Business Law

Avoiding Waiver of the Attorney-Client Privilege and Work Product Protection When Using Generative AI Tools

Author: Christina M. Chan

While attorneys are increasingly using artificial intelligence tools to assist with drafting, research, and analysis, the legal profession’s rapid integration of generative artificial intelligence raises a critical issue: whether disclosing client information to these tools risks waiving the attorney-client privilege and work product protections.

Guidance from the American Bar Association and the California State Bar, together with the recent federal court decision in United States v. Heppner, demonstrate a clear theme: absent appropriate safeguards, courts are likely to treat AI platforms as third parties for purposes of the attorney-client privilege and the work product doctrine. Below are some key guidelines on how to use AI tools while preserving these protections.

ABA Formal Opinion 512

In 2024, the American Bar Association issued Formal Opinion 512 regarding generative AI. While the opinion did not create any new rules addressing this topic, it emphasized that practitioners should be cognizant of their existing duties under the Model Rules when using AI tools.

Notably, application of Model Rule 1.6 (which imposes the duty to keep confidential all information relating to the representation of a client, regardless of its source, unless the client gives informed consent, disclosure is impliedly authorized to carry out the representation, or disclosure is permitted by an exception) requires practitioners to understand how AI tools handle data and assess whether client information could be disclosed, retained or used for AI model training. Before entering any client-related information into an AI tool, practitioners should assess the risk that the information could be disclosed or accessed by others, whether outside the firm or internally. This risk varies depending on the sensitivity of the information, the tool’s data practices and the safeguards in place. The opinion also highlights how self-learning AI systems present increased risks because user inputs may not remain isolated and may later emerge in another context. Because entering sensitive client information into certain tools could result in disclosure of such information beyond the attorney-client relationship, practitioners should avoid inputting sensitive client information unless they are confident it will remain protected.

Thus, at a minimum, when using these tools practitioners should review the AI provider’s Terms of Use, privacy policies and related contractual terms and policies of any generative AI tool they use to learn who has access to the information that they input into the tool, or consult with a colleague or external expert who has read and analyzed those terms and policies. This may require them to consult with IT professionals or cybersecurity experts to fully understand these terms and policies, as well as the manner in which generative AI tools use information. Additionally, practitioners may likely need to obtain a client’s informed consent, which means they must provide the client with a clear explanation of how the tool works, what data may be exposed and the potential consequences.

California State Bar’s Practical Guidance for the Use of Generative Artificial Intelligence

Similarly, the California State Bar has released practical guidance for practitioners in using generative AI tools. The guidance reinforces these concerns, particularly for attorneys practicing in California. To preserve the confidentiality of client information, practitioners should not input any confidential information of the client into any generative AI solution that lacks adequate confidentiality and security protections. The guidance directs practitioners to anonymize client information and avoid entering details that can be used to identify the client. Additionally, similar to ABA Formal Opinion 512, practitioners are instructed to review the Terms of Use or other information to determine how the AI tool uses inputs and ensure that the provider does not share inputted information with third parties or utilize the information for its own use in any manner, including to train or improve its product. This may involve consulting with IT professionals or cybersecurity experts to ensure that any AI system in which practitioners might input confidential client information adheres to stringent security, confidentiality and data retention protocols.

United States v. Heppner

The recent federal court decision in United States v. Heppner highlights the significant attorney-client privilege risks associated with using public generative AI tools in the legal context. Particularly, the court held that documents created as a result of defendant Heppner’s communications with a consumer AI platform were not protected by the attorney-client privilege because:

  1. The communications were with an AI tool, which is not an attorney;
  2. The documents were generated through a third-party AI platform that is not confidential (as the privacy policy clearly stated that information submitted may be subject to disclosure under their terms of service, including potential access by third parties or use of data for model training); and
  3. The defendant did not communicate with the AI platform for the purpose of obtaining legal advice.

To this last point, the court noted that had the defendant acted at the direction of their counsel, the communications arguably might have protected under the Kovel doctrine, assuming AI platform had acted in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege. (See United States v. Kovel (2d Cir. 1961) 296 F.2d 918.) However, because Heppner communicated with the AI platform by his own choice, what matters in determining whether the attorney-client privilege applies is whether Heppner intended to obtain legal advice from the AI tool, and not whether he subsequently shared the tool’s outputs with his counsel. Additionally, the AI tool specifically disclaims providing legal advice. The court also emphasized that non-privileged communications could not be transformed into privileged communications through the subsequent sharing of AI-generated materials with counsel.

Finally, with respect to the work product doctrine, the court concluded that the defendant’s AI-generated documents were not protected under the work-product doctrine because they were not created by or at the direction of counsel in anticipation of litigation or for trial, and they did not contain defense counsel’s legal strategy. Because counsel had not instructed Heppner to use the AI tool, neither Heppner nor the AI tool could be treated as counsel’s agents, and the AI-generated documents were not protected under the work product doctrine.

Practical Implications for Legal Practice

While AI tools can help practitioners work more efficiently, it is important to take adequate steps to protect against the risk of unintended disclosure. At a minimum, practitioners should avoid entering identifiable or sensitive client information into AI systems unless they have confirmed that adequate safeguards are in place. This includes reviewing vendor terms of service, understanding data retention policies, and ensuring that inputs will not be used to train the AI model or shared with others — which may likely involve consulting the firm’s IT professionals or cybersecurity experts. In some situations, informed client consent may be necessary, particularly where AI tools are used to generate client-specific legal strategies and documents. Additionally, since law firms are increasingly adopting internal policies governing AI use (which may mandate restricting access to approved platforms and requiring oversight for AI-assisted tasks), practitioners should be mindful to comply with such policies.

Absent careful consideration and appropriate safeguards, the use of AI tools may result in the loss of the attorney-client privilege and work-product protections. For now, the most prudent approach is to treat any AI tool as a potential third party.

Christina Chan is a content attorney for CEB Practitioner, where she collaborates with experienced attorneys to develop practical resources that provide attorneys with expert guidance and insights, helping them bridge the gap between legal research and real-world application.

A version of this article previously appeared on the Continuing Education of the Bar website. © The Regents of the University of California, 2025. Reprinted with permission. Click here to learn more about CEB’s legal research and CLE products and our commitment to service the California legal community.


Forgot Password

Enter the email associated with you account. You will then receive a link in your inbox to reset your password.

Personal Information

Select Section(s)

CLA Membership is $99 and includes one section. Additional sections are $99 each.

Payment