Law firms
AI for law firms, with client confidences kept out.
Short answer
Under ABA Model Rule 1.6 and Formal Opinion 512, a lawyer must make reasonable efforts to keep client information from reaching an AI tool without informed consent. Safe-Desk swaps client names and identifiers for placeholders before a message leaves, stops text marked privileged or attorney work product, and gives the supervising lawyer a log of what was caught.
Updated September 24, 2026 · SOPHIA XT LLC
The risk
Associates and staff use AI to summarize depositions, draft letters and tidy memos. Each of those prompts tends to carry the client's name, the matter and the facts. Formal Opinion 512 points out that a self-learning tool may surface what one user typed to another user later, and that a lawyer must understand what a tool does with the input before using it with client information.
The rules that apply
Model Rule 1.6. Rule 1.6 forbids revealing information relating to the representation without informed consent, and paragraph (c) requires reasonable efforts to prevent its inadvertent or unauthorized disclosure. Your state's version of the rule is what binds you; most follow the model rule closely.
ABA Formal Opinion 512. Issued July 29, 2024 (the opinion, ABA summary), it applies the duties of competence, confidentiality, communication, supervision and reasonable fees to generative AI. It says informed client consent is required before putting information relating to a representation into a self-learning AI tool, and that boilerplate consent in an engagement letter is not enough. It also reminds managing and supervising lawyers of their duties under Rules 5.1 and 5.3 to set clear policies on AI use and to train staff.
Keeping the identifying details out of the prompt is one of the reasonable efforts Rule 1.6(c) asks for. It does not remove every question the opinion raises, such as checking the AI's output and billing fairly for time saved.
How Safe-Desk works in a law office
Staff keep using ChatGPT, Claude, Gemini, Copilot, Perplexity or DeepSeek. The Safe-Desk extension for Chrome and Edge, or the Safe-Desk Windows app for the ChatGPT, Claude and Copilot desktop apps, checks each message before it leaves. Client data becomes a placeholder such as [SSN_1], and only that version reaches the AI provider. When the answer comes back, the staff member who sent it sees the real values again; nobody else does. Passwords, keys and text marked privileged are stopped and sent nowhere. The owner gets a log of who sent what kind of data and which rule caught it, never the value itself, plus phone alerts and a monthly report. See how it works and the security page.
What the law firm template catches
Pick Law firms at sign-up. Text marked privileged or attorney work product is stopped outright, so a memo headed that way never reaches the AI. The owner can change names, places and dates to off, flag or protect, paste the client list, and add custom topics such as a matter's code name.
| What | What happens by default |
|---|---|
| Court case number | Swapped for a placeholder and reported to the owner. |
| Bank routing number | Swapped for a placeholder and reported to the owner. |
| Bank account number | Swapped for a placeholder and reported to the owner. |
| USCIS A-number | Swapped for a placeholder and reported to the owner. |
| Passport number | Swapped for a placeholder and reported to the owner. |
| Driver's license number | Swapped for a placeholder. |
| Medical record or patient ID | Swapped for a placeholder and reported to the owner. |
| Private key | Stopped. Nothing is sent. |
| API key or access token | Stopped. Nothing is sent. |
| Login token | Stopped. Nothing is sent. |
| Password inside a link | Stopped. Nothing is sent. |
| Password or PIN | Stopped. Nothing is sent. |
| Payment card number | Swapped for a placeholder and reported to the owner. |
| ITIN (taxpayer number) | Swapped for a placeholder and reported to the owner. |
| Social Security number | Swapped for a placeholder and reported to the owner. |
| Privileged or work-product material | Stopped. Nothing is sent. |
| Date of birth | Swapped for a placeholder. |
| Email address | Swapped for a placeholder. |
| Phone number | Swapped for a placeholder. |
| Names on your client list | Swapped for a placeholder wherever they appear as written. |
| Other people's names, found from context | Swapped for a placeholder. |
| Addresses, found from context | Swapped for a placeholder. |
| Dates, found from context | Sent as written and reported to the owner. |
| Custom topics the owner adds (a matter, a deal, a code name) | Handled as the owner sets for each topic. |
Read from the Law firms template in the product. In strict mode, messages with identifiers such as SSNs and account numbers are stopped instead of swapped.
A worked example
Your staff type
Summarize this for client Marcus Hale, passport number 123456789, case number 2:25-cv-01432. Keep it to one page.
The AI sees
Summarize this for client [NAME_1], passport number [PASSPORT_1], case number [CASE_NO_1]. Keep it to one page.
The owner's log
Sep 24, 2026, 2:14 PM UTC: Front desk. The message was sent. Swapped out: Court case number, Passport number, Person's name (detected).
The staff member reads the answer with the real values back in. The log names what kind of data was caught, never the values.
Your staff type
PRIVILEGED AND CONFIDENTIAL attorney work product: our settlement floor is $250,000.
The AI sees
Nothing. The message is stopped before it leaves.
The owner's log
Sep 24, 2026, 2:14 PM UTC: Front desk. The message was stopped and nothing was sent: 2 × Privileged or work-product material.
Text marked privileged is stopped. Nothing is sent to the AI.
What it does not do
Safe-Desk does not make a firm compliant on its own and does not certify compliance. It has not been audited for SOC 2. It does not sign a Business Associate Agreement, so it is not for patient information. Names, addresses and dates are caught from your client list and from context; context detection is a best effort, because names have no checksum. Anything your firm sets to Flag is sent as written and reported to the owner.
Safe-Desk does not check whether the AI's answer is right. Rule 1.1 and Opinion 512 still expect a lawyer to review AI output before relying on it.
Setup and price
Safe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person. A firm with no IT person can ask us to set it up; everything we do on your behalf is written to the firm's activity trail.
Questions
Does ABA Formal Opinion 512 ban lawyers from using ChatGPT?
No. It allows generative AI and sets out the duties that apply: competence, confidentiality, communication with the client, supervision and reasonable fees. For self-learning tools it requires informed client consent before information relating to the representation goes in.
If the AI never sees the client's identifiers, do I still need consent?
That is a judgment for you and your state's rules. Opinion 512 ties consent to the risk of disclosure of information relating to the representation, and facts can identify a client even without a name. Safe-Desk lowers that risk by swapping identifiers and stopping privileged text; it does not decide the consent question for you.
What happens to a document marked privileged?
Text marked privileged or attorney work product is stopped. Nothing is sent to the AI, and the owner's log records that the rule fired, without the text.
Can partners see what associates sent?
The owner sees who sent what kind of data, when, and which rule caught it. Never the message or the values. That record supports the supervision duties under Rules 5.1 and 5.3.
Related
- A ChatGPT and AI use policy for small firmsWhat the policy should say, and a one-page sample to copy.
- Is it safe to use ChatGPT with client data?What happens to what you type, business versus consumer plans, and the rules that apply.
- How Safe-Desk compares with the other ways to keep client data out of AIEnterprise DLP, browser-only extensions, private workspaces and banning AI, side by side.
- SecurityWhat we keep, what we never keep, and every subprocessor.
Try it at your firm.
Start free trialSee how it worksSafe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person.