How Lawyers Can Leverage AI Without Ending Up on the Wrong Side of the Courtroom: What Information Is Safe to Include in AI Prompts

August 20, 2026
Contributors
Share

Artificial intelligence, or AI, has officially arrived in courtrooms and law firms across the United States. The result is that the legal community has increasingly been exposed to fabricated court cases, parties, legal arguments, and hallucinations. On the other hand, the legal community is becoming more effective in some respects due to AI’s ability to expedite the process of finding court cases, point out weaknesses in arguments, and review and answer questions about contracts. In this new era of AI, lawyers in particular must be cautious not to over-rely on AI. This is because attorneys swear an oath that states that among other things, they will uphold their ethical duties, which include their duty of confidentiality. This blog post will outline what data to avoid putting into large language models and what information is generally safe to put into them.

Ethics and ABA’s Formal Opinion 512 

By understanding the limitations of large language models, the legal community can properly uphold their professional duties of understanding the technologies used to provide legal services, while also leveraging AI as a tool alongside their profession and not a replacement for their profession. While once merely optional, cybersecurity is now a requirement in the age of AI to prevent cybersecurity attacks and best secure all data. 

The American Bar Association’s (ABA) Formal Opinion 512 mandates that lawyers adhere to ethical standards when using generative AI.1 These ethical standards include keeping client information confidential regardless of what the source is unless given informed consent from the client, communicating with the client about all the means by which the attorney will achieve the client’s goals, and providing competent representation to the client by understanding the technologies used to provide legal services. While many individuals in the legal community regularly use AI, whether that be for analyzing contracts, researching, or other various usages, individuals must be cautious with what they share with AI because AI often trains on sensitive data that users provide to it, including healthcare, biometric, and financial information.2

Besides training on sensitive data, large language models can correctly infer sensitive data, even if it was not given this data, by grouping together information from different sources.3 Naveen Balakrishnan, managing director at TD Securities, says, “Attackers now have access to incredible tools that allow them to search your public data, your personal information, and do very personalized deep phishing tactics”.4 Due to these great concerns, below are some guidelines on what data the legal community should avoid putting into large language models and what is generally safe to put into them.

The AI Prompt Checklist: What’s Safe vs. What’s Risky?

Avoid putting this information into large language models:

  • Medical Records and Information
  • Privileged Legal Documents
  • Personally Identifiable Information: This includes Social Security numbers, driver’s license numbers, or passport details.
  • Contact Information: This includes phone numbers, addresses, and email addresses. 
  • Passwords, Login Credentials, or Secure URLs
  • Documents Subject to Protection Orders
  • Children’s Personal Information 
  • Business Plans and Strategies 
  • Financial Information
  • Intellectual Property

Generally safe information to put into large language models:

  • Brainstorming Ideas
  • Public Knowledge
  • Fictional Stories
  • General Questions
  • Grammar Checks
  • Organizing Research

Utilizing Cybersecurity to Protect Against AI

If you're ever in doubt about the type of information you can put into a large language model, err on the side of caution and assume nothing is safe. Since large language models store large amounts of information, strong data protection practices are key to preventing cybersecurity attacks that target this information. To avoid personal data being leaked, some solutions include having strong controls such as multi-factor authentication, automatic backups, encryption, training staff on recognizing AI-generated phishing, and complying with all privacy and cybersecurity laws. Questioning suspicious links, having strong passwords, and downloading updates are all grouped in what the CISA calls, “cyber hygiene”.5 Cyber hygiene refers to the regular steps that users can take to protect their data from cybersecurity attacks.6 Essentially, it is the personal hygiene for data. 

the ultimate goal of utilizing large language models in the legal community is to expedite the process of legal services, which can then lower the cost spent on these services for clients. However, what attorneys can’t do is prioritize speed and convenience over their ethical duties to their clients. To strike the perfect balance between efficiency and ethics, attorneys should set restrictions on what data they put into these large language models. Further, through security measures such as multi-factor authentication, attorneys can protect their clients’ data from exposure to cybersecurity attacks. 

References

  1. American Bar Association. (2024). ABA issues first ethics guidance on use of Gen AI Tools. ABA. https://www.americanbar.org/advocacy/governmental_legislative_work/publications/washingtonletter/august-24-wl/ai-ethics-guidance-0824wl/
  2. Gomstyn, A., & Jonker, A. (2024, September). Exploring privacy issues in the age of AI | IBM. IBM. https://www.ibm.com/think/insights/ai-privacy
  3. NIST. (2024). NIST trustworthy and responsible AI NIST AI 600-1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
  4. Short, L. (2025, July 12). AI and the Future of Cybersecurity. Harvard Extension School. https://extension.harvard.edu/blog/ai-and-the-future-of-cybersecurity/
  5. Cybersecurity best practices | cybersecurity and infrastructure security agency Cisa. (n.d.). https://www.cisa.gov/topics/cybersecurity-best-practices.
  6. Cyber Hygiene: Overview & Best Practices. Tenable®. (2026, January 27). https://www.tenable.com/cybersecurity-guide/learn/what-is-cyber-hygiene
Subscribe to our newsletter
By clicking Subscribe, you're confirming that you agree with our Terms of Service.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.