For law firms

ABA Formal Opinion 512, explained: duties, state-bar follow-ups and a ten-step checklist (2026)

Published 17 July 2026 · Updated 30 August 2026 · Occlira team

ABA Formal Opinion 512 (29 July 2024) is the ABA’s first formal ethics opinion on generative AI. It applies the existing Model Rules: understand the tool, evaluate the confidentiality risk, get informed consent where the tool could disclose client information, verify every output, supervise your people, and bill actual time. Below: the opinion with page cites, what state bars and courts have added through 2026, and a ten-step checklist for a firm policy. General information, not legal advice.

Jump to: the rules in play · confidentiality and consent · anonymizing client data · sanctions · supervision · fees · what changed since 2024 · checklist · FAQ

Short answer. The confidentiality core of Opinion 512: before inputting information relating to a representation into a self-learning tool, evaluate the risk and, where the tool could disclose the information, obtain the client’s informed consent; a boilerplate engagement-letter clause “is not sufficient.” The opinion says nothing about anonymization. Most of the state and local bar opinions that address it (table below) treat stripping client identifiers before input as a primary safeguard; D.C.’s warns that unusual facts can still identify the client anyway.

What ABA Opinion 512 says

Formal Opinion 512, “Generative Artificial Intelligence Tools” (the opinion abbreviates it “GAI”), was issued on 29 July 2024 by the ABA Standing Committee on Ethics and Professional Responsibility. Its headnote: lawyers using generative AI “must fully consider their applicable ethical obligations, including their duties to provide competent legal representation, to protect client information, to communicate with clients, to supervise their employees and agents, to advance only meritorious claims and contentions, to ensure candor toward the tribunal, and to charge reasonable fees.” (Source: ABA Formal Opinion 512, p. 1; ABA press release.)

It creates no new “AI rule”; it interprets the Model Rules as amended through August 2023 (fn 4). It is persuasive, not binding: your duties come from the rules your jurisdiction has adopted. And it dates itself on purpose: its consent conclusion “is based on the risks and capabilities of GAI tools as of the publication of this opinion. As the technology develops, the risks may change in ways that would alter our conclusion” (fn 34).

The Model Rules Opinion 512 puts in play

Model RuleWhat the opinion says it means for generative AI
1.1 — CompetenceLawyers “need not become GAI experts” but must have “a reasonable understanding of the capabilities and limitations of the specific GAI technology” they use, and that understanding “is not a static undertaking” (pp. 2–3). Relying on output “without an appropriate degree of independent verification” can violate the duty (pp. 3–4).
1.6 — ConfidentialityEvaluate the risk of disclosure before inputting any information relating to a representation; for self-learning tools, “a client’s informed consent is required” (p. 7). Duties to former (1.9(c)) and prospective (1.18(b)) clients apply too (p. 6).
1.4 — CommunicationDisclose GAI use when a client asks and when the engagement terms require it. Consult the client, a conversation rather than a notice, when consent is needed, when the use is “relevant to the basis or reasonableness” of the fee, and when the output “will influence a significant decision in the representation” (p. 8).
3.1, 3.3 & 8.4(c) — Meritorious claims and candor“Even an unintentional misstatement to a court can involve a misrepresentation under Rule 8.4(c). Therefore, output from a GAI tool must be carefully reviewed to ensure that the assertions made to the court are not false” (p. 10): citations, analysis and controlling authority.
5.1 & 5.3 — SupervisionManagerial lawyers “must establish clear policies regarding the law firm’s permissible use of GAI”; supervisors must make reasonable efforts to ensure lawyers and nonlawyers comply (p. 10). Vet GAI vendors as you would any outsourcing (p. 11).
1.5 — FeesBill “actual time” (p. 12); a flat fee may become unreasonable if the tool changes the work (p. 12); per-use tool costs can be passed through at cost (p. 13); a lawyer “may not charge a client to learn about how to use a GAI tool” the lawyer will use regularly (p. 14).

Quotations and page numbers from the official PDF.

The confidentiality core: Rule 1.6, self-learning tools and informed consent

The duty is broad: keep confidential “all information relating to the representation of a client, regardless of its source” (p. 6). Before inputting any of it, lawyers “must evaluate the risks that the information will be disclosed to or accessed by others outside the firm” (p. 6). The same test runs inside the firm: against colleagues who “will not adequately protect the information,” often because they do not know it came from a client of the firm, and against anyone behind an ethical wall (pp. 6–7). That analysis “will be fact-driven and depend on the client, the matter, the task, and the GAI tool used to perform it” (p. 6).

The opinion’s operative sentence is that “because many of today’s self-learning GAI tools are designed so that their output could lead directly or indirectly to the disclosure of information relating to the representation of a client, a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool” (p. 7). Informed means the client has “the lawyer’s best judgment about why the GAI tool is being used, the extent of and specific information about the risk, including particulars about the kinds of client information that will be disclosed, the ways in which others might use the information against the client’s interests, and a clear explanation of the GAI tool’s benefits to the representation” (p. 7).

It rejects the usual shortcut: “merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient” (p. 7). There is one exception: consent is not needed when “the lawyer will not be inputting information relating to the representation,” and the opinion’s example is using the tool for idea generation (p. 7).

There is also a baseline. “As a baseline, all lawyers should read and understand the Terms of Use, privacy policy, and related contractual terms and policies of any GAI tool they use to learn who has access to the information that the lawyer inputs into the tool or consult with a colleague or external expert who has read and analyzed those terms and policies” (p. 7). The duty is to know what the terms say; the opinion lets you get there through someone who has read them. That includes whether the tool “retains information submitted by the lawyer before and after the discontinuation of services or asserts proprietary rights to the information” (p. 11). For what the consumer chatbots currently do with pasted text, see whether ChatGPT saves your data.

The classification that matters is not the brand but the design: a self-learning tool can use your input to train the model, and any tool can retain it or expose it to others. So the questions to put to any product, including a firm deployment of a consumer brand, are whether inputs are used for training, how long they are retained and who can access them. The Terms of Use answer most of that, and the answer shapes the risk assessment and whether informed consent is required.

Does anonymizing client data satisfy Opinion 512?

Opinion 512 never uses the words “anonymize,” “de-identify” or “redact.” Its trigger is “information relating to the representation,” which is broader than client-identifying data. The anonymization guidance comes from state and local bar opinions, two of them issued before 512. Eight are quoted below:

JurisdictionOpinionOn anonymizing client data before AI
AlaskaEthics Op. 2025-1 (Apr 2025)“To safely use GAI that self-learns outside of a closed system, lawyers must fully anonymize their inputs to protect client confidences and secrets, unless a client gives informed consent otherwise.”
OregonFormal Op. 2025-205 (Feb 2025)“When using an open model without client consent, lawyers need to anonymize or redact information that the client considers sensitive. Lawyers must ensure that the anonymization or redaction is complete and effective, and even so, the client’s informed consent may still be required.”
New York City BarFormal Op. 2024-5 (Aug 2024)Consent is “not needed if no confidential client information is shared, for example through anonymization of client information”; even with consent, a lawyer should “avoid entering details that can be used to identify the client”.
New MexicoFormal Advisory Op. 2024-004 (Sep 2024)“[L]awyers should always anonymize client information and refrain from inputting details that could lead to the discovery of the client’s identity into Generative AI tools.”
KentuckyKBA E-457 (Mar 2024)“[A]n attorney should take care that any information inputted into a generative AI product does not identify the client or the nature of the representation.”
North Carolina2024 FEO 1 (Nov 2024)“Generally, and as of the date of this opinion, lawyers should avoid inputting client-specific information into publicly available AI resources.”
AlabamaFormal Op. 2026-01, “Artificial Intelligence Use: Best Practices Under Existing Professional Conduct Rules” (published 2026; the document itself is undated)From its quick-reference checklist: “Anonymized or removed identifiable client information from my prompts, or obtained client consent for its inclusion.”
D.C. BarEthics Op. 388 (Apr 2024)The limit: the rule that hypotheticals are fine where the client cannot be identified “may tempt GAI users to try to protect client confidentiality by anonymizing information that they submit to the GAI,” but “the more information a lawyer provides to a growing GAI dataset, the greater the likelihood that the GAI or one of its other users will be able to connect the dots and link the information the lawyer provided to the client in question.”

Sources: Alaska 2025-1, Oregon 2025-205, NYC Bar 2024-5 (the “avoid entering details” wording is quoted from California’s 2023 Practical Guidance, which California replaced in May 2026), New Mexico 2024-004, Kentucky E-457, North Carolina 2024 FEO 1, Alabama 2026-01, D.C. Bar 388.

Six of the eight (Alaska, Oregon, New York City, New Mexico, Kentucky and Alabama) treat stripping identifiers as a safeguard. Alaska uses “must,” for self-learning tools outside a closed system. New York City treats it as the alternative to consent when the tool is open. Oregon requires it too but stops short of calling it a substitute: even after complete redaction, “the client’s informed consent may still be required.” Of the other two, North Carolina prefers avoidance: keep client-specific information out of public tools altogether. D.C. states the limit, which is also in Model Rule 1.6 itself: the prohibition “also applies to disclosures by a lawyer that do not in themselves reveal protected information but could reasonably lead to the discovery of such information by a third person” (Comment [4]). (Source: ABA Model Rule 1.6, comments.)

Strip the names and paste, for example, our client, the only female CFO of a Fortune-500 aerospace firm, admits she backdated the option grant: the identifiers are gone, but the client is not.

Minimization is the safeguard most of these opinions converge on, though the line is not moving only one way. The 2023 California guidance that supplied much of this language told lawyers they “must anonymize client information”; the version that replaced it in May 2026 drops the word entirely and asks instead whether the tool “may present material risks to confidentiality or security,” in which case informed consent is what the rule requires. Where minimization is still the answer, it must be complete: Oregon’s “complete and effective” is where shortcuts fail (a name in a footnote, a document’s comments and author metadata, a case number in a header). And it does not replace the consent judgment for facts that still relate to the representation.

Verify every output: what courts have done

On candor, the opinion is direct: “Issues that have arisen to date with lawyers’ use of GAI outputs include citations to nonexistent opinions, inaccurate analysis of authority, and use of misleading arguments” (p. 10). In a judicial proceeding, the duties owed to the tribunal require the lawyer to review the output before filing and “to correct errors, including misstatements of law and fact, a failure to include controlling legal authority, and misleading arguments” (p. 10).

How much checking is a sliding scale, not a rule of re-reading everything: “The appropriate amount of independent verification or review required to satisfy Rule 1.1 will necessarily depend on the GAI tool and the specific task that it performs,” and a lawyer who has already tested a summarizer against a sample “would not necessarily have to manually review the entire set of documents” (p. 4). Citations are the exception. Those get checked one by one, and the cases below are what happens when they are not. Courts have put numbers on it:

WhenCaseConsequence
June 2023Mata v. Avianca (S.D.N.Y.)$5,000, jointly against two lawyers and their firm, for six fabricated ChatGPT cases
Feb 2025Wadsworth v. Walmart (D. Wyo.)$5,000 across two Morgan & Morgan lawyers ($3,000 and $1,000) and the lawyer serving as local counsel ($1,000); one pro hac vice admission revoked; the fake cases came from the firm’s internal AI platform
May 2025Lacey v. State Farm (C.D. Cal.)$31,100 against Ellis George and K&L Gates; “approximately nine of the 27 legal citations… were incorrect in some way”
July 2025Johnson v. Dunn (N.D. Ala.)Three Butler Snow lawyers publicly reprimanded, disqualified from the case and referred to the state bar; the fabricated citations came from ChatGPT and were never checked, despite the firm’s written AI policy
Dec 2025 – Mar 2026Couvrette v. Wisnovsky (D. Or.)$110,204.38 in total: a $15,500 fine ($500 per non-existent case, $1,000 per fabricated quotation) plus the other side’s fees and costs, finalized in March 2026; 15 non-existent cases and 8 fabricated quotations across three briefs
Mar 2026Whiting v. City of Athens (6th Cir.)$15,000 per lawyer plus the other side’s full appellate fees and double costs; “smaller fines have plainly been inadequate”
Apr 2026Nebraska Supreme Court (disciplinary order)Attorney suspended “until further notice” pending disciplinary proceedings after a brief in which, by opposing counsel’s count as reported at the time, 57 of 63 references had problems; he had denied using AI when the justices asked him directly, then admitted it in a later filing
Apr 2026Ibach v. Stewart (Ala.)Appeal dismissed outright over AI-fabricated citations; the appellants’ lawyer ordered to pay $17,200 in fees and costs plus double costs, referred to the state bar, and barred from filing anything further in that court unless a lawyer in good standing co-signs

Sources: Mata (docket, CourtListener); Wadsworth and Lacey (Volokh Conspiracy); Johnson v. Dunn (EDRM); Couvrette (ABA Journal, on the December 2025 order) and the orders of 12 December 2025 and 23 March 2026 (D. Or. No. 1:21-cv-00157); Whiting (LawSites); Nebraska (WOWT); Ibach v. Stewart (Ala., 24 April 2026).

The AI Hallucination Cases database maintained by Damien Charlotin listed 1,983 decisions worldwide, 1,364 of them in the United States, as of 30 August 2026. Worldwide, 363 carried a monetary sanction and 154 a disciplinary referral, on the database’s own filters and out of the 1,964 entries it does not class as merely alleged. (Source: AI Hallucination Cases, accessed 30 August 2026.)

Supervision, policies and vendors (Rules 5.1 and 5.3)

“Managerial lawyers must establish clear policies regarding the law firm’s permissible use of GAI, and supervisory lawyers must make reasonable efforts to ensure that the firm’s lawyers and nonlawyers comply with their professional obligations when using GAI tools” (p. 10). Training, the opinion suggests, could include “the basics of GAI technology, the capabilities and limitations of the tools, ethical issues in use of GAI and best practices for secure data handling, privacy, and confidentiality” (p. 10). One concrete idea sits in a footnote: that “all materials produced by GAI tools be marked as such when stored in any client or firm file” (fn 52).

Vendors get the treatment the ABA already prescribed for cloud services and outsourcing: check reliability, security measures and policies, and make sure the tool “is configured to preserve the confidentiality and security of information” (p. 11). Johnson v. Dunn shows the limit of a policy on paper: the firm had one from 2023, the sanctioned lawyers did not follow it, and the court sanctioned them, not the firm.

Fees (Rule 1.5)

Hourly lawyers “must bill for their actual time” (p. 12). The opinion’s example: a lawyer who spends 15 minutes inputting the relevant information to draft a pleading “may charge for the 15 minutes as well as for the time the lawyer expends to review the resulting draft for accuracy and completeness” (p. 12). A flat fee agreed before the tool changed the work may become unreasonable (p. 12).

Tool costs fall on either side of a line: an embedded feature like a grammar checker is overhead, while a per-use third-party service can be billed “as an expense for the actual out-of-pocket expense incurred” (p. 13). Where a cost is passed on, the opinion adds, the lawyer must explain the basis for the charge before making it, preferably in writing (p. 12). A lawyer “may not charge a client to learn about how to use a GAI tool or service that the lawyer will regularly use for clients.” The one exception is narrow: if the client asks for a specific tool the lawyer does not know how to use, billing “may be appropriate,” after the two of you agree the billing terms (p. 14).

What changed after July 2024: state bars and court rules

As of August 2026 the ABA has issued no further formal opinion on generative AI; Formal Opinions 513 through 524 address other subjects (see the ABA’s opinion index). Its Task Force on Law and Artificial Intelligence published a Year 2 report in December 2025 on how far AI use has spread across practice. (Source: LawSites, December 2025.) What has landed since Opinion 512:

  • State ethics opinions. Besides the anonymization table above: Pennsylvania and Philadelphia’s Joint Opinion 2024-200 says no confidential information should go into AI that “lacks adequate confidentiality and security protections.” Texas Opinion 705 (February 2025) tells lawyers to be “reasonably satisfied that the program will not reveal confidential information to others,” and bars billing for time “saved.”
  • Colorado, 8 January 2026. The Colorado Supreme Court amended its Rules of Professional Conduct (Rule Change 2026(02)). A new Scope comment [20A] says technology’s “role does not diminish a lawyer’s responsibilities under these Rules.” A new Rule 1.1 comment [9] adds that “reliance on technology does not diminish the lawyer’s duty to exercise independent judgment in the representation of a client.”
  • New York, 22 NYCRR Part 161, in force 1 June 2026. Statewide: AI use in court papers “should not be prohibited,” and lawyers “should not be required, upon submitting papers, to disclose to the court that they have used AI,” because the existing duties already apply. Individual courts may adopt the rule’s model certification that a paper contains no fabricated cases. (Source: NY Courts, Part 161.)
  • Florida Rule 2.515(d)(2), effective 15 June 2026. The opposite design: every signer now represents that “the legal authorities identified exist and are accurately cited,” replacing a patchwork of circuit-level AI certification orders; the rule lists sanctions from reprimand to dismissal. A federal magistrate judge in Florida has since suggested the same certification for Rule 11. (Sources: Jones Day, June 2026; Barnes & Thornburg, June 2026.)
  • Individual judges’ standing orders requiring disclosure or verification of AI-assisted filings, beginning with Judge Brantley Starr’s May 2023 certification in the Northern District of Texas. Ropes & Gray’s tracker cataloged over 550 standing orders, local rules and decisions as of May 2026. Check the judge before you file. (Source: Ropes & Gray, 6 May 2026.)

An ABA Opinion 512 compliance checklist: ten steps for a firm AI policy

Ten steps, each anchored to the opinion or to the state guidance quoted above. The same list is available as a one-page PDF to print or drop into your firm’s AI policy.

  1. Know the tool before you use it. Read its Terms of Use and privacy policy, or have a colleague or an outside expert who has read them brief you (p. 7): who can access what you input, whether it trains on it, and whether the tool “retains information submitted by the lawyer before and after the discontinuation of services” (Opinion 512, pp. 7, 11).
  2. Classify the task. Idea generation that inputs no information relating to the representation needs no consent. Anything that touches the matter triggers the Rule 1.6 analysis (p. 7).
  3. Assess the risk with the Comment [18] factors. Sensitivity of the information, likelihood of disclosure without safeguards, cost and difficulty of safeguards, and how far they hamper the representation (p. 6; Rule 1.6, Comment [18]).
  4. Minimize before input. Remove client identifiers and any facts whose disclosure “could reasonably lead to the discovery of such information by a third person” (Rule 1.6, Comment [4]), and do it before the text is submitted to the tool. Then check the result: Oregon’s opinion says anonymization must be “complete and effective,” and D.C.’s warns that unusual facts can still identify the client.
  5. Decide on consent, and make it specific. If information relating to the representation will go into a self-learning tool, obtain informed consent that explains the tool, the risk and the benefit. A boilerplate engagement-letter clause “is not sufficient” (p. 7).
  6. Check the engagement terms and communicate. Follow any client instructions or outside-counsel guidelines on AI; disclose when asked or when the terms require it; consult the client when consent is needed, when the use bears on the fee, or when the output drives a significant decision (pp. 8–9).
  7. Verify every output before it leaves your desk. Confirm each cited authority exists and says what you claim, check the facts, and make sure controlling authority has not been left out (p. 10).
  8. Supervise. A written firm policy, training on the tools’ limits and on secure data handling, and (one suggestion in the opinion) marking AI-generated materials as such in the file (pp. 10–11, fn 52).
  9. Bill honestly. Actual time, not time saved; revisit flat fees; pass tool costs through at cost after explaining the basis for the charge; do not bill for learning a tool you will use regularly (pp. 12–14).
  10. Check your own jurisdiction and your court. State opinions differ: Alaska’s says lawyers “must fully anonymize” inputs to a self-learning tool outside a closed system unless the client consents; Texas and Pennsylvania add conditions of their own. Some courts now require a certification that cited authorities exist (Florida statewide from June 2026, and many individual judges by standing order). Check both before you file.

How Occlira helps with the minimization step

Occlira performs one step of the checklist, minimizing before input, and nothing else. It runs on the lawyer’s own computer, with detection on-device and no account; the app connects only to activate the license, download the model and check for updates. Open a document, email, spreadsheet or scan and it finds the personal data: names, addresses, phone numbers, ID and account numbers, dates. Each item carries a confidence score, so you decide what to keep or remove, and you can add anything it missed by selecting it.

Word and Excel files come back with formatting intact and their hidden layer cleaned (comments, tracked changes, author metadata); PDFs, emails and scans come back as clean text. Values are replaced by consistent placeholders such as <PERSON_1>, and the mapping to restore them stays on your machine.

Occlira flagging client identifiers (names, an organization, dates, an address and a phone number) in a document for local review before a lawyer uses an AI tool.
Occlira flags the identifiers in a document so you can remove them locally before any AI tool sees the file.

It does one thing: it helps keep identifying material out of a self-learning tool. It is not everything the state opinions ask for: North Carolina would keep client-specific information out of public tools altogether. And the consent duty can still attach to non-identifying facts that relate to the representation, so Occlira is a tool for the minimization step, not a compliance guarantee and not legal advice. The mechanics are in anonymize text before ChatGPT, the file-by-file how-to in redact Word, PDF and Excel, and the wider picture for firms in Occlira for law firms.

Frequently asked questions

The American Bar Association’s first formal ethics opinion on lawyers’ use of generative AI, issued on 29 July 2024 by its Standing Committee on Ethics and Professional Responsibility. It creates no AI-specific rule; it explains how the existing Model Rules (competence, confidentiality, communication, candor, supervision and fees) apply when a lawyer uses a generative-AI tool.

No. ABA formal opinions are persuasive guidance. Your duties come from the rules of professional conduct your jurisdiction has adopted and from your own bar’s opinions, which are themselves advisory. More than a dozen states have issued generative-AI opinions since 2024, and some go further than the ABA: Alaska’s, for example, says lawyers “must fully anonymize their inputs” to a self-learning tool outside a closed system unless the client gives informed consent.

Often, yes. The opinion says that because many self-learning tools could disclose what you put in, “a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool.” Consent is not required when you input nothing relating to the representation, such as using the tool for idea generation. The opinion adds that this conclusion reflects the tools as of 2024 and may change as the technology develops.

No. The opinion states that “merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient.” Informed consent means the client has your best judgment about why the tool is used, what client information will be disclosed, how others might use it, and what the benefit is.

Opinion 512 does not say either way. Several state and local bars do. The New York City Bar says consent is not needed if no confidential client information is shared, “for example through anonymization.” Alaska goes further: inputs to a self-learning tool outside a closed system must be fully anonymized unless the client consents. The counterweight is Rule 1.6 Comment [4] and D.C. Bar Opinion 388: disclosures that could reasonably lead to identifying the client are still disclosures, and unusual facts can let a tool “connect the dots.” Treat anonymization as the safeguard these opinions converge on, not as a clearance: verify it is complete, and still make the consent judgment for sensitive matters. North Carolina is stricter and would keep client-specific information out of public tools altogether.

Yes, in the opinion’s own words, and it tracks rules your jurisdiction has already adopted. Output “must be carefully reviewed to ensure that the assertions made to the court are not false,” and even an unintentional misstatement can be a misrepresentation under Rule 8.4(c).

No. Under Rule 1.5, hourly billing is for actual time. The opinion’s example is a lawyer who spends 15 minutes inputting information to draft a pleading: bill those 15 minutes and the review time, not the time the tool did not take. Flat fees may need revisiting, and per-use tool costs can be charged at cost once you have explained the basis for the charge. You may not bill for learning a tool you will regularly use for clients, unless the client asked for a specific tool you do not yet know how to use and you agreed the billing terms in advance.

It depends on the court. New York’s Part 161 (in force 1 June 2026) says lawyers “should not be required” to disclose AI use as long as they meet their existing duties, though individual courts may adopt a certification. Florida’s Rule 2.515(d)(2) (15 June 2026) makes every signer certify that cited authorities “exist and are accurately cited.” Many individual federal judges have standing orders requiring disclosure or certification, so check the local rules and the judge’s order before filing.

No further formal ethics opinion on generative AI as of August 2026; Formal Opinions 513 through 524 address other subjects. The ABA Task Force on Law and Artificial Intelligence published its Year 2 report in December 2025 on how AI use has spread across legal practice.

Yes: the ten-step checklist above, also available as a PDF, turns the opinion’s duties into a firm policy: know the tool, classify the task, assess the risk, minimize before input, decide on consent, check the engagement terms and communicate, verify every output, supervise, bill honestly, and check your own jurisdiction and court. It is a working aid, not a compliance guarantee; the rules that bind you are the ones your state has adopted.

It performs one step, stripping identifiers before input, on the lawyer’s own computer. It takes a file (a document, email, spreadsheet or scan), detects the personal data in it, lets you review and confirm each item, replaces the values with consistent placeholders, and restores them locally afterward; nothing is uploaded. It is a tool for the minimization step, not a compliance guarantee and not legal advice, and it does not remove the consent judgment for facts that still relate to the representation.

Keep client data out of public AI

Minimize client data locally, then use any AI tool on the anonymized copy. Free for 14 days on Windows and macOS (Apple Silicon); multi-seat licenses for firms.

More: is ChatGPT private? · does ChatGPT save your data? · what is PII? · how your data is handled