David Nowak.
Home/Decision brief · Lawyers & solo attorneys
Decision brief

Can a lawyer use AI safely?

9 min read · Sep 2026 · Every tool linked to its full review · Not legal advice — talk to your state bar if in doubt
Straight answer

Yes — for the work product around the practice, not the confessions. Client letters, demand drafts, marketing, intake forms, deposition summaries for your own review.

But this is the one profession where the line isn't just about privacy — it's about duty: a client's matter details pasted into a public tool can breach your duty of confidentiality, and a chatbot's invented citation can get you sanctioned. Both problems are avoidable, and one of them has a clean local answer.

The hard line

One line you can't cross

Your duty of confidentiality runs to anything a client tells you in representation — names, matter facts, documents, settlement positions, even the fact that you represent them. Pasting a draft motion, a client email, or a matter summary into a public chatbot hands it to a third party without the protections you owe. Bar associations are issuing opinions on exactly this; they're still forming, which means the safest rule is also the simplest one.

The second danger is the AI's, not yours to delegate: a fabricated case citation has already sanctioned real attorneys. Verify every citation. Always.

The line — for the whole firm

Matter details — names, case facts, documents, drafts, even the client's existence — never go in the public chatbot. De-identify down to "a contract dispute over deliverables," or use a tool that never sends data anywhere.

The second habit is the one that keeps you out of the sanction headlines: every case citation gets pulled and checked against the actual reporter before it leaves the building. The AI drafts, you verify — that's the whole arrangement.

Safe to start

What's safe to start with

Four uses with real payoff for a practice. Each links to the vetted review that covers it.

Anything confidential, run locally
A capable AI on your own machine: no account, no cloud, nothing sent anywhere. The one setup where pasting matter details doesn't break the line — because there's no third party to breach.
Ollama
$0 forever · your hardware sets the quality
Drafting client-facing text
Engagement letters, plain-language explanations of process, demand letters built from your notes — with client details swapped for placeholders before you paste.
Claude · ChatGPT
best-in-field at admitting ignorance
Answering the phone
Intake calls while you're in deposition: capture the caller, the practice area, and the callback — nothing more. Route anything that sounds like a retainer to you.
Retell · Bland
documented compliance in the base product
Marketing and intake forms
Website copy, FAQ pages, consultation request forms — public-facing work with no client facts in it at all.
ChatGPT · Canva
free tiers cover a solo practice

Why the local option leads this brief: a solo attorney is the single best fit for running AI on your own machine — small volume, sensitive matters, and one person's workflow to secure. Ollama is free forever and sends nothing anywhere; the catches are your hardware and your patch discipline. For an attorney who wants one tool they can paste a draft into without thinking twice, that's the cleanest answer in the market.

The drafting catch: Claude admits ignorance more readily than its rivals and holds the lowest measured hallucination rate in its class — but its free tier runs dry fast, and every citation still gets checked by you.

Never

What never goes in a public tool

Never

Anything about a specific client's matter — names, case numbers, documents, settlement positions, even the fact of the representation.

Never

Drafts of pleadings, contracts, or demand letters — the draft is the matter. De-identify or go local.

Never

Citations accepted as found — an AI-invented case is how attorneys got sanctioned. Pull and verify every cite before it leaves the building.

Never

Client intake recordings routed through a phone agent without documented data handling — the intake call is already privileged territory.

The test that holds up when the bar asks how you handled client data: if you wouldn't put it in opposing counsel's hands, don't put it in the public chatbot. Same exposure, fewer witnesses.

Before you sign

The five-minute vendor check

Run any vendor through these before money moves. A good vendor answers plainly. A deflecting one tells you what you need to know.

  1. Is my data used to train your model — and can that change? You want "no" on the tier you're buying, in writing. A free tier's yes quietly becomes your breach story.
  2. Do you sign a data-protection agreement? A privacy-policy promise is marketing; a signed agreement is a duty. Ask what it covers — retention, subprocessors, and whether your data is wiped when you leave.
  3. Where is my data stored, and can your staff see it? You want a location, an encryption answer, and a named access policy — not reassurance.
  4. What happens on cancellation? Client files and intake records must come out whole, and the vendor must delete everything they kept, in writing.
  5. Which of your vendors touch our data? A phone agent is a stack — speech recognition, language model, telephony. Each is a company. A serious vendor names every one; a vague answer is your answer.
If it goes wrong

If something goes wrong

AI doesn't need to be perfect in a practice — it needs to fail quietly and get caught. Three steps, in order:

Step 01

Stop using the tool for anything client-related the same day. Don't debug it with real matters.

Step 02

Write down what went where: which tool, what client information, roughly how much, how long ago. If this becomes a bar question, the record is the answer.

Step 03

Tell the client and loop in counsel — yours. Disclosure obligations in a confidentiality breach are exactly the kind of thing you don't want to be reading about for the first time.

This is general information, not legal advice. Your malpractice carrier's line exists for this call — that's what you pay it for.

Your call

The honest trade-off

The profession's trade-off is sharper than most: the best AI quality lives in the cloud, and your duty of confidentiality lives in your building. The bridge is the split in the routing table — public tools for de-identified work, the local option for anything that smells like a matter, documented-compliance phone agents for intake. It's one more habit than other businesses need: de-identify before you paste, verify before you cite.

What it buys: a solo practice can run a local model at $0 forever, draft marketing on free tiers, and take intake calls around the clock — without a single client fact crossing your firewall. That's not a compromise position. That's the position the technology has finally made affordable.

The 30-second takeaway

Yes to AI for drafting, intake, and marketing — no to client matters in public tools. De-identify what you paste or run it locally where nothing leaves the building, pull and verify every citation yourself, and make any phone agent show documented data handling before it hears an intake call.

I'm David. I build AI that keeps your data yours.

David Nowak

Twenty years building software for businesses like yours — cloud tools when they fit, your own machines when the data demands it. Fixed fee projects starting at $500, or a standing second opinion on your AI and software decisions from $300 a month.

Book a session

Bring one real problem. You leave with a plan — whether we work together or not.

Prefer writing first? Enable JavaScript to see the email

"Most companies are selling you fear and complexity. He cuts through the bullshit and just fixes things. That's what partnership looks like."
Jim · Owner, media production company · more testimonials