Legalnaut

AI IN PRACTICE 2026-09-28 6 MIN READ

Should you upload a client's case file to ChatGPT?

What bar regulators on both sides of the Atlantic have said, and the two duties that still apply once the file is uploaded

Regulators in Europe and the US have already addressed this. Confidentiality and responsibility for the output both survive the upload, and a general assistant rarely shows you the page an answer came from.

Regulators have already described this exact situation, and none of them answers it with a flat yes or no. The Solicitors Regulation Authority in England and Wales, in its Risk Outlook report on artificial intelligence (20 November 2023), lists as a particular threat to confidentiality "a staff member using an online AI, such as ChatGPT, to answer a question on a client's case". Bar bodies elsewhere have reached the same place by their own routes. What they set out, in different words, are two duties that still apply once the file has been uploaded: confidentiality, and responsibility for what comes back.

The same two duties, in different rulebooks

Every legal profession has a duty of confidentiality or professional secrecy, and every one holds the lawyer responsible for the work product. The wording, the exceptions and the consequences differ. Three examples show how close the positions are:

  • United States (ABA Formal Opinion 512, 29 July 2024). Under Model Rule 1.6, where a "self-learning" tool could disclose information relating to the representation, the client's informed consent is required before that information goes in, and "merely adding general, boiler-plate provisions to engagement letters" is not enough. State rules and state bar opinions govern in practice, and they vary.
  • England and Wales (SRA Risk Outlook, 20 November 2023). Firms "will need to make sure that their use of it protects confidentiality and legal privilege", and "you will remain responsible and accountable for the outputs from AI you are using".
  • Europe (CCBE Guide on the use of generative AI by lawyers, 2 October 2025). Lawyers "should refrain from entering any personal, confidential or other data related to the client" into a generative AI tool "unless there are appropriate safeguards in place", and should verify the output before it is used in their work where the use case requires.

These are illustrations, not a survey. Civil-law systems often treat professional secrecy as a matter of criminal law as well as conduct rules, which raises the stakes of a careless upload. Check the rules and any published AI guidance of your own bar, law society or regulator before relying on any of the above.

There is also a cautionary story on the second duty. In Ayinde v London Borough of Haringey [2025] EWHC 1383 (Admin) (6 June 2025, paragraph 6), the Divisional Court said freely available tools such as ChatGPT "are not capable of conducting reliable legal research" and may "purport to quote passages from a genuine source that do not appear in that source". That case concerned legal research, not a client's documents. The failure it describes, a confident quotation that is not in the source, is still the one that matters when the source is your own case file.

Confidentiality turns on the terms you accepted

"ChatGPT" covers several products. A free personal account, a paid individual plan and an organisation's contract with a provider can come with different terms on retention, on training and on who at the provider may see the content. Those terms also change. This post does not summarise any provider's current policy, because a summary dated today can be wrong by next quarter. Read the terms and settings attached to the account you would actually use, on the day you use it.

The questions to put to any AI tool before a client's documents go into it are the ones you would put to any outsourced service holding client material:

  1. Where is the material processed and stored, and under what data processing agreement?
  2. Is your content used to train a model, and where is that written down?
  3. How long is it kept, and can you delete it?
  4. Who else in your firm, or at the provider, can see it?
  5. Which sub-processors touch it?
  6. Does your engagement letter, the client's instructions or your bar's rules require the client's consent first?

If an honest answer to any of these is "I don't know", there is a confidentiality question to settle before the choice of tool comes up at all. How your firm resolves it is a matter for your own compliance function and, where needed, the client.

The second problem: an answer you cannot trace

Suppose the terms are acceptable. A general assistant can still give you an answer you cannot take into a hearing, for a structural reason. It answers from whatever it holds in the conversation plus what it learned in training, and it does not have to show you which page a sentence came from. With a thirty-page file that is manageable, because you can check by reading. With a disclosure set of several thousand pages, much of it split across uploads, the check becomes the whole job.

Illustration (not a real matter): you ask when the defendant first knew about the defect. The answer comes back "March 2022, when the site manager emailed the project director". It reads well. But there are four emails from the site manager that month, one attachment is a scan, and the answer names none of them. Before that date can go into a witness statement, someone has to find the email, confirm the wording, and check nothing earlier says otherwise. If the quotation was paraphrased or blended from two documents, you will only find out by reading both.

That is the practical meaning of being responsible for the output, whichever rulebook you work under. The output is only as usable as your ability to trace each factual sentence back to a document and a page. We set out a method for doing that before anything is filed in Check these 5 things before AI text enters a filing.

What to require of a tool that reads the case file

Requirement Why it matters
Every factual sentence names a document and page You can verify it in one click instead of a search
Quotations are checked against the source text An invented quotation is caught before you see it
A failed check is reported, not silently repaired You know which sentences are unsupported
The file stays fixed once imported The page you cited is the page the other side will see
Terms on training and retention are in writing Your confidentiality analysis has something to rest on

To be fair to general assistants: for a handful of documents and a one-off question, or for drafting help that is not about a specific file, they are often the quicker tool, and nothing here says otherwise.

Anchored answers in practice

Legalnaut was built for the second problem. Every answer and every draft names the document, the page and the quotation it relies on, and each one goes through a citation check against the file before you read it: the document exists, the page exists, the quoted words are really there. Anything that fails is reported to you as a failure. Each imported file is fingerprinted with sha256, so the page you cite does not change underneath you. Your material is never used to train any model: Legalnaut does not train on customer data, and the language models it uses run under agreements that prohibit training on your material. On security, the operator holds SOC 2 Type II (A2Z WEB infrastructure). The security page lists where the data sits and the sub-processors that touch it, so you can run the six questions above against it yourself. A side-by-side comparison, including when a general assistant is the better choice, is on the comparison page for uploading a case file to ChatGPT.

This is general information about professional obligations, not legal advice on your own matter or your own bar's rules.

Create your account and ask a question of a real matter where every answer names its document, page and quotation. No card needed.

Legalnaut does this to your own case file: a chronology built from the documents, every finding showing the source it came from. See the plans.