Tuesday, September 15$199late booking, seats still openBook a seat
← All guides

Can lawyers use ChatGPT and keep client confidentiality?

Yes. ABA Formal Opinion 512, issued 29 July 2024, permits generative AI use under the existing Model Rules. State and local bars from Florida to Texas to the District of Columbia have reached the same conclusion. But competence, confidentiality, communication and reasonable fees all attach. For self-learning tools, the ABA says client informed consent is required before you input client information.

Yes. ABA Formal Opinion 512, issued 29 July 2024, permits generative AI use under the existing Model Rules. State and local bars from Florida to Texas to the District of Columbia have reached the same conclusion. But competence, confidentiality, communication and reasonable fees all attach. For self-learning tools, the ABA says client informed consent is required before you input client information.


What ABA Formal Opinion 512 actually says

On 29 July 2024, the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first formal opinion on generative AI in law practice (ABA news release, 29 July 2024).

The opinion runs 15 pages and creates no new rules. It applies existing ones. The ABA release names four rules as principally applicable: Model Rule 1.1 on competence, Model Rule 1.6 on confidentiality, Model Rule 1.4 on communications and Model Rule 1.5 on fees (ABA news release). The opinion also reaches candor to the tribunal and supervisory duties.

The framing is permissive, not prohibitive. Lawyers and firms using generative AI must "fully consider their applicable ethical obligations," the opinion says. Consider, not avoid.

This page is not legal advice. It summarizes published ethics opinions so you know which ones to read.

The confidentiality test the opinion sets

Opinion 512 sets a duty to assess before you paste. "Before lawyers input information relating to the representation of a client into a GAI tool, they must evaluate the risks that the information will be disclosed to or accessed by others outside the firm," the opinion states (summarized with citations by the NCBE Bar Examiner, Fall 2024).

There is no single answer, because tools differ. The assessment is fact-based and tool-specific. That is why the opinion tells lawyers to "read and understand the Terms of Use, privacy policy, and related contractual terms and policies of any GAI tool they use to learn who has access to the information that the lawyer inputs into the tool," or to consult a colleague or expert who has (NCBE Bar Examiner).

The duty runs beyond current clients. Opinion 512 flags the confidentiality obligations of Rule 1.9(c) for former clients and Rule 1.18(b) for prospective clients.

The self-learning tool rule, which is the sharpest line in the opinion

Opinion 512 singles out "self-learning GAI tools" as the highest-risk category. Their nature, the opinion says, "raise[s] the risk that information relating to one client's representation may be disclosed improperly, even if the tool is used exclusively by lawyers at the same firm" (NCBE Bar Examiner).

The conclusion follows directly. Because many of today's self-learning tools could lead to disclosure of client information, "a client's informed consent is required prior to inputting information relating to the representation into such a GAI tool" (NCBE Bar Examiner).

Two limits keep this workable. If you use a self-learning tool without inputting information relating to the representation — idea generation, for example — no consent is required. And the consent must be real. "Boilerplate waivers will not suffice as informed consent," the opinion says. The client needs your best judgment on why the tool is used, what specific kinds of client information will be disclosed, how others might use it against their interests, and what the tool actually buys the representation.

Where the internet is commonly wrong: the disclosure myth

The most repeated claim online is that lawyers must always tell clients when they use AI. That is not what the opinions say, and jurisdictions genuinely differ.

The New York State Bar Association's April 2024 task force report does not direct attorneys to inform clients or obtain consent when AI will be used. That report was approved by the NYSBA House of Delegates on 6 April 2024 and runs close to 90 pages (NYSBA Task Force report).

The New York City Bar reached a similar landing point. Formal Opinion 2024-5, issued August 2024, frames its guidance as guardrails rather than bright-line rules and does not impose a duty to disclose routine AI use (NYC Bar Formal Opinion 2024-5). It also expressly disagrees with the NYSBA task force's call for new AI-specific rules.

Under ABA Opinion 512, consent is triggered by a specific fact pattern — a self-learning tool receiving client information — not by AI use in general. Treating disclosure as a blanket requirement is a misreading of every one of these documents.

Which jurisdictions have weighed in

Jurisdiction Document Date Notable position
ABA Formal Opinion 512 29 July 2024 Informed consent required for self-learning tools receiving client information
Florida Bar Ethics Opinion 24-1 19 January 2024 Non-binding; research the tool's data retention, sharing and self-learning policies
District of Columbia Ethics Opinion 388 April 2024 Competence, Rule 1.6 data protection, Rule 5.3 supervision of AI output
Pennsylvania / Philadelphia Joint Formal Opinion 2024-200 May 2024 Permitted with safeguards; verify all citations and cited material
New York State NYSBA Task Force report 6 April 2024 No direction to inform or obtain client consent
New York City Formal Opinion 2024-5 August 2024 Guardrails, not new rules; no duty to disclose routine use
New York City Formal Opinion 2025-6 2025 Addresses AI recording, transcribing and summarizing client conversations
Texas Opinion 705 February 2025 Competence includes understanding how the tool works; no billing for time saved
California State Bar practical guidance 2023, under review Guidance the California Supreme Court directed the Bar to consider folding into formal rules

Counts of "how many states have ruled" vary widely across trackers, from around eleven to around fifteen jurisdictions with formal opinions, depending on whether task force reports, court rules and standing orders are counted. We could not verify a single authoritative tally, so the table above lists only opinions we confirmed against a primary or bar-published source. The direction of travel is consistent even where the count is not: competence, confidentiality, verification, supervision and reasonable fees appear in every one.

Fees, and the trap of billing for speed

Opinion 512 is unusually concrete on money. When billing hourly, lawyers must bill only for actual time. "A fee charged for which little or no work was performed is an unreasonable fee," the opinion says (NCBE Bar Examiner).

The ABA release gives a worked example. A lawyer who spends 15 minutes inputting information to draft a pleading may charge for those 15 minutes, plus the time spent reviewing the draft for accuracy and completeness. But "in most circumstances, the lawyer cannot charge a client for learning how to work a GAI tool" (ABA news release).

Texas Opinion 705 lands in the same place, stating that lawyers should not charge clients for the time saved by using a generative AI program (Texas Center for Legal Ethics, Opinion 705).

A seven-step intake before a firm adopts any AI tool

  1. Read the terms of use and privacy policy end to end. Opinion 512 makes this an ethical step, not an IT step.
  2. Establish whether the tool is self-learning. This single fact decides whether informed consent is required before client information goes in.
  3. Confirm the training default in writing. OpenAI states that for business users, including ChatGPT Business, ChatGPT Enterprise and the API, "we do not train on any inputs or outputs" by default (OpenAI Help Center).
  4. Confirm retention and who can access stored content. Ask for the retention period in days and the access grounds in writing.
  5. Write the consent language if consent is required. Specific, not boilerplate. Name the tool, the information going in, the risk and the benefit.
  6. Set a verification rule for every citation. Pennsylvania's Joint Formal Opinion 2024-200 requires lawyers to check and verify all citations and cited material (PBA/Philadelphia Joint Formal Opinion 2024-200).
  7. Assign supervision. D.C. Ethics Opinion 388 treats AI output under Rule 5.3, meaning it gets the scrutiny you would give a junior associate's work (D.C. Bar Ethics Opinion 388).

The honest summary

Nothing in these opinions bans generative AI. Every one of them assumes competent lawyers will use it. What they refuse to accept is unverified output, undisclosed risk to client information, and fees charged for work that was not done.

The failure mode in practice is almost never "a lawyer used AI." It is "a lawyer filed something without reading it." That is an old violation wearing new clothes.

sources:

related:


A page of standing instructions that writes your weekly document for you

Rather do this with someone than read about it?

Automate reports and documents with AI is a live two-hour class built on exactly this problem. 25 seats, your own files, and you leave with a saved set of instructions that writes that document for you, the way you want it.

Read next

Can my ChatGPT conversations be subpoenaed?

Yes, and they already have been. In New York Times v. OpenAI, a court ordered OpenAI to produce 20 million de-identified ChatGPT conversations.

How do I stop AI making things up in my documents?

You cannot turn it off, so you build a checking step instead. Feed the AI your own source files, make it quote and cite, then verify every name, number…

How many professionals have been sanctioned for AI errors?

The best public count is Damien Charlotin's AI Hallucination Cases database. As of its 2 September 2026 update it lists 2,008 court decisions worldwide,…