Est.

Attorney-Client Privilege Risks in Legal AI Platforms

Courts are now weighing platform architecture against four privilege factors.

Columnist · · 10 min read
Cover illustration for “Attorney-Client Privilege Risks in Legal AI Platforms”
AI in Regulated Industries · September 22, 2026 · 10 min read · 2,303 words

Attorney-client privilege doesn't disappear because a lawyer used AI. It disappears, or survives, based on four specific factors courts are now applying to actual cases, and the architecture of the platform, meaning who touches the data and where it travels, turns out to matter more than most firms have accounted for. This piece walks through how privilege doctrine is meeting AI use in real rulings from 2026, and what that means for the platforms lawyers pick.

The numbers explain why this can't wait. Firm-level AI adoption went from 26% in 2024 to 42% in 2026, and 74% of legal professionals now use AI tools several times a week. Roughly a third admit to using tools their firm never approved. Adoption outran policy, and now the courts are catching up to that gap.

What attorney-client privilege requires, and why AI use puts each element under pressure

Privilege gets treated, casually, like a blanket. It's a doctrine built from discrete parts, and every part has to hold for the whole thing to stand. It's a doctrine built from discrete parts, and every part has to hold for the whole thing to stand. Courts applying privilege to AI use keep coming back to four factors, and Maynard Nexsen's analysis frames these as the consistent test through which traditional privilege doctrine continues to apply "without AI exceptions," meaning judges aren't inventing new rules for AI. They're running the old rules against a new fact pattern.

The first factor is who used the tool: was it the client, or someone acting on the client's behalf, seeking legal advice? The second is purpose: was the AI used to get legal advice, or for something more exploratory or business-driven? The third is direction: did counsel direct the AI use, or did it happen independently, outside any attorney's supervision? The fourth is confidentiality: did the platform's own terms of service undercut any reasonable expectation that the input would stay private?

Each of these maps to a real, checkable fact about how a tool gets used inside a firm or by a client. Who has access. What the workflow looks like. Whether legal counsel is in the loop before or after the prompt gets typed. Whether the vendor's contract says your data trains their model. None of this is abstract, and that's why two cases decided in the same week, in 2026, reached opposite outcomes.

United States v. Heppner: the first federal ruling to apply those factors to AI platform use

Bradley Heppner was indicted on October 28, 2025, on securities fraud, wire fraud, and related charges. After he got a grand jury subpoena, he turned to Anthropic's consumer Claude platform, on his own, with no lawyer directing him, to draft reports exploring possible defense strategies. That single fact, that he acted independently rather than at counsel's direction, sits at the center of everything that follows.

FBI agents executing a search warrant at his home seized around thirty-one documents that recorded his prompts and Claude's outputs. Heppner later handed these over to his attorneys, who logged them as privileged: "artificial intelligence-generated analysis conveying facts to counsel for the purpose of obtaining legal advice." That's a reasonable-sounding label. It just doesn't survive contact with the four-factor test.

Judge Jed S. Rakoff ruled from the bench on February 10, 2026, with a written opinion following on February 17. The court treated the question as one of first impression at the federal level, and the reasoning tracked the factors directly: Heppner wasn't directed by counsel when he used Claude, and a consumer AI platform's terms of service don't create the kind of confidential channel privilege requires. Two of the four factors failed. Heppner wasn't directed by counsel when he used Claude, and a consumer AI platform's terms of service don't create the kind of confidential channel privilege requires, and those two failed factors were enough to defeat the privilege claim.

Warner v. Gilbarco and the cases that push back

The same week, a different court reached a different result, and the contrast is instructive rather than contradictory. In Warner v. Gilbarco, Inc., decided in a federal district court on February 10, 2026, a pro se plaintiff's use of generative AI to prepare for litigation was held to be protected work product.

Judge Patti's reasoning centered on a narrower question than the one in Heppner. AI platforms, the court said, are tools, and disclosing something to a tool isn't disclosure to an adversary. Work product protection is waived by disclosure to an adversary, or in a way likely to reach one, and a chatbot doesn't qualify as either. That's the whole test, and Warner never addressed the platform's privacy policy or terms of service. Work product protection is waived by disclosure to an adversary, or in a way likely to reach one, and a chatbot doesn't qualify as either, so that settled the case on its own.

So Heppner and Warner aren't in tension the way a first glance might suggest. Heppner turned on confidentiality and direction, two of the four factors. Warner turned on a different doctrine, work product, resolved by a different question entirely: did the disclosure reach an adversary? Different elements, different frameworks, different outcomes. Reading these as conflicting precedent misses what each court was actually asked to decide.

The UK Upper Tribunal's ruling: how an English court framed the open and closed platform distinction as the waiver test

In another jurisdiction, an appellate immigration tribunal issued a ruling that pushed the platform's architecture further into the foreground. In UK (Munir) v. Secretary of State for the Home Department, [2026] UKUT 81 (IAC), the tribunal became the first English court or tribunal to directly address legal professional privilege where confidential material had been uploaded to an open-source AI tool such as ChatGPT.

The tribunal's observation was made in passing, as obiter dictum rather than binding holding, but the substance carries weight regardless: uploading confidential documents to open-source AI tools breaches confidentiality and waives legal professional privilege. What makes the ruling notable is the line the court drew. It distinguished explicitly between open-source AI tools and closed AI systems that operate within a secure network, treating that architectural distinction, not the user's intent, as the test for whether privilege survives.

The tribunal referred one practitioner to the Solicitors Regulation Authority over the conduct, and this carried disciplinary consequences beyond the evidentiary ruling itself. The tribunal referred one practitioner to the Solicitors Regulation Authority over the conduct, and said it would have referred a second practitioner too, had he not already self-referred. Waiving privilege through AI use, in other words, wasn't treated as a private mistake between a lawyer and a client. It became a professional discipline matter.

What open and closed mean architecturally, and why enterprise branding doesn't settle the question

The open and closed distinction sounds tidy until you try to apply it to the actual products lawyers use, and this is where most firms are operating on assumptions rather than facts.

Consumer-grade tools, the free tier of a general-purpose chatbot, typically use what users type in to train future models unless the user opts out somewhere in a settings menu. The terms of service are written for general consumers, not regulated professionals handling privileged material. There's no legal-industry data processing agreement, no audit trail a firm can point to later, and limited say over where the data physically sits. This is the category the UK tribunal was pointing at when it referred to "open-source" tools.

Enterprise API access is a real, different thing, not just a marketing label slapped on the same product. Genuine enterprise agreements commit to no training on customer data, no retention beyond what's needed to serve the request, and no human review of the content. Those are contractual commitments, not slogans, and they matter.

But "enterprise" doesn't mean the data stays in one place, and this is what trips people up. Harvey routes client data through OpenAI's infrastructure and Microsoft's Azure infrastructure, among others, under a no-training policy on client data. CoCounsel, Thomson Reuters' platform, runs across multiple model and cloud providers, covered by Thomson Reuters' own enterprise data agreements. LexisNexis's Protégé reaches across OpenAI, Anthropic, and Google as its core model providers, with AWS, Microsoft, and Mistral serving as infrastructure and back-end partners, using what LexisNexis calls "Best Fit" auto-routing. A single client document might touch any combination of these providers depending on how the system optimizes that particular request at that particular moment.

Call this how data travels across infrastructures once it leaves the user. In one sense, the document never leaves "the enterprise," meaning it stays inside a contractually governed environment the whole time. In another sense, it crosses multiple infrastructures, each governed by its own contractual regime, and the law firm's data processing agreement is with the legal AI vendor, Harvey or Thomson Reuters or LexisNexis, not with each underlying model provider the vendor happens to route through. Whether that satisfies the confidentiality factor courts are applying is a live question, and it's not one that gets settled by the word "enterprise" on a vendor's homepage.

Beyond privilege: trade secrets, contractual obligations, and the compounding exposure from a single prompt

Diagram: One Prompt, Three Legal Consequences. Visualizes: Visualize how a single action — pasting a client document into a chatbot — simultaneously triggers three distinct legal consequences: (1) privilege waiver under attorney-client doctrine…

Privilege waiver isn't the only thing riding on this. Trade secret protection depends on showing "reasonable measures" were taken to keep information secret, and uploading client pricing models, product roadmaps, source code, security architecture, or M&A materials to a public large language model undercuts that showing directly. Once it's out, arguing the information was reasonably protected gets a lot harder.

Master service agreements, NDAs, data processing agreements, and outside counsel guidelines routinely bar disclosure to third parties without consent, and a public LLM is a third party under any plain reading, so a contractual layer governs this too. Master service agreements, NDAs, data processing agreements, and outside counsel guidelines routinely bar disclosure to third parties without consent, and a public LLM is a third party under any plain reading of those terms. A single employee pasting a client document into a chatbot can breach several agreements at once, without anyone involved intending to breach anything.

One disclosure event, one prompt, can waive privilege, undercut trade secret protection, and breach a contract, all from the same action. One disclosure event, one prompt, can waive privilege, undercut trade secret protection, and breach a contract, all from the same action. Three separate bodies of law, three separate consequences, triggered by one keystroke.

This lands hardest on corporate legal departments and outside counsel doing transactional work, where privilege sometimes doesn't even apply but confidentiality obligations under contract are every bit as strict. A term sheet or a due diligence file doesn't need privilege to be protected. It needs the confidentiality agreement to hold, and an AI prompt can break that just as easily.

The parallel enforcement wave of AI hallucination sanctions

Privilege waiver is one enforcement track. Running alongside it, on a separate but related track, is a wave of sanctions over AI hallucinations, meaning fabricated case citations that make it into court filings. Researcher Damien Charlotin, who maintains the most comprehensive public database tracking these cases globally, has now catalogued over a thousand of them, and the pace picked up sharply in early 2026, with Charlotin's data showing the pace accelerating markedly in early 2026.

The dollar figures are climbing too. Sanctions grew substantially in early 2026, with notable penalties including a significant award in Oregon and Nebraska's first license suspension tied to AI misuse, no longer slap-on-the-wrist fines. These aren't slap-on-the-wrist fines anymore.

What should worry firms relying on commercial platforms is the 5th Circuit sanction from early 2026, which involved an attorney using vLex and Thomson Reuters' CoCounsel, both licensed, paid, enterprise legal AI products. Enterprise licensing buys contractual protections around data handling. It does not buy immunity from hallucination, and it does not replace a lawyer's obligation to check the citations before filing. Competence risk and confidentiality risk are separate problems, and paying for the "professional" version of a tool solves neither one automatically.

A practical framework for platform evaluation: the questions privilege doctrine now requires firms to ask

Running a platform through the four factors turns out to be a workable exercise, and it starts with direction. Is AI use inside the firm supervised and initiated by counsel, or can clients and junior staff fire up a tool on their own, with no attorney in the loop? Policy documents don't answer this. Access controls and actual workflow do.

Purpose comes next. Is the AI plugged into a workflow built around getting legal advice, or is it being used more loosely, for drafting or general research or exploration? An audit trail that records why a given AI query was made carries real evidentiary weight if the question of privilege ever comes up later.

Confidentiality splits into two layers. The contractual layer asks whether the platform carries a legal-industry data processing agreement, whether it commits to no training, no retention, no human review, and, critically, whether those commitments run from the vendor directly or get inherited from whichever underlying model provider the vendor happens to route through that day. The architectural layer produces a blunter question that governs all of it: does client data leave the user's own environment at all, and if it does, how many separate infrastructures does it cross before the answer comes back?

None of these questions has a universally right answer sitting in a vendor's marketing page. What Heppner, Warner, and the UK tribunal's ruling in Munir all point toward, together, is that the answers exist, concretely, in how a given platform is built and how a given firm chooses to use it. Privilege doctrine hasn't changed to accommodate AI. It's just being applied, factor by factor, to a set of tools most firms adopted faster than they thought through.

More in AI in Regulated Industries