Skip to main content
Secured AI - Protecting You in the AI Age
Legal AI Ethics

Can Lawyers Use ChatGPT with Client Data?

No, not with unmasked client data on a consumer ChatGPT account. OpenAI's own Data Controls FAQ states that consumer Free and Plus content is usable for model training unless you manually opt out, and ABA Formal Opinion 512 ties confidential inputs to informed client consent. Enterprise tiers change the data handling, and masked prompts change what leaves your machine at all. Here is the evidence, case by case.

August 26, 20269 min read

TL;DR

Consumer ChatGPT and client confidences do not mix by default. OpenAI's consumer terms permit training on your prompts unless you opt out, courts have sanctioned lawyers for unverified AI output at a rising pace, and ComplexDiscovery counts $145,000 in AI-citation sanctions in Q1 2026 alone. The workable middle ground is a sanctioned tool plus prompt-level masking, so client identifiers never leave the device in the first place.

The Short Answer

The question splits in two, and both halves have documented answers. The first half is data handling: what happens to the text after a lawyer pastes it into the box. That depends entirely on which ChatGPT tier is in use, and OpenAI publishes the difference itself. The second half is professional responsibility: what the ethics rules say about putting information relating to a representation into a third-party model at all.

On the first half, the OpenAI Help Center's Data Controls FAQ draws a hard line between consumer accounts and business accounts. On the second half, the American Bar Association issued Formal Opinion 512 in July 2024, and it conditions confidential inputs on informed client consent. Neither half is ambiguous. What varies is what firms have actually built to close the gap, which is where most of the risk now lives. The broader phenomenon of staff using unsanctioned tools is covered in our shadow AI overview.

One distinction worth drawing early: the sanctions that make headlines are about fabricated citations, not leaked confidences. Confidentiality failures rarely reach a court order, because nobody sees a prompt leave a laptop. That asymmetry is exactly why this question deserves a precise answer rather than a wave of the hand.

What Courts Have Actually Done

Start with the case everyone knows. In Mata v. Avianca, Inc., decided in the S.D.N.Y. on 22 June 2023, Judge P. Kevin Castel sanctioned plaintiff's counsel $5,000 after they submitted a brief containing multiple fake case citations with fabricated quotes generated by ChatGPT, then kept defending the citations after the court and opposing counsel could not locate them.

The court's own framing matters as much as the dollar figure. As Seyfarth Shaw noted in its analysis, the judge explicitly stated the attorneys were not sanctioned merely for using ChatGPT as a research tool. They were sanctioned for failing to verify the output and for standing behind fabricated cases after being challenged. The operative failure was unverified AI output entering a court filing.

The pattern has since hardened. On 28 May 2025, in the S.D. Indiana case Mid Central Operating Engineers Health & Welfare Fund v. HoosierVac LLC, Bloomberg Law reported that Judge James Patrick Hanlon sanctioned attorney Rafael Ramirez $6,000 for filing briefs with AI-fabricated citations. The recommending magistrate judge had proposed $15,000 and wrote that "prior sanctions assessed against attorneys who've made AI-related errors have evidently failed to act as a deterrent."

The appellate courts have now joined in. In Whiting v. City of Athens, the Sixth Circuit sanctioned two attorneys for filing briefs with "over two dozen fake citations and misrepresentations of fact," as covered by the Sixth Circuit Appellate Blog. The attorneys were ordered to reimburse the appellees' full reasonable attorney fees on appeal, pay double appellate costs, and each personally pay $15,000 in punitive sanctions to the court registry.

The aggregate picture is the part firm leadership should sit with. ComplexDiscovery counted a combined $145,000 in sanctions tied to AI-generated fake citations in Q1 2026 alone, and researchers had documented 1,313 court proceedings involving AI-generated content submitted to courts as of April 2026, with 496 involving licensed attorneys.

Read together, these decisions say one thing clearly: courts have lost patience with unverified AI output. They say nothing directly about confidentiality, because a pasted client fact pattern does not surface in a docket the way a fake citation does. The confidentiality exposure is quieter, and it runs through the vendor's data pipeline rather than the courtroom.

Consumer vs Enterprise: What OpenAI Does with Your Data

The single most useful document for answering this article's title is OpenAI's own Data Controls FAQ, because it states the defaults in plain terms.

For ChatGPT Team, ChatGPT Enterprise, and API Platform accounts, OpenAI does not train on business inputs and outputs by default. Those products carry a contractual Data Processing Addendum prohibiting training use. Standard retention is up to 30 days for abuse monitoring, and Zero Data Retention is available only under Enterprise Agreements.

Consumer Free and Plus accounts have the opposite default. Content is usable for model training unless the user manually opts out via account data controls, and the 30-day retention for safety review still applies regardless of the training opt-out. That last clause is the one firms most often miss: opting out of training does not opt you out of retention.

This is why the question "can lawyers use ChatGPT?" cannot be answered without a follow-up question: which tier, under whose account, with what contractual terms? A lawyer on a personal Plus account and a lawyer on a firm Enterprise seat are having two very different data experiences with the same interface. The wider architecture questions around sanctioned deployments are covered in our piece on enterprise AI for regulated industries. What the ethics rules add on top is the subject of the next section.

The Masked Prompt Path

Between "ban it" and "let everyone paste freely" sits a third option that changes the question entirely: mask the identifiers before the prompt leaves. A lawyer asking a model to tighten the structure of a deposition outline does not need the witness's real name in the request. A model can summarize the shape of a contract dispute without the matter number, the opposing party, or the settlement figures. Most drafting and analysis tasks survive redaction well, because their difficulty is structural, not personal.

Done by hand, masking is unreliable under deadline pressure, which is why the interesting version of this path is masking that happens automatically, on the device, before the request is transmitted. Combined with a business-tier account and its no-training default, a masked prompt means the model receives a question about "the client" rather than a named client, and there is nothing client-identifying to retain, train on, or expose.

Two practical notes for firm leadership. First, this path only works if staff actually use it, which is a detection and alternatives problem as much as a tooling problem. We cover the signals in how to detect shadow AI and, for the legal-sector deep dive, in shadow AI in law firms and what to do next. Second, if you are weighing approaches, our comparison of approaches to shadow AI at law firms lays the options side by side. For how this applies to legal workflows specifically, see Secured AI for legal teams.

Where Secured AI Fits

Secured AI implements the masked prompt path. It sits between the user and the model, and it detects and masks identifiers, including names, dates of birth, account and record numbers, contact details, and custom patterns, on the device before the prompt leaves. When the response comes back, real values are restored locally. Identifiers are held in a zero-knowledge vault, and the master key is never stored server-side.

For law firm use, its legal data detection covers client names, matter numbers, case names, opposing parties, witness names, contract terms, and settlement details. It works with OpenAI and DeepSeek, requires no behaviour change for staff, and supports matter-level policies and role-based access. Its usage logging is deliberately honest about what it is: a record of what left and what was masked. The product is built with compliance-focused architecture, and how any firm deploys it in light of its ethical duties is, as throughout this article, a question for that firm's ethics counsel.

Frequently Asked Questions

Has a lawyer actually been sanctioned for using ChatGPT?
Yes, in several documented cases. The best known is Mata v. Avianca in the Southern District of New York, and courts have kept imposing sanctions since, including a Sixth Circuit decision ordering punitive payments from two attorneys. The courts' stated rationale in these decisions is the failure to verify AI output before filing, not the use of AI itself.
Does ChatGPT train on the client data lawyers paste into it?
On consumer Free and Plus accounts, yes, by default, unless the account owner manually opts out through OpenAI's data controls. OpenAI's Data Controls FAQ also describes a safety-review retention window that applies even after opting out. Team, Enterprise, and API accounts carry a contractual Data Processing Addendum that prohibits training on business inputs and outputs by default.
Is ChatGPT Enterprise different from consumer ChatGPT for confidentiality?
Yes, in how data is handled. OpenAI's Data Controls FAQ states that Team, Enterprise, and API accounts do not train on business content by default and operate under a Data Processing Addendum, while consumer accounts train on content unless the user opts out. Ethical duties under the Model Rules apply regardless of tier. How your firm uses any tier is a question for your ethics counsel.
Do I need client consent before using ChatGPT on a matter?
ABA Formal Opinion 512 states that lawyers should obtain informed client consent before inputting information that could reveal confidential details into a generative AI tool, unless an exception to Model Rule 1.6 applies. Whether consent is needed in a specific matter, and what that consent should cover, is a question for your ethics counsel.
What is a masked prompt, and how does it work?
A masked prompt is one where identifiers are replaced before the request is sent to the model. Secured AI detects and masks identifiers such as names, dates of birth, account and record numbers, contact details, and custom patterns on the device, then restores the real values locally when the response returns. The model works on the structure of the question, not the client's identifying details.

Keep the speed. Change what leaves.

Secured AI masks client identifiers on the device before a prompt reaches any model, restores them locally, and keeps a record of what left and what was masked. See how it works for legal teams.