RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 7, 2026

You Pasted It Into a Chatbot. Is It Still Privileged?

Privilege is not a property of a document. It is a claim about how a communication was made and kept, which means it can be lost by an operational detail nobody treated as a legal decision — a retention default, a sampling job, a hold notice that named four systems instead of five.

The short version. Two separate doctrines are at stake and they fail differently. Attorney-client privilege is fragile to disclosure and turns on confidentiality being maintained. Work-product protection is more robust to disclosure but has entry requirements — prepared by or for a party or its representative, in anticipation of litigation — that a lot of AI output never met.

Almost every real-world problem below is one of those two sentences applied to a system that was procured by someone who had never read either.

Four Moments Where It Breaks

01

The paste

A lawyer drops a draft settlement memo into a consumer AI account to tighten the language.

What the doctrine does with it

The consumer terms of a general-purpose assistant are not a confidentiality agreement. Where the provider may retain the content, have humans review it, and use it to improve the service, the disclosure looks less like handing a document to a retained agent and more like handing it to a stranger who is allowed to keep it.

What survives

Work-product protection often survives this better than privilege does, because the test is whether the disclosure substantially increased the risk of the adversary getting it — but only if the memo qualified as work product in the first place.

02

The business-side draft

A product manager asks an internal assistant to summarise the legal risk of a launch, then forwards the summary to counsel.

What the doctrine does with it

Privilege attaches to communications for the purpose of obtaining legal advice, not to every document that discusses law. A risk summary generated by a non-lawyer, from a model, before counsel was involved is a business record. Forwarding it to a lawyer afterwards does not retroactively wrap it in privilege.

What survives

What is protected is counsel's subsequent advice about it. The underlying model output stays what it always was: a discoverable business document that now also reads as notice of the risk.

03

The eval dataset

Six months later, an ML team samples real assistant conversations to measure output quality. Privileged threads are in the sample.

What the doctrine does with it

This is the disclosure nobody logged. The content leaves the system where access controls were designed for it and lands in a dataset shared across an engineering org, frequently copied to a notebook, a spreadsheet and a shared drive. Confidentiality is assessed on what actually happened to the material, not on the access-control diagram drawn when the feature shipped.

What survives

Very little, cleanly. This is why the eval and fine-tuning pipeline belongs in the privilege conversation even though it feels like an engineering concern.

04

The hold that missed a system

Litigation begins. The hold notice covers email, chat and the document store. It does not name the AI assistant's prompt history or the vendor's logs.

What the doctrine does with it

Preservation duties attach to relevant material within a party's possession, custody or control, and control is a practical question — data a vendor holds for you under contract is frequently within it. A retention window that silently deletes prompt history on a 30-day cycle keeps running through the hold.

What survives

The privilege question becomes secondary to a spoliation question, which is a far worse conversation to have.

The Agent Analogy, and Where It Runs Out

The strongest argument for AI tooling being privilege-compatible is old and well-established: privilege extends to third parties engaged to assist counsel in providing legal advice. Translators, accountants retained through counsel, e-discovery vendors, testifying support staff — the doctrine has never required that only the lawyer and the client touch the material.

That analogy holds when the tool is engaged the way those vendors are engaged: under a written agreement, for the purpose of assisting with legal advice, with confidentiality obligations and defined use restrictions. It runs out in three specific places, and each one is a procurement fact rather than a legal one.

  • The engagement is missing. A tool adopted by an individual on a personal or self-serve plan has no agreement running to the firm or the company, which makes the assisting-counsel framing hard to assert after the fact.
  • The purpose is missing. A general-purpose assistant used across sales, support and engineering is not engaged to assist in the rendering of legal advice, and its use in one legal thread does not change what it was procured for.
  • The confidentiality is nominal. Terms that permit content to be used for service improvement, reviewed by human raters, or retained indefinitely undercut the claim that confidentiality was maintained, whatever the marketing page says.

What the Privilege Log Has to Say About a Model

A log entry has to describe a withheld document specifically enough that the other side can test the claim without seeing the content. The fields that get awkward with AI in the chain are author, recipient and date.

Author

A model is an instrument, not a person. The defensible entry names the human who directed the work and adopted the output; treating the tool as the author invites a challenge that no human ever exercised legal judgment over it.

Recipients

The list is people, but the transmission history includes a provider. That is a custody fact, and if the confidentiality basis is contested it is the fact that gets litigated.

Date

Anticipation of litigation is a timing question. A draft that was generated as part of routine analysis and revised for litigation later has two dates and only one of them supports the claim.

The Preservation Problem Is Bigger Than the Privilege Problem

Waiver arguments are at least arguments. Spoliation is a different category of trouble, and AI systems are unusually good at producing it by accident, because the retention behaviour is a product decision made for cost and latency reasons.

When a hold issues, the systems that hold potentially relevant material now routinely include the assistant's conversation history, the prompt-caching layer, the vendor's request logs, the vector index built from internal documents, and the evaluation dataset sampled from real usage. Most hold templates were written before any of those existed. The remediation is unglamorous: enumerate the AI systems in the data map, confirm who controls the retention switch for each, and add them to the template rather than remembering them case by case.

A Policy That Actually Changes Behaviour

Blanket prohibitions on AI use fail the same way blanket prohibitions on personal cloud storage failed: the work still needs doing, so the tool moves off the managed account and out of visibility. The version that holds up separates the decision into tiers people can apply without calling anyone.

  1. Name the approved instance. One enterprise tenant, under an agreement that addresses confidentiality, use, retention, subprocessors and notice on legal process. Everything else is a personal tool and is treated as public.
  2. Draw the line at identifiable matter facts. Asking a model to explain a doctrine is not a disclosure. Pasting the client's settlement position is. Most staff can apply that distinction; very few can apply "use good judgment".
  3. Exclude legal workspaces from sampling. The eval and fine-tuning pipeline needs an exclusion list, and it needs to be enforced in the pipeline rather than in a policy document.
  4. Put the AI systems in the hold template. Named, with an owner, with a documented way to suspend deletion.
  5. Record adoption. Where a model contributed to a document later claimed as work product, a contemporaneous record that a lawyer directed and reviewed it is worth far more than a reconstruction two years later.

Where This Gets Contested

Opposing counsel asks whether any third party had access to the withheld communications.

This is the question that turns a vendor relationship into a privilege fight. The answer you want is a written agreement, a configuration that matched it, and a provider whose staff could not read the content. The answer you do not want is that nobody knows which account was used.

The tool was self-serve and paid for on an expense report.

Then there is no agreement running to the organisation, and the assisting-counsel framing has nothing to rest on. This is the single most common fact pattern and the cheapest one to fix in advance, because it is a procurement problem rather than a legal one.

The output was generated before anyone anticipated litigation.

Then work-product protection likely never attached, and asserting it invites a challenge that draws attention to the document. Some material is simply an ordinary business record that has to be produced, and the strategic error is claiming otherwise.

A hold issued but prompt history had already rolled off.

The analysis shifts from waiver to preservation: when the duty attached, whether the material was within the party's control, what steps were taken once the duty was known. Documenting that the retention was suspended promptly on the systems still holding data is the mitigation available at that point.

Related Reading

Check What Your Site Promises About Confidentiality

Firm and vendor sites carry absolute statements — everything you share stays confidential, your data is never used for training, all communications are privileged — written before the assistant, the prompt log and the eval pipeline existed.

See every confidentiality, privacy and compliance claim on your site in one pass. Run a free scan and check each one against how your tools actually handle text.

This article is general information and not legal advice. Privilege and work-product doctrine vary by jurisdiction and by whether federal or state rules apply, and outcomes turn heavily on specific facts. Consult qualified counsel before relying on any conclusion here.