Client Data and AI: Can I Paste This?
Firms strip names and context before pasting into AI tools, then wonder why the output is useless. Five DPA questions answer what you can actually paste.
A lawyer on r/legaltech asked how anyone uses AI with client data without panicking about privacy. Every answer ran on the same unwritten rule: do not paste the client file.
So people paste a version of it. Names swapped. Numbers rounded. Half the context stripped out. Then they are confused when the output is useless.
The rule is not wrong. It is just standing in for a question nobody has actually answered about the tools the firm already pays for:
Does this vendor train on what I type? How long do they keep it? Who else touches it? What country does it sit in? Is there a signed agreement, or a marketing page that says "enterprise grade"?
All five answers exist. They are buried in a DPA nobody at the firm has opened.
What should exist is a grader. Pick your tool, get a red, yellow or green on those five, and one plain line telling you what you can and cannot paste. Ten seconds instead of a policy meeting.
Until someone builds it, the workaround is doing it once, by hand, for the three tools your people actually use, and writing the answer on one page everyone can see. That page is worth more than another AI training session.
Start with what the tools actually are: the vendor-neutral Counterbench tool directory, plus the legal AI evaluation framework, which scores privilege handling before you buy.