Before You Give an AI Agent the Master Key to Your Law Firm’s Inbox
An overloaded email account looks like an obvious job for artificial intelligence. An AI agent can sort messages, identify stale conversations, summarize long threads, suggest folders, and separate genuine client work from years of digital clutter.
That was the promise behind a recent project involving a badly entangled law firm mailbox. The concern appeared when we examined what the proposed AI agent would need in order to perform the work.
The application requested broad access to the firm’s Microsoft 365 environment, potentially including every user’s mailbox and extensive read, write, and administrative rights. Email content could then be transmitted to an outside AI provider for processing.
At that point, the project was no longer just an email-cleanup exercise. It was the digital equivalent of giving an outside company a master key to every file cabinet in the firm.
The right question was not simply, “Does the AI work?”
The better question was, “Can the firm explain and defend every place its client information will go?”
The Ethical Duty Is Broader Than Privilege
ABA Model Rule 1.6 covers information relating to a client representation, regardless of whether the information would qualify as an attorney-client privileged communication in court. It also requires lawyers to make reasonable efforts to prevent unauthorized access or disclosure. What counts as reasonable depends on the sensitivity of the information, the likelihood of disclosure, the available safeguards, and the practical difficulty of using those safeguards.
ABA Formal Opinion 512 applies those principles to generative AI. It explains that lawyers must evaluate the risk that client information entered into an AI tool could be accessed by people outside the firm or by people inside the firm who should not receive it. The opinion also directs lawyers to understand the tool’s terms of use, privacy policies, security practices, retention rules, and access arrangements, either personally or with the assistance of qualified technology and cybersecurity professionals.
The ABA does not prohibit lawyers from using cloud services or outside AI systems. The standard is fact-specific. A secure, carefully limited enterprise system may present a very different risk than a consumer AI account or an agent with unrestricted mailbox access.
One terminology point also matters. The ABA Model Rules are models used by licensing jurisdictions, not a single nationwide AI regulation. Formal Opinion 512 is influential guidance, but firms must also review their state rules, client agreements, outside counsel guidelines, court orders, protective orders, and applicable privacy laws.
Six Questions That Should Come Before the Demo
1. Where does the information actually travel?
“Processed securely in the cloud” is not a meaningful answer.
The vendor should identify each system that receives information, including the AI company, cloud host, logging provider, analytics service, support platform, and any other subprocessor. The answer should cover email bodies, attachments, headers, sender and recipient information, summaries, prompts, responses, and temporary files.
The firm should also know the countries and regions in which the information is processed, stored, backed up, and accessed.
2. What permissions does the agent truly need?
A tool cleaning one mailbox should not automatically receive access to every mailbox in the firm.
Microsoft recommends that applications request only the least-privileged permissions needed for their purpose. Exchange Online also provides application role-based access controls that can restrict an application to selected mailboxes.
For an email-cleanup pilot, the safest starting point is usually one named mailbox, read-only access, and no permission to send, forward, permanently delete, or create mailbox rules. Any broader access should require a documented technical explanation.
3. What remains after processing?
The original email is only part of the data trail.
An AI system may create summaries, classifications, embeddings, indexes, cached copies, error logs, monitoring records, or persistent “memory.” These derived materials can reveal client information just as clearly as the original message.
The vendor should disclose the maximum retention period for every category. It should also explain what deletion means, including when information disappears from caches, replicas, and backups.
“No training” is an important answer, but it is not a complete answer. The firm must also ask whether information is used for model evaluation, service improvement, abuse monitoring, product testing, or human review.
4. Who can access the information?
An absolute statement that “no one can ever access customer data” may be unrealistic. System administrators, security responders, and support personnel sometimes have technical access.
The more useful question is who can access the information, under what circumstances, with whose approval, and with what logging.
A strong system prohibits routine employee access. Exceptional access should be limited, time-bound, approved, logged, and subject to confidentiality obligations.
5. Can an email trick the AI agent?
Email is untrusted input. A malicious message or attachment may contain instructions intended to manipulate an AI system. This is known as indirect prompt injection.
NIST describes indirect prompt injection as an attack in which adversarial instructions are placed in information that an AI-enabled application is likely to retrieve. An email agent therefore needs controls that treat message content as data, not as authority to change its instructions or use additional tools.
An AI agent should not be able to follow an email’s instructions to forward documents, reveal secrets, visit an external website, change a mailbox rule, or permanently delete information. High-impact actions should require human approval.
6. What happens when something goes wrong?
The firm needs logs showing which mailbox was accessed, when it was accessed, what action occurred, which system initiated the action, and whether a human or automated process was involved.
The contract should also define a security incident broadly enough to include unauthorized access, cross-customer disclosure, improper retention, credential compromise, prompt-injection exploitation, and an AI agent taking an unauthorized action.
ABA Formal Opinion 483 says lawyers must make reasonable efforts to monitor external vendors handling data and must notify affected clients when a breach involves, or is substantially likely to involve, material client information. A vendor that waits weeks to disclose an incident may leave the law firm unable to satisfy its own obligations.
Security Promises Are an Opening Statement, Not Evidence
A SOC 2 report, ISO/IEC 27001 certificate, penetration-test summary, data-retention policy, and subprocessor list can all provide useful evidence. None of them, standing alone, proves that a particular deployment is appropriate for a law firm.
The real evidence is the complete record: the data-flow diagram, exact permissions, model-provider terms, retention settings, access logs, incident obligations, deletion process, and enforceable contract.
No AI vendor can make a law firm “ABA compliant” by declaration. The vendor supplies the technology and controls. The lawyer remains responsible for deciding whether those controls are reasonable for the particular client, matter, task, and information involved.
AI may be able to clean an inbox. It should not clean away the firm’s ability to explain who accessed client information, why they accessed it, and what happened afterward.
Companion article
Read: The Law Firm AI Vendor Questionnaire: 38 Questions, Acceptable Answers, and Red Flags
for a detailed due-diligence checklist to use before connecting an AI system to firm email, documents, or client data.
