“Is AI confidential?” is the wrong question, and it produces confident answers in both directions that are equally useless. The right question is narrower: for the specific plan your firm pays for, what do the terms say about training, retention, and access?
Two lawyers can use the same branded product and be in completely different positions because one is on a consumer subscription and the other is on a business agreement. Here is the checklist to run before client material goes anywhere.
The nine questions
Does the vendor train models on our content? For legal work the answer needs to be no, and it needs to be in the terms rather than in a marketing page.
How long is data retained, and can we set it to zero? Zero-retention options exist on enterprise tiers at the major providers. Understand that zero retention often disables features like conversation history, which is a real tradeoff to make deliberately.
Who at the vendor can access our content, and under what circumstances? Most providers retain limited access for abuse investigation and legal process. That is normal. You want to know the specifics rather than assume either extreme.
Will they sign a business associate agreement? If you touch medical records, this is not optional. It is also not automatic, and usually has to be asked for.
Where is data processed and stored? Relevant for some client industries and for anything with cross-border sensitivity.
Do they have a SOC 2 Type II report, and will they show it? A vendor that cannot produce one is not necessarily disqualified, but it tells you how mature their security program is.
What happens to our data if we cancel? Deletion timeline, in writing.
Do they notify us of a breach, and how fast? Your own notification obligations may run from when you knew.
Are subprocessors listed? Your vendor’s vendors also touch your data.
The consumer tier trap
This is the single most common mistake, and it is invisible from inside the product because the interface looks identical.
A lawyer signs up for a personal subscription with a credit card, uses it for months, and assumes the terms match what they read about the enterprise offering. Consumer and business tiers of the same product frequently differ on exactly the two dimensions that matter, training and retention.
Check what your firm actually pays for. If people expensed individual subscriptions, you have a mix of tiers across the firm and no consistent posture, which is worse than a bad policy consistently applied because you cannot even describe your exposure.
Where the real leak usually is
Not the vendor. The shadow account.
Someone at your firm is using a personal account on a personal device for work, because it is faster than asking. That material is outside every agreement you negotiated and outside any log you could produce if asked.
The fix is not a stern policy memo. It is providing an approved tool that is good enough and easy enough that nobody has a reason to route around it. Firms that ban AI outright get the most shadow usage, and get it invisibly.
What to keep out regardless
Some material should not go to an outside service even under good terms.
Anything under a narrow protective order until you have read the order and concluded it permits vendor disclosure.
Material subject to specific client instructions or an outside counsel guideline restricting third-party technology. Corporate clients increasingly address AI expressly, and those guidelines control.
Sealed filings and grand jury material.
Another client’s confidential information sitting in a document you happen to be analyzing, which is easy to miss when you upload an entire file.
Writing it down
A short policy beats a long one nobody reads. One page covering the approved tools and tiers, what may and may not be entered, the requirement that a human reviews output before it goes to a client or a court, and who to ask when unsure.
Then look at your engagement letter. Many already contain technology and vendor language broad enough to cover this. If yours does not, that is a conversation with whoever handles your risk management, and it is easier to update the template once than to have the discussion per matter.
The competence and supervision obligations behind all of this are covered in AI ethics for lawyers, and the analysis is worth reading before you write your own policy.
Do this today
Find out which AI subscriptions your firm actually pays for and at which tier, including anything expensed by individuals.
Most firm owners are surprised by that list. You cannot evaluate exposure you have not inventoried, and the inventory takes one email to your bookkeeper.