confidentiality

Confidentiality in the Age of Generative AI: What Singapore's Legal Community Must Get Right

Adira EditorialLegal AI desk4 min read
Editorial illustration for Confidentiality in the Age of Generative AI: What Singapore's Legal Community Must Get Right

The Old Rules, a New Problem

Legal professional privilege and confidentiality obligations did not arrive with the internet, and they will not be rewritten by large language models. The core duties remain: lawyers must safeguard client information, and in-house counsel must protect commercially sensitive data. What changes with generative AI is the surface area of risk. Every prompt sent to an external model is, in some meaningful sense, a disclosure. Whether that disclosure constitutes a breach depends on jurisdiction, contract, and context, but the question deserves a serious answer rather than a shrug.

In Singapore, the Legal Profession (Professional Conduct) Rules 2015 impose a continuing obligation to preserve client confidentiality. The Personal Data Protection Act adds a separate layer for personal data. When a lawyer or in-house team member pastes contract text into a third-party AI tool, both regimes are potentially engaged. The Singapore Law Gazette has noted that the legal community's familiarity with specific AI products has outpaced its understanding of how those products handle the data fed into them. That gap is where liability quietly accumulates.

What 'Reading from Your Side' Actually Means

Adira is built on a straightforward premise: a contract AI should read the contract from the perspective of the party who owns it. That design choice is not merely commercial. It has direct implications for confidentiality.

When a system processes a counterparty's draft and surfaces risk from your vantage point, it needs access to your context: your standard positions, your prior agreements, your risk appetite. That context is sensitive. A system that aggregates it across clients, or trains on it without restriction, creates exactly the kind of disclosure problem that professional conduct rules are designed to prevent. Adira processes client data under strict data handling commitments, with no cross-client training. The architecture is designed so that what you tell Adira about your business stays with your business.

This is not a minor technical footnote. It is the foundation on which in-house legal teams and law firms can actually use AI without asking their risk and compliance colleagues to look the other way.

Jurisdiction Matters More Than Lawyers Assume

One of the more persistent misconceptions about generative AI in legal work is that the law being applied is somehow universal. It is not. A contract governed by Singapore law raises questions about the Contracts (Rights of Third Parties) Act, the Electronic Transactions Act, and sector-specific regulations that differ materially from their equivalents in England, the United States, or Australia.

Generic AI tools trained on predominantly English or American legal corpora will surface analysis that sounds authoritative but may be wrong for Singapore. The same problem applies to confidentiality itself: the scope of legal advice privilege under Singapore law has been shaped by local case law and does not map precisely onto English common law, despite the shared heritage.

Adira is designed to work within the legal framework of the jurisdiction it is deployed in. For Singapore users, that means the analysis reflects local statute and precedent, not a global average. This is not a small distinction when a firm is advising on whether a particular disclosure falls within the scope of privilege, or when in-house counsel is deciding whether to flag a data processing clause to the DPO.

Practical Steps for In-House Teams Right Now

While the broader policy debate continues, legal operations teams do not have the luxury of waiting. There are concrete steps that reduce confidentiality risk without abandoning the genuine productivity benefits that AI offers.

First, classify before you paste. Not every contract needs the same level of protection. A standard vendor NDA carries less sensitivity than a term sheet for a material acquisition. Build a quick classification habit into your workflow so that the most sensitive documents are handled through approved, controlled systems rather than consumer-grade tools.

Second, review your AI vendor agreements with the same scrutiny you apply to any data processor agreement. The questions to ask are straightforward: Where is data stored? Is it used for model training? Who has access? What are the breach notification obligations? If your vendor cannot answer these questions clearly, that is itself an answer.

Third, document your AI use policy and update it regularly. Singapore's PDPC has published guidance on AI governance that provides a useful framework. A written policy also provides a defence in professional conduct proceedings if a question about disclosure ever arises.

The Firms That Will Get This Right

Confidentiality in the generative AI era is not a problem that resolves itself through inaction or through blanket prohibition of AI tools. Both responses leave value on the table while doing little to manage the actual risk.

The firms and in-house teams that navigate this well will be those that treat AI procurement as a legal risk exercise from the start, not an IT project reviewed by legal at the end. They will choose tools that are transparent about data handling, built for the jurisdictions they work in, and designed to read contracts from the right side of the table. The technology is ready for that standard. The question is whether the legal community will demand it.

Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom