AI ETHICS Moreover, there are complex contractual risks of enterprise AI tools. For example, when a firm subscribes to an AI-powered legal research platform offered by a vendor such as Thomson Reuters or RELX, it enters into a direct contractual relationship with that vendor. Yet vendors building on top of third-party models routinely incorporate, by reference or by flow-down clauses, the acceptable use policies and terms of service of their upstream model providers such as OpenAI, Anthropic, Google, or others. The result is that a law firm’s subscription agreement may silently bind users to a set of third-party obligations that are never surfaced during contract negotiation, are subject to unilateral amendment by the upstream provider, and may impose restrictions on data inputs, outputs, or use cases that are difficult to reconcile with ordinary legal practice. The confidentiality analysis under Rule 1.6 addresses the broad category of information “relating to the representation.” Attorney-client privilege presents a narrower but equally important concern. Privileged communications between lawyer and client receive special protection, and defenders must take care that AI use does not waive or compromise privilege. “There remains a plausible argument that uploading . . . privileged client information would destroy confidentiality and privilege.” 65 Entering privileged communications into an open, insecure AI system might constitute disclosure to the AI vendor and its personnel. Defenders should exercise particular caution with privileged materials. Even when using enterprise AI systems with strong confidentiality protections, defenders should consider whether processing privileged communications through AI serves a legitimate purpose that justifies any waiver risk. When doubt exists, defenders should err on the side of keeping privileged materials out of AI systems. Information entered into most free versions of consumer-facing tools may be incorporated into training data or otherwise retained by the provider. The terms of service for many consumer AI products explicitly permit such uses, and even products that currently do not permit such use may change terms and conditions without the user’s knowledge. Defenders who enter client facts, case theories, or discovery materials into unsecure AI systems risk violating Rule 1.6 by allowing confidential information to leave their control. This is perhaps most problematic when defenders use their own personal devices and personal versions of an LLM — like using ChatGPT on a personal laptop or its mobile app on a personal cell phone — to do legal work. Discovery materials present particular challenges. Protective orders often restrict how parties may use and store produced materials. Entering protected discovery into an AI system might violate the protective order if the system’s data practices conflict with the order’s requirements. Defenders should review protective orders carefully before processing discovery through AI tools and seek modifications if necessary to permit appropriate AI-assisted review.
28
Parity in Practice: The Defender’s Duty to Ethically Use AI
Made with FlippingBook Online document maker