NormalNormal

Client confidentiality when your firm uses AI: the questions to ask any vendor

Client confidentiality when your firm uses AI: the questions to ask any vendor

Short answer: confidentiality isn't a reason to avoid AI. It's a checklist — and any vendor who bristles at the checklist is telling you something. Here are the questions, in the order we'd ask them, plus the one option most vendors never bring up: running the whole thing on hardware inside your own office.

Law firms carry duties other businesses don't. Client confidences are the currency of the practice, and the ethics rules — competence, confidentiality, supervision — apply to AI the same as to an associate. Used carefully, AI is fine. Used carelessly, it's a breach with your name on it.

The questions, in order

1. Where does client information physically go? Which servers, in which country, owned by which companies? Get the list of every subprocessor. If the vendor can't produce it in writing, stop there.

2. Is my firm's data used to train anyone's model? The correct answer is no, contractually, for your data and for anything derived from it.

3. Who at the vendor can see our information? Under what circumstances, with what controls, and with what logging?

4. Can this run on hardware in our own office? This is the question that separates vendors from slogans. For firms with real confidentiality requirements — litigation strategy, sensitive client matters, simply a low tolerance for the cloud — the right architecture is local: your records stored on your equipment, the AI running on your equipment. It's a real option, it costs less than most firms expect, and the fact that a vendor never mentioned it tells you who their product was built for.

5. What happens on day one of us leaving? Your data, your documents, and any work product should return to you, in usable formats, on request. If exit looks murky, imagine it during a dispute.

6. How does the ethics piece work in practice? The duties don't change with new tools: competence includes understanding the technology you deploy; confidentiality applies to everything the tool touches; supervision means a human reviews what the AI prepares before it goes anywhere. The ABA's guidance on generative AI (Formal Opinion 512) frames exactly this kind of review. A vendor who designs for human review — drafts, never autonomous sends — is aligned with your obligations. One who advertises "fully autonomous" is aligned with your malpractice carrier's nightmares.

What good looks like

A deployment that respects confidentiality has a shape you can describe in one breath: the assistant reads only what you approved, stores what it learns on systems you control (yours — or hardware in your office if you asked for that), prepares drafts with citations, and never sends a word to a client without a lawyer's review. Conflicts and access walls you already maintain in your practice management system carry through automatically.

A realistic first step

Before you pick any tool, write down your five confidentiality questions and make every vendor answer them in writing. You'll learn more from the answers than from any demo — including ours. And if the on-premises option matters to you, ask about it by name. We're glad to walk through the whole list — or show you how this works for law firms generally.

Related: when a law firm should automate intake · AI medical chronologies without the hallucination risk · what on-premises actually means.

Talk with us

Let's see if your business is a good fit.

Book a 30-minute conversation with us. We will ask how your business runs and where your records live, then tell you plainly whether this makes sense and what a first step would look like. If it is not a fit, we will say so.