Disclaimer: this isn't legal advice and I'm not your lawyer. Attorney-client privilege is jurisdiction-specific and governed by your state's ethics rules. Talk to your state bar and your own counsel before you decide anything about AI tools and client information.

Every law firm conversation I have starts the same way. "Can we use cloud AI if we've got an NDA with the vendor?"

No. Not because NDAs are worthless. Because privilege is a rule of evidence, not a contract. Breaking it doesn't violate somebody's terms of service, it costs you the protection, and the protection was the entire point.

ABA Model Rule 1.6 and the Third-Party Disclosure Problem

Model Rule of Professional Conduct 1.6 requires lawyers to maintain confidentiality of client information. It's broad and it's strict. Secrets, strategies, plans, everything a client tells you in confidence for the purpose of obtaining legal advice. All of it.

Rule 1.6(a) does carve out space for disclosure when it's reasonably necessary to carry out the representation. Billing services, document management systems, paralegals, co-counsel. Client information has to leave the strictest vault of privilege sometimes, because the work demands it.

The operative word's "necessary." If you can do the work without the third-party disclosure, you must. Share unnecessarily and you've put privilege on the table.

Cloud AI is where that breaks down. Send client information to OpenAI, Claude, or any cloud service and you're disclosing to a third party that isn't your employee, isn't under your supervision, and isn't bound by your client retainer. The model processes data from millions of sources. Your specific query may touch systems in several countries.

Was that disclosure necessary? For most of the law firm workflows I've looked at, the honest answer's no. Local inference does the same job. The disclosure happens because the cloud's convenient, not because the work requires it.

ABA Formal Opinion 477R: The 2017 Ruling That Still Governs

In 2017 the ABA issued Formal Opinion 477R, addressing cloud-based legal services directly. It doesn't ban cloud use. It establishes conditions: the cloud provider has to be contractually bound by confidentiality and security obligations comparable to the lawyer's own, and the lawyer has to exercise reasonable supervision and due diligence over the provider.

That sounds workable, and it's a sensible opinion. Here's the catch sitting in the same document: the lawyer remains responsible for any breach by the cloud provider. If the vendor leaks, the client sues the lawyer and not the vendor, because the lawyer's the one who made the disclosure decision.

477R came out in 2017, before large language models existed. No major state bar has since clarified how it applies to AI systems that train on input data, that modify model behavior based on usage patterns, or that operate under terms of service explicitly reserving the right to use submissions for improvement. The legal terrain is moving, not settled, and not in law firms' favor.

Where State Bars Are Heading

California State Bar Opinion 2023-201 warns that lawyers must obtain informed client consent before using generative AI with client information. Informed consent means the client understands what the tool is, who operates it, where the data goes, and how it might be used. Ask most clients that question in plain language and they say no.

Through 2024, New York and several other states issued ethics opinions raising explicit concerns about AI use with privileged information. The emerging consensus is narrow: cloud AI with client data is permitted only with explicit client consent and demonstrable necessity.

Five years ago this was a gray area most firms quietly ignored. Now it's moving toward prohibition unless you meet strict conditions, and that trajectory isn't reversing.

Why Terms of Service Don't Fix This

A vendor's NDA isn't privilege protection. Here's the structural reason why.

Privilege governs whether a court will compel you to disclose information. If you've disclosed client information to a third party, even under a confidentiality agreement, a court may hold that privilege is waived. The information stops being protected.

A vendor's promise not to use your data doesn't restore it. It gives you a breach-of-contract claim if they break the promise. But the evidence has already been disclosed, and once it's disclosed a court can compel it.

Walk through the hypothetical. You send a client's sensitive tax strategy to a cloud AI under an NDA with the vendor. Two years later your client gets audited. The IRS subpoenas the chat history. The vendor deletes conversations daily, so nothing comes back. But if anything did, you've arguably waived privilege by sharing with a third party, NDA or not.

The NDA protects against a data breach. It doesn't protect against disclosure. Those are fundamentally different things.

How Privilege Breaks in Practice

Most privilege failures in law firms aren't intentional. They're casual. A partner wants to draft a motion faster, copies the complaint into a cloud chat, and nobody in the building's thinking about waiver. It's just convenient.

Then opposing counsel requests all communications related to the motion. Your firm discloses the chat history. Opposing counsel subpoenas the vendor's servers. The vendor says they don't retain conversation data, which may well be true, but the motion's now on the record as having been processed by a cloud system.

A sophisticated opposing counsel argues privilege was waived the moment you disclosed to a third party. Some courts will agree, particularly in jurisdictions that read privilege narrowly. Internal attorney strategy that was fully privileged an hour earlier is now potentially discoverable.

And the cost is potentially every communication connected to it, not just that one motion draft.

What Local Inference Changes

Run the model on your own server and the data never leaves your premises, so no third-party disclosure occurs and there's nothing to waive.

That's structural rather than theoretical. No confidentiality agreement to parse, no vendor terms of service to audit, no argument about whether the disclosure was "necessary." And the capability objection has quietly gone stale: open-weight models like DeepSeek V4-Flash handle drafting, research and first-pass analysis well enough that the tradeoff firms assumed they were making mostly isn't one anymore.

It doesn't relieve anybody of thinking carefully about how AI touches client data. You still need internal policy, staff training, and access controls. What it removes is the disclosure question, and the disclosure question's the one that hurts you in court.

Building Internal Policy Around Local AI

Even running locally, good practice wants structure.

Designate which matters can use AI assistance and which can't. Some firms treat it as internal support only, covering drafting, research and initial analysis, and keep it out of final client deliverables without explicit consent. Others permit it in client communications as long as the system isn't cloud-based.

Control access. Not every staff member should be able to query the most sensitive matters. Whatever interface your firm ends up sitting in front of, OpenWebUI or otherwise, it needs per-user permissions so you can restrict who reaches which models, and it needs to leave an audit trail behind it.

Establish retention. How long do conversation histories live, and who's allowed to retrieve them? Locally that's your decision to make. In the cloud, the vendor owns the answer.

Document your decisions. If you restrict AI use on a particular matter, record why. If you use it only in limited ways, record how. When a privilege question surfaces two years later, you want evidence that somebody thought it through.

Air-Gapping: When Maximalist Makes Sense

Some firms go further and run the hardware completely offline. No internet connection. No external API calls. Nothing leaves the network except physical mail.

That's overkill for most practices, and I'll say so in the room rather than sell you the bigger posture. For firms handling M&A, CFIUS matters, or client information that's itself a trade secret, it's entirely reasonable. And if your compliance posture says the box never touches the internet, then it never touches the internet, period.

The Client Consent Conversation

Even with local AI, consider getting explicit client consent. Most jurisdictions don't legally require it, but it's sound practice and it takes thirty seconds.

"We use local AI systems to assist with research, drafting, and analysis. The systems run on our own hardware, not cloud services. Your information stays on our network. Do you consent to this use?"

Most clients say yes. The consent letter goes in the file and becomes evidence of a firm that thought about it before it had to.

What I Won't Tell You Until I've Watched You Work

Here's where a vendor usually hands you a configuration. I won't, and it isn't modesty. I don't know your firm yet.

I don't know how your litigation paralegal builds a privilege log out of a Relativity export, reconciling every author and CC against the cast-of-characters list to prove the person on that line was acting as in-house counsel in that specific email. I don't know what your docketing specialist does with an incoming minute order, hand-deriving the deadline cascade off FRCP plus local rules plus that judge's standing order, with the malpractice exposure sitting right there in the arithmetic. I don't know which production your litigation support analyst is chasing because the .OPT and .DAT load files disagree on Bates ranges, or how many hours your billing coordinator loses reworking a LEDES file after the client's portal rejects it. That knowledge has been accumulating for fifteen or twenty years and it barely lives in the documentation.

So the sequence runs backwards from how this normally gets sold. I show up, sit down next to those people, and shut up until I understand the work the way they run it instead of the way the SOP describes it. Discovery turns up the use cases already sitting in the building. Only then do I recommend a stack, and what I recommend is whatever the work turned out to need. Then we deploy and configure it together on site, and I onboard the firm on the workflows and the agentic orchestration that fit how the practice really operates. That last part decides whether the thing's still in use a year after I've gone.

What You Should Do Right Now

If your firm's putting client information into cloud AI, stop. The risk isn't speculative anymore. State bars are issuing opinions. Courts have begun addressing privilege waiver in the context of AI use. The trend runs toward treating cloud disclosure as disclosure, full stop.

If you're considering it, don't. The convenience is real. So's the exposure, and only one of those shows up in a motion to compel.

If you're already running locally, document it. Train your staff. Build the audit trail. Be able to explain exactly why you chose local systems and how you manage access. My compliance briefs map the adjacent frameworks, from CLOUD Act exposure to what on-premises really involves.

And if you want to know what it'd look like inside your firm, start there, and I'll come to you.

Summary: Privilege is a rule of evidence, not a contract, so a vendor NDA can't restore what disclosure to a third party may already have waived. Model Rule 1.6 permits only the disclosure that's reasonably necessary, ABA Formal Opinion 477R leaves the lawyer responsible for the provider's breach, and California State Bar Opinion 2023-201 wants informed client consent first. Running inference on the firm's own hardware removes the disclosure question rather than arguing it.