The text that applies

Rule 1.6(c): "A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."

The key phrase is "reasonable efforts." The rule does not require a perfect technical solution — it requires a deliberate one. Bar disciplinary bodies assess whether the safeguard taken was commensurate with the sensitivity of the information and the known data practices of the platform. An attorney who submits client names to ChatGPT without any precaution, knowing that ChatGPT processes and logs submissions server-side, has not made reasonable efforts.

ABA Formal Opinion 512 (2023)

The ABA's formal guidance on generative AI was issued in July 2023. Formal Opinion 512 concludes that attorneys may use AI for legal work, but must:

  1. Understand how the AI platform handles submitted data — including whether it is retained, used for training, or accessible to third parties.
  2. Apply confidentiality safeguards before submission — ensuring client information is not among the data transmitted.
  3. Supervise AI-assisted work product — reviewing outputs for accuracy before relying on them.

The Opinion does not prohibit AI. It requires that the attorney understand what happens to the data they submit — and take steps to ensure client confidences are not among that data.

What state bars have added

More than thirty state bars have issued supplementary guidance. The substantive position is consistent with the ABA's: AI use is permissible, but client confidentiality requires a deliberate precaution before any AI submission. California's guidance emphasizes that attorneys must evaluate whether specific AI tools meet their confidentiality obligations before use, not after. Florida and New York have taken similar positions.

What a compliant safeguard looks like

The cleanest safeguard is one that mechanically prevents client information from reaching the AI server at all. On-device redaction — where a tool detects identifying content in the prompt, replaces it with anonymous placeholders on the attorney's machine, and restores real values in the response before the attorney reads it — satisfies Rule 1.6(c) by design.

The client's information never leaves the browser. There is no transmission to prevent; the disclosure simply does not occur. This is what Naosuu does for every ChatGPT, Claude, and Gemini prompt an attorney submits.

Satisfy Rule 1.6 at the technical level

Naosuu ensures client information never reaches AI servers — on-device redaction before every prompt, automatic rehydration in every response. 30-day free trial, no credit card required.

Start free trial