Legal professionals can ethically use business-tier generative AI tools like ChatGPT and Claude if properly configured to protect client confidentiality.
Generative Artificial Intelligence (GAI) tools, such as ChatGPT and Claude, have rapidly gained traction in the legal industry, with a majority of lawyers now integrating them into their work-related tasks. While early ethical opinions often warned against the use of consumer-grade AI due to confidentiality risks, these guidelines also acknowledged the fast-paced evolution of technology. This necessitates an adaptive approach to ethical compliance, prioritizing thorough vetting of AI tools over blanket prohibitions, and highlighting a significant shift towards embracing AI within legal workflows while addressing inherent risks.
The New York State Bar Association (NYSBA) Task Force on Artificial Intelligence underscores that lawyers' primary ethical duty when using GAI tools is to meticulously vet the software. This ensures the robust protection of confidential client information and other sensitive data. Attorneys must obtain explicit assurances from tool providers regarding data security and segregation, alongside conducting regular monitoring to identify and mitigate any changes that could compromise confidentiality. This emphasis shifts the focus to proactive due diligence and continuous oversight, rather than merely the type of technology employed.
Traditionally, legal-specific AI platforms have been developed to cater to the unique workflows and stringent data privacy requirements of legal professionals, though often at a significant cost. However, publicly available GAI tools like ChatGPT, Claude, and Google Gemini have matured to offer more secure business and enterprise-level tiers. These advanced versions are specifically designed to meet high security standards, providing viable and often more cost-effective alternatives for law firms seeking to integrate cutting-edge AI functionality into their practices, thereby broadening access to powerful AI capabilities within the legal sector.
Attorney Carolyn Elefant, a notable voice in legal technology, has concluded that business and enterprise-tier general GAI tools can be ethically used by lawyers for confidential data, provided they are properly selected and configured. She highlights key protections offered by these tiers, including contractual safeguards through Service Agreements and Data Processing Addendums. These agreements typically prohibit the training of AI models on user data, restrict human review to security incidents rather than content monitoring, and provide administrative controls over data retention and workspace security. Her analysis offers practical guidance for legal professionals navigating the ethical landscape of AI adoption.
The article emphasizes that ethical AI adoption in the legal profession is ultimately determined by the diligence exercised in selecting the appropriate version of GAI and configuring it correctly. Compliance is not an inherent feature of any tool but a result of a lawyer’s commitment to vetting, understanding contractual protections, and implementing administrative controls. Regardless of whether a firm chooses a legal-specific AI platform or a robust business-tier general AI tool, the critical factor for maintaining ethical standards, particularly regarding client confidentiality, is the meticulous and ongoing management of the account setup.