Skip to main content

Generative AI and professional secrecy: An ethics guide

How can generative AI be reconciled with professional secrecy? Professional-ethics obligations, CNB and CCBE recommendations, and a compliance checklist for lawyers

The rise of generative artificial intelligence is profoundly transforming the practice of regulated professions (lawyers, judges, notaries, chartered accountants, doctors, etc.). Legal research, drafting of legal documents, contract analysis, case-file summaries: use cases are multiplying and delivering significant productivity gains, but they also create major risks for confidentiality, privacy and professional secrecy.

This guide offers an operational framework for reconciling the impact of AI on the law with the ethical requirements binding on lawyers. It recalls the obligations to which they are subject, the data that must never be entered, the security measures to put in place and the main liability risks, based on the recent recommendations of the professional bodies.

Professional secrecy and generative AI

Professional secrecy is one of the pillars of the relationship of trust between a lawyer and their client — and, more broadly, between any regulated profession and the people it assists.

E.g. notaries, chartered accountants, medical professions. It imposes an absolute duty of confidentiality over information entrusted or discovered in the course of professional practice, the breach of which can lead to disciplinary, civil and criminal sanctions.

Generative AI is profoundly transforming professional practice, particularly in legal research, the drafting of legal documents, case-file summaries and contract analysis. These tools, capable of producing new content from simple prompts, deliver considerable time savings and efficiency gains — but at the cost of heightened risks for data confidentiality and professional secrecy.

The main risks stem from several converging factors:

  • the circulation of data through complex technical infrastructures (cloud, APIs, multiple subprocessors);

  • the difficulty, for the user, of verifying where the data is hosted, who accesses it and for what purposes;

  • the possibility that the data entered may be used to train or retrain (“fine-tune”) the models;

  • exposure to breaches of confidentiality or data leaks where unsecured or non-sovereign tools are used.

Generative AI can only be integrated into lawyers’ practice with caution, critical judgment and ethical vigilance: the tool must remain a mere assistant under the professional’s constant control, and must never substitute for their analysis.

Against this backdrop, reconciling generative AI with professional secrecy calls for a structured approach: understanding the risks, rigorously selecting legal tools (legal AI software), putting internal procedures in place, and adopting a genuinely ethics-driven approach to digital transformation.

Professional-ethics obligations in the face of generative AI

The professional-ethics rules applicable to lawyers make clear that the professional remains solely responsible for the decisions taken and the documents produced, including when using a generative AI tool. AI is neither a co-decision-maker nor a delegate of responsibility: it is merely a technical instrument.

The main ethical duties that must be observed when using generative AI are the following:

Responsibility and professional competence

The legal professional personally assumes responsibility for the engagement, so they must remain in command of their reasoning and verify the accuracy of the information produced by the AI as part of that responsibility.

The risks of factual errors and algorithmic hallucinations require systematic re-reading and human validation of generated content.

The duty of competence also entails understanding, at least in broad outline, how the tools used work, their limits, their biases and their level of security.

Professional secrecy and confidentiality

Entering personal data or privileged information into an unsecured tool is expressly identified as a breach of the duties of secrecy and discretion.

Lawyers must therefore make sure that AI tools offer strong guarantees of confidentiality, data sovereignty and non-reuse of the information transmitted.

Transparency and loyalty towards the client

Good ethical practice recommends informing clients of the legal and ethical risks involved in entering personal data or privileged documents into non-sovereign, freely accessible generative AI tools.

This information forms part of a logic of informed client consent, particularly where data concerning them could be processed by AI systems.

GDPR compliance

GDPR compliance is, of course, a key indicator of the robustness of a legal AI tool and of its resistance to cyberattacks.

Lawyers acting as data controllers must take care to engage only processors offering sufficient guarantees in terms of technical and organisational measures, in accordance with Article 28(1) of the GDPR.

Preserving critical thinking and independence

The texts stress the risk of losing critical distance and of impoverished intellectual reasoning if the professional relies excessively on the machine. AI must remain an assistance tool, and must never lead to an abdication of responsibility or to excessive standardisation of analyses and legal documents.

Categories of data incompatible with the use of generative AI

The professional-ethics recommendations converge on one clear principle: never enter any personal or confidential data into an unsecured tool.

The following are, in particular, incompatible with the use of a consumer-grade or non-sovereign generative AI:

  • data covered by professional secrecy (lawyer-client correspondence, case-file documents, litigation strategies, legal opinions, unsigned draft instruments, etc.);

  • clients’ personal data, in particular special categories of data (health data, political opinions, etc.) and data relating to criminal convictions and offences, whose uncontrolled disclosure could amount to a serious breach of the GDPR;

  • information that is strategic or sensitive for the firm or the company (financial data, restructuring plans, trade secrets);

  • any document or element likely to identify, directly or indirectly, a natural or legal person, where the tool does not guarantee robust pseudonymisation or anonymisation.

Conversely, the use of generative AI may be considered, subject to sufficient technical safeguards, for data that is:

  • already public (official texts, case law, published legal scholarship);

  • or properly anonymised, within secure RAG (Retrieval-Augmented Generation) systems or on-device solutions (local execution) that transmit no data to third parties. Pseudonymising data is also a valuable safeguard for limiting the risks of identification and of breaching professional secrecy.

The recommendations of the professional bodies

Several national and European institutions have published reference texts on the use of generative AI by justice professionals: guides, ethical charters and recommendations.

The recommendations of the Conseil national des barreaux (CNB)

In France, the Conseil national des barreaux (CNB, the French national bar council) has notably produced:

  • a practical guide on the use of generative AI systems (published 09/2024)

  • an analytical grid (Grille de lecture) of artificial intelligence tools (published 06/2025), which recalls what is at stake, proposes criteria for choosing legal AI tools and presents a comparison of the solutions audited.

The main guidelines emerging from this work can be summarised as follows:

Understand the issues and get trained

Professionals must train themselves in generative AI, its risks (bias, hallucinations, breaches of confidentiality) and the applicable legal framework (privacy, intellectual property, GDPR).

The CNB grid distinguishes two broad families of tools:

  • traditional legal publishers and LegalTech (legal research, legal AI, legal drafting software, legal review software);

  • tools plugged into the firm’s internal content (super-assistants, productivity AI);

  • The criteria for choosing among these solutions include:

  • data sovereignty (hosting in France or the EU, nationality of the hosting provider, absence of extraterritorial legislation such as the Cloud Act);

  • non-reuse of data for LLM training;

  • the possibility of full prior anonymisation or of installing the model locally (on-premise or on-device LLM);

  • the presence of a secure RAG to ring-fence the firm’s data.

The first requirement is, of course, confidentiality and security.

The recommendations of the Council of Bars and Law Societies of Europe (CCBE)

The Council of Bars and Law Societies of Europe (CCBE) has likewise produced its own guide on the use of generative artificial intelligence by lawyers. It recommends, in particular:

  • getting trained in how GenAI works, its limits and its risks (hallucinations, bias, black box, etc.).

  • systematically verifying outputs before any professional use whenever there is a risk for the client, the proceedings or a third party (legal content, citations, case law, document analysis);

  • understanding appropriate / inappropriate use cases and adjusting the level of control to the risk (exploratory research vs drafting documents submitted to the court);

  • attending the training offered by the bars and following their specific guidelines;

  • embedding GenAI in a structured internal policy (choice of tools, legal and security validation, quality-control procedures, incident management);

  • addressing AI-specific cybersecurity risks (enhanced phishing, prompt injection, data / model poisoning) and adapting technical and organisational measures.

Securing the use of generative AI in organisations bound by professional secrecy

For law firms, securing the use of generative AI is not just about choosing a high-performing tool: it means defining a framework of use that meets both professional-ethics requirements and clients’ expectations.

Secure technical architecture and secure RAG

The CNB recommends using secure RAG systems, combining an internal knowledge base (case files, templates, internal legal scholarship), an LLM that is not retrained on sensitive data, and reinforced security measures (encryption, segregation, access control).

  • Technical measures notably include:

  • encryption of data in transit and at rest (TLS/HTTPS, AES-256);

  • pseudonymisation and anonymisation of personal data before processing;

  • protective measures against attacks (firewalls, antivirus, intrusion-detection systems);

  • and logging and traceability of actions performed on the data.

Internal governance and security policies

The recommended organisational measures, for their part, aim to give the firm a clear, shared framework for the use of AI.

This means, on the one hand, structuring information security around rules inspired by good practice (notably the ISO 27001/27002 standards) and, on the other, embedding GDPR requirements concretely in the firm’s day-to-day operations (managing rights of access, rectification and erasure of data).

These measures also involve thinking upstream about the risks associated with personal data, through appropriate impact assessments, an ongoing effort to raise awareness and train teams, and the adoption of internal AI-use charters that explain in simple terms what is allowed, what must never be entered into the tools, how to validate outputs and how responsibilities are allocated.

Confidentiality agreements and oversight of processors

It should be noted that law firms must also frame their relationships with legal AI vendors contractually, with clear commitments on data confidentiality and security.

In practical terms, this means requiring that prompts not be durably retained — or, at the very least, that they be deleted quickly — and prohibiting any reuse of the firm’s or its clients’ data for model training.

The contract must also specify the guarantees offered as to hosting locations, any subprocessors, and security audit and certification arrangements (for example ISO 27001 or SOC 2).

Risks and grounds of liability

The use of artificial intelligence brings productivity benefits, but the price of those benefits is a set of major professional-ethics risks.

The use of AI by lawyers carries several risks that must be assessed holistically, as both the Conseil national des barreaux’s Règlement Intérieur National (RIN, the national rulebook of the French legal profession) and the same Council’s analytical grid on artificial intelligence point out.

The lawyer may be tempted to defer to the tool, forgetting that they remain solely responsible for the decisions and documents produced.

Such an abdication of responsibility, contrary to the essential principles of conscience, independence, competence and prudence, may engage their disciplinary liability.

Moreover, as the CNB’s analytical grid on AI points out, models trained on past data can reproduce or amplify stereotypes and discrimination, particularly in risk assessment and legal characterisation. This requires the lawyer to exercise critical control over the AI’s suggestions in light of the principles of equality and non-discrimination.

The work of the Conseil national des barreaux and of the Conseil supérieur de la magistrature (the French High Council for the Judiciary) also stresses the risk of factual errors and algorithmic hallucinations.

Producing false statutory or case-law references exposes the professional to professional misconduct if they reuse them without verification.

The duty of competence, as interpreted by the RIN, therefore requires systematically verifying the sources cited and never settling for a simple copy-paste of AI outputs.

Added to this are risks of breaches of confidentiality and of professional secrecy where confidential data is entered into an unsecured tool. The CNB’s recommendations identify this as a potential breach of the duties of secrecy and discretion, which can lead to disciplinary sanctions.

The risks of data leaks, cyberattacks or requisition by foreign authorities are heightened when data is hosted outside the EU — echoing the warnings issued by the CNB on digital sovereignty and data localisation.

Massive, uncontrolled use of AI can also lead to a loss of critical thinking and an impoverishment of reasoning, resulting in standardised legal output and reduced legal creativity.

The Conseil national des barreaux insists, in this respect, on the need to preserve the lawyer’s intellectual and strategic added value by avoiding any dependence on AI tools

These risks must be built into an overall risk assessment (legal, ethical, technical) and give rise to appropriate measures, whether that means choosing specialised tools, training teams on AI or carrying out regular audits.

The compliance instruments available for framing AI

Professionals already have a set of compliance instruments at their disposal for framing the use of generative AI.

These tools, mostly issued by the authorities and professional bodies, provide a frame of reference for assessing risks and defining good practice in order to select suitable technical solutions.

Ethics texts and official guides

Several professional-ethics texts and official guides now govern the use of generative artificial intelligence by judges and lawyers. At European level, the European Ethical Charter on the Use of Artificial Intelligence in Judicial Systems (CEPEJ, 2018) and the work of the Council of Europe and the European Union (AI Act, framework convention) govern the use of AI in the justice system.

In France, several judicial and professional institutions have adopted reference texts. The joint advisory council on ethics in judge-lawyer relations (Conseil consultatif conjoint de déontologie de la relation magistrats-avocats) has set a minimum core of good practice for the use of generative AI, based on human supervision, ethical vigilance, bias prevention, protection of privilege and keeping AI as a mere assistance tool.

At European level, the European Ethical Charter on the Use of Artificial Intelligence in Judicial Systems (CEPEJ, 2018) and the work of the Council of Europe and the European Union (AI Act, framework convention) govern the use of AI in the justice system.

In France, several judicial and professional institutions have published recent reference texts.

In addition, the Conseil consultatif conjoint de déontologie de la relation magistrats-avocats has defined good practice for the use of generative AI, based on reinforced human supervision and constant ethical vigilance, so that AI remains a mere assistance tool.

For the legal profession, the Conseil national des barreaux has adopted several structuring instruments:

  • a practical guide on the use of generative artificial intelligence systems (September 2024);

  • an analytical grid of generative artificial intelligence tools (June 2025)

They explain how lawyers can familiarise themselves with generative artificial intelligence (GenAI) and propose operational criteria for choosing tools (data sovereignty, confidentiality, security, reliability).

At European level for the legal profession, the CCBE published in 2025 a guide on the use of generative artificial intelligence by lawyers, which ties these uses back to the profession’s essential principles (confidentiality, competence, independence, loyalty, dignity and honour of the profession).

Taken together, these texts and the profession’s internal ethics rules — notably the CNB’s Règlement Intérieur National — form a compliance baseline that enables professionals to define a generative-AI usage policy that respects their ethical obligations as well as data protection.

Standards and certifications

Many legal AI solutions highlight compliance programmes, in particular the ISO 27001 information-security standard, sometimes supplemented by other frameworks such as ISO 27017 (cloud security) or ISO 27018 (protection of personal data in the cloud).

They may also rely on codes of conduct for generative AI, internal ethical charters or sector labels (membership of “responsible AI” hubs or programmes).

Some vendors also highlight structured GDPR-compliance programmes. E.g. audits by the CNIL (the French data-protection authority), support from the authorities, “zero data retention” policies, certified hosting providers located in the European Union.

Taken together, these instruments give lawyers concrete benchmarks for assessing regulatory compliance, the confidentiality guarantees offered by AI tools and the conditions for integrating them into their practice.

Examples of the professional recommendations in action

The professional-ethics recommendations are not merely theoretical: they are already reflected in the design and deployment of several AI tools specialised for lawyers and in-house counsel.

Today the imperative is clear: to promote, as far as possible, better AI practice in the field of law.

Solutions such as Doctrine, Lexbase, Lamyline and Predictice offer legal research, decision summarisation, memo generation and document analysis features, relying on:

  • LLMs hosted on European infrastructure (Microsoft Azure, AWS, OVH);

  • commitments not to reuse data for model training;

  • segregated environments, with zero data retention or rapid deletion of prompts;

  • secure RAG mechanisms combining LLMs with proprietary or official document databases.

These tools illustrate how legal AI can be integrated into daily practice while respecting professional secrecy and the GDPR.

In addition, the Jimini solution positions itself as a copilot for legal professionals, offering:

  • Sourced analysis of large internal document bases, audits of high volumes of documents, and drafting assistance (contracts, court submissions, memos);

On the security front, Jimini operates hosting in France on certified infrastructure (Scaleway; ISO 27001, 27017, 27018, HDS):

  • 256-bit encryption of data at rest and in transit;

  • access control based on the principle of least privilege;

  • regular vulnerability testing;

  • ISO 27001 certification.

This example illustrates better AI practice: a tool designed from the outset to meet the requirements of professional secrecy, data sovereignty and regulatory compliance.

Other solutions such as Ordalie, Septeo Brain and Haiku illustrate the use of generative AI for:

  • bulk analysis of contracts and exhibits;

  • finding factual elements in large volumes of data;

  • generating summaries, comparison tables and multi-document syntheses;

  • connecting to document-management systems and firms’ internal databases.

These companies marketing legal AI software implement secure RAG, European hosting, advanced encryption mechanisms and codes of conduct on generative AI — a concrete translation of the practices recommended by the CNB and the professional-ethics bodies.

Ultimately, generative artificial intelligence is a powerful lever for technological innovation in law and for AI assistance for lawyers, provided it is embedded in a structured approach to regulatory compliance, data management and ethical vigilance.

The CNB’s guides, the ethical charters and the specialised legal AI solutions now offer a genuine practical guide to AI for professions bound by professional secrecy.

Operational checklist

  • Has an internal “generative AI” policy / charter been formalised, approved and communicated to all teams (lawyers, support staff, trainees)?

  • Have users been trained in how LLMs work, in RAG, and in the risks of hallucination, bias, loss of competence and abdication of responsibility?

  • Do the internal rules explicitly state what may / may not be entered into AI tools (data types, permitted and prohibited use cases)?

  • Has an “AI / compliance” lead (or committee) been identified to arbitrate sensitive questions and track developments in the texts (CNB, CCBE, CEPEJ, etc.)?

  • Prior check: is the data I am about to enter covered by professional secrecy (correspondence, case-file documents, strategy, draft instruments, etc.)?

  • Does the data include personal data, in particular special categories (health, political opinions, offences, etc.)?

  • If so, has the tool been expressly designated as “secure” and “sovereign” by the firm (rather than a consumer-grade or non-sovereign tool)?

  • Has robust pseudonymisation / anonymisation of the data been carried out before anything is sent?

  • Have I excluded anything that could directly or indirectly identify a natural or legal person where the tool does not offer sufficient guarantees?

  • Has the tool been validated by the firm beforehand (internal approved list, due diligence, DPO / CISO opinion)?

  • Is the tool suited to the use case (legal research, contract analysis, assisted drafting, case-file summarisation, etc.) and to the practice area concerned?

  • Does the vendor provide data-sovereignty guarantees (hosting in France/the EU, no Cloud Act exposure, location of the LLMs and databases)?

  • Does the tool rely on a secure RAG (no fine-tuning)?

  • Are data flows encrypted in transit (TLS/HTTPS) and at rest (AES-256 or equivalent)?

  • Does the firm control the encryption keys, or does it have sufficient contractual guarantees?

  • Are prompts and documents subject to a genuinely documented limited-retention policy (zero data retention or rapid deletion)?

  • Is access to the data by the vendor’s employees strictly controlled (authorisations, logging, audits)?

  • Are AI-specific cybersecurity measures in place (protection against prompt injection, data poisoning, enhanced phishing)?

  • Does the vendor hold relevant certifications (ISO 27001, 27017, 27018, HDS, SOC 2, etc.) and provide trust documentation (Trust Centre, security policy)?

  • Is the firm’s role clearly identified (controller / joint controller / processor) for the use case concerned?

  • Does a contract compliant with Article 28 GDPR govern the relationship with the vendor (clauses on purpose, duration, security, subprocessing, transfers outside the EU)?

  • Are any transfers of data outside the EU covered by appropriate safeguards (standard contractual clauses, BCRs, adequacy decision)?

  • Has an impact assessment been carried out for high-risk processing (sensitive data, large volumes, automated decisions)?

  • Is the client informed, where relevant, that generative AI tools are used in handling their matter, and of the associated risks (confidentiality, bias, errors)?

  • Are the conditions under which AI is used compatible with the contractual commitments made to the client (confidentiality, service level, deadlines)?

  • Have I critically re-read all generated content (analyses, draft documents, summaries) before any communication to the client, the opposing party or the court?

  • Have I systematically checked the references cited (legislation, case law, legal scholarship) to detect hallucinations or factual errors?

  • Is the legal reasoning adopted understandable, explainable and one I can stand behind before the client and the judge (no uncontrolled “black box”)?

  • Is an internal register of the AI tools used, the use cases and incidents (serious errors, leaks, unexpected behaviour) kept up to date?

  • Is an incident-management procedure defined and known (internal notification, CNIL, clients, bar, insurer)?

  • Is feedback from experience fed into regular updates of the AI charter, training and tool settings?

  • Is a periodic compliance audit (professional ethics, GDPR, security) of AI usage planned and carried out (internal or external)?

Join the legal professionals
of tomorrow.