AI for law firms · Guide
Is AI safe for law firms? What Australian firms should check first
Is AI safe for law firms? It can be, if the firm controls three things: which tool staff use and where it sends client data, what information goes into it, and who verifies the output before it reaches a client or a court. Australian regulators and courts already expect all three, so check them before anyone drafts with AI.
- By
- Elias
- Published
- Last reviewed
- Reading time
- 7 min read
Is AI safe for law firms to use at all?
AI can be used safely in a law firm, but the safety comes from the firm’s controls rather than the tool. The same assistant can be fine for suggesting how to structure a letter and wrong for summarising a subpoenaed bundle. What decides it is the plan and settings behind the tool, the information that goes in, and whether a lawyer verifies what comes out.
Australian regulators have not banned generative AI. The Law Society of New South Wales, the Legal Practice Board of Western Australia and the Victorian Legal Services Board and Commissioner published a joint Statement on the use of artificial intelligence in Australian legal practice that treats AI as one more tool lawyers must use within their existing duties: confidentiality, independent advice, competence and diligence, and fair costs. The rest of this guide turns those duties into checks.
What have Australian regulators and courts said about generative AI?
Three documents set the expectations for most Australian firms as at September 2026. None of them prohibits AI outright, and all of them put the responsibility on the practitioner rather than the vendor.
| Source | What it says | What it means for your firm |
|---|---|---|
| Joint regulators’ statement (NSW, WA and Victorian regulators) | Lawyers “cannot safely enter confidential, sensitive or privileged client information into public AI chatbots/copilots (like ChatGPT)”. Commercial tools need a careful review of contractual terms. | Personal AI accounts are out for client work. Business tools need a documented review of their terms. |
| NSW Supreme Court Practice Note SC Gen 23 (commenced 3 February 2025) | Gen AI must not generate the content of affidavits, witness statements or character references. Where it helps with written submissions, the author must verify that every citation exists, is accurate and is relevant, and not solely with an AI tool. Using Gen AI to prepare an expert report needs the court’s leave. | Litigation teams need a verification step, a file note, and a clear list of documents AI must not write. |
| OAIC guidance on commercially available AI products (21 October 2024) | As best practice, organisations should not enter personal information, particularly sensitive information, into publicly available generative AI tools. | A prompt containing client personal information is a use or disclosure under the Australian Privacy Principles. |
Other courts and tribunals have issued their own guidance, and the details differ. Check the current practice notes of every jurisdiction your litigators appear in, not only New South Wales.
Does using AI put confidentiality or privilege at risk?
It can. Depending on the terms and controls, entering client material into an AI service can amount to disclosing it to the provider, and the NSW practice note lists “the lack of adequate safeguards to preserve the confidentiality, privacy or legal professional privilege” of material given to a public chatbot as a known risk. Whether privilege survives in a particular case is a legal question for your firm, not something a vendor’s settings page can answer.
The practice note also gives a practical test for the most sensitive material. Information subject to suppression or non-publication orders or the Harman undertaking, material produced on subpoena, and material under a statutory publication ban must not be entered into a Gen AI program unless the practitioner is satisfied that it will stay within the platform’s controlled environment under confidentiality restrictions on the supplier, will be used only for that proceeding, and will not be used to train any model (paragraph 9A). Firms that never appear in the NSW Supreme Court can still adopt those three conditions as their minimum standard for any tool that touches client files.
Size does not change the professional duty. A firm with annual turnover of $3 million or less may fall outside the Privacy Act (OAIC), but the duty of client confidentiality in the conduct rules still applies.
Where does client data go when staff use AI?
It depends on the plan more than the brand. Personal and business plans from the same vendor handle data differently, and a business plan does not automatically mean local storage or processing. As at September 2026:
| Tool and plan | Trains on your content by default? | Location and retention |
|---|---|---|
| ChatGPT Free, Go, Plus, Pro | Yes, unless the user opts out | Stored “in the US and around the world”; deleted chats removed within 30 days |
| ChatGPT Business | No | Admins set retention; a storage-region choice is rolling out gradually; no Australian processing option |
| ChatGPT Enterprise | No | New workspaces can store content at rest in Australia; in-region processing is offered only in the US, Europe and the UAE |
| Claude Free, Pro, Max | The user chooses | Data kept up to five years if the user allows training; otherwise a 30-day retention period applies |
| Claude Team, Enterprise | No | Commercial terms apply; Enterprise adds custom retention controls |
| Microsoft Copilot (work accounts) | No | Stored with your Microsoft 365 content; Microsoft’s roadmap targets local processing in Australia for supported interactions in December 2026 |
Sources: OpenAI consumer data, OpenAI enterprise privacy, OpenAI data residency, Anthropic consumer terms, Claude plans, Microsoft Copilot privacy and Microsoft’s roadmap.
Storage and processing are separate questions, which is why data residency needs reading closely. Our guide to where ChatGPT stores your data covers each plan and the Australian options in detail.
How should lawyers verify AI output before relying on it?
Treat every AI output as a first draft from a capable but unreliable junior. Language models produce fluent, confident text that can be wrong, including hallucinated cases and legislative references, and the joint statement says no tool based on current models can be free of them. Verification is the lawyer’s job, and the NSW practice note says it cannot be done solely with another AI tool.
A workable routine for anything that leaves the firm:
- Extract every authority, section reference and quotation from the draft into a list.
- Open each one in an authorised report, the official legislation register or your research service, never in the tool that produced it.
- Check the proposition as well as the citation: the case must say what the draft claims, at the pinpoint given.
- Check every reference to evidence against the affidavit or transcript.
- Record on the file who verified the document and when.
- Bill for the work actually done. The joint statement expects charges to reflect real legal work, and AI should not push costs above traditional methods because of time spent correcting it.
What should a firm check before staff use AI?
Start with a decision about information, then choose tools to match. The aim is that every lawyer knows which tools are approved, for which tasks, and with which information.
- Find out what staff already use. Ask them, and check sign-in logs and browser extensions. Unapproved personal accounts are the gap to look for first.
- Approve specific tools on business plans. Personal ChatGPT or Claude accounts should not be used for firm work, because the individual, not the firm, controls their training and retention settings.
- Review the terms in writing. Cover training use, retention, human review by the vendor, sub-processors, and where data is stored and processed.
- Set the admin controls. Single sign-on, multi-factor authentication, retention periods and which connected apps are allowed. If you use Microsoft Copilot, note that Microsoft turns Anthropic’s models on by default for most commercial tenants outside the EU, EFTA and UK, and that those models are currently excluded from its in-country processing commitments (Microsoft Learn). Decide deliberately whether to keep them on.
- Classify your information. Define what may never go into a general AI tool: material under suppression orders or the Harman undertaking, subpoenaed documents, and the content of affidavits and witness statements.
- Write the policy. Set out which tools, who may use them, for what tasks and with what information, and how juniors are supervised. The joint statement recommends making it available to clients on request.
- Tell clients. Update engagement letters or client information so clients know when AI may be used on their matter and how it affects costs.
- Review every quarter. Vendor settings and plan names change often; Microsoft 365 Copilot, for example, is now called Microsoft Copilot.
When does a law firm need private AI rather than a business plan?
A firm needs private AI when its work regularly involves material that a shared service’s terms cannot cover to the partners’ satisfaction, or when it wants AI to answer from its own precedents with control over who sees what. Typical triggers are litigation material under court restrictions, clients whose contracts require local processing, and precedent banks that should not be uploaded piecemeal into a chat tool.
Our Private AI & Knowledge Assistants service is built for that case: a staff assistant and an “ask our documents” assistant, with client data stored in fully GDPR-compliant data centres, that answers from your precedents and cites its sources.
For example, a 25-lawyer firm might approve ChatGPT Enterprise for drafting and research that contains no client identifiers, and route discovery review and precedent questions through a private assistant. We compare the two in private AI vs ChatGPT for law firms, and explain the privacy rules in AI and the Australian Privacy Principles.
This is general information, not legal advice.
