Artificial intelligence tools are becoming central to legal operations, but they introduce a new risk: confidentiality. When you feed a contract to an AI tool to analyze, you are sending sensitive information to a third-party vendor. That vendor may store your data, train on your data, or expose your data in a breach.

Understanding what data risk comes with AI, how to vet vendors, and how to design safe workflows is not optional. It is a professional responsibility issue that affects both your firm and your clients.

Key takeaways

  • Using public AI tools (ChatGPT, Gemini without a paid enterprise agreement) on confidential work is prohibited. These tools train on user inputs, creating confidentiality breaches.
  • Vendor selection requires evaluating data handling policy, encryption, breach history, and contractual commitments. A cheap tool with weak security is not a bargain.
  • Workflow design should gate which data goes to AI. Highly confidential work (M&A, litigation, trade secrets) should not go to third-party tools, even if they claim strong security.
  • Contractual protections (Data Processing Agreements, no-training clauses, audit rights, breach notification) are non-negotiable. Do not sign a vendor contract without them.
  • Professional responsibility rules (ABA 2024) make you accountable for tool selection and use, even if the vendor later fails to protect data.

What data risk comes with using AI tools

The core risk is that AI vendors have access to your data in multiple ways:

1. Storage and retention. When you upload a document to an AI tool, the vendor stores it on their servers. The question is how long and under what conditions.

  • Vendor policy 1: “We store documents for 30 days then delete.” This is low risk if true.
  • Vendor policy 2: “We store documents indefinitely for product improvement.” This is high risk.
  • Vendor policy 3: “We store documents on customer request only.” You need clarity on what the default is.

Ask vendors specifically: “If I upload a document today, when is it deleted? Who can access it while it is stored? Can I request deletion immediately?”

2. Training data use. Some AI vendors use customer data to improve their models. This means your contracts become part of the training set for future versions of their tool, where other customers might see patterns similar to your work.

Example: You upload an NDA template to an AI tool. The vendor uses it to improve their NDA extraction model. Later, a competitor of yours uses the same tool and the model is better at extracting NDA clauses (in part because it learned from your template). Inadvertently, you have shared competitively sensitive information.

3. Third-party sharing. Some vendors sell anonymized data to third parties (academic researchers, other AI companies). While “anonymized,” it may still be de-anonymizable if someone has access to the originals.

4. Breach and subpoena exposure. Even if a vendor has strong security, breaches happen. If your documents are breached, they are in the wild. If they are subpoenaed, they are discoverable. If a vendor stores your data, that data is subject to legal process in the vendor’s jurisdiction, even if you operate elsewhere.

5. Vendor lock-in and leverage loss. If you depend on a vendor’s AI tool and the vendor is acquired, goes bankrupt, or changes terms, you may lose access to your analysis and have limited recourse.

These are not theoretical risks. They are documented in vendor terms of service, breach reports, and lawyer ethics opinions.

Vendor selection: The checklist

Before you use any AI tool on client or confidential work, vet the vendor against these core criteria.

Data handling policy: Demand a written commitment that your documents are not used to train models, not sold to third parties, and deleted within 30-60 days. Refuse vendors who are vague on this or resist putting it in a Data Processing Agreement (DPA).

Security certifications: Require SOC 2 Type II and ISO 27001 certification, encryption in transit and at rest (AES-256+), and breach notification within 72 hours.

Data residency and jurisdiction: Know where servers are physically located. If you have client data subject to GDPR, you need EU servers. If you operate in Canada, ask about Canadian data residency options.

Breach history: Check the vendor’s public statements and the Identity Theft Resource Center database. Transparency about past breaches is better than silence.

Audit rights and transparency: Insist on the right to audit data handling, inspect access logs, and approve any sub-processors the vendor uses.

Financial stability and size: Evaluate whether the vendor is profitable and established (5+ years in business). Early-stage vendors may have the latest features but lack security maturity and financial stability.

Workflow design: Gate what data goes to AI

Not all work should go to AI tools, even if the vendor is secure. Some data is so sensitive that third-party processing is not acceptable.

Category 1: Safe to send to AI (with vendor DPA)

  • Routine contract extraction and risk flagging (vendor agreements, NDAs, service agreements).
  • Legal research and case law analysis (using tools like Westlaw AI, Lexis+ AI).
  • Intake form completion and request triage (using tools with strong data protections).
  • Document automation and template generation (standard contracts, not confidential client work).

Condition: The vendor has a strong DPA, no-training clause, and SOC 2 certification.

Category 2: Conditional – requires workflow controls

  • Customer contracts and large commercial agreements.
  • Regulatory compliance analysis (if not confidential).
  • Employment or HR legal analysis.

Conditions: Use legal-specific AI (not general chatbots), redact sensitive information before sending, avoid confidential positions or strategy, and require a DPA with audit rights.

Category 3: Do not send to third-party AI tools

  • Trade secrets or highly confidential business information.
  • M&A due diligence (confidentiality agreements with counterparties often prohibit use of third-party tools).
  • Litigation hold documents or litigation strategy.
  • Client privileged communications or attorney-client privileged work.
  • Pending patent applications or other sensitive IP.

For this work: Use internal tools only (on-premises AI, private instances, or vendor services where data stays on your own servers).

Contractual protections: Non-negotiable DPA terms

A Data Processing Agreement (DPA) is mandatory. Your DPA must cover:

No training on your data: Your documents must not be used to train or improve the vendor’s models and must not be sold or shared with third parties.

Encryption and security: Data must be encrypted in transit and at rest (AES-256+), and the vendor must maintain SOC 2 Type II certification.

Data retention and deletion: Your data must be deleted within 30-60 days of your request or upon contract termination. Vendors should provide written deletion certification.

Audit rights: You have the right to audit the vendor’s data handling and security controls with reasonable notice.

Breach notification: The vendor must notify you within 24-72 hours of any suspected or confirmed breach.

Data location: Specify where servers are located and that data will not be transferred without your consent. If the vendor is acquired, you have the right to terminate without penalty.

Do not sign a vendor contract without these terms in writing.

Compliance and professional responsibility

The ABA’s 2024 guidance on AI in legal practice (and equivalent bar associations in the UK, Canada, Australia) makes clear that using AI tools for client work carries professional responsibility obligations: competence (understand what the tool does), confidentiality (only use tools that protect client data), communication (disclose AI use to clients), and due diligence (vet vendors before deployment).

Failure to follow these rules can result in bar discipline, malpractice liability, and client relationship damage.

Red flags to watch for

If a vendor refuses to put no-training commitments in a DPA, avoid them. If their privacy policy is vague (“we may use data to improve our services”), assume they train on your data. Offshore vendors with weak data protection laws and no local data center are high-risk for GDPR or PIPEDA compliance. Vendors offering “free tier” or “freemium” models for confidential work almost always train on data; only use paid enterprise plans. If a vendor’s contract claims ownership of outputs or the right to use your work for examples, reject it entirely.

FAQ

Can we use ChatGPT or Copilot on confidential work if we have a paid enterprise account?

Enterprise accounts offer some protections (data is not used to train the public model), but check the specific terms. Microsoft’s Copilot Pro has stronger confidentiality guarantees than the free tier, but even enterprise versions may have data retention and logging that creates risk. For truly sensitive work, use a legal-specific tool with a full DPA. Do not rely on consumer or general-purpose tools.

What if a vendor refuses to sign a DPA?

Do not use them on confidential work. If a vendor will not contractually commit to protecting your data, they do not deserve access to it. There are many vendors who will sign a DPA; use them instead.

How do we handle work that clients explicitly prohibit third-party processing on?

Honor the prohibition. If a client’s engagement letter or NDA says “all work must be done in-house and cannot be processed by third parties,” do not send that work to AI tools, even if the vendor claims strong security. The client has the right to control how their data is handled.

Should we tell clients we are using AI on their work?

Yes, if the AI tool is processing their data or analyzing their work. Include a disclosure in engagement letters: “We may use AI-assisted tools to accelerate analysis and research. All AI analysis is reviewed by a qualified attorney. Our AI vendors are contractually bound to protect confidentiality and do not train on client data.” Get consent before proceeding.

What if we discover that an AI vendor violated the DPA (e.g., trained on our data or was breached)?

Notify the vendor in writing, demand corrective action, and preserve evidence. Consider whether clients need to be notified (depending on your contract and jurisdiction). If the vendor does not respond satisfactorily within 30 days, terminate the relationship and move to a different vendor. Consider whether a malpractice claim against the vendor is appropriate (though vendor liability for data breach is often capped in contracts).

Can we use offshore AI vendors safely?

Yes, if they are properly vetted, have a strong DPA, and are compliant with data residency and privacy laws in your jurisdiction. Offshore location alone is not disqualifying. What matters is: Do they have SOC 2 certification? Do they promise no training on data? Do they comply with GDPR, PIPEDA, and other privacy laws? If yes, they can be safe. If no, they are high-risk.

Building your AI vendor governance

Do not deploy AI tools ad hoc. Establish a vendor evaluation and approval process:

  1. Create a vendor questionnaire: Ask about data handling, security, certifications, breach history.
  2. Require a DPA: No exceptions. Make it a standard requirement.
  3. Run a pilot: Test on non-sensitive work first and measure effectiveness.
  4. Document approval: Keep records of which tools are approved, by whom, and for what use cases.
  5. Audit periodically: Check that approved vendors are still compliant with your standards.

We help legal teams establish AI vendor governance frameworks and build vendor evaluation discipline that protects confidentiality while enabling AI-driven productivity.

If you are evaluating an AI tool and want to know if it is safe for your work, or if you already use AI tools and want to audit them for confidentiality risk, we can help.

Reach out to discuss your AI vendor selection and confidentiality risk management.