Artificial Intelligence is rapidly becoming part of professional legal practice.
Lawyers are using AI tools for legal research, drafting, summarisation, document review, proofreading, translation, case-law analysis, contract review and administrative work. These tools can significantly improve efficiency.
But legal practice involves something that ordinary business activity often does not: highly confidential and privileged information.
A lawyer may have access to:
This raises an increasingly important question:
Can lawyers use AI tools without compromising client confidentiality and professional obligations?
The answer under Indian law is not that AI tools are prohibited. There is currently no general Indian rule that says an advocate cannot use artificial intelligence for legal work.
However, the use of AI does not reduce or transfer the advocate's existing professional obligations. If confidential information is entered into an AI system, the advocate remains responsible for ensuring that the use of that system does not result in an unauthorised disclosure or misuse of client information.
The starting point is simple:
A lawyer's duty of confidentiality exists regardless of the technology used to perform the work.
The Bar Council of India Rules prescribe standards of professional conduct and etiquette for advocates. Rule 17 states that an advocate shall not, directly or indirectly, breach the obligations imposed by Section 126 of the Indian Evidence Act.
The statutory framework has now moved from the Indian Evidence Act, 1872 to the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which came into force on 1 July 2024.
Section 132 of the BSA deals with professional communications.
It provides that, subject to specified exceptions, an advocate cannot disclose a communication made to the advocate by or on behalf of the client in the course and for the purpose of professional service, disclose the contents or condition of documents learned in that professional capacity, or disclose legal advice given to the client, without the client's express consent. The obligation continues even after the professional service has ended.
This is highly relevant to AI.
If a lawyer gives confidential client material to an external AI service, the issue is not simply:
"Did the lawyer personally disclose the information?"
The more important question is whether the lawyer has allowed confidential information to be processed or disclosed through a third-party system in a manner inconsistent with the lawyer's legal and professional obligations.
Section 132(1) of the BSA protects:
The protection is subject to important exceptions, including communications made in furtherance of an illegal purpose and facts observed by the advocate during professional service showing that a crime or fraud has been committed since the commencement of the service. The obligation continues after the professional engagement ends.
This is not merely a matter of professional courtesy.
It is part of the legal framework governing the advocate-client relationship.
The BCI Rules independently impose professional obligations upon advocates.
Rule 17 specifically prohibits an advocate from directly or indirectly breaching the obligations relating to professional communications.
The Rules also state that an advocate should not do anything whereby the advocate abuses or takes advantage of the confidence reposed in the advocate by the client.
The Delhi High Court has also recognised the confidential and privileged nature of documents generated during professional legal services. In Mr. Diljeet Titus, Advocate v. Mr. Alfred A. Adebare & Ors., the Court considered the confidentiality obligations surrounding client-related documentation and the relevance of the BCI Rules and professional privilege.
Therefore, the use of technology must be consistent with the same professional standards that apply to traditional files, emails, physical documents and other methods of handling client information.
No.
There is an important distinction between:
and
For example, a lawyer may use an AI system to:
These uses do not necessarily involve disclosure of privileged client information.
The risk changes significantly when a lawyer uploads:
"Here is my client's confidential agreement. Please identify the breach and advise us on litigation strategy."
The document could contain:
The lawyer must then consider where the information is going, how it will be processed, who may access it, how long it may be retained, whether it may be used for model improvement or other purposes, and what contractual and security protections apply.
One of the most common misconceptions is:
"I am only using AI to help me draft, so confidentiality is not an issue."
The method of processing matters.
When confidential information is entered into an external AI platform, the lawyer should consider whether the information is being transmitted to or processed by a third-party service provider.
This creates several questions:
The lawyer should understand the relevant hosting and storage arrangements.
Access controls and administrative access matter.
The service's retention policy may be relevant.
The terms applicable to the particular product and account should be examined rather than assumed.
Cloud and AI services may involve multiple infrastructure providers.
The lawyer should understand applicable deletion and retention mechanisms.
Incident-response arrangements should be considered.
The answer to these questions can differ substantially between AI products and between consumer and enterprise offerings.
Therefore:
Never assume that every AI tool provides the same level of confidentiality.
Law firms should distinguish between:
consumer-grade AI services
and
enterprise or professionally managed AI environments.
Enterprise products may offer additional contractual, administrative and security controls. Depending on the provider and plan, these may include matters such as:
But even an enterprise AI platform should not automatically be treated as legally privileged simply because it is labelled "enterprise."
The lawyer should examine the actual:
This distinction is extremely important.
This concerns the lawyer's professional obligations toward the client and the legal protection applicable to professional communications.
This concerns the processing and protection of personal data under applicable data-protection law.
A document can involve both.
For example, a criminal case file may contain:
Sending such material to an AI system may therefore raise both professional confidentiality and data-protection questions.
India's Digital Personal Data Protection Act, 2023 (DPDP Act) creates a statutory framework for processing digital personal data.
The Act received Presidential assent on 11 August 2023. Its commencement has been notified in phases, rather than all provisions becoming operative simultaneously. The Government notified the DPDP Rules, 2025 on 13 November 2025, with implementation also structured in phases.
The substantive compliance provisions are subject to the notified commencement timeline, with the principal compliance provisions scheduled for the later phase of implementation. Current legal commentary based on the Government's notifications places that major compliance phase at approximately May 2027.
This means law firms should distinguish between:
what is legally operative today
and
what organisations should prepare for under the incoming framework.
A prudent law firm should not wait until the final compliance date before developing secure AI and data-handling practices.
The Information Technology Act, 2000 and its related framework have historically imposed obligations concerning protection of sensitive personal data.
Section 43A of the IT Act addresses compensation for failure by a body corporate to implement and maintain reasonable security practices and procedures when handling sensitive personal data or information and wrongful loss or wrongful gain results.
Accordingly, firms handling sensitive information through digital systems should consider appropriate security practices rather than relying solely on confidentiality clauses.
This is one of the most legally sensitive questions.
There is currently no Indian Supreme Court ruling establishing a blanket rule that uploading privileged material to an AI platform automatically destroys privilege.
Nor is there a general statutory provision specifically stating that use of an AI system constitutes waiver of advocate-client privilege.
Therefore, it would be incorrect to state categorically that:
"Using AI automatically waives privilege."
That proposition is not presently established as a general rule of Indian law.
However, the absence of such a ruling does not make careless disclosure safe.
A lawyer should consider whether sending confidential information to an external third party is consistent with:
The prudent approach is to minimise unnecessary disclosure.
Client consent can be relevant, but it should not be treated as a complete solution to every AI-related risk.
Section 132 of the BSA expressly refers to the client's express consent in relation to disclosure of protected professional communications.
However, obtaining a generic statement such as:
"The client agrees that the lawyer may use AI"
does not necessarily resolve every issue.
The firm should still consider:
Consent should therefore be informed and appropriately scoped, where consent is relied upon.
Yes, but legal research creates a different risk.
A lawyer can use AI to:
But AI-generated legal research must be independently verified.
This is particularly important because generative AI systems can produce:
The responsibility for legal advice remains with the lawyer.
A practical rule is:
AI may assist legal research; it should not replace legal verification.
Every authority relied upon in a pleading, opinion or submission should be checked against an authoritative source.
As a general risk-management principle, lawyers should avoid uploading complete confidential case files to a general-purpose external AI service unless the firm's legal, contractual, security and client-consent framework has been appropriately assessed.
A safer workflow may involve:
Step 1: Remove unnecessary personal information.
Step 2: Anonymise names and identifiers where possible.
Step 3: Remove privileged material that the AI does not need.
Step 4: Provide only the minimum information required for the task.
Step 5: Use an appropriately secured and contractually reviewed AI environment.
Step 6: Independently verify the AI output.
This follows a basic data-governance principle:
If the AI does not need the information, do not give it the information.
A law firm should ask:
What is the minimum information necessary for the AI to perform this task?
For example, instead of:
"Review this entire 100-page client agreement and tell me whether our client has breached the agreement."
A lawyer may first anonymise the document and provide only the relevant provisions if the task permits.
Instead of:
"Here is my client's entire criminal case file."
The lawyer could ask an AI system a general question:
"What legal issues should an advocate examine when analysing a prosecution based on circumstantial evidence?"
The second approach does not expose client information unnecessarily.
One useful way of thinking about AI is:
Treat an external AI service as a third-party service provider—not as a member of your chambers.
Before allowing confidential information to be processed, the firm should ask:
This is particularly important for firms handling high-value corporate, criminal, regulatory, arbitration and constitutional matters.
Every modern law firm should consider implementing an internal AI Use and Confidentiality Policy.
It can establish:
Examples:
Examples:
Depending on the firm's risk assessment:
AI should not become the final decision-maker in legal practice.
For example, AI can help identify possible arguments.
But the advocate must determine:
The lawyer remains accountable for the professional work product.
The risks become even greater when AI-generated material is incorporated into:
An advocate should verify:
Every citation.
Every quotation.
Every statutory provision.
Every factual assertion.
Every case reference.
AI-generated material should never be treated as authoritative merely because it sounds legally sophisticated.
This is one of the most obvious practical risks.
An AI system may produce a citation that appears authentic but does not exist or may inaccurately describe a real decision.
A lawyer who relies upon it without verification risks:
The solution is straightforward:
AI-generated legal research must be independently checked against authoritative legal databases, official court websites, legislation and other reliable sources before reliance.
As a practical risk-control measure, law firms should generally prohibit or tightly restrict uploading the following to unapproved systems:
The exact policy should depend upon the firm's practice areas and contractual obligations.
Cloud storage itself is not necessarily incompatible with confidentiality.
Modern law firms routinely use:
The legal question is not simply:
"Is the document in the cloud?"
The relevant questions include:
Who controls the system?
What contractual safeguards exist?
What security measures are implemented?
Who can access the information?
Where is it processed?
What happens in the event of a breach?
The same approach should be applied to AI platforms.
EOS Chambers—or any law firm considering AI adoption—can use a simple 7-point AI confidentiality framework:
Identify whether the information is public, internal, confidential, sensitive or privileged.
Provide only the information necessary for the task.
Remove names, identifiers and unnecessary personal information wherever possible.
Review the AI provider's terms, privacy policy, security documentation and data-use practices.
Use only AI tools approved by the firm.
Independently check legal authorities, facts, quotations and analysis.
The final legal judgment must remain with the advocate.
| AI Use | Confidentiality Risk | Recommended Approach |
|---|---|---|
| Public legal research | Low | Generally suitable |
| Grammar correction of public text | Low | Generally suitable |
| Generic legal brainstorming | Low | Suitable with normal review |
| Anonymised legal problem | Moderate/Low | Generally safer |
| Internal non-client information | Moderate | Firm policy required |
| Client contract | High | Approved environment + safeguards |
| Privileged advice | Very High | Avoid external unapproved AI |
| Criminal investigation file | Very High | Highly restricted |
| Personal/sensitive data | High | Minimise + security assessment |
| Complete confidential case file | Very High | Avoid unless specifically authorised and secured |
This is a risk-management framework, not a statement that Indian law assigns these exact categories or risk levels.
The answer is:
AI can be a useful professional tool when deployed within an appropriate framework.
The issue is not whether lawyers should use technology.
The issue is whether technology is being used in a way that remains consistent with:
Indian law already places confidentiality obligations upon advocates. The arrival of AI does not remove them.
Artificial Intelligence will probably become increasingly integrated into legal practice.
Lawyers may use AI for:
But the core responsibilities of an advocate remain human:
judgment, ethics, confidentiality, accountability and responsibility to the client and the Court.
AI can process information.
It cannot take over the advocate's professional responsibility.
The question is no longer whether lawyers will use Artificial Intelligence.
They already are.
The more important question is how responsibly they use it.
Indian law provides a strong framework protecting professional communications between advocates and clients. Section 132 of the Bharatiya Sakshya Adhiniyam, 2023 protects specified professional communications, documents and legal advice, subject to statutory exceptions. The Bar Council of India Rules separately require advocates not to breach their professional obligations concerning such communications.
At the same time, India's digital privacy framework is evolving, with the DPDP Act, 2023 and DPDP Rules, 2025 being implemented through a phased commencement framework.
Therefore, the responsible approach is neither:
"Never use AI."
nor:
"AI is safe for everything."
It is:
Use AI where it creates value, but never outsource professional responsibility.
For a law firm, the most important principle should remain simple:
A Division Bench of the Supreme Court, while allowing a bail plea, held that the grant of bail to a co-accused person cannot be contingent on the surrender of another accused who is also pertinently the main accused in the ...
The Supreme Court emphasized that where there is an absence of any specific rule or prescription, the last day for fulfilling eligibility is the last date of submission of the application. The Court made the observation while refusing the benefit ...
The Rajya Sabha has passed the Jammu and Kashmir (Reorganization) Bill, 2019, which is set to bifurcate the state of Jammu and Kashmir into two Union territories – Jammu and Kashmir, which will have a legislature, and Ladakh, which will ...
The Supreme Court has held that if an Indian Entity’s Establishment is operating in Oman and has a ‘Permanent Establishment’ status under Double Taxation Avoidance Agreement (“DTAA”), then the dividend income received by the Indian Entity from such Establishment would ...
For Non-Resident Indians (NRIs), navigating inheritance and succession laws in India can be complex. Whether dealing with ancestral property, inheriting assets, or managing family estates, NRIs must understand the legal framework to safeguard their rights and avoid disputes. Here are ...
In today’s rapidly evolving legal landscape, the integration of technology has become more than just a trend—it’s a fundamental shift that is reshaping how legal professionals operate and deliver services. As we embrace this digital transformation, the role of legal ...