Managing partners, directors of operations, and IT leads at law firms

We rolled out Harvey, CoCounsel, or Copilot, and staff still use ChatGPT

Sources verified Sanitized Ai Team

The short answer

This is normal, and a sanctioned tool alone will not end it. People keep using the AI they already know because it is fast, familiar, on their phone, and sometimes better at a given task than the approved tool. Close the gap by finding out which tasks drive people elsewhere, setting a clear rule on personal accounts, and adding a control at the prompt that catches client data before it reaches any tool the firm has not approved.

The situation

The firm signed an enterprise agreement for a legal AI tool six months ago. There was a launch lunch, a training session, and a memo. Adoption dashboards look healthy. Then a clerk mentions that half the litigation group still drafts emails in ChatGPT on their phones, and an associate admits they use a personal account for summaries because it is quicker.

Nothing about this means the rollout failed. It means the firm now runs two AI environments: one it chose and one its people chose. The second one is where client information can leave without any record.

Why people keep using the unapproved tool

  • Familiarity. Many lawyers started with a consumer AI assistant before the firm bought anything. The habits, saved prompts, and muscle memory live there.
  • Speed. Opening a browser tab on a personal account takes seconds. The approved tool may need a separate login, a matter number, or a document upload workflow.
  • Personal accounts on personal devices. Phones and home laptops sit outside the firm's network and device management, so a network block does not reach them.
  • Tool gaps. Legal AI tools are built for legal work. Staff reach for a general assistant for everything else: a tricky client email, a spreadsheet formula, a translation, a quick rewrite. Some of those tasks still carry client data.
  • Access gaps. In some firms, licences go to lawyers first. Assistants, clerks, and students may not have a seat at all.

This pattern is not unique to law. In a 2026 Gartner survey of more than 12,000 employees and managers, 88% of employees with enterprise AI access also used personal AI tools for business tasks, often to save time. For background on the wider pattern, see what shadow AI is.

What the rules actually say

No Canadian law society rule names a specific AI product or requires a firm to buy one. The duties are the familiar ones: confidentiality, competence, supervision, and candour with clients.

The Law Society of Ontario's practice resource on generative AI and professional obligations advises licensees to review a tool's terms of use, to avoid entering confidential or identifying client information into systems without appropriate confidentiality, security, and retention safeguards, and to give employees clear guidelines on what may and may not be entered. It describes supervising AI use as similar to supervising a non-licensee employee.

The Law Society's checklist for building a generative AI policy goes further on this exact situation. It asks firms to decide whether individuals may use personal accounts for work product, and suggests considering allowing only accounts created under the organization's own email and credentials. It also asks which privacy settings must be turned on in allowed tools. These are guidance, not binding rules, but they show what a regulator expects a firm to have thought about.

Enterprise tools usually come with business terms. For example, Microsoft states that organizational use of Copilot is covered by its Data Protection Addendum and Product Terms, and that prompts and responses are not used to train foundation models. Legal AI vendors publish their own commitments; read your contract rather than the marketing page. None of those terms apply when the same person opens a personal account in another tab.

Why policies and bans fall short

A policy that says "use only the approved tool" is necessary. It is not sufficient, because it depends on each person remembering it at the moment of a deadline, on a device the firm may not manage. The firm learns about a breach of the policy only if someone volunteers it.

Blocking consumer AI sites on the firm network has a similar limit. It stops the easy path on managed laptops and pushes the rest onto phones, where the firm sees nothing. We cover this in more depth in why banning ChatGPT does not work.

The underlying issue is that the rollout controlled which tool the firm pays for. The risk sits in which data leaves, through whatever tool is open.

What a practical control looks like

  1. Ask why. Run a short, no-blame survey or a few conversations: which tasks send people to other tools? Fix the gaps you can in the approved tool, and give seats to the people who lack them.
  2. Write a clear rule on personal accounts. Decide whether personal AI accounts may be used for any firm work, and for what data. Put it in the policy in one sentence.
  3. Configure the approved tool well. Turn on the privacy and retention settings the vendor offers, and document them so you can answer client questionnaires.
  4. Train on data, not brands. Teach people which categories never go into an unapproved tool: client names and identifiers, personal information, deal terms, and privileged advice.
  5. Set an incident path. Make it easy to report a mistake quickly. See what to do in the first 48 hours after a client file is pasted into ChatGPT.
  6. Measure the gap over time, so you can tell whether the approved tool is winning.

Sanitized Ai is a browser extension that works across the major AI assistants, approved or not. When someone is about to submit client identifiers, personal information, or deal terms, it redacts or blocks that content before submission and explains in plain language what was flagged and why. That turns the moment of risk into a short lesson, without taking away the tool the person chose.

For the firm, administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never see prompt content. That shows where unapproved use concentrates and whether it is falling, which is useful evidence of reasonable safeguards when a client or insurer asks. See how it fits law firms.

Frequently asked questions

Did we waste money on the enterprise legal AI tool?

No. A sanctioned tool with business terms gives staff a safer default and gives the firm contractual commitments it can point to. The mistake is assuming the rollout ends unapproved use. It reduces it, and the remaining use needs its own control.

Should we block ChatGPT on the firm network?

Blocking tends to move use onto personal phones and home laptops, where the firm has no view at all. Most firms get better results from a clear rule on personal accounts, a well-supported approved tool, and a control that stops client data at the prompt regardless of which AI assistant is open.

Does the Law Society of Ontario say anything about personal AI accounts?

Its checklist for building a generative AI policy asks firms to decide whether staff may use personal accounts for work, and suggests considering allowing only accounts created with the firm's own email and credentials. It is guidance, not a rule, but it is a useful benchmark.

Is Microsoft Copilot safe for client information?

Microsoft states that organizational use of Copilot is covered by its Data Protection Addendum and Product Terms and that prompts and responses are not used to train foundation models. Whether it fits a given matter still depends on your licence, configuration, and client instructions, so confirm with your IT provider and, where relevant, the client.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Related guides

Further reading