Generative AI Processing Convenience vs. Client Data Confidentiality
Permit client data use only in AI tools with contractually and technically verified no-retention, no-training configurations; anonymize inputs for all others.
CyberTRIZ analysis · LegalTech contradiction CP003 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Business Context
Using a generative AI tool to draft, summarize, or analyze documents containing client information is often the most convenient way to apply the tool’s capability to real legal work, and restricting the tool to only non-confidential, hypothetical inputs significantly reduces its practical usefulness. However, depending on the specific AI vendor’s data-handling and model-training practices, submitting client information to the tool can create genuine confidentiality risk, including the possibility, with certain tool configurations, that submitted information could influence future model outputs for other users.
Resolution
Rather than banning generative AI use on any client information or using it without regard to a vendor’s specific data-handling commitments, the resolution requires a documented, tool-specific confidentiality assessment confirming whether a given AI tool’s contractual and technical configuration prevents client data from being retained or used for model training, permitting client-data use only for tools that meet this standard, and restricting other tools to non-confidential or appropriately anonymized input.
Applicable TRIZ Principles
Principle 3 – Local Quality Apply differentiated confidentiality rules to different AI tools based on each tool’s specific, verified data-handling configuration.
Principle 10 – Prior Action Confirm a tool’s data-handling commitments before permitting client data use, rather than discovering the actual practice after submission.
Principle 24 – Intermediary Insert an anonymization or data-minimization step for tools that do not meet the required confidentiality standard.
Expected Outcome
Confidentiality protection calibrated accurately to each tool’s actual data-handling practices
Preserved practical usefulness of AI tools verified to meet the required standard
Reduced risk of client data being retained or used for training without authorization
Clearer institutional record of which tools are approved for which categories of client data
Decision Indicators
Early indicators that this contradiction is limiting organizational performance include:
No documented, tool-specific confidentiality assessment for AI tools processing client information
Attorneys using AI tools on client data with no verification of the vendor’s data-handling practices
A single confidentiality policy applied uniformly to all AI tools regardless of their actual configuration
No process for reassessing a tool’s confidentiality standing if the vendor changes its data practices
Client agreements silent on the categories of AI tools that may process their information
Monitoring these indicators helps firms use generative AI on client work without unknowingly compromising confidentiality.