervisory lawyers must make reasonable efforts to ensure lawyers and nonlawyers comply — including training on the ethical and practical aspects and on secure data handling. The opinion carries the cloud-era vendor diligence forward: ensure the tool is configured to preserve confidentiality and security, investigate its security measures and policies, and determine whether it retains submitted information both before and after the services are discontinued, or asserts proprietary rights to it.
- What that means in practice:
- Ship the written policy and the training before the tool, and run vendor diligence with the same instrument you would use for any provider that touches client information.
06Fees — Model Rule 1.5
- What the opinion says:
- Hourly lawyers bill actual time: if the tool turns a task into fifteen minutes, the client is charged fifteen minutes plus the review time. Lawyers may not charge clients for time spent learning a tool they will use generally — unless the client has requested that a specific tool be used and the billing for that time has been agreed — and expenses must be passed through at actual cost with appropriate disclosure.
- What that means in practice:
- Set the billing treatment for tool time, review time, and tool cost in writing before the first matter uses it.
Consumer, enterprise, or private: the facts change
Rule 1.6(c)'s reasonable-efforts standard runs on facts — the likelihood of disclosure and access, the sensitivity of the information, and the safeguards in place. The same brand name can sit on top of three very different sets of those facts, which is why "can we use ChatGPT" is a question asked at the wrong resolution: the tier and the terms are what the analysis actually touches.
| Consumer chat tools | Enterprise tiers | Private deployments | |
|---|---|---|---|
| Where prompts go | To the provider's consumer service under its standard terms; the firm has no say in the data path and often no visibility into it. | To the provider's business service under commercial terms that typically add administrative controls and data-handling commitments. | Into an environment the firm governs — in the strongest form, a data plane running inside the firm's own cloud account, where the data path is inspectable. |
| Training use | Consumer tiers of general-purpose assistants commonly reserve the right to use conversations to improve models, with opt-outs the user must find and exercise — and the terms can change. | Business tiers commonly commit by default to not training on customer content; the commitment lives in the contract and should be verified there, not assumed. | No-training is a contractual term the firm holds directly, and the surface area for surprise is smaller because fewer parties ever see the content. |
| Retention and deletion | Retention follows the provider's consumer policy, including copies kept for abuse monitoring; deletion is a request, not a control the firm operates. | Retention windows are typically documented and sometimes configurable; deletion and post-termination handling are contract questions Opinion 512's diligence expects you to ask. | Retention is a setting the firm operates, and inference can run under contractual zero-retention terms, so the model provider does not store prompts. |
| Logs and administrative control | No firm-level administration: no user roster, no usage log the firm owns, no way to answer who asked what, when. | Admin consoles and audit logs exist at the provider's discretion and in the provider's format; export what you can and test it. | Every request is logged with user identity, timestamp, and model identity, exportable from logs the firm owns, so the firm can answer “how was AI used in this matter” from its own records. |
| Whose terms govern | The provider's click-through terms, which the provider can revise; Opinion 512's read-the-terms baseline falls entirely on each individual user. | A negotiated or at least reviewable commercial agreement — the artifact the firm's vendor diligence and Opinion 512's cloud-era factors actually attach to. | A direct contract plus the firm's own infrastructure controls; more of the analysis rests on evidence the firm can inspect rather than representations it must trust. |
The columns are planes, not endorsements: what each tier does with retention and training is exactly the territory the zero data retention vs no training guide maps plane by plane, and the retention clocks that attach to what a firm does keep are the subject of the prompt log retention crosswalk.
The review checklist
Ten items for a firm evaluating any AI tool — ChatGPT, a legal-specific product, or a governed workspace. Each carries what to record, because the written determination is the artifact that separates a considered program from an accidental one.
01Classify the use case before the tool
- Why:
- Opinion 512 turns on whether information relating to a representation is input at all: idea generation that inputs none may require no client consent, while matter work changes every answer that follows.
- What to record:
- A written use-case inventory naming which uses touch representation information and which never do.
02Read the Terms of Use, privacy policy, and data-processing terms
- Why:
- This is the opinion's stated baseline for all lawyers — with a colleague or outside expert who has analyzed them, and IT or cybersecurity professionals where needed.
- What to record:
- The reviewed terms, dated, with the version captured — terms change, and the review is only as good as its date.
03Determine training use and the default
- Why:
- Whether content is used to improve models — and whether protection is the default or an opt-out someone must exercise — is the single fact that most changes the confidentiality analysis.
- What to record:
- The clause or setting, quoted, plus who verified it and when.
04Determine retention, deletion, and post-termination handling
- Why:
- Opinion 512 carries forward the cloud-era question: does the tool retain submitted information both before and after the services end, and does it assert proprietary rights to what was submitted?
- What to record:
- The retention windows per plane, the deletion mechanism, and the contract's answer to the end-of-relationship question.
05Map the tier and forbid the wrong one in policy
- Why:
- The consumer tier and the business tier of the same product are different tools for this analysis. Most firm risk lives in individual lawyers using consumer tiers informally.
- What to record:
- A policy line naming approved tools and tiers, and stating that consumer tiers are not approved for client work.
06Evaluate exposure inside the firm
- Why:
- The opinion is explicit that risk includes disclosure to people inside the firm who should not see the information — across ethical walls, or from one client's matter into another's.
- What to record:
- How workspaces, access controls, and matter separation prevent cross-matter exposure, tested rather than assumed.
07Decide the informed-consent posture
- Why:
- For self-learning tools whose output could disclose representation information, the opinion requires informed consent before inputting it — and says boilerplate engagement-letter provisions are not sufficient.
- What to record:
- The consent standard per use case, and the form of consent where one is required — specific, explained, and documented.
08Put privilege on its own track
- Why:
- Waiver by disclosure to a third party is a separate doctrine from the ethics duty, it is fact-specific, and no vendor's architecture can guarantee the outcome. The question belongs with the firm's own counsel, matter by matter where it is live.
- What to record:
- A named owner — general counsel or ethics counsel — and the firm's position on which uses raise the question at all.
09Write the supervision policy and train on it
- Why:
- Model Rules 5.1 and 5.3 make permissible-use policies and training a managerial duty, covering nonlawyer staff as well as lawyers.
- What to record:
- The policy, the training record, and the review cycle that keeps both current as tools change.
10Set the billing treatment and the audit posture
- Why:
- Rule 1.5 governs what tool time and tool cost can be charged, and courts and clients increasingly ask how AI was used — an answer that should come from logs the firm owns.
- What to record:
- The billing policy for tool use, and where the usage log lives, who can export it, and how long it is kept.
The vendor-facing half of this work is already written as an instrument: the AI vendor security questionnaire carries 21 scored questions across data flow, retention, logging, isolation, training use, incident response, and access control.
How PrivateStack fits this analysis
PrivateStack changes the facts the Rule 1.6 analysis runs on, in the directions the checklist asks about. The governed workspace logs every request with user identity, timestamp, and model identity, exportable from logs the firm owns — so "how was AI used in this matter" is answerable from the firm's own records. Hosted inference runs zero-retention through a disclosed subprocessor under contractual no-training terms, so prompts are never stored by the model provider and never used for training. The Enterprise deployment runs the data plane inside the customer's own AWS account. The honest limits, stated plainly: none of this performs the firm's own Rule 1.6 evaluation, decides its consent posture, or substitutes for reading the terms — those determinations are the firm's, made with its counsel, and no platform can make them. And on privilege the position above does not soften for our own product: a private deployment does not guarantee that privilege attaches or survives, and we will not tell you otherwise. The legal solution page covers the law-firm deployment in detail, and the security page carries the full control set.
Questions people actually ask
- Can a law firm use ChatGPT with confidential client information?
- Not on a consumer tier without confronting Model Rule 1.6 head-on, and on any tier only after the analysis ABA Formal Opinion 512 describes: a fact-driven evaluation of disclosure and access risk that depends on the client, the matter, the task, and the tool — plus the client's informed consent before representation information goes into a self-learning tool. Business tiers and private deployments change the facts that analysis runs on (training use, retention, logging, whose terms govern); they do not remove the duty. And the ethics analysis, done perfectly, still leaves evidentiary privilege as a separate question.
- Does using an AI tool waive attorney-client privilege?
- There is no general answer, and be wary of any page that offers one. Privilege is a doctrine of evidence law that can be waived by voluntary disclosure of a privileged communication to a third party, and whether a particular tool, tier, and use amounts to that is fact-specific and decided by courts, not vendors. No deployment architecture — ours included — can guarantee that privilege attaches or survives. Treat privilege as its own track, owned by the firm's own counsel.
- Does Opinion 512 prohibit lawyers from using generative AI?
- No. It states that lawyers using generative AI must fully consider their existing duties — competence, confidentiality, communication, meritorious claims and candor, supervision, and reasonable fees — and it analyzes how each applies. It neither bans the tools nor blesses them; it makes the existing rules reach them.
- Is client consent always required before a lawyer uses a generative AI tool?
- No. Opinion 512 requires informed consent before inputting information relating to the representation into a self-learning tool whose output could disclose it, and it notes that consent is not necessary where the lawyer inputs no representation information at all — idea generation is its example. Between those poles, disclosure duties under Rule 1.4 depend on the facts. Where consent is required, it must be actual and informed: general boilerplate in an engagement letter is not sufficient.
- What does a private deployment change in this analysis?
- It changes the inputs, not the duty. Rule 1.6's reasonable-efforts standard weighs the likelihood of disclosure and access against the safeguards in place — so where prompts go, whether they train models, how long anything is retained, and who holds the logs all move the analysis. A deployment the firm governs makes more of those facts inspectable and contractual. What it does not do is make the analysis unnecessary, and it does not answer the privilege question, which no architecture can.
Weighing the deployment models themselves? The closed-API comparison scores a governed workspace against calling a model API directly, including where the direct API wins.
Primary sources
Every statement above traces to one of these publications. Read the instrument before any vendor's interpretation — including ours.
- ABA Formal Opinion 512 — Generative Artificial Intelligence Tools (July 29, 2024) — The Standing Committee on Ethics and Professional Responsibility's guidance: competence, confidentiality and informed consent, client communication, candor, supervision of people and vendors, and fees, as they apply to generative AI use.
- ABA Model Rule 1.6 — Confidentiality of Information — The duty not to reveal information relating to the representation absent informed consent, implied authorization, or an exception, and paragraph (c)'s reasonable-efforts duty against inadvertent or unauthorized disclosure and access.
- Comment on Rule 1.6 — Comments [18] and [19] — Acting competently to preserve confidentiality: the factors for what efforts are reasonable — sensitivity, likelihood of disclosure without safeguards, cost and difficulty of safeguards, and their effect on the representation — and reasonable precautions when transmitting communications.
- ABA Model Rule 1.1 — Competence — The competence duty Opinion 512 builds on, with Comment [8]: keeping abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.