Our pilot partners are not choosing local AI because it is fashionable. They are choosing it because sending their data to a third-party model is, for them, a regulated act — and in many configurations, a violation.
This page collects what the rules actually say. It is an evidence review of published regulatory guidance, bar association opinions, and vendor contract terms as they stood in mid-2026. It is not legal advice, and the compliance posture of any specific tool changes constantly — verify current terms before relying on any of it.
Law: privilege is the asset, and the rules now say so explicitly
The American Bar Association's Formal Opinion 512 (July 2024) was the first national ethics framework for generative AI in legal practice. Its core holding is that AI is not a shortcut around a lawyer's existing duties: competence (Model Rule 1.1), confidentiality (1.6), and supervision (5.3) all apply in full. Under Rule 1.6, a lawyer must keep confidential all information relating to a representation regardless of source, unless the client gives informed consent.
State bars have built on it rapidly. By early 2026, 35+ state bar associations had issued AI guidance. Florida's Opinion 24-1 recommends obtaining the affected client's informed consent before using a third-party generative AI program if that use would disclose confidential information. Texas issued Opinion No. 705 in February 2025. The New York City Bar's Ethics Opinion 2024-5 requires lawyers to understand the data-retention and disclosure practices of any tool used on client matters.
The practical failure mode is mundane and common: an attorney under time pressure pastes a full contract — client names, deal terms, confidential provisions — into a consumer chatbot whose terms permit training on submitted data. The result is an uncontrolled copy of privileged material outside the firm's custody. Nothing about that is exotic; it is a Tuesday.
There is also an unsettled question underneath the ethics rules that should concern any firm: whether disclosure to a third-party AI provider affects privilege itself. The New York City Bar's working group has examined how the third-party doctrine's evolution bears on privilege waiver. The law is not settled. Firms that never transmit the material never have to find out.
Healthcare: without a BAA, it is a violation
Under HIPAA, any vendor handling protected health information on a covered entity's behalf must execute a Business Associate Agreement. The compliance line is drawn at the product tier, not the brand:
- Consumer tiers — ChatGPT Free, Plus, Pro, Team, and self-serve Business — are not BAA-eligible. Putting PHI into them is a HIPAA violation, full stop.
- BAA coverage exists for specific enterprise and API paths, sometimes limited to endpoints eligible for zero data retention — and the eligible endpoint list has changed over time.
- Penalties are tiered by culpability, with per-violation figures reported in the range of roughly $141 to more than $2.1 million.
- Liability flows upward: a business associate's actions are imputed to the covered entity under HIPAA's strict-liability regime.
Two failure modes dominate in practice. The first is product-tier mismatch — an organization holds a BAA-eligible enterprise tenant while staff log in through personal consumer accounts, routing around the agreement entirely. The second is shadow AI: a 2026 industry survey found 17% of healthcare professionals admit to using unauthorized AI tools. Neither is solved by procurement. Both are solved by architecture — if the inference never leaves the device, there is no disclosure to govern.
Education: FERPA's school-official rule does not fit a consumer chatbot
FERPA-protected education records cannot be sent to a general-purpose AI service without either prior written consent from the parent or eligible student, or a properly documented "school official" designation under 34 CFR § 99.31(a)(1). Consumer accounts cannot satisfy that designation: there is no written contract restricting data use, no direct-control commitment, and no FERPA-aligned terms. Compliant paths in 2026 are contracted enterprise tiers with appropriate terms, dedicated EdTech platforms carrying FERPA/COPPA and state-law-aligned agreements, or redaction at the source, so no education record ever leaves the device. That last option is the one this lab studies.
Why this is a research problem and not only a procurement problem
Every compliant cloud path above shares a structure: a contract promising that data will be handled properly, and an audit trail that depends on the vendor's own attestations. That is a reasonable posture, and for many organizations it is sufficient. But it is a promise, and it is enforced after the fact.
The alternative posture is architectural: the data never leaves the device, and the organization holds a cryptographic artifact proving it. That converts a contractual assurance into a verifiable fact — something a compliance officer can independently check rather than trust. Producing that artifact reliably, on consumer hardware, is AEOLI's third thrust. The regulatory landscape on this page is precisely why we think it matters.
If you work in compliance, privacy law, or institutional IT and see something here we've gotten wrong or oversimplified, we want the correction: support@yforest.ai.
Sources
ABA Formal Opinion 512; Florida Bar on Opinion 24-1; NYC Bar, The Intersection of AI, Privacy, and Privilege; NYC Bar analysis of ethics guidance (PDF); HIPAA Journal, Is ChatGPT HIPAA Compliant?; Business Associate Agreements in 2025 (MDRXLaw); AI BAA vendor guide 2026; FERPA and AI in schools and EdTech; Clio, AI Ethics Opinions guide.