Ethics & professional responsibility
Protect client confidentiality when using AI
A practical workflow for minimizing confidential data in AI prompts, reviewing product settings, and using sanitized fact patterns where appropriate.
Practice note
Product terms and account settings are only part of the analysis.
Reduce confidentiality risk before using an AI tool
| Factor | Unrestricted AI Input | Minimized and Approved AI Input |
|---|---|---|
| Information provided | May include more client information than the task requires. | Use approved, non-confidential material or a sanitized fact pattern when appropriate. |
| Account review | Assume settings or product terms are the same across accounts. | Confirm the specific product, account, settings, data terms, and retention posture. |
| Professional responsibility | Treat a privacy control as a complete answer. | Follow client instructions, firm policy, and the lawyer’s duty to protect confidences. |
How to sanitize a document
How to sanitize a document
Before uploading a document, find and replace identifying details with neutral descriptors. For example: John → Employee 1; Sarah → Supervisor; BigCo → the employer. Also replace identifying dates, locations, account numbers, contact information, and other facts the analysis does not need. Keep a secure original and verify that the substituted version still accurately preserves the facts material to the legal question.Edited transcript
Transcript
Hey lawyers, are you concerned that AI might compromise confidential data?
1. Do Not Input Confidential Information Into a Material-Risk Tool
If not, you should be, because it most certainly can if it's not used correctly.
The California State Bar updated its AI guidelines in April 2026. The new guidance is clear: do not input confidential client information into an AI tool that presents a material confidentiality risk.
2. Review the Account and Product Settings
Many AI tools use whatever you type or enter into the model to train other models. That means your client’s information could literally become part of somebody else’s answer. This must be prevented.
Here’s how to stop this in Claude: go to Settings, then Privacy. Find the Help Improve Claude setting and toggle that off. Now your new chats will not train the model.
3. Minimize and Sanitize the Material You Provide
But settings are only half the answer. The best practice is not to give AI confidential details that it does not need in the first place.
Limit uploads to non-confidential documents such as court filings, and when analyzing anything confidential, change the identifying information. For example, swap names for Employee A or the supervisor.
Most of the time, the legal analysis works just as well on a sanitized fact pattern. Follow me for more information on how to use AI in your legal practice.