The duty you carry
Three duties meet in the prompt box: confidentiality under your law society's rules, solicitor-client privilege, and supervision of the people doing the work. Courts are prepared to treat pasting client material into a public AI tool as voluntary disclosure, and the duty of technological competence means "we didn't know the tool did that" is not a position a firm wants to argue. What clients and regulators expect is what they have always expected: reasonable safeguards, demonstrably applied.
The moment it breaks
Synthetic example. The real version happens on your busiest day.
Caught at the prompt box: the drafting help still arrives, the client and the matter never leave the firm, and the event is logged as evidence of supervision.
Caught, in your vocabulary
Client and party names
People, companies, opposing parties: the identifiers that connect a prompt to a matter.
Matter facts and deal terms
Figures, dates, and draft language whose confidentiality is the point of the retainer.
Contact and account details
Client emails, phone numbers, and payment details sitting in intake notes and correspondence.
The rules you answer to
Law society rules
Confidentiality, supervision, and the duty of technological competence adopted across Canadian law societies. These duties follow the work into every new tool.
Solicitor-client privilege
Privilege depends on confidentiality being kept. Disclosure to a third-party AI tool is a voluntary act no deletion request can undo. Prevention is the only remedy that works.
PIPEDA & Quebec Law 25
Client personal information is still personal information, and Law 25 expects control over its communication, with penalties reaching C$25M or 4% of worldwide turnover.
Answers for your situation
GuidesAn associate pasted a client file into ChatGPT: the next 48 hours
Treat it as a possible confidentiality breach, not a training issue. In the first 48 hours, preserve the facts, find out exactly what was submitted and under which account, assess whether privacy law requires a report (PIPEDA or Quebec's private sector act), decide how the client will be told, and give your professional liability insurer prompt notice. Confirm each step with your law society's practice advisors and your insurer.
Can a Quebec lawyer use ChatGPT? The Barreau du Québec, professional secrecy, and generative AI
Yes: the Barreau du Québec encourages supervised use of generative AI, but professional secrecy leaves no room for approximation. Its practical guide states that simply entering information protected by professional secrecy into an open system, such as a public AI tool, is a breach, even without any actual reproduction or disclosure. In practice, that means anonymizing, keeping data to the strict minimum, not using the tool when anonymizing is impossible, and supervising how the whole team uses it.
Can litigators put discovery documents into AI tools under the implied undertaking rule?
Canadian law has not settled this, so treat discovery material as restricted. Documents and answers obtained on discovery may be used only for the proceeding in which they were produced, and in Ontario rule 30.1.01 expressly binds parties and their lawyers. Building a chronology for the same case may be a permitted use, but sending the material to an AI provider whose terms allow retention or training raises a real question about disclosure to a stranger to the litigation, so use a vetted tool and get advice first.
Can patent and trademark agents use ChatGPT under the CPATA Code?
Yes, with care. The CPATA Code of Professional Conduct does not mention or prohibit generative AI, and CPATA's 2025 guidance treats it as a tool agents may adopt if they use it safely and competently. The Code does require agents to hold client information in strict confidence, take reasonable care to protect it, and directly supervise their staff, so confidential client material should not reach AI tools the firm has not vetted.
Can researchers use AI tools on invention disclosures before a patent is filed?
Not with the unfiled technical details, unless the tool is one the institution has approved for confidential research information. A prompt is not automatically a public disclosure, but it hands the invention to a third party under that party's terms, creates novelty questions nobody can fully answer, and Europe offers no general grace period to fall back on.
Can you translate patent specifications with AI for national phase or French filings?
Often yes for text that is already public, such as an international application that WIPO has published, provided a qualified person checks the result, because the applicant is responsible for the accuracy of any translation filed with CIPO. The risk sits elsewhere: unpublished applications, claim amendments not yet filed, client instructions, and new matter for divisional or continuation filings are still confidential. Those should not go into AI or translation tools the firm has not vetted.
Can you use AI tools to draft freedom-to-operate and patentability opinions?
Yes, but only with tools and settings the firm has approved, and never with the client's unreleased product details, the unfiled invention, or the draft conclusions pasted into a personal AI account. These inputs are confidential, often privileged, and may later be examined in litigation, so the firm needs to control what reaches any AI tool before it is submitted.
Canadian firms prosecuting at the USPTO: how do you meet US guidance on AI use?
Canadian agents registered to practise before the USPTO are bound by its rules, and the USPTO's April 2024 guidance explains how those existing rules apply to AI tools. In practice, that means keeping client information confidential under 37 CFR 11.106, personally reviewing anything filed under 37 CFR 11.18, disclosing information material to patentability, and supervising staff. The guidance specifically warns that entering invention details into AI tools can disclose confidential information and raise export control issues, so firms need controls on what reaches those tools.
Does pasting into AI affect patent and trademark agent privilege?
It can, although no Canadian court has yet applied the statutory agent privilege to AI tools. Section 16.1 of the Patent Act and section 51.13 of the Trademarks Act protect agent and client communications that are intended to be confidential and made for advice on protecting an invention or a trademark, and the protection ends if the client expressly or implicitly waives it. Sharing that advice with a third-party AI service gives an opposing party an argument about confidentiality and waiver, so the safer course is to keep privileged material out of tools the firm has not vetted.
How does a law firm with outsourced IT and no security team govern AI?
Give ownership to the managing partner and an operations lead, not to the MSP. Adopt a short policy and one sanctioned AI tool, then ask the MSP to deploy browser-level controls through the browser management it already runs, and review a simple monthly report. The professional duties stay with the firm; the MSP carries out the technical pieces.
Is it safe to put an unannounced brand name into an AI tool during trademark clearance?
Not in a personal or unapproved AI account, and not together with launch plans. Until the application is filed, a new mark and the strategy around it are confidential client information, and in Canada entitlement turns on who filed or used first, so a firm should keep that combination out of AI tools it does not control.
M&A boutiques: can the deal team put data room documents and diligence summaries into AI?
Only into a tool the firm has vetted, and only if the NDA, the client and the law allow it. Evaluation material is usually shared under an NDA that limits who may receive it and what it may be used for, personal information in the data room is often shared under a privacy law exception tied to the transaction, and a public company deal may involve undisclosed material facts. Pasting that material into a personal AI account can fall outside all three.
New managing partner: a 90-day AI risk checklist
Spend days 1 to 30 finding out how AI is actually used across the firm, days 31 to 60 deciding on a policy, approved tools, and rules for client data, and days 61 to 90 putting controls and training in place and collecting evidence that they work. Anchor each step in the guidance your law society has already published, and in what clients and insurers are starting to ask.
Outside counsel guidelines with AI clauses: how to comply
AI clauses in outside counsel guidelines tend to ask for the same things: notice or consent before AI is used on the client's matters, no client confidential information in public AI tools, no training on client data, fair billing for AI-assisted work, and disclosure of which tools the firm uses. Comply by recording each client's terms, mapping every obligation to a control and a piece of evidence, and making sure the rule operates at the prompt, not only in a memo.
We rolled out Harvey, CoCounsel, or Copilot, and staff still use ChatGPT
This is normal, and a sanctioned tool alone will not end it. People keep using the AI they already know because it is fast, familiar, on their phone, and sometimes better at a given task than the approved tool. Close the gap by finding out which tasks drive people elsewhere, setting a clear rule on personal accounts, and adding a control at the prompt that catches client data before it reaches any tool the firm has not approved.
What does the Law Society of BC's generative AI guidance require?
The Law Society of British Columbia has not created AI-specific rules. Its practice resource, Guidance on Professional Responsibility and Generative AI, applies existing BC Code duties: competence (rule 3.1-2), confidentiality (rule 3.3-1), candour, supervision (rule 6.1-1), fair fees, and the records security obligations in Law Society Rules 10-3 and 10-4. Its core advice on confidentiality is to leave client confidential and identifying information out of generative AI tools, and to consider informed client consent where redaction is not possible.
What does the Law Society of Ontario say about generative AI?
The Law Society of Ontario has not adopted AI-specific rules. Its April 2024 white paper and companion practice resources explain how existing duties apply to generative AI: technological competence under rule 3.1-2, confidentiality under rule 3.3-1, supervision under rule 6.1-1, candour with clients, fair billing, and not misleading a tribunal. The guidance tells licensees not to put confidential or privileged client information into a generative AI tool unless adequate safeguards are in place.
From our research
How One Careless AI Prompt Can Waive Privilege
A single prompt pasted into a public AI tool can strip privilege or break confidentiality on a client's matter. Early court rulings show the disclosure is voluntary — and irreversible. Here's how firms are closing the gap.
What the Duty of Technological Competence Now Requires When Your Firm Uses ChatGPT
Law societies expect lawyers to understand the technology they use. When an articling student pastes a client's file into ChatGPT, that duty is no longer abstract — it's a disclosure you can't recall.
What a Partner Owes When an Articling Student Pastes a Client File Into AI
An articling student pastes a client file into ChatGPT to speed up a memo. The partner signs the work and carries the risk. Here is what supervisory duty actually requires when juniors use AI.
Compliance standards that apply
Key terms
AI tools your team may already use
Also built for
See it on your own scenarios
Twenty minutes, your examples, no slideware. Or start with the five-question readiness check. No email required.