Stop Sending Client Files to AI Tools That Were Never Built for Law Firms
Photo by Albert Stoynov on Unsplash
6 min readJuly 17, 2026

Stop Sending Client Files to AI Tools That Were Never Built for Law Firms

Data PrivacyNJ RPC 1.6AI Tools

There's a habit spreading through solo and small firm practice that nobody is talking about loudly enough: attorneys pasting client documents, deposition summaries, and case facts directly into consumer AI tools, the free tier of ChatGPT, Google Gemini, or whichever app showed up in a bar association newsletter.

It's understandable. The tools are fast, accessible, and genuinely useful. But the version you're using for free, or even on a personal subscription, was built for a general audience. It was not built to hold your client's confidential information.

This isn't a scare tactic. It's a data flow problem, and it has a concrete answer.

What "Consumer-Grade" Actually Means for Your Data

When you use a standard (non-enterprise) subscription to a general-purpose AI product, your inputs may be used to train or improve the model unless you specifically opt out. Some products do offer an opt-out buried in privacy settings. Others offer it only on higher-tier or business plans. A few products, particularly those marketed to the general public, retain your prompts for a period of time as a matter of course.

For a typical consumer, this is a mild inconvenience at most. For a New Jersey attorney, it raises a direct question under RPC 1.6, which prohibits revealing information relating to the representation of a client unless the client gives informed consent or an exception applies.

The New Jersey Supreme Court's ACPE (Advisory Committee on Professional Ethics) has not yet issued a formal opinion specifically on AI tools, but the analytical framework is not ambiguous. If client information enters a system that could expose it to third parties, whether human reviewers, model trainers, or a vendor's subprocessors, you have a disclosure problem.

The good news: the fix doesn't require you to stop using AI. It requires you to use the right version of the right tool.

The Specific Risk Points in a Typical Workflow

Here's where attorneys most commonly create exposure without meaning to:

Drafting with real facts. You paste a client's name, the facts of a dispute, and a contract excerpt into a free AI tool to get a draft demand letter. The draft is good. The data is now in a system you don't control.

Summarizing documents. You upload a PDF of a deposition transcript or a medical record to get a quick summary. Many consumer tools accept file uploads now. Those files go somewhere.

Asking research questions with embedded facts. "My client signed a non-compete in Bergen County in 2022. Can this clause be enforced under NJ law?" That question contains enough to identify a matter, and you've handed it to a third-party system.

None of these feel dangerous in the moment. That's precisely why they keep happening.

What a Safer Workflow Looks Like

The practical standard most data-conscious firms are settling on has two tiers.

Tier one: anonymized prompts for consumer tools. If you're using a free or personal-subscription AI tool for any purpose touching client work, strip out all identifying information before you write the prompt. Replace the client's name with a placeholder. Remove specific geographic identifiers if they narrow the matter. Describe the document type without uploading the actual document. This approach isn't perfect, but it materially reduces exposure and keeps the interaction closer to a general research task than a confidential disclosure.

Tier two: enterprise-grade tools with a data processing agreement for anything substantive. If you're uploading real documents, working with real client names, or building any kind of systematic AI-assisted workflow, you need a tool that offers a business associate agreement (if health information is involved) or at minimum a data processing agreement with clear terms on retention, subprocessor access, and training opt-outs. Microsoft Copilot for Microsoft 365 (on a qualifying business plan), the enterprise tier of ChatGPT, and legal-specific platforms like Clio Duo or Harvey (for firms that qualify) all provide some version of this. The contracts differ, and you should read them, but the category of tool is materially different from the free version.

The Due Diligence Step Most Attorneys Skip

Before you run any client data through an AI tool, ask the vendor three things in writing, either by reviewing their terms of service or by contacting their sales or legal team:

  1. Do you use customer inputs to train or improve your models, and how do I opt out?
  2. Who are your subprocessors, and where is data stored?
  3. What is your data retention period for my inputs and outputs?

If the vendor won't answer all three questions clearly, that is itself the answer.

New Jersey attorneys have a competence obligation under RPC 1.1 that the ACPE has consistently read to include understanding the tools you use in practice. You don't need to be a security engineer. You do need to know whether the tool you're using is appropriate for the sensitivity of the information you're putting into it.

Start there. Audit one tool you're currently using today, pull up its privacy policy, and check whether your current subscription tier covers the data handling you've been assuming it does. Most attorneys who do this audit find at least one gap they didn't expect.

Get the weekly roundup

New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.