confidentiality

Confidentiality in the Age of Generative AI: What Singapore's Legal Community Must Confront

Adira EditorialLegal AI desk4 min read
Editorial illustration for Confidentiality in the Age of Generative AI: What Singapore's Legal Community Must Confront

The Quiet Erosion of a Foundational Duty

Confidentiality has always been the bedrock of legal practice. A client shares commercially sensitive details, a counterparty discloses its true risk appetite during negotiation, an in-house team circulates a draft agreement containing undisclosed M&A intentions. Every one of those moments carries a duty that practitioners have long understood intuitively. What the generative AI era has done is not abolished that duty. It has complicated the infrastructure through which the duty must be discharged.

The Singapore Law Gazette recently noted that tools like Claude have become almost unavoidable in legal conversations today. The observation is accurate, and it points to a deeper question that neither vendors nor regulators have fully answered: when confidential legal information enters a third-party AI system, what exactly happens to it, and who bears the professional consequences if something goes wrong?

Jurisdiction Matters More Than People Realise

One of the persistent weaknesses in how organisations adopt AI tools is the assumption that a product built in one jurisdiction carries adequate legal sensitivity for another. Singapore practitioners are bound by the Legal Profession (Professional Conduct) Rules 2015, which impose specific confidentiality obligations that go well beyond a general duty of care. The Personal Data Protection Act adds a further layer, governing how personal information contained within contracts and correspondence may be processed.

A generic AI model, trained predominantly on English-language common law materials with limited sensitivity to Singapore-specific regulatory frameworks, is not automatically equipped to flag when a clause or a data-sharing arrangement triggers local compliance concerns. This is not a theoretical risk. It is a structural gap that in-house counsel and law firms operating in Singapore should treat as a live exposure rather than a distant possibility.

Adira is built on the principle that jurisdiction-aware legal AI is not a premium feature. It is the minimum viable standard. When Adira reads a contract, it does so through the lens of the law that actually governs the agreement, including the confidentiality and data-handling obligations that apply in Singapore or whichever market the user operates in.

The Problem with Feeding Contracts into General-Purpose Tools

The practical temptation is understandable. A lawyer or contract manager faces a time-pressured review, reaches for a general-purpose AI assistant, pastes in the contract, and asks for a summary. The output arrives in seconds. The problem is not the speed. The problem is the chain of custody that the lawyer has just initiated without necessarily understanding its implications.

Most general-purpose AI tools process inputs through infrastructure that is not designed with legal professional privilege in mind. Some retain query data for model improvement. Others route requests through servers in jurisdictions with materially different data-protection regimes. Firms that would never dream of forwarding a client's draft agreement to an unvetted third party are, in effect, doing something analogous when they use tools that lack transparent, auditable data-handling commitments.

The answer is not to avoid AI. The answer is to use AI that reads contracts from your side of the table, within an environment you control, with data governance you have actually reviewed.

What In-House Teams Should Be Asking Right Now

For in-house legal teams, the governance question is particularly acute. Unlike law firms, which have external regulatory oversight to prompt compliance reviews, in-house teams often self-govern their technology choices. That autonomy is valuable, but it places the burden of due diligence squarely on the general counsel or chief legal officer.

The questions worth asking before any AI tool handles contract data are straightforward. Does the vendor retain input data, and for how long? Where is that data processed, and does the location create any cross-border transfer issues under Singapore's PDPA or the contracts themselves, which may contain data-residency clauses? Does the tool have legal professional privilege protections built into its architecture, or does it treat legal documents as equivalent to any other text?

Adira's approach is to keep contract data within the client's own environment and to treat every document as privileged until instructed otherwise. That is not a marketing position. It is a structural choice that reflects how confidentiality obligations actually work in practice.

Building a Practice That Can Defend Its AI Choices

The Singapore Law Gazette's framing of trust in the headline of its recent feature is apt. Trust in AI tools for legal work is not established by brand recognition or by the sophistication of the underlying model. It is established by the ability to explain, under scrutiny, why a particular tool was appropriate for the work and how confidential information was protected throughout.

Regulators, clients, and counterparties are all becoming more sophisticated in their understanding of AI-related risk. A firm or in-house team that cannot articulate the data governance behind its AI choices is exposed, not only to professional sanction, but to the erosion of the client trust that makes legal practice viable in the first place.

Adira exists to close that gap: AI that knows the law it is applying, reads contracts from your side, and gives you the audit trail to defend every decision it supports.

Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom