If you work in a technology-driven business (or have clients who do), you’ve likely already experimented with generative AI to research a question, ask for advice on setting strategy, or draft an internal memo. There’s a big challenge, however, when those questions, strategies, and memos are related to issues of law.

The uncomfortable truth is that conversations between non-lawyer and AI are discoverable in litigation and not protected by attorney-client privilege. When having those chats with a GPT involves disclosing information that would not otherwise be discoverable in litigation, the “I was just trying to help” can quickly turn into critical evidence. Protecting clients’ interest in this new world of AI means that lawyers need to understand how it impacts privilege.

The Rules of Privilege

Protection of communications between clients and counsel.

Legal privilege is what keeps conversations between clients and lawyers from becoming discovered in trial and used as evidence against the client. To be considered “attorney-client privileged” the communication must meet a three-part test requiring that it: (1) is between a client and their attorney; (2) that it is intended to be, and in fact is, kept confidential; and (3) for the purpose of obtaining or providing legal advice. The concept of attorney-client privilege is generally construed narrowly because it operates as an exception to the rule that “all relevant proof is essential” for a complete record and for “confidence in the fair administration of justice”.

However, it is also fiercely protected because it is seen as a necessity to ensure that lawyers are capable of meeting their ethical requirements of competency and representation – basically the need for lawyers to have the information necessary to have a comprehensive and frankly honest discussion with the client in order to provide the client with fully informed, competent advice and assist the client in complying with the law.

“The social good derived from the proper performance of the functions of lawyers acting for their clients is believed to outweigh the harm that may come from the suppression of the evidence in specific cases.”

In other words, privilege is important because without it, clients may not be sufficiently candid with their lawyers for the lawyers to give good legal advice. The availability of good legal advice is of higher social importance than what may come from the suppression of evidence.

The “Work Product Doctrine”: Protecting Attorney Work

The work product doctrine is another type of privilege associated with legal representation. It is similar to attorney-client privilege in that it provides qualified protection for materials provided by or at the behest of counsel in anticipation of litigation or for trial. It is more tightly tied to the work of the attorney than the attorney-client privilege that protects communications between clients because it is designed to protect the thought process of the lawyers in relations to pending or anticipated litigation.

The test for work product is simpler than the attorney-client privilege. It is simply that the work was prepared by or at the direction of a lawyer in anticipation of trial. So, there must be: (1) a lawyer; (2) preparation by either the lawyer or someone the lawyer is directing; and (3) anticipation of trial. Again, all of those elements must be present for the materials to be considered privileged under the work product doctrine. Specifically absent from protection is materials that are merely in the possession of the lawyer, particularly if they are not related to the attorney’s thought process. This is why clients can’t simply hand over evidence to their lawyers and claim privilege.

Pro Se litigants: Privilege without Lawyers

The rules for pro se litigants – those who elect to represent themselves as opposed to hiring a lawyer – are a bit different. Because they act as their own attorneys, they may be able to protect the work they do (including conversations they have with AI) as privileged work product. Rules regarding confidentiality likely still apply but may end up being slightly different. Perhaps courts will find that the Terms of Service are not as crucial to the question of confidentiality so long as no other human parties are involved, particularly if the generative AI tool requires payment in order to exclude user input from model training.

Because, however, this blog is about interest in the business use cases of AI and not personal use cases, the pro se litigant will not be addressed here.

In-house Counsel and Privilege

In-house lawyers are unique in that they have only one client – their employer – and often provide a combination of legal, business, and ethics advice. In fact, the role of in-house counsel has been continuously broadening over the last several years, driven by legal, economic, business, and political changes.

The United States

In the United States, the law continues to protect communications between in-house counsel and the company. When the advice includes both business advice and legal advice, the privilege will protect communications so long as the communication was made primarily for the purpose of generating legal advice. Complications can then arise when trying to determine whether the legal advice was appropriately given to “the client” (which is the company, not the individual employees of the company) and whether such advice remained sufficiently confidential.

There is also the question of confidentiality. It is not sufficient that all employees work for the same entity where the client is the entity. The limits of confidentiality as an element of legal privilege are no different from the rules of confidentiality around highly sensitive business information and generally rely on a “need to know” requirement before disclosure can be made. Company communication tools like email, shared drives, Slack, and Teams are often geared far more towards efficient communication that strict access controls.

Europe

The global nature of business also affects the ability to maintain privilege of attorney-client communications and work products. In the European Union (EU), in-house lawyers are often trained and licensed very differently from their American counterparts. In-house counsel in the EU often have only a Bachelor of Laws degree and may not be a fully-licensed member of the bar association or law society of their country. In fact, in some jurisdictions, lawyers with bar admissions are specifically required to give up their bar membership when transitioning to an in-house role.

The challenge for privilege is that the genesis of privilege stems from attorneys’ obligations of confidence and competent advice and how they are held accountable to those standards. Without licensing oversight, the duties of confidence and competence cannot be professionally enforced outside of the employment context.

Logistical realities

The frameworks for privilege obviously create a number of logistical challenges for in-house legal teams. Most in-house lawyers are familiar only with the “Upjohn Warning” that they provide as part the corporate onboarding program or internal investigations. Now we have a new challenge: Artificial Intelligence.

AI, Privilege, and Overeager Clients.

In the post-Internet era, any in-house lawyer can attest to the number of incoming clients who are already certain that they know the legal outcome of their issue. Generative AI tools and the ease with which they can now get cited case law and arguments have exponentially raised their confidence.

There is one thing that AI cannot do, though - create privilege.

U.S. v. Heppner: Humanity is Required for Privilege

In October 2025, the Department of Justice brought charges against Bradley Heppner. Shortly after a search, defense counsel informed the government that, before his arrest, Heppner had run queries related to the government’s investigation through Anthropic’s Claude generative AI tool in which he had outlined defense strategy, analyzed the factual and legal landscape of the charges he anticipated, and prepared materials. Heppner’s defense team sought to protect these communications and materials as attorney-client privileged communications and attorney work products. The government disagreed. The government won.

Judge Rakoff’s ruling asserted that neither the communications with Claude nor its output materials could be considered privileged because Claude is neither an attorney nor human. “All [recognized] privileges require, among other things, “a trusting human relationship,” such as…a relationship “with a licensed professional who owes fiduciary duties and is subject to discipline.”

Heppner also tried to rely on another common misunderstanding seen by in-house lawyers: that all they have to do to protect information from being discovered is bring it to the legal team, label it as ‘privileged’ and it will magically become privileged. As the court aptly noted, “it is black letter law that non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel.”

Mitigating Risks

Many lawyers will joke that the biggest risk to their ability to provide good legal advice is simply the client. Client use of AI is complicating legal practices in many ways. Lawyers must have and use competence to advise clients on how to maintain privilege while still taking advantage of this powerful technology.

AI Policy Updates

For in-house teams, the starting point is usually the AI Policy. Check that it addresses issues of legal privilege. Does your AI policy restrict the use of AI to only the legal team on issues such as obtaining legal advice or preparing for legal proceedings? It should.

Practical Playbooks

If you have a playbook and/or training on privilege, update it to address AI tools. Be sure to include both how lawyers and non-lawyers can use AI tools, and which tools they are permitted to use.

Address vendor agreements

For cybersecurity forensics teams or other non-legal service providers working on matters relating to potential litigation, contract terms restricting the use of generative AI should be considered. Understand expectations of when and how AI can be used if/when the services in question may result in legal investigations.

Attorneys must be cautious with the tools they use. There is a duty of competence that requires licensed attorneys to understand the technology they are using and to competently manage it in a way that preserves privilege. It’s not enough to simply configure Claude, ChatGPT, or Gemini to avoid training on data – legal teams must now vet every new technology to determine how they treat data at every layer of the technical stack.

The TL;DR

A competent understanding of AI – including how it is used by clients – is not just a duty of your legal license, but necessary to help protect the privileges that encourage the candid conversations with your clients necessary to provide good legal advice.

  • Update Guidance on Privilege. Make sure clients are aware of how their use of AI in legal matters can put their legal position at risk.
  • Confidentiality by default. Configure AI and check your vendors. No model training on customer data, and assurances of controls relating to confidentiality at their application layer.
  • Ensure lawyer-directed workflows. Client-led workflows are likely to be seen as “ordinary course of business” and not work done in anticipation of litigation.
  • Need-to-know access controls at the matter level. Not everyone at the company needs to know all legal advice.
  • Evidence-ready logging. A lack of logging will eventually hurt when producing privilege logs in response to legal demands.

Artificial intelligence is a powerful tool that can greatly improve legal services and business outcomes. Responsible use of AI in legal requires both technically and legally competent attorneys with a high level of awareness of how clients act when unsupervised.