Generative artificial intelligence has entered the practice of law with remarkable speed. Lawyers now routinely use AI-powered tools to draft documents, conduct legal research, summarize lengthy materials, analyze contracts, prepare litigation strategies, and generate first drafts of everything from demand letters to regulatory submissions. The efficiency gains are real, and the technology is not going away. But the integration of AI into legal practice raises a question that has yet to receive a definitive answer from any court or legislature: when a lawyer inputs confidential client information into a generative AI tool, and when that tool produces output based on that information, does attorney-client privilege protect those inputs and outputs from compelled disclosure?
The answer, as of today, is genuinely uncertain. The legal framework for privilege predates the existence of large language models by decades, and courts have not yet had sustained occasion to apply that framework to AI-assisted legal work. What we have instead is a set of first principles, a growing body of state bar ethics opinions, some analogous case law from earlier technology contexts, and an evolving set of practical norms. This article examines that landscape carefully, identifies the major legal risks, and offers concrete guidance for business clients whose legal matters are being handled, in whole or in part, with AI assistance.
The Foundation: What Privilege Requires
Attorney-client privilege protects confidential communications between a lawyer and a client made for the purpose of obtaining or providing legal advice. Every element of that definition matters when analyzing AI-assisted legal work. The communication must be between a lawyer and a client. It must be made in confidence. And its purpose must be legal advice, not business strategy, general information, or any other objective.
The confidentiality requirement is the element most directly implicated by AI use. Privilege does not protect communications that are disclosed to third parties who are not within the attorney-client relationship. The long-standing rule is that voluntary disclosure of a privileged communication to a third party destroys the privilege with respect to that communication. The rationale is straightforward: confidentiality is a precondition, not just a feature, of the privilege. If the client or the lawyer shares the substance of a privileged communication with an outside party, the law infers that the communication was not truly held in confidence, and the protection falls away.
This is where AI tools create a legal problem that earlier legal technologies did not. When a lawyer uses a word processor to draft a privileged memorandum, no third party receives the content. When a lawyer uses encrypted email to communicate with a client, the communication remains bilateral. When a lawyer uses a legal research database to find relevant cases, no client information is transmitted to the database. Generative AI is structurally different: the lawyer feeds client-specific information into a tool operated by a third-party technology company, and that company’s systems process, store, and potentially retain the information. The legal question is whether that transmission to the AI provider breaks the confidentiality that privilege requires.
The Third-Party Disclosure Problem
The doctrine governing third-party involvement in privileged communications is more nuanced than the simple rule that any outside disclosure destroys privilege. Courts have long recognized that privilege can survive the involvement of third parties when those third parties are necessary to facilitate the attorney-client relationship or are so integrated into that relationship as to be functionally within it. The classic example is the Kovel doctrine, drawn from United States v. Kovel (2d Cir. 1961), which held that communications with a third-party accountant retained by a law firm to assist in providing legal advice were protected by privilege. The principle extends to legal assistants, paralegals, co-counsel, interpreters, and other agents whose involvement is necessary to the rendering of legal services.
The question for AI tools is whether they fit within this framework. Can a generative AI platform be treated as a necessary agent of the attorney-client relationship in the same way as a paralegal or an outside expert retained to assist with legal analysis? The argument in favor of that characterization has intuitive appeal: the lawyer is using the AI tool as an instrument to help render legal services, much as one might use any other professional tool or service. On this view, the AI is simply a more sophisticated version of the legal research service, the document management platform, or the outside consultant — all of which can be involved in the legal matter without destroying privilege.
The argument against is more structural. When information is transmitted to a commercial AI provider, it is not being shared with an agent retained by the attorney to serve the client. It is being transmitted to an independent corporation with its own commercial interests, its own terms of service, its own data retention practices, and potentially its own disclosure obligations. The AI provider has no fiduciary duty to the client, no ethical obligation of confidentiality under any bar rules, and no professional accountability for how it handles the information it receives. That is a meaningful difference from the Kovel accountant, who operates under the supervision of counsel and for the direct benefit of the client.
Courts examining analogous questions — such as whether privilege survives disclosure to litigation support vendors, cloud storage providers, and e-discovery platforms — have generally protected those communications, but with an important condition: the disclosure must be reasonably necessary and the party claiming privilege must have taken reasonable precautions to maintain confidentiality. The question of what constitutes reasonable precaution in the AI context is where the analysis becomes most practically important for lawyers and their clients.
Terms of Service, Data Retention, and the Confidentiality Condition
The single most important factor in assessing whether AI-assisted legal work retains privileged status is the contractual and technical framework governing the AI tool itself. Not all AI tools are alike. Consumer-facing versions of generative AI products typically reserve the right to use inputted data to train their models, retain conversation histories, and share information with affiliated companies for a variety of purposes. Under those terms of service, a lawyer who inputs a client’s confidential business information into a consumer AI tool has, in a meaningful sense, voluntarily disclosed that information to a third party with the contractual right to use it for purposes entirely unrelated to the legal matter at hand.
Enterprise AI deployments operate differently. Many major AI providers — including Microsoft (through its Copilot for Microsoft 365 and Azure OpenAI Service), Google (through Workspace AI features), and others — offer enterprise agreements that expressly prohibit the use of customer data to train models, commit to data isolation, and provide detailed security and compliance representations. Under these enterprise arrangements, the AI provider’s access to the data is limited, contractually constrained, and arguably more analogous to the position of a cloud infrastructure provider than to an independent recipient of confidential information. Legal commentators and, increasingly, state bar ethics committees have drawn a meaningful distinction between consumer AI deployments and enterprise deployments with robust data protection commitments.
The American Bar Association addressed this landscape in its Formal Opinion 512, issued in July 2023, which analyzed lawyers’ ethical obligations when using generative AI. The Opinion emphasized that lawyers must understand the terms under which an AI tool operates before using it to process confidential client information. It drew on the existing framework of Model Rule 1.6, which prohibits disclosure of client information without consent, and Model Rule 1.1, which requires competence — including technological competence. The Opinion noted that some AI tools present unacceptable disclosure risks and that lawyers must, before using any AI tool, conduct a reasonable inquiry into how the tool handles data.
From a privilege standpoint, the practical implication of this framework is that the answer to whether privilege survives AI use depends heavily on which AI tool is used and how. A lawyer who uses a properly configured enterprise AI deployment, with contractual data protection guarantees and no model-training use of client data, has a substantially stronger argument that no meaningful third-party disclosure has occurred. A lawyer who inputs client information into a free-tier consumer AI product with permissive data-use terms has a substantially weaker one, and may face the argument that privilege has been waived altogether.
Work Product Doctrine: A Parallel Analysis
The analysis of AI-generated materials is not limited to the attorney-client privilege. The work product doctrine, which protects materials prepared by or for a lawyer in anticipation of litigation, provides a separate and often broader layer of protection. Work product protection does not depend on confidential communication between lawyer and client in the same way that privilege does. It extends to the lawyer’s own mental processes, strategies, legal theories, and judgments about the case.
When a lawyer uses a generative AI tool to draft a litigation strategy memorandum, analyze the strengths and weaknesses of a case, or develop a theory of defense, the resulting document has strong attributes of opinion work product — the most protected category, which reflects the lawyer’s mental impressions and professional judgment. The fact that an AI tool assisted in generating the text does not, by itself, transform that document into something other than work product. The lawyer directed the analysis, provided the inputs, and shaped the output. The AI is analogous to any other research tool or drafting aid that a lawyer uses in the course of preparing for litigation.
That said, work product protection also has a confidentiality dimension. Courts have held that work product can be waived by disclosure to adversaries or to parties who do not share a common interest in the matter. If AI-generated work product is disclosed to the AI provider in a manner that gives the provider rights to use or share the information, that disclosure could be argued to constitute a waiver — just as any other third-party disclosure could. The analysis thus circles back to the same core question: what are the terms governing the AI tool, and does the transmission of information to the tool constitute a disclosure that is inconsistent with maintaining confidentiality?
State Bar Ethics Opinions and Emerging Guidance
In the absence of binding case law, state bar ethics committees have been the most active source of guidance on AI and confidentiality. By mid-2025, a substantial majority of U.S. states had issued formal ethics opinions or informal guidance addressing the use of AI in legal practice. While the specific conclusions vary by jurisdiction, a number of common themes emerge from this body of guidance.
First, virtually every opinion emphasizes that the use of AI tools does not suspend the lawyer’s professional obligations. The duty of competence requires that lawyers understand, at a reasonable level, how the AI tools they use function, including how they handle data. The duty of confidentiality requires that lawyers not expose client information to third parties without authorization, which in turn requires an assessment of the AI tool’s data practices. Some opinions have noted that a lawyer who uses an AI tool without understanding its terms of service may violate Rule 1.6 even if the tool does not, in the event, disclose the information to anyone.
Second, many opinions have addressed the specific question of whether client consent is required before using AI to process client information. The California State Bar’s guidance and opinions from New York, Florida, and other major jurisdictions have generally taken the position that express client consent is not required before using AI tools with robust data protections, but that clients should be informed of the use of AI when that information is material to the representation. If a lawyer is using an AI tool that presents meaningful confidentiality risks — for instance, a consumer product with permissive data retention terms — then disclosure and consent may be required. Several opinions have noted that law firm engagement letters and retainer agreements should be updated to address AI use as a standard matter.
Third, the ethics guidance has uniformly stressed that AI output must be supervised and verified by the lawyer. This has obvious relevance to the quality of legal services, but it also has privilege implications. An AI-generated document that is reviewed, edited, and adopted by the lawyer as her own work product is more defensibly privileged or work-product protected than a raw AI output that was never reviewed. The lawyer’s intellectual engagement with the output is part of what makes it legal work product rather than a mere data-processing result. Firms that deploy AI in ways that minimize rather than support lawyer engagement with the output may be creating privilege vulnerabilities alongside the quality risks.
The Outputs Problem: AI-Generated Documents in Litigation
A separate but related question concerns the status of AI-generated outputs once they are produced. If a lawyer uses an AI tool to generate a research memorandum, a contract analysis, or a draft brief, and that document is later sought in discovery or a regulatory proceeding, will the court treat it as privileged work product, as a non-privileged business record, or as something else entirely?
The answer depends, first, on whether the underlying communication with the AI was itself privileged — which depends on the analysis described above — and second, on whether the resulting document was prepared in anticipation of litigation or for the purpose of rendering legal advice. A document that was generated by AI at the direction of counsel, for the purpose of advising a client on a specific legal question, and treated as confidential throughout, has a strong claim to privilege or work product protection. A document generated by AI for general business planning purposes, or that was widely circulated within the company for non-legal purposes, does not.
Courts have not yet established definitive rules for how AI-generated documents should be categorized, but the existing doctrinal framework is adequate to address most scenarios. The key factors are purpose, confidentiality, and the lawyer’s role in directing and adopting the output. What is new is not the legal analysis but the factual complexity: because AI tools make it easier to generate large volumes of apparently legal-looking documents quickly, there is a risk that companies will treat AI-generated materials as privileged even when the circumstances do not support that characterization. The volume and accessibility of AI-generated output may create privilege logs and confidentiality claims that are harder to sustain under scrutiny than their human-authored equivalents.
International Dimensions: A Compounded Uncertainty
For companies operating internationally, the uncertainty surrounding AI and privilege is compounded by the jurisdictional divergence described in our companion article on international privilege. The EU, in particular, presents a challenging environment. The EU’s General Data Protection Regulation imposes strict rules on the transfer of personal data to AI providers, particularly when those providers are based outside the EU, as most major AI companies are. A lawyer who transmits client communications containing personal data to a U.S.-based AI provider may be creating GDPR compliance issues alongside privilege vulnerabilities.
More fundamentally, the in-house counsel privilege gap that characterizes EU competition law proceedings — the ECJ’s ruling that in-house counsel communications are not privileged — means that EU regulators may be entitled to access AI-generated legal analysis produced by in-house lawyers regardless of how carefully the information was handled from a U.S. privilege standpoint. This intersection of international privilege law and AI creates a particularly acute risk for companies that are simultaneously subject to EU regulatory scrutiny and that use AI tools to support their in-house legal functions.
The lack of a uniform international framework for AI data governance means that the terms of service analysis described above must be conducted jurisdiction by jurisdiction. An enterprise AI agreement that adequately protects confidentiality under U.S. law may not satisfy the data localization requirements, cross-border transfer restrictions, or regulatory access rules applicable in other countries. Companies with global operations should ensure that their AI governance frameworks are reviewed by counsel with expertise in each relevant jurisdiction.
Practical Guidance for Business Clients
Given this state of legal uncertainty, what should business clients do to protect the privilege status of AI-assisted legal work? Several practical principles emerge.
Business clients should ask their outside counsel and in-house teams to confirm what AI tools, if any, are being used in connection with the client’s legal matters, and to provide a brief description of the data governance framework applicable to those tools. This is not an unreasonable request, and responsible law firms should be able to answer it readily. Firms that cannot explain what AI tools they use or how those tools handle client data are operating in a manner that creates privilege risk, and clients should be aware of that.
Where AI tools are used, the engagement should be governed by a proper enterprise agreement that prohibits the AI provider from using client data to train its models, commits to data security and confidentiality, and provides contractual protections that can be pointed to in any future privilege dispute. Consumer-tier AI products — even those provided by reputable technology companies — do not offer these protections, and their use for confidential legal matters is difficult to defend as a matter of both professional ethics and privilege preservation.
Law firms and in-house legal departments should implement AI use policies that require lawyer review and approval of any AI output before it is incorporated into client work, communicated to the client, or used in any proceeding. This review requirement serves multiple purposes: it ensures quality, satisfies the ethical competence requirement, and establishes the lawyer’s intellectual engagement with the output as a necessary element of the work-product analysis.
Companies should also revisit their litigation hold and document preservation procedures in light of AI use. If AI tools generate documents that are potentially privileged, those documents should be preserved, logged, and reviewed with the same care as any other privileged material. The failure to properly log AI-generated documents that are later claimed as privileged can result in adverse rulings or the forced production of materials that might have been protected with better procedural hygiene.
Finally, companies should consult with counsel before disclosing the existence or content of AI-assisted legal work to any third party, including regulators, in the context of settlement negotiations or cooperation arrangements. As with any privileged material, selective disclosure of AI-generated legal analysis can constitute a waiver — and the scope of that waiver may be difficult to control once the disclosure has occurred.
Conclusion: A Developing Area Requiring Careful Management
The intersection of generative AI and attorney-client privilege is one of the most consequential unsettled questions in American evidence law. The doctrine itself has not changed: privilege still requires confidential communication for the purpose of legal advice, and work product still requires materials prepared by a lawyer in anticipation of litigation. What has changed is the factual landscape within which those requirements must be assessed. The involvement of AI tools introduces a third-party technology provider whose role, contractual commitments, and data practices are highly variable, and whose involvement may or may not be consistent with maintaining the confidentiality that privilege demands.
The current legal environment rewards careful, informed management. Law firms and legal departments that use properly configured enterprise AI tools, maintain clear documentation of AI use, require lawyer review of AI output, and update their client communications accordingly are in a substantially better position than those that deploy AI opportunistically without attention to these issues. The question is not whether to use AI — the technology is too valuable and too prevalent to avoid — but how to use it in a manner that preserves the protections on which clients depend.
The law in this area will develop. Courts will eventually address the privilege status of AI-generated materials in concrete disputes. Legislatures may act. The bar associations will continue to refine their guidance. Businesses should anticipate that the rules applicable today may be clearer, and possibly stricter, within a few years. The best posture, in the meantime, is to treat AI-assisted legal work with the same care and discipline that has always governed the most sensitive communications between lawyer and client — because no court has yet held that anything less is sufficient.
This article is intended for general informational purposes and does not constitute legal advice. The law governing attorney-client privilege and AI-assisted legal practice is evolving rapidly and is jurisdiction-specific. Businesses should consult qualified legal counsel regarding the specific implications of AI use for their legal matters.
