Can You Use AI for Legal Research Without Risking Client Confidentiality?
What ABA Formal Opinion 512 means for prompts, client information, provider terms, local AI, verification, and fees.
AI becomes more useful when it knows the details. Those details are also where a lawyer’s confidentiality problem begins.
A generic request for research terms may reveal nothing about a client. Uploading a complaint, interview transcript, or proposed deal gives the system a great deal of information relating to a representation. Before doing that, the lawyer needs to know who receives it and what happens next.
The ABA addressed the issue in Formal Opinion 512. The opinion covers competence, confidentiality, communication, candor, supervision, and fees. It does not ban generative AI. It asks lawyers to understand and supervise the particular use.
Start with the information, not the prompt box
Rule 1.6 protects information relating to a representation, a broader category than privileged communications. Removing a client’s name may not solve the problem. A distinctive combination of dates, locations, medical facts, transaction terms, or allegations can identify the matter.
Ask what the system genuinely needs. Research based on public authorities may not need client facts at all. A document-comparison task may work with a limited, redacted set. Sometimes the full record is necessary, but that should be a decision rather than the default.
Find out what the provider does
Do not rely on the product category. Consumer, business, enterprise, and API accounts from the same company may have different retention, training, and access rules. Settings and terms can change.
Before using client information, confirm:
- whether prompts, files, and outputs are retained;
- whether customer material is used to train or improve models;
- whether provider personnel or subprocessors may access it;
- where the information is processed and stored;
- what confidentiality and security obligations are in the contract;
- whether retention can be reduced or disabled; and
- how deletion works when the matter or account ends.
Save the relevant terms and configuration decision. “The website said it was secure” is difficult to reconstruct months later.
Opinion 512 explains that informed consent may be required before information relating to a representation is entered into some self-learning tools. Generic boilerplate may not be sufficient. The client needs an understandable explanation of the facts and risks relevant to the decision.
A free account is not a confidentiality plan
It is tempting to treat an open browser chatbot like a private research notebook. It is not one unless the current terms, settings, and technical design make it so.
If the firm has not reviewed and approved the account, keep client and firm-confidential information out of it. “I changed the names” is not enough when the remaining facts still point to a real person or dispute.
An enterprise agreement can improve the position through no-training commitments, access controls, retention choices, and contractual duties. It still needs review. A legal-specific label does not answer who can read the data or whether a subprocessor receives it.
Local processing changes one part of the risk
When a model runs entirely on hardware the firm controls, matter content need not be sent to a model provider. That can remove an important external disclosure path. It does not make the whole workflow private by itself.
The computer may synchronize files to another service. Operating-system telemetry, backup software, plugins, remote support, or later cloud features may introduce other recipients. The device still needs encryption, access control, patching, and a tested backup. Confirm the complete data path rather than relying on the word “local.”
Usus is being designed around local-first work and client-controlled encryption for optional synchronization. That design choice is meant to reduce provider access to matter content. We will publish the exact architecture and its limits before release so firms can evaluate the implementation, not just the claim.
Confidentiality is only half the review
A private answer can still be wrong. A model running on a lawyer’s desk can invent a case or misread a record as fluently as a cloud model.
For research and drafting, open the underlying authority, check quotations in context, confirm current validity and jurisdiction, compare factual statements with the record, and look for contrary material. The amount of review should reflect the task and the consequence of error.
The lawyer also remains responsible for communications and fees. If AI use is material to the representation or the basis on which the client agreed to the service, discuss it. Under hourly billing, charge for time actually spent rather than time the task might once have taken. Any separate technology charge must be reasonable and properly explained.
A five-minute check before use
Before submitting client-related material, write down:
- the task and why AI would help;
- the minimum information required;
- the account, current settings, and applicable provider terms;
- whether consent or client discussion is needed;
- the sources and facts a qualified reviewer will check; and
- the record the firm will retain.
AI can be a valuable research and drafting assistant. The safe question is not “Do lawyers use AI?” It is “What is this tool doing with this client’s information, and how will I verify the work?”
Primary reference
This article offers general information, not legal or ethics advice. Check the rules and opinions that apply in your jurisdiction.
This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.