✒️ Blog / The profession

AI and Attorney-Client Privilege: What Happens When the Machine Sees the File

The privilege question is not whether the AI is a lawyer. It is whether the disclosure destroyed the confidentiality that privilege requires — and a February 2026 ruling is the first court to say it clearly.

Every lawyer who has run client material through an AI tool has asked the same question: did I just waive the privilege? The instinct is right, and the answer is more precise than the fear. Using AI does not automatically waive privilege. Disclosing client information to a third party that can retain, train on, or share it — that is what destroys the confidentiality the privilege requires. In February 2026, a federal court in New York became the first to apply that framework squarely to AI. This article walks through the doctrine, the ruling, and what it means for how you use these tools.

It is the doctrinal companion to our earlier piece on where your client's data goes — that article covered the chain of custody and the practical checklist; this one covers the law.

The elements privilege rests on

The attorney-client privilege protects confidential communications between a lawyer and client made for the purpose of obtaining legal advice. Three elements matter for the AI question:

  • Confidentiality. The communication must be made with a reasonable expectation that it stays private. This is the element AI tests hardest.
  • The relationship. The communication must be with a lawyer — a licensed professional in a trusting relationship. An AI tool is not a lawyer and cannot form an attorney-client relationship.
  • The purpose. The communication must be for the purpose of obtaining legal advice, not something else.

The general rule that flows from the first element: disclosure to a third party waives the privilege, unless the disclosure was necessary to obtain legal advice or the third party is functioning as the lawyer's agent. That is the rule that has governed translators, accountants, and consultants for decades, and it is the rule courts are now applying to AI.

The Kovel doctrine and the agent question

There is a well-known exception. Under the Kovel doctrine, privilege survives when a third party is necessary to facilitate the lawyer's legal advice — the classic cases are translators and accountants working at the lawyer's direction, functioning as an extension of the lawyer. Courts have also protected disclosure to vendors that are the functional equivalent of in-house staff, working under the lawyer's control with confidentiality guaranteed.

This is where the AI analysis gets honest. No court has held that a general-purpose AI vendor is a Kovel-style necessary intermediary. A consumer chatbot is not a translator or an accountant; it is a software service. Whether the agent exception could ever protect an AI arrangement will depend on facts no consumer tool provides: the vendor acting at the lawyer's direction, bound by confidentiality, with the client's material not used for anything else. The safe assumption for every AI tool is the default rule: the vendor is a third party, and disclosure to it is waiver risk unless the arrangement is structured to protect confidentiality.

The first ruling on point: United States v. Heppner

In February 2026, Judge Jed Rakoff of the Southern District of New York decided the question in United States v. Heppnereppner — described by the court as a "nationwide" matter of first impression: whether communications with a publicly available AI platform during a pending criminal investigation are protected by privilege or work product.

The facts: a criminal defendant, aware he was a target of a federal investigation, used a consumer AI platform on his own — not at his lawyers' direction — to organize and synthesize information for his defense. The government seized 31 AI-generated documents, and his lawyers asserted privilege over them. Judge Rakoff ruled they were not protected, and his reasoning is the template for the whole field:

  • No attorney-client relationship. The AI tool is not a lawyer. Its own terms disclaimed that it provides legal advice.
  • No reasonable expectation of confidentiality. The platform's privacy policy disclosed that user inputs and outputs could be used for model training and disclosed to third parties. Under those terms, the communications were not confidential — and this finding rested on the tool's actual data practices, not on the mere fact that a third party was involved.
  • Not for the purpose of obtaining legal advice. Heppner used the tool to organize his own thoughts, independently of counsel.
  • No work product protection. The materials were not prepared at counsel's direction, so they did not reflect counsel's strategy.

The court was careful to say the ruling was not a new anti-AI rule: it applied "longstanding legal principles" to a new intermediary. It even noted the result might have differed had counsel directed the client's use of the tool. The lesson of Heppner is precise: the privilege failed because the disclosure channel was not confidential — the platform trained on inputs and reserved the right to share them — not because the tool was an AI.

"The tool did not waive the privilege. The disclosure through a channel that trained on the client's file did. That distinction is the whole ballgame."

What the ethics opinions say

The ethics framework has been consistent since ABA Formal Opinion 512 (July 2024), which held that generative AI is governed by the existing rules: competence (Rule 1.1), confidentiality (Rule 1.6), candor to the tribunal (Rule 3.3), and supervision (Rules 5.1 and 5.3). On confidentiality, the opinion requires reasonable efforts to protect client information — which, applied to AI, means evaluating the tool's data practices before use and declining to use tools that cannot keep client material confidential.

State bars have said the same thing. North Carolina's 2024 Formal Ethics Opinion 1 — the first comprehensive state treatment — holds that a lawyer may use AI if it is used competently, securely, and with proper supervision. It applies Rule 1.6(c)'s "reasonable efforts" standard to the choice of AI tools, applies Rule 5.3 to third-party AI providers, and adds a pointed note: whether sharing information with an AI tool violates the attorney-client privilege is a legal question outside the ethics rules, and the lawyer should research and resolve privilege questions before engaging a third-party AI program with client-specific information.

Notice what the ethics opinions do not say: they do not say AI use is unethical, and they do not say AI use waives privilege. They say the opposite — that the lawyer remains in control, and the obligations adapt to the tool. The privilege risk is a function of how the tool handles the data, which the lawyer can and must investigate.

The practical test: three questions before you paste

Before client material goes into any AI tool, ask three questions — they map exactly onto the elements the courts and opinions care about:

  1. Can the vendor see it? Does the provider's policy allow training on inputs, retention beyond the session, or disclosure to third parties? If yes, the expectation of confidentiality is already undermined — the Heppner fact pattern.
  2. Is there a contract that says otherwise? Enterprise agreements with no-training and no-disclosure commitments change the analysis materially. Consumer terms almost never provide these protections.
  3. Is the tool acting as your agent, or as an independent service? If the tool is an independent service that reuses your data, it is a third party for waiver purposes. If it processes locally, retains nothing, and shares nothing, the third-party disclosure that drives the waiver analysis simply does not happen.

Local processing and the architecture answer

This is where the architecture argument gets concrete. The privilege risk is a disclosure risk: it exists because client material leaves the firm and enters a system that may retain, train on, or share it. A tool that processes everything on the lawyer's own machine — no cloud, no vendor, no training on client data, nothing retained after the session — removes the disclosure that the waiver analysis depends on. That does not make the lawyer's other duties disappear: competence and supervision apply to every tool, local or cloud. But it removes the single risk that the courts have actually enforced: the client's file ending up in a system the client never agreed to share it with.

What Lawyer Assistant does about this

Lawyer Assistant is built on exactly this logic. It runs entirely on your machine — documents, queries, and results never leave your computer. There is no vendor with access to your files, no training on your data, no cloud retention. The Rule 1.6 half of the confidentiality problem is handled by architecture rather than by a promise in a privacy policy. That is not a claim that privilege is automatic — privilege is a legal conclusion for a court to reach, and no software can guarantee it. It is a claim that the disclosure risk the courts have enforced is designed out of the system. The competence and supervision duties remain yours, as they always are.

The bottom line

The privilege question has a clear answer, and it is not the scary one. Using AI does not waive the privilege; disclosing client information through a channel that is not confidential does. Heppner is the first court to say so on the record: the tool's terms — training on inputs, sharing with third parties — defeated the expectation of confidentiality. The ethics opinions say the rest: the lawyer must evaluate the tool, keep control, and resolve privilege questions before client data goes in. A tool that never sees the data in a way that can be shared, trained on, or retained is a tool that takes the waiver question off the table — which is the entire design philosophy behind Lawyer Assistant.

Sources & further reading

This article is general information about technology and professional practice. It is not legal advice for any specific matter, and rules vary by jurisdiction — verify against the authority applicable to your matter.

Questions, answered

The key questions from this article, answered plainly.

Does using an AI tool waive the attorney-client privilege?

Not automatically. Waiver turns on whether the disclosure destroyed the confidentiality that privilege requires. The first ruling on point — United States v. Heppner (S.D.N.Y. 2026) — applied traditional principles: a consumer AI platform whose privacy policy allowed training on inputs and disclosure to third parties defeated any reasonable expectation of confidentiality, so no privilege attached. The tool did not waive privilege; the disclosure through an unsecured channel did.

What makes client data shared with an AI tool confidential enough to protect privilege?

The same things that protect it with any third-party vendor: a contractual commitment that the provider will not use the data to train models or share it, technical security that prevents unauthorized access, and an arrangement where the provider functions like an agent of the lawyer. Tools whose terms allow training on inputs, disclosure to third parties, or retention for other purposes are the ones that destroy the expectation of confidentiality — exactly what happened in Heppner.

What is the Kovel doctrine, and does it protect AI vendors?

The Kovel doctrine protects privilege when a third party is necessary to facilitate the lawyer's legal advice — the classic examples are translators and accountants. Courts have not held that a general-purpose AI vendor is a necessary intermediary in that sense, and the safer assumption is that consumer AI tools are ordinary third parties: disclosure to them is waiver risk unless the arrangement is structured with confidentiality protections.

What does ABA Formal Opinion 512 require for confidentiality?

Model Rule 1.6 requires reasonable efforts to prevent disclosure of information relating to the representation. Applied to AI, that means evaluating the tool's data practices before use — whether inputs are used for training, whether they are shared, how they are secured — and declining to use tools that cannot protect client information. North Carolina's 2024 ethics opinion makes the same point: competence (Rule 1.1), confidentiality (Rule 1.6(c)), and supervision (Rule 5.3) all apply to AI.

If the AI runs locally on my machine, is the privilege question different?

Yes, in practice. The privilege risk is a disclosure risk: it comes from sending client material to a third party that may retain, train on, or share it. A tool that processes everything locally, sends nothing to a vendor, and stores nothing in the cloud eliminates the third-party disclosure that drives the waiver analysis. The ethics analysis still applies — competence and supervision never go away — but the confidentiality half of the problem is handled by architecture.

Filed under The profession · Privilege · Confidentiality ← All articles
Next steps

Put it to work on your own documents.

Lawyer Assistant runs entirely on your machine — install it in minutes, read the documentation, or browse more notes from the Legal Desk.