Back to Blog

Is ChatGPT Safe for Client Data? What Canadian Lawyers Need to Know

Solicitor-client privilege, the US CLOUD Act, and why the transcription tool on your desk might already be a compliance problem.

Every law firm in Canada is running the same experiment right now, whether they've admitted it or not: an associate pastes a client email into ChatGPT to tighten the language, a paralegal uploads a deposition transcript to a cloud tool to summarize it, a partner dictates case notes into a consumer transcription app on their phone. None of it goes through IT. None of it shows up in a privilege log. And almost none of it would survive scrutiny if a regulator — or opposing counsel — asked where that data actually went.

The question isn't "is ChatGPT good." It's "who else can read this."

Consumer AI tools are built for a different problem than the one law firms have. They're optimized for capability and speed, not for data residency or evidentiary control. When you send text to a general-purpose AI product, a few things are typically true:

None of this makes the tools malicious. It makes them the wrong category of tool for privileged information.

The CLOUD Act problem, specifically

The US CLOUD Act allows US law enforcement to compel US-based technology companies to produce data stored on their servers — regardless of where in the world that data physically sits, and regardless of whether the data belongs to a Canadian client who has never set foot in the United States. For a law firm, this means that data sitting on US-controlled infrastructure is potentially discoverable through a channel that has nothing to do with Canadian courts, Canadian privacy law, or the client's own legal proceeding.

That's a materially different risk profile than "is this vendor trustworthy." It's a jurisdictional exposure that exists independent of the vendor's intentions.

What "solicitor-client privilege and AI" actually requires

Privilege isn't just about who can read a document — it's about maintaining control over who does. Courts have historically found privilege can be weakened when a firm can't demonstrate it took reasonable steps to control access to privileged material. Sending client communications through a third-party AI product that a firm doesn't operate, doesn't audit, and can't fully account for is a hard thing to defend as a "reasonable step."

Practically, that means firms adopting AI tools should be able to answer:

  1. Where does the data physically reside while it's being processed?
  2. Who — as a legal entity, in which jurisdiction — has the technical ability to access it?
  3. Is there an audit log we could produce if asked?
  4. Is any of this data used to train a model that other users might eventually query?

If the honest answer to any of those is "we don't know," that's the gap.

What a Canada-hosted alternative actually changes

The fix isn't "don't use AI." Transcription, document search, and drafting assistance are genuinely useful, and firms that use them well save meaningful hours. The fix is where and how the processing happens:

This is the model WizardX runs for Canadian law firms: transcription, secure voice recording, and document intelligence deployed on infrastructure the firm effectively controls, inside Canada, with nothing shared and nothing exported.

If you're already using AI tools in your practice — and at this point, most firms are, whether it's sanctioned or not — the question worth asking this week isn't whether to keep using them. It's whether the ones you're using right now could survive being described, in detail, to a client.