Hardly any sector benefits as directly from language models as legal practice — and hardly any has harder guardrails: professional secrecy carries criminal sanctions in Germany, and the most famous AI accident in legal history happened, of all people, to a lawyer. Together, the two yield a clear operating manual.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
For holders of professional secrets, handling client data is not a mere data-protection question: in Germany, breaching private secrets is a criminal offence (Section 203 Criminal Code), and German bar rules demand particular care when engaging service providers (Section 43e Federal Lawyers' Act) — bar rules elsewhere impose equivalent duties of confidentiality and supervision. A draft pleading with names, file references and facts in a public free tool is therefore not an efficiency gain but a professional risk.
In practice that means: AI tools only on a contractual footing (data processing agreement, confidentiality commitments, training switched off) — or with rigorously anonymised inputs, where the facts are abstracted far enough that no inference to the mandate is possible.
Mata v. Avianca (S.D.N.Y. 2023): a New York lawyer filed a brief that ChatGPT had supported with six precedents — all six freely invented, with plausible citations and quotes. A hearing and a sanction of 5,000 US dollars followed. The lesson is not “no AI”, but: every authority is checked against the original before it goes into a filing. Language models are drafting aids, not research authorities.
| Use | Line |
|---|---|
| Drafting and structuring help for pleadings | With anonymised facts or in vetted legal-tech tools; professional review remains indivisibly with the lawyer. |
| Summarising your own documents | Only in tools with a contract; every “addition” by the AI is a hallucination and is thrown out. |
| Firm marketing, client newsletters | Unproblematic — ordinary texts carry no labelling duty; fact-check as with any text. |
| Research results, citations, case law | Distrust on principle: verify at the original (database, EUR-Lex, official reports). |
Clients — especially companies with compliance duties of their own — increasingly ask their firms about their AI practice; professional indemnity insurers are following. The answer is the same organisation the AI Act suggests: a tool inventory, a firm policy (permitted tools, taboo data, review duties), and training records per person — from partner to trainee. Article 4 of the EU AI Act has required firms, as deployers, to support their team's AI literacy since February 2025; the provision carries no separate fine, but the management's duty of organisation exists independently of it.
Free 2-minute check; team training (35–45 minutes per person) with a publicly verifiable certificate, inventory, policy and audit file in the subscription from €49/month. The legal analysis of the individual case naturally remains your domain — we supply the organisation underneath.
Yes — but not with client data in public free tools: professional secrecy is criminally protected in Germany (Section 203 Criminal Code), and bar rules elsewhere impose equivalent duties. Permissible are tools on a contractual footing with training switched off, or rigorously anonymised inputs with no inference to the mandate.
ChatGPT supplied a New York lawyer with six freely invented precedents complete with plausible citations; he filed them unchecked — a sanction of 5,000 US dollars followed (S.D.N.Y. 2023). The lesson: every authority is verified at the original before it goes into a filing.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free