Yes, but running AI in your office doesn’t settle the ethics or privilege questions for you. It helps with your duty of confidentiality, because client files are processed on your own machine and not sent to an AI company whose terms may let it keep or share them. It doesn’t make anything privileged. Privilege still depends on who is communicating, and why. The firm still has to handle access, supervision, review of output, and what to tell clients.
What the ABA says
ABA Formal Opinion 512, issued in July 2024, is the ABA’s formal guidance on lawyers using AI. It interprets the ABA Model Rules, and your state’s own rules are what bind you. Under Rule 1.6, you have to understand how a tool handles information relating to the representation before you use it, and make reasonable efforts to keep that information from getting out. The opinion also covers competence, supervision, candor to the court, and fees.
The opinion is strictest about tools that learn from what users type, since one client’s information could show up in work for another client, even inside the same firm. For those, it says you need the client’s informed consent first, and a general clause in the engagement letter doesn’t count. Many state bars have issued their own opinions since, so check yours too.
The Heppner ruling
In February 2026, in United States v. Heppner, Judge Jed Rakoff of the Southern District of New York held that documents a criminal defendant created with the consumer version of Claude were not protected by attorney-client privilege or the work product doctrine. The court gave several reasons. Claude isn’t a lawyer, so the exchanges weren’t communications with counsel. The defendant used it without direction from counsel. And the tool’s privacy policy let the vendor train on inputs and disclose them to third parties, including the government, so the exchanges weren’t confidential.
Keeping files on your own machine speaks to that last reason, not the other two. The judge suggested that use directed by counsel might be argued differently, but the ruling didn’t decide how enterprise or on-site tools would be treated.
What changes when the AI runs in your office
With On Premises, the model runs on a machine plugged into your network. Prompts and files are processed there, and the model doesn’t need the internet to answer. No AI company’s privacy policy applies to what your lawyers type, and the model changes only when you approve an update.
Anything else the machine connects to, like backups, model downloads, or our remote support, is set up to your rules and written into the deployment scope.
The risk that stays inside the firm
An internal system can still show one client’s information to people working for another. If every lawyer can search every uploaded file, an ethical wall around a matter is only on paper. The On Premises workspace can limit document search by matter or team, so a lawyer only searches the files for matters they’re on. Set up those groups before you load client files.
The system
- Runs the AI model on hardware in your office
- Gives each person their own login and chat history
- Limits document search by matter or team
- Keeps usage records on your system, not ours
- Changes models only when you approve
- Stays yours, data included, if you cancel
Your firm
- Deciding who belongs to each matter, and updating it
- Deciding who gets an account, and closing accounts when people leave
- Supervising how lawyers and staff use it
- Checking output before it goes to a client or a court
- Deciding how chat history fits retention and legal holds
Do you have to tell clients?
Opinion 512 ties informed consent to the risk that information relating to the representation gets disclosed, whether outside the firm or to others inside it. It also says to tell clients when they ask, when the engagement terms or outside counsel guidelines call for it, when AI output will influence a significant decision in the representation, and when it affects fees. How that applies to a system inside your office is a call for your firm under your state’s rules.
What can On Premises see?
Our remote monitoring covers hardware health: uptime, temperatures, load, and drive health. It doesn’t read prompts, documents, or chat history.
Repairs can get closer. If we log in to fix the chat app while client files are on the machine, we could see them. Rule 5.3 asks you to make reasonable efforts to ensure that outside help like ours handles client information in line with your obligations. We sign confidentiality and vendor-access terms that set out what support can reach and how we handle anything we see. Have your firm review them before install.
Try it without client files
Our pilot runs one of your workflows on a demo machine for half a day. It can run on made-up documents shaped like yours, so no client information has to be involved. You get a written report and a go or no-go within two business days.
This page is general information, not legal advice, and it isn’t an ethics opinion. Check the rules and bar guidance in your state. See our Terms for how site content should be read.
Last updated: September 23, 2026