Last Updated: July 16, 2026
When client data is uploaded into an AI platform, that content can be processed by three categories of outside parties before the requested work product is returned: the model providers that perform the AI analysis, the subprocessors that support the analysis, and the cloud infrastructure that stores and moves the data. Each of these groups is governed by agreements with the AI provider, and thus, their protection measures differ across platforms.
Client Data
User
Processors
Subprocessors
Cloud
Work Product
The free/self-learning versions of AI models widely used by consumers are typically built for general use, rather than submission of sensitive information. In most cases, their privacy policies allow them to train on customer data to improve their model, meaning that prompts and inputs are not confined to the user’s specific chats. For lawyers, this is important to their duties of confidentiality and protecting against disclosure of client data. Several bar associations, as well as the ABA, have warned against using self-training models for processing confidential client information, as doing so raises the risk of unlawful disclosure. Formal Opinion 512, which provides the ABA’s main guidance on AI use, says, “…the self-learning GAI tool may disclose information relating to the representation to persons outside the firm who are using the same GAI tool.” Lawyers are encouraged to use self-learning AI tools with caution, and the ABA requires obtaining a client’s informed consent before inputting information about their representation into them.
01
Client Prompts
Data entered into chats or queries reaches the model directly.
02
Retention & Training
Content is stored and used to refine the model’s future outputs.
03
Access via LLM
Other users may see similar outputs surface in their own sessions.
A second category of AI tools, used primarily by customers that work in industries requiring specific data protection measures and practices around sensitive information (hence the name “enterprise” tools), makes no-training commitments with their users, as well as with the processors and subprocessors that also access the data. The mechanism for ensuring this comes in the form of Zero-Data Retention (ZDR) agreements, which contractually bar the model providers from storing the data, and thus training on it. Under ZDR, the prompt and the response are processed in memory to generate the output and are not stored afterward. Since the prompt and the responses are deleted as soon as the output is generated and are never written to the providers’ storage, there is nothing retained on which a model could be trained. This is often described as a “closed-loop” system: because the data isn’t used to train public models, it essentially stays contained within the firm that submitted it.
01
Client Prompts
Data entered into the enterprise tool the same way as any AI query.
02
Isolated Processing
The prompt is handled in a private session, walled off from the base model.
03
No Retention or Reuse
The session is discarded after the response. No training, no exposure to other users.
If an AI platform ensures Zero-Data Retention with its model providers, and commits to no self-training through its own platform, the only place data is actually stored is within the cloud hosting infrastructure. To ensure security down the chain of data processing, enterprise AI systems also must receive agreements from the hosting service that it will not access or use customer data except as necessary to provide the service requested by the user or to comply with the law. Amazon Web Services (AWS), the most widely used cloud computing service of this kind, encrypts data in transit and at rest and holds the common certifications associated with secure cloud storage. This arrangement is not unusual within the law practice, as lawyers routinely store privileged information in cloud-based email, file-synchronization services like Dropbox and Google Drive, and case management platforms. Most of these systems run on AWS or similar platforms, thus adopting an AI tool that operates under these terms is comparable to the decision a firm makes when it decides to use any cloud-based vendor.
The questions now raised about artificial intelligence closely resemble those raised when cloud computing first became common. Lawyers and bar regulators asked what entrusting client data to a remote, third-party service meant for the duty of confidentiality, and how the technology could be adopted responsibly. In Formal Opinion 498, the ABA addressed virtual practice and cloud storage, drawing on the same guidance (Rules 1.1 and 1.6) as it has now applied to generative AI use. These rules require lawyers to remain "abreast of…relevant technology," and to make "reasonable efforts" to prevent unauthorized disclosure of client information. Under this framework, the ABA permitted the use of cloud management platforms and software systems, provided that the lawyer has carefully vetted the provider and follows appropriate safety protocols.
“If the access to such ‘files is provided through a cloud service, the lawyer should (i) choose a reputable company, and (ii) take reasonable steps to ensure that the confidentiality of client information is preserved…’”
—ABA Formal Opinion 498
Now, secure cloud computing is used by the vast majority of legal practitioners through their case management systems and document storage platforms. AI appears to be similarly positioned to expand into everyday use in legal practice, thus receiving a similar response from the ABA. In Formal Opinion 512, the ABA's long-awaited formal response to AI use in legal practice, the ABA used the same rules of technological competence and client confidentiality (Rules 1.1 and 1.6) to allow AI use under the provision that lawyers must be thorough in their evaluation of an AI vendor's data protection policies. Noting this similarity, the ABA provides the following practical guidance for vetting AI vendors:
“In particular, opinions developed to address cloud computing and outsourcing of legal and nonlegal services suggest that lawyers should: ensure that the [GAI tool] is configured to preserve the confidentiality and security of information, that the obligation is enforceable, and…investigate the [GAI tool’s] reliability, security measures, and policies…”
—ABA Formal Opinion 512
This guidance highlights a consistent principle regarding law and emerging technologies: no matter the third-party provider, lawyers must rigorously assess the policies and practices of any vendor to which they entrust client data. Before adopting a tool, a lawyer should ask what security protections the provider offers, whether it uses enforceable confidentiality agreements, and whether the company has undergone third-party security audits. Gathering this information is how lawyers satisfy not only the duty of technological competence, but also their broader obligation to protect client confidentiality.
Data protection makes up a huge part of the discussion around AI platforms in the legal-tech space and lawyers’ obligations to safeguard client information when using them. Like cloud computing and previous technological advancements affecting the practice of law, AI is likely to become a standard part of client representation and will continue to require lawyers to apply their professional judgment in evaluating the vendors they choose to disclose client data to. A tool should not only ensure that it will not train on this data, but also that its processors, subprocessors, and hosting infrastructure will not train on it. Any conversation about deploying AI at your firm and sharing data with third-party platforms should start there.
How to Contact Us
For questions about this guide or Parley's compliance features, please email us at [email protected]


