Back to blog

Private AI for Lawyers: How to Keep Client Data Safe (2026)

Author: TheLawGPT Team|12 min|September 29, 2026
Private AI for Lawyers: How to Keep Client Data Safe (2026)
On this page

Every lawyer who uses AI eventually asks the same question: where does my client's data go when I hit enter? Private AI for lawyers is the answer vendors give, but "private" has become a marketing word. Some tools mean they never train on your data. Some mean nothing is stored at all. Some mean the model runs on a server nobody else touches. Those are very different promises.

In 2026 the difference matters more than ever. Two federal rulings this year, United States v. Heppner and Morgan v. V2X, made it clear that the AI tool you choose can affect privilege, work product, and your obligations under a protective order. This guide explains what "private AI" actually means, what the courts and the ABA expect, and gives you a checklist for vetting any legal AI tool before client data touches it.

What "Private AI for Lawyers" Actually Means

Vendors use "private" to describe at least five different things. When you evaluate a tool, figure out which of these it actually offers:

LevelWhat it meansWho typically offers it
No training on your dataYour prompts and documents are not used to train or improve AI modelsMost business and legal AI tools; consumer tools only if you opt out
Contractual no-training commitmentThe no-training promise is in a signed agreement or DPA, not just a settings toggleBusiness/enterprise tiers, legal AI vendors
Limited or zero data retention (ZDR)Inputs are processed and discarded, or deleted after a short windowEnterprise API tiers, some legal AI vendors
Tenant isolationYour data is logically separated from other customers'Most reputable SaaS
Private deploymentA dedicated model instance, or the model runs on your own infrastructureEnterprise contracts, self-hosted open-source models

A tool can honestly call itself "private" at the first level and still keep your documents on its servers indefinitely. Ask which level a vendor means before you rely on the word.

Why Private AI Matters More in 2026

ABA Formal Opinion 512

The ABA's Formal Opinion 512 (July 2024) is still the baseline. Under Model Rules 1.1 (competence) and 1.6 (confidentiality), lawyers must understand how a generative AI tool handles client information. If a tool is "self-learning", meaning inputs can be used to train it, the opinion says lawyers generally need the client's informed consent before putting confidential information into it. Boilerplate in an engagement letter is not enough. We break the opinion down in our guide to ABA Formal Opinion 512 and legal AI ethics.

United States v. Heppner (S.D.N.Y. 2026)

In February 2026, Judge Rakoff ruled in United States v. Heppner that a criminal defendant's exchanges with a consumer AI chatbot were not protected by attorney-client privilege or work product. The court reasoned that the AI is not a lawyer, and that sharing information with a third-party platform whose privacy policy allows disclosure is like sharing it with any other third party. The defendant had used the tool on his own, without direction from counsel, which mattered to the result.

The lesson for lawyers: consumer AI conversations can be treated as disclosures to a third party. We covered the discovery side of this in are ChatGPT conversations discoverable?.

Morgan v. V2X (D. Colo. 2026)

In March 2026, a magistrate judge in Morgan v. V2X, Inc. amended a protective order so that parties could not upload confidential discovery material to AI tools unless the provider was contractually barred from training on it. The court also held that a pro se litigant's use of AI can be protected work product, but that the name of the AI tool used on confidential material had to be disclosed.

It was one of the first times a court effectively sorted AI tools into "acceptable" and "not acceptable" for confidential material based on their data terms. Expect more protective orders to include similar language.

Here is how the main categories compare on the questions that matter for confidentiality, as of September 2026. Always check the current terms of the specific plan you use.

QuestionConsumer chatbots (free/personal plans)Business/enterprise AI plansPurpose-built legal AI
Trains on your inputs by default?Often yes, unless you opt outNo, by defaultShould be no. Verify
No-training promise in a contract?No, it's a settings toggleYes, in business terms/DPAUsually yes. Ask for the DPA
Zero or limited retention available?RarelyOn qualifying enterprise/API termsVaries by vendor
Data Processing Agreement (DPA)?NoYesShould be yes
Published subprocessor list?Rarely relevantYesShould be yes
Built for legal workflows?NoNoYes

The key distinction the courts are now drawing is between a setting and a commitment. A consumer opt-out toggle can change with a policy update. A contractual no-training clause cannot, at least not without notice.

For a deeper look at the consumer side, see is it safe to upload legal documents to ChatGPT?.

The 10-Point Private AI Checklist for Lawyers

Use this before you put any client information into an AI tool. If a vendor can't answer a question in writing, treat the answer as "no".

  • Does the tool train on my inputs? You want a clear "no", not "not by default".
  • Is that commitment in a contract? Ask for the terms of service section or DPA that says so.
  • How long are prompts and documents retained? Look for a specific number of days, or zero retention.
  • Can I delete my data, and does deletion cover backups and logs?
  • Who are the subprocessors? Which AI model providers, hosting providers, and analytics tools see your data, and what exactly do they see?
  • Do the underlying model providers train on the data? Legal AI tools usually call models from larger AI companies. The vendor's API terms with those providers matter.
  • Is data encrypted in transit and at rest? TLS 1.2+ in transit and AES-256 at rest are the norm.
  • Is my data isolated from other customers?
  • What certifications does the vendor hold, or is working toward? SOC 2 Type II and ISO 27001 are the common ones. "Aligned with" and "certified" are not the same thing.
  • Would this tool satisfy a Morgan v. V2X-style protective order? If the provider is not contractually barred from training on your inputs, the answer is probably no.

How to Use AI Privately Without Blowing Privilege

Even with a good tool, how you use it matters.

Minimize what you share

Strip names, account numbers, and identifying details when they are not needed for the task. A clause analysis rarely needs the counterparty's name. Many legal AI tools anonymize some context automatically, but do not rely on that alone.

Direct the client's AI use

Heppner turned partly on the fact that the defendant used AI on his own. If clients are going to use AI to organize facts for you, tell them which tool, and document that the work is at counsel's direction. It won't guarantee protection, but it is a better position than the one in Heppner.

If a tool could use inputs for training, or if you are unsure, get the client's informed consent under ABA Opinion 512. For sensitive matters, it is simpler to use a tool that does not train on inputs.

Check your protective orders

Before uploading discovery material to any AI tool, read the protective order. After Morgan v. V2X, more orders explicitly restrict AI use, and some require disclosure of the tool.

Keep an audit trail

Know which tool you used, on which matter, for what. If a court or client asks, you should be able to answer.

Private AI Options for Law Firms in 2026

There is no single "most private" tool. The right choice depends on your firm size, budget, and risk tolerance.

OptionPrivacy levelCostEffortBest for
Self-hosted open-source modelHighest. Data never leaves your infrastructureHardware + IT staffHighLarge firms with IT teams
Enterprise AI plan with ZDRHigh. Contractual no-training, limited retentionEnterprise pricingMediumFirms with procurement and IT support
Purpose-built legal AIContractual no-training, legal workflowsLow to enterpriseLowSolo lawyers and small to mid-size firms
Consumer chatbot with opt-outLow. Settings-based, not contractualFree to lowLowNon-confidential tasks only

Self-hosting gives the most control, but it is out of reach for most small firms. You need hardware, security staff, and the expertise to keep open-source models current and accurate. For most solo lawyers and small firms, a purpose-built legal AI tool with contractual data terms is the practical middle ground.

How TheLawGPT Handles Your Data

We want to be specific here, because vague privacy claims are the problem this article is about. As of September 2026, here is what TheLawGPT does and does not do, as listed on our Trust & Security page:

In place today:

  • No AI training on your data. Queries and documents are never used to train or fine-tune AI models.
  • Query anonymization. Personally identifying context is stripped before queries are sent to AI model providers.
  • Encryption. AES-256 at rest and TLS 1.3 in transit.
  • Tenant isolation. Each account's data is logically isolated.
  • Deletion on request. You can request full deletion of your data.
  • Published subprocessors. We list every AI model provider and infrastructure vendor we use, and what data each receives.
  • DPA available. You can request a Data Processing Agreement from [email protected].
  • Breach notification within 72 hours of a confirmed breach.

Not yet available:

  • SOC 2 Type II is in progress, not complete.
  • Dedicated private AI deployment and SSO are not currently offered.

If your matter requires a dedicated deployment or a completed SOC 2 report, TheLawGPT is not the right fit for that matter yet, and we would rather you know that up front. For everyday confidential work like reviewing contracts, drafting letters, and researching legal questions, it gives solo lawyers and small firms contractual no-training commitments without enterprise pricing. Plans start at $19.99 per month, with a free tier.

See the details for yourself. Review our Trust & Security page, then try TheLawGPT free. No credit card required.

Frequently Asked Questions

What is private AI for lawyers?

Private AI for lawyers is an AI tool that keeps client information confidential. At a minimum, it does not train on your inputs. Stronger versions add contractual no-training commitments, limited or zero data retention, tenant isolation, or a dedicated model deployment. The term is used loosely, so ask vendors exactly which protections they provide.

Is ChatGPT private enough for client information?

Consumer ChatGPT plans can use your inputs for training unless you turn it off, and that opt-out is a setting rather than a contractual commitment. Business and enterprise plans do not train on your data by default and offer stronger terms. After Morgan v. V2X, a consumer plan may not satisfy a protective order that requires the provider to be contractually barred from training. Our ChatGPT for lawyers guide covers the broader limits.

Does using AI waive attorney-client privilege?

It can. In United States v. Heppner (S.D.N.Y. 2026), a defendant's exchanges with a consumer AI chatbot were held not privileged, partly because sharing information with a third-party platform was treated like disclosure to a third party. The risk is lower when counsel directs the AI use and the tool has contractual confidentiality terms, but the law is still developing.

What is zero data retention (ZDR)?

Zero data retention means the AI provider processes your input to generate a response and then discards it, without storing it. It is usually available on enterprise or API terms, not consumer plans. ZDR is stronger than a no-training promise, because a tool can promise not to train on data while still storing it.

Under ABA Formal Opinion 512, you generally need informed client consent before putting confidential information into a self-learning AI tool that may use inputs for training. If the tool does not train on inputs and has appropriate confidentiality protections, consent may not be required for routine use. Check your state bar's guidance too, since several states have issued their own opinions.

Can I upload discovery documents to an AI tool?

Only if your protective order allows it. After Morgan v. V2X, some courts require that the AI provider be contractually barred from using the data for training, and may require you to disclose which tool you used. Read the order first.

What is the most private AI for law firms?

A self-hosted model on your own infrastructure is the most private option, but it requires significant IT resources. For most firms, the practical choice is a legal AI tool or enterprise AI plan with a contractual no-training commitment, a DPA, encryption, and clear retention terms.

The Bottom Line

"Private AI" is not one feature. It is a set of commitments about training, retention, access, and contracts. In 2026, courts have started treating those commitments as the line between acceptable and unacceptable AI use with confidential material.

Before any client data goes into an AI tool, get the vendor's answers to the checklist above in writing. Choose a tool whose privacy is a contract, not a toggle. And be honest with clients about how you use AI in their matters.

This article is for informational purposes only and does not constitute legal advice. Rules on AI use and confidentiality vary by jurisdiction. Consult your state bar's guidance and applicable court orders.