MTC: Judges Will Be Hunting These AI Tricks After Brazil’s Scandal

it is hard to believe that judges will be happy if lawyer insert “code” into their online filings!

Recently, Brazilian court officials uncovered something that should make every tech‑savvy lawyer sit up straight. In a labor court, staff discovered a filing that looked ordinary to the human eye—until they examined it more closely. Hidden in the document was text written in white font on a white background, invisible to anyone casually reading the PDF but fully legible to the court’s AI system.

That invisible text was not a typo. It was an instruction—what technologists call a “prompt injection”—telling the court’s AI software to review the case only superficially and not to challenge the evidence submitted. In other words, the filing was designed to trick the judiciary’s own AI tools into rubber‑stamping a favorable outcome by smuggling in commands that humans would never see.

Fortunately, court staff caught the scheme before it affected the proceedings. But Brazilian authorities immediately recognized the incident as a new species of digital fraud and began discussing safeguards: automatic detection of invisible text, formatting checks before AI processing, and stronger human oversight at every stage. They also raised the prospect of stricter ethics rules and sanctions for lawyers who try to manipulate court AI systems.

For our purposes, the Brazil case does three important things:

  1. It confirms that AI now sits inside judicial workflows—not just law firm workflows.

  2. It shows that some lawyers will try to game those systems if they think they can get away with it.

  3. It gives us a concrete example of what not to do and what to watch for as courts in the U.S. and elsewhere adopt similar tools.

From an ABA perspective, a “white‑text prompt injection” is not clever lawyering—it’s a direct collision with Model Rule 3.3 (candor toward the tribunal) and Model Rule 8.4(c)’s prohibition on conduct involving dishonesty, fraud, deceit, or misrepresentation. And because the Brazil incident exploits the very AI tools that the judiciary is using, it also implicates Model Rule 1.1 and Comment 8: the duty of technology competence now includes understanding how these systems can be abused.

So let’s unpack what we should learn from Brazil—starting with what not to do.

What Not To Do: Hidden Instructions and “Clever” Hacks

The Brazil case is a textbook on the wrong way to think about AI in litigation.

  • Do not embed hidden commands in filings (through white‑on‑white text, metadata, or other tricks) with the intent to influence how a court’s AI tools process your case.

  • Do not treat court‑side AI as just another system to be “SEO‑optimized” or hacked. Unlike a marketing algorithm, this is part of the machinery of justice; trying to tilt it in your favor crosses a bright ethical line.

  • Do not assume that “if the judge doesn’t see it, it doesn’t count.” Malicious prompts aimed at judicial AI are still part of your submission to the tribunal, and they reflect directly on your candor and honesty under Model Rules 3.3 and 8.4.

In short: if you would never say it to the judge in plain black‑and‑white text, you should not whisper it to the court’s AI in invisible text.

What To Watch For: How to Recognize This Behavior

lawyers need to be prepared to vet opposing counsel’s filings for ai injection!

The harder question is how you, as a solo or small‑firm lawyer, can spot similar tactics when others use them—especially when you don’t control the court’s systems.

Here are practical signals and questions:

  • Suspicious formatting in PDFs or Word files. Odd spacing, unexpected blank pages, or inconsistent fonts can sometimes signal hidden layers of text. While you won’t always spot white‑on‑white content, unusual formatting should prompt closer inspection.

  • Metadata anomalies. If you routinely examine document properties, look for multiple authors, unusual editing histories, or automation tags that do not match the face of the document. These can indicate heavy automated processing or embedded instructions.

  • Patterns in AI‑mediated decisions. If certain filings—often from the same party—seem to sail through automated queues or receive unusually favorable, boilerplate orders, you may be seeing the downstream effect of prompt manipulation or aggressive “AI‑targeted” drafting.

Because you usually won’t have direct access to the court’s internal AI, you may need to raise these concerns procedurally: requesting clarification on how filings are screened, asking whether AI systems were involved in certain steps, or moving for relief if you believe your client’s matter was prejudiced by automated processing.

How To Protect Yourself and Your Clients:

Brazil’s experience is a warning shot—not just about bad actors, but about what a healthy response should look like.

Here’s how to translate that into a practical “do this, not that” playbook for your own practice:

1. Assume courts will adopt AI—and plan for it:

Brazil’s judiciary uses AI to prioritize cases, draft reports, and propose decisions in response to massive backlogs. U.S. courts are already experimenting with similar tools, even if not as publicly. Competence under Model Rule 1.1 now includes staying informed about these trends and understanding their implications.

2.     Build “AI integrity” into your litigation strategy.

  • Treat any automated system that touches your filings—court e‑filing portals, online forms, AI‑assisted triage tools—as part of the tribunal.

  • Resolve that you will never include hidden instructions, misleading metadata, or manipulative formatting in documents submitted to those systems.

3.     Advocate for transparent safeguards.

  • In Brazil, authorities responded by exploring automatic detection of invisible text and stronger human oversight.

  • When U.S. courts announce AI pilots or tools, comment on proposed rules, advocate for clear notice when AI is used, and request mechanisms for lawyers to challenge AI‑influenced outcomes.

4.     Document your own good‑faith use of AI.

it may be deemed a “fruad upon the court” if a lawyer injects ai into their electronic filings.

  • If you rely on AI to format or generate parts of your filings, keep internal records of prompts, outputs, and human review.

  • This documentation will help if a court or disciplinary body later asks how you ensured candor and accuracy, especially in a world where Brazil‑style abuses are making judges more skeptical.

Final Thoughts

AI isn’t just something we use; it’s now part of the institutional environment—just like e‑filing, CM/ECF, or digital signatures. The line between legitimate technology use and unethical manipulation is not about whether you use AI, but how you use it and whether you’re honest about it.

MTC

🎙Bonus Episode: TSL Labs's 🧪 Deep Dive into our July 13, 2026, Editorial, Law School, Laptops, and AI: Why Banning Computers Misses the Point!

Join us for an AI-powered deep dive into the ethical challenges facing legal professionals in the age of generative AI. 🤖 In this episode, we unpack our editorial “Law School, Laptops and AI: Why Banning Computers Misses the Point,” and explore why laptop bans in law schools are less about ethics and more about administrative convenience — and how that choice could leave future lawyers unprepared for a fully digital profession.

In our conversation, we cover the following

00:00:00 — From “no calculators” to “no laptops”: how old tech panics mirror today’s AI fears in legal education 📚🧮

00:01:00 — AI panic hits law schools: blanket bans on generative AI and even laptops in the classroom 🎓⚠️

00:02:00 — Why Michael supports limiting AI in 1L while still opposing laptop bans: building foundational legal judgment 💪⚖️

00:03:00 — ABA Model Rule 1.1 and competence: why early overreliance on AI short-circuits “intellectual muscle” 🧠

00:05:00 — Why banning laptops “misses the point”: the scalpel vs leeches analogy and modern legal training 🩺🖥️

00:06:00 — Accessibility and fairness: Michael’s 2002 law school story and laptops as essential accessibility tools ✍️💻

00:07:00 — Digital-native students and analog exams: how bans unfairly shift the playing field instead of leveling it 🎯

00:08:00 — Law practice is 100% digital: e‑discovery, e‑filing, and why stripping laptops undermines tech competence 🌐📑

00:08:30 — ABA Model Rule 1.1, Comment 8: the ethical duty to understand the benefits and risks of relevant technology 📘

00:09:30 — Lazy enforcement: why laptop bans are about visual policing, not thoughtful AI policy 🧍‍♂️👀

00:10:00 — ABA Model Rule 5.3: supervising AI as a “digital clerk” and why hiding the tech creates ethical gaps 🤖📎

00:11:30 — Guardrails, not prohibitions: network geofencing, offline laptops, and locked‑down software environments 🧱📶

00:12:30 — Clear AI policies in assignments: when AI is permitted, when it is prohibited, and how disclosure builds discipline 📝

00:13:00 — Teaching prompt engineering as a core legal skill: delegation, context, and structured AI use 🧩

00:13:30 — ABA Model Rule 1.6 and confidentiality: the risks of pasting client secrets into public AI tools 🔐

00:14:30 — Cognitive offloading vs cognitive atrophy: why tech can strengthen legal reasoning when used wisely 🧠⚙️

00:16:00 — Verifying AI outputs: hallucinations, fake cases, and training students to check everything against primary law 📚

00:17:00 — Temptation vs discipline: why bans don’t teach judgment, but supervised AI use can 🎯

00:18:00 — The false dichotomy: foundational human judgment vs tech competence and why future lawyers must have both ⚖️💡

00:19:00 — The future horizon: when AI becomes the “senior partner” and the lawyer becomes the supervisor‑in‑chief 🧑‍⚖️🤖

00:20:00 — Final challenge: law schools can’t ban their way out of the future — they have to teach students to wield the tools safely 🔍🚀

RESOURCES

Mentioned in the episode

Software & Cloud Services mentioned in the conversation

If you care about the future of legal education, client protection, and real‑world tech competence, hit play now and then share this episode with a colleague who still thinks “just ban the laptops” is a solution. 🎧💬

Word of the Week: Vendor Risk Management for Law Firms in 026: Lessons from the Clio–Alexi CRM Fight ⚖️💻

Clio vs. Alexi: CRM Litigation COULD THREATEN Law Firm Data

“Vendor risk management” is no longer an IT buzzword; it is now a core law‑practice skill for any attorney who relies on cloud‑based tools, CRMs, or AI‑driven research platforms.⚙️📊 The Tech‑Savvy Lawyer.Page’s February 2, 2026 editorial on the Clio–Alexi CRM litigation showed how a dispute between legal‑tech companies can reach straight into your client list, calendars, and workflows.⚖️🧾

In that piece, Clio and Alexi’s legal fight over data, AI training, and competition was framed not as “tech drama,” but as a live test of how well your firm understands its dependencies on vendors that control client‑related information.🧠📂 When the platform that hosts your CRM, matter data, or AI research tools becomes embroiled in high‑stakes litigation, your risk profile changes even if you never set foot in that courtroom.⚠️🏛️

Under ABA Model Rule 1.1, competence includes a practical understanding of the technology that underpins your practice, and that now clearly includes vendor risk.📚💡 You do not have to reverse‑engineer APIs, yet you should be able to answer basic questions: Which vendors are mission‑critical, what data do they hold, how would you respond if one faced an injunction, outage, or rushed acquisition.🧩🚨 That is vendor risk management at a level that is realistic for lawyers with limited to moderate tech skills.🙂🧑‍💼

LawyerS NEED TO Build Vendor Risk Plan for Ethical Compliance

Model Rule 1.6 on confidentiality sits at the center of this analysis, because litigation involving a vendor can expose or pressure the systems that hold client information.🔐📁 Our February 2 article emphasized the need to know where your data is hosted, what the contracts say about subpoenas and law‑enforcement requests, and how quickly you can export data if your ethics analysis changes.⏱️📄 Vendor risk management, therefore, includes reviewing terms of service, capturing “current” versions of online agreements, and documenting export rights and notice obligations.📝🧷

Model Rule 5.3 requires reasonable efforts to ensure that non‑lawyer assistance is compatible with your professional duties, and 2026 legal‑tech commentary increasingly treats vendors as supervised extensions of the law office.🧑‍⚖️🤝 CRMs, AI research tools, document‑automation platforms, and e‑billing systems all act as non‑lawyer assistants for ethics purposes, which means you must screen them before adoption, monitor them for material changes, and reassess when events like the Clio–Alexi dispute surface.📡📊

Recent legal‑tech reporting has described 2026 as a reckoning year for vendors, with AI‑driven tools under heavier regulatory and client scrutiny, which makes disciplined vendor risk management a competitive advantage rather than a burden.📈🤖 Practical steps include maintaining a simple vendor inventory, ranking systems by criticality, reviewing cyber and data‑security representations, and identifying a plausible backup provider for each crucial function.📋🛡️

LAWYERS NEED TO SHIELD THEIR CLIENT DATA FROM CRM LITIGATION AS MUCH AS THEY NEED TO PROTECT THEIR EthicS DUTIES!

Vendor risk management, properly understood, turns your technology stack into part of your professional judgment instead of a black box that “IT” owns alone.🧱🧠 For solo and small‑firm lawyers, that shift can feel incremental rather than overwhelming: start by reading the Clio–Alexi editorial, pull your top three vendor contracts, and ask whether they let you protect competence, confidentiality, and continuity if your vendors suddenly become the ones needing legal help.🧑‍⚖️🧰

MTC: PornHub Breach: Cybersecurity Wake-Up Call for Lawyers

Lawyers are the first line defenders for their clientS’ pii.

It's the start of the New Year, and as good a time as any to remind the legal profession of their cybersecurity obligations! The recent PornHub data exposure reveals critical vulnerabilities every lawyer must address under ABA ethical obligations. Third-party analytics provider Mixpanel suffered a breach compromising user email addresses, triggering targeted sextortion campaigns. This incident illuminates three core security domains for legal professionals while highlighting specific duties under ABA Model Rules 1.1, 1.6, 5.1, 5.3, and Formal Opinion 483.

Understanding the Breach and Its Legal Implications

The PornHub incident demonstrates how failures by third-party vendors can lead to cascading security consequences. When Mixpanel's systems were compromised, attackers gained access to email addresses that now fuel sextortion schemes. Criminals threaten to expose purported adult site usage unless victims pay cryptocurrency ransoms. For law firms, this scenario is not hypothetical—your practice management software, cloud storage providers, and analytics tools present identical vulnerabilities. Each third-party vendor represents a potential entry point for attackers targeting your client data.

ABA Model Rule 1.1: The Foundation of Technology Competence

ABA Model Rule 1.1 requires lawyers to provide competent representation, and Comment 8 explicitly extends this duty to technology: "To maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology". This is not a suggestion—it is an ethical mandate. Thirty-one states have adopted this technology competence requirement into their professional conduct rules.

What does this mean practically? You must understand the security implications of every technology tool your firm uses. Before onboarding any platform, conduct due diligence on the vendor's security practices. Require SOC 2 compliance, cyber insurance verification, and detailed security questionnaires. The "reasonable efforts" standard does not demand perfection, but it does require informed decision-making. You cannot delegate technology competence entirely to IT consultants. You must understand enough to ask the right questions and evaluate the answers meaningfully.

ABA Model Rule 1.6: Safeguarding Client Information in Digital Systems

Rule 1.6 establishes your duty of confidentiality, and Comment 18 requires "reasonable efforts to prevent [the inadvertent or unauthorized] access or disclosure” to information relating to the representation of a client. This duty extends beyond privileged communications to all client-related information stored digitally.

The PornHub breach illustrates why this matters. Your firm's email system, document management platform, and client portals contain information criminals actively target. The "reasonable efforts" analysis considers the sensitivity of information, likelihood of disclosure without additional safeguards, cost of safeguards, and difficulty of implementation. For most firms, this means mandatory multi-factor authentication (MFA) on all systems, encryption for data at rest and in transit, and secure file-sharing platforms instead of email attachments.

You must also address third-party vendor access under Rule 1.6. When you grant a case management platform access to client data, you remain ethically responsible for protecting that information. Your engagement letters should specify security expectations, and vendor contracts must include confidentiality obligations and breach notification requirements.

ABA Model Rules 5.1 and 5.3: Supervisory Responsibilities Extend to Technology

lawyers need to stay up to date on the security protocOls for their firm’s software!

Rule 5.1 imposes duties on partners and supervisory lawyers to ensure the firm has measures giving "reasonable assurance that all lawyers in the firm conform to the Rules of Professional Conduct". Rule 5.3 extends this duty to nonlawyer assistants, which courts and ethics opinions have interpreted to include technology vendors and cloud service providers.

If you manage a firm or supervise other lawyers, you must implement technology policies and training programs. This includes security awareness training, password management requirements, and incident reporting procedures. You cannot assume your younger associates understand cybersecurity best practices—they need explicit training and clear policies.

For nonlawyer assistance, you must "make reasonable efforts to ensure that the person's conduct is compatible with the professional obligations of the lawyer". This means vetting your IT providers, requiring them to maintain appropriate security certifications, and ensuring they understand their confidentiality obligations. Your vendor management program is an ethical requirement, not just a business best practice.

ABA Formal Opinion 483: Data Breach Response Requirements

ABA Formal Opinion 483 establishes clear obligations when a data breach occurs. Lawyers have a duty to monitor for breaches, stop and mitigate damage promptly, investigate what occurred, and notify affected clients. This duty arises from Rules 1.1 (competence), 1.6 (confidentiality), and 1.4 (communication).

The Opinion requires you to have a written incident response plan before a breach occurs. Your plan must identify who will coordinate the response, how you will communicate with affected clients (including backup communication methods if email is compromised), and what steps you will take to assess and remediate the breach. You must document what data was accessed, whether malware was used, and whether client information was taken, altered, or destroyed.

Notification to clients is mandatory when a breach involves material client confidential information. The notification must be prompt and include what happened, what information was involved, what you are doing in response, and what clients should do to protect themselves. This duty extends to former clients in many circumstances, as their files may still contain sensitive information subject to state data breach laws.

Three Security Domains: Personal, Practice, and Client Protection

Your Law Practice's Security
Under Rules 5.1 and 5.3, you must implement reasonable security measures throughout your firm. Conduct annual cybersecurity risk assessments. Require MFA on all systems. Implement data minimization principles—only share what vendors absolutely need. Establish incident response protocols before breaches occur. Your supervisory duties require you to ensure that all firm personnel, including non-lawyer staff, understand and follow the firm's security policies.

Client Security Obligations
Rule 1.4 requires you to keep clients reasonably informed, which includes advising them on security matters relevant to their representation. Clients experiencing sextortion need immediate, informed guidance. Preserve all threatening emails with headers intact. Document timestamps and demands. Advise clients never to pay or respond—payment confirms active monitoring and often leads to additional demands. Report incidents to the FBI's IC3 unit and local cybercrime divisions. For family law practitioners, understand that sextortion often targets vulnerable individuals during contentious proceedings. Criminal defense attorneys must recognize these threats as extortion, not embarrassment issues. Your competence under Rule 1.1 requires you to understand these threats well enough to provide effective guidance.

Personal Digital Hygiene
Your personal email account is your digital identity's master key. Enable MFA on all professional and personal accounts. Use unique, complex passwords managed through a password manager. Consider pseudonymous email addresses for sensitive subscriptions. Separate your litigation communications from personal browsing activities. The STOP framework applies: Slow down, Test suspicious contacts, Opt out of high-pressure conversations, and Prove identities through independent channels. Your personal security failures can compromise your professional obligations under Rule 1.6.

Practical Implementation Steps

THere are five Practical Implementation Steps lawyers can do today to get their practice cyber compliant!

First, conduct a technology audit to map every system that stores or accesses client information. Identify all third-party vendors and assess their security practices against industry standards.

Second, implement MFA across all systems immediately—this is one of the most effective and cost-efficient security controls available.

Third, develop written security policies covering password management, device encryption, remote work procedures, and incident response.

Fourth, train all firm personnel on these policies and conduct simulated phishing exercises to test awareness.

Fifth, review and update your engagement letters to include technology provisions and breach notification procedures.

Conclusion

The PornHub breach is not an isolated incident—it is a template for how modern attacks occur through third-party vendors. Your ethical duties under ABA Model Rules require proactive cybersecurity measures, not reactive responses after a breach. Technology competence under Rule 1.1, confidentiality protection under Rule 1.6, supervisory responsibilities under Rules 5.1 and 5.3, and breach response obligations under Formal Opinion 483 together create a comprehensive framework for protecting your practice and your clients. Cybersecurity is no longer an IT issue delegated to consultants; it is a core professional competency that affects your license to practice law. The time to act is before your firm appears in a breach notification headline.

🧪🎧 TSL Labs Bonus Podcast: Open vs. Closed AI — The Hidden Liability Trap in Your Firm ⚖️🤖

Welcome to TSL Labs Podcast Experiment. 🧪🎧 In this special "Deep Dive" bonus episode, we strip away the hype surrounding Generative AI to expose a critical operational risk hiding in plain sight: the dangerous confusion between "Open" and "Closed" AI systems.

Featuring an engaging discussion between our Google Notebook AI hosts, this episode unpacks the "Swiss Army Knife vs. Scalpel" analogy that every managing partner needs to understand. We explore why the "Green Light" tools you pay for are fundamentally different from the "Red Light" public models your staff might be using—and why treating them the same could trigger an immediate breach of ABA Model Rule 5.3. From the "hidden crisis" of AI embedded in Microsoft 365 to the non-negotiable duty to supervise, this is the essential briefing for protecting client confidentiality in the age of algorithms.

In our conversation, we cover the following:

  • [00:00] – Introduction: The hidden danger of AI in law firms.

  • [01:00] – The "AI Gap": Why staff confuse efficiency with confidentiality.

  • [02:00] – The Green Light Zone: Defining secure, "Closed" AI systems (The Scalpel).

  • [03:45] – The Red Light Zone: Understanding "Open" Public LLMs (The Swiss Army Knife).

  • [04:45] – "Feeding the Beast": How public queries actively train the model for everyone else.

  • [05:45]The Duty to Supervise: ABA Model Rules 5.3 and 1.1[8] implications.

  • [07:00] – The Hidden Crisis: AI embedded in ubiquitous tools (Microsoft 365, Adobe, Zoom).

  • [09:00] – The Training Gap: Why digital natives assume all prompt boxes are safe.

  • [10:00] – Actionable Solutions: Auditing tools and the "Elevator vs. Private Room" analogy.

  • [12:00] – Hallucinations: Vendor liability vs. Professional negligence.

  • [14:00] – Conclusion: The final provocative thought on accidental breaches.

RESOURCES

Mentioned in the episode

Software & Cloud Services mentioned in the conversation

MTC: The Hidden Danger in Your Firm: Why We Must Teach the Difference Between “Open” and “Closed” AI!

Does your staff understand the difference between “free” and “paid” aI? Your license could depend on it!

I sit on an advisory board for a school that trains paralegals. We meet to discuss curriculum. We talk about the future of legal support. In a recent meeting, a presentation by a private legal research company caught my attention. It stopped me cold. The topic was Artificial Intelligence. The focus was on use and efficiency. But something critical was missing.

The lesson did not distinguish between public-facing and private tools. It treated AI as a monolith. This is a dangerous oversimplification. It is a liability waiting to happen.

We are in a new era of legal technology. It is exciting. It is also perilous. The peril comes from confusion. Specifically, the confusion between paid, closed-system legal research tools and public-facing generative AI.

Your paralegals, law clerks, and staff use these tools. They use them to draft emails. They use them to summarize depositions. Do they know where that data goes? Do you?

The Two Worlds of AI

There are two distinct worlds of AI in our profession.

First, there is the world of "Closed" AI. These are the tools we pay for - i.e., Lexis+/Protege, Westlaw Precision, Co-Counsel, Harvey, vLex Vincent, etc. These platforms are built for lawyers. They are walled gardens. You pay a premium for them. (Always check the terms and conditions of your providers.) That premium buys you more than just access. It buys you privacy. It buys you security. When you upload a case file to Westlaw, it stays there. The AI analyzes it. It does not learn from it for the public. It does not share your client’s secrets with the world. The data remains yours. The confidentiality is baked in.

Then, there is the world of "Open" or "Public" AI. This is ChatGPT. This is Perplexity. This is Claude. These tools are miraculous. But they are also voracious learners.

When you type a query into the free version of ChatGPT, you are not just asking a question. You are training the model. You are feeding the beast. If a paralegal types, "Draft a motion to dismiss for John Doe, who is accused of embezzlement at [Specific Company]," that information leaves your firm. It enters a public dataset. It is no longer confidential.

This is the distinction that was missing from the lesson plan. It is the distinction that could cost you your license.

The Duty to Supervise

Do you and your staff know when you can and can’t use free AI in your legal work?

You might be thinking, "I don't use ChatGPT for client work, so I'm safe." You are wrong.

You are not the only one doing the work. Your staff is doing the work. Your paralegals are doing the work.

Under the ABA Model Rules of Professional Conduct, you are responsible for them. Look at Rule 5.3. It covers "Responsibilities Regarding Nonlawyer Assistance." It is unambiguous. You must make reasonable efforts to ensure your staff's conduct is compatible with your professional obligations.

If your paralegal breaches confidentiality using AI, it is your breach. If your associate hallucinates a case citation using a public LLM, it is your hallucination.

This connects directly to Rule 1.1, Comment 8. This represents the duty of technology competence. You cannot supervise what you do not understand. You must understand the risks associated with relevant technology. Today, that means understanding how Large Language Models (LLMs) handle data.

The "Hidden AI" Problem

I have discussed this on The Tech-Savvy Lawyer.Page Podcast. We call it the "Hidden AI" crisis. AI is creeping into tools we use every day. It is in Adobe. It is in Zoom. It is in Microsoft 365.

Public-facing AI is useful. I use it. I love it for marketing. I use it for brainstorming generic topics. I use it to clean up non-confidential text. But I never trust it with a client's name. I never trust it with a very specific fact pattern.

A paid legal research tool is different. It is a scalpel. It is precise. It is sterile. A public chatbot is a Swiss Army knife found on the sidewalk. It might work. But you don't know where it's been.

The Training Gap

The advisory board meeting revealed a gap. Schools are teaching students how to use AI. They are teaching prompts. They are teaching speed. They are not emphasizing the where.

The "where" matters. Where does the data go?

We must close this gap in our own firms. You cannot assume your staff knows the difference. To a digital native, a text box is a text box. They see a prompt window in Westlaw. They see a prompt window in ChatGPT. They look the same. They act the same.

They are not the same.

One protects you. The other exposes you.

A Practical Solution

I have written about this in my blog posts regarding AI ethics. The solution is not to ban AI. That is impossible. It is also foolish. AI is a competitive advantage.

* Always check the terms of use in your agreements with private platforms to determine if your client confidential data and PII are protected.

The solution is policies and training.

  1. Audit Your Tools. Know what you have. Do you have an enterprise license for ChatGPT? If so, your data might be private. If not, assume it is public.

  2. Train on the "Why." Don't just say "No." Explain the mechanism. Explain that public AI learns from inputs. Use the analogy of a confidential conversation in a crowded elevator versus a private conference room.

  3. Define "Open" vs. "Closed." Create a visual guide. List your "Green Light" tools (Westlaw, Lexis, etc.). List your "Red Light" tools for client data (Free ChatGPT, personal Gmail, etc.).

  4. Supervise Output. Review the work. AI hallucinates. Even paid tools can make mistakes. Public tools make up cases entirely. We have all seen the headlines. Don't be the next headline.

The Expert Advantage

The line between “free” and “paid” ai could be a matter of keeping your bar license!

On The Tech-Savvy Lawyer.Page, I often say that technology should make us better lawyers, not lazier ones.

Using Lexis+/Protege, Westlaw Precision, Co-Counsel, Harvey, vLex Vincent, etc. is about leveraging a curated, verified database. It is about relying on authority. Using a public LLM for legal research is about rolling the dice.

Your license is hard-earned. Your reputation is priceless. Do not risk them on a free chatbot.

The lesson from the advisory board was clear. The schools are trying to keep up. But the technology moves faster than the curriculum. It is up to us. We are the supervisors. We are the gatekeepers.

Take time this week. Gather your team. Ask them what tools they use. You might be surprised. Then, teach them the difference. Show them the risks.

Be the tech-savvy lawyer your clients deserve. Be the supervisor the Rules require.

The tools are here to stay. Let’s use them effectively. Let’s use them ethically. Let’s use them safely.

MTC