Can You Use AI for Legal Research Without Risking Client Confidentiality?

Generative AI is quickly becoming a real research and drafting aid rather than a novelty — and solo lawyers, who can’t delegate to associates, arguably stand to gain the most from it. But the confidentiality question sits in the middle of the room: to get useful help on a real matter, you generally have to tell the AI about the matter. Where does that information go?

In July 2024 the ABA answered with its first comprehensive guidance, Formal Opinion 512. If you use — or are avoiding — AI tools in your practice, it’s worth understanding what it actually says.

What Opinion 512 requires

The opinion walks through the Model Rules that generative AI implicates: competence (1.1), confidentiality (1.6), communication (1.4), candor toward tribunals, supervision, and fees. The practical core comes down to four obligations:

Understand the tool. The technology-competence duty applies: you needn’t become a machine-learning engineer, but you must reasonably understand what a given AI tool does with your inputs — including whether it uses them for training.

Protect client information going in. Because Rule 1.6 covers all information relating to a representation, typing matter facts into an AI tool is a disclosure to that tool’s operator. For self-learning tools — ones that may train on your inputs — the opinion says lawyers should obtain the client’s informed consent before inputting information relating to the representation. Boilerplate in an engagement letter doesn’t cut it; informed consent means the client actually understands what’s being shared and the risks.

Verify everything coming out. Generative AI produces confident, fluent, and sometimes fabricated output — including citations to cases that don’t exist. Courts have already sanctioned lawyers for filing AI-hallucinated authority. Independent verification isn’t optional; it’s the competence duty applied to a new kind of assistant.

Bill for it honestly. You can bill time spent using AI on a client’s matter and reviewing its output — but in most circumstances not the time spent learning to use the tool, and efficiency gains should flow to the client where the engagement contemplates hourly billing.

Where the real risk concentrates: consumer chatbots

The sharpest confidentiality risk isn’t the legal-specific AI products — it’s the free consumer chatbot open in a browser tab. Consumer tiers of general-purpose chatbots have historically defaulted to using conversations to improve their models, with opt-outs buried in settings. Client facts pasted there may be retained, reviewed by the provider’s personnel under its policies, and folded into future training.

If a lawyer wouldn’t email a client’s file to a stranger who promises to “probably” keep it quiet, the same instinct should apply to pasting that file into a free chatbot.

That leaves lawyers with three broad postures, in ascending order of protection:

  1. Use AI only on public information. Research abstract legal questions without client facts. Safe, but sharply limits usefulness — and abstraction is harder than it sounds; a detailed enough hypothetical is client information.
  2. Use enterprise-grade tools under real agreements. Business tiers with contractual no-training commitments, retention limits, and confidentiality terms. This is where most reputable legal AI products live. Your vendor-diligence duties from Rule 1.6 apply in full — read the terms, not the marketing page.
  3. Keep the AI on your own machine. Run models locally, so matter information never crosses the internet at all. No third party receives the data, so there is no third party to vet, and no training question to negotiate. This was exotic two years ago; consumer hardware and open models have since made it practical for real research and drafting assistance.

Local AI changes the shape of the question

We’ll disclose our bias: we’re building Usus around the third posture, because we think it’s the only one where confidentiality is a property of the architecture rather than a promise in a contract. When inference happens on your own hardware, the Opinion 512 analysis gets dramatically shorter — there’s no operator on the other side of the prompt.

Two honest caveats, though. First, local models trade some raw capability against frontier cloud models, and the gap matters for some tasks; the right comparison is against what you’d otherwise do safely, not against the best model money can rent. Second, local doesn’t mean infallible. A model running on your desk can hallucinate a citation just as fluently as one in a data center. Verification — reading the authority yourself before you rely on it — remains your job under any architecture. That’s why we build research workflows with adversarial review passes designed to catch weak authority before it reaches you, rather than pretending the problem away.

A practical checklist

Before using any AI tool on client matters, you should be able to answer yes to all of these:

  • I know whether this tool trains on my inputs, and where my inputs are stored.
  • If it’s a self-learning tool, my client has given informed consent — or I’m not inputting representation information at all.
  • The tool is covered by real confidentiality terms (or runs locally, so none are needed).
  • I independently verify every authority and factual claim before relying on it.
  • My fee practices around AI-assisted work would survive a client’s scrutiny.

AI is neither forbidden fruit nor a free lunch. It’s a powerful assistant that the rules require you to supervise — same as they always have, for every assistant you’ve ever used.

This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction — consult yours.