Protecting Attorney-Client Privilege and Work Product in the Age of Generative AI

For centuries, the attorney-client privilege has served as the bedrock of the legal profession, ensuring that a client can speak candidly to their counsel without fear that those disclosures will be used against them in court. It is a sanctuary of confidentiality designed to foster the honest exchange of information necessary for effective representation. However, that sanctuary is facing an unprecedented challenge from a new, invisible intermediary: generative artificial intelligence.

The risk isn’t necessarily the AI itself, but how it is accessed. As clients and lawyers alike integrate tools like ChatGPT, Claude, and Gemini into their workflows, they are inadvertently introducing a third party into a two-party conversation. When a client inputs sensitive legal queries or proprietary data into a public, consumer-grade AI tool, they may be doing more than seeking efficiency—they may be waiving their legal protections entirely.

Steve Puiszis, general counsel at the national law firm Hinshaw, recently highlighted these vulnerabilities in a discussion with Mealey’s Litigation Report: Artificial Intelligence. Puiszis warns that while the doctrines of attorney-client privilege and work product protection are well established, their application to generative AI is a “new development” that is only now beginning to be tested in the courts.

The ‘Third-Party’ Trap in Consumer AI

At the heart of the issue is the fundamental requirement of confidentiality. For attorney-client privilege to apply, the communication must be intended to be confidential and must remain so. In the eyes of the law, sharing a secret with a third party typically waives the privilege.

The 'Third-Party' Trap in Consumer AI
Protecting Attorney Client Privilege

Public AI tools often operate on a “training” model. When a user inputs a prompt, the data may be used to refine the model’s future responses. From a legal perspective, this transforms a private consultation into a data contribution to a commercial entity. If a client uses a public AI to draft a summary of a legal dispute before sending it to their lawyer, that summary—and the facts contained within it—could potentially be flagged as non-privileged because it was shared with a third-party AI provider.

Puiszis notes that this is particularly problematic with “consumer grade” tools. Unlike enterprise-level AI installations—which often include strict data silos and “no-training” clauses—public tools are designed for broad utility, not legal confidentiality. This creates a precarious gap where a client might believe they are using a tool to assist their lawyer, while actually exposing their most sensitive information to a corporate database.

Updating the Engagement Letter

Law firms are now scrambling to close this gap before it becomes a liability. The traditional engagement letter, which outlines the scope of representation and the duties of both parties, is becoming a primary tool for risk mitigation.

Updating the Engagement Letter
Protecting Attorney Public

According to Puiszis, firms are exploring new ways to alert clients to these risks. One emerging best practice is the inclusion of explicit warnings within engagement letters or via standalone communications, advising clients against the use of public AI tools for matters related to their legal representation. By doing so, firms are not only protecting the privilege but also establishing a record that the client was warned about the risks of data leakage.

This shift represents a broader change in the lawyer’s role. Counsel are no longer just legal advisors. they must now act as digital hygiene officers, guiding clients through the technical pitfalls of the modern software ecosystem to ensure that the legal strategy remains shielded from discovery.

Comparing AI Environments in Legal Practice

Not all AI is created equal. The level of risk depends heavily on the architecture of the tool being used. The following table outlines the primary differences between the tools clients might use and the secure environments firms are attempting to implement.

How Do Attorney-client Privilege And Work Product Doctrine Differ? – Courtroom Chronicles
Comparison of AI Tool Risks for Legal Privilege
Feature Public/Consumer AI Enterprise/Legal-Specific AI
Data Training Often used to train global models Typically opted-out of training
Confidentiality Third-party access possible Strict data silos/encryption
Privilege Risk High risk of waiver Lower risk; managed environment
Control Managed by AI provider Managed by firm/client agreement

The New Frontier of Discovery

The legal industry is moving toward a period of inevitable conflict. As generative AI becomes ubiquitous, the “discovery” phase of litigation—where parties exchange evidence—will likely expand to include AI prompts and outputs.

Opposing counsel may soon begin requesting the “prompt history” of a client or a law firm to determine what information was fed into an AI and whether that information was shared in a way that waived privilege. If a client used an AI to “brainstorm” a legal strategy, the resulting log of those prompts could become a goldmine for an adversary if a court rules that the use of the AI constituted a public disclosure.

Puiszis suggests that these parameters will be “hammered out” through a series of disputes and court rulings. We are currently in a window of ambiguity where the rules are being written in real-time. Until a definitive Supreme Court or appellate precedent is set, the safest course of action for legal professionals is a policy of extreme caution regarding any tool that does not guarantee absolute data isolation.

The stakes extend beyond a single case. If the courts decide that AI interactions are not privileged, it could fundamentally alter how clients interact with their lawyers, potentially chilling the open communication that is essential for a fair trial and robust legal defense.

Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. Readers should consult with a qualified legal professional regarding specific attorney-client privilege concerns and the use of AI in their practice.

The legal community now awaits further guidance from state bar associations and upcoming judicial opinions that will likely address the intersection of the Federal Rules of Civil Procedure and generative AI. These rulings will determine whether the “reasonable expectation of privacy” extends to the digital prompts of the 21st century.

Do you think AI prompts should be protected by attorney-client privilege? Share your thoughts in the comments or share this article with your professional network.

You may also like

Leave a Comment