The confidentiality problem with AI is not abstract. It is what happens to a client's matter the instant it lands in a text box that may retain or train on it. We read the terms and the data flow so your firm knows exactly which tools are safe for confidential work, and your counsel makes the privilege call on facts, not hope.
When a lawyer or a paralegal pastes matter facts into a generative AI tool, that text leaves the firm's control and enters the vendor's systems. Whether that is safe turns entirely on the tool's terms: does it use inputs to train or improve the model, how long does it retain them, which subprocessors touch them, and does a business or enterprise tier change any of it. A self-learning tool that trains on what you type is a different risk class than an enterprise deployment with contractual no-training and retention limits. Most firms have never read the difference.
This is the technical work we do. We map how each tool handles matter data, read the terms against your confidentiality exposure, and classify every tool as permitted, restricted, or prohibited for confidential work, in writing. ABA Formal Opinion 512 points to informed client consent before confidential information enters a self-learning tool; we make sure you can tell which tools trigger that question. Whether privilege is preserved or waived on a given matter is a legal determination for your counsel. We give your lawyers the data-flow facts; the judgment stays theirs.
We read the terms, privacy policy, and data-processing terms of the AI tools your firm already uses, and tell you in plain language what each does with matter data.
Read more ›Every tool sorted into a tier for confidential matter data, with the reasoning documented so the firm can supervise and defend the calls.
Read more ›The confidentiality controls folded into a written policy under the supervisory rules: approved tools, prohibited uses, and human verification of AI output.
Read more ›An independent read of where your AI and cloud vendors actually send and store your data, so no tool is trusted on marketing alone.
Read more ›An independent vendor-and-terms review of the AI and cloud tools in use at a multi-attorney professional practice: each tool's data handling mapped, classified by data-sensitivity risk, and delivered as a written use policy. Professional-firm engagements are anonymized by default; we speak to the work and share references privately, never a public client roster.
Whether privilege is preserved or waived is a legal question your firm's counsel answers. What we do is the technical side that informs it: we analyze where matter data goes when it enters a given tool, whether the terms allow retention or training, and who else could access it, so your lawyers can make the privilege determination on facts rather than assumptions.
A self-learning tool reserves the right to retain your inputs and use them to train or improve the model, which means confidential matter data can persist beyond your session and outside your control. A tool that's safer for confidential data offers contractual no-training terms, limited retention, and access controls, usually in a business or enterprise deployment. The difference lives in the terms and the configuration, not the brand name.
Opinion 512 points to informed client consent before confidential information is entered into a self-learning generative AI tool that trains on inputs. Whether consent is required on a particular matter is a legal judgment for your lawyers. We make sure you can tell which tools would trigger that question and keep confidential data out of the ones that would.
The answer is in the terms of use, privacy policy, and data-processing terms: whether inputs are used to train or improve models, how long data is retained, which subprocessors touch it, and whether business or enterprise tiers change any of that. We read those documents against your confidentiality exposure and translate them into a plain permitted, restricted, or prohibited call for matter data.
A tiered policy of which tools may touch which data, enterprise deployments with no-training and retention limits, access controls, and a firm rule that no confidential matter data enters an unapproved tool. Paired with human verification of AI output, these controls keep the firm in command of where its client data goes. We build and document them so the firm can supervise and defend the setup.
I use AI to make good people faster, sharper, and harder to beat, never to replace them. Better, faster, stronger: the goal is a firm that grows and hires more humans, not fewer.
A scoped, plain-language read on what each tool does with matter data, and which ones your firm should never let near a client's confidence.
DeSoto Consulting LLC provides technology and AI advisory services and does not provide legal advice or legal representation.
No pitch deck. No sales process. Just a straight conversation about what you're facing.