Insights · AI ethics
Is ChatGPT Confidential for Lawyers? It Depends on the Account, Not the Model
The confidentiality of an AI chatbot rarely turns on the model; it turns on whether your firm signed consumer terms or a commercial contract.
Whether a chatbot keeps your client's information confidential rarely turns on the model. It turns on the account. The same underlying system can be configured to learn from everything you type or to contractually promise it will not, and the line between those two states is the difference between a consumer tier and a business tier.
That distinction is the single most important thing a managing partner can understand about generative AI and Rule 1.6. It is also the thing most lawyers get wrong, because they sign in with the personal account they already had and assume the privacy terms are the same as the ones their firm would negotiate. They are not.
Why the account type controls the confidentiality answer
ABA Model Rule 1.6(a) prohibits a lawyer from revealing information relating to the representation of a client without informed consent or another exception. Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, that information. Pasting client facts into a tool that may feed those facts into a vendor's training pipeline implicates both subsections.
The practical question, then, is what the vendor is permitted to do with your inputs. And the honest answer is that it depends entirely on which contract governs your account.
Consumer tiers operate under consumer terms of service. Those terms increasingly allow the provider to retain inputs and use them to train and improve the model, usually with an opt-out the user has to find and toggle. Business and enterprise tiers operate under commercial terms, often with a data processing addendum, that contractually commit the provider not to train on your inputs by default. Same brand, same logo, very different promise.
What the consumer tiers actually say
On August 28, 2025, Anthropic announced updates to its Consumer Terms and Privacy Policy. Under the prior policy, consumer chats were generally deleted within roughly 30 days and were not used to train models. Under the revised policy, inputs from the consumer plans (Free, Pro, and Max) may be used to train Claude and may be retained for up to five years, unless the user opts out. Existing users were prompted to make a selection, with a deadline reported as September 28, 2025, and new users choose at signup. Critically, Anthropic stated that these changes do not apply to its commercial offerings: Claude for Work, Claude for Government, Claude for Education, and API access remain governed by separate commercial terms.
OpenAI draws the same line. For the personal consumer plans, ChatGPT Free, Plus, and Pro, training is on by default, and the user must affirmatively opt out under Settings, Data Controls, by turning off the option to improve the model for everyone. Even after opting out, OpenAI notes that if a user submits a thumbs-up or thumbs-down on a response, the associated conversation may still be used for training. The default posture, in other words, is disclosure to the vendor's improvement process unless the lawyer intervenes.
The takeaway for the recurring question, is ChatGPT confidential for lawyers, is that the question is incomplete. ChatGPT on a personal Plus account, with default settings, is not configured to keep your inputs out of model training. The same brand on a properly provisioned business account is.
What the business and enterprise tiers say
The contrast is what makes the consumer vs enterprise AI decision so consequential for a firm.
- ChatGPT Team, ChatGPT Enterprise, and the OpenAI API. OpenAI states that, by default, it does not train its models on inputs or outputs from these business products. Business accounts are backed by contractual commitments, including a data processing addendum, rather than a toggle the individual user can flip.
- Claude for Work and the Anthropic API. These run under Anthropic's commercial terms, which do not use your inputs to train models by default and were expressly carved out of the August 2025 consumer change.
- Microsoft 365 Copilot under enterprise data protection. Microsoft states that Microsoft 365 Copilot prompts, responses, and data accessed through Microsoft Graph are not used to train the foundation models, and that interactions are processed within the Microsoft 365 service boundary, inheriting your existing identity, permission, sensitivity-label, and retention controls.
Two features distinguish these tiers and matter for a Rule 1.6 analysis. First, the no-training commitment is contractual and on by default, not a setting an associate has to remember. Second, the account attaches to a licensed, firm-administered work identity, which means the firm controls provisioning, can apply administrative settings, and can off-board a departing lawyer. A personal account does none of that. It belongs to the individual, follows them out the door, and is invisible to the firm's administrators.
ABA Opinion 512 and informed consent for self-learning tools
ABA Formal Opinion 512, issued July 29, 2024 by the Standing Committee on Ethics and Professional Responsibility, is the first formal ABA guidance on generative AI, and it speaks directly to this problem. The opinion advises that before a lawyer inputs information relating to the representation of a client into a self-learning generative AI tool, the lawyer must consider whether informed client consent is required. A self-learning tool is precisely the consumer-tier scenario described above: one that takes your inputs and uses them to improve itself.
Opinion 512 is also pointed about the quality of that consent. It states that boilerplate consent buried in an engagement letter is not sufficient, and that a general reference to using technology does not satisfy the informed-consent standard for self-learning tools. The opinion situates this within the lawyer's broader duties of competence, confidentiality, communication, supervision, candor, and reasonable fees, and it cautions that guidance will need to evolve as the technology does.
The practical reading is straightforward. If you use a tool configured to train on client inputs, you likely need specific, informed client consent, obtained in a meaningful way. If you use a tool that contractually does not train on those inputs and keeps them within a protected boundary, the confidentiality calculus changes substantially, because you have made the reasonable efforts Rule 1.6(c) contemplates and have not disclosed the information to a self-learning process in the first place.
State authorities point the same direction. The California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, released November 16, 2023, leads with the duty of confidentiality and warns that a lawyer should not input confidential information into a tool that lacks adequate confidentiality and security protections, noting that some tools use inputs for training. The Florida Bar's Ethics Opinion 24-1, approved January 19, 2024, recommends that a lawyer obtain the affected client's informed consent before using a third-party generative AI tool if doing so would disclose confidential information, while observing that the concern is mitigated when the tool does not disclose information to a third party. Across the ABA and the states, the analysis keys on the same fact: what the tool does with your inputs.
The practical fix
The fix is not to ban the technology. It is to move every lawyer in the firm off personal accounts and onto a firm-administered business or enterprise tier, then verify the settings rather than assume them. Concretely:
- Provision firm accounts on a business or enterprise tier. ChatGPT Team or Enterprise, Claude for Work, Microsoft 365 Copilot under enterprise data protection, or comparable commercial offerings. Have the firm, not the individual, own the license.
- Read the governing terms for the no-training commitment. Confirm in writing that the commercial terms or data processing addendum state that your inputs are not used to train models by default, and confirm retention behavior. Do not rely on a marketing page; rely on the contract that governs your account.
- Audit for shadow consumer accounts. Survey who is using personal ChatGPT, Claude, Gemini, or Copilot logins for client work. These are the accounts most likely set to train by default, and they are outside firm administration entirely.
- Set a written AI-use policy and supervise it. Rule 5.1 and 5.3 supervision duties, reinforced by Opinion 512, mean partners are responsible for what associates and staff feed into these tools. Name the approved tiers, prohibit client data in unapproved consumer tools, and require human verification of every output.
- Decide your informed-consent posture deliberately. If any approved workflow uses a self-learning configuration, build a specific, plain-language consent process rather than relying on engagement-letter boilerplate that Opinion 512 says will not do.
- Treat the default as the enemy. The August 2025 Anthropic change is the reminder: consumer defaults can shift under you, and an opt-out you set last year is not a substitute for a contract that never permitted training in the first place.
The reason to get this right is that the question of law firm AI client data is ultimately a question of which contract you signed, not which model you used. A business tier moves the no-training promise from a setting an associate might forget into a contractual term the firm controls. For a 3-to-30-attorney firm without a dedicated information-security team, that shift is the most efficient confidentiality control available, and it costs less than the time it takes to argue about whether ChatGPT is safe.
This is general information for lawyers and law-firm leaders, not legal advice, and it does not create an attorney-client relationship. The authorities are cited so you can read them yourself.
The longer argument continues in AI in the Defender’s Office, a national field guide now in production.
Read about the book →