Published June 20, 2026 · Updated September 18, 2026
The short answer: yes, lawyers can use ChatGPT and other AI assistants, but not with unredacted client information on a default consumer account. The duty of confidentiality applies to anything you paste, standard ChatGPT stores conversations and (by default) may use them for training, and no consumer chatbot offers the confidentiality guarantees privileged material requires. Safe use means redaction, minimal sharing, and a privacy-focused setup, all covered below.
The Main Reason for Lawyers: an AI Council That Cross-Checks the Answer You Rely On
Privacy is what sends most lawyers looking for an alternative. The AI Council is the reason to use one: you ask once, several top models answer the same question in parallel, and a referee model then compares their answers claim by claim and shows you exactly where they disagree. The full panel is ChatGPT, Claude, Gemini and Grok, one from each company, each running its own live web search; a lighter two-model panel runs within the daily free quota and answers without search. A hallucinated case or a misstated rule doesn't announce itself in a single chatbot's answer: a fabricated citation is normally written with the same fluency as a real one, and fluency authenticates nothing. A panel that splits on it's visible on the page, and it tells you which line to pull the authority for first. That matters here more than in most professions: the 2026 New York and Florida filing rules discussed below put the obligation on verification by the signer rather than on disclosing that AI was used, and standing orders elsewhere vary.
Two limits, stated up front. Agreement between models is evidence, not proof: they're trained on overlapping data and can be confidently wrong together, so a council narrows what you must read yourself; it never replaces reading it. And a council sends your question to every model on the panel, so it widens where your text travels rather than narrowing it: everything below about redacting client detail before you paste applies with more force, not less.
AI assistants have become genuinely useful for legal work: drafting clauses, summarizing long documents, untangling dense language, and offering a quick second perspective on an argument. But for lawyers there's a catch that most professionals never face: almost every text you handle is confidential, and some of it's privileged. The duty of confidentiality doesn't pause because a tool is convenient.
That tension is real, and it's worth being honest about. No mainstream AI chat tool is "safe" for confidential client material by default, and no private AI tool, including this one, makes the risk disappear. What a privacy-focused setup can do is make AI use safer: it reduces some of the exposure that comes with typical consumer chatbots. The responsibility for protecting client data, however, stays with you. This article explains where the risk comes from, what "safer" actually means, and the practical safeguards to apply before you paste a single sentence.
This article is general information, not legal or ethics advice. Follow your jurisdiction's professional conduct rules and your firm's policies, and consult your bar's guidance on AI where it exists.
Why Confidential Text and Mainstream AI Don't Mix Well
The problem is structural, not accidental. When you paste text into a typical consumer AI chatbot, that text leaves your control the moment it reaches the provider's servers. Several things can happen to it that matter for a lawyer:
- Retention. Conversations are often stored, sometimes for extended periods, and tied to your account.
- Human review and training. Many consumer tools may use conversations to improve their models unless you actively opt out, and some allow human reviewers to read samples.
- Account-linked identity. A chatbot account usually knows who you are, which links sensitive prompts to a real person and firm.
For a lawyer, the consequences aren't just privacy preferences; they're professional duties. Sharing a client's confidential information with a third-party service that may store or process it can sit uneasily with the duty of confidentiality. In some situations, disclosing privileged communications to an outside service could raise questions about whether privilege has been protected. The safe assumption is simple: treat anything you put into an AI tool as something that has left your office.
The Rules That Actually Govern This
An article about lawyers and AI that never cites the rules isn't much use, so here they are.
ABA Formal Opinion 512 (July 2024), the ABA's first ethics opinion on generative AI, applies the familiar duties: competence under Model Rule 1.1 includes a reasonable understanding of a tool's capabilities and limitations; confidentiality under Rule 1.6 covers all information relating to a representation, whatever its source; and Rule 5.3 extends supervisory duties to the vendors you rely on. The requirement most often missed is consent: before entering information relating to a representation into a self-learning GAI tool, Opinion 512 says a lawyer must obtain the client's informed consent — a real conversation about material risks and reasonably available alternatives, not a line in an engagement letter.
Keep confidentiality and privilege apart while you're at it. Rule 1.6 is an ethical duty and is far broader; privilege is an evidentiary doctrine with its own elements. A tool can satisfy neither, one, or both, and a vendor's privacy guarantees don't decide the privilege question.
What the Courts Have Actually Done: Not All One Way
Since February 2026 there's case law, and it cuts in both directions. Blanket warnings that AI use destroys protection are now too strong.
- United States v. Heppner (S.D.N.Y., Judge Rakoff, 10 February 2026): privilege and work product never attached to roughly 31 defence documents a criminal defendant produced on his own initiative using consumer Claude: the tool isn't an attorney, and the consumer terms defeated confidentiality. It's a non-attachment holding, not a waiver holding, whatever the alert headlines say.
- The same day, Warner v. Gilbarco (E.D. Mich.) protected a self-represented litigant's ChatGPT research as work product, reasoning that generative AI is a tool rather than a person, so using it wasn't disclosure to an adversary.
- Morgan v. V2X (D. Colo., 30 March 2026) agreed but conditioned it, ordering disclosure of which platforms were used and an AI-specific protective order. Tym v. Cerno (D.N.M., 22 April 2026) adopted Morgan from the bench for that case only. Tate Group Automotive (Business Court of Texas, 3 June 2026) protected most of a represented party's ChatGPT material and declined to follow Heppner. Assini v. Hayward (Sup. Ct. Nassau County, 4 June 2026) applied the same framework to subpoenas served on the AI provider itself.
- Two later decisions settle what the dividing line actually is, and it isn't criminal versus civil. Tremblay v. OpenAI (N.D. Cal.) protected prompts written by counsel to test ChatGPT as opinion work product — the near-absolute tier. Shealy v. Seaside Investments (Suffolk County Superior Court, Business Litigation Session, Mass., 16 June 2026) refused protection in a civil case for a represented party, because the material was generated by the plaintiff's romantic partner rather than by counsel: a non-attorney third party isn't a "representative" under Rule 26(b)(3).
The practical read for a practitioner: counsel direction is the axis. Prompts you write, or direct, in furtherance of a matter have the strongest argument; Tremblay puts them in the opinion tier. A client running their own queries, or a client's partner running them, is where protection has failed. It remains an argument rather than a guarantee, no appellate court has ruled, and none of it helps the ordinary conversation from before any dispute existed.
Filing Rules: Verification, Not Disclosure
Two 2026 rules are worth knowing because they're commonly misdescribed as AI-disclosure mandates. Neither is.
- New York, Part 161 (effective 1 June 2026) permits attorneys to use AI in preparing court papers and does not require disclosure, but requires you to review the paper and independently ensure it contains no fabricated or fictitious cases, statutes or other material.
- Florida, Rule 2.515 (amended 28 May 2026, effective 15 June) makes the signer of any filing certify that "the legal authorities identified exist and are accurately cited". Again no AI disclosure: the Supreme Court simultaneously preempted the patchwork of circuit orders that had required it. Sanctions run from reprimand to striking the filing.
The obligation is verification, and it sits on the signer. Check your own local standing orders, which vary.
What "Safer" Actually Means, and What It Doesn't
This is the most important section in the article, so it comes before the benefits rather than after them.
A private AI workspace can reduce exposure in meaningful ways: less data sitting in a cloud account, less linkage between prompts and your identity, and clearer handling of what happens to a conversation afterward. That's a real improvement over pasting client text into a default consumer chatbot.
But "safer" isn't "confidential," and it isn't "compliant by default." Here's the honest boundary: to answer your question, the AI model still has to read your prompt. With a multi-model cloud service like this one, your text is sent to the selected model provider (such as the company behind GPT, Claude, Gemini, Grok, or Perplexity), so it can generate a response, and to each provider on the panel when you run an AI Council. That means the content is processed off your device by a third party. This isn't local, on-device AI, and it isn't end-to-end encrypted from the model provider.
So the right mental model is harm reduction, not immunity. Using a privacy-focused tool lowers certain risks; it doesn't remove your obligation to decide what is appropriate to share, to minimize confidential detail, and to comply with your professional rules. If a matter is so sensitive that no third party may ever see it, the answer isn't a different cloud chatbot; it's to keep that material out of any cloud AI entirely.
For that highest-sensitivity tier, a firm can go further and run AI on infrastructure it controls (a corporate deployment inside the firm's own environment, or an open-source model running locally on a lawyer's machine), so the text never leaves the organization at all. That's the strongest privacy posture available, but it comes with a real trade-off: the open-weight models you can self-host today are generally not as capable as the top-tier models offered only through the providers' APIs. In practice that often means a split approach: a self-hosted model for the most confidential material, and a privacy-focused gateway to the strongest commercial models for everything else, with redaction applied either way. Before budgeting for a firm machine, it's worth knowing how large that capability gap really is and what closing it would cost in hardware: we measured both in local LLMs vs a private gateway.
How Secret Chat AI Makes Legal AI Use Safer
Secret Chat AI is a private AI assistant and multi-model gateway built around privacy-conscious defaults. At its core it's an anonymizer: it builds no profile of you and never associates your prompts with your identity (the email you sign up with is used only for account access and payment), so even where a provider retains data, it isn't linked to you. It doesn't turn cloud AI into a confidential vault, but it removes several of the rough edges that make mainstream chatbots a poor fit for sensitive work.
- Your chat history stays on your device. Conversations are kept in your browser's local storage rather than in a cloud chat archive on Secret Chat's servers. Uploaded files are also held in local browser storage. Your long-term record of what you discussed lives with you, not in an account history someone else maintains.
- Minimal-identity registration. Sign-up uses an email address only: no name, no phone number, no profile building. There's less identifying information connecting you to your prompts.
- IP masking from model providers. Requests are routed through Secret Chat's infrastructure, so the underlying model provider doesn't see your IP address directly.
- Deletion handling with a session privacy report. Where a provider supports it, Secret Chat requests deletion or no-storage handling of the processed content, and each message can produce a Session Privacy Report (PDF) showing what was done, including, honestly, when a deletion step didn't succeed so you aren't left guessing.
- Model choice in one place. You can pick the assistant that fits the task and compare answers, instead of opening multiple accounts across multiple providers.
One practical note on documents: file uploads support images and PDFs, and since September 2026 also Word files, spreadsheets, PowerPoint decks, CSV, text and code files, and zip archives of them. Images and PDFs go to the model as files; a Word file or a spreadsheet is converted to text in your browser and only that text is sent, so the file itself never leaves your machine — but note that conversion keeps the document's text, not its comments or tracked changes, and the text does reach the provider. Remove anything that shouldn't be shared before you attach; the app shows you the exact text it is about to send.
The same formats now go the other way. The model selector has a Generators group, eight of them, and each answers with a finished piece rather than a wall of text. Document drafts a contract, an act or a letter as a Word file (.docx). Table turns a chronology, an exhibit list or a fee breakdown into a sortable spreadsheet (.xlsx or CSV), and Chart draws it — damages over time, hours by matter — as a JPG or a PDF. Presentation builds a .pptx (or a PDF of it) for a client briefing or a CLE talk. Email writes the client update or the demand letter in the tone and language you set; Translator renders a foreign-language clause into any language on its list; Article and Social Post draft the firm's client alert and the LinkedIn post announcing it, the post already within the network's limit. Editing works the same way as drafting: attach the engagement letter, the fee schedule or the deck, say what to change, and it comes back as a fresh file with everything you gave it kept — a new file, not a redline, so run Word's Compare against the original if you need the changes marked. When you supply the material the model structures it and doesn't go looking on the web for more unless you switch the web on yourself. Two details were decided with legal work in mind. The Document generator leaves whatever you didn't state as a blank, [___], and offers no PDF at all: it's a template you finish in Word, because the road to a finished-looking PDF runs through typing the parties, the sums and the bank details into a chat, which is exactly the data this product is built to keep away from providers. And the .docx, .xlsx or .pptx you download is assembled in your browser from the model's reply — it is never built or stored on a server — and lands in the app's Library next to your chats, on your device, with an Edit button that reopens it on its generator. What you gave it still travelled to the provider you chose, exactly as a typed prompt would, so the redaction rule above applies to a file you want edited as much as to a question. The generators run on the paid models (ChatGPT, Claude, Gemini, Grok).
The Limits You Must Not Ignore
Because the stakes are high in legal work, these limits deserve to be stated plainly rather than buried:
- The model provider still receives your prompt. Inference happens off your device. Review the relevant provider's terms for the model you choose, especially for anything sensitive.
- You remain responsible for confidential data and personal information. The tool doesn't automatically scrub names, account numbers, addresses, or other identifying details from your text. If you don't want a detail processed, don't include it: remove it yourself before sending.
- Privacy features reduce risk; they don't guarantee outcomes. Deletion requests depend on provider support and can fail, which is exactly why the report shows the result instead of promising success.
- This is not a substitute for professional judgment or legal advice. AI output can be wrong, outdated, or fabricated. Verify every citation, rule, and factual claim against authoritative sources before relying on it.
- Your ethical duties still apply. Client consent, engagement terms, jurisdictional rules, and firm policy all govern whether and how you may use AI on a given matter.
Practical Safeguards for Lawyers Using AI
The single most effective protection is the one entirely within your control: limit what you share. The less confidential detail leaves your device, the smaller the exposure if anything goes wrong.
- Redact before you paste. Strip client names, party names, case numbers, account numbers, addresses, dates of birth, and other identifiers. Replace them with neutral placeholders like "the Claimant" or "Company A."
- Work in hypotheticals where possible. Often the legal question can be posed in the abstract without any client-specific facts at all.
- Share the minimum. Upload or paste only the specific clause, paragraph, or page you need help with, not the entire file.
- Clean up documents before converting. When exporting pages to PDF, remove tracked changes, comments, and hidden metadata, and include only the pages that matter.
- Verify everything. Treat AI output as a first draft from a junior assistant: useful, but checked against primary sources before it leaves your desk.
- Mind consent and jurisdiction. Confirm that using AI on the matter is consistent with client expectations, your engagement terms, and your bar's guidance.
A simple way to frame a request so it stays useful without exposing the client:
Act as a contracts assistant. I have redacted all identifying details and replaced parties with "Company A" and "Company B." Review the following clause for ambiguity and suggest clearer wording, and flag any terms that typically need negotiation. Here's the clause:
Where AI Genuinely Helps Legal Work
Used with the safeguards above, AI can save real time on tasks that don't require sharing sensitive specifics:
- Clarifying and tightening language in a draft clause or letter once identifiers are removed.
- Summarizing a redacted PDF to get the gist of a long document before you read it closely.
- Starting points for research — outlines, issue spotting, and plain-language explanations you then verify against authoritative sources.
- Brainstorming arguments and counterarguments in the abstract, then comparing how different models frame them.
- Translating dense legalese into plain language for your own understanding or for client-facing explanations you review.
- Producing the file, not just the text — a template with blanks as a .docx, an exhibit list as a spreadsheet, a chart of it, a client-briefing deck as a .pptx, a client alert and the post about it — through the Generators described above, from redacted material.
In each case, the pattern is the same: AI accelerates the draft, and you supply the judgment, the verification, and the confidentiality discipline.
The fourth of those is worth doing properly rather than by hand, and the reason people skip it's time. Comparing how different models frame an argument normally means opening each one in turn, pasting the question again, waiting through each answer separately, and then reading several long replies against each other in a gap in the day that never appears. The AI Council removes both costs. The models are put to the question at the same moment rather than one after another, so the check runs for about as long as its slowest member instead of the sum of the panel, and each answer opens as that model finishes. The referee then does the reading: it extracts the factual claims, lines them up model by model, and returns a short synthesis of what at least two models reached independently, with everything still contested listed separately to verify before you rely on it. What reaches you at the end is therefore shorter than a single chatbot's answer, not four times longer, and the lines the panel split on, the ones worth pulling the authority for first, are named rather than left for you to notice. The two limits in the note at the top of this article still apply to that synthesis: it tells you what to verify and never counts as having verified it, and it widens where your text travels.
Conclusion
AI is a powerful drafting and research aid, and lawyers shouldn't have to give it up over privacy concerns. But the honest position is the responsible one: a privacy-focused tool like Secret Chat makes confidential-text AI use safer (through local storage of your chats and files, minimal-identity sign-up, IP masking, and transparent deletion handling) without making it risk-free. The model provider still processes your prompt, and the duty to protect client data and personal information stays with you.
If you treat AI as a capable assistant that never sees more than it needs to, you can capture most of the benefit while keeping the risk in check. Want a privacy-conscious workspace to start from? Try Secret Chat AI, and keep your own redaction and verification discipline firmly in place.
Sources
- ABA Formal Opinion 512 — Generative Artificial Intelligence Tools (July 2024)
- New York Unified Court System — Part 161, Use of Artificial Intelligence Technology
- The Florida Bar — Supreme Court amends Rule 2.515 on AI use in court filings
- Assini v. Hayward, 2026 NY Slip Op 26086
- OpenAI — Enterprise privacy and data controls
Frequently Asked Questions
- Is it safe for lawyers to put confidential text into AI?
No cloud AI tool is fully "safe" for confidential client material by default, because the model provider has to process your prompt to answer it. A privacy-focused tool can make it safer by reducing retention and identity exposure, but you remain responsible for confidentiality. The most reliable protection is to redact identifying details and share only what is necessary.
- Does Secret Chat keep my client documents private?
Secret Chat keeps your chat history and uploaded files in your browser's local storage rather than a cloud archive, masks your IP from model providers, and can request deletion of processed content with a per-message privacy report. However, the selected model provider still receives your prompt for processing, so it isn't the same as fully confidential or on-device AI. Sensitive matters still require your own judgment about what to share.
- What file types can I upload for legal documents?
Images, PDFs, Word (.docx), spreadsheets (.xlsx, .xls, .ods, .csv), PowerPoint (.pptx), text, Markdown, code files and zip archives of them. A Word file or spreadsheet is converted to text in your browser before being sent — the app lets you read that text first — so use that moment to remove anything that shouldn't be shared.
- Can it draft or edit a contract as a Word file?
Yes. Choose Document in the Generators group and describe what you need, or attach the existing .docx and say what to change; the answer is a new Word file built in your browser, with anything you didn't specify left as a
[___]blank. There is no PDF option on purpose — a finished-looking PDF would tempt you to type the parties and the figures into the chat. Table, Chart and Presentation do the same for spreadsheets, charts and .pptx decks; Email, Translator, Article and Social Post cover the correspondence, a foreign-language clause, a client alert and the post about it. Whatever you attach still reaches the model provider, so redact first, exactly as with a question. - Does the tool automatically remove client names or personal data from my text?
No. You should assume nothing is stripped automatically. If you don't want a name, number, or other identifier processed, remove it yourself before sending. Handling personal and confidential data remains your responsibility.
- Can I rely on AI answers for legal work?
Treat AI output as a starting draft, never a final authority. Models can produce wrong, outdated, or invented information, including fake citations. Verify every rule, case, and factual claim against authoritative sources, and apply your own professional judgment before relying on anything.