confidentiality
Confidentiality in the Age of Generative AI: What Singapore's Legal Community Must Reckon With

The Quiet Erosion of an Old Assumption
For decades, legal confidentiality rested on a relatively stable foundation: client information stayed within the firm, shared only with colleagues who needed it and third parties who were contractually bound to protect it. Generative AI disrupts that foundation not through any dramatic breach, but through a gradual normalisation of behaviour that would once have raised immediate professional concern.
When a lawyer pastes a clause from a client's draft acquisition agreement into a general-purpose AI assistant to get a redline suggestion, something has happened to that information. Where it went, who trained on it, whether it persists in a model's weights or a provider's logs: these are not hypothetical anxieties. They are live questions that Singapore's professional conduct framework is only beginning to address in any systematic way.
The Singapore Law Gazette has noted that Claude, Anthropic's large language model, has become a fixture in legal community conversations. That prominence makes it a useful lens. The question is not whether Claude specifically is safe or unsafe. The question is what confidentiality even means when the tool doing the legal work is a cloud-hosted model trained on data you did not audit, governed by terms of service you probably did not read closely, and operated by a company incorporated in a jurisdiction whose data laws differ materially from Singapore's PDPA regime.
What the Professional Rules Actually Say
The Legal Profession (Professional Conduct) Rules 2015 impose a duty of confidentiality that extends beyond active engagements. Rule 6 is clear that the obligation survives the retainer. What it does not do is specify how that duty interacts with AI-assisted workflows, because it was drafted before those workflows existed at scale.
The Law Society of Singapore has issued guidance on technology use, but guidance is not a rule, and guidance written for cloud storage or e-discovery does not map cleanly onto a system that can infer, synthesise and generate from whatever it receives. In-house counsel face a parallel problem under their own obligations, particularly where the company's data governance policies conflict with the defaults built into the AI tools their teams have begun using without formal procurement processes.
The gap between existing rules and current practice is not unique to Singapore, but Singapore's position as a regional arbitration and transactions hub gives it particular salience here. Counterparty information shared in M&A due diligence, arbitral pleadings, or regulatory submissions carries confidentiality obligations that travel beyond the client relationship itself.
The Contractual Layer That Often Goes Missing
Contracts are where confidentiality obligations are made specific and enforceable. An NDA between two companies negotiating a joint venture will typically define confidential information broadly, restrict its use to evaluation purposes, and prohibit disclosure to third parties without prior written consent. A general-purpose AI assistant is a third party. Most NDAs were not drafted with that in mind.
This is the contractual layer that in-house teams frequently overlook when adopting AI tools rapidly. The legal operations team might approve a tool on data security grounds, satisfy themselves that the provider does not use customer data for model training under the enterprise tier, and move forward. But the NDA with the counterparty may impose a stricter standard than the provider's terms permit, regardless of how well those terms are written.
Adira is built to read contracts from your side of the table, which means it surfaces these obligations before they become violations. When a company's contract portfolio contains active NDAs restricting disclosure to third-party systems, that constraint should inform how AI tools are deployed against those agreements, not the other way around.
Jurisdiction-Aware AI Is Not Optional
One aspect of the confidentiality conversation that receives insufficient attention is the jurisdictional dimension. Singapore law governs many commercial contracts in the region, but the AI tools processing those contracts may be subject to US export controls, EU data transfer rules, or the data localisation requirements of any number of other jurisdictions depending on where servers sit.
A tool that does not know the law of the jurisdiction it is working in cannot flag when a proposed disclosure would breach a statutory obligation, a regulatory requirement, or a court order that binds the client. Legal AI that operates as a general language processor, agnostic to jurisdiction, will produce outputs that are fluent but potentially non-compliant in ways that neither the lawyer nor the client will immediately detect.
Adira's design premise is that jurisdiction-awareness is foundational, not a feature to be added later. The law you are working under shapes the analysis, not just the formatting.
Building Practice Norms Before Regulators Do
The most practical message for Singapore law firms and in-house teams is this: the window for self-regulation is open, but it will not stay open indefinitely. The Law Society and the Ministry of Law are watching how the profession adapts. Firms that develop coherent, documented AI governance frameworks now, including clear policies on what information may be processed by which tools under which contractual conditions, will be in a far stronger position when formal rules arrive.
Confidentiality is not a compliance checkbox. It is the foundation of the trust that makes legal work possible. Generative AI is genuinely useful. The task is to make it useful without dismantling what the profession is built on.
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomRelated reading

