Privilege, Confidentiality and AI: What Changes When a Document Leaves Your Control
Privilege does not survive on good intentions
The question a lawyer should ask before putting client material into any AI system is not “is this tool secure?” It is narrower and harder: who, other than me, is now in a position to read this, and what happens if someone later argues that it was disclosed?
Attorney-client privilege protects confidential communications made for the purpose of legal advice. Confidentiality is not a mood; it is a condition. Disclosure to a third party can waive it, and the fact that the disclosure was inadvertent, or made to a machine, is an argument rather than an answer.
That is the frame for this piece. Not fear of AI — precision about what changes when a document leaves your control.
Three distinct duties, often confused
Confidentiality under the rules of professional conduct is broad: it covers information relating to the representation, whatever its source, and it applies whether or not the material is privileged.
Privilege is narrower and is an evidentiary doctrine. It protects certain communications from compelled disclosure, and it can be waived.
Work product protects material prepared in anticipation of litigation, with its own rules and its own waiver analysis.
An AI tool can implicate all three at once, and the analysis is not the same for each. A summary of a client’s account of events may be confidential, privileged and work product simultaneously.
What actually happens to a document
When you paste or upload material to a hosted service, ask these in order:
- Where is it processed, and where is it stored? Processing and retention are different questions with different answers.
- How long is it retained, and can you require deletion?
- Is it used to train or improve a model? A contractual “no” is meaningfully different from an absence of a promise.
- Who can access it? Support staff, subprocessors, and anyone responding to a subpoena directed at the vendor.
- What happens in litigation against the vendor, or on their insolvency? Your client’s material is an asset in someone else’s dispute.
- Can you produce an answer to all of the above if opposing counsel asks how the document was handled?
That last one is the practical test. Not whether the vendor is trustworthy — whether you can describe the arrangement precisely enough to defend it.
The case for local processing, made narrowly
For a great deal of legal work, a reputable hosted service under a proper agreement is a reasonable choice, and treating every cloud tool as reckless is not a serious position.
But there is a category where it is genuinely different: material under a protective order, sealed records, criminal defence files, medical records, matters involving third parties who never chose to be in your case. For those, the strongest available answer to “who else could read this?” is nobody, because it never left our infrastructure.
That is why local, air-gapped processing matters in this field. Not because hosted services are dangerous in general, but because for some matters, the only defensible answer is the one that requires no trust in a third party at all.
Client consent, and when to ask
Two situations argue for telling the client and getting agreement:
- Where the engagement or the client’s own policies address it. Corporate clients increasingly do.
- Where the material is unusually sensitive, or the client would obviously care.
Some courts are pushing in the same direction from the other end. At least one federal standing order’s own example of an acceptable AI certification recites that the party was advised of and consented to the use — see AI certification in the District of Colorado. A conversation had at the start of the matter is far easier than one had after a filing.
A workable firm position
- Classify by matter, not by tool. Decide which categories of material may go to a hosted service and which may not, and write it down.
- Keep a short list of approved tools, with a note of what was agreed with each vendor and when.
- Record the decision. If asked in two years how a document was handled, a contemporaneous note is worth far more than a recollection.
- Prefer tools that can run locally for the sensitive categories, so that the policy is enforceable rather than aspirational.
- Review annually. Vendor terms change, and a policy written against last year’s terms is a document about the past.
The connection to verification
There is a link between confidentiality and accuracy that is easy to miss. A tool that shows you exactly which document and which page an answer came from is also a tool that tells you exactly what material it processed. Opacity about reasoning and opacity about data handling tend to travel together — and a system you cannot audit on one is rarely auditable on the other.
How COAPP treats this
COAPP is built so that appellate work on a sealed or protected record can be done without the record leaving your environment: local processing on hardware you control, with no external API calls, alongside the cloud option for matters where that is appropriate. Every generated section is attributed to the record documents it drew from, so what the system read is as visible as what it produced.
The choice between those two modes is a legal judgement about the matter, not a technical preference — which is why it should be made deliberately, and recorded, at the point the file is opened.