Skip to main content

AI Basics >

Confidentiality

Core Concepts

Exercise caution about materials uploaded into a Generative AI system

Before using any GenAI system, review the Terms of Service to understand how inputs and outputs will be used. Confirm that any uploaded information will be protected by the service provider and that your settings have been adjusted to provide maximal protection. Do not upload sealed filings, dockets with sealed filings, confidential materials, personnel data, and other non-public information. The Codes of Conduct Committee AI guidance considers draft opinions to be confidential information and advises against uploading into a GenAI system, especially if the information may be accessed by the public.

Data exposure happens

Data can be exposed in various ways. Some GenAI systems may use inputs and outputs to train future models. This means that your prompts, the system’s responses, and content you upload may not be private and may appear in or influence the GenAI’s responses to other users. It is critical to read the Terms of Service and check your privacy settings. Incorrect privacy settings could have unintended outcomes; for example, people have inadvertently shared links to chats that surfaced in subsequent GenAI-generated search engine results. Even if your privacy settings are configured correctly, your inputs into a free general-purpose AI system may be exposed through hacks and breaches and potentially sold to third parties. Providers of paid frontier general-purpose AI systems regularly monitor cybersecurity but they are not immune to hacking, prompt-injection attacks, and other forms of manipulation. Another potential risk of data exposure lurks in internet browsers (and browser extensions) that integrate AI features—the browser itself can pose a data exposure risk. 

Free vs. paid systems: the difference can matter

The free versions of general-purpose AI systems (e.g., ChatGPT, Claude, Gemini) are trained on internet and proprietary data and may incorporate or train on user inputs and outputs. The paid tiers may or may not do the same. It is essential to review the Terms of Service and confirm that user settings are properly configured to maximize privacy and security.

Configuring tools for privacy and safety

If using general-purpose AI systems, specific settings must be properly configured: opt out of model training, disable or reset memory features in shared environments, never share chat links, and purge conversations when appropriate. Non-public information should not be uploaded into general-purpose GenAI systems. Even when using legal AI systems, it is important to review and configure the default settings.

Generative AI-related ethical guidelines applicable to attorneys

The American Bar Association issued a formal ethics opinion on generative AI. ABA Formal Opinion 512 (July 2024) identifies key concerns for attorneys using AI, including protecting confidential client information when using GenAI tools and providing competent counsel. Many state bar associations have promulgated similar rules. Understanding these obligations helps judges recognize and respond to potential issues related to attorney conduct. There is a developing line of case law involving judicial sanctions for inappropriate GenAI use by counsel. Many judges have issued standing orders on the use of GenAI by counsel, some requiring disclosure and others requiring an affirmation that all GenAI output was reviewed and verified.

Short Videos

Practical Guides

  • Checklist: Generative AI Privacy Settings

    Step-by-step instructions for adjusting privacy settings for GenAI systems

  • Talking to your Law Clerks about GenAI

    Checklist of topics to address when discussing GenAI use with law clerks.

Frequently Asked Questions

Curated Resources