Technology & ethics
ABA Model Rule 1.6: protecting client confidentiality when using AI in immigration practice
Rule 1.6 and Rule 5.3 do not prohibit using software on client files. They do impose obligations that most general-purpose AI tools cannot satisfy.
Karthik Subramanian
General Counsel
March 6, 2026
10 min read
What the rules actually require
Model Rule 1.6(a) prohibits revealing information relating to the representation without informed consent. Rule 1.6(c) adds an affirmative duty: a lawyer shall make reasonable efforts to prevent inadvertent or unauthorised disclosure of, or unauthorised access to, information relating to the representation.
Rule 5.3 extends the lawyer's supervisory responsibility to non-lawyer assistance. Comment 3 makes clear this includes vendors outside the firm. Using a service to process client documents is squarely within the rule, and the obligation is to make reasonable efforts to ensure the vendor's conduct is compatible with the lawyer's professional obligations.
The specific risk with general-purpose AI
Immigration files are among the most sensitive documents a firm holds: passports, alien registration numbers, financial records, medical records in humanitarian matters, and in VAWA and U visa cases, accounts of abuse protected by 8 USC 1367.
Pasting any of that into a general-purpose assistant raises a question the firm usually cannot answer: what happens to it. Consumer tiers of most services reserve the right to use submitted content for model improvement. Even where an enterprise tier disclaims training, the disclaimer often lives in a policy page that can change rather than in the contract.
The questions to ask a vendor
The diligence here is not complicated, but it has to be specific, and the answers should be in the agreement rather than in marketing material.
- Is exclusion from model training in the contract, or only in a policy page?
- Does the exclusion cover fine-tuning and evaluation as well as pre-training?
- Where is data stored, and can residency be constrained?
- What is the retention default, and can the firm set it per matter?
- Can data be purged on demand with a certificate of destruction?
- Is there a current SOC 2 Type II report, and does it cover these controls?
- Which subprocessors touch client content, and are they disclosed?
Reasonable efforts, documented
Rule 1.6(c) sets a reasonableness standard, and Comment 18 lists factors: sensitivity of the information, likelihood of disclosure absent safeguards, cost of additional safeguards and difficulty of implementing them. Immigration files sit at the sensitive end, which raises what reasonable means.
Firms that handle this well do the diligence once, record the answers, keep the executed DPA and the SOC 2 report on file, and re-check annually. That file is the evidence of reasonable efforts if the question is ever raised.