July 15, 2026

Anthropic’s updated privacy policy took effect on July 8, and buried inside it is a line that should worry every managing partner whose associates use Claude for quick research between meetings. The company can now share user conversation data with law enforcement based on its own internal “good faith belief” that disclosure is warranted. No subpoena. No warrant. No court order required first. I read that clause twice before I believed it applied the way it does.
Here’s the part that makes this an actual ai confidentiality risk for law firms rather than just a privacy headline: the clause only applies to Claude Free, Pro, and Max accounts. Claude for Work, Team, Enterprise, and the API are explicitly carved out. So the question isn’t whether Anthropic changed its policy. It did. The question is which version of Claude is sitting on your associates’ laptops right now, and whether anyone at your firm actually checked.
I keep coming back to that word, checked. Not approved, not licensed, checked. A firm can have a beautiful AI use policy sitting in a binder somewhere and still carry a real ai confidentiality risk law firm leadership has never actually looked for, simply because nobody went and verified which tier of the tool is running on which laptop.
The clause itself is narrower than the headlines make it sound, and it’s worth reading closely rather than reacting to a summary. Anthropic can share personal data with government authorities where it has a good faith belief that disclosure is reasonably necessary to comply with law, prevent serious harm, address fraud or illegal activity, or protect its own rights and the rights of its users. That’s a fairly standard sounding list on paper.
What’s not standard is skipping the formal legal process most comparable platforms require before they’ll hand anything over. A subpoena creates a paper trail. A warrant requires a judge to sign off on probable cause. A company’s own internal judgment call requires neither and there’s no independent check on how that judgment gets made in any individual case.
A closer read of the policy language suggests Anthropic is not doing anything nefarious here. This reads more like a company trying to build in flexibility for genuinely serious situations, harm prevention, fraud, that kind of thing. But intent doesn’t really matter once the mechanism exists. Once a company can decide on its own that disclosure is warranted, the actual bar for disclosure is whatever that company’s internal process says it is, and outside parties, including the client whose information is in that conversation, have no visibility into where that bar sits.
Strip away the legal language and this is a plain ai confidentiality risk law firm leadership can explain to a client in one sentence: your conversation with an AI tool might get shared with law enforcement on the vendor’s own judgment, not a judge’s.
Most industries can absorb a policy change like this without much drama. Law firms can’t, not really, because privilege doesn’t work the same way once a third party is sitting in the middle of the conversation.
Attorney client privilege depends on a reasonable expectation of confidentiality. Courts have already wrestled with what happens to that expectation when a lawyer uses a cloud storage vendor, or an email provider, or a transcription service. Add a clause where the AI vendor itself can proactively decide to hand conversation content to law enforcement, without asking a judge first, and you’ve introduced a genuinely new wrinkle into that same old question. Nobody has fully litigated this yet. That’s exactly why getting ahead of it matters, instead of finding out the hard way during a discovery dispute.
Here’s a scenario that’s probably playing out at more firms than anyone wants to admit right now. An associate pastes a redacted but still identifiable summary of a client matter into Claude to get help structuring an argument or summarizing a deposition. That associate is using a personal Pro account because it’s fast, familiar, and nobody at the firm ever said not to. Under the new policy, that conversation now sits in a bucket the vendor can voluntarily disclose without a warrant, a bucket the firm’s actual enterprise agreement, if one exists, was specifically built to avoid.
A few state bars have already started weighing in on generative AI and client confidentiality, mostly through ethics opinions that predate this specific clause but still apply directly to it. The general guidance so far leans the same direction every time: lawyers remain responsible for protecting client information regardless of which tool touched it, and ignorance of a vendor’s data practices isn’t a defense. An ai confidentiality risk law firm hasn’t reviewed yet doesn’t stop being the firm’s problem just because a vendor wrote the policy.
This is where governance and procurement actually intersect, and where I think most firms are quietly exposed without realizing it. We’ve written before about what a law firm’s biggest AI risk actually looks like, and the pattern holds again here: firms spend their energy debating which AI vendor to pick, and almost none debating which tier of that vendor everyone is actually using day to day.
Claude for Work, Team, and Enterprise sit outside this new disclosure clause entirely, along with API based deployments. If your firm has a real enterprise agreement with Anthropic, this specific risk mostly doesn’t apply to you, at least not under this clause. If your associates are quietly running Claude Pro on personal accounts because IT never rolled out an approved enterprise option, or because the enterprise rollout only covers certain practice groups, that gap is exactly where this risk lives.
I’d bet most managing partners assume the firm’s approved AI tool covers everyone using it, tier included. That assumption is usually wrong, and it’s rarely tested until something forces the question. Checking which tier of Claude, or any other AI vendor for that matter, is actually installed across the firm is a five minute conversation with IT. Most firms haven’t had that conversation yet.
There’s also a procurement angle here worth raising with whoever handles vendor contracts. If your firm is renewing or negotiating an Anthropic agreement, or evaluating one for the first time, ask directly whether the enterprise terms explicitly exclude the good faith disclosure clause the consumer policy now includes. Get that answer in writing, not as a verbal assurance from a sales rep. A vendor contract is exactly where an ai confidentiality risk law firms are exposed to gets closed for good, or quietly left open.
This whole situation is really a shadow ai law firm problem wearing a new hat. We built our shadow AI assessment for law, energy, and medical practices around exactly this blind spot: not which tools are officially approved, but which ones people are actually using, on real client matters, that nobody signed off on or even knows about.
The Anthropic policy change doesn’t create shadow AI risk. It just raises the stakes on a risk that was already sitting there, quietly, before this. A free or personal AI account being used for client work was already a governance gap. Now it’s a governance gap with a specific, documented disclosure mechanism attached to it, one a court or a bar disciplinary committee could point to directly if it ever came up.
Data leaving your firm’s environment through an ungoverned personal account is exactly the blind spot our data loss prevention page is built to catch, and it’s worth reading with this specific scenario in mind. Traditional DLP tools were built to watch for files leaving through email or USB drives. Most of them were never built to notice a paragraph of client facts getting typed into a chat window on a personal AI account, which is precisely how this kind of exposure tends to slip past every control a firm already has in place.
None of this means Claude is unsafe to use, or that firms need to panic and ban AI tools outright. That would be an overcorrection, and a costly one given how much genuine value these tools bring to legal work when they’re actually governed properly. What it does mean is that “AI policy” needs to specify which tier, not just which vendor.
A workable version of this is short. Confirm which Claude tier, or whichever AI tool’s tier, your firm actually has under contract. Confirm it covers everyone who’s using the tool, not just the practice group that piloted it first. Put in writing that client matter work only happens on the governed tier, and check that this is actually happening rather than just written down somewhere nobody reads. None of this is complicated. It’s just a step most firms haven’t taken yet, mostly because nobody’s asked the question out loud.
Treat this as a standing item on whatever committee reviews technology risk, not a one-time fix. Vendors change their policies, tiers get renamed, new practice groups pick up tools nobody vetted. An AI confidentiality risk that a law firm closes this quarter can quietly reopen next quarter if nobody is keeping watch.
Want a clearer picture of where your firm’s actual AI exposure sits, beyond which vendor you’ve officially approved?
Our AI Readiness Assessment is built to catch exactly what standard DLP tools miss once AI tools are already in the picture, which is precisely the gap this whole post has been circling. A reasonable next step before your next AI policy review, not after a client asks why their conversation summary ended up somewhere it shouldn’t have.
Call or email Cocha. We can help with your cybersecurity needs!
About the Author:
Co-Founder & Managing Director, Cocha Technology
Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.