Artificial intelligence and professional secrecy

Artificial intelligence and professional secrecy

AI and professional secrecy: why ChatGPT, Claude AI, Copilot or Microsoft 365 can put your liability at stake. The Cloud Act and the question of verifiability explained simply.

Lawyers, accountants, auditors, doctors: for two years, generative AI tools like ChatGPT, Claude or Copilot have been invited into firms. Practical for summarizing a contract, summarizing an exchange or structuring data, they nevertheless raise a central question: how to reconcile their use with the absolute obligation of professional secrecy?

Professional secrecy is not a simple recommendation of prudence. It is a strict legal obligation, unlimited in time, which engages the criminal and disciplinary liability of each professional.

About professional secrecy

For lawyers (article 66-5 of law no. 71-1130 of December 31, 1971), it covers “all information provided by the client, consultations, correspondence, documents in the file, facts known in the exercise of the profession”. The lawyer cannot be relieved of this by the client himself.

Chartered accountants (article 21 of ordinance no. 45-2138 of September 19, 1945), auditors (article L. 822-15 of the Commercial Code) and doctors (article R. 4127-4 of the Public Health Code) are subject to equivalent obligations. The data concerned includes contracts, financial statements, diagnostics, customer strategies or personal data (names, SIRET, bank details).

The sanctions provided for by article 226-13 of the Penal Code are one year’s imprisonment and a fine of €15,000, to which are added disciplinary measures which may go as far as expulsion.

Public LLMs and controlled solutions: the essential distinction

AI tools fall into two broad categories:

  • Public LLMs (ChatGPT, Claude.ai, general public versions of Copilot): data is sent to external servers, often in the United States.
  • On-premise solutions: Solution installed and hosted on your own servers (on your premises or infrastructure that you fully control), without going through the public cloud.

Between the two there is a gray area: the “Enterprise” or European cloud versions with Data Processing Agreement or DPA (data processing agreement signed between you and the service provider which defines the rules of confidentiality, security and use of your data). These contracts generally provide for the non-reuse of data for training and compliance with the GDPR. They constitute real contractual protection, but raise a question of verifiability for secrecy professionals.

The Cloud Act: an American legal constraint

Adopted in 2018, the American law Clarifying Lawful Overseas Use of Data Act (Cloud Act) allows American federal authorities to obtain data held by companies subject to American jurisdiction (Microsoft, Google, OpenAI, Anthropic, etc.), even if this data is stored in Europe.

A strong DPA contractually binds the provider, but cannot override federal law. In practice, the liberal professional does not have a direct technical means of continuously auditing possible access nor of receiving total transparency in the event of a request subject to a “gag order” (order of silence).

The professional orders are aware of this. They do not systematically condemn all cloud tools, but insist on control of data flow and verifiability.

Positions of professional orders (2024-2026)

  • CNB (lawyers): The ethical guide on AI (March 2026) recalls that professional secrecy prohibits the transmission of confidential data to a generative AI without sufficient guarantees. It requires systematic human verification and caution on uncontrolled tools.
  • CNOEC (accountants): The AI ​​usage charter recommends particular vigilance on tools that access messaging or customer data, emphasizing confidentiality and the GDPR.
  • CNOM (doctors): Health data requires HDS (Health Data Host) certified hosting. No negotiation possible on this point.

The orders recognize the usefulness of AI while positing the personal responsibility of the professional as a principle.

Risky practices and good practices

Here is a series of concrete cases to simply assess your level of exposure. The objective is to enable you to quickly identify risky situations and the measures to take.

Case 1: My employee copies and pastes a customer contract or a report into ChatGPT, Claude.ai or a general public version of Copilot

Yes, you are exposed. Confidential data is transmitted to a third party (OpenAI, Anthropic, Microsoft) without a specific protection contract adapted to professional secrecy. You have no control over the storage or possible use of this data (even if promises of “no training” exist), nor their possible requisition by the American authorities via the Cloud Act. This is the maximum risk scenario.

Recommendation: Formally prohibit this type of use for any data covered by professional secrecy.

Case 2: My firm has deployed Microsoft 365 + Copilot (or Google Workspace + Duet AI) on workstations, with hosting announced in Europe

You are exposed to significant risk to customer data. Even with a DPA and primary hosting in Europe, the Cloud Act applies because Microsoft and Google are American companies. The data passes to the AI ​​servers for processing. You have a solid contract, but you cannot independently verify possible access to US authorities. Automatic activation on emails, SharePoint or Teams amplifies the risk.

Recommendation :

  • Use Copilot/Duet only on non-confidential documents and data.
  • Disable or strictly limit automatic scanning of customer mailboxes.
  • Document internal policy and train teams.

Case 3: We use a European cloud solution with DPA, SecNumCloud or ISO 27001 certification

Reduced residual risk, but subject to verifications. The contract offers clear contractual guarantees (non-reuse for training, EU accommodation). However, verifiability remains partial: you must regularly audit the service provider, verify the absence of transit to third party jurisdictions and document these checks. This is not a “zero risk” solution, but it is generally considered acceptable by the orders if the measures are actually implemented.

Recommendation: Establish a register of AI tools, carry out periodic audits and keep a written record of technical choices.

Case 4: We use an on-premises solution or hosted by a fully controlled EU service provider (with audit rights)

You are in the safest configuration. You (or a service provider under your contractual control) physically and legally control the data flow. No applicable Cloud Act, complete traceability, real possibility of verification. This is the solution that offers the best compliance with absolute professional secrecy.

Recommendation: Maintain this control and document technical and organizational procedures.

General cases – Best practices applicable to all scenarios

  • Non-confidential data (public research, generic brainstorming, writing models without customer data): public tools are acceptable.
  • Customer data: systematically favor controlled solutions. Always humanly verify AI results.
  • For doctors: strict compliance with HDS certification for all health data.
  • Cross-sectional measurements:
    • Train and raise awareness among all employees.
    • Adopt an internal charter for the use of AI.
    • Document the authorized tools and the protective measures put in place (this will allow you to demonstrate your diligence in the event of an inspection).

In summary: the risk is not linked to AI itself, but to the level of control of the flow of confidential data. The more you control the infrastructure and the more you document your choices, the more you reduce your criminal and disciplinary exposure.

You can integrate this grid directly into your internal policy or your AI charter. If you have a specific use (e.g.: extraction of accounting data, summary of medical letters, etc.), do not hesitate to describe it to refine the analysis.

Humans remain at the center

A contract, even if well drawn up, does not replace technical mastery and verifiability. Secret professionals have an obligation to be able to justify their choices before their order or a court.

AI is neither forbidden nor magical. It is a powerful tool whose use must remain compatible with unchanged ethical rules. The orders (CNB, CNOEC, CNOM, etc.) have published updated guides between 2024 and 2026: consult them directly and adapt your processes accordingly.

Ethics have not changed with AI. What has changed is the ease with which data can leave the scope of control. It is up to each firm to decide, with full knowledge of the facts, where to place the cursor between productivity and absolute responsibility. The human decides, the AI ​​produces – but it is always the human who takes responsibility.

Jake Thompson
Jake Thompson
Growing up in Seattle, I've always been intrigued by the ever-evolving digital landscape and its impacts on our world. With a background in computer science and business from MIT, I've spent the last decade working with tech companies and writing about technological advancements. I'm passionate about uncovering how innovation and digitalization are reshaping industries, and I feel privileged to share these insights through MeshedSociety.com.

Leave a Comment