Yes, if client information only goes into a business account under contract (ChatGPT Business or Enterprise, or a tool built on OpenAI's API, with the data processing addendum signed and no training on your data), clients have been told, and nothing identifying goes into personal accounts. Breaches happen on free and Plus accounts, and when unchecked output reaches a client or court.
Confidentiality isn't the only test. Privilege is a separate question, and courts have started to look at it. In February 2026 a judge ruled that a client's own exchanges with the consumer version of Claude weren't protected by privilege, partly because the consumer terms gave him no reasonable expectation that the chats were confidential. That was a client acting alone, not a firm on business terms, but it shows that courts read the provider's terms. Your regulator's guidance on generative AI is the other document to read before you decide.
Three separate tests: confidentiality, privilege and data protection
Firms often treat "is ChatGPT safe?" as one question. It's three, and a setting that answers one doesn't answer the others.
| Test | What it protects | What breaks it with AI | What protects you |
|---|---|---|---|
| Confidentiality | Everything you learn about a client's affairs | Client information in a tool whose provider may use or disclose it; staff using personal accounts | Business plan, signed data processing terms, a rule on what goes in, access controls |
| Privilege | Lawyer-client communications, and material prepared for litigation, from compelled disclosure | Communications shared with a third party on terms that show no expectation of confidentiality | Business terms that promise confidentiality, use at the lawyer's direction, clear record of purpose |
| Data protection | Personal data about clients, witnesses, opponents and staff | No lawful basis, no processor contract, data kept longer than needed, transfers without safeguards | Processor terms, a record of the processing, retention limits, privacy notice updated |
OpenAI's business plans are designed to meet the first and third tests: business content isn't used for training by default, and OpenAI will sign a data processing addendum for ChatGPT Business, Enterprise and API customers. The privilege position depends on how the tool is used as much as which tool it is.
What the February 2026 privilege ruling does and doesn't settle
The facts matter. A defendant in a fraud case used the public, consumer version of Claude on his own initiative to analyse his position and sketch out defence arguments. Documents recording those chats were seized. The court held they weren't privileged: the AI isn't a lawyer, the consumer terms meant the conversations weren't confidential, and the work wasn't done at his lawyers' direction.
What it doesn't decide: how a court would treat a lawyer's own use of an enterprise tool whose terms promise confidentiality and no training. Commentators have pointed out that business terms at least arguably preserve the expectation of confidentiality that the consumer terms destroyed. It's one decision in one court, not settled law everywhere.
The practical lessons for a small firm are clear enough:
- Keep matter work on business terms. The contrast between consumer and business terms was central to the reasoning.
- Record that AI use was at a lawyer's direction and for the matter, for example in the file note or the prompt library.
- Warn clients. The client, not the lawyer, created the problem in that case. A client who pastes your advice into a free chatbot "for a second opinion" may be putting it at risk.
A client-care line many firms are now adding, which you can adapt (have it checked against your regulator's rules):
Please do not copy our advice, or documents about your case, into public AI chatbots or similar online tools. Doing so may mean the information is no longer confidential and could affect whether it is protected from disclosure. If you want help understanding our advice, ask us: explaining it is part of our service.
The risk is easy to picture: a letting agency client in a dispute with a landlord receives the firm's advice on its prospects, pastes the letter into a free chatbot, and forwards the chatbot's more optimistic take to the solicitor asking "which is right?" The solicitor now has two problems: correcting the chatbot's view, and a copy of privileged advice sitting on a consumer platform. The line above, sent at the start, makes the second one less likely.
The warning sits better next to a plain statement of the firm's own use. A filled-in version of the AI paragraph for the client-care letter, which a small firm might adapt (again, check it against your regulator's rules):
We use AI tools to help prepare some drafts, such as routine letters, summaries and attendance notes. We use business versions of these tools under contracts that keep your information confidential and stop it being used to train the provider's systems. A solicitor reads and checks everything before it is sent or relied on, and remains responsible for it. We don't use AI to decide what to advise you. If you would prefer us not to use AI tools on your matter, tell us and we will note it on your file.
Each sentence answers a question clients actually ask: what it's used for, whether their information is safe, who checks it, and how to opt out. The last sentence is the one to connect to something real, which in the set-up record below is the "No AI" flag.
Where ChatGPT Business is defensible and a legal tool fits better
For drafting routine letters, summarising documents the firm is entitled to use, preparing attendance notes from the lawyer's own notes and turning dense advice into plain English, ChatGPT Business on signed terms is a defensible choice for a small firm. At $25 a seat a month (or $20 billed annually, minimum two seats) it's also cheap.
Attendance notes show both the value and the trap. A solicitor's rough notes after a call with an employment client might say "C unhappy with offer, might go to 40k if ref agreed, wants to talk to wife first, chase Fri". Asked to "write a formal attendance note from these notes", an illustrative first draft reads:
Attendance note: telephone call with client, 25 minutes.
The client confirmed that she is willing to accept a settlement of
$40,000 provided an agreed reference is included. We will write to
the respondent's solicitors to put this proposal forward and will
follow up on Friday.
It reads well and it's wrong. "Might go to 40k" has become "willing to accept", "wants to talk to wife first" has disappeared, and the model has invented an instruction to write to the other side. An attendance note is evidence of what the client said, so a hardened position like that could matter later. Add one line to the prompt ("record the client's position exactly as tentative or firm as the notes show; don't add actions that aren't in the notes") and the second draft says the client is considering $40,000 with an agreed reference, will discuss it at home, and that the firm will call again on Friday before taking any step.
Legal-specific tools earn their extra cost where the work needs legal sources, playbooks or tighter data terms. Spellbook, for example, works inside Microsoft Word and says it protects client data with zero data retention agreements. The trade-offs are set out in ChatGPT or a legal AI tool for a small firm. And if the firm lives in Microsoft 365, Copilot's handling of business data is covered in whether Microsoft 365 Copilot keeps business data private.
None of these tools removes the duty to check. General chat assistants can invent case citations and state rules from the wrong jurisdiction with complete confidence. The checking routine is in how to stop AI inventing case law.
Material that stays out, even on a business plan
A business plan fixes the provider's terms. It doesn't lift restrictions that come from the matter itself. Before uploading, check for these:
- Documents disclosed by the other side in litigation, where disclosure rules may limit their use to the proceedings. Using them for AI analysis in the case is usually within that purpose; reusing them elsewhere isn't.
- Material covered by a court order, an undertaking or a confidentiality ring that restricts who may see it. A third-party processor may be outside the permitted circle.
- Third-party information under a non-disclosure agreement that forbids sharing with service providers, or requires consent first.
- Anything a client has asked you not to put into AI tools. Flag the matter so the instruction survives staff changes.
- Identity documents and payment details, which the task almost never needs.
The second item is the one that catches small firms out, because it rarely looks like a restriction when the documents arrive. Imagine a four-solicitor firm acting for a small manufacturer in a supply dispute. The other side discloses its pricing spreadsheets into a confidentiality ring limited to "the parties' external legal representatives named in Schedule 1". A trainee, asked to summarise 60 pages of pricing history, uploads them to the firm's ChatGPT Business workspace. The provider isn't named in Schedule 1, so whether that upload is allowed depends on the order's wording and not on the firm's plan. The safer routine is a single question on the matter opening form: "Is any material on this matter restricted by an order, undertaking or agreement? If so, who may see it?" Where the answer is yes, a solicitor reads the terms before anything goes into any tool, and if there's doubt the firm either asks the other side to agree or does the summary by hand.
Some tasks also shouldn't be delegated whatever the data: final advice, anything filed with a court, and judgements about a client's credibility. Which legal tasks a small firm should never hand to AI covers that list.
Setting up the firm's workspace before the first matter
A filled-in set-up record for a four-solicitor firm (illustrative), which doubles as the evidence you'd show a regulator or insurer:
| Item | Decision | Done |
|---|---|---|
| Plan | ChatGPT Business, 4 seats, annual billing | 1 Oct |
| Data processing addendum | Signed; copy in the risk folder; sub-processor list saved | 1 Oct |
| Personal accounts | Not to be used for any matter facts; confirmed by each fee earner by email | 3 Oct |
| Connected apps | None enabled for now; review in three months | 1 Oct |
| Projects | One per recurring task (letters, attendance notes), not one per client | 6 Oct |
| Chat deletion | Matter chats deleted when the output is saved to the file; the file is the record | 6 Oct |
| Client-care letter | AI paragraph and chatbot warning added for new matters | 10 Oct |
| Objections | "No AI" flag added to the case management system | 10 Oct |
| Review rule | No AI output leaves the firm without a solicitor reading it; citations checked at source | 1 Oct |
On Business, chats stay until someone deletes them, and deleted chats are removed from OpenAI's systems within 30 days unless the law requires longer retention. That's why the firm above treats the matter file, not the chat history, as the record.
The record is only as good as the habits behind it, so check them. A realistic slip: a fee earner working from home on a Sunday opens the ChatGPT app on a personal phone, still signed in to a Plus account, and pastes in a client's email to get a quick reply drafted. Nothing looks wrong, and the reply is fine. It surfaces weeks later, when the same fee earner mentions that the app "remembered" the client's name in an unrelated chat. The response is the same as for any other confidentiality slip: delete the chats, note what went in and when, and ask your data-protection adviser whether it needs reporting. The prevention is practical: sign staff phones in to the business workspace, not personal accounts, and once a quarter compare who is marking drafts as AI-assisted with who is actually using a business seat. A heavy drafter with a barely used seat is probably working somewhere else.
Prompting without over-sharing: before and after
Even on a business plan, share what the task needs and no more. A common first attempt, and a better one, for a letter before action on behalf of a guest-house owner:
Before:
"Draft a letter before action for my client [full name], [home
address], date of birth [..], who owns [guest house name] at [full
address]. A former guest, [full name], left a false review and has
since emailed threats. Attached are the client's bank statements
showing lost bookings and the guest's emails."
After:
"Draft a letter before action from a guest-house owner (the
client) to a former guest about a review the client says is false
and emails the client regards as threatening. Firm tone, no
insults, 350 words. Leave [placeholders] for names, dates and the
loss figure. Set out: the facts in outline, what the client
requires, a 14-day deadline, and what happens if there's no reply."
The second prompt produces a draft that is just as usable, without the client's date of birth, home address or bank statements going anywhere. The names go in at the end, in the firm's own document system.
Sample output extract (illustrative):
"...Your review of 12 August contains statements that are untrue
and amount to a criminal offence. Courts have consistently awarded
damages of at least 10,000 in cases of this kind, and our client
will seek the same..."
That extract shows why review is not optional. The model has turned a civil complaint into a "criminal offence" and invented a damages benchmark nobody gave it, both of which could embarrass the firm and escalate the dispute. Delete them, state the client's position in plain terms, and check any statute, authority or figure the draft contains against the source before it goes out. For summarising longer material safely, see how to summarise bundles and transcripts with AI safely.
What regulators' AI guidance tends to ask of a firm
Guidance on generative AI from legal regulators and professional bodies differs in detail, but it has tended to return to the same five duties. Read your own regulator's current version, because it changes, and map each duty to something the firm actually does:
- Competence: understand what the tool does and where it fails before relying on it. Evidence: a short note of what the firm tested and what it found.
- Confidentiality: know where client information goes and on what terms. Evidence: the set-up record above.
- Supervision: the responsible lawyer checks work produced with AI help by juniors and support staff. Evidence: the review rule, and drafts marked when AI was used.
- Communication: clients can find out how the firm uses AI on their matter. Evidence: the client-care paragraph.
- Fair charging: don't bill for time that wasn't spent. If AI turns a three-hour first draft into forty minutes of checking, the time record should say forty minutes, or the matter should be on a fixed fee.
The charging point is worth a quick sum, because it changes how a small firm prices routine work. At an illustrative $250 an hour, a three-hour first draft billed on time is $750. Drafted with AI help and checked in forty minutes, the honest time record is about $167. Firms that keep billing hourly on those tasks see fees fall; firms that move the work to a fixed fee of, say, $450 give the client a lower price than before and keep a better margin on the solicitor's time. Either is fair. Billing the old three hours for forty minutes of work is not.
A quick test for any task on any matter
- Is it the firm's business account, with signed terms? If not, no matter facts.
- Does anything in the matter restrict who may see this material? If yes, check before uploading.
- Has the client objected to AI use? If yes, stop.
- Does the task need identifying details? If not, use anonymised facts and placeholders.
- Will a solicitor read and check the output, including every citation? If not, don't start.
Five yeses and the task is as defensible as any other outsourced support the firm uses. One no, and the answer is to change the task, the tool or the data before going ahead.
Solicitors' follow-up questions on ChatGPT and confidentiality
If I anonymise a document, can I use my personal ChatGPT account?
For genuinely anonymised material, such as a clause with names and figures removed, the confidentiality risk is small. The trouble is that legal facts identify people easily: a date, a street and an unusual dispute can point to one client. Treat personal accounts as suitable only for general drafting and research questions with no matter facts, and do matter work on the firm's business account.
Do we need each client's consent before using ChatGPT on their matter?
Many firms rely on an explanation in the client-care letter rather than separate consent, but the right answer depends on your regulator's rules and your clients. At minimum, tell clients that you use business-grade AI tools under contract with lawyer review, and record any objection on the matter file. Check your regulator's current guidance before settling the wording.
Can trainees and paralegals use ChatGPT on matters?
Yes, within the firm's rules and under supervision, just as they would draft any other document. The supervising lawyer remains responsible for what goes out. Many firms add a simple rule: anything a junior produces with AI help is marked as such in the draft so the reviewer knows to check citations and facts with particular care.
Is Microsoft 365 Copilot a better fit than ChatGPT for a small firm?
If the firm's documents and email already live in Microsoft 365, Copilot is often easier to govern because it works inside those files and respects existing permissions. It still needs the same rules on what may be drafted and who reviews. ChatGPT Business may still suit heavier drafting. Pick one approved home for each type of task and write it down.
Further reads
- Can Lawyers Use AI Note Takers in Client Meetings? — The same confidentiality questions for recording client meetings.
- AI Acceptable Use Policy for a Small Professional Firm — Turn these rules into a one-page firm policy.
- Does ChatGPT Train on Client Data? Business vs Free Plans — The plan-by-plan detail on training and retention.
- How Small Law Firms Use AI to Draft Letters and Routine Documents — Once the set-up is right, the first drafting jobs to try.
- Questions to Ask Before Buying AI That Touches Client Data — Questions for any legal AI vendor before matter data goes in.
- AI Implementation Plan for a Small Law Firm: The First 90 Days — A 90-day plan once the confidentiality rules are settled.
- Per-Seat or Pay-As-You-Go? Legal AI Pricing for Small Firms — When a legal AI seat beats paying by use, how to work out who in the firm needs one, three monthly budgets and the costs quotes leave out.
- AI Readiness Checklist for Accountants, Solicitors, Consultants — Twenty checks, grouped and scored, that tell an accountancy, law or consulting firm whether it is ready to pilot AI or has gaps to fix first.
- AI Client Intake for Law Firms: Qualify Enquiries Out of Hours — Set up overnight AI intake that gathers facts, screens fit and urgency, books consultations and hands a clean summary to a person each morning.
- How Small Law Firms Use AI to Answer Client Status Questions — A status-note template, drafting prompts and approval rules so AI answers 'where are we?' from the matter record instead of guessing.
- How Conveyancers Use AI to Cut Admin on Each Transaction — Stage-by-stage admin savings for a conveyancing file, a title-summary prompt with sample output, chaser wording and the tasks AI must never touch.
- AI Marketing for Small Law Firms: Content, Reviews and the Rules — How a small law firm can use AI for guides, posts and review replies while staying inside platform, consumer-law and professional conduct rules.
- AI for Small Law Firms: What to Automate First — A scoring method and a firm-tested order for what a small law firm automates first, with the legal work that should wait.
- AI Contract Review for Small Firms: What It Catches and Misses — What AI contract review reliably catches, what it misses and why, with a worked review, a test method and a prompt that demands evidence.
- Can Therapists Use ChatGPT for Session Notes? — Personal plan, de-identified shorthand, business plan or a therapy note tool: where each lands, and why removing a name rarely removes the client.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI enterprise privacy page and help articles on chat retention; published commentary by several law firms and the Harvard Law Review on the February 2026 ruling that a client's consumer-Claude chats were not privileged; Spellbook pricing and security page.