The privilege problem with public AI
Pasting client material into a consumer AI tool can constitute disclosure to a third party — and courts weigh whether a firm took reasonable steps to protect confidentiality. Shadow AI use by associates is now a privilege risk, not just an IT one.
A governance framework
- An acceptable-use policy that names approved tools and prohibits client data in unapproved ones.
- Enterprise AI with contractual data protections (no training on your inputs).
- Data classification so sensitive matter material is handled correctly.
- Training, so the rules are understood, not just published.