It happens before anyone decides to let it happen. A paralegal is drafting a pour-over will. The trust she's working from has an unusual distribution clause, something she hasn't seen before. The answer probably lives in a senior associate's head, but he's in a deposition until four. She has a deadline. She opens ChatGPT, pastes the relevant section, and types: What does this clause mean and how should the pour-over will reference it?

She gets a useful answer. She meets her deadline. No one is notified. Nothing unusual appears in the file. And from the outside, nothing happened. Except that a fragment of a client's irrevocable trust now exists outside the firm, on servers the firm neither controls nor has contracted with, processed under terms of service the firm never reviewed, and potentially used to improve a model that competitors will also use.

This is not a hypothetical. Variants of it are happening in small law offices every day, for the same reason Samsung engineers pasted proprietary source code into ChatGPT in 2023: the tool is fast, it's free, it's right there, and the person using it is trying to do their job well.

The Data Flow Your Firm Doesn't Control

When text is submitted to a consumer AI tool (ChatGPT, Gemini, Claude, Copilot in its default configuration), several things happen at once, and most of them are invisible to the user.

The input is transmitted to the provider's servers and processed. Depending on the tool's current terms and settings, that input may be logged for safety review, retained for a period of time, or used in future training runs. Some providers offer enterprise versions with explicit data-retention controls; the consumer-tier products that most small-firm employees are actually using carry no such guarantees, and the defaults have historically erred toward retention.

More practically: you don't know what happens next. You don't know which employees saw the data during a safety review. You don't know whether the retention setting was changed between the time your paralegal created her account and today. You don't know what jurisdiction the servers are in. And you have no contractual relationship with the provider that would give you any of those answers, because the paralegal signed up herself, under her own account, and your firm agreed to nothing.

The Samsung Pattern

In April 2023, Samsung engineers pasted proprietary chip designs and internal meeting notes into ChatGPT while using it to debug code. The information was transmitted to OpenAI's servers before anyone realized the implications. Samsung subsequently banned the use of generative AI tools on company devices while it developed internal policies. The ban came after the fact, with no recovery mechanism available.

The pattern is not unique to Samsung. It recurs wherever a capable tool is available before a governing policy exists. Small law firms are in that window now.

What Rule 1.6 Actually Says

Model Rule 1.6 prohibits an attorney from revealing information relating to the representation of a client unless the client gives informed consent, the disclosure is impliedly authorized to carry out the representation, or a specific exception applies. ABA Opinion 512, issued in 2023, extended this analysis directly to generative AI tools.

The opinion's central holding on confidentiality is not complicated: before using a generative AI tool in connection with client matters, an attorney must understand what the tool does with the information it receives. If the tool transmits data to third-party servers, the attorney must assess whether that constitutes a disclosure under Rule 1.6, and obtain client consent if it does, or decline to use the tool in that context.

The attorney doesn't need to have been in the room. The question is whether the attorney was exercising the supervision Rule 5.3 requires.

This places a supervisory obligation on the attorney that doesn't disappear because a nonlawyer made the decision. Model Rule 5.3 requires attorneys to make reasonable efforts to ensure that the conduct of nonlawyer assistants is compatible with the attorney's professional obligations. If a paralegal uses a tool that the firm has neither approved nor prohibited, under a policy the firm has neither written nor communicated, the question isn't whether the paralegal did something wrong. The question is whether the attorney was exercising the supervision Rule 5.3 requires.

In the scenario above, the answer is almost certainly no. Not because the attorney was negligent in any culpable sense, but because the firm hadn't yet built the structure that makes supervision possible. There was no approved-tools list. There was no guidance on what categories of information could or couldn't be submitted to an AI tool. There was no training on the difference between the consumer and enterprise tiers of these products. The paralegal improvised within a vacuum, and the attorney is responsible for the vacuum.

The Consent Problem No One Has Solved

Opinion 512 suggests that informed consent might cure the disclosure issue. It might. But securing it in practice is harder than it sounds, and most small firms haven't thought through what it would require.

Informed consent under Rule 1.6 means the client understands the material risks of the proposed course of action and the reasonably available alternatives. For AI disclosure, that means explaining which tools are being used, what those tools do with the information they receive, what the firm knows and doesn't know about retention and training, and what alternatives exist. Most retainer agreements don't contemplate this at all. And even if they did, a blanket consent obtained at engagement doesn't easily extend to tools adopted after the client signed, or to tools the client wasn't specifically told about.

There's also the problem of what the client is consenting to. A client who agrees to let the firm use AI assistance probably imagines something like spellcheck or document formatting. They are almost certainly not imagining that a fragment of their estate plan will be transmitted to a third-party server, retained for an indeterminate period, and potentially used to improve a commercial product. Whether that gap in understanding vitiates the consent is a question that has not been definitively answered, and that is precisely the kind of unsettled question that creates professional liability exposure.

How This Failure Mode Compounds

In the trust scenario, assume the paralegal's ChatGPT session was retained and used in a training run. Nothing happens immediately. The firm has no idea anything occurred. The client has no idea anything occurred. Life proceeds.

Now consider what the compounding looks like over eighteen months in a small estate practice. Five paralegals, each using AI tools to varying degrees, each operating without guidance, over dozens of client matters. The aggregate exposure is not five times one incident. It's a systematic pattern of disclosure, undocumented, unconsented to, and unexamined.

When the bar complaint arrives (not if, but when, as the legal profession works through the first wave of discipline under the emerging AI guidance), the firm that can produce a written AI usage policy, a training record, an approved-tools list, and evidence of ongoing supervision is in a different position than the firm that cannot. The former has a defense. The latter has an explanation.

Incident in the Framework Air Canada · 2024

Air Canada's customer-facing chatbot gave a passenger incorrect information about the airline's bereavement fare policy. The passenger relied on it, booked a full-fare ticket, and later sought the discount he'd been promised. Air Canada argued the chatbot was a separate legal entity responsible for its own statements, and that the airline therefore bore no liability.

The Civil Resolution Tribunal rejected the argument. Air Canada was held liable for its AI's output regardless of any disclaimer. The lesson for law firms isn't about bereavement fares. It's about the doctrine that organizations are responsible for the representations their AI tools make, and for the decisions those tools enable.

What a Minimum-Viable Policy Addresses

A written AI usage policy for a small estate practice doesn't need to be exhaustive. It needs to address four things clearly enough that a paralegal can follow it without calling an attorney to ask.

  1. Approved tools and tiers. Which products are permitted, in which configurations. The distinction between a consumer-tier account and an enterprise account with a data processing agreement is not obvious to a nonlawyer. A policy that says "ChatGPT" without specifying which version and what settings is not a policy. It's a gesture toward one.

  2. What may and may not be submitted. A category-based rule is more durable than a case-by-case one. Client-identifying information, document text relating to a specific matter, and information drawn from the firm's case management system should be treated as presumptively off-limits for consumer-tier tools. The policy should say so plainly.

  3. How to handle ambiguous situations. A paralegal who doesn't know what to do and has no guidance will improvise. The policy should create a clear escalation path: when in doubt, ask before submitting. This is a culture question as much as a policy question, but it starts with the written rule.

  4. Supervisory review mechanism. Rule 5.3 requires more than a written policy; it requires ongoing supervision. The policy should specify how AI-assisted work product will be reviewed before it reaches a client, and by whom.

None of this is technically complicated. The gap between firms that have it and firms that don't is not a gap in sophistication. It's a gap in having set aside two hours to write it down.

The Practical Question for Supervising Attorneys

If you're a solo practitioner or a managing partner at a small firm, the relevant question isn't whether your staff is using AI tools. They probably are, in ways you may not know about, on matters that are already closed. The question is whether you have the structure in place to supervise that use going forward, not because the bar is watching, though it is, but because supervision is what you owe your clients.

ABA Opinion 512 frames the competence question squarely: an attorney who uses AI tools without understanding what those tools do with client information is not competent in their use, and incompetent use of AI is not different in kind from incompetent use of any other tool the representation depends on. The obligation is to understand, not to abstain. Most AI tools used appropriately are fine. Most of the current risk in small-firm practice isn't the tools. It's the absence of a framework for using them.

The paralegal in the scenario at the top of this piece wasn't doing anything malicious. She was doing her job under time pressure with the resources available to her. The failure was structural, not personal. Structural failures are fixable, but only before the next deadline, not after.