
Direct Answer
Law firms can use AI while protecting client information by establishing clear rules about which AI tools employees may use and what information may be entered into them.
Before using AI for client work, the firm should understand:
- What information will be entered
- What happens to information submitted to the AI platform
- Whether information is retained or used to train or improve the service
- What security and privacy controls are available
The firm must also decide:
- Whether confidential or sensitive information may be entered
- Who may use the tool
- How AI-generated work will be reviewed
Employees should not enter confidential client information into an AI tool simply because the tool is readily available.
Why This Matters
AI makes it easy to paste documents, emails, contracts, case information, and other material into a prompt.
That convenience creates risk when employees do not understand what happens to the information they submit.
The firm needs rules for AI use before confidential client or firm information is entered into these tools.
Editor's Insight
"The information you put into an AI tool deserves the same consideration as the information you give to any other outside service provider."
What Should a Law Firm Do Before Using AI for Client Work?
1. Establish an AI Use Policy
The firm should establish clear rules for attorneys and employees using AI.
The policy should address:
- Which AI tools are approved
- What information may and may not be entered
- Whether client information may be used
- Who may use the tools
- How AI-generated work must be reviewed
- What employees should do when they are unsure whether a particular use is permitted
The policy should be clear enough that employees can follow it in their everyday work.
2. Know What Happens to Information Entered Into the AI Tool
Different AI services, account types, and settings may handle information differently.
Before approving a tool, the firm should understand:
- Whether submitted information is retained
- How long it is retained
- Whether it may be used to train or improve the service
- Who may have access to it
- Whether retention or training can be disabled
- What privacy and security controls are available
ABA Formal Opinion 512 cautions lawyers to understand an AI tool's terms, privacy policy, and how information submitted to the tool is handled when evaluating confidentiality risks.
3. Protect Client Confidentiality
Attorneys should not assume that entering client information into an AI tool is acceptable.
The firm needs to determine whether the particular tool and intended use provide appropriate protection for the information involved.
ABA Formal Opinion 512 applies lawyers' existing confidentiality obligations to generative AI. Depending on the circumstances, informed client consent may be required before information relating to a representation is entered into a self-learning generative AI tool.
The New Jersey Supreme Court guidance similarly emphasizes that attorneys' existing ethical responsibilities are maintained when AI is being used.
4. Require Human Review of AI-Generated Work
AI-generated information can be incomplete or incorrect.
Attorneys remain responsible for the work they produce. Research, summaries, citations, documents, and other AI-generated material should be reviewed before being relied upon or provided to a client, court, or other party.
ABA Formal Opinion 512 states that lawyers using generative AI need a reasonable understanding of its capabilities and limitations and cannot leave professional judgment to the tool.
5. Train Employees on Appropriate AI Use
An AI policy is only useful if employees understand it.
Training should explain:
- Which tools employees may use
- What information may and may not be entered
- How AI-generated work must be reviewed
- What employees should do when they are unsure
This is especially important because employees may begin experimenting with readily available AI tools before the firm has formally adopted them.
Two Questions We Hear
Can attorneys put client information into AI?
Not automatically.
It depends on the information, the AI service being used, how that service handles the information, the firm's policy, and the attorney's professional obligations.
Confidential client information should not be entered into an AI tool without first determining whether the information will be protected in accordance with the firm's confidentiality obligations.
Is a paid AI account automatically safe for confidential information?
No.
Paying for an AI service does not by itself establish how information is retained, used, or protected.
The firm still needs to evaluate the particular service, account type, settings, terms, and privacy and security controls before deciding what information may be entered.
How Avenue M Helps
Avenue M Computers helps law firms create AI-use policies that establish how employees may use AI while protecting confidential information.
We review the AI platform's policies regarding the use and retention of information to determine whether they comply with the firm's confidentiality obligations.
Three Key Takeaways
- Understand how an AI provider uses, retains, and protects information before approving the tool.
- Establish rules for AI use before employees enter client or firm information into AI tools.
- Require human review of AI-generated work before relying on it.
Related Articles
- How Can a Law Firm Protect Client Confidentiality and Comply With ABA Cybersecurity Obligations?
- How Often Should Law Firms Conduct Cybersecurity Awareness Training?
- Why Is Multi-Factor Authentication (MFA) Essential for Law Firms?
- What Happens During a Cybersecurity Risk Assessment?
- How Should a Law Firm Create an IT Budget?
Technology should help your law firm practice law more securely, efficiently, and confidently, not become another distraction.

