The fastest way to have a bad AI week in New Jersey is not a clumsy prompt. It is a good prompt with a real name in it, typed into a tool that was never hired as staff.
RPC 1.6 still covers information relating to the representation, not only the privileged bits. RPC 1.6(f) still asks for reasonable efforts to prevent inadvertent or unauthorized disclosure, and unauthorized access. The Supreme Court’s January 24, 2024 Preliminary Guidelines apply those duties to AI systems. Before you enter non-public client information, you are responsible for the security of the system you are about to feed.
That is an affirmative job. “I used the free tier because the associate already had an account” is not a security review.
The Court handed you four boxes. Check one.
The March 2026 starter policy does not pretend every firm will land in the same place. It asks you to pick one confidentiality rule and write it down:
- no AI tools at all on client information or matters
- no client or matter information in public AI tools
- public tools only after you have stripped identifying information (the template’s de-identification option; if you use it, mean it)
- only approved vendor tools, after reasonable diligence on privacy, retention, security, and data-use practices
Pick one. Tell the paralegals. Put it in the engagement letters if that is how your practice talks. Do not check all four in your head and then do whatever Chrome autocomplete suggests.
What “reasonable diligence” looks like in a small office
You do not need a twenty-page vendor questionnaire to start. You do need answers you could repeat to a client without wincing:
- Does this product train on our prompts by default?
- Where does the data sit, and for how long?
- Who else can see a prompt: the vendor, subprocessors, a model researcher, a random other customer?
- What happens on termination? Can you delete the matter?
- Is there a written confidentiality commitment that matches RPC 1.6, or only a marketing page with a lock emoji?
If the terms of service say the company may use customer content to improve the model, that is not a trick question. It is the whole question. Consumer chat products often do exactly that unless you are on a plan that says otherwise. Read the plan you are actually on, not the enterprise brochure for a product you did not buy.
The 2026 sample also says to check tool settings before anyone at the firm uses an AI feature. Default settings are not your policy. They are the vendor’s policy, wearing your letterhead.
Public tools still have a job
A public chatbot can outline a statute you pasted from the official site. It can turn your own notes, already stripped of names, into a clearer list. It can help you explain a court packet in plain English, which is most of what this blog is for. That is not the same as uploading the client’s demand letter, the teenager’s school records, or the medical chronology with dates of birth still in the headers.
I will train firms on general tools, including Grok. I will also say out loud that Grok is not as confidential as a private system. For confidential documents, the work I do through Bonnie Law Consulting is on-site private setup, not a browser tab the intern opened at lunch. You do not have to buy that. You do have to stop pretending the two are the same garden.
A small ritual that prevents most of the disasters
- Write the one confidentiality rule on a half page.
- Name the approved tools, if any.
- Ban pasting captions, Social Security numbers, medical records, and “the thing opposing counsel emailed at 11 p.m.” into anything not on that list.
- If you de-identify, have a second person look at the prompt. You are bad at spotting the identifying detail you just typed.
- When a new button appears in Word or your case manager, treat it as a new tool. Check the settings. Then decide.
RPC 1.6 is older than the chatbot. The chatbot is not a loophole. It is a very fast photocopier with a poor sense of who is allowed to read the copies.