# Shadow Ai Studi Legali Segreto Professionale **Source:** https://lanpartners.com/en/blog/shadow-ai-studi-legali-segreto-professionale **Language:** English --- # AI and professional secrecy: how to avoid the hidden risks of Shadow AI in law firms ![shadow AI law firms](https://www.lanpartners.com/wp-content/uploads/2026/08/Lanpartners_Shadow_AI_Cover.jpg) ### Summary - Why AI is entering law firms - What is Shadow AI - What data should not be entered into a public chatbot - The Heppner case and the Warner case: what US jurisprudence teaches - GDPR, professional secrecy and firm liability - How to evaluate a LegalTech AI platform - Technical requirements: DPA, access, retention, logs, and training - The role of Lanpartners and IT CONCIERGE® - Final checklist for the law firm - FAQ on AI in law firms - Is it possible to use ChatGPT or other public chatbots in the law firm? - Does simply publishing data online allow it to be included in a chatbot? - Is a LegalTech platform automatically GDPR compliant? - What checks must a firm perform before adopting an AI platform? - Can AI replace the lawyer's review? - Has your firm already adopted AI tools? Law firms face the daily challenge of balancing the operational speed required by the analysis of large document volumes with the essential need to protect confidentiality and professional secrecy. In this scenario, the uncontrolled adoption of public chatbots risks exposing sensitive data, turning an efficiency tool into a potential point of vulnerability. In this article, we analyze the phenomenon of Shadow AI, the relationship between consumer tools and professional secrecy, and the lessons learned from the US cases Heppner and Warner. We will also examine what checks to perform before adopting a LegalTech AI platform and how Lanpartners can support the firm in evaluating the infrastructure, suppliers, and internal policies. ## **Why AI is entering law firms** The legal sector is undergoing a technological transformation which now concerns the daily operational efficiency of law firms, not just future prospects. Professionals today handle growing volumes of data: from e-discovery in large commercial litigation to due diligence in M&A transactions. In this context, AI significantly reduces the time needed to extract specific clauses, summarize technical documents, or prepare initial drafts of agreements. This urgency to adopt new tools has, however, anticipated, in many firms, **the development of adequate IT governance** . While steering committees discuss long-term strategies, employees often begin to use online tools independently to optimize their daily work. ## **What is Shadow AI** “Shadow IT” is defined as the use of technological devices, software, and services by employees without the approval or control of the IT department. With the spread of Large Language Models (LLMs), this phenomenon has taken on a more insidious form, known as “Shadow AI”. In the legal sector, an environment that is by definition sensitive, Shadow AI manifests itself, for example, when an associate or trainee copies parts of a confidential document and pastes them into the prompt of a public chatbot to obtain a summary or translation, effectively bypassing the firm's policies. ## **What data should not be entered into a public chatbot** The risk stems from the business model and technical architecture of general-purpose chatbots intended for the public. The terms of use of these tools often provide for the possibility of using the data entered to train the models or sharing them in certain contexts. Entering personal data, judicial data, or information covered by professional secrecy into a public chatbot may violate confidentiality obligations and data protection regulations when the processing has not been previously assessed, authorized, and protected. Once a confidential document is processed by these tools, the law firm risks losing control over its location, retention, and actual confidentiality. ## **The Heppner case and the Warner case: what US jurisprudence teaches** The issue of confidentiality in the man-machine relationship recently reached US courtrooms with two decisions showing how the jurisprudential framework is still in a consolidation phase. On November 4, 2025, during the arrest of Bradley Heppner (accused of fraud), the FBI seized documents reporting records of communications held by the defendant with the generative AI Claude, used to develop defensive arguments and evaluate strategic lines. The defense requested the exclusion of these documents from the trial, but on February 10, 2026, federal judge Jed Rakoff rejected the request, ruling that the conversations and materials produced through a public AI platform were protected neither by the attorney-client privilege nor by the work-product doctrine. This decision belongs to the US legal system and does not constitute a binding precedent for Italian courts, but it remains relevant because it highlights the procedural risks linked to the ungoverned use of consumer-based AI tools. The Heppner case does not establish that every use of artificial intelligence undermines professional secrecy; rather, it shows how a consumer platform, lacking any defensive mandate and a professional relationship with the user, can weaken or exclude confidentiality claims in a specific case. A different orientation emerges from Warner v. Gilbarco, Inc., decided around the same period: Michigan federal judge Anthony Patti recognized the protection of the work-product doctrine for certain documents that a party, defending itself pro se, had prepared with the aid of ChatGPT. The comparison between the two cases confirms that there is automatic rule linked to the simple use of a chatbot: what makes the difference are the context, the purpose, the confidentiality of the information entered, the platform chosen, and the methods by which the provider handles the data. ## **GDPR, professional secrecy and firm liability** The duty of confidentiality intertwines with the professional legal discipline, particularly with what is provided for by articles 13 and 28 of the Forensic Ethical Code, as well as with the applicable provisions on personal data protection. On these aspects, the most appropriate assessment remains the one conducted together with one's DPO and legal counsel: the objective of this article is not to delve into the interpretative merits of ethical rules, but to provide the firm with practical elements useful for asking the right questions when adopting AI tools. Regulation (EU) 2016/679 (GDPR) does not prohibit the use of AI, but requires careful evaluation of processing purposes, legal basis, privacy roles, security measures, and data minimization. Case files managed by a law firm may contain special categories of personal data pursuant to Article 9 of the GDPR, or data relating to criminal convictions and offenses governed by Article 10. Not all files necessarily contain both categories, but their potential presence requires a prior assessment of purposes, legal basis, and security measures. Transmitting this information to an AI platform therefore means clearly defining who assumes the role of Data Controller and who assumes the role of Data Processor, while at the same time verifying the guarantees offered by the provider. ## **How to evaluate a LegalTech AI platform** In our experience, **l AI can offer a valuable contribution to the law firm** , provided that it is adopted through robust governance and careful vendor evaluation. We recommend favoring specialized LegalTech platforms natively designed for the legal sector, because they tend to promote regulatory compliance and limit the risks typical of consumer solutions. Professional platforms differ from one another in terms of architecture and objectives: - **Harvey:** flagship tool for legal generative AI . The supplier contractually declares the prohibition of using customer data to train its own models, in accordance with the contractual conditions and configurations applicable to the service, and provides enterprise controls such as Single Sign-On (SSO), audit logs, and data lifecycle management. - **Lexroom, Legòra and Lybra:** these solutions offer features oriented toward research, document analysis, and drafting, with controls and configurations to be verified on a case-by-case basis in relation to the contract, the geographical processing area, and the chosen implementation model. ## **Technical requirements: DPA, access, retention, logs, and training** Before implementing an AI solution, the firm should verify some fundamental technical and contractual requirements: - **Data Retention and Training:** The contract and, where applicable, the Data Processing Agreement (DPA) must clarify whether prompts, outputs, and documents are used to train the models, how long they are retained, what technical logs and backups are maintained, the deletion methods, and which sub-suppliers can access them. - **Data localization:** when possible, it is preferable to choose providers and processing areas within the EEA. When platform servers are located outside the European Economic Area, it is essential to verify that the transfer is covered by Standard Contractual Clauses (SCC) or an adequacy decision, avoiding uncontrolled flows to jurisdictions lacking guarantees equivalent to the GDPR. - **Data Protection Impact Assessment (DPIA):** it is necessary to assess whether the processing presents a high risk to the rights of individuals and, when the conditions of Article 35 of the GDPR are met, to carry out a DPIA before starting the project. - **Access management:** it is advisable to adopt, where available and proportional to the risk, multi-factor authentication (MFA), Single Sign-On, and activity logging and monitoring systems to support accountability. - **Staff training:** The best policies and technical infrastructures lose effectiveness if there is a lack of awareness on the part of those who use them. Scheduling periodic training sessions on the risks of Shadow AI is essential to prevent accidental data leaks and protect the firm's professional secrecy. ## **The role of Lanpartners and IT CONCIERGE®** From our daily experience in the field with the IT CONCIERGE® service , we have understood that the adoption of AI in a law firm is not a mere software issue, but a delicate balance between innovation and the protection of professional secrecy. Lanpartners, backed by ISO/IEC 27001 certification for information security and over 25 years of supporting legal professionals, operates not merely as an IT supplier, but as a strategic partner that guides the firm through a structured governance journey. Our intervention focuses on a deep understanding of the specific needs of the practice, starting with a rigorous infrastructure audit and an accurate vendor assessment. Through IT CONCIERGE®, we implement internal policies and technical measures (such as access control and data segmentation) necessary to isolate AI activities from the risk of data leaks. In this context, our collaboration with platforms such as Lexroom stems from the search for solutions that combine technological excellence and a focus on compliance, adopting more controlled data retention policies, relevant ISO certifications, and architectures designed with GDPR and the new European AI regulatory framework in mind. ## **Final checklist for the law firm** Before adopting an AI tool, check these key points: ☐ Is there an internal policy on the use of AI? ☐ Have the tools already used by the staff been inventoried? ☐ Does the vendor formally state whether or not they use data for training? ☐ Are the DPA and the updated list of sub-suppliers available? ☐ Are accesses managed with SSO and MFA? ☐ Has it been defined who can upload documents and use specific AI features? ☐ Is it possible to apply different roles and permissions to users? ☐ Are activity logs kept and monitored? ☐ Has it been evaluated whether the processing requires a DPIA pursuant to Article 35 GDPR? ☐ Is there a procedure in place to report incidents, errors, or unauthorized use? ☐ Has the staff received practical instructions and training on the use of the tools? ☐ Is human control (human-in-the-loop) provided over the AI-generated outputs? ## **FAQ on AI in law firms** ### **Is it possible to use ChatGPT or other public chatbots in the law firm?** Yes, but only in compliance with internal policies and without entering confidential information, unnecessary personal data, or content covered by professional secrecy. Before authorizing its use, the law firm should verify the service conditions, data retention settings, potential use for model training, and the guarantees offered by the provider. The CCBE guide recommends particular caution when entering client-related data into generative AI systems. ### **Does simply publishing data online allow it to be included in a chatbot?** No. The fact that information is available online does not mean it can be used without further assessment. It is necessary to consider the purpose of the processing, the legal basis, the nature of the data, the data subject's expectations, and the terms of the platform used. The public nature of the data does not automatically eliminate the obligations set out by the GDPR or professional secrecy. ### **Is a LegalTech platform automatically GDPR compliant?** No. A platform designed for the legal sector may offer more suitable tools and guarantees compared to a consumer chatbot, but compliance also depends on the contract, configuration, privacy roles, storage methods, sub-suppliers, and procedures adopted by the firm. Therefore, it is necessary to conduct a vendor assessment and correctly define responsibilities, access controls, and security measures. ### **What checks must a firm perform before adopting an AI platform?** You should check at least: - If the data is used to train the models; - For how long are prompts, documents, outputs, and logs retained?; - Where is the data processed; - Which subcontractors can access it; - If DPA, MFA, SSO, RBAC, and audit logs are available; - How cancellations, incidents, and support requests are handled; - If the project requires a DPIA pursuant to Article 35 GDPR. These elements help to concretely assess the level of control, security, and traceability of the solution. ### **Can AI replace the lawyer's review?** No. AI-generated outputs must be verified by a qualified professional before being used in a legal instrument, client communication, or legal research activity. The lawyer must check accuracy, completeness, up-to-date sources, potential errors, and compliance with the procedural context: human oversight remains essential even when the platform uses specialized legal sources. ### **Has your firm already adopted AI tools?** Book a consultation with us to evaluate infrastructure, vendors, policies, and usage methods. Discover how to integrate AI into your firm's workflows with greater control, security, and awareness, reducing the risks of Shadow AI. #### Related articles - IT Concierge: the people-driven partnership that turns technology into value - AI for law firms: why Lanpartners chose Lexroom as its technology partner - Managed IT Services for Law Firms and Notaries 2026 - Data Act 2025 and businesses: what changes for data sharing - AI Act 2026: what changes for Italian law firms and SMEs and how to prepare