IntegrationsBlogBook a free AI assessment
Industry

Shadow AI in Law Firms: The Risk, the Rules, and the Fix

Shadow AI puts client data in personal AI accounts. What ABA Opinion 512 and Rules 1.6, 5.1 and 5.3 require, how to find it, and how to replace it.

By Mustafa Najoom»Oct 6, 2026»13 min read»shadow ai law firms
Shadow AI in Law Firms: The Risk, the Rules, and the Fix

Shadow AI in a law firm means lawyers and staff using unapproved AI tools on client work, such as personal ChatGPT, Claude or Gemini accounts. It creates a confidentiality problem under Model Rule 1.6 and a supervision problem under Rules 5.1 and 5.3, and ABA Formal Opinion 512 tells managerial lawyers to set clear policies on permissible use and supervisors to make sure lawyers and nonlawyers are trained. In practice that also means giving people an approved tool, because a ban alone rarely ends it: the personal account is one tap away on every phone.

What does shadow AI look like inside a law firm?

Shadow AI looks like ordinary diligence done in the wrong place. An associate pastes a draft clause into a personal chatbot, a paralegal summarizes a deposition in a free phone app, or a lawyer lets an AI note-taker join a client call. The firm did not approve the tool and cannot see what went into it.

Diagram of client matter data leaving a law firm through four unapproved routes: personal chatbot accounts, browser extensions, AI meeting note-takers and new AI features in licensed tools. An approved, firm-administered tool behind single sign-on with training off is the one route the firm controls.

Four unapproved routes out, and one approved route the firm controls.

It arrives through four doors:

  • Personal chatbot accounts on free or paid consumer tiers.
  • Browser extensions that read whatever page a lawyer has open.
  • AI meeting note-takers that send call transcripts to a service the firm never assessed.
  • New AI features in licensed tools, added after the firm approved the product.

Why does banning ChatGPT not stop shadow AI?

A ban removes the approved route without removing the demand, so the use moves to personal phones and home browsers the firm cannot see. A firm that only prohibits risks keeping the same use with less information about it.

Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 knowledge workers in 31 markets, found that 78 percent of people using AI at work were bringing their own tools, and that 52 percent were reluctant to admit using it for their most important tasks. The Thomson Reuters Institute's 2025 Generative AI in Professional Services Report, which surveyed 1,702 professionals across legal, tax, risk and government in early 2025, found 41 percent personally using publicly available tools such as ChatGPT, while 52 percent believed their organization had no generative AI policy. Microsoft and Thomson Reuters both sell AI products, and Thomson Reuters screened respondents for familiarity with generative AI, so treat these as direction, not prevalence.

If half of AI users are reluctant to admit using it for their most important work, a firm that asks once has measured willingness to disclose, not actual use.

What do the Model Rules and ABA Formal Opinion 512 require?

ABA Formal Opinion 512, issued 29 July 2024, applies existing duties of competence, confidentiality and supervision to generative AI. For shadow AI, the key line is addressed to management: "Managerial lawyers must establish clear policies regarding the law firm's permissible use of GAI."

A firm with no policy has not done that. Underneath the opinion, Rule 1.6(c) requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to" client information. Rule 5.1(a) requires managers to make reasonable efforts to ensure the firm has "measures giving reasonable assurance that all lawyers in the firm conform" to the rules, and Rule 5.3 sets a parallel duty for paralegals and other nonlawyers. Rule 1.1 adds competence: Opinion 512 expects lawyers to understand a tool's capabilities and limitations and to verify or review its output. Our legal AI hub works through Rules 1.6 and 5.3 in detail.

Four points in Opinion 512 bear directly on personal accounts:

What Opinion 512 saysWhat it means for shadow AI
Before inputting client information, lawyers must evaluate the risk of disclosure outside and inside the firmA lawyer who cannot say what the provider does with inputs has not evaluated it
For self-learning tools, informed client consent is required before inputting information relating to the representationA consumer account that trains on inputs fits that description on a fair reading
General boilerplate in an engagement letter does not make that consent informedA broad AI clause does not cover an associate's personal account
Lawyers should read the tool's terms of use and privacy policy, or consult someone who hasEach personal account runs on terms the firm never reviewed

The opinion also says idea generation that inputs no information relating to the representation needs no client consent, so a policy can permit general questions while forbidding client facts.

The Model Rules bind only as each state adopts them, and ethics opinions are advisory. This page is information, not legal advice; take specific questions to ethics counsel.

What happens to client information in a personal AI account?

Client information in a personal AI account sits under the provider's consumer terms, in an account the firm cannot administer, search, preserve or delete. Those terms are written for individuals and change on the provider's schedule, not the firm's.

OpenAI's data usage policy says consumer ChatGPT conversations may be used to improve its models unless the user turns that setting off, while its business offerings are not used for training by default. Anthropic's consumer terms update of 28 August 2025 asked users of Claude Free, Pro and Max to choose whether their chats could be used for training, with five year retention for those who allow it and 30 days for those who do not. Claude for Work and the API were excluded. Neither choice is the firm's to make.

In The New York Times Company v. Microsoft Corporation, No. 1:23-cv-11195 (S.D.N.Y.), a 13 May 2025 order directed OpenAI to preserve and segregate ChatGPT output log data that would otherwise have been deleted. A 9 October 2025 stipulation and order ended that obligation as of 26 September 2025. Logs already preserved stayed held, apart from requests from the EEA, Switzerland and the UK, and OpenAI kept preserving logs for accounts tied to domains the News Plaintiffs named. For more than four months, chats users had deleted were held for a lawsuit they had nothing to do with.

And when a lawyer leaves, the account and its history leave too, outside the firm's control and hard to bring under a litigation hold.

Does putting client facts into a consumer AI tool waive privilege?

We found no decision on whether a lawyer's own use of a consumer AI tool waives privilege, and rulings on parties' own use point in different directions. In February 2026 one federal court treated a public AI platform as an ordinary third party, while another held a pro se litigant's ChatGPT materials were protected work product.

In United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y.), Judge Rakoff's 17 February 2026 memorandum held that a represented defendant's exchanges with a public AI platform were neither privileged nor work product, relying in part on its consumer privacy policy, and said any privilege was waived "just as if he had shared it with any other third party." In Warner v. Gilbarco, No. 2:24-cv-12333 (E.D. Mich. 10 February 2026), the magistrate judge reasoned that work product waiver requires disclosure to an adversary or in a way likely to reach one, and AI programs are "tools, not persons." In Morgan v. V2X, No. 1:25-cv-01991 (D. Colo. 30 March 2026), another magistrate judge held that AI interactions "do not automatically compromise" a pro se litigant's work product protection.

Morgan also amended the protective order: material designated confidential may go into an AI platform only if the provider is contractually barred from storing or using inputs to train its model and from disclosing them to third parties, except where needed to deliver the service. All three involved a party using AI on their own, not a lawyer; Warner and Morgan did not decide attorney-client privilege; and none binds another court. Our full reading of Heppner sets out which facts would change the answer.

Timeline of three 2026 federal rulings on a party's own AI use: Warner v. Gilbarco (E.D. Mich., 10 February 2026) protected a pro se litigant's ChatGPT materials as work product, and United States v. Heppner (S.D.N.Y., 17 February 2026 memorandum) held a represented defendant's exchanges with a public AI platform neither privileged nor work product. Morgan v. V2X (D. Colo., 30 March 2026) held AI interactions do not automatically compromise work product and let confidential material go only to AI platforms contractually barred from storing or using inputs to train and from disclosing them; none binds another court.

Three 2026 rulings on a party's own AI use. None binds another court.

How do you find the shadow AI already in use?

To find shadow AI, look in four places: network and endpoint telemetry, your identity provider's third-party app grants, expense and card records, and the people themselves through a no-penalty amnesty. None is complete on its own, and none can see a personal phone on mobile data.

Where to lookWhat it findsWhat it misses
Network and endpoint discoveryAI sites and apps reached from firm devices and networksPersonal phones and home devices
Identity and app grantsNote-takers, extensions and apps connected to firm email, calendars or documentsTools with no connection to firm systems
Expenses and corporate cardsConsumer AI subscriptions claimed backFree tiers and plans paid personally
Amnesty surveyWhich tools, for which tasks, with what dataWhatever people still prefer not to say

If your firm licenses Microsoft Defender for Cloud Apps and Defender for Endpoint, the tooling exists. Microsoft's guidance on managing generative AI apps describes filtering discovery to a Generative AI category and tagging apps as unsanctioned, which blocks them automatically on devices onboarded to Defender for Endpoint, with an option to warn and educate users instead. Start in warn mode. Blocking on day one, before an approved tool exists, recreates the ban problem with better logging.

Frame the amnesty around tasks, not confessions: what were you trying to get done, and which tool did it best? The answers become the replacement's requirements.

What should a law firm AI policy actually say?

A policy people follow names the approved tools, says what data may go into each one, and draws a clear line between work AI may draft and work a lawyer must own. It should take five minutes to read and offer a better option than the one it takes away.

The Gaper Ownership Map sorts work into three tiers, drawing the same line Opinion 512 draws between AI-assisted drafting and work that needs a lawyer's personal judgment:

TierLaw firm examplesRule of thumb
AutomatedFile conversion and OCR, de-duplication, routing an intake form to the right practice groupNo legal judgment and no client-facing output
Agent-drafted, human-approvedFirst drafts of letters and clauses, deposition summaries, research memosA named lawyer reviews and owns the result before it leaves the firm
Human-ownedLegal advice, negotiation, signing and filing, privilege calls, conflict decisionsAI may assist the lawyer, but never performs the task

Opinion 512 is explicit: lawyers may not leave legal advice, negotiation, or other functions requiring a lawyer's personal judgment to AI tools alone. Our guide to human-in-the-loop AI covers designing the review step.

The rest fits in a short list:

  • Approved tools, by account type. Name the product and tier, such as a firm-administered business account, not just "ChatGPT".
  • Data rules per tool. Separate public information, firm templates and client information. Personal accounts get no client information.
  • Consent. Say when informed client consent is needed and who obtains it; boilerplate does not supply it.
  • Verification. A person checks every citation and quotation before anything is filed or sent.
  • Labeling and training. Opinion 512 suggests marking AI-generated material in files, and treats training of lawyers and nonlawyers as part of supervision.
  • Reporting without penalty. If admitting an off-list tool ends in discipline, you stop hearing about it.
  • An owner and a review date. The tools change often; the approved list must too.

Should a firm buy a sanctioned tool or build an agent in its own tenant?

Most firms should buy first for general drafting and research, because a business license with training off by default and central administration is the fastest way to give people an approved route. Build when one workflow touches matter data at volume and should run in your own cloud, owned by the firm.

The Rent-vs-Own test tips toward ownership when the workflow is specific to the firm, must respect ethical walls in iManage or NetDocuments, and would cost more to rent indefinitely than to own. Your own tenant changes the facts, not the duty. Microsoft's data privacy documentation for Azure-hosted models says prompts and completions are not available to OpenAI or used to train the models, but flagged content may be stored for human review under abuse monitoring unless the customer is approved for modified monitoring. Know which applies before promising clients anything.

Reference build: illustrative, not a client engagement. A deposition summary agent runs in the firm's own Azure subscription, reads only transcripts the requesting lawyer can already open, drafts a summary with page and line references, and queues it for an associate to approve, with prompts, outputs and approvals logged to firm storage.

Gaper does that work. We build supervised AI agents for law firms through the Gaper method (Assess, Scope, Build, Supervise, Hand over), and the firm owns what we hand over: code, prompts, evaluations and runbook. If a business license solves your problem, we will say so. A free AI assessment tests whether one workflow is worth building; our guides to scoping a first agent project, build vs buy and AI agent security cover the rest.

What should a managing partner do in the next 90 days?

Find the shadow use, switch on an approved tool, publish a short policy, train everyone, and then check again. Order matters: the approved tool must exist before blocking starts.

Timeline of the 90-day plan: discover in weeks 1 to 2, decide in weeks 2 to 4, publish the policy with approved tools live in weeks 4 to 6, train in weeks 6 to 8, and enforce and re-check in weeks 8 to 12. Approved tools go live before unsanctioned apps move from warn to block.

Approved tools go live before blocking starts.

  1. Weeks 1 to 2, discover. Turn on discovery in warn mode, pull app grants and expenses, and run the amnesty.
  2. Weeks 2 to 4, decide. Choose approved tools by account type and sort common tasks into the Ownership Map tiers.
  3. Weeks 4 to 6, publish and enable. Issue the policy with approved tools live the same day, behind single sign-on, with training off.
  4. Weeks 6 to 8, train. Cover lawyers and nonlawyers, using real tasks from the amnesty.
  5. Weeks 8 to 12, enforce and re-check. Move unsanctioned apps from warn to block, rerun discovery, and compare.

Meet the demand shadow AI reveals with a tool the firm controls, and keep a lawyer's name on everything that leaves the building.

Book a free AI assessment

Thirty minutes, no commitment. We map one workflow, make the build or buy call, and scope the smallest thing worth shipping.

Frequently asked questions

What does shadow AI look like inside a law firm?
Shadow AI looks like ordinary diligence done in the wrong place. An associate pastes a draft clause into a personal chatbot, a paralegal summarizes a deposition in a free phone app, or a lawyer lets an AI note-taker join a client call. The firm did not approve the tool and cannot see what went into it.
Why does banning ChatGPT not stop shadow AI?
A ban removes the approved route without removing the demand, so the use moves to personal phones and home browsers the firm cannot see. A firm that only prohibits risks keeping the same use with less information about it.
What do the Model Rules and ABA Formal Opinion 512 require?
ABA Formal Opinion 512, issued 29 July 2024, applies existing duties of competence, confidentiality and supervision to generative AI. For shadow AI, the key line is addressed to management: "Managerial lawyers must establish clear policies regarding the law firm's permissible use of GAI."
What happens to client information in a personal AI account?
Client information in a personal AI account sits under the provider's consumer terms, in an account the firm cannot administer, search, preserve or delete. Those terms are written for individuals and change on the provider's schedule, not the firm's.
Does putting client facts into a consumer AI tool waive privilege?
We found no decision on whether a lawyer's own use of a consumer AI tool waives privilege, and rulings on parties' own use point in different directions. In February 2026 one federal court treated a public AI platform as an ordinary third party, while another held a pro se litigant's ChatGPT materials were protected work product.
How do you find the shadow AI already in use?
To find shadow AI, look in four places: network and endpoint telemetry, your identity provider's third-party app grants, expense and card records, and the people themselves through a no-penalty amnesty. None is complete on its own, and none can see a personal phone on mobile data.
MN
Written by

Mustafa Najoom

Marketing & GTM, Gaper

Mustafa is a CPA turned B2B marketer focused on go-to-market strategy, working on growth at Gaper, the AI-native partner that builds and deploys production AI agents.

Ready to turn AI into execution?

Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.