Λdvocate

Practice guide · Updated August 2026

AI for Criminal Defense Lawyers: Move Faster Without Losing Control

AI can multiply a defense team’s capacity. It can also expose client information, invent authority, and make a bad answer look certain. Here is the practical standard for using it well.

AI is becoming an advantage in criminal defense, but speed is useful only when confidentiality stays protected and every important answer can be verified against the original record.

Reported impact 10×

One Advocate user described AI as making her work ten times more productive. That is an individual account, not a promise of results.

Filing standard 0

Unverified cases, quotations, or material facts should reach a court filing.

The advantage is real. So is the risk.

A lawyer who can search a full record, compare hours of video, build a cited chronology, and retrieve the exact source during testimony can operate with more coverage and less delay. A lawyer who avoids AI entirely may give up an increasingly meaningful edge in preparation, issue spotting, and responsiveness. Competence now includes understanding the benefits and risks of relevant technology.1

But AI is not an associate who owes your client professional duties. It is a technology supplied under written terms, operated through infrastructure, retention rules, access controls, and sometimes safety review. It can also produce a polished answer that is completely wrong. The right approach is neither blind adoption nor blanket refusal. It is controlled use: approve the system, limit the data, require sources, verify the work, and preserve the lawyer’s judgment.

Privacy comes before productivity

Three protections are often discussed as though they mean the same thing. They do not. A lawyer evaluating an AI product should analyze each one separately.

01 · Ethical duty

Client confidentiality

Model Rule 1.6 reaches all information relating to the representation, whatever its source. It is broader than the attorney-client privilege. Lawyers must also make reasonable efforts to prevent unauthorized access or disclosure.2

02 · Evidence doctrine

Attorney-client privilege

The privilege generally protects confidential communications between lawyer and client made for legal advice. It does not make the underlying facts secret. Disclosure to a third party can jeopardize protection, but the result is fact-specific and varies by jurisdiction.3

03 · Litigation protection

Attorney work product

Work product protects materials prepared in anticipation of litigation, with special protection for counsel’s mental impressions and strategy. Ordinary and opinion work product receive different treatment. Disclosure and waiver rules are not identical to privilege rules.45

AI output is not automatically privileged or protected merely because a lawyer requested it. The analysis turns on the governing law, the purpose of the communication or material, the confidentiality maintained, the product’s role, and the circumstances of disclosure. State statutes and evidence rules can differ materially from federal doctrine.

ABA Formal Opinion 512 applies duties of competence, confidentiality, communication, supervision, candor, and reasonable fees to generative AI. It instructs lawyers to evaluate the risk that a tool will retain, reuse, or expose representation-related information and explains that informed consent may be required. Boilerplate is not a substitute for explaining material risks and reasonable alternatives.6

California’s 2026 practical guidance likewise directs lawyers to understand how a system uses information, including for training, whether inputs are shared, and what safeguards protect client data. California separately imposes a broad duty to preserve client secrets under Business and Professions Code section 6068(e)(1).7

Before the first uploadRoute the data, not just the task.
Live matter Reports · video · client facts
Consumer chat Stop until terms and settings are approved Training · review · retention · disclosure
Approved legal system Proceed with matter-level controls Contract · access · deletion · source audit

Consumer AI is not a privileged room

ChatGPT and Claude are powerful tools. Their consumer products should not be treated like a confidential conference room merely because the conversation feels private.

Product context What the provider says What counsel should do
Consumer ChatGPT

OpenAI says individual-service content may be used to train models unless the user opts out. It also says limited personnel and service providers may access content for abuse or security investigations, support, legal matters, and model improvement unless the user opted out of that use.89

Do not place live client information in an ordinary consumer account based only on a settings toggle. Analyze the complete terms, purpose, retention, access, and client or court requirements.

Consumer Claude

Anthropic lets consumer users choose whether chats improve Claude. If enabled, retention can extend to five years. Anthropic also says conversations flagged by safety classifiers may still be used for internal trust and safety models, harmful-content detection, policy enforcement, or safety research.1011

Treat this as secondary use beyond answering the legal prompt. Do not assume incognito mode or training opt-out resolves every confidentiality question.

Business, enterprise, or API

OpenAI says business products and API inputs and outputs are not used for model training by default. Anthropic’s consumer-training update expressly excludes its commercial offerings and API.810

Better defaults are not the end of diligence. Review the contract, data processing terms, subprocessors, retention, human access, legal process, deletion, and security controls.

The law enforcement issue: serious, but state it precisely

Anthropic’s policy does not say that Claude casually forwards ordinary conversations to police. It says Anthropic may disclose customer or user information in response to valid legal process, such as a subpoena or warrant, and may make an emergency disclosure when it believes imminent physical harm or death may be averted. It also says users generally receive notice unless prohibited or a rare exception applies.12

That is still a major issue for defense counsel. Once privileged strategy, client statements, witness information, or protected files sit with a consumer provider, those materials are within a third party’s systems and subject to its retention, safety, legal-review, and government-request processes. OpenAI also maintains a law-enforcement policy for valid legal process and emergency disclosure requests. This risk is not unique to Claude.13

No responsible vendor can promise to ignore a valid court order. Counsel should instead ask whether the vendor requires valid process, narrows overbroad requests, gives notice when legally permitted, directs requests to enterprise customers first, records access, and publishes a law-enforcement policy. Those are contract and governance questions, not branding questions.

The second danger is invented law and invented facts

Generative AI predicts plausible language. Plausible is not the same as true. A model can invent a case, create a quotation that sounds judicial, reverse the holding of a real opinion, combine two witnesses, or state a disputed fact as settled.

In June 2026, the Ninth Circuit sanctioned attorneys whose filings included nonexistent cases, misattributed quotations, and gross misrepresentations produced through generative AI. The court made the central point clear: using AI was not itself the violation. Signing and filing unverified fabrications was.14 The United States Bankruptcy Court for the Central District of California similarly warns that AI can create nonexistent authorities, incorrect quotations, unsupported facts, and inapplicable law, with sanctions or denial of relief among the potential consequences.15

The two-verification rule

Never verify an AI answer with another AI answer.

Facts Open the original record.

Check the report page, transcript line, audio, or video moment. Review enough surrounding context to test speaker, timing, negation, uncertainty, and attribution.

Law Open the primary authority.

Read the opinion, statute, rule, order, and later history in an authoritative source. Confirm the court, jurisdiction, date, quotation, proposition, and current validity.

Source-grounded case intelligenceAn answer is a lead. The source is the proof.
People v. Ramirez3 sources linked
Question

Did Officer Jones direct Ramirez to exit?

Source-grounded answer

The report describes Ramirez as leaving voluntarily. The body-camera recording captures Officer Jones directing him to leave.

Officer_Jones_Bodycam.mp4
“I am instructing you to leave the vehicle.”
Original video moment opened for attorney verification

Source linking materially reduces the cost of verification, but it does not eliminate attorney review. A source can be miscited. OCR can fail. A transcript can mishear a word. A video model can misidentify an object. The defensible product standard is immediate access to the underlying material, not a confidence score or a reassuring citation badge.

What AI should actually do for defense counsel

The strongest uses start with the evidence and preserve a path back to it. They increase coverage while leaving materiality, strategy, credibility, and courtroom judgment with the lawyer.

01

Build one searchable case record

Ingest reports, discovery, jail calls, interviews, transcripts, CAD data, photos, and video. Preserve filenames, speakers, dates, page numbers, timestamps, and chain-of-custody information.

Advocate does this: one source-linked workspace across documents, audio, video, and data.
02

Review what was said and what was visible

Transcripts miss visual evidence. A useful system can index movements, people, objects, camera angles, and events, then open the exact frame and surrounding footage.

Advocate does this: time-coded speech and visual analysis remain connected to the original recording.
03

Compare every account

Test reports, interviews, depositions, client statements, and video against one another. Alerts should show both versions and their context, not declare that a witness lied.

Advocate does this: possible conflicts return with the underlying page, line, or timestamp.
04

Prepare a cited chronology

Build the sequence by event, person, source, and uncertainty. Separate direct evidence from inference, disputed facts from undisputed facts, and missing time from true silence.

Advocate does this: chronology entries retain their source receipts.
05

Draft from verified facts

Use AI for first drafts of summaries, client updates, cross topics, investigation plans, and motion sections only after the record is organized. Verify every material fact and authority.

Advocate does this: drafting begins from the matter record and carries citations into review.
06

Carry the record into court

Where permitted, capture time-coded testimony, compare it with prior sources, and retrieve an exhibit or video moment while the witness is still available. Confirm recording, transcription, device, and standing-order rules first.

Advocate does this: counsel can open the cited source, verify it, and decide what comes next.
07

Leave court with the work moving

Turn the captured proceeding into a reviewed summary, deadline list, investigation tasks, and a source-linked first draft while the hearing is fresh.

Advocate does this: the same case record continues after testimony instead of starting over.
08

Research with primary authority

Use AI to identify issues and search paths, not to certify the law. Verify every proposition in the controlling opinion, statute, rule, and later history before relying on it.

The rule: a working link is not enough. Read the authority.

A safe adoption playbook

  1. 01
    Classify the data before choosing the tool.

    Separate public material, internal administrative material, representation-related information, privileged communications, work product, sealed records, protective-order material, criminal-history data, biometric data, health information, and information restricted by contract or statute.

  2. 02
    Approve products by account type and purpose.

    “Claude” or “ChatGPT” is not a complete product description. Consumer, team, enterprise, API, cloud-hosted, and integrated products can have different terms and controls. Record the specific product, settings, and approved uses.

  3. 03
    Start with a closed or synthetic matter.

    Use a case the team knows well. Measure missed facts, false positives, citation accuracy, retrieval speed, export quality, correction handling, and deletion. Do not make a live client the first quality-control exercise.

  4. 04
    Set verification thresholds before the demo.

    Require direct source access for material facts, primary authority for legal propositions, attorney approval for external communication, and manual review before filing, disclosure, or courtroom use.

  5. 05
    Use least privilege.

    Limit each person and integration to the matters and functions needed. Require multifactor authentication, prompt offboarding, matter-level permissions, audit logs, and secure sharing rather than public links.

  6. 06
    Supervise the system like consequential delegated work.

    Assign a lawyer to review output, document material corrections, monitor recurring errors, and stop a workflow that is not performing safely. A vendor cannot assume counsel’s duties.16

  7. 07
    Confirm client, court, and jurisdiction requirements.

    Check engagement terms, protective orders, discovery restrictions, local rules, standing orders, recording and transcription rules, required AI disclosures, and state ethics guidance. Consent may be required for some uses.

  8. 08
    Prepare for failure.

    Maintain originals and backups. Define incident response, breach notice, legal-hold, export, correction, and deletion procedures. Keep a manual courtroom fallback when connectivity or transcription fails.

The vendor questions that matter

A “secure” badge does not answer the lawyer’s questions. Put the following points in writing and evaluate the answers in the context of the matter.

Data use

Are prompts, files, outputs, feedback, or metadata used for model training, product research, safety research, benchmarking, advertising, or any purpose beyond providing the service?

Human access

Who can view matter content, for what reasons, under what controls, and with what logs? Does opt-out apply to safety, support, or legal review?

Retention and deletion

What is retained, where, for how long, including backups and logs? Can the firm enforce matter-level deletion and receive confirmation?

Subprocessors

Which model providers, cloud vendors, transcription services, and support vendors receive content? Where is data processed, and how are changes disclosed?

Security

What encryption, access control, multifactor authentication, tenant isolation, audit logging, testing, and incident-response commitments apply?

Legal process

Does the vendor require valid process, narrow overbroad requests, provide notice when permitted, and direct requests to the firm before producing enterprise data?

Ownership and export

Who owns inputs and outputs? Can the firm export the complete matter with sources, annotations, audit history, and usable file formats?

Accuracy controls

Can every material answer link to its source? Does the product reveal uncertainty, preserve corrections, and distinguish extracted fact from inference?

Florida Ethics Opinion 24-1 provides a useful example of the level of diligence expected. It tells lawyers to research retention, data sharing, and self-learning, and recommends informed consent before disclosing confidential information to a third-party generative AI program. It also emphasizes enforceable confidentiality, breach or legal-process notice, provider reputation, security measures, and what the provider retains after service ends.17

Frequently asked questions

Is it unethical for a criminal defense lawyer to use ChatGPT or Claude?

Not categorically. The ethical question depends on the task, the information disclosed, the specific product and account, its terms and settings, the safeguards used, the lawyer’s competence and supervision, and any required client or court communication. Nonconfidential brainstorming presents a different risk from uploading a live client file.

Does turning off model training preserve privilege?

No single toggle settles privilege or confidentiality. Training opt-out may reduce one secondary use, but counsel must still analyze retention, human review, service providers, security, legal process, purpose, consent, and the governing law.

Does AI use automatically waive attorney-client privilege?

No automatic rule applies across every product and jurisdiction. Third-party disclosure can jeopardize privilege, but the result can depend on confidentiality, necessity, agency, contract, safeguards, governing law, and the facts. Avoid making the client the test case. Obtain jurisdiction-specific advice before exposing privileged communications.

Is every AI-generated draft attorney work product?

No. Work-product protection depends on governing law and whether the material was prepared in anticipation of litigation, among other facts. The degree of protection can differ for factual work product and counsel’s mental impressions. AI generation alone does not create the protection.

Can a source-linked system still hallucinate?

Yes. Source grounding narrows the problem and makes review faster, but a system can still choose the wrong source, misread text, mishear audio, or misstate context. Counsel should open and inspect every material source.

Can AI determine that a police officer or witness is lying?

No. A system can surface a possible conflict between words, documents, timing, or video. Credibility, context, materiality, admissibility, and examination strategy remain attorney judgments.

What is the safest first AI workflow for a defense practice?

Begin with a closed or synthetic matter and a narrow task such as transcription navigation, visual video indexing, or source-linked chronology building. Require direct source access, test against known answers, and complete privacy and vendor review before live use.

Should the lawyer disclose AI use to the client or court?

Sometimes. The answer may turn on the materiality of the use, the risks, client expectations, engagement terms, jurisdictional ethics rules, court orders, filing requirements, or local practice. ABA Formal Opinion 512 explains that informed consent may be required for some disclosures of representation-related information.

Primary authorities and provider policies

  1. ABA Model Rule 1.1, Comment 8: competence and relevant technology
  2. ABA Model Rule 1.6: Confidentiality of Information
  3. Upjohn Co. v. United States, 449 U.S. 383 (1981)
  4. Hickman v. Taylor, 329 U.S. 495 (1947)
  5. Federal Rule of Civil Procedure 26(b)(3): Trial Preparation Materials
  6. ABA Formal Opinion 512: Generative Artificial Intelligence Tools
  7. State Bar of California, 2026 Practical Guidance for the Use of Generative AI
  8. OpenAI: How your data is used to improve model performance
  9. OpenAI: Data Usage for Consumer Services FAQ
  10. Anthropic: Updates to Consumer Terms and Privacy Policy
  11. Anthropic: Who can view consumer Claude conversations?
  12. Anthropic: Policy for governmental requests for user information
  13. OpenAI Law Enforcement Policy, version 2025-12
  14. LNU v. Blanche, No. 24-4790 (9th Cir. June 3, 2026)
  15. U.S. Bankruptcy Court, Central District of California: Risks of AI-generated filings
  16. ABA Model Rule 5.3: Responsibilities Regarding Nonlawyer Assistance
  17. Florida Bar Ethics Opinion 24-1

Private by design. Sources within reach.

See what source-linked AI looks like on a real defense workflow.

Advocate connects documents, calls, audio, video, and live testimony in one attorney-controlled case record.

See Advocate live
© 2026 Advocate AI, Inc.A tool for attorneys. It does not provide legal advice.