Shadow AI at Law Firms: How to Find Unauthorized AI Tools Attorneys Are Using Without Touching Client Data
Last updated: June 2026
To find unauthorized AI tools attorneys at your firm are using, check two places without touching a single client file: your Google Workspace OAuth audit log (Admin Console → Reporting → Audit and investigation → OAuth log events) and your firm's card and expense statements filtered for AI vendor names. The OAuth audit shows every tool connected with a work Google account. The card review catches subscriptions billed directly. Neither requires accessing emails, documents, or client matter files.
The Problem
In February 2026, a federal judge in the Southern District of New York ruled in United States v. Heppner that a defendant's exchanges with Anthropic's Claude were neither attorney-client privileged nor protected work product. Judge Rakoff identified three independent grounds: Claude is not an attorney; the communications were not confidential because Anthropic's consumer-tier privacy policy at the time reserved rights to retain and disclose user data; and Heppner was not using Claude to obtain legal advice from counsel.
One important nuance from the ruling: Judge Rakoff wrote that if counsel had directed Heppner to use Claude, the analysis might have been different — Claude could "arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent." The legal landscape is still developing, and some courts have since taken a more fact-specific approach. But the core lesson is clear: consumer-grade AI tools used with client information, without attorney direction and without contractual confidentiality, put privilege at serious risk.
The problem at most law firms is not that partners are making reckless decisions. It is that associates, paralegals, and junior staff are using AI tools they learned in law school or found online — tools like ChatGPT Free, consumer-tier Claude, and Otter.ai — without understanding the data retention implications. According to the Clio 2025 Legal Trends Report, 79% of legal professionals now use AI tools. But 44% of law firms have not implemented any formal AI governance policies. That gap is where the exposure lives.
Why This Happens at Law Firms Specifically
Attorneys face competing pressures. Clients expect faster turnaround. Billing rates are under pressure from alternative legal service providers. AI tools that can draft a first pass in four minutes instead of four hours are genuinely useful — and associates who know how to use them get more done.
The problem is that AI adoption happened faster than governance. ABA Formal Opinion 512 (July 2024) established the national ethics framework: lawyers may use AI, but their duties of competence, supervision, and confidentiality remain fully in force. As of early 2026, more than 35 state bar associations have issued formal guidance building on that framework. But knowing the rules exist and knowing which specific tools comply with them are two different things.
The result is a common pattern: an attorney uses a consumer AI tool for what feels like a low-risk task — summarizing a deposition transcript, drafting a demand letter, searching for case law — without realizing the tool's terms of service allow the provider to retain and use that input for model training. The client information is out of the firm's control. The firm had no visibility that it happened.
How to Find Shadow AI at Your Firm: Three Methods
The distinguishing feature of this audit for law firms: every method below reads system-level metadata only. You are not opening client files, reading email content, or reviewing any communication covered by attorney-client privilege. You are checking what tools exist and have access — not what was put into them.
Method 1 — Google OAuth Audit
Every time an attorney or staff member clicks "Sign in with Google" on an AI tool, Google logs it. This is your most complete source for tools connected to work accounts.
Go to: Google Admin Console → Reporting → Audit and investigation → OAuth log events
Extend the date range to 90 days. Look for these AI tools specifically in a law firm context:
Consumer tools — highest risk under Heppner:
- OpenAI / ChatGPT (Free and Plus tiers train on user data by default as of June 2026)
- Claude.ai (consumer tier — distinct from enterprise agreements)
- Perplexity (commonly used for quick research)
Meeting recorders — high risk for client calls:
- Otter.ai (transcribes calls; requests Google Calendar access to join meetings automatically)
- Fireflies.ai (joins meetings automatically via calendar integration)
- Grain (meeting recorder; connects to Zoom and Google Meet)
Writing tools with broad text access:
- Grammarly (requests access to text across browser applications)
- Jasper / Copy.ai (drafting tools)
Legal-specific AI tools — generally lower risk if on enterprise agreement:
- Harvey AI
- CoCounsel (Thomson Reuters)
- Lexis+ AI
- Spellbook (contract drafting)
When you find a tool in the OAuth log, check the Scopes column. Tools with auth/drive, auth/gmail.readonly, or auth/calendar have access to firm documents, emails, or meeting schedules. Those are the ones that warrant immediate review.
For a domain-wide view of every third-party app connected across all users: Admin Console → Security → Access and data control → API controls → Manage third-party app access
Method 2 — Card and Expense Statement Review
Pull 90 days of firm card statements and expense reimbursements. Search for these vendor names:
- OPENAI (ChatGPT subscriptions; DALL-E is also billed here)
- ANTHROPIC (Claude.ai Pro or Teams)
- OTTER / OTTER.AI
- FIREFLIES
- HARVEY (Harvey AI — if found, this is actually a lower risk tool but worth knowing)
- GRAMMARLY
- PERPLEXITY
- JASPER / COPY.AI
Note: billing names vary by card network. Search partial matches. Any recurring AI tool subscription that did not go through formal firm procurement is a candidate for review.
Also audit expense reimbursements separately. Consumer AI subscriptions are often $20/month — small enough to be approved without scrutiny but large enough to accumulate across a team.
Method 3 — Legal Research Platform AI Tier Review
This category is unique to law firms. Your existing legal research platforms — LexisNexis, Westlaw, Clio — have added AI features, often at higher tier pricing. Some of these are appropriate for client work; some have data handling terms worth reviewing.
Check with your account representative for each platform whether:
- AI features are enabled for your account
- Which data handling tier you are on (does it opt you into training data?)
- Whether a data processing agreement or BAA is in place
This is distinct from shadow AI — these are sanctioned tools — but the AI feature tiers within them often have different privacy terms than the base subscription.
Where This Breaks Down
The OAuth audit and card review give you the visible layer: tools connected to work accounts or billed to the firm. They do not show you the attorney who opens a personal browser window, navigates to ChatGPT.com on their own login, and pastes in deposition excerpts. That usage is invisible to every technical control available.
This is not a gap that technology alone closes. It requires a written policy that attorneys acknowledge — specifying which tools are approved for client work, which are prohibited for anything involving client data, and what the consequences of violation are. The Heppner ruling gives you exactly the leverage to have that conversation: this is no longer a theoretical risk, it is a federal judge ruling that client communications in an AI chat are discoverable.
How Terrier Handles This
Terrier identifies AI tools that have been connected to your firm's Google Workspace accounts via OAuth — showing which tools have been granted access to Drive, Gmail, or Calendar — and cross-references AI subscriptions appearing on the firm's card against your current staff directory.
It does this entirely from OAuth grant records and transaction metadata. It does not open a single document, read a single email, or access any data covered by attorney-client privilege or client confidentiality. For law firms specifically, that is the only acceptable way to run this audit — and it is the reason enterprise SaaS management tools that require deep file system access are a poor fit for legal.
terrierops.com — free to scan your first month.
One Thing You Can Do Right Now
Search your Google OAuth log for "Otter" and "Fireflies." These meeting recording tools connect directly to attorneys' Google Calendars and automatically join and transcribe client calls. If they appear in your OAuth log for any user, that tool has been attending your client meetings — and depending on the tier and terms of service, those transcripts may not be covered by attorney-client privilege. That is your most urgent finding to investigate first.
Frequently Asked Questions
Q: Does using ChatGPT with client information violate attorney-client privilege?
It can, and a February 2026 federal court ruling illustrates the risk precisely. In United States v. Heppner, Judge Rakoff of the Southern District of New York held that a defendant's exchanges with consumer-tier Claude were neither privileged nor protected work product, on three independent grounds: (1) Claude is not an attorney; (2) the communications were not confidential because Anthropic's privacy policy reserved rights to retain and disclose user data; and (3) the defendant was not using Claude to obtain legal advice from counsel. Notably, Judge Rakoff wrote that if counsel had directed the use of Claude, the outcome might have differed. The legal landscape is still developing — some courts have since taken a more fact-specific approach — but the practical lesson is clear: consumer tiers of ChatGPT, Claude, and similar tools, used with client data without attorney direction and without enterprise-level confidentiality agreements, put privilege at serious risk.
Q: What does ABA Formal Opinion 512 require?
ABA Formal Opinion 512, issued in July 2024, is the national ethics framework for AI use in legal practice. It permits lawyers to use generative AI but holds that existing ethical duties remain fully in force. The three key obligations are: competence (understanding how the tool works, including how it handles data), supervision (treating AI output as a draft that must be verified before use), and confidentiality (understanding the tool's data retention and third-party disclosure terms before inputting client information). As of early 2026, more than 35 state bar associations have issued guidance building on this framework.
Q: What is the difference between consumer AI tools and legal AI tools in terms of confidentiality?
Consumer tools (ChatGPT Free, ChatGPT Plus, Claude.ai personal tier) typically have terms of service that permit using inputs for model improvement by default — unless you actively opt out, and opt-out may not be available on all tiers. Legal-specific AI tools (Harvey, CoCounsel, Lexis+ AI, Westlaw AI) are built with law firm data requirements in mind and generally include contractual confidentiality, zero data retention options, and data processing agreements. Enterprise tiers of consumer tools (ChatGPT Enterprise, Claude for Enterprise) also offer stronger confidentiality terms. The distinction matters: the Heppner ruling turned on the specific terms of service of the tool used, not on AI use in general.
Q: Does Terrier read client files or case matter content to do this audit?
No. Terrier reads two things only: Google OAuth grant records (which show that a tool was authorized to access certain Google account features, without reading the content of those features) and corporate card transaction metadata (vendor name, amount, date). It does not access Google Drive files, Gmail messages, calendar event content, or any document inside your practice management system. The audit is entirely at the connection and billing layer.
Q: Do we need to tell clients we are using AI?
State bars differ on disclosure requirements. California, New York, and several other states have issued guidance suggesting disclosure when AI plays a significant role in client work. ABA Formal Opinion 512 does not require disclosure in all cases but notes that transparency is consistent with the duty of communication. Most bar guidance converges on this principle: if AI is used in a way that touches client data or substantively shapes work product, clients should be informed. Your engagement letter is the right place to address this — and updating it now, before a state bar mandates it, puts you ahead of the requirement.
Q: What AI tools are generally considered safer for law firm use?
Tools built specifically for legal practice with enterprise data agreements — Harvey, CoCounsel (Thomson Reuters), Lexis+ AI, Westlaw AI, Clio Duo — are generally designed for law firm data requirements and include contractual confidentiality. Enterprise tiers of general-purpose tools (ChatGPT Enterprise, Claude for Enterprise with a data processing agreement) offer stronger protections than consumer tiers. For any tool used with client data, the key questions are: does the provider retain inputs? Can inputs be used for training? Is there a signed data processing or confidentiality agreement? If you cannot answer all three, do not use that tool for client work.
Q: What should our firm's AI policy include?
At minimum: a list of approved tools for client work, a list of prohibited tools for any matter involving client data, a clear statement that consumer AI tools without enterprise data agreements may not be used with client information, a requirement that all AI output be reviewed and verified before use or submission, and an acknowledgment that attorneys remain responsible for all work product regardless of how it was generated. State bar guidance in California, Florida, New York, and North Carolina provides useful policy frameworks. Clio and several legal technology organizations also publish policy templates.
Terrier is a SaaS spend optimization platform for Google Workspace companies. It identifies unauthorized AI tools connected to firm accounts and flags AI subscriptions in minutes — without accessing email content, client files, or any attorney-client communications. terrierops.com