The legal profession is rapidly adopting generative AI tools for research, drafting, and client communications. Many of these tools, whether standalone or embedded in cloud-based platforms, operate under terms of service that grant providers broad rights to access, analyze, and even use uploaded data to train their AI models. If attorneys do not scrutinize these terms, they risk inadvertently exposing privileged information, work product, or client PII to unauthorized access or use by the AI provider—or worse, by third parties.
Unlike musicians, whose primary concern is copyright and creative control, lawyers have an ethical and legal duty to protect client confidentiality. The American Bar Association’s Model Rules of Professional Conduct require attorneys to make reasonable efforts to prevent unauthorized disclosure of client information. Using a generative AI tool with permissive or ambiguous TOS could violate these duties, especially if sensitive documents are uploaded without clear assurances that the data will not be used for AI training or shared beyond the intended scope.
Past precedents highlight the urgency of this issue. In 2024, Utah’s court system implemented MyCase, a case management platform that claimed ownership of all user-generated data, including attorney work product and client communications, while disclaiming liability for breaches. Similarly, Google’s 2025 Local Services Ads policy update asserted ownership over law firms’ client intake data, including call recordings and messages, which could be analyzed by AI without explicit consent - see my editorial MTC: Google’s Claim Over LSA Client Intake Recordings: Why Lawyers Must Rethink Cloud Service Risks in 2025 ⚖️☁️. These cases mirror broader industry trends, such as Vultr’s short-lived attempt to claim perpetual commercial rights to cloud-hosted content and Slack’s controversial data export fees. For lawyers, these examples demonstrate how easily confidential information can fall under third-party control—often through clauses buried in updates to terms of service. The ABA’s Formal Opinion 512 and analysis from The Tech-Savvy Lawyer.Page emphasize that such risks are not theoretical, urging practitioners to treat TOS reviews as a core component of client protection1.
Security and the Adversarial Risk
One of the gravest risks is that information uploaded to a generative AI platform could be accessed or inferred by the opposition or other unauthorized parties. If an AI provider uses your data to train its models, there is a risk—however small—that elements of your confidential work could surface in responses to other users. This is not a hypothetical concern; it has already happened in other industries, and the consequences for legal practice could be catastrophic.
Practical Steps: Protecting Clients and Your Practice
SoundCloud’s TOS incident is a stark reminder: always read and understand the terms of service for any platform or AI tool before uploading client data. The New Solo podcast episode “AI And The Terms Of Service. Know What You Are Sharing!” echoes this advice, emphasizing that lawyers—even those who draft TOS for others—often neglect to scrutinize these agreements for their own practice. Key questions include:
Who owns the data entered into the platform?
What rights does the provider claim over your data?
Is your data used solely to deliver the service, or is it also used to train AI models?
What safeguards are in place to prevent unauthorized access or disclosure?
As with the SoundCloud controversy, where artists discovered their music could be used for AI training without their knowledge, lawyers must be vigilant to prevent their confidential work from being similarly exploited.
The Adversarial Risk: More Than Just Theory