Legal 9 min read

Can law firms use AI without breaking confidentiality? What Rule 1.6(c) actually requires.

Most coverage gets the ethics rules wrong. There is no prohibition on AI in legal practice. There is a duty of reasonable efforts, and the deployment model determines how hard that duty is to satisfy.

The Short Answer

No ethics rule prohibits law firms from using AI. ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. ABA Formal Opinion 512 (July 2024) and North Carolina 2024 FEO 1 (November 2024) both permit AI use under existing duties of competence, confidentiality, and supervision. The compliance question is not whether your firm can use AI. It is where client data goes when you do.

Ask ten managing partners why their firm has not adopted AI and at least half will cite confidentiality. Some will reference "the ethics rules" as if those rules contain a ban. They do not. The actual text of the rules, and the two most important opinions interpreting them, tell a different story: one that permits AI, assigns responsibility, and rewards firms that control where their data lives.

This piece walks through what the rules say, what the ABA and the North Carolina State Bar actually concluded, and how the analysis changes depending on whether an AI tool runs in someone else's cloud or in your firm's own environment.

The rule everyone cites and few quote

The confidentiality obligation lives in ABA Model Rule 1.6. Paragraph (c), added in 2012 well before generative AI existed, is the operative language for technology decisions:

ABA Model Rule 1.6(c)
"A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."
ABA Model Rules of Professional Conduct, Rule 1.6: Confidentiality of Information

Three things about this language matter for AI adoption.

First, the standard is reasonable efforts, not perfection. The rule does not require a guarantee against disclosure. It requires a considered, defensible process for protecting client information. Comment 18 to the rule lists factors: the sensitivity of the information, the likelihood of disclosure without safeguards, the cost and difficulty of additional safeguards, and the extent to which safeguards adversely affect the lawyer's ability to represent clients.

Second, the rule is technology-neutral. It applied to fax machines, then email, then cloud document storage, and now AI. In each prior transition, bar regulators reached the same conclusion: the technology is permitted, and the lawyer is responsible for using it carefully. AI is following the identical pattern.

Third, the rule regulates disclosure and access, not tools. Nothing in Rule 1.6 addresses AI by name. What it addresses is whether client information can be seen by people who should not see it. That framing is exactly why the deployment model, not the AI itself, is where the analysis lives.

What ABA Formal Opinion 512 actually says

On July 29, 2024, the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first formal guidance on generative AI in legal practice. The opinion's premise is permission, not prohibition: lawyers using generative AI must "fully consider their applicable ethical obligations." Use the tools. Understand your duties while doing so.

On confidentiality specifically, the opinion establishes a due diligence framework:

Notice what the consent obligation attaches to: not AI as a category, but tools whose data practices create disclosure risk. Change the data practices and you change the obligation.

North Carolina made it concrete

On November 1, 2024, the North Carolina State Bar adopted 2024 Formal Ethics Opinion 1, "Use of Artificial Intelligence in a Law Practice." For firms in the Carolinas, this is the controlling guidance, and it is notably practical.

The opinion permits AI use across a lawyer's practice, subject to the duties the profession already knows: competence under Rule 1.1, confidentiality under Rule 1.6, supervision, and candor. Its most quoted line is a caution, not a ban: lawyers should avoid inputting client-specific information into publicly available AI resources, because the lawyer, not the vendor, is responsible for the security of information entered into an AI program.

Read that carefully, because the qualifier is doing real work. The concern is not AI. The concern is publicly available AI, meaning consumer tools where inputs may train shared models, where the firm has no contractual control over retention, and where the vendor's data practices can change with a terms-of-service update. The opinion draws the exact line that matters: the risk lives in the deployment model, not the capability.

The reasonable efforts test, applied to cloud AI

Here is what satisfying Rule 1.6(c) actually looks like when a firm evaluates a typical cloud AI tool. For each tool, the firm needs defensible answers to at least these questions:

  1. Are prompts and uploaded documents used to train the vendor's models, now or under any future terms?
  2. Who at the vendor, and at the vendor's subprocessors, can access stored client data?
  3. How long are inputs and outputs retained, and can the firm compel deletion?
  4. What happens to firm data if the vendor is acquired, breached, or subpoenaed?
  5. Does the vendor agreement permit any secondary use of firm data, however described?
  6. Which clients require notice or informed consent before their information touches the tool?

None of these questions is unanswerable. Enterprise AI vendors publish data processing agreements, and careful firms negotiate them. But the analysis is per-vendor, per-tool, and perpetual, because terms change, subprocessors change, and every new AI feature a vendor ships restarts the review. For a 10 to 75 attorney firm without a dedicated technology counsel, that recurring diligence burden is the real cost of cloud AI, and it is the honest reason many firms have simply opted out.

How private deployment changes the analysis

Now run the same six questions against an AI system deployed privately, in the firm's own environment, on infrastructure the firm controls.

Rule 1.6(c) question Public cloud AI tool Private deployment
Do inputs train outside models? Depends on tier, terms, and settings. Must be verified per tool and re-verified as terms change. No. The model runs in the firm's environment. Client data never reaches a shared training pipeline.
Who can access client data? Vendor personnel and subprocessors, governed by the vendor's contracts, not the firm's. Only firm-authorized users, under the firm's existing access controls and ethical walls.
Retention and deletion Vendor retention schedules. Deletion rights vary by agreement. The firm's own retention policy applies. Nothing exists outside firm systems.
Breach, acquisition, subpoena exposure Firm data sits in a third party's risk envelope. Firm data stays inside the firm's existing risk envelope, already covered by its security program.
Secondary use of data Governed by evolving vendor terms that require ongoing monitoring. None. There is no counterparty with an interest in the data.
Client consent trigger Frequently triggered, since data leaves firm control. Opinion 512 says boilerplate consent is inadequate. Rarely triggered, since information relating to the representation stays within the firm, like any other internal system.

The pattern is consistent: private deployment does not make the ethical duty disappear. It relocates the analysis from a vendor's data practices, which the firm cannot control and must perpetually monitor, to the firm's own security program, which the firm already maintains, documents, and answers for. That is a question firms know how to answer, because it is the same question they answer about their document management system.

Rule 1.6(c) is a reasonable efforts standard. Keeping client data inside the firm is the single most defensible reasonable effort available.

A practical checklist for managing partners

If your firm is evaluating AI adoption this year, the ethics-driven path looks like this:

  1. Inventory current AI exposure. Attorneys are already using consumer AI tools, with or without a policy. NC 2024 FEO 1 makes the firm responsible either way. Find out what is actually in use.
  2. Write the policy around data flow, not tool names. A rule that says "no ChatGPT" ages badly. A rule that says "no client-specific information in tools the firm does not control" tracks the actual ethics guidance.
  3. Classify use cases by data sensitivity. Drafting a marketing email and analyzing a client's deal documents are different Rule 1.6 events. Match the deployment model to the sensitivity tier.
  4. For client-data workloads, require firm-controlled deployment. This is where the reasonable efforts analysis is cleanest and where the consent question largely resolves itself.
  5. Document the diligence. Reasonable efforts is a process standard. The firm that can show its analysis has already satisfied most of it.

The bottom line

The ethics rules were never the obstacle. Rule 1.6(c) asks for reasonable efforts. ABA Formal Opinion 512 supplies the diligence framework. NC 2024 FEO 1 draws the line at publicly available tools and puts responsibility on the firm. Every one of those authorities is compatible with AI adoption, and all three point toward the same conclusion: the firms best positioned to use AI on real client work are the ones that keep the intelligence, and the data it runs on, inside the building.

That is a deployment decision. And unlike the ethics rules, it is entirely within your control. See how private AI for law firms works in practice.

Primary Sources

Frequently asked questions

Does ABA Model Rule 1.6 prohibit lawyers from using AI?
No. Rule 1.6 contains no prohibition on AI. Rule 1.6(c) requires lawyers to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. ABA Formal Opinion 512 confirms lawyers may use generative AI if they fully consider their existing ethical obligations, including competence, confidentiality, communication, and reasonable fees.
What does Rule 1.6(c) require when a law firm uses AI tools?
Rule 1.6(c) requires reasonable efforts, not perfection. Applied to AI, ABA Formal Opinion 512 says lawyers must understand how the tool uses and protects data before client information goes into it: whether inputs train the model, who can access stored prompts, how long data is retained, and whether the vendor's terms permit disclosure. The analysis is fact-specific to each tool and each deployment model.
Do lawyers need client consent to use AI?
It depends on the tool and the information involved. ABA Formal Opinion 512 recommends obtaining a client's informed consent before inputting information relating to the representation into a generative AI tool that learns from or exposes that data, and states that boilerplate consent language in an engagement letter is not sufficient. Tools that do not expose client data to third parties or model training significantly reduce when consent is required.
What does North Carolina's 2024 FEO 1 say about AI?
North Carolina 2024 Formal Ethics Opinion 1, adopted November 2024, permits lawyers to use AI in a law practice subject to existing duties of competence, confidentiality, and supervision. It makes the lawyer responsible for the security of information entered into an AI program and cautions lawyers to avoid inputting client-specific information into publicly available AI resources. It does not prohibit AI use.
How does private AI deployment change the Rule 1.6 analysis?
Private deployment removes the hardest parts of the reasonable efforts analysis. When the AI system runs in the firm's own environment, client data does not leave the firm's control, inputs are not used to train shared models, no third-party vendor holds prompts or outputs, and access follows the firm's existing security controls. The confidentiality analysis shifts from evaluating an outside vendor's data practices to applying the firm's own, which is a question firms already know how to answer.

Mitch Boraski

Co-Founder of Deepvine AI. Deepvine installs private AI knowledge systems for law firms, RIAs, CPA firms, and other knowledge-driven businesses: connected to your systems, backfilled with your history, deployed in your environment, and owned by you.

This article is provided for general informational purposes only and does not constitute legal advice. Ethics rules and formal opinions vary by jurisdiction and are subject to amendment. Firms should consult their own ethics counsel or state bar before adopting any AI tool or policy.

Private AI for Law Firms

Keep the intelligence inside the building.

Deepvine deploys a private AI knowledge system in your firm's environment: your matters, your documents, your institutional memory, answerable in Slack with source-backed citations. Your data never leaves your control.

Bring us one real question about your practice. We will show you where the answer comes from.