The legal profession is adopting AI quickly, and the adoption numbers that circulate are mostly measuring the wrong thing. There is a large and growing difference between individual lawyers using tools for drafting and research, and a firm deploying AI at the matter level — where the system has access to client communications, pleadings, deal documents and privileged strategy.

The first is a productivity decision. The second is an architecture decision with professional-conduct consequences, and it is where the market's real fault line sits.

Why the two are not on a continuum

A lawyer pasting a public clause into a general assistant is making a judgement about one document. A firm connecting a platform to its document management system has made a standing decision about every document, for every client, until someone revisits it.

The professional obligations attach to the second in a way they do not to the first. Model Rule 1.6(c) requires reasonable efforts to prevent unauthorised disclosure, and Comment 18 makes that a balancing test — sensitivity, likelihood of disclosure absent safeguards, cost and difficulty of the safeguards, and their effect on the representation.[1] What is reasonable for one clause is not automatically reasonable for a matter.

The confidentiality question got sharper, not softer

The standard vendor answer to confidentiality is a set of contractual commitments: zero-retention terms, an audited control report, a processing agreement. These are real protections and they are worth negotiating. They are also answers to a different question from the one privilege asks.

In February 2026 the Southern District of New York addressed the point directly. In United States v. Heppner, material generated through a consumer-tier AI assistant was held protected by neither the attorney-client privilege nor the work-product doctrine.[2] Two independent grounds carried the result: the tool's terms permitted the provider to disclose user data and to use prompts for training, so no reasonable expectation of confidentiality survived; and the research had been conducted by the defendant rather than at counsel's direction, which defeated work product on its own.

The court was careful about scope. It said that enterprise products which exclude user data from training and provide contractual confidentiality "might support a different expectation-of-confidentiality analysis" — while cautioning that contractual protection alone does not automatically establish privilege.[3] That is not a clean bill of health for enterprise cloud AI. It is an open question, and firms are the ones carrying it.

What the regulators have actually said

ABA Formal Opinion 512, issued in July 2024, is the anchor document. It does not prohibit cloud AI. It places the burden on the lawyer: understand the tool, protect confidentiality, verify the output, and — where confidential information will be disclosed to a generative tool — obtain the client's informed consent first.[4]

State-level guidance has followed the same shape. The Professional Ethics Committee for the State Bar of Texas addressed lawyers' use of AI in Opinion 705, again emphasising caution about entering confidential information into tools whose data handling the lawyer does not control.[5]

The pattern is consistent, and it is not a prohibition. It is a transfer of responsibility onto the person who cannot delegate it.

Why this decides market structure

Three consequences follow, and none of them depends on a forecast.

  • Procurement scrutiny moves from features to architecture. The questions that stall deals are about where inference runs, how matter boundaries are enforced and who can produce the audit record — and they are asked by risk functions, not practice groups.
  • Informed consent becomes a product requirement. A firm can only obtain it if the vendor's answer about data handling is short enough to repeat to a client.
  • The capability argument for accepting the trade-off has weakened. Open-weight models now handle the extraction, classification and first-draft work that fills most legal workflows, which removes the reason firms tolerated the exposure.

None of that is a claim about any particular vendor's prospects, and we are not in a position to make one. It is a claim about which questions decide purchases — and those questions have moved.

The distinction worth holding onto

Platforms built for the convenience requirements of enterprise software optimise for time-to-value, breadth and frictionless deployment. Platforms built for the confidentiality requirements of legal practice optimise for a boundary that holds, a record that can be produced and a supervision gate that cannot be skipped.

Both are legitimate products. They are answers to different questions, and a firm that buys the first while believing it bought the second will discover the difference at the worst possible moment — in a discovery dispute, in a client's security review, or in a conversation with an insurer.