In 2026 the conversation about professional secrecy and AI has shifted from warnings to design. Two recent documents put that shift into sharp focus: the technical guide of the Council of Bars and Law Societies of Europe (CCBE) for lawyers, and the joint exploratory note by the CNIL and the Conseil de l'IA et du Numérique (CIANum) on agentic AI. Together they show that confidentiality in the AI context is no longer solely about how you handle case files, but about how you set up systems technically and organisationally.
What the CCBE guide asks of lawyers
The CCBE explicitly ties lawyers' use of AI to compliance with professional secrecy and other professional obligations. Lawyers may not enter personal, confidential or client-related data into generative AI interfaces without appropriate technical and organisational safeguards. They must, for each AI tool, analyse the data flows, contracts, storage, training and verification processes in order to demonstrate compatibility with professional secrecy.
An analysis by Deeplit summarises this as an architectural choice: a preference for local or secured environments under the firm's control, strict separation between confidential data and public AI interfaces, and verification processes in which AI output never enters the case file unchecked. Professional secrecy is presented here as a design requirement: anyone deploying AI must be able to demonstrate where client information does and does not end up, which contracts and technical measures underpin that choice, and how AI output enters the case file via human control.
Agentic AI and control over personal data
The CNIL/CIANum note introduces a GDPR-focused risk analysis for agentic AI. Complex data flows and persistent memory functions put users' control over their personal data under pressure. It can be difficult for data subjects to understand which agent has collected which data, where it is stored and to whom it has been passed on. For this reason, memory cloisonnement, sandboxing, per-task traceability and kill-switch-style emergency stop mechanisms are recommended to limit loss of control and breaches of confidentiality.
An interpretation by Univers Convergents translates the note into concrete design recommendations: a dedicated, limited and automatically expiring memory space for each agent, sandboxed environments, detailed traceability of which data has been used and which agents and services have intervened, and a risk-based classification of actions requiring explicit human validation, culminating in a kill-switch. In this way, high-risk operations involving personal data remain under the control of the user and the data controller.
The same logic in other high-trust domains
The issue is not limited to the legal world. A systematic review in BMC Medical Ethics of international guidelines for AI in healthcare shows that privacy, security, patient autonomy and confidentiality recur structurally. Health data is designated as particularly sensitive, and using AI for diagnostics or decision-making is only responsible when there are strong safeguards for data minimisation, secure infrastructure, transparency about data use and mechanisms through which healthcare professionals can understand and control decisions.
Lawyers, civil-law notaries and healthcare professionals thereby follow the same logic: professional secrecy and confidentiality are, in the AI context, anchored through a visible architecture of secure environments, limited and separated memory layers, traceable agent actions and human control points. This is not about policy statements alone, but about technical and organisational measures that are demonstrable.
Verification as a visible layer
Within that structure, a verification console such as IamVera.ai fits modestly but concretely. Vera does not replace professional secrecy and does not set the standards; it can, however, make visible how professional secrecy is safeguarded in each AI-supported step. Per high-trust workflow, such a layer supports insight into which AI tools and agents have been used, which data classes fall under professional secrecy, where that data technically does or does not flow to, which human controls and kill-switch mechanisms have been applied, and how log and evidence chains provide insight into the AI-supported work and offer support in assessing whether professional secrecy has been respected.
That architecture makes this plausible: pre-processing and anonymisation take place on EU infrastructure, the workflow is designed to send only anonymised content to the selected AI models, and when a privacy check fails, nothing is forwarded. In this way a verification layer can give more insight into how existing professional-secrecy standards are applied in AI use, while the professional final judgement always remains with the user. Professional secrecy in AI practice has thereby become above all a design question: not to be solved with cautious prompts, but through a confidentiality-safe, auditable architecture in which data flows, memory layers and control points are visible and verifiable.