AI and the Attorney-Client Privilege
Does entering confidential information into an AI platform destroy attorney-client privilege?
A June 2026 New York City Bar Association report argues that the answer should not turn on the mere fact that a technology provider processes the information. It explains that generating a response does not, by itself, train the model on the user’s information. Nor is the possibility that information could become part of a trained model the same as a provider retaining a readable record of the conversation. Those are separate questions, with different implications for confidentiality. That is, a provider may retain prompts and responses even when it does not use them for training. Understanding the particular product’s terms, settings, and data practices is therefore essential.
The report also challenges the assumption that a provider’s ability to access information necessarily defeats confidentiality. Lawyers routinely rely on email and cloud services operated by third parties. The report argues that courts should examine the actual function of an AI tool and the practical exposure of information rather than automatically treating the tool as another person receiving a disclosure.
But the report does not promise that AI use preserves privilege. It acknowledges differing judicial approaches and emphasizes that attorney-client privilege and work-product protection have different waiver standards. A ruling protecting AI-assisted litigation materials as work product does not necessarily establish that privileged communications entered into the same tool remain protected.
Before employees or counsel enter sensitive legal information into an AI platform, examine the specific product and its contractual protections. Determine whether prompts are retained, used for training, accessible to others, or transmitted to outside services. Document counsel’s direction where appropriate, and establish clear rules for handling privileged information. The report also recommends advising clients about independent AI use and cautioning against sharing or exporting conversations involving privileged matters.