Duty of Confidentiality (AI)

Duty of Confidentiality (AI)

Duty of Confidentiality (AI)

Model Rule 1.6 prohibits revealing information relating to a representation without informed consent. Entering client information into a third-party AI system is a disclosure to that vendor, so the analysis turns on the vendor's terms, security posture, and whether inputs are used to train models.

ABA Formal Opinion 512 distinguishes self-learning tools that retain and learn from inputs from tools contractually barred from doing so, treating the former as raising materially greater risk.

Alternative Names:

AI Confidentiality Duty

Why it Matters?

This is where most firm AI policy actually operates. Consumer AI tools with training-on-input defaults are unsuitable for client confidential information, while enterprise deployments with no-training commitments and zero-retention terms present a manageable analysis. The practical failure mode is shadow usage, where lawyers paste client material into unapproved consumer tools that the firm never evaluated.

Frequently Confused with

Related terms

Frequently asked questions

Can client information be entered into a public AI tool?

Can client information be entered into a public AI tool?

Generally not without evaluating the terms. Tools that retain inputs or use them for training create disclosure risk that most confidentiality analyses will not tolerate for identifiable client information.

Does anonymizing the information solve the problem?

Does anonymizing the information solve the problem?

It helps but is not a complete answer. Matter details can be identifying even without names, and Rule 1.6 protects information relating to the representation broadly, not just identifiers.