Confidentiality and Privilege
What Actually Happens to the Text You Paste
When client material goes into a hosted AI tool, it leaves the firm and is processed on infrastructure the firm does not control. What happens next is determined by the contract, not by the interface. The material may be transmitted and discarded, logged for a retention period, reviewed by humans for safety or quality purposes, used to improve the service, or retained indefinitely under general terms. Consumer and free tiers of general-purpose assistants have historically had the most permissive terms, often including use of inputs for model improvement. Enterprise agreements typically exclude training use, commit to defined retention, and offer contractual confidentiality — but those protections come from the specific agreement, and assuming them without reading is the recurring error.
- The interface tells you nothing about data handling — the contract determines it
- Consumer and free tiers have historically had the most permissive terms, often including training use
- Enterprise agreements typically exclude training and define retention, but only if negotiated and read
- Human review for safety or quality is a common term and is a confidentiality question in its own right
- In the US, ABA Model Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorised disclosure of client information
Consumer Versus Enterprise Is the Load-Bearing Distinction
The same underlying model can be available under radically different terms. A practitioner using a free consumer assistant and a colleague using the same vendor's enterprise offering are in materially different positions on retention, training use, human review, geographic processing, and audit rights — with no difference in what the screen looks like. This is why "we use an approved AI vendor" is not a sufficient control: the approval must attach to a specific product tier under a specific agreement. Firms should maintain an approved-tools list identified at that level of precision, and should expect that personal accounts will be used unless the sanctioned route is at least as convenient as the unsanctioned one.
- The same model under different tiers gives materially different confidentiality positions
- Approve specific product tiers under specific agreements, never a vendor in the abstract
- The screen looks identical, so users cannot tell which position they are in — the firm must
- Shadow use follows friction: if the approved route is slower, personal accounts will fill the gap
Privilege, Waiver, and the Honest Uncertainty
Whether disclosing privileged material to an AI vendor risks waiver is an area where the law is developing and answers differ by jurisdiction. Reasoning by analogy to established practice — privilege is generally not waived by disclosure to agents engaged to assist in providing legal services, subject to confidentiality — suggests a properly contracted enterprise arrangement is in a defensible position, while pasting privileged material into a consumer tool with training rights is plainly weaker. But this is analogy, not settled authority in most places, and the conservative course is to avoid creating the test case. Where material is genuinely sensitive, consider minimisation, redaction, or self-hosted options rather than relying on an untested argument.
- Waiver analysis for AI vendors is developing and jurisdiction-dependent — treat confident answers with caution
- Analogy to agents assisting in legal services supports a contracted enterprise arrangement
- Consumer tools with training rights sit in a much weaker position on any analysis
- Prefer minimisation, redaction, or self-hosting for the most sensitive material over an untested argument
Practical Controls That Work
A few measures do most of the work. Minimise what you send: much AI-assisted work can be done on redacted or abstracted material, and a clause analysis rarely needs party names. Match the tool to the sensitivity tier rather than approving one tool for everything. Read the actual terms on retention, training use, human review, sub-processors, and geographic processing, and get the important ones into a negotiated agreement rather than relying on published policy that the vendor can revise. Prohibit personal accounts for client work in clear terms, and then make the approved path genuinely convenient, because the effectiveness of the prohibition depends almost entirely on that second half.
- Minimise and redact — a great deal of useful work does not need identifying detail
- Tier tools by sensitivity rather than approving one tool for all client material
- Get retention, training exclusion, human review, sub-processors, and location into the agreement
- Ban personal accounts and then make the sanctioned route fast enough that the ban holds
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.