5 min readSanitized AI Team

What a Partner Owes When an Articling Student Pastes a Client File Into AI

AI GovernanceRiskComplianceData PrivacyData Security

An articling student is behind on a research memo, so they paste the client's engagement letter and a summary of the file into ChatGPT to get a faster first draft. The student never mentions it. Three weeks later the partner signs the memo, bills the client, and never learns that the client's confidential information left the firm's control on a personal account. The work looked fine. The exposure is invisible — and it is the partner's to answer for.

This is the scenario that should keep supervising lawyers up at night, and it has almost nothing to do with the sanctioned-brief stories about fabricated citations. The risk here is not a bad answer. It is confidential client data leaving the firm the moment it enters a prompt box, on a tool no one at the firm chose or controls.

The junior's mistake is the supervising lawyer's liability

Rules of professional conduct treat delegated work the way they always have: whatever an articling student, junior associate, or assistant produces, the responsible lawyer owns. A supervising lawyer is expected to oversee the work of those they delegate to, and errors flow uphill. An AI tool used by a junior sits inside that same framework — it behaves like another junior whose output you are accountable for, except this one silently transmits whatever it is fed.

That changes the nature of the supervisory duty. It is no longer enough to review the memo for accuracy. The partner is also responsible for how the memo was produced, because the method itself — pasting client confidences into a public AI tool — can breach confidentiality and, in the wrong circumstances, put solicitor–client privilege at risk. Once that information is submitted, it may become subject to the provider's terms of use, which can grant broad rights to retain and process it. There is no recall button. The disclosure has already happened before anyone at the firm knows a prompt was typed.

And it will happen. Juniors reach for the tools they already use. In a 2026 Gartner survey, 88% of employees with enterprise AI access also used personal AI tools for work; Cyberhaven found in 2025 that 82.8% of legal documents entered into AI tools went to non-corporate accounts. The people closest to your client files are the ones most likely to paste them somewhere you cannot see.

A firm policy the partner cannot see is not supervision

Most firms have responded with a policy: don't put client information into ChatGPT. The trouble is that a policy no one can observe being followed is not a control — it is a hope. If a student uses a personal account on their own laptop, the firm has no record that the rule was broken, and no record that it was kept.

That gap cuts both ways. It means risky use goes undetected. It also means the partner has no way to demonstrate that reasonable steps were taken, which matters when something goes wrong. Discipline and penalties can be reduced when a lawyer shows they took adequate steps to prevent the harm. A partner who can point to a record showing that sensitive client data was caught before it reached an AI tool has evidence of reasonable safeguards. A partner relying on an unenforced memo has a document that proves the rule existed and nothing about whether it worked.

This is why bans and paper policies fail the supervisory test. They are written to control which tool a junior uses. But no one dictates which AI a lawyer or student reaches for — they use what is fast and familiar. The supervisory question is not which tool but what data leaves. Reframe the duty around the data and the picture gets clearer: the partner needs visibility into where client information is at risk, and a way to stop it from leaving before it does.

Visibility into risk, not surveillance of people

There is an obvious tension here. A partner needs to know where AI use is creating exposure across their staff. But nobody wants to read what an articling student typed into a prompt, and turning supervision into keystroke surveillance corrodes the trust a training relationship depends on.

The distinction that resolves it: a supervising lawyer needs to see the policy event — that client data was flagged, in what kind of prompt, how often, and where risk concentrates — not the contents of anyone's work. Knowing that risky pastes are being caught in the corporate group, or that a particular workflow keeps triggering flags, is exactly the visibility supervision requires. Reading the prompt itself adds nothing to the duty and takes on new problems.

There is also a moment the junior deserves. When a student is about to paste a client's file into a public tool, the most useful thing that can happen is not silent logging — it is an explanation, in plain language, of what was flagged and why. That turns a near-miss into training, and a student who learns why the engagement letter should not go into ChatGPT is a student who will not make the mistake on the next file. Over time, that record shows the firm's people getting measurably better at safe AI use — which is what demonstrable diligence actually looks like.

This is the principle Sanitized AI is built on: sensitive client information is caught and redacted before a prompt reaches the AI tool, the junior gets an in-the-moment explanation, and the supervising lawyer sees that risk was managed — never what anyone typed. The control acts where the duty lives, before the disclosure that cannot be undone.

The question to answer this quarter

Ask it plainly: if an articling student pasted a client file into ChatGPT tomorrow, would you ever know — and could you show a client, or a regulator, that your firm took steps to prevent it? If the honest answer is no on both counts, the supervisory gap is already open. It is worth closing before a signed memo turns into a disclosed confidence.

If you want to see how a firm can protect client data at the prompt while giving partners visibility into risk without reading anyone's work, request a demo.

See how Sanitized AI stops sensitive data from leaving the prompt box.