PRZEWODNIK Społeczny

Generative AI and Attorney-Client Privilege

Entering client information into a generative AI tool does not automatically waive attorney-client privilege, but it can put confidentiality at risk when the tool's terms let the provider train on, retain or review inputs.

  • 4 minuty czytania
  • Ostatnia aktualizacja
Na tej stronie4 minuty czytania
  1. Przegląd
  2. Głębokie nurkowanie
  3. Wpływ strategiczny
  4. The Future of Generative AI and Attorney-Client Privilege
  5. Implementacja w świecie rzeczywistym
  6. Zagrożenia i poręcze
  7. Plan wdrożenia
  8. Odkrywaj dalej
  9. Często zadawane pytania

Przegląd

The safer position is using tools under enterprise terms that bar training, limit retention and restrict access, because both the ethical duty of confidentiality and a court's view of waiver depend on whether confidentiality was reasonably protected.

Głębokie nurkowanie

Three protections are often blurred together. Attorney-client privilege is an evidentiary rule shielding confidential communications between lawyer and client made to obtain or give legal advice. Work product protects materials prepared in anticipation of litigation. The ethical duty of confidentiality under Rule 1.6 is broader, covering all information relating to the representation, and requires reasonable efforts to prevent unauthorized disclosure. Privilege is generally waived by voluntary disclosure to a third party outside the privileged relationship. Courts have long accepted, however, that lawyers can use service providers such as email hosts, cloud storage and eDiscovery vendors without waiver when confidentiality is reasonably maintained. AI tools are likely to be analyzed similarly, which makes the vendor's terms central. Case law applying waiver doctrine specifically to AI prompts is still thin, so lawyers should not assume a favorable outcome. Risk rises when terms let the provider use inputs to train models, keep them indefinitely, or allow human reviewers to read them, because each undercuts a claim that the communication stayed confidential. Consumer versions of popular chatbots have generally allowed training on conversations by default unless users opt out, while business and API offerings typically do not. Litigation can also affect retention: in 2025, the court in The New York Times's copyright suit against OpenAI ordered the company, for a period, to preserve user chat logs, including ones users had deleted. Work product is harder to waive; disclosure generally waives it only if it substantially increases the chance that an adversary obtains the material. Clients raise a separate issue. When they discuss their legal problems with a chatbot before or instead of talking to counsel, those conversations are not communications with a lawyer and may be discoverable. A common misconception is that turning off chat history makes a consumer tool safe. It may limit training use, but providers often still retain data for a period for abuse monitoring.

Wpływ strategiczny

Ryzyko i bezpieczeństwo

Zarówno katastrofalne, jak i codzienne szkody spowodowane sztuczną inteligencją zależą od tego, kto rozumie ryzyko i kto może podjąć działania.

Jaśniejsze decyzje

Umiejętność korzystania z usług publicznych i zawodowych wpływa na to, czy silna polityka bezpieczeństwa jest politycznie możliwa.

Przebijanie się przez szum

Jasne wyjaśnienia ograniczają wpływ szumu, PR laboratoryjnego i niejasnego teatru etycznego.

The Future of Generative AI and Attorney-Client Privilege

Courts have only begun addressing how privilege and work product apply to AI prompts and outputs, and early decisions may differ by jurisdiction and facts. Commentators and some policymakers have discussed whether conversations with AI should receive special protection, but no such privilege currently exists. Meanwhile, vendors increasingly offer legal-industry terms, private deployments and zero-retention options, which make confidentiality easier to defend. Lawyers should expect more discovery requests aimed at AI chat logs, both their own and their clients', and more firms advising clients directly not to discuss their matters with consumer chatbots.

Implementacja w świecie rzeczywistym

A lawyer pastes a client's email about an internal investigation into a free consumer chatbot with default settings that allow training; even if privilege survives, the lawyer may have fallen short of the duty under Rule 1.6 to take reasonable measures to protect client information.

A firm licenses an AI tool under an enterprise agreement that specifies no training on customer data, a defined retention period, encryption and no vendor access without permission, and records that review in its vendor file.

A client works through the facts of a dispute with a consumer chatbot before calling a lawyer; those chats are communications with a third-party service, not with counsel, and may be discoverable.

Before running a sensitive matter through an AI tool, a lawyer removes client names and identifying details, reducing what would be exposed if the data were ever accessed.

Zagrożenia i poręcze

  • Traktowanie ryzyka egzystencjalnego jako science-fiction, choć łączy w sobie możliwości.

  • Mylenie bezpieczeństwa produktów powierzchniowych z wyrównaniem przy dużej autonomii.

  • Pozostawienie odbiorcom nieanglojęzycznym i nieeksperckim jedynie źródeł o niskiej jakości.

Plan wdrożenia

  1. Oddziel ryzyko szkód, niewłaściwego użycia i utraty kontroli/niewspółosiowości produktu.

  2. Zapytaj, jakie dowody zmieniłyby Twój pogląd na temat terminów i dotkliwości.

  3. Przedkładaj źródła pierwotne i konkretne oceny nad twierdzenia marketingowe.

  4. Zidentyfikuj jedną ścieżkę działania: karierę, politykę, finansowanie lub umiejętności – nie tylko świadomość.

Odkrywaj dalej

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Generative AI and Attorney-Client Privilege quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Rozpocznij quiz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Często zadawane pytania

What is Generative AI and Attorney-Client Privilege?

Entering client information into a generative AI tool does not automatically waive attorney-client privilege, but it can put confidentiality at risk when the tool's terms let the provider train on, retain or review inputs. The safer position is using tools under enterprise terms that bar training, limit retention and restrict access, because both the ethical duty of confidentiality and a court's view of waiver depend on whether confidentiality was reasonably protected.

Jaka ochrona obejmuje wszystkie informacje związane z reprezentacją, a nie tylko komunikację prawnika z klientem?

Zasada 1.6 poufności jest szersza niż przywilej, który obejmuje poufną komunikację w celu uzyskania porady prawnej, oraz produkt pracy, który obejmuje materiały procesowe.

Jak sądy na ogół traktują korzystanie przez prawników z dostawców usług, takich jak hosty poczty e-mail i usługi przechowywania w chmurze?

Sądy od dawna przyjmują, że korzystanie z takich dostawców nie oznacza zrzeczenia się przywilejów, jeśli poufność jest odpowiednio chroniona, a narzędzia sztucznej inteligencji będą prawdopodobnie analizowane w podobny sposób.

Które warunki dostawcy, według przewodnika, zwiększają poufność i ryzyko odstąpienia od umowy?

Każde z nich podważa twierdzenie, że komunikacja pozostała poufna. Inne opcje to środki ochronne.

Co sąd nakazał OpenAI zrobić w 2025 r. w pozwie dotyczącym praw autorskich złożonym przez The New York Times?

Nakaz zabezpieczenia pokazał, że postępowanie sądowe może unieważnić normalne praktyki dostawcy dotyczące usuwania, które mają znaczenie w przypadku wszelkich treści umieszczanych na czacie.

Kiedy zgodnie z przewodnikiem ujawnienie informacji zazwyczaj zrzeka się ochrony produktu roboczego?

Z produktu pracy trudniej jest zrezygnować niż z przywileju; zwykły test pyta, czy ujawnienie znacznie zwiększyło prawdopodobieństwo, że przeciwnik zdobędzie materiał.