Education8 min read

Can Law Firms Use ChatGPT With Client Data? The Confidentiality Question Answered

Not safely on consumer tiers: free and Plus ChatGPT can train on your prompts. Here's what confidentiality actually requires before AI touches client files.

By Nic Chin|

The short answer: not on the free or Plus tiers, and not without a firm policy — but the answer isn't "never use AI." ChatGPT's consumer tiers can use your prompts for model training by default, which makes pasting client documents into them a confidentiality problem from the first keystroke. The professional path is narrower: tools with contractual confidentiality, no training on your data, and isolation between your documents and everyone else's.

Here's the full picture — what's actually risky, what the sanctions cases really teach, and what a defensible setup looks like for a small or mid-sized firm.

What Actually Happens to Text You Paste Into ChatGPT?#

It depends entirely on the tier — and most lawyers experimenting with AI are on the wrong one.

  • ChatGPT Free and Plus: prompts can be used for model training by default. Your client's settlement terms become potential training data unless you find and toggle the opt-out. Conversations also sit in OpenAI's retention systems subject to their policies — and, as some firms learned uncomfortably, chat logs can be discoverable. Major U.S. law firms have issued client advisories warning that conversations with AI chatbots carry no legal privilege.
  • ChatGPT Enterprise and Team: zero data retention options and contractual confidentiality that consumer tiers don't offer. Materially better — though still a general-purpose tool with no citations, no document-grounding, and no refusal behavior when it doesn't know.

The test for any tool is four questions: Where does the text live? Who can read it? Does the vendor train on it? Can you prove the answers in writing? If you can't answer all four, the tool hasn't earned client data.

Is This Actually a Breach of Confidentiality Rules?#

Confidentiality obligations attach to disclosing client information to third parties without informed consent. Submitting client documents to a system that retains them, can train on them, and offers no contractual confidentiality is hard to distinguish from disclosure. Several bar associations have reached effectively that conclusion, and North Carolina's bar association now frames the realistic question as which policy, not whether — because lawyers are using these tools regardless.

The numbers back that up: Clio's Legal Trends data shows 79% of legal professionals using AI tools, while 44% of firms still have no formal governance policy. That gap — widespread use, absent policy — is where confidentiality incidents come from. A ban doesn't close the gap; it just pushes usage underground onto personal accounts, which is the worst possible configuration.

What About the Hallucination Sanctions Everyone's Heard About?#

They're real, they're escalating, and they're a different risk from confidentiality — but they teach the same lesson. The progression:

The Wadsworth detail matters most: the problem isn't one bad product, it's any AI output that can't be verified against a source. A general-purpose model generates plausible text; it doesn't know what your documents say, and it doesn't show its work.

That's the design difference with document-grounded systems. SureCiteAI answers only from documents your firm uploaded, cites the exact source passage for every answer, and refuses to answer when the documents don't support one. You can't be sanctioned for a citation you verified by clicking through to the source — verification is built into the workflow rather than left to discipline. The plain-English mechanics are in our RAG guide for business leaders.

Consumer AI vs a Confidentiality-Grade Setup#

| Question | ChatGPT Free/Plus | ChatGPT Enterprise | Document-grounded workspace (SureCiteAI) | |---|---|---|---| | Trains on your prompts? | Yes, by default | No (contractual) | Never | | Where do documents live? | OpenAI retention systems | Enterprise controls | Your firm's isolated tenant | | Answers cite sources? | No | No | Every answer, to the passage | | Behavior when it doesn't know | Generates anyway | Generates anyway | Refuses to guess | | Other tenants' data mixed in? | N/A (no doc store) | N/A | Row-level isolation per firm | | Setup | Instant | IT procurement | ~5 minutes, no IT project |

The middle column is fine for what it is — drafting help on non-confidential text. The right column is what it takes for the actual files.

What Should a Small Firm's AI Policy Actually Say?#

You don't need 40 pages. Four rules cover most of the risk:

  1. Client-identifying information never goes into consumer AI tools. No exceptions, including "I anonymized it" (de-anonymization through context is trivially easy in legal documents).
  2. Approved tools only, with written confidentiality terms. A short list: which tool, which tier, what it's approved for.
  3. Every AI output gets verified against a source before it's relied on. Citations clicked, passages read. This is the rule the sanctions cases enforce at $110,000 a lesson.
  4. Disclosure where required. Some courts now require certification of AI use in filings; know your jurisdictions.

Pair the policy with a tool that makes compliance the path of least resistance. If the approved tool is better at answering "what does the indemnity clause in the Hartmann contract say?" than ChatGPT is — because it actually has the Hartmann contract and cites it — the policy enforces itself. Choosing that tool is its own topic: see how to choose an AI document search platform.

What Does a Realistic Rollout Look Like for a Small Firm?#

Policy documents don't change behavior; workflows do. Here's the rollout pattern that works for firms without IT departments, in four weeks of part-time effort:

Week 1 — Find out what's actually happening. Ask, without sanctions attached: who's using AI for what? Expect the answer to surprise you — the Clio data (79% adoption, 44% no policy) means your firm almost certainly has unmanaged usage today. You can't design rules for behavior you haven't seen. The amnesty framing matters: punished disclosure goes underground.

Week 2 — Pick the approved stack. Two tools cover most legal use cases: one general assistant on a contractual-confidentiality tier for non-client work (drafting, research orientation, summarizing public material), and one document-grounded workspace for anything touching client files. Get the confidentiality answers in writing for both.

Week 3 — Load one practice area and pilot. Choose your most document-heavy practice group. Upload its precedents, closed-matter files, and templates into the isolated workspace. Give the group two weeks and a one-page cheat sheet: what's approved, what's banned, and the verification rule. Real questions from real matters will surface the workflow issues no policy meeting anticipates.

Week 4 — Write the policy from what you learned. Now the four rules from the section above get specifics: named tools, named tiers, named owners. Add a quarterly review — AI vendor terms change, and a policy with a review cadence stays credible while a static one decays into shelfware.

The pattern to avoid is the inverted version: six months drafting a comprehensive policy, then a firm-wide announcement, then discovering usage simply moved to personal phones. Behavior follows the path of least resistance; your job is making the compliant path the easy one. A workspace that answers document questions better than ChatGPT — because it actually contains your documents and cites them — does more for compliance than any memo.

The Billable-Hour Math of Doing This Right#

A 12-lawyer firm where each lawyer loses 30 minutes a day hunting through documents is losing roughly 1,500 hours a year — at $250/hour blended, about $375,000 in capacity (the full calculation is in the hidden cost of document chaos). That's the prize that pushes lawyers toward AI tools in the first place. The confidentiality question isn't whether to capture that value — 79% adoption says that ship has sailed — it's whether the firm captures it through a controlled workspace or leaks client data through personal ChatGPT accounts trying.

FAQ#

Is it ever OK to use free ChatGPT at a law firm?#

For genuinely non-confidential work — explaining a doctrine, drafting a marketing email, summarizing a published case you provide — yes, with verification. The line is client information: anything a client gave you, or that identifies their matter, stays out.

Does anonymizing client documents make ChatGPT safe?#

Mostly no. Legal documents are dense with re-identifying context (deal size, dates, industry, jurisdiction), and effective anonymization takes longer than the AI saves. A contained workspace removes the problem instead of managing it.

Are conversations with AI chatbots privileged?#

No. Firms have warned clients explicitly that AI chat logs carry no privilege and can surface in discovery. Treat anything typed into a consumer chatbot as potentially readable by opposing counsel someday.

What's the difference between ChatGPT Enterprise and a tool like SureCiteAI?#

Enterprise ChatGPT solves the retention and training problem but remains a general-purpose generator: no document grounding, no citations, no refusal behavior. SureCiteAI is built for the specific job of answering questions from your firm's documents with verifiable sources — the thing the sanctions cases punish lawyers for not having.

How do we roll this out without an IT department?#

Pick a tool with tenant isolation and no integration requirements, load one practice area's documents, and run a two-week pilot with the four-rule policy above. Setup guide: set up an AI knowledge base in 5 minutes.

What should we ask any AI vendor before signing?#

Get written answers to: Do you train models on our data? Where is it stored and how is it isolated from other customers? Who at your company can access it? What happens to it if we leave? A vendor who hesitates on any of these has answered the real question.


Want AI that's built for client-confidential work? Try SureCiteAI — your firm's private, isolated document workspace with source-cited answers. Five-minute setup, no IT project, and it refuses to guess.

Stop Searching. Start Finding.

Upload your documents and get AI-powered answers in minutes. No coding, no IT department, no complex setup.

No credit card required. Setup takes less than 5 minutes.