LeanLaw
Blog

Legal Practice Management

Is It Safe to Upload Client Data to a Public AI Tool?

The LeanLaw Team · · Updated July 3, 2026

Is It Safe to Upload Client Data to a Public AI Tool? Legal Practice Management

Generally, no — uploading confidential client data to a public AI tool is not safe, because many consumer tools use your inputs to train their models. Once client information is used that way, you may have breached your duty of confidentiality and, in some cases, waived attorney-client privilege. The exposure exists whether or not anyone ever sees the data again.

Why “public” is the operative word

The risk lives in the terms of service. A public, consumer-grade AI tool is often free precisely because your inputs help improve the model. That arrangement is fine for a grocery list and disqualifying for a client’s settlement position or trust balance. Under ABA Model Rule 1.6, information relating to a client’s representation has to stay protected, and handing it to a third party’s training pipeline is a disclosure.

Does sanitizing the data make it safe?

Partly, and only if you’re rigorous. Stripping names, matter numbers, and identifying details reduces risk — but legal facts are often identifying on their own. A specific set of circumstances can point to one client even with the name removed. Treat sanitization as a helpful reduction, not a guarantee, and never rely on it for highly sensitive matters.

What safe use actually looks like

Safe AI use on client data depends on the deployment meeting a few conditions: the vendor doesn’t train on your inputs, your data is isolated from other customers’, access is controlled by role, and retention and deletion are transparent. Enterprise and legal-specific tools that contractually commit to these are a different category from the free chatbot in a browser tab. The move is to decide, in writing, which tools clear that bar — our AI policy template helps — and to keep confidential data out of everything that doesn’t.

Frequently asked questions

Can I use a public AI tool for non-client work? Yes. General research, drafting a blog post, or summarizing a public statute carries no confidentiality risk. The rule applies to information relating to a client’s representation.

What if the tool has a “don’t train on my data” setting? That helps, but verify it’s contractual and on by default, not a toggle someone can forget. For confidential data, a vendor commitment is stronger than a user setting.

Is uploading client data to AI an automatic ethics violation? It can be, depending on the tool and the data. The safest posture is to assume public tools are not confidential and route sensitive data only to tools that meet your firm’s security bar. See our data-privacy guide for the full analysis.

The LeanLaw Team

Published by

The LeanLaw Team

The LeanLaw Team is the legal-finance content team behind LeanLaw — the billing, trust accounting, and revenue-reporting platform built natively on QuickBooks Online. Drawing on years of work alongside law firms and the accountants who serve them, the team writes about trust accounting, IOLTA compliance, legal billing, and law-firm financial operations. LeanLaw is a QuickBooks Online Premium App Partner.

Clarity into your firm's revenue. Agency over what comes next.

Take control of your firm's financial health with one connected revenue experience — the next step is a demo with your data, not ours.

1,000+

law firms run on LeanLaw

70%

faster invoice collections

$61K

leaked revenue recovered per attorney each year

20–50×

ROI for a typical 10-attorney firm

Figures reflect aggregate results reported by LeanLaw customers — faster collections, recovered revenue, and ROI. Individual firm results vary.