MatterLayer / Field note
Security and privacy diligenceCan a law firm put client data into AI tools?
There is no responsible yes-or-no answer at product level. A firm must assess the particular client information, purpose, provider, contractual and technical controls, applicable obligations and matter-specific risk before approving a workflow.
Classify the information and purpose
Begin with what the proposed workflow actually sends. Client data may include personal information, sensitive information, confidential communications, privileged material, identity documents, commercial information or court material. The legal and professional treatment depends on the circumstances; these labels are not interchangeable. Record the minimum fields or documents required and ask whether the same outcome can be achieved with less information or without AI. For organisations subject to the Privacy Act, the APPs may regulate collection, use, disclosure and other handling of personal information. The OAIC recommends caution and due diligence for commercially available AI, including attention to necessity, intended use, access and human oversight. That analysis does not replace confidentiality, privilege, contractual or court requirements. The approving person should understand the actual matter context and not rely on a generic vendor category such as 'enterprise' or 'private'.
Interrogate the provider and service chain
Ask where data is processed and stored, who can access it, whether inputs or outputs are used to train models, how long they are retained and which subprocessors participate. Review authentication, tenant separation, encryption, logging, incident notification, deletion, export and support-access controls. Examine how terms can change and which commitments are contractual. Australian hosting may be relevant to a firm's risk decision, but it is not a universal legal requirement and does not by itself answer questions about remote access, ownership, subcontractors or lawful demands. Conversely, an offshore component is not automatically impermissible in every circumstance. The firm needs a documented, proportionate decision for the information and obligations at issue. Professional guidance in Victoria and Queensland gives practitioners further jurisdiction-specific prompts about public tools, confidentiality, terms, training use and provider access.
Apply shared responsibility in practice
A secure provider does not configure the firm's users, choose appropriate data or verify legal outputs. The Australian Signals Directorate's cloud shared-responsibility guidance explains that provider and customer responsibilities vary by service model and should be understood. Translate that into named controls: the provider may protect infrastructure, while the firm manages identity, authorised use, device security, data selection, matter permissions and response procedures. Test whether access follows real matter restrictions, including ethical walls and departed users. Decide which logs the firm will review and who owns incident triage. A cyber event, a policy exception and a notifiable data breach are different classifications; do not label every anomaly as a reportable breach without the required assessment. The operating plan should say who preserves evidence, who assesses impact and when legal, privacy, security or client teams are involved.
State the Pilot boundary so users can follow it
A safe Pilot does not say simply 'approved for client data'. It identifies the permitted matter cohort, data categories, workflow, users, provider configuration, retention setting and prohibited inputs. Start with the least sensitive data that can test the decision. Use read-only integration where possible, prevent the service from taking consequential action and place review before any output leaves the approved environment. Show the boundary at the point of use and train participants with examples of allowed and excluded material. Record deviations and stop if the control cannot be operated consistently. The Pilot should also test revocation and deletion. Success means the firm can explain what was processed, why, by whom, under which controls and with what review. It does not establish that every later client, matter or AI feature is approved.
Source file
Primary reading
- 01Guidance on privacy and the use of commercially available AI products
Office of the Australian Information Commissioner
- 02Statement on the use of artificial intelligence in Australian legal practice
Victorian Legal Services Board and Commissioner
- 03Cloud shared responsibility model: guidance for individuals and small and medium businesses
Australian Signals Directorate
- 04Guidelines for procurement and outsourcing
Australian Signals Directorate