ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Shadow AI at Your Law Firm: How to Find It and Bring It In

Staff are likely using AI tools you have not approved. Here is how to discover shadow AI at your firm and replace risky habits with safe, supported options.

3 min readBy Counsel Cyber Team

Ask a room of law firm employees whether they have used an AI chatbot for work and watch how few hands go up. Then ask whether they have used one to reword an email, summarize a document, or translate something, and more hands appear. This quiet, unsanctioned use is what security people call shadow AI, and it is rarely malicious. It usually starts with someone trying to meet a deadline.

The risk is that client information gets pasted into a consumer tool whose terms nobody at the firm has read. Under ABA Model Rule 1.6(c), lawyers are expected to make reasonable efforts to prevent unauthorized disclosure of client information, and ABA Formal Opinion 512 discusses confidentiality in generative AI use at length. You cannot protect what you cannot see.

Why shadow AI happens

  • The tools are free, fast, and easy to reach from any browser
  • Firms have not offered approved alternatives
  • Staff do not know a policy exists, or there is none
  • Deadline pressure rewards shortcuts
  • Many everyday applications now include AI features turned on by default

Punishing the behavior without addressing the cause usually just drives it further underground.

Step 1: Find out what is in use

Ask, without blame

Run a short anonymous survey. Questions to include:

  • Which AI tools, plug-ins, or browser extensions do you use for work?
  • What do you use them for?
  • Have you ever entered client information into one?
  • What would make your work easier?

State clearly that the aim is to learn, not to discipline. You will get more honest answers.

Check the technical signals

Your IT provider can often review:

  • Web traffic or DNS logs for visits to popular AI services
  • Browser extensions installed on firm devices
  • Applications and plug-ins connected to Microsoft 365 accounts, since many AI tools request access to mail and documents
  • AI features recently enabled inside software you already license

Cloud access security tools and endpoint management can provide more detail where the firm has them.

Step 2: Sort what you find

Place each tool in one of three groups.

  1. Approve: the vendor's terms, security, and data handling meet your standards
  2. Approve with limits: acceptable only for non-confidential material, public information, or particular teams
  3. Block: unacceptable data handling or no clear terms

Document the reason for each decision. That documentation becomes part of your AI use policy and your answers to client questionnaires.

Step 3: Offer something better

People use shadow tools because they work. If the firm only says no, the need remains. Provide at least one approved option for the common tasks: drafting, summarizing, research assistance, and meeting notes. Make it easy to access, ideally through single sign-on, and explain what it is good for.

Step 4: Set clear, short rules

A one-page guideline works better than a twenty-page policy. Consider these elements:

  • Only approved tools may be used with client information.
  • Never paste privileged communications, personal identifiers, or case facts into an unapproved tool.
  • A lawyer reviews and verifies all output before it is used.
  • Report mistakes right away. Early reporting is rewarded, not punished.

Step 5: Control what you can technically

  • Restrict which third-party apps can connect to Microsoft 365 and require administrator approval for new ones
  • Block categories of unapproved AI sites on firm devices where appropriate
  • Apply data loss prevention rules to flag sensitive content leaving the firm
  • Review AI-related settings in the software you already own, since defaults may not match your policy

Technical blocks will not catch personal phones, so training matters too.

Step 6: Train and repeat

Hold a short session with real examples of what is safe and unsafe. Repeat it at onboarding and at least annually. Revisit the approved list every few months, because new tools and new features appear constantly.

What to do if confidential data was already pasted

Do not panic. Identify what was shared and with which tool. Check whether the vendor allows deletion on request and whether data is used for training. Involve the supervising attorney, and consider with counsel whether any client communication is warranted. Confirm your state bar's guidance.

A final point

Shadow AI is a symptom of unmet demand. Firms that channel that demand into approved, well-configured tools tend to end up safer than firms that rely on prohibition.

Counsel Cyber can help you run the discovery, configure the technical controls, and draft the guidelines. If you would like to know what is being used at your firm today, we can help you find out.