Artificial intelligence is finding its way into everyday legal work, from research and drafting to document review. But as law firms expand their use of these tools, they are also having to address concerns like how to protect confidential client information when AI becomes part of the workflow.
Thomson Reuters’ 2026 Future of Professionals report found that among professionals across law, tax, audit, accounting, compliance, risk, and global trade worldwide, 34 percent reported using AI tools that their organisations had not sanctioned, highlighting the growing problem of ‘shadow AI’ within professional services.
At the same time, confidentiality has emerged as one of the central requirements for professional AI adoption. Ninety-six per cent of professionals surveyed in the report said AI should safeguard confidential data, while 94 percent wanted outputs grounded in authoritative content and 90 percent wanted explainable reasoning.
“There’s a gap between individual and institutional adoption. Lawyers are already using AI, sometimes with their firm’s blessing, but just as often on their own, with whatever tool gets the job done. If the firm doesn’t provide something official, people just find their own workarounds. When the firm’s only answer is a thick policy document, it’s already lost. Policies usually say “no,” but chatbots don’t, they make things easy,” said Gunjan Paharia, founder and managing partner at ZeusIP Advocates LLP.
Law firms are figuring out what information lawyers are permitted to put into these systems, where that information is processed and retained, who can access it and whether it can subsequently be used to train or improve an AI model.
Indian law firms are increasingly deploying AI across research, drafting, document review and transaction workflows, with firms adopting a mix of commercial platforms and customised systems.
International market trends suggest that as AI becomes more deeply embedded in legal workflows, global firms are heavily investing in the infrastructure development and safeguards around these systems, and not around the AI models alone.
Latham & Watkins has recently invested in its own Nvidia GPU servers and customised open-weight AI models, with data-centre infrastructure accessible only to its staff. The firm has more than 900 technology specialists, including machine-learning and AI engineers, software engineers and coding lawyers.
Freshfields has partnered with Anthropic to jointly develop AI tools for legal work and is also working with legal AI platforms including Harvey and Legora. The firm is among a growing group of global law firms investing in both commercial AI platforms and customised AI capabilities. Kirkland & Ellis has committed USD 500 million over the next three to four years to develop its own AI platform.
Confidentiality obligation remains unchanged
Legal professionals say use of AI has expanded the number of points at which confidential information can potentially leave a firm’s controlled environment.
“It is no longer simply, ‘Do you use AI?’ They want to know which tools are being used, for what purpose, whether their information is uploaded, where it is processed or retained, whether it can be used for model training, who has access to it, and what human review takes place,” said Ankit Sahni, partner at Ajay Sahni Associates.
“The underlying professional obligation has not changed. Confidentiality, privilege, competence and responsibility for the work product remain exactly where they were,” he added. “AI has changed the risk architecture around those obligations.”
“AI requires greater awareness of what and where information is being shared, with which tools, and under what safeguards. That is why policy, approved technology, training and responsible user behaviour all need to work together,” said Komal Gupta, chief innovation officer at Cyril Amarchand Mangaldas.
Indian law firms are increasingly responding by creating controlled environments in which client information can be processed.
Law firms are attempting to establish approved pathways for confidential information and it can include enterprise contracts with restrictions on data retention and model training along with internal access controls.
At Trilegal, Kirti Balasubramanian, partner at Trilegal said, “All AI usage using identifiable information only happens on Lucio, our internal AI tool, which ensures that data never leaves the Trilegal cloud, and is not used to train the model.”
“At Khaitan & Co, we simply don’t put client information, privileged communications or deal terms into any public AI or non AI tools. The AI we use sits within secure, enterprise environments, so client data stays within a controlled perimeter,” said Rohit Shukla, chief digital officer at Khaitan & Co..
Client demands are also contributing to the change.
“GCs and inhouse clients want to know what AI tools the law firms are using, where their data goes, and what audit trail is available. AI hasn’t changed our professional obligations. It has just made them much more visible and, in some ways, more difficult,” Shukla added.
IP data carries a different level of risk
The confidentiality question becomes considerably more weighted in intellectual property work, where information can have legal and commercial value precisely because it has not been disclosed.
“Unpublished patent applications, invention disclosures, trade secrets, and proprietary technical information warrant materially stricter treatment than routine confidential business information,” said Swati Sharma, partner and head – intellectual property at Cyril Amarchand Mangaldas.
“While all client information is considered confidential, unpublished inventions, trade secrets and proprietary technical information require a higher degree of care. Disclosure of such information can affect patent rights, compromise trade secret protection or expose commercially sensitive technology,” said Adheesh Nargolkar, partner at Khaitan & Co.
“Disclosure to an AI platform of a pending invention can trigger an independent, irreversible legal consequence: it may count as a ‘public disclosure’ that creates prior art capable of invalidating a later-filed patent claim,” Sharma added.
Sharma identified three principal areas of concern including potential loss of patent rights, loss of trade-secret protection and uncertainty around how AI platforms handle submitted information, including retention, training, human review and third-party access.
“Unpublished patent specs and invention disclosures are completely out until the client gives us written permission. That’s because their whole value comes from staying secret until they’re made public. For trade secrets that a client gave us under a specific NDA, we keep those out unless the agreement says third-party processors are allowed. And when it comes to foreign clients whose outside counsel guidelines say “no AI processing”, that’s final, no matter how secure our platform is. We follow the client’s rules. Bottom line: the tool has to be at least as private as the old locked filing cabinet,” Paharia added.
Clients are setting tighter rules for AI use
Clients of law firms are increasingly asking questions about how their counsel use AI, especially when matters involve sensitive IP or confidential information. The level of scrutiny varies, depending on the nature of the work, the information involved and the client’s own approach to AI.
“Clients increasingly expect disclosure and transparency about which AI tools are used, how they handle data, and what safeguards are in place,” Sharma said. She added that businesses are increasingly being advised to adopt written AI-use policies that govern what employees and external advisers can submit to AI tools. Such policies can also form part of the documented evidence of “reasonable measures” relevant to protecting trade secrets.
According to Paharia, some clients restrict the use of AI models based outside specified jurisdictions, while others require disclosure of AI use in invoices or work product. Some also prohibit AI use in matters involving unfiled inventions. “We just bake these restrictions into the engagement terms and set up the tool to enforce them automatically. That way, the system guards against mistakes instead of relying on a lawyer’s memory,” she said.
“We are seeing clients pay closer attention to how external counsel use AI when handling their confidential information. Some clients have specific AI policies or require prior approval before their information is processed using AI tools,” said Nargolkar.
“The choice of AI-usage is client dependent at the moment – and where clients do not have policies around the granular aspects of how legal services are provided to them, we use our professional judgment, and ensure oversight for all tasks – no matter how elementary,” said Balasubramanian.
“Lawyers and for that matter all of us want to adopt AI at the speed of a consumer app, download it, try it and start using it. But responsible adoption doesn’t work that way. We need governance, security, and clear guardrails around how the technology is used,” concluded Shukla. “The real challenge for large law firms is therefore finding that balance, moving fast enough to benefit from AI, but not so fast that we compromise the trust our clients place in us.”



