Legal AI

CoCounsel

Medium risk

Thomson Reuters' professional AI assistant, delivered inside Westlaw Precision for legal work and as CoCounsel Tax, Audit & Accounting for advisory practices.

Verified 2026-08-31Thomson Reuters (ex-Casetext)www.thomsonreuters.com/en/cocounsel

Is CoCounsel safe for confidential data?

CoCounsel is one of the better-documented legal AI products on data handling: Thomson Reuters publishes a security FAQ stating that all calls to third-party LLM providers (OpenAI, Google) use zero-retention APIs, that those providers are contractually prohibited from training on customer data, and that TR has disabled third-party abuse monitoring so no human at the provider sees prompts. The residual risk is structural rather than contractual: privileged client material still transits OpenAI and Google infrastructure, the zero-retention claim cannot be independently audited by a customer, and courts have not squarely resolved whether routing privileged documents through an LLM vendor could support a privilege-waiver argument. Firms should treat it as safe for confidential work only under a signed agreement, with the security FAQ terms mirrored in the contract.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

CoCounsel Legal (in Westlaw Precision)
No training

Sold as part of the Westlaw Precision subscription under Thomson Reuters' standard terms; no-training and zero-retention commitments apply.

CoCounsel Tax, Audit & Accounting
No training

Same published security posture: zero-retention API calls, no training on user content, U.S. processing, TLS 1.2 in transit and AES-256 at rest.

Data handling

Training on inputs

Thomson Reuters states user content and prompts are not used to train CoCounsel or any third-party LLM, and that OpenAI and Google are contractually prohibited from training on customer data. There is no consumer tier with different terms.

Retention

Third-party LLM calls are made via zero-retention APIs, so prompts are not stored by OpenAI or Google. Uploaded content persists in the customer's CoCounsel account for the life of the account unless deleted by the user.

Residency

Prompts and content are processed and hosted in the United States per the published security FAQ. Non-U.S. firms (including Canadian firms subject to PIPEDA or provincial rules) should confirm cross-border transfer terms in their agreement.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAANot verified

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • SSO / SAML
  • Zero-retention API calls to LLM providers
  • Third-party abuse monitoring disabled
  • AES-256 at rest, TLS 1.2 in transit
  • Standard Thomson Reuters DPA available

Frequently asked questions

Is CoCounsel safe for confidential client data?

Under a signed subscription, its data handling is stronger than most alternatives: zero-retention calls to OpenAI and Google, contractual no-training terms, and abuse monitoring turned off. The open questions are structural — client data still transits third-party AI infrastructure, and you are relying on Thomson Reuters' contracts with its providers rather than anything you can audit. Confirm the security FAQ commitments are incorporated into your firm's agreement.

Does CoCounsel train on my data?

No. Thomson Reuters states that user content and prompts are not used to train CoCounsel, other TR products, or any third-party LLM, and that OpenAI and Google are contractually barred from doing so. That commitment is published in TR's security documentation; get it restated in your contract rather than relying on a web page that can change.

Does using CoCounsel waive privilege?

No court has held that using an enterprise legal AI tool under confidentiality terms waives privilege, and ABA Formal Opinion 512 treats vendor confidentiality terms as central to a lawyer's Rule 1.6 analysis. The greater practical risk is lawyers using free consumer chatbots for the same work outside any agreement — that is where confidentiality and privilege arguments get genuinely uncomfortable, and it is worth pairing a sanctioned tool with controls on the unsanctioned ones.

Policy changelog

  • Initial entry published from Thomson Reuters' published security documentation and cited coverage.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

CoCounsel is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles