News in Practice
ChatGPT, Claude and the client matter: what happens when you paste in a document
Adoption doubled in a year, and almost nobody declares it. What changed this summer is that the text itself now carries a trace of the tool.
For firms and legal departments whose teams use ChatGPT, Claude or another general-purpose assistant on live matters. What happens to the text, what the terms of use provide, and what to put in place instead of a ban.
Your teams use ChatGPT, Claude or an equivalent on live matters, including those advised against it, and including in all likelihood at least one partner. The Thomson Reuters 2026 AI in Professional Services Report finds that 41% of law firms and 47% of corporate legal departments now report generative AI use within their teams, against 28% and 23% respectively a year earlier. In the United States, the 2026 Legal Industry Report relayed by the American Bar Association puts personal use at 69%, against 31% 12 months earlier. This is not indiscipline: it is what happens when a free, available and genuinely useful tool meets a real workload. Moral reproach is therefore beside the point. What deserves attention is what actually happens to the text, and one element of that has just changed.
The concession: the need is well founded
Asked without consequence, those who declare such uses describe precise situations. An impossible deadline. A question outside their practice area on which they want an initial bearing before troubling a partner. A passage to rework at 10 p.m. A concept to grasp quickly.
On those uses, the tool does what is asked of it, and will do so increasingly well. Claiming otherwise would be dishonest and would destroy the credibility of everything that follows. A firm that opens this discussion by denying the usefulness of these tools loses the argument in the first minute, because those who use them know exactly what they get from them.
The problem therefore does not lie in the use itself. It lies in the fact that nobody in the firm knows what has been submitted, by whom, or on which matters.
What the terms of use provide
They vary by provider and, above all, by subscription type, and that variation is the problem. A consumer account is governed by terms written for consumers; a professional offering is governed by commercial terms, with a data processing agreement and, generally, a contractual prohibition on training from submitted content.
The difference is not a setting, it is a regime. An associate who opens a personal account to get through a Friday evening benefits from none of those guarantees, however reputable the provider.
Three questions arise, and the answer is rarely the same. Is submitted content used for training? How long is it retained? Who can access it, and for what purposes?
A firm cannot answer these questions for a use it does not know about. That is what separates declared use from clandestine use: the first can be governed even imperfectly, the second cannot be governed at all.
What changed this summer
Since August 2, 2026, pursuant to the transparency obligations of European regulation, several major providers embed a machine-readable mark in the text their models produce.
It is a statistical signal, imperceptible on reading, inserted at model level. It does not visibly alter the text, it survives copy-and-paste, and it can survive some subsequent editing. It is applied worldwide, not only to European users.
The development is legitimate in itself: it answers a need for traceability of information whose principle nobody disputes. Its practical consequences, however, were not designed with legal production in mind.
The mark attests that a model processed the text. It does not attest that the model wrote it, and nothing distinguishes the two.
Why this matters particularly to a lawyer
The decisive point fits in one sentence: the mark signals processing, not authorship.
A fully generated text carries it. A text drafted by an associate and then submitted for rephrasing carries it too. A text merely corrected for spelling carries it as well. These three situations are profoundly different from a professional standpoint, and indistinguishable from the standpoint of the mark.
Yet that distinction is precisely what matters to a lawyer. Signing work one has directed and signing work one has received do not engage the same thing, and a firm using these tools for review finds itself treated like one using them for production.
There is also an asymmetry of timing. Marks are being applied now, in texts that circulate, are filed and are archived. The tools required to detect them are not yet widely available. A firm therefore has no way today of knowing which of its own past output carries one.
The ordinary case, which is the worrying one
Take the most mundane situation rather than the most spectacular.
An associate drafts submissions. He submits one paragraph to check its clarity and improve its phrasing. He takes the suggested version, reworks it, integrates it. The final text is his, the analysis is his, the strategy is that of the partner who signs.
That text now carries a mark. If detected, it attests that a model processed the passage. It does not say that the reasoning came from the model, and nothing in the signal allows that to be established.
The difficulty is not strictly legal: it is a difficulty of proof. The firm will have to explain what happened, and will only be able to do so if it has kept a record of its own production process. All of this news therefore creates no new obligation: it makes suddenly useful a traceability that few firms had organised.
What foreign courts have already held
Two decisions handed down abroad are worth knowing, provided they are not transposed: French professional secrecy is not the same construct as legal professional privilege.
In February 2026, a United States federal court held that a defendant's exchanges with a consumer assistant, and the documents resulting from them, were protected neither by privilege nor by work-product doctrine. One ground is of particular interest here: because the provider's policy permitted retention, training and disclosure to third parties, the individual could have no reasonable expectation of confidentiality. On the same day, another federal court reached the opposite conclusion in a different matter, holding that such programmes are tools, not persons.
In November 2025, a United Kingdom tribunal put it more starkly still, concerning a solicitor who had submitted client correspondence to an assistant: uploading confidential documents into an open AI tool amounts to placing that information in the public domain, and thus to breaching the confidentiality owed to the client. No leak had been identified; the breach was constituted by the upload itself.
What runs through these decisions, despite their divergence, is a single finding: the channel used determines the level of protection, regardless of the intention of the person using it.
The detail that should give pause on traceability
One aspect of the American case deserves to be isolated, because it is counter-intuitive.
It was not an investigation that revealed those exchanges. It was the privilege log produced by the defence itself, in which an entry described documents as an AI-generated analysis transmitted to counsel for the purpose of obtaining legal advice. That description drew the prosecutors' attention, and they sought production.
So it was the documentation of the use that triggered the demand. One might conclude that it is better to document nothing: that would be the wrong lesson, and it would expose a firm further. The right one is that poorly built traceability turns against you, and that one must know precisely what is being recorded and what that record establishes.
What this does not mean
Three excessive readings should be set aside, because they circulate and they hinder the discussion.
The mark is not evidence admissible as such. It is a probabilistic signal, it can disappear on rewriting, and its interpretation depends on tools whose specifications are not yet published.
It does not concern every model. It applies to those launched from a given date, and coverage of earlier models is in progress. A firm therefore cannot know, for older output, whether it is affected.
And it does not render the use unlawful. Nothing prevents a lawyer from using a tool; what is at stake is the ability to describe what was done, which is an old requirement rather than a new one.
The three other risks, which have not changed
The mark has made visible a subject that existed before it, and it would be a pity if the news obscured the underlying difficulties.
The escape of information covered by professional secrecy, which remains the first issue. A document submitted from a personal account escapes all governance, and nobody can say afterwards what left.
The absence of traceability. Work produced this way leaves no record of what was verified, what was set aside, or which sources were actually consulted. The reviewer receives a smooth text, with no indication of where attention would be needed.
And the question of references. A citation may be accurate, approximate or non-existent, and all three present identically. This is the one point on which an absolute rule is justified: no source cited should appear in outgoing work without someone having opened it.
A point that commits us
It would be dishonest to suggest the problem lies with the models themselves. Professional legal processing layers, ours included, rely on the same engines referred to above. That is in fact a deliberate choice: depending on a single provider would be a weakness, and the progress of these models directly benefits whoever knows how to frame them.
What distinguishes the two situations is therefore not the power of the engine, which is identical. It is what surrounds it: what actually leaves the firm, in what form, under what contractual regime, with what records. A document whose identifying elements have been replaced locally before any external processing does not raise the same question as one pasted whole into a personal account.
Put that way, the question becomes verifiable: one no longer asks whether a provider is trustworthy, one asks what leaves the infrastructure.
The shift: what to put in place
A ban is the quickest answer to produce and the least effective. It cannot be verified, it deprives the firm of its only source of information on actual usage, and it turns governable use into clandestine use.
What can effectively be governed is structural: which systems the firm makes available, which data they access, what leaves and in what form, what records remain. A decision of that kind applies of itself, without requiring anyone to give anything up through discipline.
It rests, however, on one condition without which it amounts to a ban in disguise: the means provided must be at least as convenient as the one it replaces. If the firm's system is heavier to reach than a tool open in a browser tab, undeclared use will continue and the firm will have added a cost without obtaining a result.
That is what links this question to deployment rather than to ethics. The issue is not what to prohibit; it is what to make available so that a real need finds an answer the firm can account for.
This article sets out the facts as at its review date. It does not constitute legal advice and does not replace a professional's analysis of a specific situation.