Plain Answers · Legal
Can law firms use ChatGPT?
Yes. The question is what you put in it.
Yes, with care — and the care is almost entirely about confidential client information. No AI tool is "ethics compliant" as a product; whether a particular use is acceptable depends on the tool's terms, its security, what you feed it, and whether your client has agreed. The State Bar of California has written guidance on exactly this, and it's the right place to start.
Rules that may apply to you
Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your firm's ethics counsel or the State Bar's ethics resources. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.
- State Bar of California — Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law(opens in new tab)
- State Bar of California — Ethics & Technology Resources(opens in new tab)
- California Rules of Professional Conduct — Chapter 1, Lawyer-Client Relationship(opens in new tab)
- California Rules of Professional Conduct — Chapter 5, Law Firms and Associations(opens in new tab)
- California Business and Professions Code section 6068(opens in new tab)
- California Evidence Code section 952(opens in new tab)
- State Bar of California — Proposed Amendments to the Rules of Professional Conduct Related to Artificial Intelligence(opens in new tab)
Start with the State Bar's own guidance
The State Bar of California publishes practical guidance on using generative AI in the practice of law, and has been revising it. It's the first link in the list above. It's short and it's free. Read the current version yourself rather than anyone's summary of it — including ours.
California lawyers may also be subject to confidentiality, competence, and supervision duties under the Rules of Professional Conduct and the Business and Professions Code. Those are linked above too, and reading them against a specific AI tool is work for you and your ethics counsel.
Our own takeaway, as the non-lawyers who get asked to install these systems: a vendor's homepage saying "secure" is not diligence. You need the actual terms for the actual plan, and somebody at the firm needs to have read them.
The privilege question
We won't tell you whether a given AI use affects privilege; that's your call and your ethics counsel's, and the Evidence Code section linked above is where that reading starts. What we can tell you is which facts the analysis is likely to need: who receives your text, who at the vendor can read it, what it's used for, and how long it's kept. Get them in writing before anyone needs them.
What to ask an AI vendor
- Which plan are we on, and which terms govern it? Consumer and business plans of the same product carry different terms.
- Are prompts and uploads used to train or improve models?
- Can your employees or contractors read our content? When, and is access logged?
- How long is everything retained — including after we delete it?
- Who are your subprocessors, and where is data processed?
- Will you notify us of a breach or a legal demand for our data?
- Can the terms change without our signature? Some products treat continued use as acceptance of new terms. Ask how you'd find out.
Output is the other half
Confidentiality gets the attention, but the work product matters just as much. Treat AI output the way you'd treat a draft from a confident first-year nobody has supervised yet: every citation checked, every quotation pulled from the source, every time. AI drafts are fluent and occasionally wrong, and the wrong parts read exactly like the right parts.
The same goes for staff. Have a written AI policy before your paralegals write one for you by habit. One more California detail: the State Bar has also been considering rule amendments related to AI (last link above). Ask your ethics counsel where they stand before you finalize a firm policy.
What we check when we deploy for a firm
- Matter-level walls. A private knowledge base should respect the same ethical walls as your document management system. If an associate can't open the file, the AI can't quote from it to them.
- Nothing leaves. Outbound traffic from the AI server is blocked at the firewall, and we test it with the uplink unplugged.
- Every answer cites its source. The system shows the passage it relied on, from your own documents, so checking takes seconds rather than trust.
- Logs you control. Who asked what, and when — kept on your hardware, for as long as your retention policy says.
- Agent permissions, narrowly. If a tool can act — send, file, calendar — each permission is granted on purpose, with approval steps where the stakes are high.
What private AI changes, and what it doesn't
A model on a server in your own office keeps client information inside the firm. There's no outside AI vendor whose terms need parsing, because none receives the text. A single 24GB graphics card can hold a long contract in memory at once; entry servers run $1,500 to $7,500, and a private knowledge base over your own documents starts at $2,500.
It doesn't change the need to review what comes out, to supervise who uses it, or to keep clients informed the way your ethics counsel advises. For the general version of this question, see Is ChatGPT safe for business documents?