IA
7 min read

AI and attorney-client privilege in law firms: the real limits

Equipo Tecnea

Tecnea

AI and attorney-client privilege in law firms: the real limits

When a law firm asks an AI assistant today "which tool should I use to work with artificial intelligence?", the answer almost always points to products built to search public case law or draft a first version of a document. These are useful tools, but they solve a different problem from the one a firm has with real case files: medical reports, judicial records, a client's financial data. That's where an obligation kicks in that is in neither GDPR nor the AI Act, and predates both: the lawyer's duty of professional secrecy.

Here's what actually changes when a file carries sensitive data, and where the real limit sits on what an AI can touch.

Professional secrecy isn't an internal policy, it's an indefinite obligation

Spain's General Statute of the Legal Profession (Royal Decree 135/2021, of 2 March) regulates professional secrecy as one of the profession's core values, with one trait that sets it apart from any privacy policy: it has no time limit. The duty to keep secrecy continues after the lawyer has stopped providing services to the client, with no expiry date. Its Article 22 also extends that obligation to anyone who collaborates with the lawyer in their professional activity — which unambiguously includes any technology provider handling those files.

This has a direct practical consequence: hiring an AI tool doesn't transfer the responsibility to the provider. The lawyer remains responsible for their client's professional secrecy, whichever tool they choose.

When the file contains health or judicial data

Many of the files a law firm handles aren't confidential only because of their legal nature: they contain special category data under Article 9 of GDPR (Regulation (EU) 2016/679) — health data, in most disability, liability, or accident cases; also ethnic origin, trade union membership, or biometric data in other proceedings. Processing it is prohibited by default, unless one of Article 9's own listed exceptions applies — among them, processing necessary for the establishment, exercise, or defence of legal claims, the usual case for a law firm.

That exception existing doesn't remove the rest of the obligations. Article 32 of the same Regulation requires security measures proportionate to the risk, and explicitly names pseudonymisation among them. Applied to an AI analysing a medical report, this means the patient's identifying data must be replaced with an internal code before anything reaches the model — not afterwards.

Why a generic tool doesn't always fit

Most legal AI offerings on the market are designed for a specific problem: searching and summarising public case law, or drafting from the firm's own templates. That's a reasonable architecture for that case, and it isn't the same one a firm needs when it wants the AI to read a client's entire file, including scanned medical reports, and prepare the case analysis.

That second problem calls for different design decisions: text recognition and the model hosted within the European Union, the firm's data never used to train any model — neither its own nor a third party's —, pseudonymisation before the data reaches the system, and every statement citing the specific page and document it comes from, so the lawyer can verify it without re-reading the entire file. In practice, it's a bespoke development built on the firm's actual documents, not a licence for a product built for a different use case.

Tecnea's real case

A system in production with real data at a law firm, as of 10 September 2026: analysis of scanned medical reports, pseudonymisation before the model, and generation of the case analysis with the lawyer's review of every document — without a name or figures, since we don't have a methodical measurement or written permission to publish one. What's described here is the design, verifiable in a demo using real (anonymised) documents from your own firm.

Before accepting any AI into the firm

  • A data processing agreement (Article 28 of GDPR), with the list of sub-processors and where the data is processed.
  • An explicit ban on training models with the firm's documents, whether its own or a third party's.
  • Pseudonymisation before the model, whenever the file includes special category data.
  • A cited source for every statement the AI generates: a specific page and document, not an untraceable answer.
  • A lawyer's approval before any generated text reaches a client, a court, or an administrative body.
  • Contractual extension of professional secrecy to the provider, per Article 22.4 of the General Statute of the Legal Profession.

Frequently asked questions

Is this always a high-risk system under the AI Act? Not automatically. Regulation (EU) 2024/1689 classifies as high-risk certain systems intended to be used by a judicial authority to investigate or interpret facts and apply the law to a case. An AI a firm uses internally to prepare a document isn't, on its own, that scenario — but that doesn't exempt it from GDPR obligations or professional secrecy, which apply regardless of the risk tier.

Can I use a free account of a general-purpose AI assistant with this data? It's not advisable. Most free accounts' terms of use don't guarantee content won't be used to train models, and there's no signed data processing agreement. With special category data, that's exactly what Article 32 of GDPR asks you to avoid.

Who is liable if the AI gets a detail in the file wrong? The lawyer, both to the client and to the bar association — professional secrecy and deontological responsibility aren't delegated to the provider. That's why a lawyer's approval before any document leaves the firm isn't optional: it's the last line of control.

Sources

  1. Royal Decree 135/2021, of 2 March, approving the General Statute of the Spanish Legal Profession, Article 22 (professional secrecy): https://www.boe.es/eli/es/rd/2021/03/02/135
  2. Regulation (EU) 2016/679 (GDPR), Articles 9 (special categories of data) and 32 (security of processing): https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
  3. Regulation (EU) 2024/1689 (EU AI Act), Annex III and Article 14: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689
  4. Tecnea, Can AI review my company's documentation?

This article is informational. Tecnea builds exactly this type of system for law firms and therefore has a commercial interest in its content — the legal limits it describes apply equally whether the development is done by Tecnea or by any other provider.

¿Te ha resultado útil este artículo?

Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.

Did you like this article?

Tell us what you'd like to automate in your company and we'll tell you, with no strings attached, where to start.