CyberTRIZPEDIA

Generative AI Processing Convenience vs. Client Data Confidentiality

Permit client data use only in AI tools with contractually and technically verified no-retention, no-training configurations; anonymize inputs for all others.

CyberTRIZ analysis · LegalTech contradiction CP003 · one of 8,235 worked contradictions published by CyberTRIZ.AI

Regulations

Business Context

Using a generative AI tool to draft, summarize, or analyze documents containing client information is often the most convenient way to apply the tool’s capability to real legal work, and restricting the tool to only non-confidential, hypothetical inputs significantly reduces its practical usefulness. However, depending on the specific AI vendor’s data-handling and model-training practices, submitting client information to the tool can create genuine confidentiality risk, including the possibility, with certain tool configurations, that submitted information could influence future model outputs for other users.

Resolution

Rather than banning generative AI use on any client information or using it without regard to a vendor’s specific data-handling commitments, the resolution requires a documented, tool-specific confidentiality assessment confirming whether a given AI tool’s contractual and technical configuration prevents client data from being retained or used for model training, permitting client-data use only for tools that meet this standard, and restricting other tools to non-confidential or appropriately anonymized input.

Applicable TRIZ Principles

Principle 3 – Local Quality Apply differentiated confidentiality rules to different AI tools based on each tool’s specific, verified data-handling configuration.

Principle 10 – Prior Action Confirm a tool’s data-handling commitments before permitting client data use, rather than discovering the actual practice after submission.

Principle 24 – Intermediary Insert an anonymization or data-minimization step for tools that do not meet the required confidentiality standard.

Expected Outcome

Confidentiality protection calibrated accurately to each tool’s actual data-handling practices

Preserved practical usefulness of AI tools verified to meet the required standard

Reduced risk of client data being retained or used for training without authorization

Clearer institutional record of which tools are approved for which categories of client data

Decision Indicators

Early indicators that this contradiction is limiting organizational performance include:

No documented, tool-specific confidentiality assessment for AI tools processing client information

Attorneys using AI tools on client data with no verification of the vendor’s data-handling practices

A single confidentiality policy applied uniformly to all AI tools regardless of their actual configuration

No process for reassessing a tool’s confidentiality standing if the vendor changes its data practices

Client agreements silent on the categories of AI tools that may process their information

Monitoring these indicators helps firms use generative AI on client work without unknowingly compromising confidentiality.

TRIZ principles applied

P3 Local qualityP10 Preliminary actionP24 Intermediary

Controls that address this (22)