← Back to Generative AI News
AI News Analysis

CCBE Technical Guide on AI for Lawyers: Items to Check on Models, Data and Confidentiality

A practical summary of the CCBE technical guide on AI for lawyers, covering deployment models, models, data management, confidentiality and the items to check with vendors.

News date
Published by LegalAgent
Updated
Reviewed by
Noriaki Asato
Status
Reviewed

Primary sources

The announcements and documents this analysis covers.

On March 27, 2026, the CCBE (Council of Bars and Law Societies of Europe), a federation of European bars and law societies, published the CCBE technical guide on the use of AI tools and models by lawyers. This 19-page guide is a practical resource that organizes the different levels of confidentiality and data control depending on how AI models are deployed (on-premises, colocation, bringing a model onto IaaS, and fully managed SaaS), the technical points to check with vendors when using fully managed services, and basic knowledge about the size and speed of models and the amount of text they can process. Because the CCBE is a federation of bars and not a judicial or administrative body, the guide itself has no legal binding force; it was published as a resource to support technical understanding for member bars and lawyers. This article explains the specific items to check listed in the guide, converted into a checklist that Japanese law firms and corporate legal departments can use as it is.

The Publisher and the Position of the Guide

The CCBE is an international non-profit association (AISBL) under Belgian law whose full members are the bars of the 27 EU member states, the 3 EEA member states (Norway, Liechtenstein and Iceland) and Switzerland, with the bars of the United Kingdom as an associate member and the bars of other European countries as associate members or observers. It represents approximately one million European lawyers and mainly engages in lobbying EU institutions and developing practice guidance, but it has no power to legally bind its member bars or individual lawyers.

The guide is not a stand-alone document; it is positioned as one of the AI-related practice resources that the CCBE has published in sequence. The text of the guide expressly states that it is intended to be read together with the CCBE guidelines on the use of cloud computing by Bars and lawyers published on February 27, 2025, and the CCBE guide on the use of generative AI by lawyers published on October 2, 2025. While the earlier generative AI guide dealt with the definition, benefits and risks of generative AI and professional ethical obligations, this technical guide is not a recommendation of particular products or an operating manual, but focuses on technical aspects: the difference between AI models and AI systems, and the architecture of each deployment model. The guide cites as its basis the principle of professional competence in the CCBE Charter of core principles, under which lawyers should understand the basic workings of the technology they use, and the obligation to ensure AI literacy under Article 4 of the EU AI Act; the latter, however, is a rule applying to entities that provide or use AI systems within the EU and does not automatically apply to Japanese companies.

Levels of Confidentiality and Data Control That Differ by Deployment Model

The guide organizes the ways AI models can be used into four categories from the perspectives of cost, required technical expertise and who controls the data. The on-premises (self-hosted) model, in which the model runs on equipment owned by the firm, sends no data outside at all, and offers the highest level of control. In the model where equipment is placed in a colocation facility or the firm's own dedicated data center, ownership and control of the equipment remain with the firm, but the reliability of the facility provider and the risk of physical intrusion must be assessed separately. In the model where the firm brings its own model onto IaaS (cloud virtual machines and the like), the firm can choose the region where the data center is located and manage its own encryption keys, but its ability to audit external engineers is limited. In contrast, with fully managed SaaS/API, where the vendor manages the model, infrastructure and updates entirely, adoption is easiest, but data is sent outside the user's control, and the guide rates the level of control as "Low."

Which model a law firm chooses for highly confidential matters is a question of trade-off between cost and control, and when fully managed SaaS is used, the contractual checks described in the next section become particularly important.

Items to Check with the Vendor When Using Fully Managed SaaS

The guide states that it is essential for lawyers using fully managed SaaS/API to understand the terms of their contract with the vendor and their practical meaning, and lists specific questions to check. Organized as a checklist that Japanese law firms and corporate legal departments can use from tomorrow, they are as follows.

  • To what extent the contract specifies how customer data is processed, and whether a data processing agreement (DPA) is available where the vendor acts as a processor.
  • Whether input prompts and responses are used for additional training of the model, and if so, whether there is an opt-out option.
  • Under what conditions the vendor's employees can access customer data.
  • Whether there is a contractual commitment to notify the user before or immediately after disclosure when responding to disclosure requests from law enforcement or other third parties.
  • Whether data is retained on the vendor's side for backup or other purposes after the user deletes it, and if so, for how long.
  • Whether the contract provides for how matters are handled if the vendor suffers a cyberattack and becomes unable to perform its contractual obligations.
  • Where the data centers are physically located and what the governing law is, and whether multiple jurisdictions may conflict.
  • Where the model is additionally trained on customer data, how likely it is that part of the input will be reproduced for another user under the same contract.
  • What restrictions the terms of use (Acceptable Use Policy) impose on use in criminal cases or human rights matters.

The guide also explains how prompts are processed. Input is tokenized and then used for the model's inference; that processing is technically transient, and the input is not automatically stored in a database in searchable form or incorporated directly into the model's parameters. However, whether input is used for training depends not on the model's architecture but on the vendor's contractual terms, technical settings and governance policies; the guide states that while enterprise contracts often contractually exclude training use, consumer services may reserve the right to use input for service improvement unless the user opts out. In addition, the guide points out, as matters to check in contract review and vendor selection, that users often cannot know at which point encryption in transit is decrypted, and that initial commitments may not be maintained as a result of the vendor's acquisition or bankruptcy or unilateral changes to its terms. When organizing contract clauses for vendor review, it is useful to operate them together with the internal policy items covered in How to Create a Generative AI Use Policy.

Technical Points to Check Regarding Model Performance and Size

For lawyers considering running models in a local environment, the guide also explains technical metrics relevant to model selection. Output speed is expressed in tokens per second (tps); for interactive use, speeds below 5 tokens per second are impractical, while speeds above 20 tokens per second exceed the reading speed of an average lawyer. The length of input and output a model can handle at once is called the "context length," and because the standard length for many models is only around 4,096 tokens, the guide states that using a model to search all of a country's statutes and case law at once is not realistic, and that other techniques such as retrieval-augmented generation (RAG) need to be combined.

The guide also gives concrete indications of deployment costs. As reference prices as of September 2025, running a small model on an existing PC involves almost no additional cost, while a dedicated machine that runs a model in the 20–40B parameter range at a practical speed costs about EUR 2,000, and running larger open models such as GPT-OSS-120B requires a GPU costing about EUR 8,000; securing performance comparable to cutting-edge commercial models in one's own environment would require an investment on the order of tens of thousands of euros. When a law firm considers moving to local operation for confidentiality reasons, the practical starting point is to evaluate cost-effectiveness in light of the fact that the required model size and hardware differ by intended use, such as drafting and revising contracts, extracting contract clauses, and searching lengthy evidentiary materials.

Relationship with Japanese Attorneys' Duty of Confidentiality

The guide takes as its starting point the principles of professional ethics and professional competence established by the bars of the EU and European countries, and is not a rule that applies directly to Japanese attorneys. For Japanese attorneys, Article 23 of the Attorney Act (Act No. 205 of 1949) (Japanese) provides that "an attorney or a former attorney has the right and bears the duty to maintain the confidentiality of secrets learned in the course of their duties," and the Basic Rules on the Duties of Practicing Attorneys of the Japan Federation of Bar Associations also contain rules on confidentiality. These differ from the EU professional ethics principles on which the CCBE relies and from the AI literacy obligation under Article 4 of the EU AI Act in both their legal basis and the persons to whom the rules are addressed.

However, the technical points to check with vendors when using fully managed SaaS, namely whether data is used for training, the conditions for disclosure to third parties, and the location of data centers, are themselves practical check items common to all jurisdictions, and I think Japanese law firms and corporate legal departments can apply them to their own AI vendor selection and contract review. The perspective of organizing the division of roles between AI tools and attorneys based on an understanding of the technical mechanisms also overlaps with the issues covered in What Is an AI Lawyer? How to Divide Work Between Attorneys and AI in Corporate Legal Practice in the Generative AI Era.

Developments to Watch

At the end of the guide, the CCBE states that agentic AI, which autonomously executes tasks through multiple steps, is not yet mature enough for the CCBE to assess its impact on legal practice and professional obligations, and indicates its intention to address it in future revisions. As of the date of writing, the following points remain unsettled or awaiting future publication and require ongoing monitoring.

  • The timing of publication of a revised version of the guide by the CCBE and of additional content on the treatment of agentic AI
  • Confirming that consistency is maintained with the generative AI guide published in October 2025 and the cloud computing guidelines published in February 2025
  • Rechecking whether the contract terms with the AI vendors the company uses (whether training use is permitted, data center location, disclosure notification obligations and the like) have changed upon contract renewal

Because the practice of designing permissions for agentic AI and auditing logs is also related to the issues explained in Checkpoints for Log Auditing and Allocation of Responsibility for AI Agents, I think it is advisable to check these together with the CCBE's future assessment.

Related articles

Articles connected to this topic.

Insight / 2026.06.26 What Is an AI Lawyer? How to Divide Work Between Attorneys and AI in Corporate Legal Practice in the Age of Generative AI Insight / 2026.05.04 Codex and Claude Code in Legal Work: Getting Started with Word-Based Practice Insight / 2026.06.13 Designing Log Audits and the Allocation of Responsibility for AI Agents Insight / 2026.06.13 How to Create a Generative AI Use Policy: Checkpoints for Internal Rules, Information Management and Allocation of Responsibility

Services connected to this topic

Generative AI Legal Consulting Support for AI terms of use, personal information, copyright, AI governance and internal AI use rules. Generative AI Support for Legal Departments Support for using generative AI in line with your legal team's workflow, usage rules and knowledge management.
More generative AI news