STRATEDGE CONSULTING

Answers

Can a law firm use AI without breaching professional confidentiality?

Yes, provided no identifiable case file ever goes into a consumer tool. Hosting in Europe, partitioned access, an audit log and a written ethics framework: those 4 points make the difference.

Direct answer

A firm can use AI without breaching professional secrecy if the data stays hosted in Europe, partitioned by case file and never reused to train a model.

The safe uses start with internal research, preparing drafts and summarising documents the firm already holds.

The uses to rule out are those that expose an identifiable document to a consumer service with no contract and no commitment against reuse.

Valentin Petitclerc · September 1, 2026

The real risk, in practice

The real risk is copy-paste. A lawyer in a hurry pastes three pages of a case file into a consumer tool, and data covered by professional secrecy leaves the firm for a service whose terms of use, server locations and retention policy nobody has read.

At that moment the firm has lost control. Depending on the tool and its settings, the content may be retained, reviewed, sometimes reused to improve the models. And the firm can no longer answer a client's question honestly: “where is my data?”

Banning solves nothing: usage goes underground, and therefore invisible. The serious answer is to provide a framework and tools that make the right move easier than the wrong one. It is as much an organisational project as a technical one, and it starts with an honest inventory of who already uses what.

The four technical conditions

First condition: hosting in the European Union, with providers bound by a processing agreement under article 28 of the GDPR. Second condition: partitioning. An agent working on case A never sees case B, and access rights follow the firm's existing authorisations.

Third condition: traceability. Every request is dated, attributed and retrievable in an audit log, kept in the same way as access to the case file. Fourth condition: no client data is ever used to train a model, and that commitment is written into the contract.

Where the matter allows it, pseudonymisation adds one more layer of protection: the AI reasons about “Mr X, employed since 2019” and never sees the person's identity. It costs little and removes a great deal of risk.

The safe uses, case by case

Within this framework, several uses pass without difficulty: summarising large sets of documents the firm already holds, preparing recurring letters and drafts from the firm's own templates, research on public sources, transcribing internal meetings.

Sorting and prioritising incoming requests can be added: the agent classifies, prepares and proposes, and a member of the firm decides. The cross-cutting rule never changes: nothing leaves the firm without human review. The AI prepares, the human signs.

Start with a single pilot use case, partitioned and measured. After a quarter, it is the hours saved and the rework rate that decide what comes next. That is the path we follow with the firms we equip.

The uses to rule out

Off limits: pasting an identifiable document into a consumer tool, whatever the goal and however urgent. Without a processing agreement and a written commitment against reuse, secrecy does not survive the journey.

Also off limits: letting an AI issue an opinion that reaches the client without review, plugging an agent into the firm's mailbox without partitioning, or using a free tool whose business model is precisely the exploitation of data.

In between lies a grey area: transcribing a client meeting, for instance. It should not be settled case by case in the corridor: it is settled in writing, in the firm's usage charter.

The written framework to have validated by your bar

The framework fits on one page: permitted uses, prohibited uses, the approved tools, and the review rule. Everyone signs it, partners included. This document removes case-by-case debates and protects every member of the firm.

Complete it with a clear mention in the engagement letter and the privacy policy: clients know what is used, within what framework, with what guarantees. Transparency is the best ethical protection.

Finally, submit the framework to your professional body: a validation or a written opinion protects the firm and settles internal debates. The audit log, kept up to date, then lets you answer any question without improvising.

Written by

Valentin Petitclerc

Founder, Stratedge Consulting

Published on September 1, 2026

Related questions

Yes. A clear mention in the engagement letter and the privacy policy is good practice.

AI leadership that knows your code of conduct

We audit your uses and build partitioned agents, hosted in Europe. First video call, no commitment.

Answers