AI for Immigration Lawyers: The Trust-First Approach
AI for immigration lawyers is a confidentiality problem before a productivity one. How to use AI without risking privilege or Model Rule 1.6.

It's late on a Thursday and your client has just told you something she has never told anyone. Not her husband. Not her sister. She told you, in her second language, because a removal hearing has a way of forcing words out. Now that disclosure lives in your notes, and tomorrow you have to turn it into a declaration that could decide whether she stays.
This is the moment where AI for immigration lawyers stops being a tooling question and becomes a trust question. Because the fastest way to draft that declaration is also, with most AI tools, the fastest way to break the confidence she just placed in you.
TL;DR
- AI for immigration lawyers is a confidentiality problem before it is a productivity one. The files are among the most sensitive any lawyer handles.
- A February 2026 federal ruling, United States v. Heppner, held that documents created with a consumer AI tool were not covered by attorney-client privilege.
- General AI tools can retain and train on what you type. A client's story pasted into one may enter a model shared with millions of strangers.
- An Individual AI is a model you own and train on your own work. It gives you the drafting speed without handing the file to a third party.
- Never type a client fact into any AI tool until the vendor has answered the Rule 1.6 questions in writing.
The confidence you're actually holding
Picture Elena. Boutique immigration practice, twelve years in, a caseload of asylum matters, hardship waivers, and family petitions. Her clients arrive frightened and leave having trusted her with the most dangerous facts of their lives: who threatened them, what happened at the border, which relative is undocumented.
ABA Model Rule 1.6 doesn't just ask Elena to keep those secrets. It asks her to make reasonable efforts to prevent unauthorized disclosure, and the commentary is explicit that the standard rises with the sensitivity of the information. Asylum narratives sit at the top of that scale. A leaked I-589 draft is not an embarrassment. It can be a removal order, or worse, a danger to family still in the home country.
Now watch what happens in thousands of firms every day. An attorney pastes a client statement into a public AI window, asks for a cleaner draft, and moves on. The words leave the screen, but they don't leave the world. Under most consumer plans they can be retained, reviewed by human evaluators, even folded into the next round of training. The transfer is quiet, disclosed somewhere in the terms of service, and it is exactly the kind of disclosure Rule 1.6 was written to prevent.
The ruling that changed the calculation
In February 2026, Judge Jed S. Rakoff in the Southern District of New York gave that quiet transfer a legal consequence. In United States v. Heppner, the court held that documents a defendant created using a consumer-grade AI tool were not protected by attorney-client privilege and were not work product. The logic was simple and cold: privilege attaches to confidential communications, and words shared with a third-party AI service are arguably no longer confidential.
Heppner was a criminal case. The principle does not care. If an asylum narrative passes through a public model whose operator can access or train on it, the claim that the polished version is privileged becomes fragile. ICE trial attorneys and opposing counsel read the same rulings you do. Discovery requests aimed at AI usage are not a hypothetical for next decade. They are a drafting risk for next year.
So the question in front of Elena is not whether to use AI. Her backlog answers that. The question is which kind.
A model that belongs to the lawyer, not the crowd
There are two shapes an AI can take. The familiar one is the general model: one giant system trained on the internet, used by millions of strangers at once, learning a little from everyone. Whatever you feed it makes someone else's product better.
An Individual AI runs the other direction. It is a private model trained on one attorney's own work, kept behind that attorney's account, never used to train anyone else's model, and never shared. You are not a data point inside it. You are the entire point of it.
This is what we build at Uare.ai, and for a practice like Elena's, three things follow.
First, it learns her practice, not the internet's idea of legal writing. Here's how that actually happens. Voice Capture is the free first step: she speaks, and her model begins. But the substance comes from what she gives it afterward. Her prior declarations. Her briefs and hardship letters. The way she frames a J-1 waiver. And the conversations she has with it, week after week, where it asks why she structured an argument a certain way and remembers the answer. Over time it stops knowing what she sounds like and starts knowing how she thinks.
Second, the data stays hers. Her model does not feed a shared system, does not train on anyone else, and treats every interaction as private by default. That is what Rule 1.6 looks like when it's built into software instead of bolted on.
Third, honestly, it will not lawyer for her. It won't spot the credibility problem in a declaration, weigh a risky filing strategy, or sit with a terrified client. It drafts in her voice and holds her reasoning. Judgment stays where it belongs.
What Elena's week looks like now
Strip away the category language and here is the actual Tuesday-to-Friday of it.
An intake consultation becomes a clean intake sheet, a case-strength read, and a missing-documents checklist, produced inside her own account instead of a shared window.
A first draft of an asylum declaration comes back sounding like Elena, because it learned from Elena's declarations, not from a template. The client's story never travels to a third-party model to get there.
A status update goes out to a client in Spanish, in Elena's own warm, plain register, without a translation service ever seeing the case file.
An I-485 packet gets checked against the way her firm has actually filed for a decade, and the inconsistencies get flagged before USCIS finds them.
And late on that Thursday, she talks through a complicated adjustment case out loud with a model that remembers every brief she has fed it and answers in her own prior reasoning. A sounding board that never leaks and never forgets.
The questions to ask before the first client fact
Whether you're evaluating Uare.ai, a legal-specific product, or a general model on an enterprise contract, the bar is the same. Get these answered in writing before a single client fact enters a prompt:
- Does the vendor retain prompts and outputs, for how long, and why?
- Is the content used to train the vendor's models or anyone else's?
- Who at the vendor can access content in the ordinary course of business?
- Is the service SOC 2 Type II or ISO 27001 audited?
- Where is the data stored, and does it comply with your state bar's cloud-computing guidance?
- Will the vendor sign a data-processing agreement naming your firm as the controller?
The ABA's Formal Opinion 512 makes the underlying duty plain: lawyers must understand the AI they use well enough to satisfy Rules 1.1, 1.6, and 5.3. "The vendor said it was fine" has never been competence.
Start with your own files, not your client's
Here's how I'd actually begin, and it involves no client data at all.
Upload some of your own material into an Individual AI. A brief you're proud of. A hardship letter that worked. Your notes on how you approach a credible-fear interview. Then ask for a draft and compare it to what a generic tool gave you. That before and after, the moment the output stops sounding like a law-school template and starts sounding like your firm, is the entire argument, and you can see it in an afternoon.
You run that experiment on your own terms the whole way: full control over your data, delete everything at any time, and none of it ever trains public models.
Your clients trust you with the facts of their lives. Authentic Intelligence is what it feels like to have an AI you can trust the same way.
FAQ
Can immigration lawyers use ChatGPT on client files?
Not on identifiable client facts under consumer plans. Consumer versions of general AI tools may retain and train on prompts, which likely breaches Model Rule 1.6 and puts privilege at risk after United States v. Heppner. Enterprise contracts with written zero-retention terms are a different analysis.
Is AI-assisted work still protected by attorney-client privilege?
It depends on where the words go. If the AI service can access, review, or train on the content, courts may treat the disclosure as breaking privilege. A private Individual AI keeps the model and the data inside the attorney's account, which is the shape privilege needs.
Does ABA Formal Opinion 512 ban AI in immigration practice?
No. It requires competent, confidential, supervised use under Rules 1.1, 1.6, and 5.3. You must understand the tool, protect client information, and review the output. That is a bar for the lawyer, not a ban on the technology.
What should a firm ask a vendor before using AI on real cases?
Prompt retention, training use, access controls, SOC 2 Type II or ISO 27001 status, data location, and a signed data-processing agreement naming the firm as controller. If the answers don't come in writing, the tool is not ready for a client matter.
By Andrew Lum, Head of Product at Uare.ai.