3 / 26
AI Fundamentals for Legal Professionals· 20 min read·Personalise for your role →

Confidentiality, Privilege, and AI

Understand the specific confidentiality and privilege risks that arise when using AI in legal practice, and how to manage them without sacrificing the productivity benefits.

In practice: Contract first-pass: 2–4 hours → 20 minutes

Step 1 of 4

Read

0% done

The Core Tension

AI tools are at their most useful when given rich context — the full contract, the complete correspondence, the detailed case facts. But rich context often means client-confidential or legally privileged information. Managing this tension is the central compliance challenge of AI adoption in legal practice.

What Are the Risks?

Data Transmitted to Third Parties

When you paste content into an AI tool, that content is transmitted to the AI provider's servers. If the provider is not bound by a suitable data processing agreement, that content may:

  • Be retained and used for model training
  • Be accessible to provider employees in certain circumstances
  • Be stored in jurisdictions with different data protection standards

Inadvertent Waiver of Privilege

In some jurisdictions, sharing privileged materials with third parties — including AI providers — can constitute a waiver of legal professional privilege if the provider is not subject to appropriate confidentiality obligations. This is an evolving area of law.

Data Breach Risk

Any data held by a third-party AI provider is subject to that provider's security posture. A breach at the AI provider level could expose client information.

Practical Mitigation Strategies

1. Use approved enterprise tools only. Your firm or organisation should maintain an approved tool list. Only use tools that have appropriate data processing agreements with your organisation.

2. Anonymise before pasting. For matters where enterprise agreements are not in place, anonymise names, company names, dates, and identifying details before submitting to AI. Use placeholder names.

3. Apply the minimum necessary test. Only include the context the AI needs to complete the task. Don't paste an entire matter file when only a specific clause needs review.

4. Treat AI output as internal workproduct. AI outputs are drafts for your review. They are not final documents and should not be sent externally without careful review.

5. Know your firm's policy. Many firms have issued specific guidance on AI tool use. Know it, follow it, and raise questions if the guidance is silent on a situation you face.

Privilege in AI-Generated Documents

A separate question: can AI-generated legal work product attract privilege? The consensus emerging is yes — if created under the supervision of a lawyer for the purpose of legal advice, AI-assisted documents can attract privilege. The key is lawyer oversight and control.

Data minimisation: full-context vs. anonymised prompt

The prompt

Review the confidentiality clause in this agreement between Acme Corp and BrightTech Solutions for their software development project. Flag any issues.

Claude's response

The confidentiality clause between Acme Corp and BrightTech Solutions appears to be a standard mutual confidentiality provision. It covers both parties' confidential information and applies for the duration of the agreement. There are no obvious red flags, though you may want to ensure the definition of confidential information is appropriately broad.

Quick check

A solicitor is working on a sensitive acquisition and wants to use AI to help draft the confidentiality provisions. The firm does not yet have an enterprise AI agreement. What is the safest approach?

Key Takeaways

  • 1Client content transmitted to AI tools may be retained by providers unless enterprise agreements prohibit it
  • 2Inadvertent privilege waiver through AI tool use is a live issue in some jurisdictions
  • 3Use only approved enterprise tools with appropriate data processing agreements for client matters
  • 4Anonymise sensitive content when enterprise tools are not available
  • 5Apply the minimum necessary information principle — only share what the AI needs

Your challenge this week

Apply what you learned in a real task

Take a standard clause or template from a document you are currently working on. Anonymise any client or deal-specific identifiers by replacing them with bracketed placeholders. Submit the anonymised version to AI for review or redrafting. Compare the output quality to what you would have got from a generic prompt.

Starter prompt · paste into Claude
Review the following [clause type] from a [agreement type]. I have anonymised the parties as [PARTY A] and [PARTY B]. Flag any provisions that: (1) [specific concern 1], (2) [specific concern 2], (3) [specific concern 3]. Indicate whether each point is standard market practice or unusual. This is for internal triage only — not for client distribution. [Paste anonymised clause]

Before you practise

In your current practice, which matters involve the most sensitive client information that you would never want to expose — even accidentally — through an AI tool? What protocols would need to be in place before you could safely use AI on those matters?

Was this lesson helpful?

Next step

Put it into practice

You've read the lesson — now apply it in a guided hands-on exercise. It takes about 5 minutes.

Ask the AI Tutor