Introduction
The rapid adoption of artificial intelligence tools across the legal profession raises fundamental questions relating to confidentiality and legal professional privilege (LPP). Generative AI systems are now routinely deployed for many tasks, including research, drafting and document review (and there is an enormous level of further investment in legal AI tools). Yet the very architecture of these systems—their data handling, training practices, and access controls—could mean that privileged material input into an AI tool loses its protected status. Any breach of confidentiality which led to a loss of privilege would not only expose the lawyer to potential claims from the client, but may also carry regulatory and data protection consequences.
There is currently limited guidance from the courts on this issue. The Upper Tribunal in UK and R (Munir) v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC); [2026] 4 WLR 37 held that uploading confidential documents into an open-source AI tool such as ChatGPT places information in the public domain, waiving privilege.[1] In April 2026, the Chancellor of the High Court, Sir Colin Birss, delivered a significant speech which considered this issue.[2] There are decisions of the courts in other jurisdictions that take a different approach and suggest that using even open AI would not lead to a loss of privilege.
This article begins with the “data journey” that any input takes through an AI system—how a provider may use the data, whether inputs are retained, and whether they are used to train the model—because it is that journey, rather than any single label, that is likely to determine the effect on privilege. It then sets out the essentials of privilege before applying them to AI in three settings of increasing difficulty: the lawyer who uses a confidential, closed system as a research tool; the use of open-source or public systems, where the limits of confidentiality are tested; and the distinct question whether AI-generated advice can itself attract privilege, including where AI is used by litigants in person. It closes with the data protection, regulatory and practical implications for practitioners.
2. The Data Journey: How AI Systems Handle User Inputs
In any generative AI system, the input is passed to and processed by a Large Language Model (“LLM”). That may be done directly through an interface operated by the owner of the LLM (for example ChatGPT for OpenAI or Claude for Anthropic). It may also be done through a third-party provider (such as Harvey or Legora in the legal market), many of which make no secret of using external LLM providers to process queries. Although the input is usually encrypted in transit, it must be decrypted so that the model can process it: whatever the transport security, the LLM necessarily has access to the input in cleartext. The protection for confidential material therefore lies not in the technology of transmission but in the contractual terms that govern what the provider may do with the input once it has it.
What happens to or may happen to the data which is processed by the LLM depends on the contractual relationship between the party making the request (which for most legal AI products will be the legal AI provider and not the end-user) and the LLM.
At one end of the spectrum are open or public systems. Most free-to-use AI systems offer no promises about the security of data once it is entered, which means the data may (though not necessarily will) be retained, used by the provider, and/or used to train the LLM. As the Chancellor of the High Court explained in his speech, when the Judicial Guidance on the use of AI was first introduced it was clear that with many public systems, such as the public version of ChatGPT, the data would not be secure, so that transferring confidential data to the LLM risked breaching the UK GDPR. The data could also be retained and used to train the model, leaving it, at least in theory, exposed to others and hence no longer confidential.
At the other end are closed or secure systems. Fully closed systems could involve an LLM running either on local hardware or in a private cloud. Sharing data with such a system would not involve transferring the data to any third party. Such a setup is uncommon for lawyers, at least at the moment; as set out above, most legal AI providers share data with LLM providers. Nevertheless, these systems are still regarded as “closed.” The protection is contractual: the LLM providers are prohibited from storing or using inputs to train or improve the model, and from disclosing inputs to third parties except where that is essential to delivering the service, and the user can require deletion of the data on request. A contractual promise of “no retention” should, however, be verified in practice, because logging, caching and agentic features can cause inputs to persist at the provider or sub-processor level even where the headline terms suggest otherwise.
3. Legal Professional Privilege and Confidentiality
The two types of privilege are well known. Legal advice privilege (LAP) protects confidential communications between lawyer and client for the dominant purpose of giving or obtaining legal advice, understood broadly across the “continuum” of communications recognised in Balabel v Air India [1988] Ch 317. Litigation privilege (LP) protects confidential communications with lawyers or third parties whose dominant purpose relates to the conduct of litigation that is in progress or reasonably in contemplation. In both cases the privilege belongs to the client and not the lawyer, so the lawyer is not authorised to waive it. Privilege is a fundamental right and a necessary corollary of the rule of law (see R v Derby Magistrates’ Court, ex p B [1996] AC 487; Three Rivers District Council v Bank of England (No 6) [2004] UKHL 48; [2005] 1 AC 610), which is why an inadvertent loss of privilege through careless use of AI is so serious.
Confidentiality is an essential pre-requisite for privilege to attach: a communication must be made in confidence and must remain confidential to stay protected. It does not follow, however, that any disclosure to a third party destroys privilege. Disclosure waives privilege only where it results in a loss of confidentiality; where confidentiality is preserved by an express or implied obligation restricting the recipient’s use of the material, privilege survives (see, for example FM Capital Partners Ltd v Marino [2018] EWHC 1768 (Comm)). Material may therefore be disclosed to a third party on terms as to confidentiality which preserve privilege, and a limited disclosure for a particular purpose need not amount to a general waiver (see SFO v Eurasian Natural Resources Corp Ltd [2018] EWCA Civ 2006; [2019] 1 WLR 791).
4. Privilege and AI
How do the principles governing whether LPP exists and is preserved apply to AI systems?
Closed systems
Take first the clearest case: an AI system that is entirely closed to the outside world—for example a locally hosted model with no access to the internet, or a properly secured enterprise deployment with a LLM running locally. Would privilege apply to the lawyer’s use of it, and if so, why? Seemingly it would, in just the same way as when a lawyer consults a textbook. The reason is that the lawyer’s use of the software is an intrinsic part of, and would evidence, either the giving of legal advice within the Balabel continuum (for LAP) or involvement in litigation (for LP). Nor should the claim to privilege be defeated by the fact that a ring-fenced AI response has, to some degree, “a life of its own.” The output is an input to the lawyer’s advice, not a communication to a third party; its probabilistic or generative character does not change its function within the privileged relationship. This is the view expressed by the Chancellor, “it is hard to see how that could have an impact on privilege,” the privilege being the client’s and the lawyer being entitled to consult other sources of legal knowledge, whether textbooks in paper or online.
Does it matter if the LLM is not hosted locally but uses a third-party provider (such as OpenAI) but with no data-retention or training of the model? Again, this should not be problematic to the maintenance of confidentiality and privilege. The data is being shared with the third party on specific terms as to confidentiality and there is no intention that the information will be shared more widely.
Open systems
The decision of the Upper Tribunal in Munir is, at present, the clearest English statement. At [60] the Tribunal held that “[u]ploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege.” Two points nevertheless limit the utility of the decision. First, the observation was directed at the paradigm public tool that retains inputs and trains on them; it is best read as fact-specific rather than as a rule that all use of AI waives privilege. Second, the privilege point arose in a decision principally concerned with hallucinations and supervision and does not appear to have been the subject of full argument. The Chancellor’s view was more nuanced. He observed that “there may be more to be said about the precise factual position of information entered into these public systems,” and that the matter is fact sensitive.
It is at this point that the distinction between “open” and “closed” systems ceases to be as useful as it first seems. If, for example, ChatGPT is used under a paid subscription that, among other things, offers a contractual guarantee that prompts will not be retained and the model will not be trained on the inputs, is that materially different from a “closed” system? It is hard to see why it would be. So far as sharing data with the LLM is concerned, the critical distinction is between retention and use of the data on the one hand and mere processing on the other, not whether the system is labelled open or closed.
The more precise course is to ask two questions: (i) are the inputs retained? and (ii) are the inputs used to train the LLM? If the answer to each is “no”, privilege is likely to be preserved, whatever the system is called.
Is sharing data with an LLM publication to a third party?
This analysis presupposes that inputting data into an LLM without any protections is the same as publishing the data, hence it loses confidentiality (which was the conclusion of the Upper Tribunal in Munir).
There is, however, a respectable counter-argument that has not yet been tested by the Court, namely that allowing material to be processed by an open-source generative tool is not the same as publishing it to the world. Confidentiality is a question of degree and of audience.
In the case of an input to an LLM, the user does not expect that their data will be published; the concern is that it may be used to train the model, even though the outputs given to other users will not ordinarily reproduce the input in any discernible way. On one view this is no different from a lawyer drawing, in later matters, on experience derived from confidential information seen in earlier ones—something never regarded as publication or a loss of confidence. Why, on this argument, should an LLM be treated differently? The analogy has force, but it is not without difficulty. Unlike a lawyer’s memory, the LLM is operated by a separate legal person that comes to hold the data, which is a disclosure a memory is not; modern models can in some circumstances reproduce training data, so the assumption that inputs will never surface in outputs cannot be guaranteed; and a lawyer’s recollection is governed by the lawyer’s own duty of confidence.
There is caselaw in the US that supports both sides of this argument, albeit the cases focus on the “work-product” doctrine[3]. In United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. 2026), the court took a Munir-like bright line, holding that neither attorney-client privilege nor the work-product doctrine applied to prompts and outputs from a public version of Claude. By contrast, in Warner v. Gilbarco, 820 F. Supp. 3d 629 (E.D. Mich. 2026), Inc. and Archie Morgan v. V2X, No. 25-CV-01991 (D. Colo. Mar. 30, 2026), Inc. the courts held that work-product protection could apply, treating AI as “a tool, not a person” for waiver purposes, and reasoning that it was “highly unlikely” a provider’s data would reach the opposing party—analogising the provider to an internet service provider holding a user’s email.
These cases suggest an “acid test” that English law might borrow, and one that maps onto the domestic touchstone of confidentiality: does the information retain “the necessary quality of confidence,” in the sense that the adversary seeking disclosure does not know it and could never realistically come to know it? The email analogy drawn in the Archie Morgan case—that information held by an intermediary such as an internet service provider does not thereby lose its confidential character—is of assistance in building the argument that privilege would not be lost, even when using a truly open AI tool.
Nevertheless, this is not, at least at present, the position in English law, and it would be prudent to assume that using an LLM without a contractual assurance that inputs will not be retained or used to train the model will amount to a waiver of privilege.
Even if privilege is not lost, legal professionals owe duties of confidentiality that extend to the tools and systems they deploy. Using a third-party AI service that lacks adequate contractual and technical safeguards is inconsistent with those duties; the position is analogous to sending privileged material to an unsecured outsourcing provider. The safeguards identified above—no retention, no training, no third-party disclosure save where essential, and a deletion right—are the practical measure of compliance.
Can AI be an adviser?
A distinct and more radical question is whether AI-generated advice could itself attract privilege, as though the machine were the adviser. This arises when AI is used by litigants in person but may also arise if a client uses generative AI to check work-product produced by a lawyer.
The Chancellor noted that courts are seeing more AI-assisted material from unrepresented litigants and observed that, in one sense, this is pro-access to justice: the case is often presented more clearly than it once would have been.
Interactions between an individual and anyone other than a lawyer do not, without more, attract privilege[4]. Yet a conceptual puzzle remains. If a litigant in person seeks advice from a lawyer, the advice attracts privilege; if they ask the same question of an AI system and receive the same answer, there is none. Is there any rationale for treating the AI as a “lawyer”? The Chancellor touches on this, noting that the courts have not yet extended privilege to a person’s interactions with other professionals. At a superficial level that makes sense: there are fundamental differences between advice from a regulated lawyer and output from an AI system. But as AI providers become more sophisticated and their output more reliable, the distinction may become harder to maintain. Providers such as Garfield expressly seek to handle smaller cases in place of lawyers, yet on the current law the client would have no privilege at all.
This illustrates the potential issue. Privilege attaches to communications with a recognised professional adviser—a legal person owing professional duties—which is precisely what an AI system is not. A 2025 Law Commission discussion paper[5] considers whether ascribing legal personality to AI systems might answer some of these questions, while identifying the numerous difficulties such a step would create; any move in that direction would require primary legislation. Unless and until that happens, the better view is that AI is a tool used by a lawyer or client, not an adviser in its own right, and it is the confidentiality of that use, rather than any privilege in the machine’s “advice,” that matters.
5. Conclusion
The intersection of privilege and AI is, at bottom, a question about confidentiality and the journey that data takes through a system. The lesson of the Chancellor’s speech and of Munir is that the data journey matters: a system that does not retain, train on, or expose user inputs is likely to preserve the confidentiality on which privilege depends, while a public system that does the opposite destroys it. That said, the current nomenclature of “open” and “closed” systems are blunt labels. The better analysis looks at data retention and model training.
Caution nonetheless remains essential. The law is developing rapidly and across jurisdictions; the factual and contractual position of any given platform requires case-by-case scrutiny; and the consequences of error are severe—waiver of privilege, breach of confidence, regulatory referral and notification to the ICO. Properly focused AI in the hands of professionals is, as the Upper Tribunal accepted in Munir, “a step forward” and it is inevitable that this will become an intrinsic part of legal practice. To do so, clear rules are needed for the safe and responsible use of AI.
4 New Square, London
[1] UTJs Lindsley, Keith, and Blundell, handed down on 17 November 2025.
[2] “Legal professional privilege in the Age of AI,” speech to the City of London Law Society, 22/24 April 2026.
[3] The US work-product doctrine (Federal Rules of Civil Procedure, Rule 26(b)(3)) is not the same as privilege. Nevertheless, the same reasoning could be applied to the privilege issues.
[4] R (Prudential plc) v Special Commissioners of Income Tax [2013] UKSC 1; [2013] 2 AC 185.
[5] “AI and the Law: Discussion Paper”, 31 July 2025.

