How it worksPricingServicesDevicesAboutFree assessment

Find where AI pays off in your business, and prove the return. A Logicly company.

Product

  • How it works
  • Pricing
  • The assessment
  • Graft Devices

Company

  • Services
  • About
  • Contact

Industries

  • AI for law firms
  • AI for accountancy firms

Resources

  • Blog

Legal

  • Privacy
  • Terms
© Graftgraft.bot
  1. Home
  2. /Blog
  3. /Is ChatGPT confidential for lawyers? What happens to client data

Is ChatGPT confidential for lawyers? What happens to client data

Consumer ChatGPT is not private the way client work needs. What OpenAI does with what you type, whether it risks privilege, and the tier distinction that matters.

This is general information, not legal or regulatory advice, and Graft is not a law firm. For advice on your obligations under the SRA Standards and Regulations, and on privilege in any specific matter, speak to your COLP, COFA, or a qualified solicitor.

The short answer is no, not in the free consumer version, and not in the way a client matter requires. That does not make ChatGPT useless to a law firm. It means the confidentiality question turns entirely on which version you use and what you put into it, and most people have never checked either. This is a look at what actually happens to the text you type, and why the regulator is worried about it.

What happens to what you enter

On OpenAI's own account, the consumer versions of ChatGPT learn from your conversations by default. In its words, "ChatGPT... improves by further training on the conversations people have with it, unless you opt out," and "when you use our services for individuals such as ChatGPT... we may use your content to train our models." There is an opt-out in the privacy settings, and once set, new conversations are not used for training. But it is off by default, which means the default state of a personal ChatGPT account is that your inputs may feed the model.

Two details matter beyond training. First, opting out of training does not fully close the loop: if you submit feedback on a response, OpenAI says "the entire conversation associated with that feedback may be used to train our models." Second, your conversations are not sealed off from human eyes. OpenAI states that access extends to "authorized employees" and "specialized third-party contractors" who may review content to investigate abuse and misuse. For most uses that is unremarkable. For a confidential client file, it is the sort of processing you cannot consent to on the client's behalf without thinking hard about it.

The tier you use changes the answer

This is the distinction that gets lost. OpenAI treats its business products differently from its consumer ones. "By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API," it says, and on its enterprise privacy page adds that customers own their inputs and outputs and can control how long data is retained.

So "is ChatGPT confidential" has no single answer. A free account, training on by default, is one thing. A properly configured enterprise or API deployment, not trained on by default and with retention controls, is another. A firm that has not drawn that line, and has not checked which one its people are actually using, is not managing the risk. It is hoping.

The part no setting controls

Even the right tier does not put you fully in charge, because litigation can reach over the top of your settings. In May 2025, in the copyright case brought by The New York Times, a US court ordered OpenAI to preserve and segregate output log data that would otherwise have been deleted, including chats users had tried to delete. By OpenAI's own summary, that order reached "ChatGPT Free, Plus, Pro, and Team" and non-zero-retention API use, though not Enterprise or Edu.

That blanket order was lifted on 9 October 2025, so it is wrong to say ChatGPT chats are kept forever. But preservation continued for accounts the Times had flagged, and the flagged list could grow. The durable lesson survives the specifics: for roughly five months, whether your "deleted" ChatGPT conversations were truly deleted was decided by a third party's lawsuit, not by you or your client. Client data in a public tool sits inside someone else's legal exposure as well as your own.

Does it waive privilege?

This is the sharp end of the question, and it deserves a careful answer rather than a scary one. There is no English decision holding that putting client information into ChatGPT waives legal professional privilege. What there is, is a well-founded risk, and a regulator now flagging it.

Privilege in English law depends on a communication staying confidential. Lose the confidentiality and you can lose the privilege, and the Law Society warns that sharing client data with a third-party AI vendor needs careful thought precisely because "it may be possible that the generative AI provider can see all your inputs." The SRA's warning notice is where it lands hardest. It quotes the Upper Tribunal's description of the danger, that to put client letters "into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain," and states that using AI this way "will likely breach client confidentiality and as a result, legal professional privilege may be permanently waived and unable to be recovered."

Read the SRA's wording precisely. It says privilege "may be" waived, not that it always is. That hedge is doing honest work: this is a serious risk grounded in the confidentiality principle, not a settled rule with a case behind it. But "may be permanently waived and unable to be recovered" is not a risk a firm runs casually on a client's behalf.

It has already happened elsewhere

The pattern is not hypothetical. In 2023, Samsung banned employee use of ChatGPT after an engineer pasted sensitive internal source code into the tool. According to reporting in The Economist Korea, staff did so on three separate occasions within about 20 days of the company first allowing it. Samsung's concern was exactly the one that applies to a law firm: once data is on the provider's servers, there is no easy way to retrieve or delete it. Substitute a client's confidential file for source code and the problem is identical, with privilege added on top.

What a firm should actually do

Not ban it. A ban does not remove the risk; it moves the usage onto personal accounts where the training-on default is live and you have no visibility at all. The workable path is the opposite: give people a sanctioned route on a tier where inputs are not used for training, be clear about what may and may not go into any tool, and, above all, know where client data is currently going. You cannot set a sensible rule until you can see the real picture.

Where Graft fits

Graft connects to the systems your firm already runs on and reads how work actually flows, which surfaces where AI is being used and, critically, where client data is meeting public models. Instead of guessing whether the confidentiality risk is live in your firm, you see it, mapped to the matters and the data each use touches, and you get the record that shows you have it under control.

Graft's free connected assessment finds where AI is already at work in your firm by reading your real systems. For the fuller picture, read AI for law firms, or the companion pieces on shadow AI in law firms and hallucinated citations in court.