Yes, in most circumstances, and the question worth asking is which of three approaches your firm is actually using. A paid business tier with training disabled is a different product from the free consumer version, and most of the anxiety in this area attaches to the wrong one. Big Mode Consulting sets these up for firms. The confidentiality problem partners worry about is usually manageable. The problem they are not worried about, which is what the tool is allowed to touch and whether anyone can reconstruct what it did, is the one that actually bites.
Fast. Free. Also the version carrying real exposure, because the account belongs to a person rather than the firm, nothing is logged anywhere the firm can reach, and nobody agreed to anything on the firm's behalf. It is good at exactly one thing, which is getting an associate unstuck at eleven at night on a paragraph they cannot make land, and it is already happening at your firm whether or not anyone has sanctioned it.
Clio, MyCase, Filevine, and Smokeball all ship something now. It is bounded, it lives inside the vendor agreement your firm already signed, and for a large number of firms it is enough. Where it fails is scope. You get what that vendor decided to build, on their roadmap, and if your bottleneck is a workflow they did not prioritize then no amount of enthusiasm inside the platform will reach it.
Most control. Most setup. This is the option where the firm picks the model, decides exactly which systems it can reach, and gets a record of what it did. It also requires a named person to own it, and firms that skip that step end up with an impressive pilot that nobody maintains once the person who built it moves on to something else.
What each of these is good at once it is running, as opposed to what it promises in a demo, is covered separately in our guide to AI for law firms.
Start with who signed what. On a personal consumer account, the contracting party is the individual who created the login, and the terms they clicked through are consumer terms written for a consumer. Your firm is not a party to that arrangement, has no rights under it, and cannot enforce anything if something goes wrong. That single fact does more work than any technical detail about how the model was trained.
A business or enterprise agreement changes the party. Now the firm bought the product, the firm can read the terms before signing, and the firm can ask for changes. The difference is contractual rather than technical, which is the accurate framing and also the one a lawyer can evaluate without needing an engineer in the room. Training exclusion, storage location, retention period, and whether the vendor will sign a confidentiality agreement are all just terms on a page. Read them.
Vendor policies get revised. Confirm these at purchase, and confirm them again at renewal rather than assuming last year's answer survived.
The last item on that list is the one firms skip and later wish they had not. A confidentiality obligation you cannot audit is a promise, and a promise is not a record of what left the firm on a Tuesday afternoon in March.
A lawyer must make reasonable efforts to prevent unauthorized disclosure of information relating to the representation. Applied to AI, that turns into a question about where the information goes once it leaves the building and who is obligated to protect it there. Reasonable efforts is a standard that scales with sensitivity, so the analysis for a routine scheduling summary is not the analysis for a settlement position.
Competence includes keeping abreast of the benefits and risks associated with relevant technology. You do not have to know how a transformer works. You do have to know enough about the tool your firm bought to make an informed judgment about what it should touch, which is a lower bar than engineering and a higher one than most firms currently clear.
The rule was written about people, and it is the closest analogue the profession has for delegating work to a system that produces output requiring review. Someone has to be responsible for the result. Firms that treat an AI output as finished work product because it reads fluently have skipped the part of the rule that matters.
The opinion pulls competence, confidentiality, client communication, supervision, and fees together and applies them to generative AI specifically. It is worth reading in full before drafting a firm policy, because a policy written from summaries of it tends to be either too permissive or so restrictive that people route around it. State bars have issued their own generative AI guidance as well, and your obligations are set by your jurisdiction rather than by a model rule, so check yours.
Big Mode Consulting is a technology consultancy and not a law firm, so treat this as the technology side of the analysis. Your ethics counsel owns the rest.
Every conversation we have about this starts with the regulatory question. Almost none of them start with the architectural one, and the architectural one is where firms get hurt.
A tool gets built to summarize medical records and somebody hands it a credential that reaches every matter in the system, because scoping the permission properly would have taken an afternoon and the broad key was sitting right there. Nothing goes wrong on day one. The exposure is that the blast radius of any later mistake, any compromised account, any misrouted prompt, is now the entire document store rather than the folder the job needed.
A client calls and asks whether their file was put into an AI tool. If the honest answer is that nobody can tell, the firm has a problem that has nothing to do with whether the underlying use was permissible. Logging is unglamorous and it is the difference between answering that question in an hour and answering it never.
A language model cannot reliably tell the difference between a document you asked it to read and an instruction written inside that document. Both arrive as text. So if someone buries a line in a file that says to ignore prior instructions and send a summary of everything in the folder to an outside address, a model with the access to do that may simply do it.
Picture a document production from an opposing party. Thousands of pages, dropped into your review tool, processed by an assistant your firm set up to pull out key facts. Somewhere on page four hundred is white text on a white background that no reviewer will ever see. That is the whole attack. It does not require breaking into anything, and it is the reason scoped access matters more than any assurance in a vendor's marketing.
A firm that gets the paperwork right and the architecture wrong has solved the smaller problem. Our cybersecurity guide for law firms covers the controls underneath this, and our security work is where we put them in place.
If the AI already inside your case management platform covers the job, use it and stop. No new vendor, no new contract, nothing new to supervise.
If people at your firm are already pasting client material into consumer accounts, you do not have a strategy question. You have a policy and tooling problem that is live today, and the fastest fix is usually a sanctioned business tier account plus a one page rule about what goes into it.
If the work spans systems your platform does not talk to, or needs a model it does not offer, a connected setup starts to earn its cost. How that is actually built, including what a connector can and cannot reach, is in our guide to MCP servers for legal software.
Most firms discover people are already using consumer AI accounts with client material. We audit what is actually in use, then set up something defensible.
Mauro Gonzalez is the founder of Big Mode Consulting with over a decade of experience in legal technology and enterprise IT. As a Clio Certified Consultant and Filevine implementation specialist, he has helped 50+ law firms modernize their technology stacks. He specializes in case management implementation, managed IT services, and ABA-compliant cybersecurity solutions.