Who really controls the data sent to AI?
A public AI chat operates under its provider's rules, and those rules and security mechanisms can change.
In a law firm, descriptions of rape, murder, threats or violence may be ordinary case file content, so they should not be automatically copied into a public chat.
Bezpieczna Kancelaria keeps data in an isolated environment and controls what information an external model needs for a specific task.
A lawyer should not have to track changes in every AI provider's policies and algorithms - the system should handle that.
Artificial intelligence is extremely convenient. We open ChatGPT, drag a document into the window, type a question and, after a few seconds, get a summary, analysis or draft letter. That simplicity can be the biggest risk, because it is easy to forget that a conversation window in a public AI system is not a closed room in a law firm.
On 24 August 2026, Niebezpiecznik described the story of Darren Shida Zhou, who used ChatGPT while planning the kidnapping, rape and murder of his former partner. According to the case description, the conversation was flagged by OpenAI's safety mechanisms and the information was passed to the authorities.
ChatGPT is not a confessional.
What you enter into AI does not disappear when you press Enter
We have become used to treating chat like a conversation. We write a question, get an answer and close the window. Technically, however, the content must be sent to the provider's infrastructure and processed according to the rules of its service and the security mechanisms it uses.
OpenAI states that when the system detects users planning to harm other people, conversations may go through a dedicated human review process. If the team determines that there is an imminent threat of serious physical harm, the case may be referred to law enforcement.
Even Temporary Chat does not mean that the conversation technically ceases to exist the moment the window is closed. OpenAI currently states that, for safety reasons, a copy of such a conversation may be stored for up to 30 days. Files may be subject to their own retention rules, separate from the chat itself.
A lawyer should know exactly what environment they are sending information covered by professional secrecy to.
For an ordinary user, this is an extreme situation. For a law firm - case material
A public AI safety system may encounter words such as: murder, rape, kidnapping, weapon, threat, drugs, violence. For an average user, this may be exceptional content. For a lawyer handling criminal, family or domestic violence cases, it may be an ordinary part of the file.
- testimony of a rape victim
- crime scene inspection report in a murder case
- messages from a perpetrator threatening the injured party
- the victim's medical records
- photos of injuries and expert opinions
- the accused's explanations
- correspondence about violence against a child
It is precisely with hundreds or thousands of pages of case files that AI can give a lawyer the greatest advantage. So the question is not whether AI may be used, but where we send the documents and who decides what the external model actually needs to see.
Turning off training is not the same as data isolation
A statement that a provider does not use data to train models should not be equated with a statement that the data does not leave the environment controlled by the law firm. These are two different issues.
You can use a business solution, an API and the right privacy settings. But the fundamental question remains: what exactly was sent to the external system? If a lawyer uploaded 400 pages of case files only because they wanted to ask about one procedural deadline, the problem arose before the model even generated an answer.
We reverse that relationship
In Bezpieczna Kancelaria, we do not want a lawyer to analyze a provider's settings, data retention periods, privacy modes or the scope of documents they may upload before every question. That should not be the lawyer's job.
The law firm's data is kept in an isolated environment. The lawyer asks a question inside Bezpieczna Kancelaria, and the system controls whether an external model is needed to complete the task, which model may be used, what information it actually needs and what prompt will be sent to it.
We do not hand the law firm over to the model. We give the model only what it needs to complete a specific task.
We are the ones who compose the question to AI
A lawyer may ask: When is the deadline for filing the response? In the public way of working, this often means opening a chat, uploading a document or the entire case file, and only then asking the question.
In Bezpieczna Kancelaria, the question first goes to the law firm's environment. The system knows the case, finds the necessary information and prepares a prompt that - if an external model is needed - will be passed on. The external model does not need to receive the client's entire history just because the lawyer needs an answer to one specific question.
The user chooses the materials to upload and must know the provider's current settings and rules. Once the data is sent, its processing is also subject to the provider's procedures.
The lawyer works in an isolated environment, and the system controls whether an external model is needed, what information it may receive and what prompt will be sent to it.
What about a year from now?
Models, features, memory mechanisms, safety systems, data retention rules and terms of service are changing. On 19 August 2026, OpenAI announced Private Safety Processing for some customers using the API and Zero Data Retention - a mechanism intended to recognize risk patterns across related interactions while maintaining zero retention assumptions for eligible customers.
This is a good example of the pace of change. We do not know what will change in six months, how models will work in 2027 or what new obligations will be imposed on their providers. A lawyer should not be forced to track this.
A lawyer should not study OpenAI's algorithms
An attorney should know the law, know the case and represent the client. They should not also have to track successive versions of the retention policies of OpenAI, Anthropic, Google or the next model provider. They should not have to remember where to turn off history, which setting applies to training or whether the vendor has just changed its safety rules.
That is what the system should handle.
If we change AI provider tomorrow, the lawyer should still ask the question in the same place. If a better model appears next year, we should be able to use it without moving the entire law firm into its producer's environment. If one provider's rules change, we should be able to limit the information sent to it or stop using it.
The biggest risk may be a simple drag and drop
There does not need to be a cyberattack, breach or password theft. An ordinary daily action may be enough: dragging case files into a public chat window. From that moment, the way the information is processed also depends on the architecture, policies and procedures of the entity we sent it to.
Law firm materials may contain information about health, assets, family, sexuality, conflicts, crimes, litigation strategy and trade secrets. Sometimes they contain things the client has told no one except their lawyer.
The question should not be: Is ChatGPT safe? The right question is: Should we give a public chatbot all the information we have about our client?
An isolated environment is not a marketing add-on
You can build a system for a law firm and simply place in it a window that connects directly to a popular AI model. It would be faster, easier and cheaper. But it would not be Bezpieczna Kancelaria.
For us, artificial intelligence does not start with the question of which model is best. It starts with the question of how to make sure the model receives exactly as much information as it should - and not a single piece more.
We separate the law firm's knowledge from external models. The law firm keeps its data, while the system controls the flow of information, selects the scope needed for the task and prepares the query sent to the external model. When the technology changes, we can change the model without changing the core principle.
The law firm's data stays on the right side of the boundary.
ChatGPT is a great tool. But it is not a law firm
The story described by Niebezpiecznik is not a story about bad ChatGPT. It shows that the provider of a public AI system has its own security mechanisms, procedures, terms and obligations. The problem appears when a law firm starts treating someone else's infrastructure as if it were its own closed environment.
We want to use the best models available - OpenAI, Anthropic, Google and models we do not yet know today. But we want to use them on our terms, without automatically handing over the entire law firm to them and without making security depend on whether a lawyer has read the provider's latest terms.
The lawyer should ask the question. Bezpieczna Kancelaria should take care of what happens to the data next.
Legal professional secrecy should not depend on a setting ticked in a chat window or on terms that may look different tomorrow. It should result from the system architecture.
Sources
- Niebezpiecznik, He Planned to Kill His Ex-Girlfriend, but ChatGPT Reported It to the Police, 24.08.2026 - https://niebezpiecznik.pl/post/planowal-zabic-swoja-ex-dziewczyne-ale-chatgpt-poinformowal-o-tym-policje/
- OpenAI, Helping people when they need it most - https://openai.com/index/helping-people-when-they-need-it-most/
- OpenAI Help Center, Temporary Chat FAQ - https://help.openai.com/en/articles/8914046-temp
- OpenAI Help Center, Chat and File Retention Policies in ChatGPT - https://help.openai.com/en/articles/8983778
- OpenAI, Offering Zero Data Retention for frontier models, 19.08.2026 - https://openai.com/index/offering-zero-data-retention-for-frontier-models/

