Most conversations about AI and confidentiality are conducted at the wrong altitude. They are about whether AI is safe, which is not a question anyone can answer, instead of about where a specific sentence goes when a specific person presses enter, which is a question with a documented answer.
The rule is shorter than people expect
A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
ABA Model Rule 1.6(c) — Confidentiality of Information
Two words in there do a lot of work.
"Reasonable efforts." Not a guarantee. Comment [18] to that rule says as much directly: unauthorized access or inadvertent disclosure is not a violation of paragraph (c) if the lawyer made reasonable efforts to prevent it. It also lists what reasonableness is weighed against — the sensitivity of the information, the likelihood of disclosure, the cost of safeguards, the difficulty of implementing them, and whether they would get in the way of representing the client.
That last factor is the one people skip. A safeguard so heavy nobody uses it is not a better answer under this rule. It is a different kind of failure.
"Information relating to the representation." Broader than privilege, and broader than most people carry in their heads. It is not limited to the confidential parts, and it is not limited to what the client told you.
Where the ABA said the AI-specific line sits
In July 2024 the ABA's Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first on generative AI. On confidentiality it turns on one property of the tool.
a client's informed consent is required prior to inputting information relating to the representation into such a GAI tool
ABA Formal Opinion 512, on self-learning tools, as quoted in The Bar Examiner, Fall 2024
And it closed the obvious escape hatch in the same breath. A general clause in an engagement letter does not do it: informed consent, per the opinion, requires the client to have the lawyer's best judgment about why the tool is being used and "the extent of and specific information about the risk, including particulars about the kinds of client information that will be disclosed."
Read that as a drafting instruction and it is brutal. You cannot write "particulars about the kinds of client information that will be disclosed" unless you know where the information goes. The consent requirement is downstream of a factual question, and the factual question is the hard part.
The same words, two accounts, two different answers
Here is the part that makes this concrete, and it is the reason this series exists.
Take one paragraph of a client's file. Paste it into a consumer account of a mainstream AI product. Now paste the identical paragraph into that same vendor's business or enterprise tier. The model is the same. The answer that comes back is the same. The response to "where did that text go and what happens to it now" is not the same, because it was never about the model. It is about the contract behind the account.
Training on inputs, retention periods, whether an administrator can produce or delete the conversation, whether there is a data processing agreement at all — those vary by plan, from the same vendor, on the same day. They are published. They are also the last thing anybody checks, because the product looks identical from the inside.
A bar that spelled out the steps
Texas issued Opinion 705 in February 2025, asking what ethical issues arise under the Texas Disciplinary Rules from a lawyer's use of generative AI. On confidentiality it gives four things to do before client information goes into a tool: understand how the technology works, review the terms of service, learn about the data-security protections, and train staff.
Nothing in that list is technical. Three of the four are reading.
The same opinion is blunt about who owns the output:
Lawyers are responsible for the work product they submit regardless of who (or what) does the original research and drafting.
Texas Professional Ethics Committee, Opinion 705, February 2025
What to do
Pick the tool your firm uses most and answer four questions about it in writing. Which plan are we on. Does the vendor's own documentation say inputs are used to train their models on that plan. How long is a conversation kept and can we delete it. Who besides the vendor can see it.
One tool, one sitting, one page.
The cost of not having those four answers is specific. Opinion 512 says informed consent requires the client to be given "particulars about the kinds of client information that will be disclosed." Nobody can draft that sentence without knowing where the information goes. Which makes the four answers above the thing that has to exist before the consent language can be relied on.
You are not looking for a tool with perfect answers. You are looking for answers you could show somebody. That is what "reasonable efforts" looks like written down, and it is a page of A4 rather than a project.
If you would rather not spend a Thursday inside four vendor documentation sites, the consulting page is the way in. The page of A4 is worth having either way, and it is yours whoever writes it.