Skip to content

AI Safety & Confidentiality

As legal practitioners, advocates hold an ethical and legal duty under the Advocates Act (Cap 16) and the Kenya Data Protection Act (2019) to protect client confidentiality and preserve legal professional privilege.

While artificial intelligence offers tremendous productivity gains, it must be used with ethical vigilance and clear boundaries.


1. MtaaLex AI vs. Public Consumer AI Tools

One of the most dangerous habits in modern law offices is lawyers copying and pasting confidential client agreements into free, public consumer AI chat tools on the internet.

AspectPublic Consumer AI ToolsMtaaLex AI Workspace
Data Usage for TrainingMany public free AI tools explicitly state in their terms that user prompts may be used to train future public foundation models.MtaaLex calls secure enterprise AI APIs. Prompts sent through MtaaLex are not used to train public models.
Workspace IsolationOpen, single-user consumer accounts without law firm governance.Strict enterprise multi-tenant boundary. Each inquiry is bound to your firm's private workspace.
Document AccessFiles uploaded to public tools can sit on unknown foreign consumer servers.Files are accessed securely through your firm's encrypted document vault.

2. Advocate-Client Privilege & AI Work Product

In Kenyan law, legal professional privilege protects confidential communications between an advocate and their client for the purpose of seeking legal advice, as well as work product prepared in contemplation of litigation (Section 134, Evidence Act).

IMPORTANT LEGAL CONSIDERATION

Never assume that text generated by an AI assistant is automatically protected by advocate-client privilege merely because it was produced inside a legal software application.

Privilege belongs to the client, not the software. If an advocate indiscriminately pastes unredacted third-party trade secrets or confidential settlement terms without proper professional context, opposing counsel could argue that confidentiality was waived.


3. Best Practices for Protecting Client Privacy in AI

To uphold the highest professional standards, adopt these simple safety habits in your daily practice:

1. Sanitize Sensitive Personal Identifiers Where Possible

When asking broad legal research questions, you rarely need to include the client's actual national ID number, passport number, personal telephone number, or bank account balance.

  • Use pseudonyms or descriptions: Instead of "Client James Mwangi, ID No. 12345678, Account 01109988...", write: "Our client, a commercial dairy cooperative...".

2. Verify Matter Context Before Uploading

When using document analysis, always ensure you have selected the correct client and case file. This prevents attaching confidential documents from Client A to the matter workspace of Client B.

3. Review AI Summaries for Omissions

AI assistants synthesize text by highlighting main themes. If an affidavit contains a subtle, critical exception or qualification, verify that the AI's summary did not inadvertently drop the nuance.


4. Firm AI Usage Policies

We strongly recommend that Managing Partners establish a clear internal firm policy regarding AI usage:

  • Mandatory Human-in-the-Loop: Establish an unshakeable rule that no AI-generated pleading, submission, or contract clause is ever filed in court or sent to a client without being reviewed, verified, and signed off by an admitted advocate.
  • Prohibition of Unapproved Consumer AI: Instruct pupils, interns, and associates never to paste client files into unapproved personal web tools.
  • Audit & Accountability: Remind all practitioners that MtaaLex records user activity in the firm audit trail, maintaining internal accountability.

PERSISTENT REMINDER

AI-generated legal content must be reviewed and verified by a qualified legal professional before it is relied upon, sent to a client, filed in court, or used as legal advice.

Empowering African Legal Practice through Technology & Compliance.