Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

AI and Law5 min read

Generative AI and lawyers' professional secrecy: what you need to know

Lawyers: use generative AI without breaching professional secrecy. Legal framework (1971 Act, GDPR, AI Act), risks, checklists, key clauses and practical action plan.

Executive summary

Generative AI is now an essential productivity tool for law firms. But professional secrecy, a pillar of the defence of rights, prohibits uncontrolled exposure of information entrusted to a lawyer. As of 15 February 2026, requirements converge: systematic anonymisation/pseudonymisation, France/EU hosting, prohibition of unsecured open tools, constant human oversight and documented use. This operational guide brings together the French and European legal framework, practical risks and a firm implementation plan.

Lawyers' professional secrecy generally covers all client confidences, advice and correspondence, notably under Article 66-5 of the Act of 31 December 1971 (reference available on Legifrance). Breach is a criminal offence under Article 226-13 of the Criminal Code (Legifrance). The principles are explained to the public and litigants on Justice.fr.

The direct consequence for generative AI: no protected data should be entered into a system that could reuse, expose, transfer it outside the EU or train on it, unless contractual, technical and organisational safeguards provide protection equivalent to professional secrecy.

2) Generative AI in a law firm: real benefits, major risks

Benefits (assistance tool, never decision-maker)

  • Faster documentary research and preliminary source assessment.
  • Preliminary drafts of legal instruments, letters and briefing notes, with systematic human validation.
  • Organising voluminous files and generating argument outlines.

These uses are promoted as efficiency tools by public guides for small businesses and professions, such as FranceNum, subject to strict human control. For lawyers, the “assistance, never decision-making” rule is also highlighted in specialist analyses (DDG).

Main risks to secrecy

  • Accidental leaks (logs, telemetry, publisher support) and reuse of prompts/outputs for training.
  • Transfers outside the EU and subprocessor access without sufficient segregation.
  • Hallucinations, bias, conflicts of interest (non-specialist models), incomplete traceability.

The CNIL warns of AI-related data protection risks and recalls GDPR duties (minimisation, security, information). The CCBE guide (2025) recommends anonymisation/pseudonymisation and advises against uncontrolled open tools for confidential information.

3) European framework: GDPR and AI Act

GDPR: lawful bases, DPIAs and security

  • Appropriate lawful basis and client information about AI use when personal data is processed (GDPR Article 13/14).
  • Data protection impact assessment (DPIA) where processing presents high risk (see guidelines from the CNIL).
  • Enhanced security measures: encryption, logging, access management, segregated environments.

AI Act (EU): transparency and model control

The AI Act introduces graduated obligations by system category, with enhanced transparency for general-purpose AI models (GPAI) and risk management for sensitive uses. Consult the text on EUR-Lex and anticipate phased application in 2025-2026.

4) Prohibitions and red lines to preserve secrecy

  • Never enter client-identifying details, litigation strategy, non-public draft instruments or procedural documents into an unsecured tool.
  • Avoid any non-EU or consumer platform that retrains on prompts/outputs by default, unless written, verified evidence proves otherwise.
  • Require France/EU hosting, compartmentalisation and a guarantee against data reuse.

These red lines arise from converging good practices published by the CNIL, public compliance portals (Service Public Pro) and European professional-body recommendations (CCBE).

5) What is “secure and sovereign AI” for a law firm?

  • France/EU hosting, encrypted data at rest and in transit, controlled keys.
  • Strict client/file segregation, no retraining on your data (contractual “no training”), auditable logs.
  • Listed and located subprocessors, data processing agreements (DPAs) and compliant transfer clauses.
  • On-premise or sovereign cloud option, regular penetration tests, incident response plan.
  • Configurable privacy settings (global opt-out), controlled deletion and retention.

Check these points in the publisher's contractual and technical documents and retain an audit trail. Security and governance requirements align with practices recommended by the CNIL and AI Act principles (EUR-Lex).

6) Step-by-step implementation in the firm

  1. Map use cases: research, summaries, drafting, without autonomous decisions.
  2. Classify data: public, internal, confidential/secret; define what must never enter a prompt.
  3. Choose a sovereign tool: EU hosting, no training, DPA, audits. Request written evidence.
  4. Configure privacy: disable non-essential telemetry, enable encryption and workspace isolation.
  5. Pseudonymise systematically: remove names, dates, places, file references; use placeholders.
  6. Conduct a DPIA for high risk: assess purposes, risks, measures (see CNIL).
  7. Inform the client of AI use where applicable and document the GDPR lawful basis.
  8. Validate 100% of outputs through human review: check sources, legal accuracy, bias.
  9. Train the team: secure prompt practices, identifier management, escalation procedures.
  10. Governance: appoint an AI lead/DPO, log, test periodically, review policy.

Need contractual structure and rapid compliance? Explore AI and law resources and Discover the Initial journey.

7) Key clauses to include (clients and AI suppliers)

With the AI publisher

  • Professional secrecy and enhanced confidentiality, enforceable against subprocessors.
  • No reuse for training; no marketing data mining.
  • EU location, list of subprocessors, no transfers outside the EU without safeguards.
  • Logging, exit arrangements, deletion on request, incident notification within 72h.
  • Audit, penalties and termination for breach.

With the client

  • Information about AI as an assistance tool and systematic human validation.
  • Prohibit entering documents or identifying details into AI without consent/appropriate measures.
  • GDPR measures, security and liability; arrangements for sharing pseudonymised data.

Refer to official legislation to coordinate these clauses with current French law (see Legifrance) and public recommendations (Service Public Pro — business guidance).

8) Quick practical examples

Case-law note

Objective: obtain a structured outline. Method: provide only public references (anonymised judgments), never case facts. Verify each cited reference.

Preliminary email draft to another lawyer

Objective: improve a generic message's clarity. Method: remove names, dates and file numbers; prohibit confidential attachments.

Template contract analysis

Objective: generate points to watch. Method: use a template without identifiers; exclude sensitive client clauses until the tool is validated as sovereign and segregated.

9) Quick compliance checks (checklist)

  • France/EU hosting, encryption, compartmentalisation: verified in writing.
  • Prompt anonymisation/pseudonymisation: systematic.
  • DPIA completed and GDPR measures documented for high risk.
  • Human oversight and legal validation of every output.
  • Internal prohibition on entering confidential data without appropriate measures.
  • Traceability: up-to-date usage logs and archiving policy.

10) Regulatory points to monitor

  • Updates from the CNIL on AI and sector DPIAs.
  • Phased AI Act application and GPAI obligations on EUR-Lex.
  • Practical public/professional guides (e.g. FranceNum) and European-body analyses (CCBE).

For more detail, you can also read other AI and law analyses published by our teams.

Short FAQ

It can assist preparation, but final drafting and validation are human. Without a sovereign, segregated solution, avoid entering information covered by secrecy.

Can I use a public chatbot if I remove the client's name?

Pseudonymisation reduces risk but is insufficient if contextual details allow re-identification or the platform retrains on your prompts.

Must I inform the client?

Yes, when personal data is processed or AI influences the service. Comply with GDPR information requirements and document your approach.

Is a DPIA mandatory?

It is required if processing presents high risk. Assess the use case against CNIL criteria and recommendations.

Which texts should I consult?

Article 66-5 (1971 Act) and art. 226-13 of the Criminal Code on Legifrance, CNIL resources, AI Act on EUR-Lex, guides from FranceNum and CCBE.

Further reading

See our related guides: GDPR and artificial intelligence: legal obligations, Legal limits on using AI in business and What is an AI-first law firm?.

Further reading

Related resources

Frequently asked questions

FAQ

Which data should never be entered into consumer AI?

Any information covered by professional secrecy (client identity, strategy, non-public documents, draft instruments) and more broadly any data enabling re-identification.

How can I check an AI publisher does not retrain on my data?

Require a contractual non-reuse clause, technical documentation, a subprocessor list, evidence of EU hosting and security audits.

Is a DPIA always required for AI in a law firm?

No. It is required if processing presents high risk. Assess purposes, volumes, sensitivity and measures; refer to CNIL recommendations.

Does the AI Act apply to a lawyer using AI?

Primarily through provider and deployer obligations. The lawyer must ensure the tool meets transparency and risk-management requirements.

Must I tell clients I use AI?

Yes, if personal data is processed or AI influences the service. Explain purposes, safeguards, absence of automated decision-making and human oversight.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles