Until recently the only question with an AI tool was what it did with the transcript: you typed, it answered, and the exposure lived in the words you chose to type. That is already out of date.
The consumer privacy policy now in effect describes a different product. It defines your interactions to include "agentic sessions (where Claude performs multi-step tasks or takes actions on your behalf)" and "connected services." When the tool stops answering and starts acting - reading your files, sending messages, pulling from one app and writing to another - the confidentiality question changes shape. It is no longer "is this transcript retained." It is "what did my agent just send, to whom, and under whose terms."
What the terms actually say now
Read the section on third-party integrations and the mechanics are plain. When you connect a service - a Connector, a plugin, an external API - the policy says Claude "may send your Inputs, Outputs, and instructions to Third-Party Services to perform actions on your behalf," and that "the Third-Party Service receives this data directly and processes it according to its own privacy policy." It also says Claude "may retrieve content and data from Third-Party Services," and that this retrieved data "becomes part of your Inputs."
Sit with both halves. Data sent out lands with a third party and is governed by that third party's terms, not the ones you just read. Data pulled in becomes an Input. On the consumer products, those Inputs may be used for model improvement when that setting is enabled, are retained under the consumer schedule, and remain subject to the consumer policy. The integration is a two-way pipe, and each direction carries a different terms regime.
And the policy is explicit about who owns the risk. Anthropic "does not control, and is not responsible for, the data practices of Third-Party Services." Before you connect one, it tells you to "ensure you have the authority to grant such access and that doing so complies with any applicable terms, policies, or confidentiality obligations."
Read that last line as a lawyer
"Confidentiality obligations" is not a generic phrase to you. It is the duty you owe your client. What the policy is doing is placing the authority-and-terms check on you: when you wire the tool into your other systems, you are the one expected to confirm the access is authorized and compliant. That is a contractual allocation. The professional duty is independent of it and would bind you whether or not the policy said a word - the duty of competence to understand where client data goes, and the duty to make reasonable efforts to protect it (Model Rules 1.1 and 1.6; 37 C.F.R. 11.101 and 11.106 before the USPTO).
Here is the concrete version. You ask the agent to pull the unfiled specification and drawings from a connected document store and send them to your paralegal, through a connected messaging app, so she can update the page count on the filing paperwork. A clerical errand. But under the policy, the retrieved spec and drawings become Inputs, and what goes out to the paralegal lands in the messaging service and is processed under that service's terms, not the ones you just read. You did not paste an unfiled application into a chatbot - you would never do that. You asked an agent to move a document you already had, for a mundane reason, and it did. The exposure did not come from a transcript. It came from the access you granted and the path the task took - and what traveled that path was an unfiled patent disclosure, exactly the material that cannot leak.
What does not change, and what does
What does not change: this is the consumer policy. If your firm is on a business tier, these specific consumer terms are not your terms - a business agreement governs, and you should know which integrations that agreement actually covers before you trust one. The agentic capability does not erase that distinction; it extends it. A consumer-tier agent moves data under consumer-tier rules. A business-tier agent is governed by the commercial agreement.
What does change: the unit of confidentiality risk. For a chat, the risk lives in the text you choose to type. For an agent, the risk lives in the access you choose to grant - and access is broader, quieter, and more persistent than a paste. A connection you grant once and forget stays authorized to reach your data long after the task is done.
What to actually do
Before you let any AI tool act rather than answer, three questions.
What access am I granting, and to what? Not what am I typing - what systems can this agent now reach on my behalf, and for how long.
Where does the data go when it acts? Each connected service receives data under its own privacy policy. Until you know which service receives the data and the terms governing it, you have not assessed the disclosure. The professional duty remains yours even when the data path runs through a vendor.
Is this access scoped to the matter, or standing? Persistent integrations are convenient and easy to forget. For sensitive work, grant narrowly, and disconnect when the task is done.
The tool getting more capable is not the risk. The risk is that "let it handle it" feels like delegation when it is actually disclosure - to systems you did not vet, under terms you did not read, on a duty that stays yours.
The risk moved from the prompt to the access. The duty did not move at all. You can delegate the task. You cannot delegate the duty - it stays where it has always been, with your name on the filing.
Anthropic's privacy policy language cited here was verified against the live policy on July 19, 2026; an archived copy is on file.
I write more on using AI in legal practice without surrendering judgment, privilege, or the duty of competence, at The Agentic Lawyer. www.theagenticlawyer.com
Educational only, not legal advice, and no attorney-client relationship is created. Views are my own. Attorney advertising in some jurisdictions.