Practical Rules for Safe AI Use: Use AI Like a Junior Assistant, Not Like a Private Vault

Eran Goldman-Malka · July 23, 2026

Use AI like a junior assistant, not like a private vault.

AI Can Still Be Useful—If Used With Guardrails

The legal cases we have covered in this series (Heppner, Mata v. Avianca, the ChatGPT search warrant case, the sanctions tracker) do not mean you should avoid AI. They mean you should govern it.

AI is powerful for:

  • Brainstorming: “What are common risk factors in vendor contracts?”
  • Issue spotting: “What clauses in this NDA might create problems?”
  • Summarizing public material: “Summarize this regulatory guidance document.”
  • Drafting internal outlines: “Draft an agenda for a board risk committee meeting on AI governance.”

But AI is risky for:

  • Sharing sensitive facts: “Here are the details of our pending investigation.”
  • Revealing legal strategy: “Here is our litigation plan against the competitor.”
  • Inputting privileged communications: “Here is the memo from our outside counsel.”
  • Relying on unverified legal research: “Draft a motion based on these cases.”

The difference is simple: Safe uses keep sensitive facts out. Risky uses put sensitive facts in.

A Simple Policy: Four Rules

If your organization does not yet have an AI use policy for legal, compliance, or governance work, here is a starting point:

Rule 1: No Privileged Facts

Do not input facts or communications that are covered by attorney-client privilege or the work-product doctrine into consumer AI tools. If you need to use AI for privileged work, use an enterprise tool with confidentiality protections, and do so at the direction of counsel.

Rule 2: No Client Names or Confidential Data

Do not input client names, deal names, investigation details, trade secrets, personal data, or other confidential information into consumer AI tools. Assume that anything you input may be logged, reviewed by humans, or used to train the model—even if the privacy policy says otherwise.

Rule 3: No Litigation Strategy or Regulatory Filings

Do not use AI to draft court filings, regulatory submissions, or investigation responses without verification by a qualified lawyer or compliance officer. AI can hallucinate citations, fabricate facts, and generate plausible-sounding but incorrect legal rules.

Rule 4: Verify Everything Before Submission

If you use AI to assist with research, drafting, or analysis, verify the output before you rely on it or submit it. For legal research, check every citation. For contract drafting, review every clause. For regulatory analysis, confirm every rule. Verification is non-delegable.

What “Enterprise Tool” Means

An enterprise AI tool is one that:

  • Is used under a commercial contract (not free consumer terms).
  • Guarantees that user inputs are not used for training.
  • Guarantees that user inputs are not shared with third parties.
  • Provides data encryption, access logging, and contractual confidentiality protections.

Examples include ChatGPT Enterprise, Claude for Enterprise, Microsoft Copilot for Business (with appropriate settings), and Google Workspace AI (with appropriate settings).

Important: Even with an enterprise tool, you do not get attorney-client privilege unless the tool is being used at the direction of counsel, as part of obtaining legal advice. The tool being “private” is not enough.

What Boards Should Ask

  1. Do we have an AI use policy for legal and compliance work? Does it define safe uses, prohibited uses, and verification requirements?
  2. Do our teams know the difference between consumer and enterprise tools? Do they know which tools are approved?
  3. Do we audit AI use in high-risk areas? Do we log who used AI, for what purpose, and whether the output was verified?
  4. Do we train our teams? Do executives, lawyers, and compliance officers understand the four rules above?
  5. What is our verification workflow? Who is responsible for checking AI outputs before they are submitted or relied upon?

Do you want a sample AI-use policy tailored to your organization? I deliver board-level courses and consult on AI governance, legal risk, and policy design. Contact me.


Relevant Sources

  1. AI, Privilege, and the Heppner Ruling: What the Court Actually Held—And How to Structure AI Use Safely — Venable LLP — https://www.venable.com/insights/publications/2026/02/ai-privilege-and-the-heppner-ruling-what-the-court
  2. United States v. Heppner, No. 1:25-cr-00503-JSR, Order (S.D.N.Y. Feb. 17, 2026) — U.S. District Court, Southern District of New York — https://jlellis.net/wp-content/uploads/2026/02/USA-v-Heppner-Order-2026-02-17-AI-Not-Privileged.pdf
  3. Practical Lessons from the Attorney AI Missteps in Mata v. Avianca — Association of Corporate Counsel — https://www.acc.com/resource-library/practical-lessons-attorney-ai-missteps-mata-v-avianca
  4. AI Hallucination Cases: The 1,598-Case Sanctions Tracker — HAQQ — https://haqq.ai/blog/ai-legal-hallucination-audit
  5. Use of Generative AI in the Law: Lessons from Two Federal Cases — American Bar Association — https://www.americanbar.org/groups/litigation/resources/newsletters/privacy-data-security/generative-ai-in-the-law/

Twitter, Facebook