AI Lawyer and Confidentiality: Is Attorney-Client Privilege Protected?

Law firms are adopting generative tools faster than they are updating their confidentiality policies, and that gap raises one urgent question: does using an AI lawyer put attorney-client privilege at risk? The short answer is that privilege survives only when AI is used correctly — free, public tools like consumer ChatGPT can destroy it instantly and permanently.

This is no longer a theoretical concern. In 2026 a federal court ruled for the first time that documents drafted on a public AI tool are not protected by privilege at all. This article is written for practicing lawyers and for their clients who want to know what is actually at stake.

What Attorney-Client Privilege and Confidentiality Actually Protect

Lawyers and clients often use “privilege” and “confidentiality” interchangeably, but they are legally distinct protections with different scopes and different ways of being lost.

A confidential attorney-client conversation in a private office

Privilege vs. the ethical duty of confidentiality

Attorney-client privilege is a rule of evidence: it shields confidential communications between a client and a lawyer that are made for the purpose of seeking or giving legal advice, and it can be invoked to keep those communications out of court. According to Cornell Law School’s Legal Information Institute, the privilege belongs to the client, not the lawyer, and it can be waived — deliberately or accidentally — if the communication is shared outside the protected relationship. The ethical duty of confidentiality is broader. Codified in ABA Model Rule 1.6, it covers essentially all information relating to the representation of a client, regardless of its source, and it applies whether or not litigation is ever filed. A lawyer can breach the duty of confidentiality without ever losing privilege, and vice versa — the two rules overlap but do not mirror each other.

The work product doctrine

The work product doctrine is a separate protection that shields materials an attorney prepares in anticipation of litigation — legal strategy, mental impressions, draft arguments — even when those materials are not themselves privileged communications. Its foundation is the Supreme Court’s decision in Hickman v. Taylor, 329 U.S. 495 (1947), later codified in Federal Rule of Civil Procedure 26(b)(3). Unlike privilege, which protects the communication itself, work product protects the lawyer’s thinking process — how a case is being built, not merely what was said.

The Achilles’ heel: the third-party rule

Both privilege and work product share a critical vulnerability. Privilege exists only for as long as the underlying communication stays confidential. The moment an outside, unauthorized third party gains access to it, the privilege can be treated as waived — permanently, in most jurisdictions. This is the exact mechanism that makes AI dangerous for confidentiality: a public AI vendor sitting between a client and a lawyer is, legally, a third party.

How AI Can Break Confidentiality and Waive Privilege

Generative AI does not need to leak data through a hack to create a privilege problem. Simply typing confidential facts into the wrong tool can be enough.

A locked cabinet symbolizing protected confidential files

A public AI tool is an “unauthorized third party.” When a lawyer or a client enters confidential case details into a free, consumer-grade generative AI platform, the vendor operating that platform effectively becomes an unauthorized third party to the communication. Many public systems retain user input and may use it as training data for future model versions. That retention is a disclosure to an outside party, and a disclosure to an outside party is precisely what triggers a privilege waiver.

Even private, vendor-hosted models carry risk. A model does not have to be free or public to be dangerous. If a vendor-hosted deployment is configured to train on user input, a court can find that confidentiality was not adequately protected, because the content could theoretically surface for other customers of the same vendor or influence the underlying model. Similar exposure comes from adjacent technology: Windows Recall, a feature that periodically screenshots a user’s screen, can inadvertently capture privileged material displayed during a client call or document review.

Hallucinations raise a separate competence problem. Beyond confidentiality, generative AI is known to fabricate facts, case names, and citations — a failure mode commonly called hallucination. Bar authorities, including New York bar associations, have stressed that lawyers must independently verify anything an AI system produces before relying on it. This obligation connects directly to Model Rule 1.1, Comment 8, which requires lawyers to understand the benefits and risks of the technology they use, not just its convenience.

It is black-letter law that non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel.

Judge Jed S. Rakoff, United States v. Heppner, No. 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026)

United States v. Heppner: The First Court Ruling

For years, whether AI-assisted drafting could waive privilege was an open, mostly academic question. In February 2026, a federal district court answered it directly.

Confidential documents at risk near an open laptop

What happened

In United States v. Heppner, No. 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), Judge Jed S. Rakoff of the Southern District of New York confronted a question of first impression: does privilege attach to documents a defendant creates on his own, with the help of a public AI tool, before ever consulting a lawyer? Defendant Bradley Heppner had used Claude, the generative AI assistant built by Anthropic, to draft roughly 31 documents on his own, and only afterward shared them with his defense attorneys. The FBI seized the documents under a search warrant, and Heppner moved to have them treated as privileged.

What the court held

The court held that none of the 31 documents were protected by either attorney-client privilege or the work product doctrine. Judge Rakoff’s reasoning rested on three independent grounds, any one of which would have been sufficient on its own. First, two non-lawyer parties — the defendant and an AI system — cannot create privilege between themselves, because privilege requires a communication made to, or for the purpose of obtaining advice from, a licensed attorney; as the court put it, Claude “is not an attorney.” Second, there was no reasonable expectation of confidentiality when the documents were generated on a public AI platform, since Anthropic’s terms of service reserved the right to log the exchanges, use them for model training, and disclose them to third parties. Third, Heppner created the documents on his own initiative before ever consulting counsel, not for the purpose of obtaining legal advice and not at a lawyer’s direction — a defect that also doomed any work product claim. The court also considered, and rejected, an attempt to invoke the Kovel doctrine, from United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), which extends privilege to non-lawyer agents assisting an attorney — the AI tool here was never engaged at a lawyer’s direction, so it never became the lawyer’s agent, though the court left open that a supervised, counsel-directed use might qualify.

The limits of the ruling

Heppner is a single, non-binding district court decision, and as of this writing no appellate court has reviewed it. It is not a blanket prohibition on lawyers using AI. The court’s analysis was expressly limited to a public platform used without any express confidentiality covenant, and the opinion left open whether a supervised, enterprise AI tool acting under a lawyer’s direction could qualify as the lawyer’s agent. Two related cases illustrate the same fault line:

  • Tremblay v. OpenAI (N.D. Cal. Aug. 8, 2024) — unused draft prompts crafted by counsel were treated as protected opinion work product.
  • Warner v. Gilbarco (E.D. Mich. Feb. 10, 2026) — a federal magistrate judge refused to compel disclosure of a pro se litigant’s AI usage, reasoning that AI programs “are tools, not persons” and that merely uploading information to an AI platform does not, by itself, waive work product protection.

The Ethics Rules: ABA Formal Opinion 512 and Model Rule 1.6

Court rulings are not the only source of obligation here. The organized bar has already spoken directly on generative AI and client confidentiality.

A courtroom landmark ruling on AI and attorney-client privilege

The table below summarizes how the main sources of authority discussed in this article intersect with confidentiality and privilege.

SourceTypeCore requirement for AI use
ABA Model Rule 1.6Ethics ruleDo not disclose client information without informed consent
ABA Formal Opinion 512Ethics guidanceProtect confidentiality, obtain informed consent, bill honestly for AI-assisted time
Model Rule 1.1, Comment 8Ethics ruleUnderstand the benefits and risks of the technology used
United States v. HeppnerCourt rulingPublic AI use without confidentiality covenants can waive privilege
FRCP 26(b)(3)Procedural ruleDefines what counts as protected work product

What ABA Formal Opinion 512 requires

Issued on July 29, 2024, ABA Formal Opinion 512 is the American Bar Association’s first official guidance dedicated to generative AI, and it remains the leading ethics reference on the topic. The opinion requires lawyers who use generative AI on client matters to:

  • Protect client confidentiality when entering information into a generative AI tool.
  • Obtain informed consent before inputting information relating to a representation, where the use carries meaningful risk.
  • Maintain the competence needed to evaluate AI-generated output rather than accepting it uncritically.
  • Supervise subordinate lawyers and staff who use AI tools, consistent with Rules 5.1 and 5.3.
  • Bill clients honestly for time spent supervising AI, rather than charging as if the work were done entirely by an attorney.

The opinion draws on several Model Rules together: 1.1 (Competence), 1.6 (Confidentiality), 1.4 (Communication), 5.1 and 5.3 (supervisory duties, which the ABA has extended to AI tools), and 1.5 (billing reasonable fees for AI-assisted work).

Model Rule 1.6 prohibits a lawyer from revealing information relating to the representation of a client without the client’s informed consent, subject to narrow exceptions. Applied to AI, this means a lawyer must understand where client data goes once it is entered into a tool — whether it is retained, whether it trains the underlying model, whether it is accessible to the vendor’s staff — and obtain the client’s consent when that use carries meaningful risk. Comment 8 to Rule 1.1 reinforces the same point from the competence angle: a lawyer who does not understand these mechanics cannot make an informed judgment about whether a given AI tool is safe to use on a matter.

How Lawyers Can Use AI Without Breaking Confidentiality

None of this means lawyers must avoid AI. It means the choice of tool and the surrounding safeguards determine whether privilege survives.

Choose enterprise AI with zero data retention

The safest starting point is an enterprise or private AI deployment that runs in a closed environment behind a firewall, with zero data retention and no training on user input. Before adopting any such tool, firms should verify relevant compliance certifications, including:

  • SOC 2 Type II attestation covering the vendor’s security controls.
  • GDPR compliance, if any client data touches EU residents.
  • PIPEDA compliance, for matters involving Canadian clients.

Firms should also negotiate contracts that include express confidentiality covenants barring the vendor from using firm or client data for model training.

An attorney reviews an informed-consent and data-security document with a client

The table below compares the two ends of the spectrum firms typically choose between.

FactorFree/public AI toolEnterprise AI with zero retention
Data retentionOften retained, may train future modelsZero retention, contractually guaranteed
Third-party exposureVendor is an unauthorized third partyVendor bound by confidentiality covenant
Compliance certificationsRarely disclosed or auditedSOC 2 Type II, GDPR, PIPEDA typically verified
Privilege risk after HeppnerHigh — no reasonable expectation of confidentialitySubstantially reduced with proper contracts

A practical checklist before adoption

  1. Conduct due diligence on the AI vendor and review its data-retention and training policies in writing.
  2. Adopt an internal firm policy governing which AI tools may be used and for what categories of matters.
  3. Negotiate contractual data-governance guarantees, including confidentiality covenants, with every AI vendor.
  4. Train all attorneys and staff on what may and may not be entered into an AI tool.
  5. Run regular audits of AI usage against the firm’s policy.
  6. In active litigation, consider seeking a Federal Rule of Evidence 502(d) protective order to limit waiver risk from inadvertent disclosure.

The single clearest rule to follow is also the simplest: never enter identifiable client information into a free, public AI tool. Where a firm does use AI on client matters, informed consent should be documented, and every AI-generated output should be checked for hallucinated facts or citations before it is relied upon or filed. A related and easily overlooked risk involves AI meeting-recording tools. The New York City Bar Association’s Formal Opinion 2025-6 flags disclosure obligations under Rule 8.4 (dishonesty and misrepresentation) when AI is used to record or transcribe conversations, and in some states — Pennsylvania among them — recording a conversation without the other party’s consent is a felony, independent of any legal-ethics analysis.

What Clients Should Know and Ask

Confidentiality protection is not only a lawyer’s responsibility; an informed client can catch a risky practice before it causes harm. A client is entitled to ask a law firm directly:

  • Does the firm use generative AI on client matters, and for which tasks?
  • Is the tool a free public consumer product or a paid enterprise deployment?
  • Does the underlying model train on submitted data, or is retention set to zero?
  • Has the firm negotiated confidentiality covenants with its AI vendor?
  • Will the client be asked for informed consent before case-specific information is entered into an AI tool?

Clients should also avoid entering their own confidential materials into public AI tools before consulting counsel, since that step alone can create the same third-party disclosure problem a lawyer would create.

This article is provided for general informational purposes only and does not constitute legal advice. Laws and professional-conduct rules governing attorney-client privilege, confidentiality, and the use of artificial intelligence vary by jurisdiction and continue to change. For guidance on a specific situation, consult a licensed attorney in your jurisdiction.

FAQ

keyboard_arrow_up