AI & Innovation

    Can Your Firm Use ChatGPT With Client Files?

    Written by Mauro GonzalezClio Certified Consultant10+ Years in Legal TechnologyLast updated:

    Yes, in most circumstances, and the question worth asking is which of three approaches your firm is actually using. A paid business tier with training disabled is a different product from the free consumer version, and most of the anxiety in this area attaches to the wrong one. Big Mode Consulting sets these up for firms. The confidentiality problem partners worry about is usually manageable. The problem they are not worried about, which is what the tool is allowed to touch and whether anyone can reconstruct what it did, is the one that actually bites.

    Mauro Gonzalez15 min readAugust 2026

    The three ways firms actually do this

    1Someone pastes into the free consumer tool

    Fast. Free. Also the version carrying real exposure, because the account belongs to a person rather than the firm, nothing is logged anywhere the firm can reach, and nobody agreed to anything on the firm's behalf. It is good at exactly one thing, which is getting an associate unstuck at eleven at night on a paragraph they cannot make land, and it is already happening at your firm whether or not anyone has sanctioned it.

    2The AI built into your case management platform

    Clio, MyCase, Filevine, and Smokeball all ship something now. It is bounded, it lives inside the vendor agreement your firm already signed, and for a large number of firms it is enough. Where it fails is scope. You get what that vendor decided to build, on their roadmap, and if your bottleneck is a workflow they did not prioritize then no amount of enthusiasm inside the platform will reach it.

    3A model your firm chooses, connected to your systems on purpose

    Most control. Most setup. This is the option where the firm picks the model, decides exactly which systems it can reach, and gets a record of what it did. It also requires a named person to own it, and firms that skip that step end up with an impressive pilot that nobody maintains once the person who built it moves on to something else.

    What each of these is good at once it is running, as opposed to what it promises in a demo, is covered separately in our guide to AI for law firms.

    What actually happens to your data

    Start with who signed what. On a personal consumer account, the contracting party is the individual who created the login, and the terms they clicked through are consumer terms written for a consumer. Your firm is not a party to that arrangement, has no rights under it, and cannot enforce anything if something goes wrong. That single fact does more work than any technical detail about how the model was trained.

    A business or enterprise agreement changes the party. Now the firm bought the product, the firm can read the terms before signing, and the firm can ask for changes. The difference is contractual rather than technical, which is the accurate framing and also the one a lawyer can evaluate without needing an engineer in the room. Training exclusion, storage location, retention period, and whether the vendor will sign a confidentiality agreement are all just terms on a page. Read them.

    Verify these before anything touches client material

    • Does the agreement state that your inputs and outputs are excluded from model training?
    • Where is the data stored, and does that location create any obligation you have already promised a client you would meet?
    • What is the retention period, who can delete data inside it, and what happens at termination?
    • Will the vendor sign a confidentiality agreement, and if the answer is no, ask why.
    • Can an administrator produce a record of what a given user sent, and how far back does it go?

    Vendor policies get revised. Confirm these at purchase, and confirm them again at renewal rather than assuming last year's answer survived.

    The last item on that list is the one firms skip and later wish they had not. A confidentiality obligation you cannot audit is a promise, and a promise is not a record of what left the firm on a Tuesday afternoon in March.

    What the rules actually require

    Rule 1.6, confidentiality

    A lawyer must make reasonable efforts to prevent unauthorized disclosure of information relating to the representation. Applied to AI, that turns into a question about where the information goes once it leaves the building and who is obligated to protect it there. Reasonable efforts is a standard that scales with sensitivity, so the analysis for a routine scheduling summary is not the analysis for a settlement position.

    Rule 1.1 comment 8, technology competence

    Competence includes keeping abreast of the benefits and risks associated with relevant technology. You do not have to know how a transformer works. You do have to know enough about the tool your firm bought to make an informed judgment about what it should touch, which is a lower bar than engineering and a higher one than most firms currently clear.

    Rule 5.3, supervision of nonlawyer assistance

    The rule was written about people, and it is the closest analogue the profession has for delegating work to a system that produces output requiring review. Someone has to be responsible for the result. Firms that treat an AI output as finished work product because it reads fluently have skipped the part of the rule that matters.

    ABA Formal Opinion 512

    The opinion pulls competence, confidentiality, client communication, supervision, and fees together and applies them to generative AI specifically. It is worth reading in full before drafting a firm policy, because a policy written from summaries of it tends to be either too permissive or so restrictive that people route around it. State bars have issued their own generative AI guidance as well, and your obligations are set by your jurisdiction rather than by a model rule, so check yours.

    Big Mode Consulting is a technology consultancy and not a law firm, so treat this as the technology side of the analysis. Your ethics counsel owns the rest.

    The risk nobody asks about

    Every conversation we have about this starts with the regulatory question. Almost none of them start with the architectural one, and the architectural one is where firms get hurt.

    Access far wider than the task

    A tool gets built to summarize medical records and somebody hands it a credential that reaches every matter in the system, because scoping the permission properly would have taken an afternoon and the broad key was sitting right there. Nothing goes wrong on day one. The exposure is that the blast radius of any later mistake, any compromised account, any misrouted prompt, is now the entire document store rather than the folder the job needed.

    No record of what the model saw

    A client calls and asks whether their file was put into an AI tool. If the honest answer is that nobody can tell, the firm has a problem that has nothing to do with whether the underlying use was permissible. Logging is unglamorous and it is the difference between answering that question in an hour and answering it never.

    Prompt injection, explained without jargon

    A language model cannot reliably tell the difference between a document you asked it to read and an instruction written inside that document. Both arrive as text. So if someone buries a line in a file that says to ignore prior instructions and send a summary of everything in the folder to an outside address, a model with the access to do that may simply do it.

    Picture a document production from an opposing party. Thousands of pages, dropped into your review tool, processed by an assistant your firm set up to pull out key facts. Somewhere on page four hundred is white text on a white background that no reviewer will ever see. That is the whole attack. It does not require breaking into anything, and it is the reason scoped access matters more than any assurance in a vendor's marketing.

    A firm that gets the paperwork right and the architecture wrong has solved the smaller problem. Our cybersecurity guide for law firms covers the controls underneath this, and our security work is where we put them in place.

    How to decide which one you need

    If the AI already inside your case management platform covers the job, use it and stop. No new vendor, no new contract, nothing new to supervise.

    If people at your firm are already pasting client material into consumer accounts, you do not have a strategy question. You have a policy and tooling problem that is live today, and the fastest fix is usually a sanctioned business tier account plus a one page rule about what goes into it.

    If the work spans systems your platform does not talk to, or needs a model it does not offer, a connected setup starts to earn its cost. How that is actually built, including what a connector can and cannot reach, is in our guide to MCP servers for legal software.

    What to put in place before anyone starts

    • A written policy naming which tools are approved, and for what kind of work. One page beats twelve.
    • A business tier agreement bought by the firm, not personal accounts expensed later.
    • Access scoped to the task. If the job is drafting demand letters, the tool does not need read access to the whole document store, and the fact that a broad credential was faster to issue is not a reason.
    • Logging that captures what was sent and what came back, retained somewhere a person who was not involved can review it.
    • A named owner. Not a committee.
    • Client consent considerations, handled at the engagement letter level and revisited on matters where the sensitivity or an outside counsel guideline warrants it.
    • Training, because the failure mode is almost always a person making a reasonable decision inside a system nobody explained to them.

    Not sure what your firm is already doing?

    Most firms discover people are already using consumer AI accounts with client material. We audit what is actually in use, then set up something defensible.

    Frequently Asked Questions

    Yes, in most circumstances. Nothing in the ABA Model Rules bars a lawyer from using a generative AI tool. What the rules require is that the lawyer understand the tool well enough to supervise it, protect client information under Rule 1.6, and verify the output. The account type matters more than the brand name. A personal consumer login used with client material is a different situation from a business tier account governed by a contract the firm signed.

    Confidentiality here is a contract question before it is a technology question. On a personal consumer account there is usually no obligation running to your firm at all, because your firm is not the contracting party. On a business or enterprise agreement, the terms are what create the obligation, and a firm should read them for four things: whether inputs are excluded from model training, where data is stored, how long it is retained, and whether the vendor will sign a confidentiality agreement. Vendor terms change, so verify them at the time you buy and again at renewal.

    This area is still developing and a firm should take its own advice on it rather than relying on a general article. The broad principle is that privilege can be affected when protected material is disclosed to a third party without a reasonable expectation of confidentiality. That is why the account type and the contract behind it matter so much. A tool used under an agreement that imposes confidentiality obligations sits in a different posture from a personal account with no such terms. Big Mode Consulting is not a law firm and does not give legal advice on privilege.

    The contracting party, the terms, and the administrative controls. On a free consumer account an individual agreed to consumer terms and the firm has no visibility into what was sent. A business tier account is bought by the firm, governed by commercial terms the firm can review and negotiate, and typically comes with administrative controls such as user management, retention settings, and audit logging. Treat those controls as things to confirm in writing rather than assume.

    It is usually simpler, which is not the same thing. The AI inside Clio, MyCase, Filevine, or Smokeball already sits inside a vendor agreement your firm signed, next to data that vendor already holds, so there is no new contracting party and no new place for data to go. The tradeoff is scope. It can only do what the platform built. If that covers the job, the platform option is the lower effort path with fewer moving parts to get wrong.

    Sometimes, and the answer turns on the matter rather than on a blanket policy. Informed consent becomes a live question when the use involves disclosing confidential information to a tool in a way the client would want to know about, when the engagement letter or an outside counsel guideline addresses technology use, or when a client has asked. Many firms address it in the engagement letter and revisit it for sensitive matters. Check your own jurisdiction, because state bars have issued their own guidance on generative AI.

    It applies existing duties to generative AI rather than creating new ones. The opinion addresses competence, confidentiality, communication with clients, supervision of lawyers and nonlawyer assistance, and fees. The practical takeaways for a firm are that a lawyer must understand the benefits and risks of the tool being used, must evaluate what happens to client information put into it, must consider whether client consent is needed, must supervise the output rather than rely on it, and must not bill for time the tool saved as though a person spent it. Read the opinion itself before writing a firm policy on top of it.

    About the Author

    Mauro Gonzalez is the founder of Big Mode Consulting with over a decade of experience in legal technology and enterprise IT. As a Clio Certified Consultant and Filevine implementation specialist, he has helped 50+ law firms modernize their technology stacks. He specializes in case management implementation, managed IT services, and ABA-compliant cybersecurity solutions.