Back to Blog
    LegalTek TrustMark shield emblem grading AI platforms green to red for legal practice
    TrustMark Report
    ABA Op 512
    COUNSEL Framework
    Vendor Due Diligence

    The LegalTek TrustMark Report

    An ABA Formal Opinion 512 and COUNSEL Framework review of the AI platforms lawyers actually use — graded, tier by tier.

    Matt MishakMatthew A. Mishak, J.D.
    June 17, 2026
    22 min read
    LegalTek TrustMark
    Share

    New: Explore the interactive TrustMark certification with filterable matrix, traffic-light tiers, and per-platform detail.

    Open the TrustMark Report →

    Prepared for Matthew A. Mishak, Managing Attorney, Mishak Law LLC; Founder/CEO, LegalTek.ai. Analytical spine: ABA Formal Opinion 512 — Generative Artificial Intelligence Tools (July 29, 2024). This is the public version of the LegalTek TrustMark deliverable.

    TL;DR

    • Under ABA Op 512, the single dispositive variable is whether client information is processed under enterprise or commercial terms that contractually bar model training. Consumer tiers of ChatGPT, Claude, Gemini, and Grok all train on inputs by default (or behind an easily-missed opt-out) and are categorically unsuitable for confidential client data.
    • Purpose-built legal platforms (CoCounsel, Lexis+ with Protégé, Harvey, Midpage) and the enterprise tiers of the general models earn the highest TrustMark grades — contractual no-training, SOC 2 Type II + ISO 27001, and ZDR options that satisfy Rules 1.1, 1.6, 5.1, and 5.3.
    • United States v. Heppner (S.D.N.Y. Feb. 17, 2026) confirms that pasting privileged information into a consumer AI can waive privilege — precisely because the vendor's privacy policy permits training and third-party disclosure. Tier selection is now an evidentiary imperative, not just procurement.

    Part I — The ABA Op 512 / COUNSEL Framework

    ABA Formal Opinion 512, issued July 29, 2024 by the Standing Committee on Ethics and Professional Responsibility, is the spine of this analysis. It identifies six duty areas; the COUNSEL Framework maps onto those duties as the operational scoring layer for each platform. Because COUNSEL is built on Op 512, the duties below control.

    Rule 1.1 — Competence

    Reasonable understanding of capabilities and limits. Independent verification of output is non-delegable. The Stanford RegLab study found Lexis+ AI hallucinated >17% and Westlaw AI-Assisted Research >34% — even purpose-built legal tools require review.

    Rule 1.6 — Confidentiality

    Evaluate disclosure risk before input. Self-learning tools require informed client consent — boilerplate engagement-letter language is insufficient. Read the TOS, privacy policy, and DPA, or have someone qualified read them for you.

    Rule 1.4 — Communication

    Disclose AI use when asked, when inputting client information, when relevant to fee reasonableness, and when output will influence a significant decision in the representation.

    Rules 5.1 / 5.3 — Supervision

    Managerial lawyers must adopt clear AI policies. Supervisory duties extend under 5.3(b) to third-party GAI providers themselves — not just to employees.

    Rules 3.1 / 3.3 / 8.4(c) — Candor

    Output must be carefully reviewed before assertion to a court. Known failure modes: fabricated opinions, inaccurate analysis, misleading argument.

    Rule 1.5 — Fees

    Bill only actual time. Do not bill clients to learn a tool the firm uses regularly. Treat overhead AI as non-billable; per-use legal-AI expenses billed at actual cost with advance disclosure.

    The Heppner overlay

    In United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026), Judge Jed S. Rakoff held that 31 documents a criminal defendant generated using the consumer version of Anthropic's Claude were protected by neither attorney-client privilege nor work product. The court found three independent grounds: Claude "is not an attorney"; Anthropic's privacy policy — which "expressly notifies users that Claude collects their inputs and trains Claude on that data" and "reserves the right to disclose such data to third parties, such as government authorities" — destroyed any reasonable expectation of confidentiality; and the documents were not prepared for the purpose of obtaining legal advice or at counsel's direction.

    Critically, Judge Rakoff suggested that an enterprise tool offering "assurances of confidentiality" and making "clear user inputs will not be used for training… could at least arguably give rise to a reasonable expectation of confidentiality," and that counsel-directed use might bring the tool within the Kovel agent doctrine. Heppner is the clearest judicial validation yet of the consumer/enterprise distinction that drives this report.

    Part II — Platform-by-platform analysis

    1. ChatGPT / OpenAI

    OpenAI's consumer Privacy Policy (updated Feb. 6, 2026) states: "we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT." The opt-out is buried in a help article. Enterprise commitments are different: "By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform — including inputs or outputs — for training or improving our models." DPA, BAA, SOC 2 Type 2, and Zero Data Retention available for eligible API endpoints.

    Litigation caveat. In NYT v. OpenAI, Magistrate Judge Ona T. Wang's May 13, 2025 preservation order (affirmed by Judge Stein, June 26, 2025) forced OpenAI to retain Free, Plus, Pro, Team, and standard-API logs that would otherwise have been deleted. Enterprise and ZDR-API customers were excluded. The preservation duty ended Sept. 26, 2025, but in November 2025 the court ordered OpenAI to produce 20 million de-identified logs. Deletion promises yield to legal process.

    Tier grades. Free / Plus / Pro / Go — F (prohibited for client data). Team / Enterprise / Edu — A-. API with ZDR — A-.

    2. Claude / Anthropic

    Following Anthropic's August 28, 2025 consumer terms update, Free, Pro, and Max chats and coding sessions now train Claude unless the user opts out, with retention extended to five years for opted-in users. Commentators flagged that the consent flow was pre-checked. Commercial terms are materially different: Anthropic does not train on inputs to Claude for Work (Team / Enterprise), API, Bedrock, or Vertex. ZDR is available per organization for eligible Claude Platform / API and Claude Code on Enterprise plans, though Anthropic "still retains User Safety classifier results" even under ZDR. BAA available for HIPAA-eligible services.

    This is the platform at issue in Heppner; the consumer policy's training and disclosure language was the express basis for the privilege ruling.

    Tier grades. Free / Pro / Max — F. Commercial / API / Bedrock / Vertex — A-.

    3. Gemini / Google

    For licensed Google Workspace with Gemini: "Submissions aren't used to train models and are never reviewed by humans," with permission inheritance (Gemini cannot see files the user cannot see), ISO 42001, BSI C5, FedRAMP High, and BAA-eligible HIPAA workloads. Consumer Gemini, by contrast, may use data for training unless Gemini Apps Activity is adjusted, and human reviewers may see conversations.

    Tier grades. Consumer Gemini — D. Workspace and Vertex AI — A-.

    4. Grok / xAI

    xAI's FAQ: "We may use your content and interactions with Grok… along with Grok's responses to train our models," subject to a settings control and a Private Chat mode. The X platform's separate policy permits sharing user data with "third-party collaborators" for their own AI training unless users opt out. Reporting conflicts on whether Grok's own default is opt-in or opt-out, and the February 2026 SpaceX/xAI combination introduces governance uncertainty across a merged ecosystem. Grok itself warns users not to share sensitive information.

    Grade. D — not recommended for client data.

    5. Manus

    Manus represents that it does not use personal information to train AI/ML models and "endeavour[s] to disable third-party training on your data," using data minimization to send only "the information needed for a specific step" to third-party AI partners. As an autonomous agent running a cloud browser, its attack surface is materially larger than a chatbot's. Independent reviewers recommend the Enterprise version for stricter isolation and formal no-training guarantees. Public reports of accounts and task content being exposed — though disputed — counsel caution.

    Grade. C- — caution; not for confidential matters absent an enterprise agreement.

    6. Westlaw / Thomson Reuters (CoCounsel)

    Thomson Reuters' CoCounsel Security FAQ: "Thomson Reuters doesn't train generative AI models on User Content or User Prompts," which "Aren't used to train or improve any 3rd party gen AI LLMs (OpenAI GPT or Google Gemini)" and "Aren't stored by Open AI GPT or Google Gemini." TR has "established systemic controls to turn off third parties' abuse-monitoring solutions to ensure there is no human access." CoCounsel Legal maintains SOC 2 Type II and ISO 27001 with a zero-retention API architecture. This is a model architecture for Rule 1.6 compliance.

    Grade. A.

    7. Lexis+ AI / Protégé (LexisNexis)

    LexisNexis represents: "We never use customer data to train AI models," and for Protégé: "Your prompts and uploaded documents are encrypted, governed by enterprise-grade data protection, and never used to train external AI models." RAG architecture with models hosted on Microsoft Azure (OpenAI), AWS Bedrock (Anthropic), and Mistral. Renamed Lexis+ with Protégé in February 2026. Competence caveat: the Stanford study found Lexis+ AI produced incorrect information more than 17% of the time, so Rule 1.1 verification remains mandatory.

    Grade. A.

    8. Midpage

    Legal research and drafting platform; SOC 2; integrations with Claude, ChatGPT, and Perplexity; coverage of roughly 99% of binding federal and state appellate decisions with an AI citator. Its Research Agent generates answers "exclusively from the cases it has reviewed, not from pre-trained memory," with hyperlinked, verifiable citations — which materially reduces Rule 1.1 hallucination risk. Venture-stage; confirm no-training terms and DPA in writing before client-confidential use.

    Grade. A- / B+ (confirm DPA).

    9. Otter.ai

    Otter's policy: "We train our proprietary artificial intelligence technology on de-identified audio recordings. We also train our technology on transcriptions… which may contain Personal Information." Personal information is shared with data-labeling providers. Now facing a consolidated privacy class action — Brewer v. Otter.ai Inc., No. 5:25-cv-06911-EKL (N.D. Cal., filed Aug. 15, 2025), consolidated as In re Otter.AI Privacy Litigation (consolidated complaint Dec. 5, 2025) — asserting ECPA, CFAA, CIPA, CDAFA, and UCL claims. The auto-join and default-recording behavior creates acute two-party-consent exposure and a direct Rule 1.6 inadvertent-disclosure risk.

    Grade. D — high risk; not recommended for client matters.

    10. Fathom

    Fathom: "None of our AI sub-processors (Anthropic, OpenAI, or Google) are contractually permitted to use our users' data to train their AI models." However, "Fathom uses de-identified customer data to improve the accuracy of our proprietary AI models," with opt-outs at the user and organization level. HIPAA, SOC 2 Type II, GDPR-compliant. The bot joins as a visible "Fathom Notetaker," aiding consent. Rule 1.6 residual: proprietary-model improvement is opt-out rather than opt-in.

    Grade. B+ / B — turn off model-improvement at the organization level for client matters.

    11. Fireflies.ai

    Fireflies: meeting content "is never used to train any AI models," with a "Zero Data Retention policy" enforced against OpenAI and Anthropic. SOC 2 Type II, GDPR, HIPAA (BAA on Enterprise), Private Storage and a Rules Engine on Enterprise. Flag: now facing biometric-privacy litigation — Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 (filed Dec. 18, 2025), and Fricker v. Fireflies.AI Corp., No. 1:26-cv-02675 (N.D. Ill. Mar. 2026) — under the Illinois Biometric Information Privacy Act over alleged voiceprint collection. All-party-consent recording rules apply.

    Grade. A- / B+.

    12. Plaud

    Plaud: "We do not use collected personal data for training, optimizing, or developing AI or machine learning models," and "User data is not used for training these models, unless explicitly opted in." Local-device default storage. ISO 27001, ISO 27701, SOC 2 Type II, HIPAA, GDPR. OpenAI, Google, and Microsoft operate under zero-data-retention agreements as subprocessors. Verify business terms and BAA for client use; recording consent applies.

    Grade. B+.

    13. Also relevant

    Microsoft 365 Copilot (enterprise). "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs," under the Microsoft Product Terms and DPA, with EU Data Boundary support and abuse-monitoring human review opted out. Consumer Copilot tiers (Free, Pro, the standalone app, and Personal/Family Microsoft 365) lack these guarantees and may use conversations for training. Enterprise A-; consumer D.

    Harvey. Contractual guarantee: "We don't use inputs, outputs, or uploaded documents to train underlying models," and "the same applies for our subprocessors and model providers"; data is "used at inference time only." SOC 2 Type II, ISO 27001 (Schellman), EU-US Data Privacy Framework certified, configurable data residency (US, EU/Switzerland, Australia), customer-set retention including zero-day. Grade A.

    Part III — Master TrustMark Matrix

    Grades are a snapshot as of June 2026 and are contingent on an executed DPA/MSA for any "Approved" enterprise tier.

    PlatformTierTrustMark
    ChatGPTFree / Plus / Pro / GoF
    ChatGPTTeam / Enterprise / EduA-
    ClaudeFree / Pro / MaxF
    ClaudeCommercial / API / Bedrock / VertexA-
    GeminiConsumerD
    GeminiWorkspace / Vertex AIA-
    Grok / xAIAll tiersD
    ManusStandardC-
    CoCounsel (Thomson Reuters)EnterpriseA
    Lexis+ with ProtégéEnterpriseA
    MidpageStandardA-
    Otter.aiAll tiersD
    FathomStandardB+
    Fireflies.aiEnterpriseA-
    PlaudStandardB+
    Microsoft 365 CopilotEnterpriseA-
    Microsoft CopilotConsumerD
    HarveyEnterpriseA

    Recommendations

    Green — Approved for client data

    • CoCounsel (Thomson Reuters)
    • Lexis+ with Protégé
    • Harvey
    • Midpage
    • ChatGPT Team / Enterprise / Edu
    • Claude Commercial / API / Bedrock / Vertex
    • Gemini Workspace / Vertex AI
    • Microsoft 365 Copilot Enterprise

    Each under a signed DPA.

    Red — Never with client data

    • ChatGPT Free / Plus / Pro / Go
    • Claude Free / Pro / Max
    • Consumer Gemini
    • Grok (all consumer tiers)
    • Consumer Microsoft Copilot
    • Otter.ai

    Yellow tier: consumer tools are usable for non-confidential general research only, strictly without client-identifying facts.

    Never input client-identifying information into any consumer tier. Heppner establishes that doing so risks privilege waiver and renders the material discoverable. The single benchmark that flips a tool from red to green is an executed enterprise/commercial agreement containing a contractual no-training clause plus a DPA. For maximum privilege protection on sensitive matters, have counsel direct the use of an enterprise, no-training tool — potentially invoking the Kovel agent rationale the Heppner court left open.

    Require, in writing, before approving any vendor

    • Contractual no-training commitment that flows down to subprocessors
    • SOC 2 Type II baseline; ISO 27001 preferred
    • Zero Data Retention or a short, defined retention period
    • Breach-notification terms
    • Data-deletion rights and confirmation the vendor asserts no proprietary rights to inputs
    • BAA where any health information is involved

    Walk away on unlimited unilateral amendment rights, vendor data-ownership claims, or refusal to disclose subprocessors.

    Engagement letters

    Obtain specific, non-boilerplate informed consent in the engagement letter for any matter in which client information will be input into a self-learning tool, identifying the tool, the benefit, and the specific risks. Op 512 is explicit that boilerplate "lawyer may use GAI" language is insufficient.

    Billing under Rule 1.5

    Bill only actual time spent operating the tool and reviewing output; do not bill clients for time learning a tool the firm uses regularly; treat embedded/overhead tools as non-billable; bill per-use legal-AI expenses only at actual cost with advance disclosure.

    Re-evaluate quarterly

    Grade-changing triggers include a vendor changing its default training posture (as Anthropic did in 2025), a new preservation or production order (as in NYT v. OpenAI), loss or lapse of a certification, new biometric or wiretap litigation (as with Otter and Fireflies), or a new Ohio or ABA ethics opinion. Maintain an evidence folder of executed DPAs, trust-center documents, and configuration screenshots to support the supervisory record under Rules 5.1 and 5.3.

    Caveats

    • Many no-training and security representations here are drawn from vendor trust-center and marketing pages rather than the operative contract. The binding document is the executed DPA/MSA — obtain, read, and retain it.
    • Vendor policies change quickly. Anthropic's August / September 2025 reversal and OpenAI's litigation-driven retention changes confirm that every grade is a snapshot subject to revision.
    • "De-identified" is not "anonymous." Otter and Fathom train proprietary models on de-identified data, which carries re-identification risk for sensitive matters. Treat de-identified training as a confidentiality concern, not a safe harbor.
    • Heppner is a trial-court decision (S.D.N.Y.) whose categorical language ("Claude is not an attorney… that alone disposes of Heppner's claim") may be narrowed on appeal or distinguished. The prudent reading is that enterprise, attorney-directed, no-training tools are materially better positioned to preserve privilege — not that AI use categorically destroys it.
    • Recording tools (Otter, Fireflies, Fathom, Plaud) implicate state two-party / all-party consent statutes independent of the AI-training analysis. Obtain all-party consent before recording any client or adverse communication.
    • Court orders and lawful process override deletion and retention promises across every platform reviewed.

    The Bottom Line

    Op 512 didn't ban AI. It made tier selection a mandatory competence task. Use the enterprise tier of a tool that contractually refuses to train on your clients' work — paired with a signed DPA, independent verification of output, and a non-boilerplate consent — and most of Op 512 takes care of itself. Use a consumer tier and, after Heppner, you have given the other side a discovery argument before you've filed an appearance.

    This report was prepared by LegalTek.ai, which builds purpose-designed AI tools for the legal profession with professional-responsibility safeguards built in. Vendor representations are sourced from public trust centers, privacy policies, and terms of service as of June 2026 and should be verified against the operative contract before reliance.

    Disclaimer: This article is for general informational and educational purposes and does not constitute legal advice. No attorney-client relationship is created by reading this material. LegalTek.ai is a technology company, not a law firm.

    Matthew A. Mishak

    Matthew A. Mishak

    Managing Attorney, Mishak Law LLC | Founder & CEO, LegalTek.ai | Creator of the COUNSEL Framework & TrustMark

    Matt Mishak is a practicing attorney and nationally recognized voice on AI governance in legal practice. He developed the COUNSEL Framework and the LegalTek TrustMark to help courts, legislators, and law firms adopt AI ethically and verifiably.