The most common AI mistake in a law office is not a hallucinated citation. It is a well-meaning attorney pasting a complete client email, a draft settlement letter, or a deposition summary into a chatbot to get help with tone or structure. The attorney was trying to work faster. The result may be that confidential information has left the firm's control.
ABA Formal Opinion 512, issued in July 2024, addresses generative AI and the duty of confidentiality. In general terms, the ABA noted that lawyers should consider the risk that information entered into an AI tool could be disclosed or used in ways the client has not authorized, and that the answer depends heavily on the specific tool and its terms. This post turns that principle into everyday habits. It is general information, not legal advice, and you should confirm your state's guidance with your bar.
Start with the tool, not the prompt
Safe prompting begins before you type. The question is not "what am I pasting?" but "what is this tool's relationship to my data?"
- Consumer accounts often allow the provider to retain conversations and may use them to improve models unless you change settings.
- Business or enterprise accounts usually offer stronger terms, administrative controls and options to disable training on your inputs.
- Tools built into software you already license, such as a Microsoft 365 add-on, inherit the protections of that agreement, but only after you have read what the agreement says.
If your firm has not reviewed and approved a tool, treat it as public.
What to keep out of unapproved tools
- Client names, addresses, case numbers and any unique identifying detail.
- Privileged communications and attorney work product.
- Medical, financial, immigration or other sensitive records.
- Opposing party and witness information.
- Firm credentials, internal financial data and strategy memos.
- Anything under a protective order or a confidentiality agreement.
The generalize-first method
When an approved tool is not available and you simply want help with structure or phrasing, strip the facts before you start.
- Replace names with roles: "Client A," "the landlord," "the vendor."
- Remove dates, dollar amounts and locations unless essential.
- Describe the legal issue in the abstract rather than the factual story.
- Ask for a template or outline, then add the real facts yourself in your own document.
This does not make every use safe, but it dramatically reduces what could be exposed.
Habits for approved tools
Even in a vetted tool, good habits matter.
- Use your individual login, never a shared one.
- Share the minimum needed for the task rather than a whole file.
- Treat every output as a draft. Check each citation and factual claim against a primary source.
- Do not rely on the tool's memory or chat history as a record of work. Save work product in your document management system.
- Log out of public or shared computers.
Watch for AI hidden in other software
Many products now add AI features by default: email summaries, meeting transcription, document assistants, browser extensions. Administrators should periodically check what has been switched on and whether the new feature sends data to a third party. A browser extension that "helps write emails" can read every page you open.
If someone pastes something they should not have
Mistakes will happen. What matters is whether the firm hears about them quickly.
- Stop and do not continue the conversation.
- Tell the firm administrator or designated lead immediately.
- Record the tool, the account, the date and what was entered.
- Delete the conversation if the tool allows, and check the provider's process for removing retained data.
- Have a partner or ethics counsel decide whether client notice is required.
Make it explicitly safe to report. If staff fear discipline, they will stay quiet and the firm loses its chance to respond.
Train with examples
A thirty-minute session using realistic examples works better than a long policy document. Show a real-looking email, ask the group what can safely be pasted, and walk through the generalized version. People retain concrete examples.
Put it in writing
One page is enough: approved tools, prohibited data categories, the verification requirement, and who to contact with questions or mistakes. Review it every few months, because both the tools and the guidance are changing.
How Counsel Cyber can help
Counsel Cyber helps law firms evaluate AI tools, configure approved accounts securely and train attorneys and staff on safe use. If you would like help drafting a one-page prompting guide for your firm, we would be glad to assist.