The situation
A client is six months from launching a new device. The engineering lead sends the firm the product specification, the roadmap for the next two versions, and a list of competitor patents the sales team keeps hearing about. An associate is asked to prepare a first-pass freedom-to-operate analysis. Late in the evening, facing forty patents and a long specification, the associate pastes the claims and the product description into a chatbot on a personal account and asks it to map one onto the other.
Patentability opinions carry the same exposure from the other direction. The input is an unfiled invention disclosure, and the output is a view on whether it is new and inventive over the prior art. Both kinds of opinion combine the client's most confidential technical information with the firm's legal judgment about it.
What the rules actually say
No Canadian regulator has issued AI rules specific to opinion work. The duties that apply are the general ones, and they fit this work closely.
Confidentiality and privilege. Lawyers owe a duty of confidentiality under their law society's rules. For patent agents, section 16.1 of the Patent Act gives privilege to communications between an agent and a client that are intended to be confidential and made to seek or give advice on protecting an invention. A patentability opinion fits that description comfortably. Whether an agent's freedom-to-operate advice, which concerns other people's patents, fits the same wording is a question to put to counsel. In every case, privilege rests on confidentiality, and a disclosure to a third party under that party's terms weakens the argument that confidentiality was kept. The patent agent privilege guide covers this in more depth.
Novelty. For patentability work, section 28.2 of the Patent Act bars a claim if the subject matter was made available to the public before the claim date, with a one-year grace period for disclosures that trace back to the applicant. Whether a prompt submitted to an AI provider counts as making something available to the public is unsettled. The point is not that it automatically does; it is that the firm has created a question it cannot answer with confidence, about an invention it was hired to protect.
Later scrutiny. Opinions do not stay in the drawer. In the United States, 35 U.S.C. s. 298 says an accused infringer's failure to obtain or present advice of counsel cannot be used to prove willful infringement, but a client who chooses to rely on an opinion is in a different position. A client who relies on an opinion as a defence generally has to put that opinion forward, which can open related communications to scrutiny. If an opinion is ever put in issue, the way it was prepared, including which tools touched the client's information, may be examined.
Why policies and bans fall short
Most IP practices already have a line in the policy manual about not putting client information into public AI tools. The problem is that opinion work is exactly the kind of task that tempts people to break it: long documents, repetitive comparison, a deadline, and a tool that is very good at summarizing. A ban moves the work onto personal accounts where the firm has no visibility at all. Gartner reported in 2026 that 88% of employees with enterprise AI access also use personal AI tools for work.
A policy also cannot tell the associate, in the moment, which part of what they are about to paste is the problem. The patent numbers are public. The product specification is not. The draft conclusion is privileged. People need that distinction at the point of use, not in an annual training session. This is the same gap described in why AI acceptable use policies struggle.
What a practical control looks like
- Classify opinion inputs. Treat unreleased product specifications, roadmaps, unfiled invention disclosures, claim charts against the client's product, and draft conclusions as restricted. Treat published patents and prior art as ordinary.
- Sanction one tool for opinion support. Choose an enterprise AI tool, review its terms on retention, training, and access, configure the settings, and restrict opinion work to that tool.
- Keep the working file clean. Record in the matter file which tools were used for what, so the firm can answer the question if the opinion is ever examined.
- Train on the distinction. Show staff concrete examples of what can and cannot go into a prompt for opinion work.
- Have an incident path. If restricted information reaches an unapproved tool, the responsible partner should know the same day and decide whether the client needs to be told.
- Talk to the client. Many technology clients now ask how their outside counsel uses AI. A short, accurate answer builds trust.
Sanitized Ai is a browser extension that supports these steps at the prompt. When someone is about to submit a product specification, invention details, client identifiers, or other sensitive data to an AI tool, it redacts or blocks that content before submission and explains in plain language what was flagged and why. Administrators see a dashboard of flagged events (which tool, what type of data, which policy, when) without ever seeing the prompt itself.
That record will not decide any privilege or novelty question, but it can help a firm show that it took reasonable steps to keep opinion inputs confidential. It does not review the analysis or check citations; the opinion remains the professional's work. For how this fits a firm's broader duties, see Sanitized Ai for law firms.