6 min readSanitized AI Team

Can Lawyers Use ChatGPT? Practical Rules for Safer Use

AI GovernanceComplianceData PrivacyShadow AIData Security

Lawyers can use ChatGPT, but the important question is not whether the technology is permitted in the abstract. The real question is whether a particular use is consistent with the lawyer's duties of competence, confidentiality, supervision, client communication, and accuracy.

That distinction matters because ChatGPT can support useful legal work without being appropriate for every task. Brainstorming a generic checklist is very different from uploading a client's confidential documents or relying on an AI-generated case citation without checking it.

For law firms, safer use starts by defining where ChatGPT can help and where professional judgment or additional safeguards are required.

ChatGPT can be useful for early-stage work such as brainstorming issues, improving the clarity of non-confidential writing, organizing public information, generating generic questions, or creating a first-pass structure for a document.

The problem begins when a lawyer treats the output as authoritative.

The Canadian Bar Association advises lawyers to verify and validate generative AI content for accuracy, relevance, and reliability. Its guidance also warns that generative AI can produce inaccurate, false, or misleading information.

This is especially important for legal research. If ChatGPT produces a case name, quotation, statute, or legal proposition, the lawyer should confirm it using an authoritative legal source before relying on it. The same applies to facts, procedural requirements, and jurisdiction-specific rules.

The lawyer remains responsible for the final work, even when AI helped produce the first draft.

Protect client information before writing the prompt

Confidentiality rules still apply when information is entered into an AI service.

The Law Society of Ontario's Rules of Professional Conduct require lawyers to hold in strict confidence information concerning the business and affairs of clients, subject to limited exceptions. The rules also state that lawyers should understand the benefits and risks of technology relevant to their practice.

Before entering client-related information into ChatGPT, ask whether the model actually needs the client's identity or confidential details.

A lawyer who wants help improving the wording of an update may be able to replace the client's name, matter number, transaction value, and opposing party with neutral placeholders. If only one clause needs attention, there may be no reason to upload the entire agreement.

Removing unnecessary information reduces exposure without eliminating the usefulness of the tool.

Use the law firm's approved account and tools

Law firms should not leave account selection entirely to individual lawyers.

A firm may approve a particular managed AI environment after reviewing its data handling, security, retention, contractual protections, and administrative controls. That approval does not automatically extend to a lawyer's personal ChatGPT account or another free AI tool.

The Canadian Bar Association recommends that lawyers perform due diligence when choosing AI tools, including considering privacy, confidentiality, security, reliability, terms and conditions, and integrations.

A useful internal rule is that firm work belongs in firm-approved systems. If a lawyer wants to use a new AI service, there should be a clear process for having it reviewed.

Know when client communication may be necessary

Some AI uses may be routine enough that a separate client discussion is not required. Others may materially affect how legal services are delivered or involve client information in ways the client would reasonably want to understand.

The Canadian Bar Association advises lawyers to consider disclosing their intended use of generative AI for activities such as research, analysis, document review, discovery, or trial preparation.

The American Bar Association's Formal Opinion 512 similarly explains that lawyers using generative AI must consider duties involving client communication and confidentiality, and that informed consent may be required in some circumstances.

Whether disclosure or consent is necessary depends on the jurisdiction, the type of information involved, the tool, and the nature of the representation. Firms should give lawyers an escalation path rather than expecting each person to make that determination alone.

Supervise staff who use ChatGPT

Lawyers may not be the only people using AI in a firm.

Articling students, law clerks, assistants, paralegals, summer students, and contractors may use ChatGPT to summarize information, draft material, or complete research-related tasks. Their use can create the same confidentiality and accuracy risks.

The Canadian Bar Association specifically recommends policies, training, and oversight for both lawyers and non-legal staff.

Training should answer realistic questions. Can an assistant upload a client document for summarization? Can a summer student use a personal ChatGPT account for a memo? Can an AI meeting assistant join a client call?

Clear examples are more useful than telling everyone to use AI responsibly.

Check court and regulator requirements

Lawyers should also consider whether the court, tribunal, regulator, or jurisdiction involved has specific rules or notices concerning AI use.

The Canadian Bar Association notes that courts and legal regulators are developing guidance on generative AI and advises lawyers to follow applicable court directions and professional rules.

A firm that practices in several jurisdictions should avoid assuming that one AI policy answers every procedural or ethical question. Matter-specific requirements may need to be checked before AI-generated material is filed or relied upon.

Use a simple test before ChatGPT enters the workflow

Before using ChatGPT for legal work, ask whether the tool is approved by the firm, whether the prompt contains confidential or privileged information, whether unnecessary details can be removed, whether the output will be independently verified, and whether the client or court needs to know about the use.

If any of those answers are unclear, the right next step is internal review rather than guessing.

Lawyers can use ChatGPT productively, but professional obligations remain with the lawyer. The safest approach is to use AI for tasks where it genuinely assists the work, keep unnecessary client information out of prompts, verify anything that matters, and make sure the firm's policies are clear enough that lawyers and staff know where the boundaries are.

The hardest part of all this is timing. Once a prompt is submitted, it cannot be recalled, and the client name, matter number, or privileged clause a lawyer meant to strip out is already gone from the firm's control. This is the principle Sanitized AI is built on: the moment to catch confidential and privileged information is before the prompt reaches the AI tool, not after, so a rushed draft or an assistant's shortcut does not become a confidentiality problem the firm discovers later.

This quarter, take one concrete step: pick the three AI tasks your lawyers and staff actually perform most often, and write down for each whether the tool is firm-approved, what information should never appear in the prompt, and who to ask when the answer is unclear. If you would like to see how that guardrail can operate before submission rather than after, request a demo.

See how Sanitized AI stops sensitive data from leaving the prompt box. Writing your own rules instead? Start from our free AI acceptable use policy generator.