
Artificial intelligence may already be inside your law firm.
Not because your firm launched a major AI initiative.
Not because IT installed a new system.
And not necessarily because management approved it.
An attorney may use an AI tool to summarize a lengthy document. A paralegal may ask AI to help organize information. Someone in administration may use it to rewrite an email, create meeting notes, or analyze a spreadsheet.
The technology is easy to access, which means employees can begin using it long before the firm has established rules for how it should be used.
That creates an important question for every managing partner, COO, office administrator, and IT leader:
When someone at your law firm enters information into an AI tool, do you know where that data is going?
For law firms, that question matters.
Your attorneys and staff regularly handle confidential client information, financial records, personally identifiable information, privileged communications, litigation materials, contracts, and other sensitive data.
AI can create tremendous efficiencies for a law firm.
But using AI safely starts with understanding what happens to the information you give it.
The Short Answer: What Happens to Data Entered Into an AI Tool?
It depends on the AI platform, the account being used, its configuration, and the provider’s terms.
Depending on the service, an AI system may process, store, retain, log, or handle information using third-party infrastructure. Different products and account types can also have very different protections.
That is why law firms should not assume that every AI tool is appropriate for confidential client information.
The State Bar of Texas has specifically addressed this issue.
In 2025, the Professional Ethics Committee for the State Bar of Texas issued Opinion 705, which discusses Texas attorneys’ ethical responsibilities when using generative AI.
Among other issues, the guidance emphasizes protecting client confidentiality, understanding the technology being used, supervising its use, and verifying AI-generated information before relying on it.
The American Bar Association reached similar conclusions in Formal Opinion 512. It identifies several professional responsibilities attorneys should consider when using generative AI, including competence, confidentiality, communication, supervision, candor, and reasonable fees.
In other words:
The question isn’t simply whether your law firm should use AI.
The better question is:
How can your firm use AI without losing control of its information?
The Rise of “Shadow AI” in Law Firms
Many business leaders are familiar with the term Shadow IT.
It happens when employees use technology, applications, cloud services, or devices that the organization hasn’t approved or managed.
AI has created a similar challenge: Shadow AI.
An employee discovers an AI application that makes a task easier and starts using it.
There may be no malicious intent whatsoever.
They’re simply trying to get their work done faster.
The problem is that management and IT may not know:
- Which AI applications are being used
- What information employees are entering
- Whether client information is involved
- How the AI provider stores that information
- Whether conversations are retained
- Whether the tool uses organizational data for model training
- Who has access to the information
- Whether the firm’s existing security controls apply
For a business handling ordinary internal information, those questions matter.
For a law firm handling confidential client information, they become even more important.
“But We’re Only Using AI for Simple Tasks”
That is often how it begins.
Imagine an attorney receives a lengthy document and wants a quick summary.
Instead of spending 30 minutes reading through it, the attorney uploads the document to an AI tool and asks:
“Summarize this document and identify the five most important issues.”
Within seconds, there’s a summary.
That’s incredibly useful.
But another question needs to come first:
Was that document appropriate to upload to that particular AI system?
The technology itself isn’t necessarily the problem.
The problem is using technology without understanding its data practices.
This is similar to the way your firm should evaluate any cloud service that handles sensitive information.
You wouldn’t intentionally upload confidential client files to an unknown file-sharing website simply because it was convenient.
AI should receive the same scrutiny.
What Texas Law Firms Need to Know About AI and Client Confidentiality
The State Bar of Texas’ AI guidance makes this especially relevant for Texas attorneys.
Opinion 705 explains that lawyers using generative AI need to take reasonable precautions to protect confidential client information. Among the considerations are understanding how the technology works, reviewing terms of service, understanding the product’s data-security protections, and training attorneys and staff to use AI appropriately.
The State Bar of Texas also provides an AI Toolkit with resources concerning ethical AI use, evaluating AI vendors, privacy, regulatory considerations, and AI-related workflows.
That makes AI adoption more than a productivity conversation.
It’s also a technology governance and cybersecurity conversation.
Not All AI Accounts Have the Same Data Protections
This distinction can easily get overlooked.
A consumer AI account and an enterprise AI service may look similar to the person typing the prompt, but what happens behind the scenes can be very different.
Microsoft provides a useful example.
For Microsoft Copilot and Copilot Chat operating with enterprise data protection, Microsoft states that prompts and responses are covered by enterprise protections and are not used to train its foundation models. Microsoft also says Copilot respects organizational identity and permission controls, although the specific protections available depend on the subscription and configuration.
That does not mean every AI tool is automatically safe for every type of legal information.
It demonstrates why firms need to understand exactly which version of an AI product employees are using and under what account.
“Are you using Copilot?” isn’t specific enough.
“Which Copilot product are you using, are you signed into the firm’s managed account, what protections apply, and what information are you entering?” is a much better conversation.
7 Questions Your Law Firm Should Be Asking About AI
Before allowing an AI application to handle firm or client information, your leadership and IT team should be able to answer questions like these:
1. Which AI tools are employees currently using?
Don’t assume you know.
Ask attorneys, paralegals, administrators, and other employees what tools they’ve incorporated into their work.
The goal isn’t to punish people for experimenting with AI.
The goal is visibility.
You cannot protect information flowing through technology you don’t know exists.
2. What information is being entered?
There is a significant difference between asking AI:
“Give me five ideas for improving meeting productivity.”
and entering client-specific documents, names, financial information, legal strategies, case details, or confidential communications.
Your firm should define what information can and cannot be entered into AI systems.
3. Does the provider retain prompts or uploaded files?
Read the terms.
Find out what happens after someone clicks Submit.
Does the provider retain prompts? Are uploaded documents stored? For how long? Can administrators control retention?
The answers may differ between consumer and business versions of the same product.
4. Is your data used to train AI models?
Verify this rather than assume it.
The answer can depend on the provider, product, account type, settings, and contractual terms.
5. Who controls the AI account?
Personal accounts can create another layer of risk.
If an employee conducts firm business through a personal AI account, your law firm may have limited visibility into or administrative control over that activity.
Whenever possible, manage business technology through business-controlled identities and accounts.
6. What happens when an employee leaves the firm?
This is an often-overlooked question.
If employees use personal or unmanaged AI accounts for work, what happens to the prompts, files, conversation histories, or custom AI tools they created after they leave?
Your firm’s IT offboarding process should increasingly account for AI alongside email, Microsoft 365, cloud applications, devices, passwords, and remote access.
7. Who is responsible for approving new AI tools?
Someone should be.
Without a defined approval process, every employee effectively becomes their own software procurement department.
That’s not a sustainable cybersecurity strategy.
AI Doesn’t Eliminate Your Existing Security Problems
There is another side of AI security that law firms shouldn’t overlook.
AI can potentially expose weaknesses that already exist.
Consider Microsoft Copilot.
Microsoft says Copilot honors a user’s existing Microsoft 365 permissions and can access organizational content the individual already has permission to view.
That means AI makes good permission management even more important.
Suppose employees have accumulated access to SharePoint sites, documents, Teams environments, or folders they no longer need.
AI doesn’t create that permission problem.
But it can make existing information much easier to find.
This is why law firms considering enterprise AI should review areas such as:
Identity and access management
Who can access what?
Microsoft 365 permissions
Have permissions accumulated over years without being reviewed?
Multifactor authentication
Are accounts properly protected?
Data classification
Does the firm know where its most sensitive information resides?
Employee onboarding and offboarding
Is access granted and removed systematically?
Device security
Are the devices accessing firm information properly managed and protected?
Backup and recovery
Can critical information be recovered following ransomware, accidental deletion, or another disruption?
AI governance shouldn’t exist separately from cybersecurity.
It should become part of it.
Blocking AI Isn’t the Same as Managing AI
Some firms may respond to AI risk by saying:
“Then nobody here should use AI.”
That may sound simple.
But prohibition doesn’t necessarily provide visibility.
Employees who see genuine productivity benefits may find unofficial ways to use the technology.
A stronger approach is to establish clear boundaries.
Employees should know:
These AI tools are approved.
These tools are not approved.
This information can be entered.
This information cannot.
These accounts must be used for business purposes.
These security controls are required.
AI-generated work must be reviewed by a qualified person.
That turns AI from an uncontrolled experiment into a managed business technology.
Your AI Policy and Your IT Environment Need to Work Together
A written AI policy is important, but policy alone isn’t enough.
Imagine your policy says employees may only use approved business AI accounts.
Great.
Can your organization identify employees using unauthorized applications?
Can administrators control access to approved platforms?
Can you manage identities and permissions?
Can you remove access when someone leaves?
Can you investigate what happened if sensitive information is accidentally shared?
This is where the conversation moves from AI policy to AI governance.
Policy establishes expectations.
Technology helps enforce them.
Training helps employees understand them.
Monitoring helps identify problems.
Leadership makes sure all four are working together.
A Practical AI Security Checklist for North Texas Law Firms
If your law firm is already using AI, start here:
- Inventory the AI tools you currently use.
- Identify what information employees are entering into them.
- Separate approved business AI tools from consumer or unapproved tools.
- Review vendor privacy, retention, security, and data-use terms.
- Review Microsoft 365 and cloud permissions before connecting AI to organizational information.
- Establish rules governing confidential and client information.
- Train attorneys and staff on appropriate AI use.
- Include AI applications in employee onboarding and offboarding procedures.
- Create a process for reviewing new AI applications before employees adopt them.
- Review the policy regularly because AI products and their terms change quickly.
Your attorney or compliance adviser should address the legal and ethical requirements that apply to your practice.
Your IT provider can help address the technology, cybersecurity, identity, permissions, access, and data-governance side of the equation.
Frequently Asked Questions About AI Security for Law Firms
Can attorneys use ChatGPT or other generative AI tools?
Attorneys can use generative AI in legal work, but they must consider their professional obligations, including competence and client confidentiality. The ABA’s Formal Opinion 512 and Texas Opinion 705 both address attorneys’ responsibilities when using generative AI.
The more useful question for a firm is not simply, “Can we use AI?”
It’s:
Which AI tools can we use, for what purposes, with what information, and under what controls?
Should lawyers put confidential client information into AI?
Law firms should not assume an AI system is appropriate for confidential information simply because it is widely used. Texas ethics guidance emphasizes understanding the technology and taking reasonable precautions to protect client information. Firms should evaluate the specific AI service, contractual terms, security controls, and applicable professional obligations before confidential information is provided to it.
Does Microsoft Copilot use law firm data to train its AI models?
For Microsoft Copilot and Copilot Chat covered by Microsoft’s enterprise data protection, Microsoft states that prompts, responses, and organizational data accessed through Microsoft Graph are not used to train foundation models. Specific protections and controls depend on the applicable product and subscription.
What is Shadow AI?
Shadow AI is the use of AI applications within an organization without appropriate organizational visibility, approval, or governance. It can occur when employees independently adopt AI tools to perform work faster.
For law firms, the concern isn't merely which applications employees use. It is whether firm or client information is being entered into systems that haven’t been properly evaluated.
Does our law firm need an AI acceptable-use policy?
A written AI policy can establish which tools are approved, what information may be entered, who can authorize new tools, how AI-generated material should be reviewed, and what employees should do if sensitive information is accidentally exposed.
For Texas attorneys, the State Bar of Texas provides an AI Toolkit that includes resources concerning ethical considerations, vendor evaluation, privacy, and responsible AI use.
Before Your Law Firm Asks “How Can We Use More AI?” Ask This First
AI isn’t going away.
And that can be good news.
Used appropriately, these tools can help attorneys and staff work more efficiently, analyze information faster, reduce repetitive tasks, and improve workflows.
But speed without governance can create risk.
Before your North Texas law firm adds another AI platform, ask:
What AI are we already using?
What information are we giving it?
Who controls it?
What happens to our data after we click Submit?
If leadership can’t confidently answer those questions, that is a good place to begin.
Know Where Your Data Is Going
Datatex Computer Services has been helping North Texas businesses manage their technology since 1975.
As AI becomes part of everyday business operations, cybersecurity isn’t just about protecting servers, laptops, and email anymore. It’s also about understanding how new tools interact with your users, identities, applications, permissions, and data.
Not sure what AI tools are touching your firm’s data?
Datatex can help you review the technology and cybersecurity side of your environment, identify potential gaps, and build a more controlled foundation for adopting AI.
Schedule a no-cost technology and security assessment with Datatex Computer Services here. Or give us a call at 972-224-0999.
This article provides general technology and cybersecurity information and is not legal or ethics advice. Law firms should consult appropriate legal or professional ethics resources regarding their specific obligations.
