53 Exposed Images, Client File Risks for Law Firms
The 53-image report is a warning for law firms
A recent report found that unsecured OpenAI agents posted 53 user-uploaded images on the public internet without the lab’s knowledge. The number is small enough that some firms may dismiss it as a technical edge case. That would be a mistake.
For a law firm, one wrongly shared file can be enough to create a serious client-confidence issue. A photograph can contain evidence, medical information, a property location, a screenshot of private communications, a minor’s identity, or material covered by privilege. Swap the image for a discovery export, draft settlement terms, intake notes, or a witness statement and the exposure becomes much more consequential.
The concern isn’t only that an agent can read a file. Most lawyers already understand that file access needs controls. The concern is that an autonomous system may take the next step. It may publish, send, upload, classify, route, or trigger an action based on incomplete permissions and poorly understood settings.
That distinction matters.
An agent that summarises a contract inside a controlled workspace is one thing. An agent that can forward that contract, post an attachment, create a public link, or connect to an external service without a human checkpoint is another.
The report should prompt every managing partner and operations leader to ask a plain question: if one of our agents handled the wrong client file, where could it send it, who would know, and could we prove what happened?
For more background on the wider issue, read our breakdown of OpenAI’s agent breach and what it means for law firms. The practical response is not to abandon automation. It is to put boundaries around what an agent can see, what it can do, and when a person has to approve its next move.
Why legal files need stricter action controls
Law firms sit on information that is valuable precisely because it isn’t public. Client files often combine identity documents, financial records, family details, trade secrets, allegations, strategy, and communications that may be privileged. A single matter can touch several confidentiality obligations at once.
That is why a basic rule should apply to every firm using agents:
No autonomous publishing, sharing, or external action on client files until permissions, human approval, audit logs, and vendor data-use settings have been verified.
This applies to more than a public website. “Sharing” can include:
- Sending an email with an attachment or public link
- Uploading a document to a connected storage platform
- Posting material into a collaboration channel
- Creating a client-facing status update
- Copying content into a third-party research or drafting tool
- Sending data through an integration or webhook
- Adding client facts to an external calendar, CRM, or task system
- Routing a matter brief to someone outside the assigned team
The risk often appears at the handoff point. A firm may correctly configure its document system, then give an agent broad access to connected applications. The agent can pull an intake attachment, summarise it, and send a notification through another tool. Each individual step might appear reasonable. Combined, they can create an unapproved path out of the matter workspace.
This is also why generic vendor assurances are not enough. Your team needs to know the live settings for your account and your integrations. Does the vendor retain prompts or files? Are they used for model improvement? Can administrators see activity logs? Does a connected tool create publicly accessible links by default? Can users install their own connectors? Can an agent call a sharing function without a reviewer?
Those aren’t theoretical questions for a $1M to $25M firm. They’re operating questions.
The manual work agents should handle, and where they should stop
Most firms don’t begin automation with a grand plan. It starts with a recurring frustration.
A receptionist misses an after-hours call. An intake coordinator sees a web form three hours later. A partner spends Friday evening sorting through forwarded emails. A junior associate works through a 900-document production set, then bills only part of the time because the matter budget won’t carry the full effort.
The work is real, repetitive, and expensive. In firms of this size, we commonly see attorneys lose four to six hours each week to intake, document handling, follow-up, and matter administration that never reaches an invoice. Associate review time can run from $200 to $400 per hour, depending on market and role.
Agents can reduce that load. They should not become unsupervised operators of confidential information.
Take an Intake Voice Agent. It can answer calls after hours, during lunch, and on weekends. It can ask the caller structured questions, capture names and contact details, identify the practice area, run a defined conflict-check workflow, and book a consultation into the firm’s calendar.
That is useful because 30% to 40% of after-hours intake often fails to convert when there is no immediate response. But the agent doesn’t need permission to email a case summary to external recipients, upload documents to a public folder, or send a detailed client record to every partner in the firm.
A Matter Triage Agent can review inbound forms and emails, classify the likely matter type, score fit against the firm’s criteria, and route the inquiry to the right partner with a one-paragraph brief. Done properly, it gives the lawyer context before they open the message. It also reduces the queue that forms around an overloaded intake coordinator.
But it should work within a least-privilege boundary. It needs access to the inbox or form queue assigned to triage. It doesn’t need broad permission across every active matter, historic archive, finance system, or personal mailbox.
A Document Review Agent can make a tangible difference to discovery and contract review. It can perform a first pass across a controlled batch, identify clauses or categories defined by the review protocol, summarise positions, and produce an associate-grade memo for lawyer review. That can free experienced associates to focus on judgment, exceptions, negotiation, and strategy.
The boundary is clear. The agent may flag and summarise. It should not independently produce to opposing counsel, amend a filing, send a draft to a client, or export a folder into an uncontrolled system.
For a practical view of securing these workflows, see AI agent security for law firms.
Build approval gates into the workflow
The safest workflow isn’t one where every task requires a lawyer to click approve. That would simply recreate the bottleneck. It is one where approval is matched to the risk of the action.
Low-risk internal actions can be automated within narrow rules. A Matter Triage Agent can tag a message, assign an owner, and prepare a brief. An Intake Voice Agent can schedule a consultation once the conflict-screening process reaches the approved stage. A Document Review Agent can place its memo into the matter workspace with a visible status of “draft for review.”
Higher-risk actions should stop at a gate.
Examples include:
- Sending files outside the firm
- Creating share links to matter documents
- Moving information to a new vendor platform
- Publishing any material to a website or social channel
- Filing documents with a court or regulator
- Communicating legal advice or settlement positions to a client
- Deleting records or changing retention classifications
- Adding new users or changing access rights
A good approval gate gives the reviewer enough context to make a decision in under a minute. They should see the source file, the proposed action, destination, recipient, reason, and any sensitivity flags. They should have clear options to approve, reject, edit, or escalate.
If the agent proposes sending a client summary, the reviewer should not need to hunt through five platforms to understand what will leave the firm. That defeats the point.
The same principle applies to prompts and external content. Prompt injection can cause an agent to follow instructions hidden inside an email, document, or website. A malicious attachment might tell an agent to reveal system instructions, fetch unrelated files, or send a summary elsewhere. Read how prompt injection can leak client data in law firms before allowing an agent to act on untrusted content.
What a controlled legal workflow looks like
Here is a realistic example.
A prospective client calls at 8:15 pm regarding an employment dispute. The Intake Voice Agent answers, explains that it is collecting information for the firm, and captures the caller’s name, employer, location, issue type, urgency, and preferred appointment time.
The agent runs the firm’s approved preliminary conflict workflow against defined names. If there is a possible match, it doesn’t make a judgment. It marks the record for conflict review and tells the caller that the firm will confirm next steps.
If there is no obvious conflict and the matter meets basic intake criteria, the agent books a consultation using the approved calendar connection. It creates an internal record with the call transcript and a short summary. The file is stored in the designated matter-intake environment, not copied across every connected tool.
The Matter Triage Agent then reads the intake record. It identifies employment law, estimates fit against the firm’s target criteria, records why it reached that result, and sends the assigned partner a one-paragraph internal brief. The partner sees the source transcript and can correct the classification.
No client document is published. No external share link is created. No legal advice is provided. No one outside the authorised intake group receives the information.
Later, if the client uploads a termination letter, the Document Review Agent can extract dates, notice provisions, stated reasons, and key allegations. It can produce a draft issue list for the lawyer. If it identifies sensitive material or the file falls outside the authorised review workspace, it stops and asks for direction.
That is automation with control. The agent does the administrative and first-pass work. Lawyers retain judgment, external communications, and authority over client data.
Audit logs are not optional paperwork
When something goes wrong, firms need more than a vague assurance that the system is secure. They need a record.
At minimum, your agent environment should log:
- Which person or service account initiated the work
- Which agent processed the request
- The matter or workspace involved
- Documents and data sources accessed
- The actions proposed and executed
- Any connected systems involved
- Approval decisions, reviewer identity, and timestamps
- Errors, blocked actions, and policy exceptions
- Changes to permissions, integrations, and configurations
Logs help with incident response, but their first value is operational. They let you see if an agent is doing work outside its intended scope. They also show where staff are bypassing the designed workflow because it is too slow or unclear.
If a lawyer asks, “Who sent this document?” the answer shouldn’t be, “We think the workflow did.” It should be traceable.
Your firm also needs a named owner for each agent. Not an abstract technology committee. A person accountable for its scope, access, approval rules, vendor settings, and quarterly review. In smaller firms, this might be the managing partner working with an operations lead and external technology adviser. The title matters less than the accountability.
Check vendor data-use settings before files enter the system
Many firms focus on the agent interface and forget the underlying account settings. Before allowing client data into any agent workflow, verify what happens to prompts, uploads, transcripts, outputs, and logs.
Ask the vendor and your internal administrator:
- Is customer content retained, and for how long?
- Is it used to train or improve systems?
- Can retention be reduced or disabled?
- Which data regions and subprocessors apply?
- Who can access account activity and administrative logs?
- Can users connect external applications without central approval?
- Are public links, exports, or automated sharing enabled by default?
- How are accounts and access removed when staff leave?
- Can the firm retrieve records for a matter, audit, or incident review?
- What happens when an agent encounters a file it cannot safely process?
The answer may differ between trial accounts, individual subscriptions, and managed business environments. Do not assume the setting applied to one product applies to the next.
If you need to set up a firm-wide operating model, our guide to AI agent governance for law firms outlines the decisions that need to be made before agents scale across practice groups.
Start with an audit, not a tool purchase
The wrong response to reports like the 53-image exposure is panic. The other wrong response is to carry on with unreviewed experiments because the technology is useful.
The sensible response is to map the actual work, data paths, permissions, and decisions inside your firm. You may find that your highest-return use case is after-hours intake. Or it may be first-pass contract review, matter opening, or email triage. The answer depends on how work currently moves through your practice.
An Omni Audit takes 60 minutes and produces three practical outputs: the workflow priorities worth addressing, the likely financial impact, and a safe first implementation path. There is no deck designed to impress you. It is a working conversation about the bottlenecks, data controls, and approvals your firm needs.
If you want a clear view of where to start, Book a 60-min Omni Audit. You can also see Omni for law firms to understand how the review is structured for legal practices.
Use this checklist before changing your intake workflow
Client intake is often the best early automation project because the commercial cost of delay is visible. It is also where confidential information arrives before the firm has even decided to accept the matter.
Our AI Client Intake Checklist for Law Firms is a practical worksheet for reviewing call handling, conflict checks, follow-up rules, access permissions, and human approval points. You can download the checklist here and use it with your office manager, intake lead, or technology provider before you introduce a new workflow.
The goal is not to make every process automated. It is to identify the points where faster response and first-pass handling can reduce the typical $80K to $250K annual leakage band, without creating a confidentiality problem in the process.
Treat autonomy as a permission, not a default
The reported exposure is a useful reminder that agents don’t need bad intentions to create bad outcomes. A misplaced permission, unsecured connection, default sharing setting, or missing review step can be enough.
Law firms can gain real value from an Intake Voice Agent, Matter Triage Agent, and Document Review Agent. The gains come from reducing missed calls, shortening response times, and moving lawyers away from repetitive administration and into client work that requires legal judgment.
But agents should earn more authority over time. Start with read-only access where possible. Keep actions inside defined workspaces. Require approval for sharing, publishing, and external communications. Review logs. Verify vendor data-use settings. Reassess permissions when a workflow changes.
That is how a firm can move quickly without treating client confidentiality as an experiment.
For a structured review of your workflow, controls, and likely return, Book my Omni Audit. Or review the AI audit for law firms before you book.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideEDNA Learn
Start free on EDNA Learn
Free account, no card. Run the Claude Code and agent-building course and start earning MENTOR credits.
Start freeEDNA Learn
Start free on EDNA Learn
Free account, no card. Run the Claude Code and agent-building course and start earning MENTOR credits.
Start free