Published on

Why Lawyers Fear the Chatbot More Than the Cloud Drive

Authors
AI chatbots, cloud storage, and attorney confidentiality

Lawyers have gotten comfortable storing confidential client files in the cloud. OneDrive, Google Drive, Dropbox, practice-management vaults—ordinary tools. Ethics guidance has largely treated that as fine when the lawyer uses reasonable care: pick the provider, understand the security model, limit access, and supervise the vendor.1

Consumer chatbots landed differently. Paste a client name, a deal term, a litigation theory, or a draft email into a public generative AI tool, and the room goes quiet. The instinct is often: that might breach confidentiality—or worse, privilege.

The tension is volume inverted. With a chatbot you might share a fragment; with a drive you might upload the entire file. Yet the panic lands on the chat. Not because cloud storage is magically “inside” the attorney-client relationship. Both involve third-party systems. The better answer is that confidentiality ethics and privilege doctrine ask different questions—and consumer generative AI often fails tests that carefully used cloud storage has been built to pass.

Confidentiality Is Not the Same as Privilege

Confidentiality is an ethics duty. Under the ABA Model Rules, a lawyer generally may not reveal information relating to the representation of a client unless the client gives informed consent, the disclosure is impliedly authorized to carry out the representation, or an exception applies—and must make “reasonable efforts” to prevent inadvertent or unauthorized disclosure or access.2 Tennessee’s Rule 1.6 imposes parallel obligations.3

That duty is broad. It covers more than privileged communications—it is about professional obligation, not just courtroom admissibility.

Attorney-client privilege and work-product are evidentiary shields. In federal court, privilege generally protects communications (1) between client and counsel (2) that were intended to be, and were, kept confidential (3) for the purpose of obtaining or providing legal advice.4 Work-product protects materials prepared in anticipation of litigation, with special protection for mental impressions.5

You can violate confidentiality ethics without anyone litigating waiver—and a privilege fight can turn on facts the ethics rules only partly address. When people say “putting this in ChatGPT waives privilege,” they are often mixing the two. Both matter. They are not interchangeable.

Cloud Storage: The “Reasonable Care” Path

Tennessee’s Board of Professional Responsibility has long said a lawyer may store confidential client information in the cloud with reasonable care—emphasizing competence in selecting and continuing to use the provider, plus reasonable efforts that the vendor’s conduct is compatible with Rules 1.1, 1.6, 1.9(c), and 5.3.6

ABA Formal Opinion 477R points the same direction: the Model Rules do not invent a special confidentiality duty for each technology. What changes is the reasonableness analysis—threat model, transmission and storage, security, vendor diligence, and when sensitivity calls for more protection.7 The opinion expressly contemplates well-vetted cloud file storage for exchanging sensitive documents.

In practice, lawyers treat a business-grade drive as a system of record. Diligence focuses on security, access, retention, breach response, and contractual confidentiality—not on whether the platform will reuse your deposition to train a public model. Uploading a complete confidential PDF to OneDrive does not equal “breaching privilege.” Weak sharing links, no MFA, or an unvetted repository can still be a problem.

Generative AI: Same Duties, Sharper Disclosure Mechanics

In July 2024, the ABA issued Formal Opinion 512—the first formal opinion on lawyers’ use of generative AI. Lawyers must understand how a tool handles inputs before putting information relating to a representation into it. For many self-learning tools, informed client consent is generally required before inputting that information; boilerplate engagement-letter “AI use” language is not enough.8

Tennessee has not issued a generative-AI-specific formal ethics opinion. Existing Tennessee rules on competence, confidentiality, and supervision still apply, and Opinion 512 is the leading national roadmap.9 The ethics story is not “chatbots forbidden, drives allowed.” It is: know what happens to the data, match the tool to the risk, and get real informed consent when the tool’s design creates disclosure risk.

Why Volume Is a Red Herring

Privilege and confidentiality do not grade risk by megabytes. What often differs with consumer / public chatbots is how inputs are used, whether the terms undercut a reasonable expectation of confidentiality, whether the interaction looks like seeking help outside the privileged relationship, and how easily prompts and outputs become seizable records.10

A well-configured cloud drive is usually infrastructure for the representation, not a conversational third party. Storage already has a diligence grammar that consumer chat products often fail on day one.

Privilege: Where the Third-Party Problem Gets Sharp

Ethics confidentiality can be satisfied or violated without a privilege motion. Privilege fights ask whether a communication was confidential and within the privileged relationship—or whether a third-party disclosure destroyed the protection.

In United States v. Heppner, the court held that a criminal defendant’s written exchanges with the consumer version of Claude were protected by neither attorney-client privilege nor the work-product doctrine.11 Treating the issue as one of first impression, the court reasoned that Claude is not an attorney; that the platform’s privacy policy—collecting inputs and outputs, training on that data, and reserving disclosure rights to third parties including governmental authorities—defeated any reasonable expectation of confidentiality; and that the defendant used the tool on his own, not at counsel’s direction.

One decision does not settle every jurisdiction or counsel-directed workflow. It does illustrate the point: the chatbot is not “your associate,” and consumer terms may destroy the confidentiality story privilege requires. “I only pasted a little” is cold comfort—these analyses care about the nature of the disclosure and the expectation of privacy, not file size.

What Actually Matters

A typical business drive is storage infrastructure; diligence and privilege turn on whether confidentiality held with reasonable controls.12 A typical public chatbot is a generative processor, often with secondary use of inputs; Opinion 512’s consent and diligence emphasis applies, and privilege turns on whether the chat was a confidential communication in a privileged relationship—or a disclosure to a third-party system.13 Volume is often high on the drive and low in the chat—and still not the test.

Practically: check terms and data use; watch for anything that undercuts a reasonable expectation of confidentiality; prefer counsel-directed use over a solo public-chat paste; get specific informed consent when Opinion 512 requires it, not boilerplate;14 supervise vendors as you already supervise cloud providers;15 minimize what goes in; and read Tennessee Rules and TBPR guidance first, with ABA opinions as persuasive authority.16

A Practical Working Rule

Use cloud systems of record with competence and reasonable safeguards—not on vibes. Use generative AI the way Opinion 512 contemplates: understand the tool, prefer configurations that do not learn from your matters, keep client information out of consumer self-learning products unless you have a clear diligence story and, where required, informed consent, and never outsource legal judgment or citation-checking to a model.17

When someone says “but we put the whole file in Drive,” answer the real question: Did that system preserve confidentiality under controls we can defend—or did we disclose matter information into a product that treats our prompt like raw material? Those are not the same act with different file sizes.

The tools are useful. The lawyers who stay out of trouble stop confusing familiar with safe—and scary with unique.

Footnotes

  1. See Bd. of Pro. Responsibility of the Supreme Court of Tenn., Formal Ethics Op. 2015-F-159 (Sept. 11, 2015); ABA Comm. on Ethics & Prof'l Responsibility, Formal Op. 477R (2017).

  2. See Model Rules of Pro. Conduct r. 1.6(a), (c) (Am. Bar Ass'n 2023).

  3. See Tenn. Rules of Pro. Conduct r. 1.6; Formal Ethics Op. 2015-F-159, supra note 1.

  4. United States v. Mejia, 655 F.3d 126, 132 (2d Cir. 2011).

  5. See Fed. R. Civ. P. 26(b)(3); Hickman v. Taylor, 329 U.S. 495, 510–11 (1947).

  6. See Formal Ethics Op. 2015-F-159, supra note 1 (discussing Tenn. Rules of Pro. Conduct rr. 1.1, 1.6, 1.9(c), 5.3).

  7. See ABA Formal Op. 477R, supra note 1.

  8. See ABA Comm. on Ethics & Prof'l Responsibility, Formal Op. 512 (2024).

  9. See Tenn. Rules of Pro. Conduct rr. 1.1, 1.6, 5.3; Formal Ethics Op. 2015-F-159, supra note 1; ABA Formal Op. 512, supra note 8.

  10. See Mejia, 655 F.3d at 132–34; United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026).

  11. United States v. Heppner, No. 25 Cr. 503 (JSR), slip op. (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.) (memorandum explaining Feb. 10, 2026 bench ruling).

  12. See Formal Ethics Op. 2015-F-159, supra note 1; ABA Formal Op. 477R, supra note 1.

  13. See ABA Formal Op. 512, supra note 8.

  14. See id.

  15. See Formal Ethics Op. 2015-F-159, supra note 1; ABA Formal Op. 477R, supra note 1; Tenn. Rules of Pro. Conduct r. 5.3.

  16. See Tenn. Rules of Pro. Conduct rr. 1.1, 1.6; Formal Ethics Op. 2015-F-159, supra note 1; ABA Formal Op. 477R, supra note 1; ABA Formal Op. 512, supra note 8.

  17. See ABA Formal Op. 512, supra note 8.