What If an Associate Fed Client Documents into an AI Tool? 

What If an Associate Fed Client Documents into an AI Tool?

Imagine the situation: It is late on a Tuesday evening. A senior associate at a boutique litigation firm faces an aggressive deadline for a complex brief. Seeking to accelerate the process, the associate opens a browser tab, logs into a public, consumer-facing generative AI assistant, and pastes 40 pages of confidential client emails, deposition transcripts, and strategy memos to draft an executive summary. The task is completed in under two minutes. The summary is clean, and the deadline is met.

Then comes the question no law firm wants to hear: “Was that document allowed to leave the firm?”

Generative AI can be extremely useful for lawyers. It can summarize documents, compare contracts, organize information, draft correspondence, and speed up research. But when a lawyer or associate puts client information into an AI tool, the firm is no longer dealing only with productivity. It is dealing with confidentiality, data security, supervision, and potentially privilege.

The American Bar Association addressed this directly in Formal Opinion 512. The ABA says lawyers using generative AI must consider their existing ethical obligations, including competence, confidentiality, communication with clients, and supervision of employees and agents. Before putting information relating to a client representation into an AI tool, lawyers need to evaluate the risk that the information could be disclosed or accessed by others.

This is becoming harder to treat as a hypothetical problem.

AI Use Is Already Happening Inside Law Firms

Recent legal sector research and judicial warnings highlight the scale of this vulnerability:

  • Pervasive Unsanctioned Use: According to an legal technology survey, while law firm AI adoption reached 42% in 2026, roughly a third of legal professionals admit to using AI tools their firm never approved or sanctioned.
  • The Financial Impact: The IBM Cost of a Data Breach Report indicates that the average cost of a data breach for professional services organizations, including law firms, stands at $5.08 million with 68% of breaches involving human error while interacting with modern software tools.
  • Loss of Attorney-Client Privilege: In formal warnings, legal authorities—such as the UK Upper Tribunal in decisions like Munir—have cautioned that uploading confidential legal records or advice into open-source public AI tools places that material into the public domain. Once confidentiality is destroyed via third-party disclosure, courts can rule that legal professional privilege has been permanently waived.

The Confidentiality Problem Is Bigger Than ChatGPT

It is tempting to reduce the issue to one question: Does the AI provider train its model on my data? That is important, but it is not the only question.

A law firm needs to understand:

  • What information is being sent to the AI tool?
  • Where is it processed?
  • How is it stored?
  • How long is it retained?
  • Who can access it?
  • Is the data used to improve or train a model?
  • What happens to uploaded files and conversation history?
  • Can the firm audit who used the tool and what happened?

The ABA specifically warns that lawyers need to understand how a GAI tool uses and protects information before entering client-related data. It also notes that self-learning AI systems can create confidentiality risks even when used inside a firm’s own environment, because information from one client’s matter could potentially be applied to another matter.

That is why “It’s an AI tool approved by IT” is not, by itself, a sufficient answer. The firm needs to know what kind of AI deployment it has approved and what controls surround it.

52822

What If the Associate Already Uploaded the Document?

First: do not panic, and do not tell the associate to delete everything. Deleting the conversation may remove evidence the firm needs to understand what happened.

Instead, treat it as a potential information-security incident.

1. Find out exactly what was uploaded.

Was it a public contract? An internal draft? A client’s financial records? A deposition transcript? A document containing Social Security numbers or other personal information? The risk depends heavily on the information involved.

2. Identify exactly which AI tool and account were used.

There is a major difference between an employee’s personal account on a consumer AI service and an enterprise AI environment contracted and configured by the firm.

The firm should establish:

  • which service was used;
  • which account was used;
  • whether the account belongs to the firm;
  • what privacy and retention settings apply;
  • whether files and prompts are retained;
  • whether the provider can access the information;
  • and whether the firm has an audit trail.

3. Preserve the evidence.

Security and legal teams need enough information to reconstruct what happened. That may include the original document, the prompt, timestamps, account information, AI-tool settings, and relevant logs. The goal is not to punish an associate for making a mistake. It is to determine whether confidential information actually left the firm’s controlled environment and what obligations follow.

4. Escalate internally.

The incident should reach the people responsible for cybersecurity, technology, risk, and professional responsibility. Depending on the circumstances, the firm may also need to involve its privacy team, cyber insurer, outside counsel, or the client. This is where having an incident-response process for AI becomes important.

5. Do not assume that “nothing happened”.

If the associate says, “I deleted the chat,” that does not establish that the information was deleted everywhere. Likewise, “The AI company says it doesn’t train on our data” does not answer every confidentiality or privilege question. The firm needs evidence, not assumptions.

Jackson Lewis Took a Different Approach

Problem: Lawyers wanted to experiment with AI for legal research, document analysis, case management, and other work. However, the firm recognized that public-facing AI tools could create security and confidentiality problems when lawyers work with client information.

What was different: Jackson Lewis developed its own private version of GPT through Microsoft rather than simply allowing lawyers to use the public version of ChatGPT. The firm’s technology team could therefore experiment with AI while maintaining greater control over the environment and the data being processed.

Outcome: The firm created a controlled environment for exploring AI rather than relying on individual lawyers to determine whether a consumer AI service was appropriate for client work.

The lesson isn’t that every law firm needs to build its own AI system. The lesson is that the environment matters.

40353

Latham & Watkins Is Moving Even Further Toward Control

In September 2026, the Financial Times reported that Latham & Watkins had invested in Nvidia servers and was building in-house AI infrastructure using open-weight models. The firm’s approach is designed to give it greater control over client data and reduce dependence on external AI vendors.

Problem: A major law firm wants to use increasingly powerful AI across a business built around highly confidential information.

What was different: Instead of treating AI purely as another cloud application, Latham invested in infrastructure it could control itself.

Outcome: The firm gained greater autonomy over how its AI systems are deployed and how client data is handled.

Again, that does not mean every firm should buy GPUs and build its own models. It does demonstrate where the industry is heading: AI adoption is increasingly becoming an IT governance question, not simply an individual lawyer’s productivity choice.

So, How Do You Prevent the Upload?

For a law firm, that can include:

Approved AI Tools
Give lawyers access to AI that has been properly vetted instead of leaving them to find their own tools.

Identity and Access Controls
Use firm-managed accounts, SSO, MFA, and role-based access rather than personal accounts.

Data Classification
Make it obvious which information can be used with approved AI tools and which information requires additional protection.

DLP and Endpoint Controls
Technology can help detect sensitive information being copied or uploaded to unsanctioned applications.

Logging and Monitoring
The firm should be able to determine which AI services are being used and investigate suspicious activity.

Clear AI Policies
Policies should explain not only what employees cannot do, but what they should use instead.

Practical Training
An associate needs to recognize that a deposition transcript, client email, draft settlement agreement, or privileged memo is not simply “a document that needs summarizing.”

Klik Solutions helps law firms build technology environments where security, access control, data protection, and AI adoption work together. If your attorneys and associates are already using AI or you are planning to introduce it, now is the time to understand what data is leaving your environment and how to control it.

Talk to Klik Solutions about building a safer AI strategy for your law firm.

Frequently Asked Questions

Can lawyers use ChatGPT with client information?

They may be able to use generative AI in legal work, but client information should not be entered into an AI tool without evaluating how that tool handles the information and whether the use complies with the lawyer’s professional obligations. ABA Formal Opinion 512 specifically addresses the confidentiality risks of entering client-related information into GAI tools.

Is an enterprise AI account automatically safe for a law firm?

No. An enterprise or business-grade account can provide stronger contractual and technical protections, but the firm still needs to understand the provider’s data handling, retention, access, security controls, and terms. It also needs internal policies governing what lawyers can put into the system.

What should a law firm do if an employee already uploaded confidential documents?

Treat it as a potential security and confidentiality incident. Preserve relevant evidence, identify exactly what information was uploaded and where it went, determine the tool and account involved, and escalate the matter to the firm’s appropriate security, technology, privacy, and professional-responsibility teams. The specific legal and ethical response will depend on the circumstances.

Does uploading a document to a public AI tool automatically constitute a data breach?

Yes, in many legal jurisdictions and regulatory frameworks. Uploading non-public client data to a public or consumer-facing AI tool whose terms permit data logging or model training transfers that information to an unauthorized third party. This can trigger mandatory disclosure duties under state bar ethics rules, privacy statutes, or contractual NDAs.

Are paid “Plus” or “Pro” consumer AI subscriptions safe for legal documents?

Not necessarily. Unless your firm has signed a dedicated Enterprise Agreement or Business Associate Agreement (BAA) with explicit zero-data-retention and non-training clauses, standard individual paid tiers may still retain data for diagnostic or server processing purposes. Always verify vendor security architecture through a formal IT audit.

Should law firms ban generative AI?

Not necessarily. A blanket ban may simply push AI use underground. A better approach is to provide approved tools, establish clear rules for different types of data, control access, monitor usage, and train employees on appropriate use. The objective is controlled adoption—not uncontrolled experimentation.

Register for klik solutions picnic

Error: Contact form not found.

sign up to attend this event

    All fields are required

    support Hope children of ukraine!

    donate now!

      All fields are required

      Thank you for your enquiry.

      thanks-icon

      Please monitor your inbox for all March Madness updates.

      Thank you!

      thanks-icon

      We will contact you soon.