Ask ten managing partners why their firm has not adopted AI and at least half will cite confidentiality. Some will reference "the ethics rules" as if those rules contain a ban. They do not. The actual text of the rules, and the two most important opinions interpreting them, tell a different story: one that permits AI, assigns responsibility, and rewards firms that control where their data lives.
This piece walks through what the rules say, what the ABA and the North Carolina State Bar actually concluded, and how the analysis changes depending on whether an AI tool runs in someone else's cloud or in your firm's own environment.
The rule everyone cites and few quote
The confidentiality obligation lives in ABA Model Rule 1.6. Paragraph (c), added in 2012 well before generative AI existed, is the operative language for technology decisions:
"A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."ABA Model Rules of Professional Conduct, Rule 1.6: Confidentiality of Information
Three things about this language matter for AI adoption.
First, the standard is reasonable efforts, not perfection. The rule does not require a guarantee against disclosure. It requires a considered, defensible process for protecting client information. Comment 18 to the rule lists factors: the sensitivity of the information, the likelihood of disclosure without safeguards, the cost and difficulty of additional safeguards, and the extent to which safeguards adversely affect the lawyer's ability to represent clients.
Second, the rule is technology-neutral. It applied to fax machines, then email, then cloud document storage, and now AI. In each prior transition, bar regulators reached the same conclusion: the technology is permitted, and the lawyer is responsible for using it carefully. AI is following the identical pattern.
Third, the rule regulates disclosure and access, not tools. Nothing in Rule 1.6 addresses AI by name. What it addresses is whether client information can be seen by people who should not see it. That framing is exactly why the deployment model, not the AI itself, is where the analysis lives.
What ABA Formal Opinion 512 actually says
On July 29, 2024, the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first formal guidance on generative AI in legal practice. The opinion's premise is permission, not prohibition: lawyers using generative AI must "fully consider their applicable ethical obligations." Use the tools. Understand your duties while doing so.
On confidentiality specifically, the opinion establishes a due diligence framework:
- Know how the tool uses data before client information goes in. Lawyers are responsible for understanding whether inputs are used to train the model, who can access stored prompts and outputs, how long data is retained, and what the vendor's terms of service actually permit.
- Assess disclosure risk inside and outside the firm. The opinion flags that multiple lawyers using the same shared AI tool can inadvertently expose one client's information to another matter. Cross-matter contamination is a confidentiality issue even when data never leaves the vendor.
- Obtain informed consent where the tool creates exposure. When client confidences will be input into a generative AI tool that learns from or exposes that data, the opinion recommends securing the client's informed consent first. And it is explicit that boilerplate consent language buried in an engagement letter does not qualify.
Notice what the consent obligation attaches to: not AI as a category, but tools whose data practices create disclosure risk. Change the data practices and you change the obligation.
North Carolina made it concrete
On November 1, 2024, the North Carolina State Bar adopted 2024 Formal Ethics Opinion 1, "Use of Artificial Intelligence in a Law Practice." For firms in the Carolinas, this is the controlling guidance, and it is notably practical.
The opinion permits AI use across a lawyer's practice, subject to the duties the profession already knows: competence under Rule 1.1, confidentiality under Rule 1.6, supervision, and candor. Its most quoted line is a caution, not a ban: lawyers should avoid inputting client-specific information into publicly available AI resources, because the lawyer, not the vendor, is responsible for the security of information entered into an AI program.
Read that carefully, because the qualifier is doing real work. The concern is not AI. The concern is publicly available AI, meaning consumer tools where inputs may train shared models, where the firm has no contractual control over retention, and where the vendor's data practices can change with a terms-of-service update. The opinion draws the exact line that matters: the risk lives in the deployment model, not the capability.
The reasonable efforts test, applied to cloud AI
Here is what satisfying Rule 1.6(c) actually looks like when a firm evaluates a typical cloud AI tool. For each tool, the firm needs defensible answers to at least these questions:
- Are prompts and uploaded documents used to train the vendor's models, now or under any future terms?
- Who at the vendor, and at the vendor's subprocessors, can access stored client data?
- How long are inputs and outputs retained, and can the firm compel deletion?
- What happens to firm data if the vendor is acquired, breached, or subpoenaed?
- Does the vendor agreement permit any secondary use of firm data, however described?
- Which clients require notice or informed consent before their information touches the tool?
None of these questions is unanswerable. Enterprise AI vendors publish data processing agreements, and careful firms negotiate them. But the analysis is per-vendor, per-tool, and perpetual, because terms change, subprocessors change, and every new AI feature a vendor ships restarts the review. For a 10 to 75 attorney firm without a dedicated technology counsel, that recurring diligence burden is the real cost of cloud AI, and it is the honest reason many firms have simply opted out.
How private deployment changes the analysis
Now run the same six questions against an AI system deployed privately, in the firm's own environment, on infrastructure the firm controls.
| Rule 1.6(c) question | Public cloud AI tool | Private deployment |
|---|---|---|
| Do inputs train outside models? | Depends on tier, terms, and settings. Must be verified per tool and re-verified as terms change. | No. The model runs in the firm's environment. Client data never reaches a shared training pipeline. |
| Who can access client data? | Vendor personnel and subprocessors, governed by the vendor's contracts, not the firm's. | Only firm-authorized users, under the firm's existing access controls and ethical walls. |
| Retention and deletion | Vendor retention schedules. Deletion rights vary by agreement. | The firm's own retention policy applies. Nothing exists outside firm systems. |
| Breach, acquisition, subpoena exposure | Firm data sits in a third party's risk envelope. | Firm data stays inside the firm's existing risk envelope, already covered by its security program. |
| Secondary use of data | Governed by evolving vendor terms that require ongoing monitoring. | None. There is no counterparty with an interest in the data. |
| Client consent trigger | Frequently triggered, since data leaves firm control. Opinion 512 says boilerplate consent is inadequate. | Rarely triggered, since information relating to the representation stays within the firm, like any other internal system. |
The pattern is consistent: private deployment does not make the ethical duty disappear. It relocates the analysis from a vendor's data practices, which the firm cannot control and must perpetually monitor, to the firm's own security program, which the firm already maintains, documents, and answers for. That is a question firms know how to answer, because it is the same question they answer about their document management system.
Rule 1.6(c) is a reasonable efforts standard. Keeping client data inside the firm is the single most defensible reasonable effort available.
A practical checklist for managing partners
If your firm is evaluating AI adoption this year, the ethics-driven path looks like this:
- Inventory current AI exposure. Attorneys are already using consumer AI tools, with or without a policy. NC 2024 FEO 1 makes the firm responsible either way. Find out what is actually in use.
- Write the policy around data flow, not tool names. A rule that says "no ChatGPT" ages badly. A rule that says "no client-specific information in tools the firm does not control" tracks the actual ethics guidance.
- Classify use cases by data sensitivity. Drafting a marketing email and analyzing a client's deal documents are different Rule 1.6 events. Match the deployment model to the sensitivity tier.
- For client-data workloads, require firm-controlled deployment. This is where the reasonable efforts analysis is cleanest and where the consent question largely resolves itself.
- Document the diligence. Reasonable efforts is a process standard. The firm that can show its analysis has already satisfied most of it.
The bottom line
The ethics rules were never the obstacle. Rule 1.6(c) asks for reasonable efforts. ABA Formal Opinion 512 supplies the diligence framework. NC 2024 FEO 1 draws the line at publicly available tools and puts responsibility on the firm. Every one of those authorities is compatible with AI adoption, and all three point toward the same conclusion: the firms best positioned to use AI on real client work are the ones that keep the intelligence, and the data it runs on, inside the building.
That is a deployment decision. And unlike the ethics rules, it is entirely within your control. See how private AI for law firms works in practice.
Frequently asked questions
Does ABA Model Rule 1.6 prohibit lawyers from using AI?
What does Rule 1.6(c) require when a law firm uses AI tools?
Do lawyers need client consent to use AI?
What does North Carolina's 2024 FEO 1 say about AI?
How does private AI deployment change the Rule 1.6 analysis?
This article is provided for general informational purposes only and does not constitute legal advice. Ethics rules and formal opinions vary by jurisdiction and are subject to amendment. Firms should consult their own ethics counsel or state bar before adopting any AI tool or policy.