Skip to content
Chapter 20/29

Privilege & Confidentiality with AI

Conversations with general-purpose AI are not privileged. They can be subpoenaed, retained, and produced in discovery. Know what you're giving away.

  • Reading time: 11 min

What this chapter covers

  1. What Privilege Requires
  2. Where Generic AI Breaks It
  3. What a Sound Stack Looks Like
  4. Practitioner Rule

TL;DR

Conversations with general-purpose AI products are not privileged. They can be subpoenaed, used as training data, retained, and produced in discovery. Every lawyer using ChatGPT or Claude for client matters needs to understand exactly what they are giving away.

1) What privilege actually requires

Attorney-client privilege protects confidential communications between a lawyer and a client made for the purpose of seeking legal advice. The communication has to stay confidential - the moment you involve a third party who isn't necessary to the legal services, privilege can be waived.

That third party can be a person. It can also be a tool that logs your inputs to a server you don't control.

2) Where general AI products break this

• Inputs are sent to vendor servers, often in unrelated jurisdictions.

• Logs are retained - sometimes indefinitely.

• Free tiers may use your data to train future models.

• Vendor employees can review flagged conversations.

• A subpoena to the vendor can produce your prompts.

3) What a legally-sound stack looks like

• Tenant isolation per firm - your prompts never train shared models.

• Data residency in your jurisdiction.

• Zero-retention or short-retention modes for sensitive work.

• Signed DPA addressing privilege explicitly.

• Audit trail you can produce for a court if needed.

Practitioner rule

Treat any AI conversation about a real client as if it were an email to a third party. If you wouldn't send the email, don't paste the prompt - unless you're using a stack designed to preserve privilege.