Confidentiality and Data Handling
Keeping client data safe when using AI tools.
Confidentiality and Data Handling
Legal work often involves sensitive client data. Use these practices to protect it when using AI.
Know where data goes
- Cloud models: Input may be used for training or stored on provider systems. Check your provider's terms.
- Local options: Tools like Claude Cowork can run on your machine and keep data local.
- Enterprise plans: Often include stricter data handling and no-training guarantees.
Before you paste
- Strip or anonymize names, identifiers, and confidential terms when possible.
- Use synthetic or redacted examples for testing prompts.
- Avoid uploading entire client files unless your provider and plan allow it.
Firm policies
- Get clear guidance from your firm on approved AI tools and use cases.
- Document what you used and what data was shared.
- Escalate before using AI on high-risk matters.
When in doubt, assume data leaves your control unless the provider states otherwise.