Chapter 06 · Section I · 16 min read
Confidentiality, privilege, and what never goes into a public chatbot
Pasting privileged material into a free chatbot is the easiest disciplinary breach a Nepali lawyer can commit in 2026, and it happens every week.
A senior advocate in Putalisadak has been negotiating a settlement for a textile importer for six weeks. On a Tuesday evening he finishes the draft of a without-prejudice letter that contains, in two short paragraphs, the client’s true walk-away number and the reasoning behind it. The English is stiff, so he opens a free chatbot in his browser, pastes the whole letter in, and asks for a smoother register. He gets a beautifully polished version back inside thirty seconds. He copies it out, edits two lines, and sends it. The letter goes to the other side the next morning. Nobody on the planet, other than the advocate, knows that the client’s negotiating floor is now sitting on a server in northern Virginia, indexed against an account, possibly used to improve a future model. He has just committed, in two clicks, the single most common breach of confidentiality in Nepali practice in 2026.
What you actually owe your client
Lawyer-client confidentiality is not one duty in Nepal — it is three, stacked on top of each other, and a single careless paste can breach all three at once.
The first is the Nepal Bar Council code of ethics, which binds you as a member of the profession and which the Council can discipline you under, irrespective of whether the client ever complains. The second is the Advocates Act and the broader statutory framework that recognises lawyer-client communications as protected and creates consequences for unauthorised disclosure. The third — and in practice the most likely to bite you commercially — is the engagement letter you signed, which almost always contains an express confidentiality clause and increasingly contains a specific clause about data handling, vendor processing, and overseas transfers.
When you paste a privileged document into a public LLM, you are not “using a tool.” You are transmitting client information to a third-party processor whose terms of service you almost certainly have not read, whose data residency is almost certainly outside Nepal, and whose use of your inputs for training is, depending on the tier and the day, somewhere between “yes by default” and “no but trust us.” None of that is something you have authority from the client to do. The fact that the breach is invisible — that the client will never know, the other side will never know, the Bar Council will never know — does not make it less of a breach. It makes it the kind of breach that compounds quietly, across a career, until one day a leak in a model’s training data or a journalist’s freedom-of-information request makes it visible.
The categories of risk — calibrate the tool to the material
Not every document is equally sensitive, and the tool you use should match the risk.
Highest risk — never goes into a public chatbot, period. Privileged correspondence between you and the client; witness statements, especially in criminal or sensitive civil matters; settlement positions, including your reasoning, your reservation prices, and your tactical assessment; draft pleadings before filing; instructions from counsel; internal strategy notes; anything covered by a non-disclosure agreement with a third party. The rule for this tier is simple and absolute. It does not go into ChatGPT, Claude, Gemini, or any consumer tier. It does not go in with the names changed. It does not go in “just to fix the grammar.” It does not go in.
Moderate risk — public tools acceptable only with serious redaction. Anonymised contract terms where party names, project descriptions, and identifying numbers have been scrubbed; structural facts of a case where the parties cannot be inferred; clause libraries you have built up over years; precedent material that contains no live-matter detail. Even here, the redaction has to be real — replacing “Himalayan Cement Pvt Ltd” with “Company A” is not redaction if the dispute is famous enough that the rest of the facts identify the party in two sentences. If a colleague in another firm could reconstruct the matter from what you pasted, it was not redacted.
Lower risk — generally fine. Pure legal-research questions with no client identifier — “what does Section 5 of the Contract Act 2056 say about coercion as a vitiating factor?” Drafting a letter from scratch with no client facts. Asking how a foreign jurisdiction handles a particular principle. Anything where you would be comfortable reading the prompt aloud in a Bar Council meeting.
Safe defaults the firm should adopt now
There are three patterns that hold up across Nepali practice in 2026, and a fourth that does not.
Pattern one: redact aggressively, then use a public tool for non-sensitive tasks. Strip party names, replace specific amounts with placeholders, remove dates that pin the matter, change identifying facts. Then use a free or low-cost tool for drafting help, grammar polishing, and structural feedback. This works for a surprising amount of day-to-day work, and it costs nothing.
Pattern two: pay for an enterprise tier with explicit no-training-on-inputs language and a data residency you can point to in a contract. The major providers all offer this in 2026 — ChatGPT Enterprise, Claude for Work, Gemini Workspace. The contract terms matter; the marketing page does not. Read the data-processing addendum, confirm in writing that inputs are not used for training, and document the choice in your firm’s AI policy.
Pattern three: run a local model on a firm machine for the most sensitive work. This is more accessible than it sounds in 2026. A mid-range workstation in the office can run a competent open-weights model that never sends a token outside the building. It is slower and less capable than the frontier models, but for summarising a sensitive bundle or drafting a delicate letter, it is enough — and it is the only option for material that genuinely cannot leave.
The pattern that does not hold: “everyone in this office is sensible, we don’t need a written policy.” This is the position every firm holds until the first incident. The problem is not the partners — the partners are usually careful. The problem is the junior who joined six months ago, who has used ChatGPT for everything since law school, and who genuinely does not know that the bundle on her desk this afternoon is different from a homework assignment. Without a written policy and a clear escalation path, that junior will paste the bundle in, and the firm will find out about it only if something goes wrong publicly.
The Nepal-specific concern: data residency
For the lawyers in this course who handle banking, regulatory, or financial work, there is a layer that most generic AI-ethics writing ignores. Nepal Rastra Bank has been progressively tightening rules around where banking customer data can be processed and stored. This is not aimed at AI specifically; it is aimed at cloud services generally. But every public LLM is a cloud service, and the moment you paste customer-identifying material from a banking matter into a US-hosted chatbot, you are inside the scope of those rules whether you meant to be or not.
The same direction of travel is visible in telecom, insurance, and increasingly in health and education. The trend across regulated sectors is towards data localisation and explicit consent for cross-border processing. If your practice touches any of these sectors — and most commercial practice in Kathmandu touches at least one — the AI policy you write for the firm needs to acknowledge it. The minimum is a written rule that material from regulated-sector clients goes only into tools whose data residency is documented and acceptable, and that material from the most sensitive matters does not leave the country at all.
The micro-policies that make this real
Policies that live in a document nobody reads do nothing. The discipline that actually works is a small number of micro-rules that everyone in the firm can recite.
Never paste a full unredacted contract into a public chatbot. Use the enterprise tier, or redact, or do not use AI for that document. Never upload a client bundle, in full, to a tool whose data handling you cannot describe in one sentence. Document the tool you used in the file note for every matter — one line is enough: “Draft prepared with assistance from [tool], partner-reviewed.” When the answer to “is this safe to paste in” is anything other than a confident yes, the answer is no. And when in doubt, ask a partner before you paste, not after.
These are not heroic rules. They are the equivalent of locking the office at night. The lawyers who internalise them will, ten years from now, have careers and reputations intact. The ones who do not will, on average, have at least one story they wish they could untell.
Check your understanding
Quick check
—You are drafting a sensitive settlement letter for a banking client. The English needs polishing. What is the safest way to involve AI?
Quick check
—A senior partner says: ‘Everyone in this office is sensible. We do not need a written AI policy.’ What is the strongest counter-argument?
What comes next
Confidentiality is the question of what goes in. The next section is the question of what comes out — the verification workflow that has to follow every AI-produced statute, case, or regulation before it goes anywhere near a pleading, a client letter, or a court. It is the second half of the same discipline.