Client Confidentiality in the Age of AI: A Guide for Colorado Law Firms
Artificial intelligence is rapidly becoming part of everyday legal work. Attorneys can use AI to summarize documents, assist with research, draft correspondence, organize information, analyze contracts, and handle administrative tasks that once consumed hours of staff time.
For Colorado law firms, these capabilities can create significant opportunities for greater efficiency.
They can also create a serious question:
What happens to confidential client information when it is entered into an AI system?
Law firms have always had a responsibility to protect sensitive information. AI does not eliminate that responsibility. Instead, it introduces new ways confidential information can leave the controlled environment of a law firm.
That means attorneys and law firm leaders need to understand not only what AI can do, but also where information goes, how long it is retained, who can access it, and how the technology fits into the firm’s larger cybersecurity strategy.
For Colorado law firms exploring AI, protecting client confidentiality should be part of the conversation from the beginning.
Why AI Creates New Confidentiality Questions for Colorado Law Firms
Generative AI tools work differently from traditional legal software.
An attorney can enter a prompt, upload a document, or provide detailed information and receive a response almost instantly. This makes AI useful for tasks such as:
- Summarizing lengthy documents
- Brainstorming arguments or questions
- Drafting emails and correspondence
- Reviewing contracts
- Organizing case information
- Creating document outlines
- Assisting with legal research
- Preparing internal summaries
- Automating administrative work
The convenience can make it easy to overlook what happens to the information after it is submitted.
Depending on the AI platform, account type, configuration, and contractual terms, information may be processed or retained in different ways. Data handling practices can also vary significantly between consumer AI applications and enterprise systems.
For a law firm, that distinction matters.
A prompt containing a client’s name, medical information, financial records, litigation strategy, intellectual property, settlement position, or other sensitive details is not simply a question typed into software.
It is potentially confidential client information being provided to a technology platform.
What Colorado Attorneys Need to Know About Their Confidentiality Obligations
AI may be relatively new, but the fundamental professional obligations surrounding client confidentiality are not.
Colorado lawyers must consider the Colorado Rules of Professional Conduct when incorporating technology into their practices.
Colorado Rule of Professional Conduct 1.6 and Client Information
Colorado Rule of Professional Conduct 1.6 addresses the confidentiality of information relating to the representation of a client.
For law firms evaluating AI, the important takeaway is straightforward:
Using new technology does not eliminate the responsibility to safeguard client information.
Before sensitive client information is provided to an AI platform, attorneys should understand how the system handles that information and whether using it is consistent with their professional obligations.
Confidentiality concerns may extend beyond traditional privileged communications. Client-related information can include facts, documents, internal discussions, strategy, business information, personally identifiable information, and other sensitive material.
Technology Competence Matters Too
Attorneys do not need to become software developers or artificial intelligence engineers.
They do, however, need an appropriate understanding of the technology they use in their practice.
That includes understanding an AI tool’s basic capabilities, limitations, and material risks.
Questions such as these are becoming increasingly important:
Does the system retain prompts?
Can submitted information be used to improve or train models?
Who can access stored information?
Can administrators control data retention?
What security protections does the provider offer?
Can information be deleted?
Are third-party integrations connected to the platform?
A law firm cannot adequately evaluate an AI platform without understanding how the platform interacts with its data.
AI Does Not Transfer Responsibility to the Vendor
Purchasing an AI product does not mean the vendor assumes the law firm’s professional responsibilities.
The same principle applies to other technology providers.
Law firms remain responsible for making appropriate decisions about the systems they use, the information they provide to those systems, and the safeguards surrounding their technology environment.
Vendor due diligence should therefore become an important component of AI adoption.
What Are the Biggest AI Confidentiality Risks for Law Firms?
The biggest AI confidentiality risks often come from ordinary behavior rather than dramatic cybersecurity incidents.
An attorney trying to save 20 minutes might paste a client email into a public AI platform and ask for a summary.
A paralegal might upload a document to generate a timeline.
An employee might use a personal AI account to rewrite a confidential email.
Another employee might connect an AI-powered browser extension to applications containing client information.
Each action may appear harmless individually.
Collectively, they can create an environment where a law firm no longer has a clear picture of where its information is going.
Some of the most important risks include the following.
Sensitive Information Entered Into Consumer AI Tools
Publicly available AI platforms can be incredibly useful, but firms should not assume that every consumer AI service is appropriate for confidential legal work.
The privacy, security, retention, and training policies of the specific service and account configuration need to be understood before sensitive information is entered.
Unclear Data Retention
How long does an AI provider retain prompts, uploaded documents, generated responses, logs, and related data?
If a law firm cannot answer that question, it may not fully understand the lifecycle of the information it is submitting.
AI Model Training and Data Use
Firms should determine whether information submitted to an AI platform can be used for model training, service improvement, human review, or other purposes.
Policies can differ between services and between consumer and enterprise versions of the same service.
Third-Party Integrations
AI systems increasingly connect with email, cloud storage, document management platforms, customer relationship management systems, browsers, and productivity applications.
Every integration can potentially expand the amount of information available to the AI system.
Law firms should understand what permissions are being granted and whether those permissions are broader than necessary.
Weak Account Security
Even an AI platform with strong security controls can become a risk if the firm’s accounts are poorly protected.
Weak passwords, shared accounts, excessive permissions, and missing multifactor authentication can create unnecessary exposure.
Shadow AI
One of the most difficult risks may be AI that firm leadership does not know employees are using.
What Is Shadow AI and Why Should Law Firms Care?
Shadow AI occurs when employees use artificial intelligence tools without the knowledge, approval, or oversight of the organization.
Imagine an attorney receives a complicated client email.
The attorney copies the email into a personal AI account and asks:
“Summarize this email and draft a professional response.”
The result might be useful.
But if the email contains confidential information, the attorney may have just transferred sensitive data into a system the firm has never evaluated.
The same situation can occur when employees:
- Upload contracts for summaries
- Paste deposition transcripts into AI tools
- Ask AI to rewrite client communications
- Analyze spreadsheets containing personal information
- Install AI browser extensions
- Use personal AI accounts for firm work
- Connect unapproved AI applications to cloud storage
Simply banning AI may not solve the problem.
Employees may continue using the technology because it makes their work easier.
A more sustainable approach is to establish clear rules regarding which AI systems are approved, what information may be entered, and which uses are prohibited.
Public AI Tools vs. Enterprise AI: Why the Difference Matters
Not every AI platform handles information the same way.
This is why law firms should avoid categorizing AI tools simply as “safe” or “unsafe.”
The more useful question is:
How does this specific AI service, under this specific configuration and agreement, handle our information?
Enterprise AI platforms may provide additional organizational controls such as:
- Centralized account administration
- Enhanced authentication
- User permission management
- Audit capabilities
- Configurable retention settings
- Contractual privacy protections
- Organizational security controls
- Restrictions on model training
- Integration management
Those features can make enterprise systems easier for organizations to govern.
However, the word “enterprise” should never replace due diligence.
Law firms should still investigate the platform’s security architecture, privacy practices, contractual terms, retention policies, and access controls before approving it for sensitive work.
Before Your Firm Uploads Client Information to AI, Ask These Questions
Before approving an AI platform for legal work, Colorado law firms should conduct a structured review.
At minimum, consider asking:
Does the provider retain our prompts or uploaded files?
Understand what is stored and for how long.
Is our information used to train AI models?
Determine whether customer information may be used for training or improving the provider’s models or services.
Who can access our information?
Consider employees, contractors, subprocessors, administrators, and other third parties.
Where is the information stored and processed?
Data location can matter depending on the client, industry, contract, or regulatory environment.
Can retention be limited or disabled?
Look for administrative controls that allow the organization to determine how long information remains available.
What happens when an account is terminated?
Determine how stored data is handled when an employee leaves or the firm’s relationship with the provider ends.
Does the platform support multifactor authentication?
MFA should be considered a fundamental security control for systems that may contain sensitive information.
Can user permissions be centrally managed?
Law firms should be able to control who has access and remove access when it is no longer necessary.
Does the platform provide logs or auditing capabilities?
Visibility can help firms identify inappropriate access or unusual activity.
What third-party integrations can access the system?
Connected applications can introduce risks that are separate from the AI platform itself.
What contractual protections does the vendor provide?
Security promises should be evaluated alongside contractual terms governing privacy, confidentiality, data use, incidents, and deletion.
The key is to evaluate AI as both a productivity tool and a potential data environment.
Do Clients Need to Know When Their Attorney Uses AI?
The answer depends on the circumstances.
AI use can raise issues involving confidentiality, communication, competence, supervision, and informed consent.
ABA guidance on generative AI has emphasized that lawyers should consider their existing ethical obligations when using these technologies. Depending on how an AI system is being used and what information is involved, client communication or informed consent may be necessary.
Colorado firms should evaluate these questions based on the specific use case rather than relying on a universal disclosure statement.
A generic clause in an engagement agreement should not be treated as a substitute for carefully evaluating the technology and circumstances.
When necessary, attorneys should seek appropriate ethics guidance regarding their professional obligations.
How Can Colorado Law Firms Build a Safer AI Policy?
A written AI policy provides employees with practical rules for using these technologies.
Without one, every employee may effectively create their own AI security standards.
A useful policy should address several areas.
1. Define Approved AI Platforms
Maintain a list of AI tools employees are permitted to use for firm-related work.
New platforms should go through a review process before adoption.
2. Define Prohibited Uses
Employees should understand what they cannot do.
For example, a firm may restrict employees from entering confidential or privileged information into unapproved AI platforms.
Rules should be specific enough to guide real-world decisions.
3. Classify Information
Not all information requires the same level of protection.
A law firm might classify information into categories such as:
- Public
- Internal
- Confidential
- Privileged
- Personally identifiable
- Highly sensitive
AI policies can then specify which categories may be processed by approved systems.
4. Establish Vendor Review Standards
AI procurement should include security and privacy review.
The newest AI feature should not automatically become an approved business tool simply because employees find it useful.
5. Require Appropriate Access Controls
Apply the principle of least privilege.
Employees should only have access to the systems and information necessary for their responsibilities.
Strong authentication, MFA, centralized identity management, and proper offboarding procedures can reduce unnecessary exposure.
6. Train Attorneys and Staff
An AI policy sitting in a folder is not enough.
Employees need practical examples showing what acceptable and unacceptable use looks like.
Training might include scenarios such as:
“Can I paste this client email into AI?”
“Can I upload this contract?”
“Can I use my personal AI account for work?”
“Can I connect an AI assistant to my email?”
“Can I use AI to summarize this deposition?”
Employees should know how to answer those questions or whom to ask when they are uncertain.
7. Require Human Review of AI Output
Confidentiality is only one aspect of responsible AI use.
Generative AI can produce incorrect, incomplete, or fabricated information.
Legal professionals should independently review and verify AI-generated work before relying on it for client matters.
Professional judgment remains human responsibility.
AI Security Should Be Part of Your Law Firm’s Cybersecurity Strategy
AI should not be treated as a separate technology issue.
It should become part of the firm’s broader cybersecurity and risk-management program.
A secure AI strategy depends on many of the same controls law firms should already be using to protect client information.
These include:
Multifactor Authentication
MFA adds another layer of protection when passwords are compromised.
Identity and Access Management
Access should be based on employee responsibilities and removed promptly when it is no longer required.
Endpoint Security
Computers and devices accessing client information should be properly secured, monitored, patched, and maintained.
Email Security
Email remains a major avenue for cyberattacks and often contains highly sensitive client information.
Secure Cloud Configuration
Cloud applications should be configured according to the firm’s security requirements rather than relying entirely on default settings.
Data Backup and Recovery
Reliable backups help firms recover from ransomware, accidental deletion, system failures, and other incidents.
Security Awareness Training
Employees need to recognize phishing, social engineering, unsafe AI usage, suspicious login requests, and other threats.
Incident Response
Firms should know what to do if confidential information is accidentally entered into an unapproved AI platform or an AI-related account is compromised.
The effectiveness of AI security ultimately depends on the security environment surrounding it.
A Practical AI Confidentiality Checklist for Colorado Law Firms
Colorado law firms evaluating AI can begin with the following checklist:
- Inventory AI tools currently being used across the firm.
- Identify unapproved or personal AI accounts being used for work.
- Establish a written AI acceptable-use policy.
- Create a process for approving new AI platforms.
- Review vendor privacy and security practices.
- Determine whether submitted information is retained.
- Determine whether customer information can be used for AI training.
- Review third-party integrations and permissions.
- Require MFA on approved platforms where available.
- Apply least-privilege access controls.
- Establish procedures for employee onboarding and offboarding.
- Train attorneys and staff on safe AI use.
- Restrict confidential information from unapproved AI systems.
- Require human review of AI-generated work.
- Develop a procedure for reporting accidental disclosure.
- Review AI policies regularly as technology and guidance evolve.
Most importantly, firms should know which AI tools are being used and what information those tools can access.
You cannot effectively protect information moving through systems you do not know exist.
AI Does Not Have to Mean Choosing Between Innovation and Confidentiality
AI offers real opportunities for law firms.
Used appropriately, it can help attorneys work more efficiently, reduce repetitive tasks, organize information, accelerate document review, and improve internal workflows.
But convenience should not come at the expense of client confidentiality.
For Colorado law firms, responsible AI adoption starts with asking the right questions before sensitive information reaches an AI platform.
Where does the data go?
Who can access it?
How long is it retained?
Is it used for model training?
What security controls protect it?
What happens if an employee uses an unapproved tool?
How will the firm respond if something goes wrong?
The firms best prepared for AI will not necessarily be those that adopt every new tool first.
They will be the firms that develop a thoughtful framework for adopting useful technology while maintaining appropriate safeguards around the information clients entrust to them.
Strengthen Your Law Firm’s Technology Before Expanding Your AI Footprint
AI security is ultimately part of cybersecurity.
Before introducing additional AI tools into your legal practice, your law firm should have a strong technology foundation that includes secure identities, properly configured systems, reliable backups, cybersecurity protections, employee training, access controls, and ongoing technology management.
eCreek helps Colorado businesses build and manage secure, reliable IT environments designed for the way modern organizations work.
For law firms exploring artificial intelligence, that means helping create a technology foundation where innovation and cybersecurity can work together.
If your Colorado law firm is evaluating AI or questioning whether its current IT environment is ready for the next generation of legal technology, talk with eCreek about strengthening your cybersecurity and managed IT foundation.
Frequently Asked Questions About AI and Client Confidentiality
Can Colorado lawyers use generative AI?
Yes. The use of generative AI is not inherently prohibited simply because the technology uses artificial intelligence. Colorado attorneys still need to comply with their existing professional obligations, including confidentiality, competence, supervision, communication, and appropriate review of work produced with AI assistance.
Can attorneys enter confidential client information into ChatGPT or another AI tool?
Attorneys should not assume that confidential information can safely be entered into any AI platform. Before submitting client information, firms need to understand the specific platform’s data handling, retention, training, security, access, and contractual protections and determine whether the proposed use is consistent with applicable professional obligations.
Does Using AI Waive Attorney-Client Privilege?
AI use can create privilege and confidentiality concerns depending on what information is disclosed, the system being used, how the information is handled, and the circumstances surrounding the disclosure. Attorneys should not assume information remains protected simply because it was submitted to an AI service for legal work.
What Should a Law Firm Check Before Approving an AI Platform?
Law firms should evaluate data retention, model training practices, privacy terms, security controls, authentication, permissions, third-party access, integrations, deletion procedures, contractual protections, and administrative capabilities before approving an AI platform.
Should Law Firms Have a Written AI-Use Policy?
A written AI policy can establish which tools are approved, what information employees may enter, which activities are prohibited, how new platforms are reviewed, and what employees should do if confidential information is accidentally exposed.
What Is Shadow AI?
Shadow AI refers to employees using artificial intelligence tools for business purposes without organizational approval or oversight. It can create cybersecurity and confidentiality risks because the firm may not know which services contain or have access to its information.
How Can a Managed IT Provider Help a Law Firm Use AI More Securely?
A managed IT provider can help strengthen the technology environment surrounding AI through identity and access management, MFA, endpoint protection, cloud security, monitoring, cybersecurity training, account management, backups, vendor evaluation, and other controls.
For law firms, these protections help establish a stronger technical foundation for adopting new technologies while safeguarding sensitive business and client information.
This article is provided for general informational purposes and is not legal advice. Law firms and attorneys should consult applicable professional rules, ethics guidance, contractual requirements, and qualified legal or ethics counsel when evaluating specific uses of artificial intelligence.

