Claremont SecurityManaged compliance · Enterprise AI protection
ABA Model Rule 1.6(c)

What are a law firm’s duties when client information goes into an AI tool?

Published Model Rule 1.6(c)Read time 3 min
The short answer

Take reasonable steps before client information goes into AI. Be able to show them.

Under the rule, lawyers must make reasonable efforts to protect everything about a client’s matter, not only what the client marked confidential. The aim is to stop disclosure by accident or without permission, and access by anyone not allowed to see it. Sending that information to an AI provider your firm has no agreement with is the unauthorized disclosure the rule asks lawyers to prevent. Each state adopts its own version of the rule, and your state’s text is the one that binds your lawyers. Keep a record of which AI tools are approved, what may go into each, who reviewed the vendor’s terms, and that lawyers were trained.

What the rule says

ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.

The duty reaches all information relating to the representation, whatever its source, not only what a client marked confidential. Sending that information to an AI provider the firm has no agreement with is the unauthorized disclosure the rule asks the lawyer to prevent.

The Model Rules are models. Each state adopts its own version of Rule 1.6, and the state’s text is the one that binds the lawyer.

Reasonable efforts is a standard, not a checklist

Rule 1.6(c) does not name a technology. It asks whether the lawyer took reasonable steps, given the circumstances and how sensitive the information is. A firm can show reasonable efforts when it can point to:

  • which tools are approved
  • what data may go into each
  • who reviewed the vendor’s terms
  • that the lawyers were trained

A firm that cannot show those four things has no evidence of reasonable efforts. That gap is what the rule exists to prevent.

Two more duties sit beside confidentiality

The first is competence. Comment 8 to Model Rule 1.1 tells lawyers to keep abreast of the benefits and risks associated with relevant technology. That includes knowing what a tool does with whatever is typed into it.

The second is supervision. Model Rule 5.3 covers nonlawyer assistance, including services from outside the firm. So someone at your firm has to be responsible for reviewing the AI vendor.

Privilege is a separate question from confidentiality

Rule 1.6 governs the lawyer. The attorney-client privilege governs the case. Voluntarily disclosing a privileged communication to a third party outside the privilege generally risks waiving the privilege. The law is unsettled on whether an AI provider bound by confidentiality terms counts as that kind of third party.

A discipline problem can be fixed. A waived privilege cannot. That is why privileged material is the category to keep inside an AI setup your firm controls.

Sourcing note. Rule 1.6(c) above was read against the ABA published Model Rules. ABA Formal Opinion 512, on generative AI, was issued on 29 July 2024 by the Standing Committee on Ethics and Professional Responsibility. It addresses generative AI under Rules 1.1, 1.6, 1.4, 1.5, 5.1, 5.3, 3.1 and 3.3; that list of rules was confirmed against the ABA’s own announcement. The opinion’s conclusion on informed consent before client information goes into a self-learning tool is widely reported. It has not yet been read here against the opinion itself, so this page does not state it as a finding.

Related questions

Does a lawyer need client consent before using AI on a matter?+

It depends on the tool. ABA Formal Opinion 512 and state opinions address the question. Read the opinion and your state’s guidance before you rely on a general answer.

Is a firm-controlled AI deployment enough on its own?+

Not on its own, but it is the strongest option short of keeping the material on the device. The vendor is bound by contract, and the data stays under your firm’s own rules and oversight. Rule 1.6(c) still asks for a written review of the vendor’s terms, a policy on what may go into each tool, and training for your lawyers.

Do the Model Rules bind my firm directly?+

No. They are models. Your state’s own adopted rule is the one that governs, and states differ in both the rule text and the comments.

Model Rule 1.6 is one duty among several that reach a firm holding confidential client material. The map shows the rest, and which control satisfies each one.

Run the law-firm rulesetSee the obligation mapTalk to us

General reference, not legal or tax advice. Every figure and deadline on this page was read against the primary source. Claremont Security does not perform audits, issue certifications, or attest to any examination.

16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States