The questions to ask any AI vendor before client information touches it.
Ten questions, each traceable to ABA Formal Opinion 512 or North Carolina's 2024 Formal Ethics Opinion 1. Read it here, or have a one-pager sent over for the partners' meeting.
Opinion 512 does not tell you which tools are acceptable. It tells you what to find out before deciding, and it expressly contemplates a lawyer relying on someone who has read and analysed the terms. These are those questions, in the order they are usually easiest to ask.
-
What does the vendor retain, and for how long?
Opinion 512 asks lawyers to determine whether the tool retains information submitted to it, both while the service is in use and after it ends. "We do not train on your data" is a different promise from "we do not store it". Ask for both answers separately.
-
Who at the vendor can read what we put in?
Support staff, contractors and subprocessors are all people. The question is not whether the vendor is trustworthy, it is who specifically has access and under what controls.
-
Is the confidentiality obligation actually enforceable?
Opinion 512 asks whether the obligation is enforceable, not whether it is stated. A marketing page is not a contract. Look for it in the terms you are agreeing to, or in a data processing agreement you can sign.
-
Will we be told if there is a breach, and how quickly?
Breach notification is named directly in Opinion 512. If the terms are silent on notice, you have no way to meet your own obligations to a client whose information was exposed.
-
Is the tool configured to preserve confidentiality, or just capable of it?
Many products have a setting that turns off training or retention and ship with it off. The opinion asks that the tool be configured to preserve confidentiality, which is a thing someone has to actually do and then verify.
-
Does the consumer version differ from the business version?
The same brand often has a free tier with quite different data terms. Whatever you conclude about the paid product may not apply to the app someone installed on their phone.
-
Where does the data go, and does that matter for this client?
Processing location and subprocessor lists matter for some engagements and are irrelevant to others. Decide which case you are in before you need the answer.
-
Can we get our information deleted, and prove it?
Retention questions have a matching deletion question. Ask what the process is, how long it takes, and what evidence you get.
-
Who reviews the output before it reaches a client or a court?
This one is about your process rather than the vendor. Opinion 512 is clear that the lawyer remains responsible for the work. A tool that drafts is fine; a tool that sends is a decision you should make deliberately.
-
Has someone actually read the terms, or are we assuming?
Opinion 512 says lawyers should read and understand the terms of use and privacy policy, or consult a colleague or external expert who has. Assuming is the failure mode it is written to prevent.
Sources: ABA Formal Opinion 512 and NC 2024 Formal Ethics Opinion 1 . Read them yourself; they are short.
Stephen is not a lawyer and does not advise on your professional obligations. This checklist is not ethics advice, and using it does not make your firm compliant or satisfy any duty you owe. Those decisions stay with your firm.
On its way.
Check your inbox. If it does not arrive, reply to any email from me and I will send it directly.
If the answers worry you
The common outcome is not that a firm is doing something wrong. It is that nobody has read the terms, so nobody can say either way. Working out which tools and configurations fit the way your firm has decided to handle client information is the technical work Stephen does, and it is where estate planning, personal injury and immigration firms usually start.
Or start with the $995 assessment
Two weeks, a written roadmap of what to change first, and a walkthrough call. If it does not identify at least 10 hours a month of time savings, you get a full refund.