SecurityTechInsider AI-veiligheid & governance
EN/ NL
Data

Veilig AI-gebruik voor advocaten en notarissen vraagt om een controlelaag, niet om voorzichtige prompts

Nieuwe CCBE-gidsen en nationale adviezen schetsen dat AI-gebruik door juristen aansluit bij een controleerbare vertrouwelijkheids- en verificatie-aanpak.

5 augustus 2026 5 min
Illustratie bij dit artikel: Veilig AI-gebruik voor advocaten en notarissen vraagt om een controlelaag, niet om voorzichtige prompts.
Lawyers must document how confidential data flows through AI systems and verify output before use in client work. Beeld: SecurityTechInsider — originele redactionele illustratie

U moet kunnen aantonen hoe vertrouwelijke gegevens worden behandeld wanneer AI-tools in uw praktijk worden ingezet. Dit vereist meer dan voorzichtige prompts: het vraagt om documentatie, contracten, technische waarborgen en verificatie van output voordat die in juridisch werk wordt gebruikt.

An analysis of 5 August 2026 of how legal professionals should structure AI use around confidentiality and verification argues that safe AI deployment in law depends on demonstrable control over data flows and output review, not on prompt engineering alone. The Council of Bars and Law Societies of Europe published technical guidance in March 2026 building on earlier principles from October 2025, establishing that professional duties—confidentiality, competence, independence and client transparency—do not suspend when AI tools are used. In our assessment, this signals a shift in how regulators and bar associations expect lawyers to think about AI: not as a tool to be used carefully, but as a system that must operate within an auditable framework of controls.

Wat vragen de gidsen van advocatenbonden concreet?

The CCBE guidance from October 2025 identifies a core risk: generative AI can breach professional secrecy if personal, confidential or client-related data is entered into a public or insufficiently secured interface. The October 2025 guidance advises against uploading such data unless appropriate technical and organisational safeguards are in place. The March 2026 technical guidance then addresses how to evaluate a tool before deploying it on casework. Both documents emphasise that AI use is a matter of configuration, data flows and contracts—not tool selection alone.

Comparable guidance has emerged outside Europe. Singapore's Ministry of Law published guidance in March 2026 recommending that lawyers classify confidential information, use only tools with appropriate security and data protection, and carefully review providers' privacy and training clauses. The Law Society of Singapore's April 2026 advisory on publicly available AI tools goes further, warning that such platforms can expose privileged, proprietary and confidential data. It advises members against uploading such material, recommends anonymisation and redaction, and asks users to verify privacy settings and opt-out options where available.

Welke risico's ontstaan als u geen controlelaag inbouwt?

  • Client confidentiality breach — sensitive case details, client names and privileged information exposed through AI interfaces or retained in model training.
  • Unverified output in legal work — AI-generated text, analysis or citations used in advice or filings without human review, creating liability for errors.
  • Loss of audit trail — no documented record of which data was processed, which model was used, or how output was verified, making it impossible to demonstrate compliance if questioned.
  • Contractual misalignment — using tools whose terms of service conflict with your professional duties or data protection obligations.
  • Dependency on provider security — relying on a vendor's security measures without contractual guarantees or technical verification that data is not retained or used for model training.

Welke concrete controles moet u kunnen aantonen?

  1. Classify and inventory confidential data — document which information is privileged, proprietary or client-related, and establish rules for what may and may not be input to AI systems.
  2. Evaluate and contract with providers — before using any tool, review its privacy policy, data retention terms, model training practices and security certifications, and ensure your engagement terms align with your professional duties.
  3. Apply technical safeguards — use tools that offer encryption, access controls, data anonymisation or on-premises processing where confidential data is involved, and verify these controls are active.
  4. Review and verify output — establish a documented process for human review of AI-generated content before it is used in legal advice, filings or client communications.
  5. Maintain an audit trail — record which model was used for which task, what data was processed, what output was generated, and how it was verified, so you can demonstrate the process if required.

Hoe past verificatie in uw bestaande compliance-structuur?

The recurring theme across CCBE guidance, Singapore's advisories and other professional standards is that AI use must integrate with existing compliance frameworks. Lawyers are already required to maintain confidentiality, verify facts, document decisions and act competently. AI does not suspend these duties; it adds a new layer of process to them. The guidance suggests that verification—checking AI output against known facts, case law, or other sources before use—is not optional. It is part of the professional competence requirement.

Multi-model verification, in which output is checked against more than one source or approach, makes the control steps visible rather than presenting a single answer as final truth. This does not guarantee correctness and does not eliminate errors. It makes review possible and creates visibility into what happened, so the professional judgment remains with you. An audit trail documenting which data was processed, which model was used and how output was verified helps you demonstrate compliance if questioned later. This aligns with the emphasis in professional guidance on demonstrable control.

Wat kunnen tools leisten en wat blijft uw verantwoordelijkheid?

Technical systems can enforce data anonymisation before content reaches an AI model, maintain encrypted storage, log access and use, and surface verification steps so you can see what was checked and what was not. They can also help you document the process, creating evidence that controls were applied. What tools cannot do is make the judgment call about whether output is correct, whether it should be used in a particular case, or whether it meets your professional standard. That judgment stays with you. The role of a control layer is to make your review possible and your process auditable, not to replace your professional responsibility.

Bronnen: Dit artikel is gebaseerd op berichtgeving en richtlijnen van CCBE, MLAW, Lawsociety en Obsidianri.

Noor El Amrani

Geschreven door

Noor El Amrani

Gegevensbescherming, anonimisering in de praktijk, en wat toezichthouders daadwerkelijk als bewijs accepteren.