
Lawyers often worry that advanced technology is the weak link in their security, but the real risk frequently isn’t the model itself. The recent exposure of thousands of shared ChatGPT conversations and thousands of Grok chats indexed by Google highlights a different problem. No model leaked anything, and nobody was hacked. The failure occurred because a simple checkbox, designed to make a chat public, was left on, and the links were left open. The AI worked exactly as it was supposed to; the sharing settings failed.
Old Habits in New Tools
This isn’t a problem unique to artificial intelligence. The same mechanism has been running in legal practices for years, often without lawyers noticing. In 2021, a lawyer likely sent a client a Dropbox link, a co-counsel a folder, or an expert a document. That link didn’t expire. Unless someone actively turned it off, every link created is still live, still pointing at whatever is in that folder now, and still openable by anyone who possesses it. That person might be an old email address, a forwarded message, or an inbox that was breached three years ago.
Checking every single link is tedious, but you do not need to check all of them. The most dangerous files are usually the ones sitting in closed matters. You should start there. Open the sharing settings for folders related to cases that are finished. Look for two things: links set so anyone with the link can open them, and people who still have access. Ten folders will usually tell you what you need to know. A link made to send one document might now be pointed at a folder holding forty files. The former assistant still has access because lawyers rarely remove people; they simply stop inviting them.
Related: Fund Payments Governed by Grammar Rules
Most of these exposures aren’t hacks. They are simply working exactly as designed. To fix it, you have to kill the links you don’t need. Turn “anyone with the link” settings into named people. Remove anyone who is no longer with the firm. If a matter is closed, the sharing on that folder should be closed too. It sounds like a one-time fix, but it becomes a habit. Closing a matter includes closing its sharing.
Checking the Rest of Your Tech
Secure file sharing for lawyers requires looking beyond cloud storage. The same question applies to every system you own. Check your email for forwarding rules you didn’t set up this year. Someone might have created one to a personal Gmail account and forgotten about it. Check your practice management system next. Does everyone have full access because setting up roles was tedious? You need to know who can open what.
Review your note-taker. What does it keep after the meeting—audio, transcript, or summary—and can you delete it? Answer that before your next client call, not after. Finally, look at anything that sends on its own. Review requests, marketing sequences, and alerts. Would you want that going to a criminal defense client? The Grok and ChatGPT stories got attention because they involved AI, but they were really about a sharing setting that did precisely what it was configured to do, for longer than anyone was paying attention. To understand how this specific AI application impacts legal operations, firms can examine how artificial intelligence assists in streamlining defense work.


