Can Lawyers Use ChatGPT with Client Documents? (2026 Ethics & Privilege Guide)
Lawyers should not put privileged or confidential client material into the consumer version of ChatGPT. The ABA's duties of competence and confidentiality require knowing where the data goes and protecting it. Here is what the rules say and the compliant path for AI in legal work.
A lawyer should not paste privileged or confidential client material into the consumer version of ChatGPT. This is not a ban on AI in legal work; it follows directly from two duties every lawyer already holds: the duty of competence and the duty of confidentiality. Both require knowing where client information goes and making sure it is protected, and the consumer chatbot, where content can be retained and used to improve models and no agreement binds the provider to protect it, fails that test for confidential material. There is a compliant path, and it runs through deployments the firm actually controls.
The two duties that govern the question
The relevant rules are not new. They are the bedrock professional-responsibility duties, applied to a new tool.
- Competence, Model Rule 1.1. A lawyer must provide competent representation, and the ABA has long read this to include a reasonable understanding of the benefits and risks of the technology a lawyer uses. You cannot meet this duty with a tool whose data handling you have not understood.
- Confidentiality, Model Rule 1.6. A lawyer must not reveal information relating to the representation and must make reasonable efforts to prevent its inadvertent or unauthorized disclosure. Feeding confidential material to a third-party system that may retain or learn from it is precisely the kind of disclosure this rule is meant to prevent.
The full text of the Model Rules is published by the American Bar Association.
What the ABA actually said about AI
In July 2024 the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first formal guidance on generative AI. The opinion does not prohibit AI. It maps the existing rules onto it: competence requires understanding the tool well enough to use it responsibly, confidentiality requires protecting client information from the tool itself and not just from outsiders, and lawyers must weigh reasonable fees, supervision, and candor to the court when AI is involved. The throughline is that the lawyer remains responsible for the work and for the data, and cannot outsource either to a model.
How the duties map to your choices
Here is the practical mapping from rule to action when an AI tool is in the picture.
| Duty | What it requires | What it rules out |
|---|---|---|
| Competence (1.1) | Understanding where data goes and how the tool behaves | Using a tool whose data handling you have not checked |
| Confidentiality (1.6) | Reasonable safeguards against disclosure of client information | Pasting confidential material into a tool that may retain or train on it |
| Supervision (5.1, 5.3) | Oversight of the tool’s output and the people using it | Treating AI output as final without review |
| Candor (3.3) | Verifying AI-generated citations and facts | Filing unverified AI output, as sanctioned lawyers have learned |
That last row is not hypothetical. Courts have already sanctioned lawyers who filed briefs containing AI-fabricated case citations, a reminder that the duty of candor does not pause for a chatbot.
The line that matters most
Privilege does not survive a confidential document being used to train someone else’s model. Privilege and confidentiality both rest on the information staying protected, and a disclosure to a third party that is not bound to safeguard it can erode the protection the privilege depends on. That is why the deployment model, more than the capability of the AI, decides this question for a law firm.
The compliant path
Lawyers can use AI on confidential matters; they need a system where the data stays under the firm’s control. A private deployment keeps privileged material inside the firm’s own environment, so nothing leaves the perimeter and no provider can retain or learn from it. Pair that with a system that grounds every answer in your own documents and cites the passage it came from, and you get AI that supports a lawyer’s judgment without asking them to trust an unverified claim. That combination, control over the data plus traceable, source-cited output, is not something you get off a shelf; it is a custom system built around how your practice actually runs, which is what we build for law firms and legal teams.
For lower-risk work, such as general legal research or drafting that involves no client confidences, an enterprise tool with the right terms can be appropriate. The discipline is matching the tool to the sensitivity of the material, and never letting convenience decide where a privileged document goes.
If you want to see what a privilege-safe AI workflow looks like for your practice, book a demo. Our broader guide to deploying AI in regulated industries covers the same principles across healthcare and finance.
Frequently asked questions
- Can lawyers use ChatGPT?
- Lawyers can use AI, including ChatGPT's enterprise products, for many tasks, but they should not put privileged or confidential client material into the consumer version. The ABA's duties of competence and confidentiality require an attorney to understand the technology and to protect client information, which means knowing where the data goes and ensuring it is not exposed or used to train a third party's model. General research and non-confidential drafting are lower risk; client-confidential material requires a properly controlled deployment.
- Does using AI waive attorney-client privilege?
- It can. Privilege depends on confidentiality being maintained, and disclosing confidential client information to a third party that is not bound to protect it can undermine the confidentiality the privilege rests on. Putting a privileged document into a consumer tool whose provider may retain or train on the content is exactly the kind of disclosure to avoid. Using a deployment where the data stays under the firm's control avoids the problem.
- What does the ABA say about AI?
- In July 2024 the ABA issued Formal Opinion 512 on generative AI, addressing how the Model Rules apply to lawyers' use of these tools. It reaffirms that competence requires a reasonable understanding of the technology, that confidentiality requires protecting client information including from the AI tool itself, and that lawyers must consider reasonable fees and candor when using AI. It does not ban AI; it requires using it responsibly.
- What is the safest AI for a law firm's confidential documents?
- A private deployment, where the model and the documents stay inside infrastructure the firm controls, is the safest path because privileged material never leaves the firm's perimeter and no third party can retain or train on it. Combined with outputs that cite their source passages so a lawyer can verify them, this keeps AI inside the bounds of competence and confidentiality.
Working in a regulated environment? Let’s talk.
Book a demo