AI and client confidentiality: what rule 9 requires.

Of everything the legal regulators have said about AI, one line does the most work. The December 2024 joint statement states that solicitors cannot safely enter confidential, sensitive or privileged client information into public AI chatbots or copilots. The Law Society of NSW guide goes further on the mechanism: placing client confidential information into a publicly available generative AI system is akin to putting it in the public domain, likely a breach of confidentiality, and clients may lose privilege.

General information only. This guide summarises published regulatory guidance and is not legal advice. Read the primary sources linked throughout, and take professional advice on your firm’s specific position.

Why rule 9 reaches AI tools

Rule 9 of the Australian Solicitors’ Conduct Rules binds a solicitor to keep client information confidential, subject to narrow exceptions. The rule says nothing about technology, and that is the point: disclosure is disclosure whatever the channel. Public AI tools learn from what users enter and may reproduce it, retain prompts on the provider’s infrastructure, and give the provider’s staff and systems access to the content. Each of those is a disclosure beyond the circle of confidence that rule 9 protects.

Public tools versus commercial tools

The guidance distinguishes public tools from commercial ones, and the bar moves rather than disappears. For commercial AI products used with any client information, the joint statement expects solicitors to carefully review contractual terms to ensure the information will be kept secure. The guide’s procurement section spells out what that review covers: how prompts and data are stored, who can access them, whether they are used for training, and where processing happens. An enterprise subscription changes the contract; it does not change the fact that client information is being transmitted to a third party, which is why our privilege guide treats transmission as the load-bearing question.

What careful firms actually do

In practice we see three postures. Some firms prohibit client information in any AI tool, which is safe and forfeits most of the value. Some run commercial tools under negotiated terms, which works in proportion to the diligence behind it and leaves the firm relying on attestations about infrastructure it cannot inspect. Some move the processing inside the practice, so the confidentiality analysis never leaves the building. The regulators do not rank these options; rule 9 simply demands that whichever you choose, you can account for who can access client information.

Where deployment posture fits

An on-premise unit processes client material on hardware inside the firm, so nothing is transmitted to an AI provider and no third party holds prompts or outputs. The remaining confidentiality work is the kind the firm already does for its file server: physical security, network security, and access control. The behavioural obligations, including staff discipline about public tools, remain, and a written firm AI policy is how the regulators expect you to manage them.

Common questions

Can lawyers use ChatGPT with client information?
The regulators' position is that confidential, sensitive or privileged client information cannot safely be entered into public AI chatbots, and the NSW guide describes doing so as akin to putting it in the public domain, with breach of confidentiality and loss of privilege as the likely consequences.
Does an enterprise AI subscription solve the rule 9 problem?
It improves the contractual position, and the guidance expects a careful review of storage, access, training use and processing location before client information is involved. The information is still transmitted to and held by a third party, so the question becomes whether that arrangement maintains confidentiality, rather than whether a disclosure is happening.
Does on-premise AI remove the confidentiality risk?
It removes the transmission: processing happens on hardware inside the practice and no AI provider receives client information. Confidentiality then rests on the firm's own physical and network security, and on staff actually using the internal tool rather than public ones, which is a policy and supervision matter.

See Dominion answering from your own documents.

A demonstration takes 30 minutes, uses no client data, and comes with no obligation.

Book a demo