Zero. That's how many client confidentiality breaches tied to free AI tools show up in a formal, industry-wide count right now.

You can't govern, insure, or reserve against a risk you can't measure, and right now, nobody can measure this one cleanly. The absence of a documented incident isn't evidence of safety, it's evidence that nothing is currently positioned to catch one.

Share
Zero. That's how many client confidentiality breaches tied to free AI tools show up in a formal, industry-wide count right now.

That's not a good number. It's an absent one — and for anyone with governance responsibility over a firm, a board seat, or a book of professional liability business, an absent number should read as a bigger warning sign than a high one.

Here's the fiduciary problem underneath it: you can't govern, insure, or reserve against a risk you can't measure. And right now, nobody can measure this one cleanly. Bar complaint data doesn't reliably tag "AI tool" as a contributing cause. Malpractice claims data is starting to — EPIC's 16th Annual Lawyers' Professional Liability Claims Survey found that 7 of the 13 insurers surveyed reported an increase in AI-related claims this past year — but that survey only captures claims that were actually filed, not the incidents caught internally, settled quietly, or never noticed at all.

Compare that to a data point that does exist: the Charlotin AI Hallucination Cases Database has logged more than 1,800 court decisions involving fabricated AI citations. That number exists because a judge read a filing and caught the error. There is no equivalent institutional catch mechanism for confidentiality — no one reviews what an associate pasted into a free-tier chatbot to speed up a summary. If it never surfaces in a filing, it never surfaces at all.

Even paid, vendor-integrated tools aren't immune from this accountability gap. In In re Rosslyn2016, LLC (S.D. Texas, Bankruptcy Court, July 2026), Westlaw Precision — a paid legal research product — produced fabricated citations that cost the firm a $29,877 penalty. The vendor disputed responsibility for the underlying cause. If accountability is already contested for a paid tool with a vendor relationship on the other end of it, there's effectively none for a free consumer tool with no relationship at all.

The natural objection: "our lawyers know not to paste client information into ChatGPT." That may be true as policy. It says nothing about practice — and the absence of a documented incident isn't evidence of safety, it's evidence that nothing is currently positioned to catch one.

The practical move: stop treating "no known incidents" as a clean bill of health. Require enterprise-tier, zero-retention agreements as the floor for any AI tool touching client information, and audit which tools your people are actually using — not just which ones are approved on paper.