Photo by Mohamed Marey, Unsplash
Protecting Client Privilege in the Age of AI
Client legal privilege existed long before lawyers had to warn clients about how using AI could affect it. Lawyers know that an anxious client may feel tempted to run the facts of their dispute, or even their legal documents, through AI and ask questions about parts that could damage their case. Many clients don’t realise that using AI in this way can be harmful in itself.
First, let’s discuss what client privilege is, why client legal privilege matters, and how to avoid losing client privilege when using AI.
What is client privilege?
- It gives a client (individual or corporation) confidence to disclose all relevant information about their situation when seeking legal advice or services.
- The right to privilege can be relied upon to resist compulsory disclosure.
You can claim privilege for communications that are confidential or prepared for or in anticipation of litigation.
When privilege is lost
In Australia, client privilege can be lost in these ways:
1. Inconsistency: If a client behaves in a way that is inconsistent with keeping a communication confidential, they waive privilege. In Cooper v Hobbs [2013], the client gave evidence about a lawyer's advice and then tried to claim privilege over that same advice. That inconsistency destroyed privilege.
2. Disclosure: A client waives privilege if they knowingly and voluntarily disclose a privileged communication. One common example is sending a solicitor’s report to a third party. In Asahi Holdings (Australia) Pty Ltd v Pacific Equity Partners Pty Limited [2014], the client sent a communication to an insurer and enclosed the solicitor's report on the matter, which resulted in a loss of privilege over that report.
3. Substance: Disclosing the substance of advice supplied, for example, a summary of solicitor advice, can also cause a loss of client privilege, even if they do not hand over the full document. For example, summarising a solicitor’s advice in an internal email or report may waive privilege over that advice: Fenwick v Wambo Coal Pty Ltd (No 2) [2011].
Privilege and AI
If emails can waive client legal privilege, what happens when a client uses artificial intelligence tools?
In United States v. Heppner, a New York court held that exchanges between a criminal defendant and the generative AI platform Claude did not invoke the attorney–client privilege.
Despite the complexity of AI technology, simple client privilege principles still apply:
1. When does privilege apply? Privilege applies to confidential communications between a client and their lawyer for the dominant purpose of obtaining legal advice or legal representation. Claude is not a lawyer, so communications with Claude do not automatically attract privilege.
2. Are AI communications confidential? The court considered that Claude did not treat user communications as confidential, because it uses user inputs and outputs to train its AI model. Many clients believe that ticking a “keep my data private” box is enough, but there are real questions about how providers manage, store and use that data, and who polices compliance.
3. What is the purpose of using AI? The client in Heppner did not use Claude to obtain legal advice from a qualified lawyer, nor did they use it under the direction of legal counsel. To highlight this principle, the Government asked Claude for legal advice; Claude responded that it could not provide legal advice.
The Heppner case raises many broader issues about AI and legal practice, but for privilege, these are the key takeaways. You can read more about Heppner here.
What does safer AI use look like?
A blanket client warning like “never put anything about your case online or in any AI platform” does not reflect how most clients now search for legal information. Many clients rely on online research, including AI tools, whether lawyers like it or not.
Safer AI use that protects client legal privilege and still supports informed decision‑making may adopt these principles:
1. Use AI for general legal research only: Clients can safely use AI to research general principles of law, key legal concepts, and to identify relevant case names, provided they do not share facts that identify their own matter.
2. Verify AI legal content: Clients should treat AI legal outputs with caution. They must check the jurisdiction for any case law research and confirm whether the decision comes from Australia or another country. Overseas decisions, such as the US case above, might highlight emerging practice-area treatment, but Australian courts may not adopt the same reasoning. AI tools also have a known risk of generating fictitious case citations (sometimes called “hallucinations”).
3. Never enter case‑specific details: Clients should not enter specific facts about their matter, including party names, dates, locations, contract terms or other identifying details. Sharing those details with an AI platform can risk waiving client legal privilege in later disputes or litigation.
Conclusion
Technology will continue to evolve and can be a valuable tool for both clients and lawyers, but it should be used with care. Just as you would not share your case details with anyone other than your lawyer, you should approach AI with the same caution, even if you feel reassured by a box stating that your data will not be shared publicly. AI is not your lawyer, and using it inappropriately could waive client–lawyer privilege. As always, if you have questions or need clarification, please reach out for legal advice.
