6 min readSanitized AI Team

ChatGPT for Law Firms: Useful Tool or Confidentiality Risk?

AI GovernanceComplianceData PrivacyRisk

Law firms have good reasons to be interested in ChatGPT. Lawyers can use it to summarize public material, improve a draft, brainstorm questions, explain technical concepts, or create a first-pass checklist. The same tool can become a confidentiality problem when a prompt includes client names, legal strategy, evidence, privileged communications, or other information the firm is required to protect.

That does not make ChatGPT automatically unsafe for legal work. It means law firms need to separate lower-risk uses from work involving confidential or privileged information, then make sure employees know the difference.

Start with the duty of confidentiality

For lawyers, the question is not simply whether an AI provider says its product is secure. Professional duties still apply.

The Law Society of Ontario's Rules of Professional Conduct require lawyers to hold in strict confidence information concerning the business and affairs of a client, subject to limited exceptions. The rules also state that lawyers should understand the benefits and risks of technology relevant to their practice.

The Canadian Bar Association's guidance on artificial intelligence makes the connection to generative AI directly. It warns that entering confidential or case-specific information into third-party AI systems can create confidentiality risks and says lawyers should reasonably ensure the security of an AI system before using it.

A practical law firm policy should therefore begin with a simple rule: do not place confidential client information into an AI tool merely because the task seems routine.

Using ChatGPT to create a generic deposition checklist is different from asking it to summarize a client's witness statement.

Lower-risk uses can include brainstorming with public information, rewriting non-confidential text, creating generic templates, or explaining general concepts. Higher-risk uses include uploading contracts, discovery material, client emails, medical records, financial records, legal opinions, or internal case strategy.

Law firms do not need to choose between unrestricted use and a complete ban. They can approve specific categories of work while requiring additional review for anything involving client or matter data.

Check which ChatGPT account is being used

Account type matters too.

OpenAI states that it does not use inputs or outputs from ChatGPT Business and ChatGPT Enterprise to train its models by default. Business data is also encrypted at rest and in transit.

A law firm that approves ChatGPT should specify the exact workspace employees are expected to use. It should not assume that a lawyer using a personal account receives the same organizational controls.

Even in a managed business environment, "not used for training" should not be interpreted as permission to submit any client information. Firms still need to consider confidentiality, privilege, contractual obligations, retention, access, and whether the AI actually needs the information.

Remove client details the task does not require

Data minimization is one of the easiest safeguards to apply.

Suppose a lawyer wants help improving the wording of a client update. ChatGPT may need the structure and tone of the draft, but it probably does not need the client's real name, company name, transaction value, opposing party, or matter number.

Replacing those details with neutral placeholders can preserve the usefulness of the task while reducing exposure.

The same principle applies to documents. If only one clause needs to be analyzed, do not automatically upload the entire agreement. If the AI can work from a fictional example, there may be no reason to provide real client data.

Be especially careful with privilege

Confidentiality and solicitor-client privilege are related but not identical.

The Law Society of Ontario explains that confidentiality covers a broader range of client information, while solicitor-client privilege generally protects confidential communications between lawyer and client for the purpose of seeking or giving legal advice. Privilege belongs to the client, and lawyers have a positive obligation to protect it.

That makes casual AI use particularly risky when prompts contain legal advice, client instructions, litigation strategy, or communications created within the lawyer-client relationship.

Whether a specific disclosure affects privilege can depend on the facts and jurisdiction. Lawyers should not rely on a general AI policy to answer a privilege question that requires legal analysis.

Verify the output before it enters a file or goes to court

Confidentiality is only one part of safe AI use.

Generative AI can produce incorrect legal propositions, invented authorities, missing qualifications, or wording that sounds more certain than the underlying information supports. The Canadian Bar Association notes that lawyers remain responsible for competence, supervision, and independent professional judgment when using generative AI.

A useful internal rule is that AI output is a draft, not authority. Citations should be checked against the original source. Legal propositions should be independently verified. Important client advice should be reviewed by the responsible lawyer before it is sent or relied upon.

This is especially important for court filings, research memos, opinion letters, and anything that could materially affect a client's position.

Give lawyers and staff a short decision process

Before using ChatGPT, ask:

  1. Am I using the firm's approved AI account?
  2. Does the prompt or file contain client, matter, confidential, or privileged information?
  3. Can I complete the task with public, redacted, or fictional information instead?
  4. Has this type of use been approved by the firm?
  5. Have I independently checked any important legal or factual output?

The same rules should apply to lawyers, articling students, paralegals, assistants, and other staff with access to client information.

ChatGPT can be useful in a law firm, but usefulness does not remove professional obligations. Firms get the most value when they define safe use clearly, keep unnecessary client information out of prompts, use approved business environments, and require human verification where legal judgment matters. The aim is to make sure convenience never becomes the reason confidential client information is handled carelessly.

The difficulty with a decision process is that it depends on a busy person pausing at exactly the right moment. Once a prompt is sent, it cannot be recalled, and the content becomes subject to the provider's terms of use. This is the principle Sanitized AI is built on: client and matter details are caught and redacted before the prompt reaches the AI tool, and the person sees a plain-language note explaining what was flagged and why, while there is still time to change course.

The step worth taking this quarter is narrower than a firm-wide AI policy. Pick one practice group, ask what they actually pasted into an AI tool last month, and see whether your current controls would have caught it. If you would like to see what stopping that at the prompt looks like in practice, request a demo.

See how Sanitized AI stops sensitive data from leaving the prompt box.