How Public AI Tools Waive Attorney-Client Privilege
Entering confidential client information into a public AI model can waive attorney-client privilege, because the data leaves the circle of confidentiality and enters a third party that retains, processes, and may disclose it. Courts have begun to treat consumer AI transcripts as unprotected.
How privilege is waived the moment data leaves the circle
Attorney-client privilege protects confidential communications made for legal advice. It survives only inside a closed circle of confidentiality. Voluntary disclosure to a third party outside that circle waives it, and a public AI vendor is a third party.
Attorney-client privilege is one of the oldest protections in common law, but it is also one of the most fragile. It shields confidential communications between a client and their attorney made for the purpose of obtaining legal advice. The protection depends entirely on confidentiality being preserved. The instant a privileged communication is voluntarily shared with a third party who sits outside the circle of confidence, the privilege is generally waived, and courts treat that waiver as difficult to undo.
A public or consumer AI platform is a third party. When a lawyer or client pastes case facts, draft strategy, or client documents into a general purpose model, that content is transmitted to and processed by the company operating the service. That company is not the client, not co-counsel, and not an agent retained under the direction of counsel. Under the plain logic of waiver doctrine, disclosing confidential material to it can break the reasonable expectation of confidentiality that privilege requires.
Typing confidential case facts into a public AI tool is treated much like discussing legal strategy out loud in a crowded public space. The information has left the protected circle, and no later regret restores the confidentiality that privilege was built to protect.
Two conditions have to hold at the moment of the communication for privilege to attach at all. First, there must be a genuine attorney-client relationship. Second, there must be a reasonable expectation that the communication stays confidential. Public AI use can fail both tests at once, which is why the exposure is not a hypothetical edge case but a structural problem with the tools themselves.
What recent courts have actually held
In 2026 federal courts began ruling on AI transcripts directly. One court held that documents a party created with a consumer AI tool were not privileged and not work product. Another preserved work-product protection where AI was used privately as a tool. The two turn on different standards.
For years the risk was argued in the abstract. That changed as courts started confronting AI transcripts in discovery. The clearest cautionary ruling treated documents that a party generated using a consumer AI assistant as falling outside both attorney-client privilege and the work-product doctrine, and the reasoning is worth understanding because it maps directly onto how these tools work.
- No attorney-client relationship. A general purpose AI model is not a licensed attorney and owes no fiduciary duty. A person confiding in it is not confiding in counsel, so the foundational relationship privilege protects never exists.
- No confidentiality. The terms of service for consumer AI tools commonly permit the provider to retain inputs, use them to train or improve models, and disclose them to third parties or the government in defined circumstances. That defeats the reasonable expectation of confidentiality.
- No legal purpose the tool will stand behind. Consumer AI products routinely disclaim that they provide legal advice, which undercuts the argument that the exchange was a communication made to obtain legal advice.
A separate 2026 decision cut the other way on a narrower question. There, a self-represented litigant had used an AI tool privately to help prepare materials, and the court declined to find that this use waived work-product protection. The key distinction is the standard. Work-product protection is waived when material is disclosed to an adversary or in a way that substantially increases the chance an adversary sees it. Privilege is waived by disclosure to essentially any third party outside the circle. Using AI privately as a drafting tool did not hand anything to the opponent, so work product survived, even though the privilege analysis in the other case did not.
Privilege and work-product protection are different doctrines with different waiver triggers. Privilege demands strict, near-absolute confidentiality and breaks on disclosure to almost any outsider. Work product tolerates some sharing and breaks mainly on disclosure to an adversary. A single act of AI use can therefore forfeit privilege while leaving work product intact.
Why deleting the chat does not fix it
Turning off history or using a temporary chat does not guarantee the data is gone. Providers often retain inputs for a period for abuse monitoring, stored transcripts are discoverable by subpoena, and consumer-tier inputs may still be used to improve models.
A common misconception is that disabling chat history or using a temporary session removes the confidentiality problem. It generally does not. Many providers retain inputs for a defined window even when history is off, frequently cited around thirty days, in order to monitor for abuse and misuse. During that window the data exists on third-party systems and is subject to legal process.
Retention is only half the exposure. Consumer-tier products often reserve the right to use inputs to train or improve future models. Once confidential facts influence a model, they are not sitting in a file you can delete, they are diffused into a system you do not control. And there is no retroactive cure. Sharing an AI generated output with your attorney afterward does not convert it into a privileged document. Protection has to exist at the moment of the communication, not be applied in hindsight.
If material was not privileged when it was created, later handing it to counsel does not make it privileged. This is why the point of exposure is the moment of input, and why controls have to be in place before anyone types a single client fact.
The ethics rules that now govern AI use
ABA Formal Opinion 512, issued in July 2024, is the first formal ethics guidance on generative AI. It confirms that duties of competence, confidentiality, communication, supervision, and candor all apply, and that lawyers must assess disclosure risk and obtain informed consent before inputting client data.
In July 2024 the American Bar Association issued Formal Opinion 512, its first formal ethics guidance addressing generative AI. It does not create new rules so much as confirm that the existing Model Rules of Professional Conduct apply fully to AI use, and it is unusually concrete about what that means in practice.
| Duty | What the rule requires | What it means for AI use |
|---|---|---|
| Competence (1.1) | Understand the technology you use, including its limits | Lawyers must grasp that generative AI can fabricate, or hallucinate, facts and citations, and must verify every output |
| Confidentiality (1.6) | Protect information relating to the representation | Assess the risk of disclosure before inputting client data, and obtain informed client consent before using self-learning tools that may retain or train on it |
| Communication (1.4) | Keep the client reasonably informed | Material use of AI in the representation may need to be disclosed to and discussed with the client |
| Supervision (5.1 and 5.3) | Supervise lawyers and nonlawyer assistants | Firms must have policies and training so staff do not leak client data into public tools |
| Fees (1.5) | Charge reasonable fees | A lawyer generally cannot bill a client for the time spent learning how to use a general AI tool |
| Candor (3.1, 3.3, 8.4) | Be truthful to tribunals and avoid dishonesty | The lawyer is responsible for accuracy, and fabricated citations produced by AI are not excused |
The confidentiality guidance is the sharpest. The opinion makes clear that a lawyer must evaluate the specific tool and its data handling before entering any information relating to a representation, and that boilerplate language buried in an engagement letter is not sufficient informed consent for using self-learning tools that may train on client data. Consent has to be genuinely informed, which means the client has to understand what the tool does with the data.
What defensible AI deployment looks like
Privilege can be preserved when AI runs inside a closed environment the firm controls, under enforceable no-training and zero-retention terms, with counsel directing the use. The governing framework is the Kovel doctrine, which extends privilege to agents working under an attorney direction.
None of this means law firms cannot use AI. It means the deployment has to be built so the data never leaves the protected circle. The safe-harbor pattern that emerges from the case law, the ethics guidance, and vendor practice has a consistent shape.
- Use enterprise or closed AI environments, not consumer products, with contractual guarantees of no training on your data and zero or strictly limited data retention.
- Push those guarantees down to sub-processors. The model provider behind the tool must be bound by the same no-training and deletion obligations, not just the vendor you contract with.
- Keep the use counsel-directed. Framing AI as an agent operating under the direction of the legal team is what brings it inside the circle under the Kovel doctrine, the long-standing rule that extends privilege to accountants, experts, and other agents assisting an attorney.
- Document that materials were prepared in anticipation of litigation and under the direction of counsel, which strengthens work-product protection independent of privilege.
- Never input sensitive client information into any tool that lacks enforceable confidentiality terms, and train every person who touches client data on that line.
Under United States v. Kovel, privilege can extend to third parties who assist an attorney in delivering legal advice, such as an accountant translating financial detail for a lawyer. An AI system deployed as a controlled, counsel-directed tool inside the firm can be positioned within that same logic, provided confidentiality is genuinely preserved by contract and architecture.
The through line is control. Privilege is not waived by using software, it is waived by disclosing confidential material to a third party who is free to retain, train on, or reveal it. When the environment is closed, the terms are enforceable, and counsel directs the work, the confidential circle stays intact. When the tool is a public model with permissive terms, the circle is already broken the moment the client fact is typed. The safest posture is infrastructure the firm owns and controls outright, rather than confidential matters routed through a rented platform whose incentives and terms can change.
Frequently asked questions.
Does using any AI tool automatically waive attorney-client privilege?
No. The waiver risk comes from disclosing confidential client information to a third party outside the circle of confidentiality. A public consumer tool with permissive terms creates that risk. A closed, enterprise environment under enforceable no-training and no-retention terms, used under the direction of counsel, is designed to keep the information inside the protected circle.
If I turn off chat history, is the data safe?
Not reliably. Many providers still retain inputs for a period, often cited around thirty days, for abuse monitoring, and stored transcripts can be reached by subpoena. Disabling history reduces some exposure but does not restore the strict confidentiality privilege requires.
Can I make an AI output privileged by sending it to my lawyer afterward?
No. There is no retroactive privilege. Protection has to exist at the moment the communication is created. Sharing a non-privileged AI output with counsel later does not convert it into a privileged document.
What is the difference between privilege and work-product protection here?
Attorney-client privilege protects confidential legal-advice communications and is waived by disclosure to almost any third party. Work-product protection covers materials prepared in anticipation of litigation and is waived mainly by disclosure to an adversary. A single AI use can waive privilege while leaving work product intact, which is why recent rulings can look like they conflict when they are applying different standards.
What does ABA Formal Opinion 512 require before using AI on a client matter?
It requires the lawyer to understand the tool and its limits, to assess the risk that inputs will be disclosed or used for training before entering client information, and to obtain genuinely informed client consent before using self-learning tools. Boilerplate engagement-letter language is not enough.
How can a firm use AI without risking privilege?
Run it inside a closed environment the firm controls, bind the vendor and its model provider to no-training and zero-retention terms, keep the use directed by counsel so it fits the Kovel doctrine, and document that materials were prepared under counsel direction. The most defensible posture is infrastructure the firm owns outright rather than confidential matters routed through a public platform.
References and further reading.
- 01ABA, First ABA ethics guidance on generative AI tools (Formal Opinion 512)
- 02White & Case, Attorney-client privilege and work product in the age of generative AI
- 03Ogletree Deakins, The intersection of AI and attorney-client privilege
- 04Duane Morris, The perils of privilege waivers through AI
- 05Frantz Ward, Privilege considerations when using generative AI in legal practice
- 06UNC Law Library, ABA Formal Opinion 512 as the paradigm for generative AI in legal practice
- 07NIST AI 600-1, Generative AI Profile to the AI Risk Management Framework
This study is provided for general information and does not constitute legal advice. Consult qualified counsel about your specific circumstances.