confidentiality

Confidentiality in the Age of GenAI: What Singapore's Reckoning Means for Every Legal Team

Adira EditorialLegal AI desk4 min read
Editorial illustration for Confidentiality in the Age of GenAI: What Singapore's Reckoning Means for Every Legal Team

The Quiet Invasion of AI into Legal Workflows

Generative AI did not arrive in law firms and legal departments with a grand announcement. It arrived through the side door: a junior lawyer summarising a lengthy agreement, a paralegal drafting a first-pass NDA, an in-house counsel asking a model to flag unusual indemnity clauses at midnight before a board meeting. By the time institutions began asking whether this was appropriate, the tools were already deeply embedded in daily practice.

Singapore's legal community is now confronting the question squarely. The Singapore Law Gazette has drawn attention to how confidentiality obligations, long settled in their application to human advisers and traditional software, face genuine uncertainty when applied to large language models and the cloud infrastructure that underpins them. The core tension is straightforward: a lawyer's duty of confidentiality is owed to the client, but the moment client information is submitted to a third-party AI system, that information travels beyond the lawyer's direct control.

What the Duty of Confidentiality Actually Requires

Confidentiality in legal practice is not simply about keeping secrets. Under Singapore's Legal Profession (Professional Conduct) Rules, and under analogous obligations in most common law jurisdictions, the duty requires lawyers to take active steps to prevent unauthorised disclosure. It is a duty of conduct, not merely of intention.

This matters enormously for AI adoption. Telling yourself that you trust a particular AI vendor is not a legal compliance position. The relevant questions are: where is the data processed, who can access it, are inputs used for model training, what happens in the event of a breach, and does the vendor's contractual commitment to confidentiality actually match the professional obligation owed to the client? Most standard commercial AI subscriptions, even those marketed to professionals, do not answer all of these questions in the affirmative.

In-house counsel face an additional layer of complexity. They must satisfy not only their own professional obligations but also their organisation's data governance policies, sector-specific regulations (especially in financial services, healthcare and government contracting), and increasingly, the expectations of counterparties who are themselves scrutinising how their information is handled during negotiations.

The Architecture Problem That Vendors Rarely Discuss

Most commentary on AI and confidentiality focuses on the contractual layer: does the vendor promise not to use your data? That is a necessary but insufficient inquiry. The architecture of how a tool is built matters just as much.

Consider a generic AI assistant accessed through a consumer or lightly-regulated business plan. The model may be hosted across multiple cloud regions, fine-tuned on aggregated inputs, and subject to access by vendor engineers for quality assurance purposes. A contractual no-training-on-your-data clause addresses one narrow vector of risk. It does not address subprocessor chains, inference logging, or the residual risk that confidential terms from a client's acquisition agreement are briefly cached on infrastructure the law firm does not control.

This is precisely why Adira is built differently. Adira processes contracts within a controlled environment that reflects the confidentiality obligations of the legal teams using it. When Adira reads a contract from your side, it does so with an understanding of your jurisdiction's law, your organisation's negotiating positions, and your clients' expectations. The data architecture is not an afterthought bolted onto a general-purpose model. It is a foundational design choice.

Practical Steps for Legal Teams Right Now

Whether or not your firm or legal department has formalised an AI policy, the following steps are immediately actionable.

First, audit which AI tools are actually being used across your team. Shadow AI adoption is common, and you cannot manage risk from tools you do not know exist.

Second, review vendor data processing agreements against your professional obligations, not just your general IT procurement checklist. The questions are different. A CISO cares about breach notification timelines. A general counsel also needs to know whether submitting a client's draft share purchase agreement to an AI system constitutes a disclosure that requires client consent.

Third, update your client engagement letters or retainer terms to address AI use explicitly. Several leading firms in Singapore and London are already doing this. Transparency with clients about the tools used in their matters is both an ethical requirement and a commercial advantage.

Fourth, prefer purpose-built legal AI over general-purpose tools where confidentiality is material. The fact that a model is powerful and popular does not make it appropriate for client work.

The Competitive Dimension

There is a final point that deserves more attention than it typically receives. Confidentiality is not only a compliance issue. It is a competitive one. Clients, particularly sophisticated institutional clients and multinational corporations, are beginning to ask their external counsel and in-house teams which AI tools are used and how data is protected. A clear, credible answer is a differentiator. An evasive one is a liability.

Legal teams that treat AI governance as a genuine professional priority, rather than a compliance checkbox, will be better positioned to win and retain mandates in a market where trust remains the core product. Singapore's legal community is asking the right questions. The answers will separate the leaders from the laggards.

Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom