The moment you paste text into an AI tool, it leaves your control. For a lawyer that is not a privacy preference — it is the duty of confidentiality, and sometimes privilege, in play. Here is how to use AI without putting client information at risk.
Educational guide · written for in-house counsel · tool details current as of May 2026 · not legal advice
Two risks, kept separate
"Don't put confidential things into AI" is the usual shorthand, but it blurs two distinct issues that deserve separate thought:
Confidentiality. ABA Model Rule 1.6 obligates a lawyer to protect information relating to the representation. Sending that information to an AI vendor is a disclosure to a third party, and you are responsible for understanding what the vendor does with it.
Privilege and work product. Attorney-client privilege and the work-product doctrine protect certain communications and materials. Disclosure to an outside party can, depending on the facts, undermine that protection. Whether a particular AI use creates a real waiver risk is a fact- and jurisdiction-specific legal question — which is exactly the analysis to run before adopting a tool, not after.
ABA Formal Opinion 512 (July 2024) makes the confidentiality duty explicit: it addresses a lawyer's use of generative AI directly under Model Rule 1.6, among other duties. A lawyer is expected to understand a tool's data practices well enough to use it competently.
What actually happens to your data
The answer depends entirely on which tier of a tool you use. The consumer version and the enterprise version of the same product can behave very differently. The details below are current as of May 2026 — and they change, so confirm them against each vendor's current terms before relying on them.
Consumer tiers
On the personal, free, and individual-paid plans of the major chatbots, your conversations may, by default, be used to train the vendor's models, and in some cases sampled by human reviewers — unless you opt out:
ChatGPT (Free / Plus / Pro): conversations may be used to improve the models by default. Opt out under Settings → Data Controls → "Improve the model for everyone." Temporary Chat is not used for training.
Claude (Free / Pro / Max): Anthropic updated its consumer terms in 2025 so that consumer chats are used for training unless you opt out, with extended retention for those who do not. Opt out in Privacy Settings.
Gemini (consumer): conversations may be used for model improvement and reviewed by humans by default. Opt out by turning off "Gemini Apps Activity," or use a temporary chat.
Opting out matters — but it is not the same as an enterprise agreement. Even opted out, consumer tiers retain data for a period, and you have no data processing agreement and no contractual control over the relationship.
Enterprise, business, and API tiers
The business and enterprise tiers of the same vendors are built differently. As a general matter, across ChatGPT Business/Enterprise, Claude for Work/Team/Enterprise, Gemini for Google Workspace, and the vendors' APIs: customer content is not used to train the models, is not routinely human-reviewed, and the relationship can be brought under a data processing agreement with defined retention. This is the tier built for regulated and confidential work.
Consumer tiers
Enterprise / business / API
Trains on your data
By default, unless you opt out
No
Human review of chats
Possible (sampling)
Generally no
Data processing agreement
No
Available
Retention control
Vendor-set
Configurable by your organization
Fit for client-confidential work
No
Yes, with the right agreement
The cautionary tale
Anthropic's 2025 change — consumer Claude chats moving to opt-out training — is the reason you cannot set this once and forget it. A vendor's data terms can change. Re-check them, and re-check your settings, periodically.
Practical rules for client-confidential work
Default to an enterprise tier under a DPA. For anything touching a client matter, use a business or enterprise account your organization controls — not a personal login.
Turn off training everywhere. On any consumer account that exists at all, opt out of model training as a baseline, even for non-client use.
Abstract the question. You often do not need the real facts. Ask the legal question in the abstract, or with names and identifying details removed, rather than pasting the actual document.
Keep privileged material out of consumer tools. Privileged communications and core work product do not belong in a consumer chatbot, opted out or not.
Read the data terms — and re-read them. Know whether a tool trains on input, how long it retains data, and where that data sits. Treat terms as something that changes.
Check client and engagement constraints. Outside-counsel guidelines and client engagement terms increasingly address AI use and may require notice or consent. Confirm before you proceed.
Mind connectors and uploads. Connecting an AI tool to your email or document system widens what it can reach. Grant the minimum access needed and review it.
A workable default
Enterprise tier, data processing agreement in place, training off, sensitive facts abstracted where possible — and a clear internal rule about what may never be pasted in. With that foundation, AI becomes genuinely usable for real legal work.
A confidentiality checklist
The tool is an enterprise/business tier, not a personal consumer account.
A data processing agreement is in place and its retention terms are understood.
Model training is turned off on every account in use.
Facts are abstracted or anonymized wherever the task allows.
No privileged communication or core work product goes into a consumer tool.
Client engagement terms and outside-counsel guidelines have been checked for AI restrictions.
Connector and upload access is limited to what the task requires.
There is a date set to revisit the vendor's terms and your settings.
Sources & further reading
ABA Formal Opinion 512, "Generative Artificial Intelligence Tools" (July 29, 2024) — ABA announcement