Philippine lawyers may find ChatGPT useful for low-risk drafting, summarization, and structured thinking, but a firm should approve the account, information boundary, purpose, and review method before client work enters the system. Whether a particular use complies with professional, contractual, privacy, and legal duties requires qualified analysis of the actual facts.

Start with information, not prompts

Do not enter privileged communications, confidential client files, sensitive personal information, passwords, complete matter records, or restricted firm knowledge into an unapproved account. Redaction may reduce risk but does not fix unclear vendor terms or a weak firm policy.

OpenAI publishes separate enterprise privacy information. Firms should review the exact service, settings, connected tools, retention, administrators, and contractual terms rather than relying on a general statement about ChatGPT.

The short operational answer

Use should depend on the account, the information, the task, and the review. The following is a risk screen, not a legal opinion.

Situation Practical posture
Public information, generic administrative task, approved account May be suitable within firm policy
Sanitized or synthetic training exercise May be suitable if re-identification and metadata risks are addressed
Client facts or matter files in an unapproved account Do not proceed
Approved business account handling information within a reviewed workflow Requires the firm’s documented authorization and controls
Legal advice, filing, or client communication with no lawyer verification Do not proceed

A paid account is not the same as an approved workflow. Approval should cover the exact plan, configuration, connectors, users, purpose, and information class.

Use cases with a clearer boundary

Lower-risk examples include outlining a public presentation, rewriting a non-confidential administrative email, creating questions from a public document, or testing a generic checklist with synthetic facts.

Legal research, client advice, pleadings, contracts, and matter summaries require a stronger source and review method. The lawyer must inspect the original authority and record, not only the generated answer.

Redaction is not a complete control

Removing a client’s name may not make a prompt harmless. A distinctive transaction, chronology, location, amount, role, or combination of facts may still identify the matter. Files can also contain comments, revision history, hidden text, or metadata.

Before using sanitized material, ask whether the remaining facts are necessary for the task, whether the person or matter can reasonably be inferred, and whether the exact tool and account are approved to receive it. If the answer is unclear, use synthetic facts or keep the work inside an approved environment.

Verify every consequential detail

Check case names, citations, quotations, dates, procedural posture, statutory text, holdings, and whether authority remains current. Confirm that the model did not import facts from another matter or jurisdiction.

The Supreme Court has publicly warned about reckless technology use and cited the danger of fictitious AI-generated case citations. A fluent answer is not evidence.

Use a source-first review sequence:

  1. separate every legal proposition and factual assertion;
  2. open the cited authority or record independently;
  3. confirm the quoted language in context;
  4. check jurisdiction, date, status, procedural posture, and subsequent treatment;
  5. compare names, dates, amounts, and instructions with the matter record;
  6. record material corrections before the output enters a work product;
  7. have the responsible lawyer accept the final text.

If the original source cannot be opened, treat the proposition as unverified.

Firm rules before use

A written policy should name approved accounts, prohibited information, permitted use cases, required review, record retention, disclosure decisions, incident reporting, and the person authorized to approve new connectors.

The firm should also answer operational questions people will actually face: May a browser extension read an open matter page? May a custom assistant retain uploaded files? May a user connect email or cloud storage? Who removes access when a lawyer leaves? What happens when a vendor changes its terms or model?

A five-minute pre-use check

Before opening a client-related workflow, the lawyer or staff member should be able to answer:

  • Is this the approved firm account and configuration?
  • Is this use case on the approved list?
  • Is every item of information permitted in this system?
  • Are connected tools and shared workspaces understood?
  • Can I check the result against original sources?
  • Am I the right reviewer, or is another lawyer responsible?
  • Do I know how to report a mistake or accidental disclosure?

One “no” or “I do not know” means stop and escalate. The purpose of the check is not to make each user perform vendor due diligence. It is to make the approved boundary usable at the moment of work.

If personal data is processed, consider the NPC AI advisory and obtain the necessary privacy and legal advice.

The practical answer is controlled use, not casual use. Begin with the law-firm AI policy template and the broader legal AI guide.

The final question is not whether ChatGPT can produce useful legal-looking text. It can. The firm must decide whether a particular workflow gives the right person enough control over the information, source, account, and final judgment. If those controls are missing, the appropriate next step is not a better prompt. It is a better boundary.

Source ledger

Sources used and checked

Verified July 13, 2026. Links may change after publication.

  1. Enterprise privacy at OpenAIOpenAI, accessed July 13, 2026
  2. Justice Zalameda urges lawyers to use technology cautiouslySupreme Court of the Philippines, accessed July 13, 2026
  3. Guidelines on AI systems processing personal dataNational Privacy Commission, accessed July 13, 2026