Confidentiality, Privilege, and Data Governance in AI-Assisted Legal Work
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 5 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Identify the three categories of information that must not be entered into commercial AI tools without appropriate data protection terms
- Distinguish between consumer AI tools and enterprise AI tools by their contractual data protection characteristics
- Apply a data classification habit before entering any content into an AI tool, assigning it to category A, B, or C
- Describe the key elements a firm-level AI governance policy must cover under SRA supervision requirements
Confidentiality is not a compliance consideration for legal professionals — it is a foundational professional duty. A solicitor who discloses client confidential information without authorization commits a professional misconduct breach, regardless of whether that disclosure was deliberate or the result of poor data governance. When AI tools enter legal practice, they introduce a new and underappreciated route for confidential information to leave the firm: through the input provided to a third-party AI tool that does not provide contractual data protection.
What Cannot Be Entered Into Commercial AI Tools
The category of information that must not be entered into a commercial AI tool without appropriate data protection terms is broader than most legal professionals initially assume.
Client confidential information covers everything a client communicates to their lawyer in the course of the professional relationship — facts about their legal situation, commercial information, financial data, personal information, strategic plans, and anything else communicated in the context of seeking legal advice. This is protected by the professional duty of confidentiality and cannot be disclosed to third parties, including AI vendors, without client consent or lawful authority.
Legally privileged communications are protected by legal professional privilege, which is a substantive right belonging to the client. Privileged communications — legal advice given in the context of an existing or anticipated legal matter, and litigation communications — cannot be disclosed without the client waiving privilege. Entering privileged content into an AI tool whose terms permit the vendor to process, store, or use inputs is a potential privilege waiver risk that must be assessed before any privileged material is used as AI input.
In the United States, this same protection is named attorney-client privilege — a distinct doctrine from legal professional privilege in its detailed case law, but functionally the same principle: confidential communications between a lawyer and client made for the purpose of seeking or giving legal advice are protected from compelled disclosure. US practitioners face the identical exposure described above under a different name — pasting privileged client communications into an AI tool whose terms permit vendor processing or retention risks being treated as disclosure to a third party outside the privileged relationship, which can support an argument that privilege has been waived.
Personal data under UK GDPR and the Data Protection Act 2018 includes any information relating to an identified or identifiable individual. Legal files routinely contain personal data belonging to clients, counterparties, witnesses, and other individuals. Processing this data using an AI tool constitutes data processing for the purposes of UK GDPR and requires a lawful basis, appropriate processor agreements, and compliance with data subject rights.
Entering client-sensitive information into a consumer-facing AI tool such as the free tier of a general-purpose AI chatbot creates a specific and serious risk: most consumer AI services reserve the right to use inputs to train or improve their models, and do not provide the contractual data protection guarantees that professional data processing requires. The SRA has reminded solicitors that using such tools with client information may breach confidentiality obligations. Check the vendor's terms before entering any client-related content — not after.
The Difference Between Consumer and Enterprise AI Tools
The critical distinction in AI tool selection for legal practice is between consumer AI tools and enterprise AI tools with contractual data protections.
Consumer AI tools — free tiers of general-purpose AI assistants, publicly accessible chatbots — typically include terms that permit the vendor to use inputs for model training or improvement. They do not provide data processing agreements, do not offer data residency guarantees, and do not accept contractual liability for data handling. They are appropriate for generating general information, research on non-client-specific questions, and drafting tasks that involve no client information whatsoever.
Enterprise AI tools — tools procured through enterprise agreements that include a data processing addendum, confirm that inputs are not used for model training, provide data residency commitments, and offer contractual accountability for data handling — are appropriate for use with client information, subject to assessment of the specific terms and your firm's data governance policy.
The boundary is the contractual data protection commitment. Before entering any client-related information into an AI tool, the question is not "is this tool good?" but "does this tool's contractual framework protect this information to the standard my professional and regulatory obligations require?"
A solicitor in a small firm wants to use an AI writing tool to help draft client correspondence. The tool is marketed as 'enterprise-grade' and has a paid subscription tier. The solicitor assumes that paying for the tool means client data can be used with it. What should they check before entering any client information?
Select one answer.
Internal AI Governance in Legal Practice
Firms and in-house legal teams need documented AI governance policies that establish: which AI tools are approved for use with client data, which tools are approved for non-client-data tasks only, what categories of information are categorically excluded from AI input regardless of tool, who holds accountability for each approved tool, and what the escalation path is when a practitioner is unsure whether a particular use is appropriate.
This is not an optional governance exercise. The SRA's firm supervision requirements include responsibility for systems and controls over how work is carried out. A firm that has allowed widespread AI tool use without a governance policy and a client confidentiality incident occurs is in a significantly worse regulatory position than a firm that had a policy and followed it.
SRA, BSB, and Law Society Guidance on AI
The Solicitors Regulation Authority has published guidance confirming that existing professional obligations — competence, confidentiality, supervision — apply fully to AI-assisted work. Solicitors remain personally responsible for outputs produced with AI assistance, and firms are responsible for implementing appropriate supervision and governance. The SRA has specifically flagged the risk of entering client information into non-compliant AI tools.
The Bar Standards Board has confirmed that barristers' duties of competence, confidentiality, and candour to the court apply when AI tools are used in practice. The cab-rank rule and the duties of an independent practitioner remain unchanged by the availability of AI assistance.
The Law Society has published a practice note on AI that addresses supervision of AI outputs, data protection, and client disclosure. It recommends that firms consider whether to inform clients when AI tools have been used in matter work and develop a clear policy on when disclosure is appropriate.
Practitioners in the United States face the same substance under a different rulebook. ABA Model Rule 1.6 (confidentiality of information) prohibits a lawyer from revealing information relating to the representation of a client without informed consent, and requires the lawyer to make reasonable efforts to prevent unauthorized disclosure of, or access to, client information — a standard that applies directly to what a lawyer enters into a third-party AI tool. A number of individual state bar associations have begun issuing their own guidance interpreting how confidentiality, competence, and supervision rules apply to generative AI use in practice; the specific content and rigor of that guidance varies by state, and the direction of travel is toward more states publishing guidance, not fewer.
Build a simple data classification habit for AI use: before entering anything into an AI tool, classify it as (A) public or general information with no client connection — appropriate for any AI tool; (B) internal information with no client data — appropriate for enterprise-contracted tools; (C) client-related or privileged information — appropriate only for tools with a signed data processing addendum and confirmed no-training commitment, and only after checking your firm's approved tool list. If you are unsure which category something falls into, default to the most restrictive treatment until you have confirmed.
Consumer AI Tool Exposure — Small Litigation Practice
Context
A sole practitioner handling a contentious commercial dispute needed to draft a witness statement quickly. To save time, she pasted a client's detailed factual narrative — names, financial figures, and background to the dispute — into a free-tier general-purpose AI chatbot to help structure the draft. She was focused on the output quality and had not read the tool's terms of service.
Action
A colleague at another firm mentioned that the tool's consumer terms permitted use of inputs to improve its model. The solicitor reviewed the terms and confirmed this was correct. She contacted her professional indemnity insurer to disclose the incident and sought guidance from her local Law Society representative on the appropriate response. She also reviewed her other recent AI tool uses against the same terms. She then introduced a personal classification habit for all future AI use — sorting every piece of content she was considering entering into a tool into one of three categories before touching the keyboard.
Outcome
The insurer noted the disclosure and confirmed no further action was required at that stage, as no harm had materialised. The solicitor revised her practice to use only an enterprise-contracted AI tool with a confirmed data processing addendum for any content with a client connection. She later reflected that the tool had produced a competent draft — but that the confidentiality exposure had come from a moment of focusing on the output rather than on the data governance of the input. The episode changed her default habit: data classification before tool access, not after.
A solicitor needs to draft a clause in a commercial agreement and pastes the relevant section of the client's existing contract into a general-purpose AI tool to ask it to suggest an improved formulation. The AI tool's terms permit use of inputs for model improvement. What is the professional problem with this approach?
Select one answer.
Exercise
Your Task
Review the AI tools you currently use in your practice — including any general-purpose AI assistants. For each tool, find and read the terms of service relating to data use. Determine whether the vendor's terms permit use of inputs for model training or improvement, whether a data processing addendum is available, and whether there is a confirmed no-training commitment. Classify each tool as appropriate for category A use only (general information, no client data), category B (internal information without client data), or category C (client-related content with a signed DPA). If any tool you regularly use with client-related content falls below category C, document the gap and identify the remediation step.
Your reflection
Did you complete this exercise? What did you find? (Saved locally in your browser)
- Client confidential information, legally privileged communications, and personal data under UK GDPR cannot be entered into AI tools without contractual data protection guarantees — the professional duty of confidentiality applies to AI vendor disclosure as it does to any other third-party disclosure.
- The critical distinction is between consumer AI tools (no data protection contracts, inputs may be used for training) and enterprise AI tools (data processing addendum, confirmed no-training commitment, data residency guarantees) — only the latter are appropriate for client-related content.
- Entering privileged material into an AI tool whose terms permit processing of inputs creates a potential privilege waiver risk that must be assessed before any privileged content is used as AI input.
- Firms need documented AI governance policies covering approved tools, approved use categories, excluded information types, accountable owners, and an escalation path — the absence of a policy when an incident occurs creates a significantly worse regulatory position.
- SRA, BSB, and Law Society guidance confirms that all existing professional obligations — competence, confidentiality, supervision, candour — apply fully to AI-assisted work, and practitioners remain personally responsible for AI-assisted outputs.