Is It Ethical to Use ChatGPT for Contract Review? The 2026 Guidance, Explained

Published: August 9, 2026 — "Can I use ChatGPT to review contracts?" is one of the most asked questions in legal tech — and since February 2026, the answer carries real consequences. Here's what the ABA's Formal Opinion 512 actually requires, why contract review is the riskiest use case, and five rules that keep you ethical.

⚖️ Quick Takeaways

Why This Question Matters More in 2026

For two years, the answer to "can I use ChatGPT for contract review?" lived in law-firm seminars and ethics CLEs. In 2026 it lives in court orders. In United States v. Heppner (S.D.N.Y., February 2026), a federal judge held that documents a defendant generated with a consumer AI chatbot were not protected by privilege — in part because the platform's terms allowed it to collect and disclose user inputs. The message for lawyers is blunt: the tool you use and the way you use it are now part of the privilege and ethics analysis, not an afterthought.

The professional-conduct baseline hasn't changed — and that's the point. The ABA's position, and the position of state bars that have followed it, is that using AI doesn't create new ethical duties; it applies the existing ones to a new tool. You just have to know what those duties are.

What the ABA Actually Says

On July 29, 2024, the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512 — its first formal ethics opinion on generative AI tools. It maps the existing Model Rules onto GAI use:

🧠 Rule 1.1 — Competence

Lawyers must have a "reasonable understanding" of the capabilities and limitations of any AI tool they use — and must review and verify output before relying on it.

🔒 Rule 1.6 — Confidentiality

All information relating to the representation is confidential. Disclosing it to a third party — including an AI provider — generally requires client informed consent.

💬 Rule 1.4 — Communication

Clients must be told how their matter is being handled when they ask, or when the use of AI materially affects the representation.

⚖️ Rule 3.3 — Candor

No fabricated citations. AI that invents cases must not reach the tribunal — the lawyer remains responsible for what's filed.

💵 Rule 1.5 — Fees

AI doesn't change the fee rules: charges must be reasonable, and you can't bill for AI the way you'd bill for attorney time without being transparent.

🏢 Rules 5.1 & 5.3 — Supervision

Firm leaders must establish clear policies on generative AI use, and lawyers must supervise anyone (human or automated) doing work on a matter.

The Confidentiality Problem Is Worse for Contracts Than Anything Else

Contract review is the highest-risk use case for general-purpose chatbots, and the reason is simple: a contract is a bundle of client confidences. Names, deal terms, pricing, intellectual property, personal data, and business strategy — the whole document is the kind of "information relating to the representation" that Rule 1.6 protects.

When you paste that contract into a public chatbot, the provider's terms govern what happens next. Many platforms collect user inputs and outputs, use them for training, and reserve the right to disclose data to third parties. Under the logic courts applied in Heppner, that arrangement can destroy the confidentiality that privilege and Rule 1.6 both depend on. You can't un-send a contract to a training corpus.

⚠️ The practical test: before you paste a single clause, ask — "If this document appeared in a training dataset or a data breach, could I defend that decision?" If the answer is uncomfortable, the document shouldn't go into the tool.

The Competence Problem: Verification Is Non-Negotiable

Confidentiality is only half the ethics equation. The other half is competence. General-purpose chatbots hallucinate — they invent clauses, misstate legal standards, and produce confident nonsense. Formal Opinion 512 is explicit: the lawyer must review GAI output and correct errors before relying on it. A contract review where the AI's summary of a liability cap or an indemnity clause goes unverified is a review where the client's risk went unmanaged.

This is why the most useful AI contract tools are built differently: they don't answer from memory, they answer from the document. A retrieval system that grounds every statement in the exact passage it retrieved — with a citation you can click and check — turns "the AI said so" into "the contract says so, on page 14." That's the difference between a hallucination risk and a workflow.

5 Rules for Ethical Contract Review With AI

  1. Know your tool before you use it. Read the provider's data, retention, training, and disclosure terms. If you can't verify how data is handled, it's not approved for client work (Rule 1.1's "reasonable understanding").
  2. Keep client documents out of public chatbots. Use tools where the document stays under your control — ideally local AI on your own hardware.
  3. Get informed consent when required. Where disclosure to a third party is involved, Rule 1.6 requires client informed consent. When in doubt, ask — and document the answer.
  4. Verify every output. Check citations, re-read the clauses the AI summarized, and correct errors before the work leaves your desk. You sign the work, not the model.
  5. Put it in writing. Under Rule 5.1, firm leadership should adopt an AI policy: approved tools, prohibited tools, and review procedures. "No policy" is itself a finding waiting to happen.

A Safer Architecture: Local AI Contract Review

The clean way to satisfy both halves of the ethics analysis at once is local AI. A local RAG pipeline indexes your contracts on your own machine, retrieves the relevant passages, and answers with inline citations — with no third party receiving anything. Confidentiality is protected by architecture rather than by a terms-of-service clause, and verification is built into the answer format.

💡 Working example. Lawyer Assistant is a free, open-source legal AI that runs 100% on-device: hybrid search across your documents, answers with citations, and a compliance playbook scan that flags, rates, and explains risky clauses. No account, no cloud, no telemetry. See how the pipeline works in Lawyer Assistant: A Privacy-First Legal AI Built on a Local RAG Pipeline, and why the confidentiality stakes are so high in AI Just Waived Attorney–Client Privilege in Court.

Frequently Asked Questions (FAQ)

Is it ethical for lawyers to use ChatGPT for contract review?

It can be ethical, but only if the lawyer complies with their professional obligations. The ABA's Formal Opinion 512 (July 2024) applies the existing Model Rules to generative AI: competence (Rule 1.1), confidentiality (Rule 1.6), communication (Rule 1.4), candor (Rule 3.3), fees (Rule 1.5), and supervision (Rules 5.1 and 5.3). The main problem with general-purpose chatbots is confidentiality — contracts contain client information.

What does ABA Formal Opinion 512 say?

Issued July 29, 2024, it is the ABA's first formal ethics opinion on generative AI. It holds that lawyers using GAI must have a reasonable understanding of the tool's capabilities and limitations, must protect client confidentiality under Rule 1.6 (with client informed consent before disclosure), must review and verify output, must be candid with tribunals, and firm leaders must establish policies under Rule 5.1.

Can I paste a contract into ChatGPT?

You should not paste full contracts or other client documents into public, general-purpose chatbots without careful analysis and client informed consent. Inputs can be collected, used for training, or disclosed under the provider's terms — which is exactly the kind of third-party exposure that courts (like US v. Heppner) have found defeats confidentiality.

What is the safest way for lawyers to use AI for contract review?

Local AI that runs on your own hardware. Documents are indexed and answered on-device, so nothing is sent to a third party. Lawyers still must verify every answer and cite sources — but the confidentiality element of the ethics analysis is satisfied by the architecture.

Do lawyers have to tell clients they used AI?

Under ABA Formal Opinion 512 and Model Rule 1.4, a lawyer must communicate with the client about how the matter is being handled when the client asks or when disclosure is needed for informed decision-making. Many jurisdictions also require or recommend disclosure before using AI on client matters — check your state bar's guidance.

⚖️ Need this built for your firm?

I design and deploy privacy-first local AI systems — private RAG, cited answers, on-premise LLMs for legal and regulated work. Contact me for a scoping conversation, no obligation. Or start with the free, open-source Lawyer Assistant — private legal AI on your own machine.