Answers · CMMC & AI compliance
Can law firms use ChatGPT?
Yes — law firms can use ChatGPT, but only with safeguards that keep client confidences out of it. State bar ethics opinions issued in 2024–2025 (including New York, California, and Florida) permit generative AI use while holding lawyers to their existing duties of confidentiality, competence, and supervision. Pasting privileged communications or client-identifying facts into a consumer chatbot risks both an ethics violation and an argument that privilege was waived. The compliant pattern: scan and block confidential content locally before any prompt leaves the firm's network.
What the bar opinions actually require
No major bar has banned generative AI. Instead, the 2024–2025 opinions converge on the same duties: understand the technology (competence), protect client information (confidentiality), supervise its output (supervision), and in some circumstances obtain informed consent before inputting client data into tools that may retain or train on it.
The confidentiality duty is the operative constraint. A consumer chatbot that retains conversations is a third party — disclosing client confidences to it without safeguards is the same category of problem as discussing a case in a crowded elevator, except logged.
The privilege problem is sharper than the ethics problem
Attorney-client privilege protects communications kept confidential. Opposing counsel will argue that routing privileged material through a retaining, non-confidential AI service was a voluntary disclosure that waived privilege. Whether that argument wins is unsettled — which is exactly why firms should never have to litigate it about their own conduct.
The compliant setup for a 50–500 attorney firm
- Publish an AI use policy: which tools are approved, what content is prohibited (client identities, privileged communications, deal terms, PII).
- Route firm AI traffic through a locally hosted scanning proxy that detects client-matter identifiers, privileged-material markers, and PII in prompts — and blocks them before transmission. Scanning happens inside the firm's network; no third party receives the content in order to check it.
- Keep the tamper-evident log. It is your evidence of supervision — for the ethics inquiry you hope never comes, and for clients (increasingly common in outside counsel guidelines) who ask how you police AI use.
Frequently asked questions
Use AI without leaking CUI
HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.