What You Can and Can't Put Into ChatGPT: An Attorney's Confidentiality Guide

8/3/20264 min read

What You Can and Can't Put Into ChatGPT: An Attorney's Confidentiality Guide

The convenience of pasting a document into a chatbot and asking it to summarize is exactly the problem. For attorneys, the real question isn't whether AI is useful — it's whether entering client information into a public AI tool breaches your duty of confidentiality. Often, it can.

This is general information, not legal advice.

The duty hasn't changed — the tool is new

California attorneys owe a duty to protect client confidences under Business and Professions Code § 6068(e) and Rule 1.6 of the Rules of Professional Conduct. That duty is broad: it covers not just privileged material, but essentially any information relating to the representation.

The State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law (first issued November 16, 2023, and updated in 2026) is direct on the point: a lawyer should not input confidential client information into a generative AI tool without first confirming appropriate protections. The reason is technical as much as ethical — many public generative AI platforms may use your inputs to train their models or share them with third parties, and their terms of use, data-retention, and security practices vary widely.

There's a further clarification worth knowing. Among the amendments California's bar has proposed (not yet adopted), a comment to Rule 1.6 would treat inputting client data into an AI tool as a potential disclosure of confidential information whenever there's a material risk the data could be accessed, retained, or used inconsistently with your confidentiality duty. Whether or not that specific comment is adopted, it reflects how the existing duty already applies: the act of entering the data can be the disclosure.

The practical dividing line

Think in terms of the tool's data handling, not its brand name.

Generally risky — public / consumer AI tools

  • Free or consumer-tier chatbots whose terms permit training on your inputs or sharing them with third parties.

  • Any tool where you can't confirm what happens to what you paste.

  • Treat these as though a stranger may read the input. That means no client confidential information, no personal identifying information (names of parties and witnesses, dates of birth, Social Security and driver's-license numbers, financial data, medical or psychiatric information), and no privileged material.

Potentially acceptable — with diligence

  • Enterprise or closed tools with contractual commitments not to train on or retain your data, appropriate security, and a reviewed terms of use.

  • Even then: vet the vendor, read the terms, and confirm confidentiality and retention protocols — ideally with IT or a security professional.

Always safer

  • Redact or anonymize before using any AI tool.

  • Prefer tools that keep data within your firm's controlled environment.

  • Get informed client consent where appropriate, and check the client's own AI restrictions.

A useful mental test: if I wouldn't email this to an unknown third-party vendor without a confidentiality agreement, I shouldn't paste it into a public AI tool.

"Private" is not automatically "compliant"

The most common mistake is assuming an enterprise or paid tier solves the problem by itself. It can reduce the risk — but only if the contract actually bars training on and retention of your data, the security is adequate, and you've read the terms. The label on the tier doesn't discharge your duty; the data handling does. Document your vetting so your confidentiality diligence is demonstrable.

How this connects to what's coming

California's pending SB 574 would add a statutory confidentiality duty aimed at keeping confidential, personal-identifying, and nonpublic information out of public generative AI systems — essentially codifying the guidance above. Notably, the bill's confidentiality provision is framed around public AI systems and doesn't clearly define that term, which is one reason "private" can't be treated as a safe harbor. But this much doesn't depend on the bill: § 6068(e) and Rule 1.6 already impose the obligation, today.

Frequently asked questions

Can I paste a client's document into ChatGPT to summarize it?
Not if it contains confidential or identifying information and you can't confirm how the tool handles your input. Redact or anonymize first, or use a vetted closed tool.

Does using a paid or "enterprise" tier solve the problem?
It can reduce the risk if the terms bar training on and retention of your data and the security is adequate — but you still must vet the vendor and read the terms. "Private" is not automatically "compliant."

Do I need client consent to use AI?
There is no bright-line disclosure rule today, but consent may be appropriate depending on the tool and the data involved, and a client's engagement terms may require it. When in doubt, disclose and confirm.

What counts as "confidential" for this purpose?
Under Rule 1.6 and § 6068(e), the duty is broad — it isn't limited to privileged communications. Treat anything relating to the representation as protected unless you've confirmed otherwise.

This article is general information, not legal advice. Confirm the current version of the State Bar guidance and any applicable rule before relying on specifics.

Sources

  • California Business & Professions Code § 6068(e)

  • California Rules of Professional Conduct 1.6 (confidential information of a client) and 1.1 (competence)

  • State Bar of California, Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law (2023; updated 2026), and proposed comment amendments to Rule 1.6

  • California SB 574 (proposed statutory confidentiality duty)

CONNECT WITH ME ON LINKEDIN!

JOIN THE 20k PLUS FOLLOWERS AND GROWING FOR WEEKLY INSIGHTS ON AI

STAY IN TOUCH

angeli@ailegalstrategist.com

© 2025. All rights reserved.