Industries / Legal · law firms, notaries, audit firms & legal departments

Professional secrecy is criminal law. Protect your firm when lawyers use AI.

Art. 321 CP makes the unauthorized disclosure of entrusted client secrets a criminal offense, for the lawyer, the notary, the auditor and every auxiliary person who sends the prompt. A prompt containing client data sent to an external LLM counts as a disclosure, unless technical controls prevent it.

DEADLINESNOW · Art. 321 CP · Art. 13 BGFA in forceSEP 2023 · revised DSG, personal liability up to CHF 250,000AUG 2026 · EU AI ACT HIGH-RISK (AI in the administration of justice)

The AI governance framework for law firms and legal departments

Five obligations. Here's our part, honestly.

We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.

Art. 321 CPCriminal professional secrecy for lawyers, notaries and auditors, including their auxiliaries and IT.✓ We solve · block/anonymize client data
Art. 13 BGFAAttorney-client privilege, unlimited in time and towards everyone, enforced by the cantonal bar supervisory authority.✓ We solve · DLP at the prompt layer
Swiss DSG / GDPRData minimization, records of processing, cross-border limits, personal liability up to CHF 250,000.✓ We solve · anonymization + RoPA
EU AI ActAI in the administration of justice is high-risk from Aug 2026, with logging, oversight and governance duties for providers and deployers.◐ We contribute · logging + oversight
Art. 730b COConfidentiality duty of the statutory auditor, for audit firms on top of Art. 321 CP.✓ We solve · DLP + anonymization

Typical scenarios in law firms and legal departments

The contract draft

A lawyer pastes a client contract into ChatGPT to check clauses. Parties, terms and the amount in dispute leave the firm in a single prompt, to a provider that knows no professional secrecy.

NativeAI Guard: parties and client data become [PERSON], [ORGANIZATION], [CONTRACT] before the prompt leaves the firm, the clause review still works.
The uploaded dossier

A paralegal uploads a statement of claim or a due-diligence dossier as a PDF to an LLM for summarization. The whole document is uploaded, with no client consent covering this processing.

NativeAI Guard: documents are inspected inside the upload, client data detected, the file blocked or anonymized before it is sent.
The research agent

An internal agent searches files, rulings and opposing submissions to prepare a brief. An opposing document with hidden instructions can redirect the agent, and its answer can expose client data from another matter.

NativeAI Guard: injected instructions are stripped before the agent sees them, and every answer is checked for client data before it comes back.

Policies, managed

The rulebook for law firms and legal departments is already written. You adapt it instead of inventing it.

A base rulebook is already written and active from day one: the rules from the Swiss DSG, GDPR and the EU AI Act, plus the requirements your industry is specifically subject to. It covers the standard cases without you writing a single line. Security and compliance practitioners review it, and we keep it current as the law changes. On top of it sit the rules that apply only to you: your own data structures, your internal requirements, your exceptions.

Legal packArt. 321 CP · privilegeArt. 13 BGFAClient data · partiesSwiss DSG · GDPREU AI Act, justice AIArt. 730b OR

During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.

Common questions

Frequently asked questions

Do you become an auxiliary person under Art. 321 CP, and what does that mean contractually?

Yes, as soon as client data passes through our servers for inspection, and we treat it that way. The secrecy duties that apply during processing must also apply to support and maintenance work. We align the data processing agreement and the non-disclosure agreement so that support staff sit inside the same scope of professional secrecy. If you want to avoid that path entirely, run NativeAI Guard on-premises: then no prompt and no log leaves the firm, not even to us.

Our clients require that files never leave the firm. What happens to the content during inspection?

It is processed transiently in volatile memory on our own servers in Switzerland and discarded immediately afterwards. Nothing is written to disk, nothing is used for model training. What remains is the audit entry: who sent what to which model, when, and what NativeAI Guard did about it. That is written into the data processing agreement, where you can check it, not only on this page.

We are a firm of forty lawyers, not a corporation. Is it worth it, and how do we start?

Yes. Smaller organizations get a flat rate instead of a per-user price, and the entry is the same as for a bank: a one-month passive pilot phase that we run end to end, with no change to your workflows. The result is a risk overview of data leaks, shadow AI and AI usage for the partners' meeting. From project start to live operation takes about two weeks, and your effort stays at admin access and a user list.

Protect client privilege when your lawyers use AI, with a pilot phase that we run for you.

A policy starter pack for law firms and legal departments, plus a risk overview of data leaks, shadow AI, AI usage and model costs for the partners' meeting. Client data is processed only transiently in volatile memory on our servers in Switzerland and never stored.