Redacting before AI: what it protects, and what it does not
· Updated · Written and maintained by Joaquín Trapero, Nonimo
You took out the name, the Social Security number and the account number, and the paragraph in front of you now reads like any other paragraph. Whether the next thirty seconds were a good idea depends less on how much you removed than on which rule you were under when you removed it.
In the United States that question has five different answers at once, and three of them do not care about identifiers at all. Privilege does not turn on the words. The ethical duty of confidentiality does not turn on the words. The rule that governs your accounting practice attaches to the record and to the contract, not to the names inside it.
The two places where removal really does change your legal position are narrow, and both of them ask for something beyond editing: a standard with a test attached, or a commitment you publish and a contract you sign. This guide walks the five, in the order a US practice actually meets them.
Does redacting protect privilege? It is the wrong question to start with
Privilege is a rule about a relationship and about who else heard the communication. It protects confidential communications between a lawyer and a client made for the purpose of obtaining legal advice, and it is lost when the communication stops being confidential. Nothing in that sentence is a statement about which characters appear in the document.
Comment 3 to Model Rule 1.6 sets the three regimes side by side and is worth reading slowly, because most confusion in this area is a collapse of the three into one. It describes the principle of confidentiality as given effect by the attorney-client privilege, the work-product doctrine, and the rule of confidentiality established in professional ethics. Three bodies of law, three different triggers.
| The rule you are under | What removing the identifiers buys you |
|---|---|
| Attorney-client privilege | Nothing by itself. The test is who received it, not what it said |
| Model Rule 1.6 | Nothing automatic. It reaches information relating to the representation |
| HIPAA safe harbor | A real exit, with all eighteen categories gone and an actual knowledge test |
| CCPA deidentified | A real exit, and two of its three conditions are paperwork, not editing |
| State breach statutes | Nothing in California or New York. Both exempt encryption, not masking |
| FTC Safeguards Rule | Nothing. The duty attaches to the record and to your vendor contract |
Does ChatGPT waive attorney-client privilege? The question is about the recipient
When a privileged communication is voluntarily handed to a third party who is not assisting the representation, the usual consequence is that privilege in it is gone. The federal rules treat that as settled rather than stating it: Rule 502(a) opens by describing a disclosure that waives the attorney-client privilege or work-product protection, and then limits how far the waiver spreads.
Masking the client’s name does not restore confidentiality to a communication that has already left the relationship. What was disclosed was the substance, and the substance is the part that was privileged in the first place. That is why a law firm AI policy has to govern what the attorney sends, and not only what a tool masks on the way out.
There is a federal rule that softens the edges, and it is narrower than it is usually quoted. Rule 502(b) of the Federal Rules of Evidence says that a disclosure does not operate as a waiver where it is inadvertent, the holder took reasonable steps to prevent it, and the holder promptly took reasonable steps to rectify the error.
Where 502(b) does not reach, which is most of a working day
Read the opening words of the rule. The protection is written for disclosure made in a federal proceeding or to a federal office or agency. A paste into a consumer chatbot on a Tuesday afternoon is neither, so the analysis falls back to the privilege law of the forum, and in most matters that is state law rather than Rule 502.
None of this means one paste is the end of the world. It means the safeguard belongs where the rules actually put it, in the account, the contract and the client’s consent, rather than in the edit. Our guide on whether pasting client data is a breach works the same ground from the notification side.
Rule 1.6 reaches information relating to the representation, whatever its source
The ethical duty is the one that will be measured against you first, because it does not need a court. Rule 1.6(a) says a lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent, the disclosure is impliedly authorized in order to carry out the representation, or paragraph (b) permits it.
Notice what the rule does not say. It does not say personally identifiable information, which is a different category with a different test. It does not say confidential communications. The category is information relating to the representation, and Comment 3 adds that the rule applies not only to matters communicated in confidence by the client but to all information relating to the representation, whatever its source.
Comment 4 already wrote the test you need
The ABA worked this out long before chatbots, for lawyers who wanted to discuss a matter without naming a client. Comment 4 permits a hypothetical so long as there is no reasonable likelihood that the listener will be able to ascertain the identity of the client or the situation involved. It also extends the prohibition to disclosures that do not themselves reveal protected information but could reasonably lead a third person to discover it.
Two things in that sentence do work that a redaction pass cannot. The test is about the listener, which means it moves with context and with whoever is reading. And it covers the situation as well as the identity, so a matter that is recognizable from its facts is still covered after every proper noun is gone.
The five factors that decide whether your effort was reasonable
Rule 1.6(c) asks for reasonable efforts against inadvertent or unauthorized disclosure, and Comment 18 says a disclosure is not a violation if those efforts were made. It then lists what reasonableness is measured on.
| Factor from Comment 18 | What it asks about your AI workflow |
|---|---|
| Sensitivity of the information | A custody file and a routine lease are not the same input |
| Likelihood of disclosure without safeguards | Which account, which retention setting, which product |
| Cost of additional safeguards | A paid plan with the right terms is usually cheap |
| Difficulty of implementing them | A firmwide rule beats deciding matter by matter |
| Effect on your ability to represent clients | A safeguard nobody uses is not a safeguard |
None of the five is the number of names you removed. That is the whole point of the list, and it is why a firm that masks carefully but pastes into a personal consumer account is in a worse position than one that masks nothing and works inside a contracted workspace.
ABA Formal Opinion 512 and the consent question it puts in front of you
On July 29, 2024, the ABA Standing Committee on Ethics and Professional Responsibility issued its first formal opinion on generative AI, 15 pages telling lawyers and firms using these tools to fully consider their applicable ethical obligations. It names seven duties, and the reason it matters here is the one it names second.
It is worth knowing what kind of document this is before quoting it. A formal opinion interprets the Model Rules, it does not enact anything, and the rules that bind you are your own state’s. What changed in 2024 is that the confidentiality question now has an answer written with these tools in mind. In court, local rules and standing orders add a layer of their own, starting with whether a filing has to disclose AI use.
The duty it puts in front of you
On confidentiality, the committee’s position is that a lawyer using generative AI must be cognizant of the duty to keep confidential all information relating to the representation of a client, regardless of its source, unless the client gives informed consent. The phrase regardless of its source is the same phrase from Comment 3, arriving in the AI context unchanged.
Competence comes first, and asks you to understand the benefits and risks of the technology you use. Communication asks you to consult the client about the means used to pursue their objectives. Fees says you may bill for the time spent putting the relevant information into the tool and reviewing the result, but generally not for learning to work it. Communication and fees both land in the engagement letter, where our sample AI disclosure language drafts each one.
What it does not say, and what people say it does
It does not say that anonymizing a document removes the confidentiality question, and it does not create a category of text that is safe to put into AI. What it does is point back at rules that were already there, which is why a guide promising that the opinion blessed some particular editing routine is describing something else.
The safer reading is that consent, not redaction, is the doorway the opinion cares about. The practical response is a written firm position, and a template you can edit is a faster start than a blank page.
Rule 5.3 already had a rule for sending client documents outside the firm
Before any of this was about models, it was about sending a box of documents to a scanning bureau. Comment 3 to Model Rule 5.3 says a lawyer may use nonlawyers outside the firm to assist in rendering legal services, and its own list of examples ends with using an Internet-based service to store client information.
That framing helps, because it is older than the anxiety. A practice that already had a position on couriers, transcription services and cloud storage has most of the reasoning it needs, and the question becomes which existing category the tool falls into rather than whether a new one has to be invented.
The terms of the arrangement are a listed factor
The obligation is to make reasonable efforts to ensure the services are provided in a manner compatible with your professional obligations, and the comment lists four things the extent of that obligation depends on: the education, experience and reputation of the provider, the nature of the services, the terms of any arrangements concerning the protection of client information, and the legal and ethical environment of the jurisdiction where the work is performed.
Three of those four are about the provider, the contract and the venue. The fourth is about the kind of work. None of them is about the document you prepared before you opened the tab.
That is a rule about the contract and the venue, and it is answerable from documents. If you want the four consumer products checked against their own published terms, we have done that for ChatGPT, Claude, Copilot and Gemini on US terms.
HIPAA is the one place where removal really does take the file out
There is a place in American law where editing the document changes its legal status cleanly, and it is the HIPAA safe harbor. It is also the standard most often claimed without being met, so it is worth saying what it costs rather than repeating the list: all eighteen categories of identifier gone, and no actual knowledge that what remains could identify the person.
We have written that standard out in full, with the catchall category and the coded re-identification route that the rule does allow, in our guide to HIPAA compliant AI. The short version for this page is that the bar is higher than a redaction pass, and that a tool which replaces the identifiers it recognizes does not clear it.
Why that standard does not travel to your matter file
The safe harbor is a rule inside one statute, for one kind of entity, about one kind of data. A litigation file about a commercial dispute is not protected health information, so the eighteen categories are not a checklist you can borrow, and clearing them would not answer Rule 1.6 anyway. Borrowing a health standard for a matter that has nothing to do with health is how a good edit ends up being mistaken for a legal status.
If the word itself is the thing you are unsure about, the vocabulary question has its own page: what the three words actually mean and which of them takes a file outside the law.
California defines deidentified, and two of its three conditions are paperwork
The second real exit is in the California Consumer Privacy Act, and reading it is instructive because most of it is not about the document. Section 1798.140(m) defines deidentified as information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, provided that the business possessing it does three things.
Two things make this worth reading even if you never notify a Californian. It is the definition American vendors reach for when they call something deidentified, and it is the clearest illustration in US law that the status is not reachable by editing alone. The same section also lists sensitive personal information, which fills a client’s personnel file from the union dues line to the accommodation request, and the guide to HR paperwork takes it document by document.
| Condition in 1798.140(m) | Is it something you edit? |
|---|---|
| Reasonable measures against association with a consumer or household | Yes, and it is the only one that is |
| A public commitment to keep it deidentified and not to reidentify | No, it is a statement you publish |
| A contract obligating any recipient to comply with the same subdivision | No, it is an agreement you sign |
What that means for a document you cleaned by hand
Two of the three are commitments rather than edits, and neither is something a person cleaning a file on a Tuesday has done. Nobody who masks a contract has published a commitment about it, and nobody has contractually obligated a chatbot to comply with subdivision (m). The status is available, and it is not available by accident.
There is a second lesson hiding in the definition’s first clause. The test is whether the information can reasonably be used to infer information about a consumer, which is an inference test rather than an identifier test, and inference is exactly what a language model is good at. That is the same distinction the three words guide draws between a status and a technique.
The state breach statutes exempt encryption, not redaction
Here is the result that surprises people, and it is worth checking against the statutes rather than against a summary, because the summaries tend to say redacted where the current text does not.
Both statutes answer the same question: when does losing a file oblige you to tell the people inside it. The exemption is where the whole argument happens, because it decides whether an incident is a notification to hundreds of people or a note to the file.
California asks one question about the file
California’s breach statute defines personal information as a name in combination with one or more listed data elements, when either the name or the data elements are not encrypted. The listed elements run from Social Security numbers through medical and health insurance information to genetic data and biometrics. The exemption is keyed to encryption. Masking is not mentioned.
New York asks the same question, and closes a door
New York reaches the same place by a different route. Its private information definition applies when the data element, or the combination, is not encrypted, or is encrypted with a key that has also been accessed or acquired. Its separate definition of personal information is broader still: any information concerning a natural person which, because of name, number, personal mark or other identifier, can be used to identify that person.
Two states are not fifty, and the wording does vary. Some state may well recognize redaction. What matters is that the two largest markets a US practice is likely to notify into both put the exemption on encryption, so a workflow built on masking has no statutory defense in either. What follows from that, and the clock you are on once it happens, is the notification question.
Accountants and tax preparers: the rule attaches to the record
If you complete income tax returns, a federal rule reaches your files, and its own examples say so. The FTC Safeguards Rule counts an accountant or other tax preparation service that is in the business of completing income tax returns as a financial institution, which is the sentence most practices are surprised by.
What the Rule then protects is customer information, defined as any record containing nonpublic personal information about a customer, whether in paper, electronic or other form, that is handled or maintained by or on behalf of you. The obligation attaches to the record and to your handling of it. A CPA firm answers to a second rule on top, and the AICPA’s own confidentiality rule follows that same record into ChatGPT.
The contract requirement is the one that bites
Section 314.4(f) requires you to oversee service providers by taking reasonable steps to select ones capable of maintaining appropriate safeguards, by requiring those service providers by contract to implement and maintain such safeguards, and by periodically assessing them. A consumer account you signed up for with a work email address is not a contracted service provider, and no amount of masking turns it into one.
The same shape appears in the insurance file, where the questions are about controls rather than about edits. We have gone through the AI section of the forms in our guide to the cyber insurance questionnaire, and through the gaps that survive a claim in what cyber insurance does not cover.
The order that follows from all five, and it is not the order you would guess
Every rule above answers a question that comes before the editing, so the editing goes last. That inverts the usual advice, which starts with a list of things to strike out and never gets to the account.
Care still matters, and it pays most where it compounds, because four of the five steps below are decided once for the whole practice and only the fifth has to be repeated on every document.
- Decide which rule you are under. A health file, a tax file, a matter file and a resident record are four different regimes, and the same edit buys different amounts in each.
- Fix the account and the contract. This is the only step that answers Rule 5.3, Comment 18 and section 314.4(f) at the same time.
- Get consent where the rule asks for it. Rule 1.6(a) makes informed consent the doorway, and Opinion 512 points at it in the AI context.
- Write the rule down once, for everybody. A firmwide position beats a decision taken matter by matter by whoever is in a hurry, and our AI acceptable use policy template is a starting point you can edit.
- Only now, reduce what leaves the building. Fewer identifiers in the prompt is worth having on its own terms. It is a reduction in exposure, not a change in legal status.
A paragraph that is clean and still recognizable
Take the kind of sentence a commercial file produces, and strip it properly. The name goes, the number goes, the dates go to the year:
Our client, a distributor in the county owned by one family, is negotiating the sale of its refrigerated logistics division after a dispute with its largest customer, a supermarket chain, over a recall in 2025.
Nothing in that sentence is an identifier. In a midsize county it may still be one business, and Comment 4’s test is whether a reader could ascertain the client or the situation. The identifiers were never the hard part, which is the same conclusion our guide for public bodies reaches from the records request side.
What Nonimo does here, and what it does not
We build a tool that pseudonymizes text on your own machine before you send it, so it is fair to say exactly where it sits against everything above.
What it does on American paper
The US layer ships, and its design is deliberately cautious for one reason: no American personal identifier carries a check digit that could confirm a guess. So American values are recognized behind their label rather than anywhere in a document, and what comes back is a visible suggestion you can read and undo, not a silent clean.
The conversation it needs to put the values back stays encrypted on that machine, as the security page sets out.
It does not restore privilege to a communication you have already shared, and it does not create the contract, the public commitment or the informed consent the rules above ask for, which is why buying anything at all is the last of the five steps, not the first. Where this fits inside a firm rather than on one desk is the conversation we prefer to have with a partner in the room.
Two things you will read elsewhere that are wrong today
The first is that removing personally identifiable information takes a document outside your confidentiality obligations. It does not, and the text of Rule 1.6 is the shortest way to see why: the category is information relating to the representation, not information that identifies someone.
The second is that a redacted file is exempt from state breach notification. In California and New York the exemption is written for encryption, and a masked file that is otherwise readable does not meet it. If you want the version of this argument that applies outside the United States, the EU AI Act guide covers who a foreign regime reaches.
The question to ask before you paste
Not what did I remove. Ask instead which rule am I under, and does that rule care what I removed.
For three of the five above the answer is no. In those three the work that protects you happens in the account, the contract and the consent, and all of them are decided once and then hold for every document afterwards.
That is also the more comfortable answer, because it is the one you can finish. A masking pass has to be right every time, on every file, under time pressure. A signed agreement and a written firm position have to be right once. For how that works across a whole organization, see how we approach firms.
Sources
Checked September 21, 2026. Two of the domains below refuse tools run from the command line and load normally in a browser, which is a measure against bots rather than a dead link: americanbar.org and nysenate.gov. Each page was opened and read.
- ABA Model Rule 1.6, Confidentiality of Information. The text of paragraphs (a) and (c): the prohibition on revealing information relating to the representation, and the duty of reasonable efforts against inadvertent or unauthorized disclosure.
- ABA Model Rule 1.6, Comment. Comment 3 separating privilege, work product and the ethical duty; Comment 4 on the hypothetical and the reasonable likelihood test; Comment 18 and its five factors of reasonableness.
- ABA Model Rule 5.3, Comment. Comment 3 listing an Internet-based service to store client information among nonlawyer services outside the firm, and the factors including the terms of the arrangement.
- ABA, first ethics guidance on a lawyer’s use of AI tools. Formal Opinion 512, issued July 29, 2024, fifteen pages; the seven duties it names and the confidentiality formulation quoted here.
- Federal Rule of Evidence 502. The scope of the rule, and the three conditions of paragraph (b) for an inadvertent disclosure made in a federal proceeding or to a federal office or agency.
- California Civil Code 1798.140. Subdivision (m), the definition of deidentified and its three conditions, including the public commitment and the contractual obligation on recipients.
- California Civil Code 1798.82. The definition of personal information, the list of data elements, and the exemption keyed to encryption.
- New York General Business Law 899-aa. The definitions of personal information and private information, and the encryption condition including an acquired key.
- 16 CFR Part 314, Standards for Safeguarding Customer Information. The definition of customer information, the example naming accountants and tax preparation services as financial institutions, and the three duties toward service providers in section 314.4(f).
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Does redacting a document protect attorney-client privilege?
Not on its own. Privilege turns on who received the communication and in what circumstances, not on which words were removed. Comment 3 to Model Rule 1.6 treats privilege, work product and the ethical duty of confidentiality as three separate bodies of law.
Can I put client information into ChatGPT if I take the names out?
Model Rule 1.6 covers information relating to the representation, whatever its source, so removing the name does not by itself take the paragraph outside the rule. Comment 4 asks whether a listener could ascertain the client or the situation.
What does ABA Formal Opinion 512 require?
Issued July 29, 2024, it tells lawyers using generative AI to fully consider their ethical obligations, and names competence, confidentiality, communication and fees among them. On confidentiality it points to the duty to keep confidential all information relating to the representation unless the client gives informed consent.
Is masked data still personal information under a state breach law?
In California and New York, yes. Both statutes make the exemption turn on encryption. California's definition applies when the name or the data elements are not encrypted, and New York's adds that an encryption key which was also acquired does not count.
What does deidentified mean under the CCPA?
Section 1798.140(m) requires information that cannot reasonably be used to infer information about or be linked to a consumer, plus three conditions: reasonable measures, a public commitment not to reidentify, and a contract binding any recipient.
Does the FTC Safeguards Rule apply to my accounting practice?
If you complete income tax returns, the Rule's own examples say yes: an accountant or other tax preparation service is a financial institution. The duty then attaches to customer records, and it includes requiring service providers by contract to maintain safeguards.
Does HIPAA's safe harbor work the way redaction does?
It is stricter. The safe harbor needs all eighteen categories of identifier removed, and it applies only if you have no actual knowledge that what remains could identify the person. Removing the obvious identifiers does not reach that bar.
Does Federal Rule of Evidence 502 save me if I paste something by mistake?
Rule 502(b) is written for disclosure made in a federal proceeding or to a federal office or agency, and it asks whether the holder took reasonable steps to prevent and to rectify. A paste into a chatbot is not that setting.
What should I do before pasting a client document into an AI tool?
Decide which rule you are under first, because that decides whether removing identifiers buys anything. Then settle the account and the contract, get informed consent where the rule asks for it, and only then reduce what leaves the building.