Can you put client data in ChatGPT?

Short answer: probably not the way you are thinking about it, and the reason has less to do with the technology than with who you promised confidentiality to.

This question comes up in almost every conversation we have with a regulated practice. Someone on the team has already been using ChatGPT to draft letters or summarize notes, the owner found out, and now nobody is sure whether that was a problem or not.

Here is the honest version, without the vendor spin in either direction.

What actually happens to what you paste

When you use a consumer AI tool, your text leaves your building, travels to someone else's servers, and is processed there. That is not a scandal. It is just how a hosted service works, and it is the same thing that happens when you send an email or use cloud accounting software.

The question that matters is not "does it leave the building". It is what is the vendor allowed to do with it once it arrives, and did you have the standing to send it in the first place.

Those are two separate problems, and most firms only think about the first one.

The business plan solves the smaller problem

Every major AI vendor now offers a business or enterprise tier where your data is not used to train their models, and there are contractual commitments around retention and access. That is a real difference from the free consumer tier, and if your team is going to use these tools at all, being on the paid business tier rather than free accounts is the single easiest improvement you can make.

But that only answers "will this end up in the next model". It does not answer the second question.

Your confidentiality obligation is to your client, not to your software vendor. A contract between you and an AI company does not retroactively give you permission to share a client's file with a third party the client never agreed to.

The part most firms miss

If you are a lawyer, your duty of confidentiality covers information relating to the representation, and sharing it with an outside service is a decision you have to be able to justify. If you are a dental or medical practice, protected health information going to a vendor generally means that vendor is a business associate, with the paperwork that implies. If you are a CPA, you have your own confidentiality rules about client tax information.

None of those rules say "AI is forbidden". What they say is that you are accountable for where the information goes. A vendor cannot absorb that accountability for you, no matter what their marketing page says.

Where this guide stops

We build AI systems. We are not your lawyer, your compliance officer, or your malpractice carrier. Everything above is a description of how the technology works and the questions it raises, not legal advice about your specific obligations.

Before any regulated practice puts client information into any AI tool, that decision belongs in front of whoever advises you on professional responsibility. If a vendor tells you their product makes you compliant, be suspicious. Compliance is a property of your whole practice, not of one piece of software.

The three ways firms actually handle this

Use AI only on information that is not confidential

Marketing copy, internal process documents, general research, first drafts written from scratch with no client facts in them. This costs nothing, needs no approval, and is where most firms should start. The limitation is obvious: the highest-value work involves the exact information you cannot paste.

Use a business tier with the paperwork done properly

Paid business account, training disabled, a signed agreement with the vendor covering your obligations, a written internal policy about what may and may not be entered, and training so the policy is actually followed. This is workable, and it is what a lot of firms land on. It also means accepting that client information sits on infrastructure you do not control, and that your exposure grows with every new tool the team adopts.

Run the model on hardware you own

The third option is to stop sending the data anywhere. Open-weight models in the 70-billion-parameter range now run on a single machine that fits in a closet, with no internet connection required. The model reads your documents, answers questions about them, and drafts from them, and none of that leaves the building because there is nowhere for it to go.

The honest tradeoffs: a local model is not as sharp as the best hosted frontier model, there is real hardware to buy and maintain, and somebody has to keep it updated. It is a bigger commitment than opening a browser tab.

What you get in exchange is that the confidentiality question stops being complicated. There is no vendor to vet, no data processing agreement to negotiate, no annual review of someone else's security posture. The answer to "where does our client data go" becomes "into a machine in the server closet".

How to decide

Work out how much of the work you actually want AI for involves confidential information. If it is a small slice, the first option is fine and you are done. If it is most of it, you are choosing between carefully governed cloud access and owning the hardware, and that choice comes down to how much of your practice depends on the confidentiality promise holding.

For a firm whose entire business model rests on clients trusting them with things they would not tell anyone else, owning the machine tends to be an easier conversation than explaining a vendor's security architecture to a nervous client.

Not sure which of the three fits your practice?

The free AI Audit maps where your firm would actually benefit, which of that touches confidential information, and what the honest options are. You keep the plan either way.

See what the audit covers