AI Tools and Attorney-Client Privilege

By: De'Von Carter

Before You Paste That Into ChatGPT: How Consumer AI Can Quietly Cost You Your Privilege

It isn’t uncommon these days for a business owner to send a summary or even a draft contract to me prior to hopping on a call to discuss what they need. Unsurprisingly, the document/draft is generated from a summary of the situation dropped into ChatGPT, with a prompt asking AI to spot weak points and summarize what the other side might argue. By the time we actually talk, the client already has a tidy one-page analysis.

Its a good idea, but also can cause problems - in pretty much every case like this, the business owner hasn’t done anything reckless by normal standards. Most of the time the action the client took was exactly what these tools are built to encourage: think out loud, get organized, move fast. But in the process the actual facts of a live legal matter were input into a third party’s system, creating a written record of the client’s own theory of the case, and possibly weakening the very protections that were supposed to keep all of that private.

This is happening constantly right now, and most business owners have no idea about the value they may be losing.

I wrote an article earlier this year about whether your AI prompts are even confidential in the first place, and the short answer was no, not in the way you’d hope. This is the follow-up, because there’s a harder problem sitting underneath that one. It isn’t just that your AI chats may never have been protected. It’s that running a legal matter through AI can strip away protection you already had.

A couple of years ago, “I asked AI about it” wasn’t a sentence anyone said about a legal matter. Now it’s pretty commonplace. The available tools are genuinely useful, they’re inexpensive, and they feel like a private space.

It feels like talking to yourself, but in many cases that couldn’t be further from the truth. This misunderstanding of reality is causing two separate risk issues to business owners.

Problem one: confidentiality

The first risk is the one I covered before, so I’ll keep it short. When you put confidential information into a consumer-grade AI tool, you may be handing it to a third party. Depending on the tool and the settings, your inputs can be stored, reviewed by humans, and used to train future models. This is most likely the case if you’re using free or low-cost consumer tiers. Business and enterprise tiers usually come with much stronger commitments about not training on or retaining your data. That difference is not marketing fluff. It is the whole ballgame, and most people have no idea which version they’re actually using.

For ordinary confidential business information, that alone is worth pausing over. For anything tied to a legal matter, there’s a second problem stacked on top, and it’s the one that doesn’t get talked about enough.

Problem two: privilege

Attorney-client privilege protects confidential communications between you and your lawyer. It is one of the most powerful privileges, but it isn’t unbreakable. The general rule is that privilege protects information you keep confidential, and disclosing privileged information to a third party can waive that protection.

That’s the concern with consumer AI tools. If a court were to treat your input into a public AI tool as a disclosure to a third party, the argument follows that you may have waived privilege over that information. And once privilege is waived, the other side can potentially discover it.

This is relatively new ground, so I don’t want to overstate the risk. However, in U.S. v. Heppner a federal court found that inputs into a consumer AI tool weren’t confidential enough to be privileged, which is the case I walked through in the earlier article. What courts haven’t squarely worked out yet is the next step: whether taking material that was already privileged and running it through AI waives the protection you started with. That answer will depend on the specific tool, its terms, and the circumstances. So the honest version is not “you will lose your privilege.” It’s “you may be handing the other side a decent argument that you did, and you don’t want to be the test case.”

Think about what makes a conversation with your lawyer privileged from the get-go: you keep it confidential. Have that same conversation at full volume in a crowded coffee shop, and you can lose the protection, because you didn’t take reasonable steps to keep it private. Typing your case into a consumer AI tool is arguably worse than being overheard. You’re not getting caught by a stranger at the next table. You’re writing it down and handing it to the company that runs the tool.

There’s a related doctrine worth knowing about: work-product protection, which shields material prepared in anticipation of litigation. That’s exactly what you might be creating when you ask the AI to map out your weaknesses and the other side’s likely arguments. Work-product protection has its own waiver rules, but the practical point is the same. You created a document, and you created it somewhere you don’t control.

The chat history is a record

Here’s where this can get truly uncomfortable. When you talk to your lawyer, there’s no transcript sitting on a server somewhere with your candid assessment of how bad your position is. You might be thinking that your lawyer probably uses AI too, maybe a transcription or note-taking assistant on your calls. We do that at Fourscore. That is why the dividing line isn't whether a record exists. It's where that record sits. A transcript your lawyer creates with a vetted, confidential tool, as part of representing you, lives inside the privileged relationship and is handled accordingly. The chat history on your personal ChatGPT account does not. One is protected work done on your behalf. The other is your candid, unfiltered assessment of how bad your position is, typed into a third party's system with no lawyer in the room. 

That chat history is a record. If privilege is waived or never attached, that record can become discoverable in litigation. So the risk isn’t only that the other side learns the facts. It’s that they may get your unfiltered, pre-lawyer theory of the case, in your own words, including the parts you’d never write out and send to the other side if you’d realized that’s what you might have been doing.

None of this means AI is off-limits. I already mentioned that at Fourscore we use secure, business-tier AI tools in our own work, and they make us faster and sharper. The issue isn’t the technology. It’s matching the tool, and the setting, and the topic to the actual sensitivity of what you’re doing.

A few practical rules of thumb:

  • Separate the general from the specific. Asking a consumer tool “how do non-competes generally work in my state” is low risk. Pasting your actual non-compete, your employee’s name, and your plan to enforce it is not the same thing.

  • Know which tier you’re on. Free and consumer accounts and properly configured business or enterprise accounts are not the same product from a confidentiality standpoint. If you don’t know which one you’re using, take a few minutes right now to figure that out - or assume the more exposed one.

  • Treat a live matter differently. Once you’re in or anticipating a dispute, the rules change. That’s the moment to stop free-handing it and check with counsel before anything matter-related goes into a tool.

  • Don’t create written analysis of your own weaknesses in someone else’s system. If you wouldn’t email it to the other side, don’t type it into a tool whose retention and discoverability you can’t control.

  • When in doubt, ask first. A thirty-second question to your lawyer is cheaper than a waiver fight.

That last one is why we recently added language to our engagement letters asking clients not to put matter-related facts, documents, or queries into any AI tool without checking with us first. It’s not because we’re anti-AI. It’s because we’d rather have the awkward “please ask us first” conversation up front than the much worse “the other side has your chat logs” conversation later.

The bottom line

AI tools reward thinking out loud, but with legal matters you have to keep it quiet. That tension is the whole issue. So, be deliberate about what information you put into AI tools, know what kind of tool you’re actually using, and bring your lawyer into the loop before you do something that can’t be undone. Privilege and confidentiality are easy to keep and hard to get back. The tool that makes you faster shouldn’t be the thing that makes you discoverable.

If you’re not sure whether something is safe to run through AI, that uncertainty is the answer. Ask first.

About Fourscore Business Law

Whether you're launching a startup, raising capital, or navigating M&A, our experienced team provides strategic, world-class legal counsel that supports your vision and enables confident decision-making at every stage of growth. Fourscore Business Law empowers forward-thinking entrepreneurs and business leaders by simplifying complex legal transactions. With a focus on efficiency and personalized service, we help you overcome legal challenges so you can focus on innovation and scaling your business. Ready to secure your startup's future? Take our free legal assessment for founders today to better understand your company’s legal health.

Picture on the top is by Steve A Johnson and is in the public domain.

Next
Next

July Update: Client Happenings & Celebrations