AI and Attorney–Client Privilege before anyone is a client
The duty does not start at the engagement letter. It starts at the first message from a stranger who is thinking about hiring you, and it survives your decision not to take the case. That is the fact that makes automated intake a procurement question and not just a script question.
Last reviewed 31 July 2026 · Rule text and opinion language checked against the linked sources on the date shown.
Does the duty apply before someone is a client?
Yes. Under ABA Model Rule 1.18, a person who consults a lawyer about the possibility of forming a client-lawyer relationship is a prospective client, and a lawyer who has learned information from that person shall not use or reveal it, subject to the same limits that apply to a former client. Intake sits inside that duty from the first message.
One distinction worth keeping straight, because the two get used interchangeably and they are not the same. Attorney-client privilege is an evidentiary doctrine, defined by state and federal law, that governs what can be compelled in a proceeding. The ethical duty of confidentiality is broader, applies regardless of source, and is what Rule 1.18 and Rule 1.6 address.1
For intake purposes the broader duty is the one that binds first and binds harder, and it is the one that governs what a vendor may be allowed to see.
Does routing intake through software break confidentiality?
Not by itself. What it changes is who has to be trusted. Every vendor in the path is a place the information can travel: the messaging provider, the automation layer, the model provider, any analytics tool watching the same page. Rule 1.6(c) requires reasonable efforts to prevent unauthorized access, and reasonable is measured by what the firm actually checked.
Rule 1.6(a) is the general prohibition: a lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent, disclosure is impliedly authorized to carry out the representation, or it is permitted by paragraph (b). Paragraph (c) adds the security duty.2
Which means the question to ask a vendor is not “is this secure?” Every vendor answers yes. The question is what you can put in a file to show what you checked.
What did ABA Formal Opinion 512 say about self-learning tools?
It singled them out. Formal Opinion 512, issued 29 July 2024, warns that self-learning tools “by [their] very nature raise the risk that information relating to one client’s representation may be disclosed improperly, even if the tool is used exclusively by lawyers at the same firm”, and calls for informed client consent before entering representation information into them.
The opinion also holds that generic consent is not enough: informed consent requires telling the client what specific information is disclosed, to what, and what could go wrong.345
Applied to intake, that produces a simple procurement rule. The intake path should not include anything that learns from what it is told. Ask the question in writing, and ask specifically about the model provider rather than only about the vendor in front of you.
What should be in the vendor contract?
Six clauses, and their absence tells you as much as their presence. No training on your data, a named data location, a stated retention period, a current list of subprocessors, a breach notification window in hours rather than best efforts, and deletion on termination that you can verify.
| Clause | What good looks like |
|---|---|
| Training on your data | Prohibited outright, including by any model provider downstream |
| Data location | Named country or region, not “globally distributed” |
| Retention | A number of days, set by you, not by the vendor default |
| Subprocessors | A current list, with notice before it changes |
| Breach notice | A stated number of hours |
| Deletion on termination | Verifiable, with written confirmation |
None of this is exotic. All of it is standard in vendor contracts outside legal, and the reason it is worth insisting on here is Rule 5.3: the supervision duty does not transfer to the vendor no matter what the contract says.6
What should the intake script avoid collecting?
Everything the firm does not need in order to route the matter. No social security number, no date of birth, no insurance policy number, no medical records and no photographs of injuries in an automated first exchange. Collect the name, the callback number, the language, what happened and roughly when, then let the human collect the rest.
This is the cheapest control available, and firms consistently skip it because a longer intake form feels more thorough. It is not more thorough. It moves sensitive material into a system before anyone at the firm has decided the matter is one you want.
Every field you do not collect is a field that cannot leak, cannot be retained past its usefulness, and cannot appear in a subprocessor’s logs. Minimising the script is a security measure, not a convenience one.
What should a firm do this week?
Write down every system that currently touches an intake message, before evaluating any new one. Most firms find between four and seven, and most find at least one nobody remembers approving. That list is the actual scope of the confidentiality question, and it exists whether or not the firm ever adds automation.
- List the path a web form takes from submission to a human reading it.
- List the path a missed call takes, including any answering service.
- Note who at each vendor can read the content, not just who can access the account.
- Note what is retained and for how long at each hop.
- Name one person responsible for keeping that list current.
Doing that exercise before shopping changes what you shop for. It usually also removes one or two tools that were sitting in the path for no current reason.
Intake that your firm can actually supervise
Versa replies to inbound web forms and missed calls only, with a target of under 20 seconds, in English and Spanish, on a script your firm writes and approves before it goes live. Your team sees every conversation, can take over at any point, and can switch it off instantly.
Watch the live demoSee pricingSources
Every rule number, figure and date above is tied to one of these. The numbered markers in the text link straight to the entry they came from.
- Model ruleAmerican Bar Association, Model Rule 1.18, “Duties to Prospective Client”americanbar.org · rule text
- Model ruleAmerican Bar Association, Model Rule 1.6, “Confidentiality of Information”americanbar.org · rule text
- Ethics opinionAmerican Bar Association, “ABA issues first ethics guidance on a lawyer’s use of AI tools” — Formal Opinion 512, issued 29 July 2024americanbar.org · announcement
- Full textABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, “Generative Artificial Intelligence Tools”PDF · full opinion
- AnalysisNational Conference of Bar Examiners, The Bar Examiner, “Generative Artificial Intelligence Tools: ABA Formal Opinion 512 Provides Needed Guidance”, Fall 2024ncbex.org · analysis
- Model ruleAmerican Bar Association, Model Rule 5.3, “Responsibilities Regarding Nonlawyer Assistance”americanbar.org · rule text