Shadow AI in Law Firms: The Risk, the Rules, and the Fix
Shadow AI puts client data in personal AI accounts. What ABA Opinion 512 and Rules 1.6, 5.1 and 5.3 require, how to find it, and how to replace it.
Shadow AI in a law firm means lawyers and staff using unapproved AI tools on client work, such as personal ChatGPT, Claude or Gemini accounts. It creates a confidentiality problem under Model Rule 1.6 and a supervision problem under Rules 5.1 and 5.3, and ABA Formal Opinion 512 tells managerial lawyers to set clear policies on permissible use and supervisors to make sure lawyers and nonlawyers are trained. In practice that also means giving people an approved tool, because a ban alone rarely ends it: the personal account is one tap away on every phone.
What does shadow AI look like inside a law firm?
Shadow AI looks like ordinary diligence done in the wrong place. An associate pastes a draft clause into a personal chatbot, a paralegal summarizes a deposition in a free phone app, or a lawyer lets an AI note-taker join a client call. The firm did not approve the tool and cannot see what went into it.
Four unapproved routes out, and one approved route the firm controls.
It arrives through four doors:
- Personal chatbot accounts on free or paid consumer tiers.
- Browser extensions that read whatever page a lawyer has open.
- AI meeting note-takers that send call transcripts to a service the firm never assessed.
- New AI features in licensed tools, added after the firm approved the product.
Why does banning ChatGPT not stop shadow AI?
A ban removes the approved route without removing the demand, so the use moves to personal phones and home browsers the firm cannot see. A firm that only prohibits risks keeping the same use with less information about it.
Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 knowledge workers in 31 markets, found that 78 percent of people using AI at work were bringing their own tools, and that 52 percent were reluctant to admit using it for their most important tasks. The Thomson Reuters Institute's 2025 Generative AI in Professional Services Report, which surveyed 1,702 professionals across legal, tax, risk and government in early 2025, found 41 percent personally using publicly available tools such as ChatGPT, while 52 percent believed their organization had no generative AI policy. Microsoft and Thomson Reuters both sell AI products, and Thomson Reuters screened respondents for familiarity with generative AI, so treat these as direction, not prevalence.
If half of AI users are reluctant to admit using it for their most important work, a firm that asks once has measured willingness to disclose, not actual use.
What do the Model Rules and ABA Formal Opinion 512 require?
ABA Formal Opinion 512, issued 29 July 2024, applies existing duties of competence, confidentiality and supervision to generative AI. For shadow AI, the key line is addressed to management: "Managerial lawyers must establish clear policies regarding the law firm's permissible use of GAI."
A firm with no policy has not done that. Underneath the opinion, Rule 1.6(c) requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to" client information. Rule 5.1(a) requires managers to make reasonable efforts to ensure the firm has "measures giving reasonable assurance that all lawyers in the firm conform" to the rules, and Rule 5.3 sets a parallel duty for paralegals and other nonlawyers. Rule 1.1 adds competence: Opinion 512 expects lawyers to understand a tool's capabilities and limitations and to verify or review its output. Our legal AI hub works through Rules 1.6 and 5.3 in detail.
Four points in Opinion 512 bear directly on personal accounts:
| What Opinion 512 says | What it means for shadow AI |
|---|---|
| Before inputting client information, lawyers must evaluate the risk of disclosure outside and inside the firm | A lawyer who cannot say what the provider does with inputs has not evaluated it |
| For self-learning tools, informed client consent is required before inputting information relating to the representation | A consumer account that trains on inputs fits that description on a fair reading |
| General boilerplate in an engagement letter does not make that consent informed | A broad AI clause does not cover an associate's personal account |
| Lawyers should read the tool's terms of use and privacy policy, or consult someone who has | Each personal account runs on terms the firm never reviewed |
The opinion also says idea generation that inputs no information relating to the representation needs no client consent, so a policy can permit general questions while forbidding client facts.
The Model Rules bind only as each state adopts them, and ethics opinions are advisory. This page is information, not legal advice; take specific questions to ethics counsel.
What happens to client information in a personal AI account?
Client information in a personal AI account sits under the provider's consumer terms, in an account the firm cannot administer, search, preserve or delete. Those terms are written for individuals and change on the provider's schedule, not the firm's.
OpenAI's data usage policy says consumer ChatGPT conversations may be used to improve its models unless the user turns that setting off, while its business offerings are not used for training by default. Anthropic's consumer terms update of 28 August 2025 asked users of Claude Free, Pro and Max to choose whether their chats could be used for training, with five year retention for those who allow it and 30 days for those who do not. Claude for Work and the API were excluded. Neither choice is the firm's to make.
In The New York Times Company v. Microsoft Corporation, No. 1:23-cv-11195 (S.D.N.Y.), a 13 May 2025 order directed OpenAI to preserve and segregate ChatGPT output log data that would otherwise have been deleted. A 9 October 2025 stipulation and order ended that obligation as of 26 September 2025. Logs already preserved stayed held, apart from requests from the EEA, Switzerland and the UK, and OpenAI kept preserving logs for accounts tied to domains the News Plaintiffs named. For more than four months, chats users had deleted were held for a lawsuit they had nothing to do with.
And when a lawyer leaves, the account and its history leave too, outside the firm's control and hard to bring under a litigation hold.
Does putting client facts into a consumer AI tool waive privilege?
We found no decision on whether a lawyer's own use of a consumer AI tool waives privilege, and rulings on parties' own use point in different directions. In February 2026 one federal court treated a public AI platform as an ordinary third party, while another held a pro se litigant's ChatGPT materials were protected work product.
In United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y.), Judge Rakoff's 17 February 2026 memorandum held that a represented defendant's exchanges with a public AI platform were neither privileged nor work product, relying in part on its consumer privacy policy, and said any privilege was waived "just as if he had shared it with any other third party." In Warner v. Gilbarco, No. 2:24-cv-12333 (E.D. Mich. 10 February 2026), the magistrate judge reasoned that work product waiver requires disclosure to an adversary or in a way likely to reach one, and AI programs are "tools, not persons." In Morgan v. V2X, No. 1:25-cv-01991 (D. Colo. 30 March 2026), another magistrate judge held that AI interactions "do not automatically compromise" a pro se litigant's work product protection.
Morgan also amended the protective order: material designated confidential may go into an AI platform only if the provider is contractually barred from storing or using inputs to train its model and from disclosing them to third parties, except where needed to deliver the service. All three involved a party using AI on their own, not a lawyer; Warner and Morgan did not decide attorney-client privilege; and none binds another court. Our full reading of Heppner sets out which facts would change the answer.
Three 2026 rulings on a party's own AI use. None binds another court.
How do you find the shadow AI already in use?
To find shadow AI, look in four places: network and endpoint telemetry, your identity provider's third-party app grants, expense and card records, and the people themselves through a no-penalty amnesty. None is complete on its own, and none can see a personal phone on mobile data.
| Where to look | What it finds | What it misses |
|---|---|---|
| Network and endpoint discovery | AI sites and apps reached from firm devices and networks | Personal phones and home devices |
| Identity and app grants | Note-takers, extensions and apps connected to firm email, calendars or documents | Tools with no connection to firm systems |
| Expenses and corporate cards | Consumer AI subscriptions claimed back | Free tiers and plans paid personally |
| Amnesty survey | Which tools, for which tasks, with what data | Whatever people still prefer not to say |
If your firm licenses Microsoft Defender for Cloud Apps and Defender for Endpoint, the tooling exists. Microsoft's guidance on managing generative AI apps describes filtering discovery to a Generative AI category and tagging apps as unsanctioned, which blocks them automatically on devices onboarded to Defender for Endpoint, with an option to warn and educate users instead. Start in warn mode. Blocking on day one, before an approved tool exists, recreates the ban problem with better logging.
Frame the amnesty around tasks, not confessions: what were you trying to get done, and which tool did it best? The answers become the replacement's requirements.
What should a law firm AI policy actually say?
A policy people follow names the approved tools, says what data may go into each one, and draws a clear line between work AI may draft and work a lawyer must own. It should take five minutes to read and offer a better option than the one it takes away.
The Gaper Ownership Map sorts work into three tiers, drawing the same line Opinion 512 draws between AI-assisted drafting and work that needs a lawyer's personal judgment:
| Tier | Law firm examples | Rule of thumb |
|---|---|---|
| Automated | File conversion and OCR, de-duplication, routing an intake form to the right practice group | No legal judgment and no client-facing output |
| Agent-drafted, human-approved | First drafts of letters and clauses, deposition summaries, research memos | A named lawyer reviews and owns the result before it leaves the firm |
| Human-owned | Legal advice, negotiation, signing and filing, privilege calls, conflict decisions | AI may assist the lawyer, but never performs the task |
Opinion 512 is explicit: lawyers may not leave legal advice, negotiation, or other functions requiring a lawyer's personal judgment to AI tools alone. Our guide to human-in-the-loop AI covers designing the review step.
The rest fits in a short list:
- Approved tools, by account type. Name the product and tier, such as a firm-administered business account, not just "ChatGPT".
- Data rules per tool. Separate public information, firm templates and client information. Personal accounts get no client information.
- Consent. Say when informed client consent is needed and who obtains it; boilerplate does not supply it.
- Verification. A person checks every citation and quotation before anything is filed or sent.
- Labeling and training. Opinion 512 suggests marking AI-generated material in files, and treats training of lawyers and nonlawyers as part of supervision.
- Reporting without penalty. If admitting an off-list tool ends in discipline, you stop hearing about it.
- An owner and a review date. The tools change often; the approved list must too.
Should a firm buy a sanctioned tool or build an agent in its own tenant?
Most firms should buy first for general drafting and research, because a business license with training off by default and central administration is the fastest way to give people an approved route. Build when one workflow touches matter data at volume and should run in your own cloud, owned by the firm.
The Rent-vs-Own test tips toward ownership when the workflow is specific to the firm, must respect ethical walls in iManage or NetDocuments, and would cost more to rent indefinitely than to own. Your own tenant changes the facts, not the duty. Microsoft's data privacy documentation for Azure-hosted models says prompts and completions are not available to OpenAI or used to train the models, but flagged content may be stored for human review under abuse monitoring unless the customer is approved for modified monitoring. Know which applies before promising clients anything.
Reference build: illustrative, not a client engagement. A deposition summary agent runs in the firm's own Azure subscription, reads only transcripts the requesting lawyer can already open, drafts a summary with page and line references, and queues it for an associate to approve, with prompts, outputs and approvals logged to firm storage.
Gaper does that work. We build supervised AI agents for law firms through the Gaper method (Assess, Scope, Build, Supervise, Hand over), and the firm owns what we hand over: code, prompts, evaluations and runbook. If a business license solves your problem, we will say so. A free AI assessment tests whether one workflow is worth building; our guides to scoping a first agent project, build vs buy and AI agent security cover the rest.
What should a managing partner do in the next 90 days?
Find the shadow use, switch on an approved tool, publish a short policy, train everyone, and then check again. Order matters: the approved tool must exist before blocking starts.
Approved tools go live before blocking starts.
- Weeks 1 to 2, discover. Turn on discovery in warn mode, pull app grants and expenses, and run the amnesty.
- Weeks 2 to 4, decide. Choose approved tools by account type and sort common tasks into the Ownership Map tiers.
- Weeks 4 to 6, publish and enable. Issue the policy with approved tools live the same day, behind single sign-on, with training off.
- Weeks 6 to 8, train. Cover lawyers and nonlawyers, using real tasks from the amnesty.
- Weeks 8 to 12, enforce and re-check. Move unsanctioned apps from warn to block, rerun discovery, and compare.
Meet the demand shadow AI reveals with a tool the firm controls, and keep a lawyer's name on everything that leaves the building.
Thirty minutes, no commitment. We map one workflow, make the build or buy call, and scope the smallest thing worth shipping.
Frequently asked questions
What does shadow AI look like inside a law firm?
Why does banning ChatGPT not stop shadow AI?
What do the Model Rules and ABA Formal Opinion 512 require?
What happens to client information in a personal AI account?
Does putting client facts into a consumer AI tool waive privilege?
How do you find the shadow AI already in use?
Missed Calls Are Quietly Draining Your Clinic, and Hiring Won't Fix It
Why forward-looking practices are solving patient access at the root, with production AI agents they own instead of a phone tree they keep staffing.
Jul 7, 2026
Offshore Accounting Staff vs AI Agents: How CPA Firms Should Decide
IndustryAI Implementation Cost for Accounting Firms (2026 Bands)
One AI workflow costs an accounting firm $12,000 to $34,000 to build and $690 to $2,630 a month to run, once you count the reviewer. Full tables and when to buy instead.
Sep 4, 2026Ready to turn AI into execution?
Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.