Zero-Trust Data Sanitization: A Client-Side Architecture for Preserving Attorney-Client Privilege in the Era of Generative AI
Ilya Sibiryakov
No 4wc86_v1, LawArchive from Center for Open Science
Abstract:
Generative AI has fundamentally dissolved the traditional law firm security perimeter. While Managing Partners and IT Directors have historically focused on defending boundaries via firewalls and Data Loss Prevention (DLP) tools, a critical vulnerability has emerged: the AI prompt. With the rapid adoption of AI tools by legal professionals to summarize depositions, review contracts, and draft briefs, highly confidential client information, M&A term sheets, and sensitive litigation data are regularly pasted into third-party AI interfaces. Traditional security controls are architecturally incapable of mitigating this risk because browser-based AI communications move through encrypted HTTPS stacks, remaining invisible to network-layer inspection. This paper outlines the Zero-Trust Data Sanitization (ZTDS) architecture—a client-side pseudonymization layer that ensures no personally identifiable information (PII) or confidential client data exits the endpoint. By implementing local, browser-based sanitization, law firms can embrace AI productivity without waiving attorney-client privilege, while maintaining absolute compliance with the ABA Model Rules of Professional Conduct (specifically Rule 1.6), GDPR, HIPAA, and emerging AI regulations.
Date: 2026-08-26
References: Add references at CitEc
Citations:
Downloads: (external link)
https://osf.io/download/6a7b8fbe81aa2f5641241d53/
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:osf:lawarc:4wc86_v1
DOI: 10.31228/osf.io/4wc86_v1
Access Statistics for this paper
More papers in LawArchive from Center for Open Science
Bibliographic data for series maintained by OSF ().