Associates paste client memos into ChatGPT. Paralegals use AI for contract review. Partners dictate strategy into AI transcription tools. Your conflict-check system catches none of it. A DNS log audit does.
Attorney-client privilege is absolute until it is waived. Pasting privileged information into an AI tool with no confidentiality agreement may constitute a waiver. The risk is existential for the firm and catastrophic for the client.
Associates upload entire contracts to AI tools for clause extraction, redlining suggestions and summary generation. Each upload sends client-confidential terms to a third-party server.
Attorneys query AI tools with case-specific facts to find analogous precedent. The query itself reveals the client's legal position, strategy and potential vulnerabilities.
Lawyers paste argument outlines, factual summaries and legal theories into AI writing assistants. These inputs expose litigation strategy and privileged analysis.
Partners use AI transcription tools during client calls, strategy sessions and depositions. Audio recordings of privileged conversations are sent to cloud servers for processing.
Lawyers use AI tools to summarise long email threads. The tool processes entire chains of privileged correspondence, including attachments and internal deliberations.
M&A teams upload data room documents to AI analysis tools for faster review. Financial statements, employment agreements and IP schedules flow to unvetted AI vendors.
Bar associations and regulators are issuing guidance on AI use faster than most firms can track. A shadow AI audit provides the factual foundation for compliance.
| Obligation | Source | Shadow AI Risk | What the Audit Produces |
|---|---|---|---|
| Duty of Confidentiality | Model Rule 1.6 | Privileged info sent to AI without client consent | List of AI tools used, with data-retention and training policies |
| Duty of Competence | Model Rule 1.1 | Relying on AI output without verification | Usage frequency and departments, for training prioritisation |
| Duty of Supervision | Model Rules 5.1, 5.3 | Partners unaware of associate AI tool usage | Per-user group usage patterns and tool risk profiles |
| Client Data Protection | State bar opinions | Client data stored by AI vendor without safeguards | Vendor data-handling assessment per tool |
| Technology Competence | Comment 8 to Rule 1.1 | Firm lacks awareness of AI tools on its network | Complete AI tool inventory with risk classification |
| Candor to Tribunal | Model Rule 3.3 | AI-generated citations not verified (hallucination risk) | Identification of generative AI tools used by litigation teams |
A sample excerpt from a shadow AI audit of a 120-attorney regional firm.
Each scenario represents patterns found across law firm shadow AI audits.
A corporate associate pastes a merger agreement into ChatGPT to identify non-standard indemnification clauses. The agreement contains deal terms, party names and negotiation positions. OpenAI's free tier uses the input for model training. The client's deal terms are now in a training dataset.
A partner uses an AI meeting transcription tool during a case strategy call with co-counsel. The recording captures privileged work-product analysis, witness assessments and settlement positions. The transcription vendor stores the audio on cloud servers with no deletion policy.
A paralegal uploads prior art documents and draft claims to an AI analysis tool. The tool processes unpublished patent applications and trade secrets. The vendor's terms allow use of uploads for service improvement, which may include training.
An associate uses an AI writing assistant to draft a custody motion. The prompt contains the client's name, children's names, allegations of abuse and financial information. The AI tool generates a hallucinated case citation. Neither the privilege breach nor the fabricated citation is detected before filing.
A phased approach from discovery to governance that respects the billable-hour reality of law firm operations.
Upload 14-21 days of DNS and proxy logs. Get a complete inventory of every AI tool accessed from the firm network, broken down by practice group.
Score each tool for privilege risk. Flag tools that train on input, lack confidentiality terms, or store data without deletion timelines. Map to bar association guidance.
Draft an AI acceptable use policy. Define sanctioned tools, prohibited uses and client-consent requirements. Distribute to all attorneys and staff.
Run quarterly audits to detect new AI tool adoption and policy drift. Report results to the managing partner and ethics committee.
Multi-framework evidence packs and audit workflows.
Cross-border data transfer risks from AI tools.
Shadow AI in banking, trading and asset management.
PHI exposure and HIPAA risks from unsanctioned AI.
Upload your DNS or proxy logs and get a privilege-risk-mapped shadow AI inventory for your firm.
Start Your Free Audit