Inteligencia artificial y secreto profesional: ¿puede el uso de la IA romper la confidencialidad?
Artificial intelligence and professional secrecy: can the use of AI break confidentiality?
El uso de herramientas de inteligencia artificial en la práctica legal se ha expandido rápidamente. Abogados y estudios jurídicos utilizan dichos sistemas para redactar documentos, realizar contratos o desarrollar investigaciones. Sin embargo, esta adopción tecnológica plantea interrogantes relevantes en materia de confidencialidad profesional. Frente a este escenario surge una pregunta relevante para sistemas jurídicos como el argentino: ¿puede la adopción de la IA poner en riesgo el secreto profesional?
The use of artificial intelligence tools in legal practice has expanded rapidly. Lawyers and law firms use these systems to draft documents, create contracts, or conduct research. However, this technological adoption raises relevant questions regarding professional confidentiality. Against this backdrop, a relevant question arises for legal systems such as Argentina's: can the adoption of AI put professional secrecy at risk?
La inteligencia artificial se instaló en el mundo profesional antes de que entendieran realmente sus limitaciones, riesgos e implicancias en materia de seguridad. En el 2025 una de las firmas profesionales más grandes del mundo se vió afectada por esta falta de certeza en el origen de la información suministrada por uno de estos sistemas: Deloitte utilizó inteligencia artificial para preparar informes destinados a organismos gubernamentales en Australia y Canadá, los cuales incluyeron citas académicas falsas y referencias inexistentes.. En el campo legal, uno de los estudios jurídicos más prestigiosos de Nueva York, Sullivan & Cromwell, tuvo que pedir disculpas a un juez federal por presentar un escrito contaminado de alucinaciones generadas por una IA.
Una tecnología que no sabe cuando se equivoca
La tecnología puede fallar, ya que la AI procesa datos e identifica patrones, el verdadero problema es cuando los profesionales utilizan la tecnología sin los recaudos y controles necesarios.
Entender que la AI alucina ayuda a dimensionar ese riesgo. Según el MIT Sloan, los modelos de lenguaje funcionan como herramientas de autocompletado avanzadas, su objetivo es generar contenido plausible, no verificar si ese contenido es verdadero, lo cual significa que cualquier precisión en sus respuestas es en parte circunstancial. Lo que la IA produce suena coherente y correcto porque estadísticamente es probable, no porque sea verdadero. Un estudio de investigadores de OpenAI (empresa fundadora de ChatGPT) publicado en el 2025 fue más lejos: demostró matemáticamente que las alucinaciones son inevitables bajo las arquitecturas actuales de los modelos de lenguaje. La causa no es un defecto técnico corregible, sino una consecuencia estructural de cómo estos sistemas aprenden. Incluso con datos de entrenamiento perfectos, la forma en que los modelos generan texto garantiza que seguirán produciendo errores. A esto se suma otro problema que señala la Harvard Kennedy School Misinformation Review: los controles humanos posteriores también fallan, porque filtrar alucinaciones sutiles es difícil , costoso y dependiente del contexto. Y quizás lo más inquietante, una investigación del MIT encontró que los modelos usan lenguaje más seguro y afirmativo cuando están equivocados.
Cuando el error tiene consecuencias jurídicas
En el mundo jurídico, ese descuido tiene consecuencias graves que van más allá de errores técnicos, como fue demostrado recientemente en Estados Unidos. En United States v. Heppner, el juez federal Jed Rakoff resolvió que los documentos generados con la plataforma de IA llamada “Claude” el modelo de IA de Anthropic, no estaban protegidos por el principio de privilegio abogado-cliente.
Bradley Heppner estaba siendo investigado penalmente por fraude y declaraciones falsas. Cuando vio venir la acusación, decidió hacer algo muy habitual en esta nueva era de la IA: hablar con Claude para organizar ideas, preparar posibles argumentos de defensa y pensar su estrategia legal. Luego, compartió esos documentos generados con IA con sus abogados, pensando que eso estaba protegido por el conocido “attorney-client privilege” y que los documentos formaban parte de su defensa legal. Cuando el FBI allanó su domicilio secuestró esos archivos, la defensa intentó invocar el privilegio y el tribunal no lo admitió.
El juez Rakoff del Southern District of New York consideró que Claude no es abogado, no tiene matrícula y que, por ende, hablar con Claude no equivale a hablar con un profesional obligado por dicha figura legal. Por lo tanto, los intercambios con la IA no quedaron protegidos (¿de qué?). Rakoff además sostuvo que no había confidencialidad suficiente, puesto que Heppner no estaba hablando directamente con su representante, sino que estaba subiendo información a una plataforma de IA propiedad un tercero (Anthropic) de acceso público. Asimismo, se tuvieron en cuenta las políticas de privacidad de Claude, las cuales admitían la posibilidad de que ciertos datos fueran recolectados, usados o revelados bajo determinadas circunstancias. Finalmente, el juez también consideró que el imputado no actuó por indicación de su abogado, sino por iniciativa propia.
¿Qué pasaría si este caso ocurriera en Argentina?
No existe una respuesta inequívoca. Esto se debe a la falta de normativa, regulación y jurisprudencia. Sin embargo, podríamos presumir que los riesgos son similares. En nuestro país el secreto profesional no es solo un privilegio probatorio, es un deber legal establecido en el artículo 156 del Código Penal y en la Ley 23.187 de ejercicio de la abogacía. Asimismo, tiene una justificación constitucional ya que se vincula al derecho de la defensa en juicio y la inviolabilidad de los papeles privados. Sin embargo, esa protección opera dentro del vínculo abogado-cliente. Cuando alguien le consulta sus problemas legales a una aplicación abierta, esa conversación no integraría, acorde al criterio de Rakoff, el ámbito protegido.
El fallo citado deja abierta una distinción relevante para la práctica futura: no toda IA genera el mismo riesgo. Las plataformas empresariales que garantizan contractualmente la confidencialidad y prohíben el uso de los datos para entrenamiento podrían recibir un tratamiento diferente. En ese escenario, y con dirección expresa del abogado, el uso de IA podría encuadrar como un agente letrado. Argentina no tiene jurisprudencia consolidada al respecto, pero el debate relacionado a esta problemática ya llegó a nuestros tribunales.
La IA no es el problema en sí. El verdadero desafío radica en la limitada regulación y normativa existente y sobre todo en su utilización adecuadamente sus consecuencias jurídicas. Para un cliente, conversar con un chatbot puede ser tan riesgoso como contarle el caso a un desconocido. Para un abogado, delegar su trabajo en ella sin supervisarla es incompatible con los deberes de competencia y confidencialidad que exige la profesión. El secreto profesional no es negociable, ni siquiera frente a la tecnología.
Artificial intelligence settled into the professional world before its limitations, risks, and security implications were truly understood. In 2025, one of the world's largest professional firms was affected by this lack of certainty regarding the origin of the information provided by one of these systems: Deloitte used artificial intelligence to prepare reports for government agencies in Australia and Canada, which included fake academic citations and nonexistent references. In the legal field, one of New York's most prestigious law firms, Sullivan & Cromwell, had to apologize to a federal judge for submitting a brief contaminated with AI-generated hallucinations.
A technology that does not know when it is wrong
Technology can fail, as AI processes data and identifies patterns; the real problem is when professionals use technology without the necessary precautions and controls.
Understanding that AI hallucinates helps to assess this risk. According to MIT Sloan, language models function as advanced auto-complete tools; their goal is to generate plausible content, not to verify if that content is true, which means that any accuracy in their responses is partly circumstantial. What AI produces sounds coherent and correct because it is statistically probable, not because it is true. A study by researchers from OpenAI (the founding company of ChatGPT) published in 2025 went further: it mathematically demonstrated that hallucinations are inevitable under the current architectures of language models. The cause is not a correctable technical defect, but a structural consequence of how these systems learn. Even with perfect training data, the way models generate text guarantees that they will continue to produce errors. Added to this is another problem pointed out by the Harvard Kennedy School Misinformation Review: subsequent human controls also fail, because filtering subtle hallucinations is difficult, costly, and context-dependent. And perhaps most disturbingly, an MIT study found that models use more confident and affirmative language when they are wrong.
When the error has legal consequences
In the legal world, that carelessness has serious consequences that go beyond technical errors, as was recently demonstrated in the United States. In United States v. Heppner, federal judge Jed Rakoff ruled that documents generated with the AI platform called "Claude," Anthropic's AI model, were not protected by the attorney-client privilege principle.
Bradley Heppner was under criminal investigation for fraud and false statements. When he saw the indictment coming, he decided to do something very common in this new era of AI: talk to Claude to organize ideas, prepare possible defense arguments, and think about his legal strategy. He then shared those AI-generated documents with his lawyers, thinking that this was protected by the well-known "attorney-client privilege" and that the documents were part of his legal defense. When the FBI raided his home and seized those files, the defense tried to invoke the privilege, and the court dismissed it.
Judge Rakoff of the Southern District of New York considered that Claude is not a lawyer, is not licensed, and that, therefore, talking to Claude is not equivalent to talking to a professional bound by that legal concept. Therefore, the exchanges with the AI were not protected (from what?). Rakoff also held that there was insufficient confidentiality, since Heppner was not speaking directly with his representative, but was uploading information to an AI platform owned by a third party (Anthropic) with public access. Likewise, Claude's privacy policies were taken into account, which admitted the possibility that certain data could be collected, used, or disclosed under certain circumstances. Finally, the judge also considered that the defendant did not act under the direction of his lawyer, but on his own initiative.
What would happen if this case occurred in Argentina?
There is no unequivocal answer. This is due to the lack of rules, regulation, and jurisprudence. However, we could presume that the risks are similar. In our country, professional secrecy is not just an evidentiary privilege; it is a legal duty established in Article 156 of the Criminal Code and in Law 23.187 on the practice of law. Likewise, it has a constitutional justification since it is linked to the right to defense in court and the inviolability of private papers. However, that protection operates within the attorney-client relationship. When someone consults an open application about their legal problems, that conversation would not, according to Rakoff's criteria, fall within the protected sphere.
The cited ruling leaves open a relevant distinction for future practice: not all AI generates the same risk. Enterprise platforms that contractually guarantee confidentiality and prohibit the use of data for training could receive different treatment. In that scenario, and with the express direction of the lawyer, the use of AI could qualify as a legal agent. Argentina does not have consolidated jurisprudence in this regard, but the debate related to this problem has already reached our courts.
AI is not the problem in itself. The real challenge lies in the limited existing regulation and rules, and above all, in properly handling its legal consequences. For a client, talking to a chatbot can be as risky as telling a stranger about the case. For a lawyer, delegating their work to it without supervision is incompatible with the duties of competence and confidentiality required by the profession. Professional secrecy is not negotiable, not even in the face of technology.