Does Sending Client Files to an AI Tool Violate NJ RPC 1.6?
Photo by Albert Stoynov on Unsplash
5 min readOctober 3, 2026

Does Sending Client Files to an AI Tool Violate NJ RPC 1.6?

NJ RPC 1.6AI confidentialitylaw firm data security

AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published October 3, 2026. Reviewed October 3, 2026.

Most NJ solo and small-firm attorneys already know, in the abstract, that AI tools raise confidentiality questions. Fewer have actually worked through what that means for their day-to-day workflow, specifically the moment they hit "upload" or paste client text into a prompt.

NJ RPC 1.6 prohibits disclosing information relating to the representation of a client unless the client gives informed consent, disclosure is impliedly authorized, or a specific exception applies. The word "disclosure" is doing a lot of work there. When you send a client's deposition transcript to an AI tool hosted on a third-party server, you are, at minimum, transmitting client information to a system you don't control. Whether that rises to a "disclosure" under RPC 1.6 depends on factors most attorneys haven't examined.

The core question isn't whether AI is involved. It's where the data goes.

Some AI tools process your input entirely within your existing software environment. Microsoft Copilot configured inside a firm's Microsoft 365 tenant, for example, operates under Microsoft's enterprise data protection terms, which typically prohibit using your prompts to train future models and include contractual confidentiality commitments. That's a meaningfully different situation than pasting the same text into the free tier of a consumer-facing chatbot, where your input may be used for model improvement by default.

The NJ Supreme Court and the ACPE haven't issued a standalone AI-specific ethics opinion as of mid-2025 (unlike some other jurisdictions that have moved faster on formal guidance). That doesn't create a gap you can exploit. It means you're applying existing principles, and RPC 1.6 combined with the competence obligations in RPC 1.1 already give you enough framework to reason through it.

Here's the practical analysis you should run before using any AI tool with real client data:

First: Read the vendor's data processing terms, not just the privacy policy.

These are usually different documents. The privacy policy tells you what the company does with data from users of their website. The data processing terms (sometimes called a DPA or BAA addendum) tell you what happens to the content you submit through the product. Look specifically for: (1) whether the vendor retains your inputs after your session ends, (2) whether your data is used for training, and (3) whether the vendor's subprocessors have access to your content. If you can't find these terms, or they're not offered, treat it as a red flag.

Second: Check whether a Business Associate Agreement is even the right instrument.

Attorneys sometimes conflate HIPAA BAA requirements with general confidentiality. A BAA is required for covered healthcare data. But a BAA's existence doesn't automatically satisfy RPC 1.6 for non-health client data, and its absence doesn't mean you've committed an ethics violation if you're not handling PHI. The instrument you want for general client data is a contractual commitment from the vendor not to use, retain, or disclose your content beyond what's needed to provide the service.

Third: Separate your workflows by data sensitivity.

Not every use of AI requires uploading actual client files. You can ask an AI tool to help you research a legal issue, draft a generic demand letter structure, or generate deposition outline questions, all without ever pasting in a single identifying fact about your client. Train yourself (and any staff) to work with sanitized or hypothetical inputs whenever possible, then import the AI's output into your actual client work.

When you do need to process real client documents, for example, running a contract through an AI review tool or using AI to summarize discovery, that's when vendor vetting matters most. You should be able to point to a specific contractual provision that addresses what happens to your upload.

Fourth: Consider whether client consent is worth building into your retainer.

A growing number of NJ practitioners are adding a short paragraph to their engagement agreements disclosing that the firm uses AI-assisted tools in its practice and explaining, in plain language, how client information is protected. This isn't legally required in every situation, but it's clean practice. It converts an ambiguous "implied authorization" argument into actual informed consent. Given that RPC 1.4 already requires you to keep clients reasonably informed about the means used in their representation, a disclosure clause in the retainer is a natural fit.

The one thing you shouldn't do is assume that because an AI tool is widely used, or because another attorney in your network uses it, it's automatically compliant with your RPC 1.6 obligations. Popularity isn't a substitute for due diligence.

If you're uncertain about a specific tool you're already using, start with the vendor's terms of service and look for the data processing addendum. That document will tell you more about your actual exposure than almost anything else.

Get the weekly roundup

New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.