NEWS & INSIGHTS
Is there any legal privilege that protects information from disclosure when a lawyer or client uses AI to formulate legal strategy?
- Artificial Intelligence (AI)
- Litigation
There are certain privileges, such as the Attorney-Client Privilege, the Attorney Work Product Privilege, the Priest-Penitent Privilege, the Spousal Privilege and the Doctor-Patient Privilege that prevent confidential matters from being disclosed. However, with routine reliance upon the use of AI as part of people’s daily lives, litigants should be very cautious in the use of Artificial Intelligence for legal research and formulating legal strategy and defenses. Sometimes, an event occurs to remind you that technology is not always your friend and that AI is not your lawyer.
With the explosion of the use of AI, it seems that that courts would inevitably need to: (1) opine whether legal strategies, communications and documents resulting from the use of AI could be shielded from disclosure; and (2) address the intersection of AI usage and the doctrines of attorney-client privilege and work product. The law is continuously developing and an “AI-Client Privilege” may someday be recognized. However, there is not yet any “AI-Client Privilege” as is evident from a recent criminal case in federal court in New York.
In United States v. Heppner in the United States District Court for the Southern District of New York, the client/defendant used AI to develop strategies to subsequently discuss with his attorneys. The Court found, in a bench ruling, that the client/defendant’s use was not protected and therefore the Court ordered disclosure. While AI can be a valuable tool for lawyers and clients, this ruling is a clear warning for both clients and attorneys to exercise caution when utilizing AI in legal matters. This decision also provides a tentative guideline for AI usage – or its avoidance – in similar legal contexts.
In this instance, the client/defendant used AI to prepare reports and outline both a factual and legal defense strategy after receiving a grand jury subpoena – all with the intention of implementing such a strategy if he were later indicted. The client shared these reports with his defense counsel. In ruling that neither the attorney-client nor work product privileges applied to these reports, the court relied on several specific factors:
- The reports were not prepared by an attorney and they were prepared before the client consulted counsel. Defense counsel did not direct the client/defendant to utilize AI in connection with its representation. Thus, the reports could not have involved defense counsel’s strategy.
- The client/defendant used an Open-source AI tool that included a non-confidentiality disclaimer. Accordingly, the client had no expectation of privacy.
The terms & conditions for open-sourced AI platforms, which are available to anyone, explicitly state that user inputs are collected and processed. Therefore, such information is not private and it is not encrypted. There is no confidentiality guarantee comparable to attorney-client conversations, and when used before consulting counsel, they cannot be deemed work product.
AI platforms generally retain conversation data even if the user deletes the chat. It seems inevitable that prosecutors will begin to subpoena open-source AI platforms to learn how criminal defendants viewed the facts of their cases prior to the defense of their criminal cases. Likewise in civil litigation – subpoenas to litigants in civil proceedings will likely involve demands to produce AI-generated legal searches.
As a result of this ruling, clients should be aware that submitting documents or information to public AI tools could forfeit the protections of the attorney-client privilege, and the resulting materials do not constitute attorney work product. Therefore, you should first discuss any legal questions or confidential information with a lawyer before using AI for legal research and strategy. Privileges, some of which are referenced below, exist to protect confidential information. A client who uses AI, even during representation by an attorney, might find his entire defense exposed before he even gets his day in Court. AI is not confidential, does not constitute legal advice from a lawyer and thus do not expect AI chats to be protected from disclosure.
1. Attorney–Client Privilege
The attorney–client privilege protects:
- Confidential communications
- Between lawyer and client
- For the purpose of seeking or providing legal advice
The AI Complication
Privilege generally requires the communication to remain confidential. If privileged information is shared with a third party, privilege can be waived — unless that third party is considered necessary to the legal representation.
When privilege is more likely preserved
- The AI tool is used internally by the law firm
- The AI provider contractually agrees to:
- Maintain confidentiality
- Not use data to train models
- Provide enterprise-level data protection
- The AI functions similarly to a paralegal, translator, or e-discovery vendor
Courts have long held that using third-party agents to assist legal representation does not automatically waive privilege if they are necessary to facilitate legal advice.
When privilege is at risk
- The lawyer or client inputs sensitive facts into:
- A public AI system
- A consumer-grade AI with unclear data retention
- The platform’s terms allow data retention, review, or model training
- No confidentiality agreement exists with the AI provider
In those situations, disclosure could be seen as voluntary disclosure to a third party — which may waive privilege.
2. Work-Product Doctrine
The work-product doctrine protects:
- Materials prepared in anticipation of litigation
- Mental impressions, strategy, legal theories
Even if privilege is waived, work-product protection may still apply — especially for “opinion work product” (legal strategy and analysis).
Using AI to:
- Draft legal theories
- Test arguments
- Outline litigation strategy
may still qualify as protected work product if it was specifically prepared for litigation purposes.
However, again, disclosure to an AI vendor could weaken that protection if confidentiality is not preserved.
3. Ethics Guidance (This Is An Emerging Area)
Bar associations are actively addressing this issue.
For example:
- The American Bar Association has issued guidance emphasizing:
- Duty of competence with technology
- Duty of confidentiality
- Need to understand AI data handling
- Several state bars (e.g., State Bar of California) advise lawyers to:
- Vet AI vendors
- Avoid inputting client-identifying information without safeguards
- Ensure compliance with confidentiality obligations
Most guidance suggests AI can be used ethically — but only with reasonable precautions.
4. Key Practical Distinction
The strongest protection exists when AI is treated like:
A secure litigation-support vendor under confidentiality controls
The weakest protection exists when AI is treated like:
A public internet search box into which sensitive facts are freely typed
5. Jurisdiction Matters
This area is still developing. Courts have not yet issued many definitive rulings specifically on AI-based privilege waiver. Outcomes may vary by:
- State vs. federal court
- Contract terms with the AI provider
- Whether litigation is already pending
- The specific facts disclosed
Bottom Line
There is no new special “AI privilege.”
Instead:
- Traditional attorney–client privilege and work-product doctrine may apply.
- Privilege can be preserved if confidentiality is maintained.
- Privilege can be waived if sensitive information is shared without adequate safeguards.
If you have any questions about AI and Legal Privilege, you can contact attorney Sean P. Murphy via our contact form or phone at 202-329-1654.
Schedule A Consultation
"*" indicates required fields