A wax-sealed document rests on the surface of a geological cross-section labeled "what the doctrine inspects," while a red fissure runs down from beneath it through strata of text, then chunks, then scattered vector points, then rows of ghosted file icons, splitting open in the dark bottom layer beside the caption "where it breaks."

From Inside the Deployments

Where Privilege Breaks

Attorney-client privilege rests on a confidentiality that most AI deployments quietly dissolve, at a layer of the system that sits below anything the doctrine was written to inspect. A procedural walk through where the protection survives, where it fails, and why those turn out to be two different questions.


A privileged document does not stay in the room anymore. Some version of it goes out over an API, into a system the firm does not own. It gets turned into a form no lawyer would recognize as a document at all, and comes back as a summary, a classification, a flag. This happens thousands of times a day now in litigation support, due diligence, and internal investigations, and most of the time nobody stops to ask what the passage out and back has cost. The question worth working through is narrow and mechanical. When a document protected by privilege moves through a modern AI deployment, what protection survives the trip, and what has quietly been spent along the way?

Two doctrines, two tests

Before following the document anywhere, it helps to have in hand the two rules it is going to be measured against, because they are not the same rule and they do not break under the same conditions.

Attorney-client privilege protects confidential communications between a lawyer and a client made to obtain or provide legal advice. It belongs to the client. Its entire operation depends on confidentiality, which means the protection exists only for as long as the communication stays inside the privileged relationship. Disclosure to a third party outside that relationship generally waives it. The privilege is, in this sense, brittle by design. It was built to be given up the moment the client lets an outsider in, because the thing it protects is the confidence between lawyer and client, and a confidence shared with a stranger has already stopped being one.

Work product protection covers a different thing and breaks under different conditions. Codified for federal civil litigation at Rule 26(b)(3), it shields materials prepared in anticipation of litigation, and its purpose is to keep an attorney's preparation out of an opponent's hands. The waiver standard follows from that purpose. Work product is not waived by disclosure to just anyone. It is waived by disclosure to an adversary, or by disclosure in a manner that substantially increases the likelihood the material will reach an adversary. Hand your litigation analysis to a neutral third party who is under an obligation to keep it in confidence, and you have probably not waived work product, because you have not handed it to the other side. The doctrine also runs in two tiers, with ordinary fact work product more exposed, and opinion work product, the attorney's mental impressions and legal theories, protected to a degree that comes close to absolute.

Those two waiver standards, one triggered by any outside disclosure and the other only by adversarial disclosure, are the reason the same deployment can waive one protection while preserving the other. They are worth keeping distinct from the outset. Most of the confusion in this area comes from collapsing them into a single question about whether "AI waives privilege," when in fact there are two questions here and they have two different answers.

Following the document

Take one privileged document and follow it through a representative deployment, the kind I help stand up for document review and internal investigations. The architecture varies from vendor to vendor, but the shape is consistent enough to trace, and each stage in it either aggravates or contains the confidentiality problem that the first stage creates.

The first thing that happens is the thing that matters most for privilege, and it is easy to overlook precisely because it looks like nothing. The document leaves the firm's environment. In practice that is an API call or an upload, which means the bytes travel to servers the vendor operates. From the moment they arrive, a copy of the confidential material exists in the custody of someone who is neither the lawyer nor the client. Whether that arrival counts as a privilege-destroying disclosure to a third party is the question everything downstream then sharpens, and the answer turns less on anything technical than on the legal relationship between the firm and the vendor, and on what the vendor is contractually permitted to do with what it now holds.

What the system does next is decompose the document. It is split into chunks, passages of a few hundred words, and each chunk is converted into an embedding. An embedding is a long vector of numbers that encodes the passage's meaning rather than its literal text, so that a later search for indemnification can surface a clause about holding a party harmless that never uses the word. It is tempting to think the embedding launders the confidentiality problem, on the theory that a list of floating-point numbers is not readable as a document. It does not. The embedding is a derivative of the privileged content, generated from it and faithful to its meaning, and it is stored, usually in a vector index that persists so the corpus can be queried again and again. A representation of the confidential material now lives in the vendor's storage. The fact that it is held as geometry rather than as prose changes nothing about whose hands it is in.

When a question is put to that corpus, the system retrieves the chunks nearest to it in meaning and passes them, as text, into the model along with the prompt. At this step the plaintext of the privileged passages is present in the vendor's inference systems, held in the model's working context for the duration of the computation, and depending on how the deployment is configured that plaintext may also be written to logs.

Most platforms retain prompts and outputs for some period, for abuse monitoring, for debugging, or for product improvement. The length of that retention, and whether the retained material can be read by the vendor's staff or used to train future models, is set by the service tier and the contract, not by anything the lawyer does at the keyboard. Enterprise arrangements commonly include zero-retention terms, under which inputs are neither persisted nor used for training. Consumer tiers commonly include close to the opposite. Two lawyers running the identical task through the identical model can therefore stand in completely different positions on confidentiality depending only on which agreement sits behind their access, and nothing in the output they see will tell them which position they are in.

On the tiers that permit it, the submitted content can be used to improve the model, which means the confidential material has been folded into a system whose future behavior is shaped by it and exposed, in diffuse and unpredictable form, to everyone who later uses that system. Formal Opinion 512 flags this hazard directly: the possibility that one client's information, absorbed by a shared tool, resurfaces in another matter. It is the confidentiality version of a problem I have written about elsewhere in this series, where what a system learns accrues to the system rather than to any person. There the thing the system kept was skill. Here the thing it keeps is a secret.

One further layer usually sits beneath all of this. The vendor frequently runs on cloud infrastructure it does not own and relies on subcontractors of its own. Each of those is another set of hands the material passes through, governed by another layer of contract that almost nobody in the matter has read.

The document returns to counsel as a summary or a set of flags. By the time it does, a copy or a derivative of it has rested in, at minimum, the vendor's ingestion systems, its vector store, and its inference servers, and possibly its logs, its training pipeline, and its subprocessors' machines. The lawyer sees the last step in that sequence. The waiver questions live almost entirely in the steps the lawyer never sees.

Why the protections come apart

Run the two tests against that pipeline and they come apart in a way that turns out to be the practical center of the whole problem.

For attorney-client privilege, the operative event is the first one, the transmission out of the firm. If the vendor is a third party outside the privileged relationship, and the material is a confidential communication for legal advice, then that transmission is the kind of outside disclosure the privilege does not survive. The technical elaboration downstream, the embeddings and the retention and the training, does not so much create the waiver as deepen and document it, multiplying the copies and lengthening the time the material sits beyond the client's control. Privilege behaves close to binary here. One qualifying disclosure spends it, and most of the pipeline is disclosure.

There is an obvious objection to that, and a court has already made it. If sending a document to a model waives privilege because the model's operator is a third party, then so does drafting in a cloud-hosted word processor, routing mail through a hosted inbox, or running a query on a legal research platform, since each of those hands the same confidential material to a company with administrators and compliance obligations of its own. Read at full strength, the transmission theory would strip privilege from nearly every tool a modern lawyer touches, which is not the law and is not going to become the law. Judge Patti made a version of the point in Warner, warning that treating the mere use of a tool as disclosure would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed. Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629, 634 (E.D. Mich. 2026).

The objection is right that transmission alone cannot be the test, and it points at what the real test is. Privilege turns on whether the client's expectation of confidentiality survived, not on whether the bytes left the building. A vendor bound by contract not to read, retain, disclose, or train on the material sits inside that expectation in roughly the way a copy service or a cloud host under a confidentiality agreement does, and transmission to it need not waive. A consumer tool whose own terms permit it to collect, retain, and disclose what it receives sits outside that expectation, and transmission to it does. That is the line Heppner drew when it reached the question: the court rested its confidentiality holding on the platform's privacy terms, which let the operator treat the input as non-confidential, rather than on the bare fact that the defendant had used software. So the operative event is still the transmission, but what turns it into a waiving event is the absence of a confidentiality obligation on the other side, which sends the whole question back to the terms of service and the tier, and to the clause almost nobody in the matter has read.

Work product bends the same objection into an easier answer, because its standard was never about any disclosure but only about adversarial disclosure. A vendor processing litigation materials under a confidentiality obligation is not an adversary, and is not, on its own, a channel likely to deliver the materials to one. On that reasoning, routing work product through a controlled deployment need not waive it. The exposure returns at the edges. A consumer tier whose terms permit the vendor to retain, disclose, or train on the input, or a public tool that carries no confidentiality commitment at all, starts to resemble a channel that substantially raises the odds the material escapes toward an adversary. And the two-tier structure means fact work product will be more vulnerable to that argument than the core opinion work product a court will strain to keep protected.

Set the two side by side and the divergence is the thing to hold onto. The identical act, sending a document to a model, can waive the privilege outright while leaving work product intact, because the two doctrines are asking different questions about the same event. A deployment designed only to capture efficiency, with no attention to which protection is actually in play, will tend to spend the fragile one to save time on tasks where the durable one was all that had ever been at risk.

Two cases, read as an experiment

The first federal decisions to work through this arrived in early 2026, and they are most useful read together, because between them they hold the technology roughly constant and vary the legal circumstances, which is about as close as the law comes to a controlled test.

In United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. 2026), decided by Judge Rakoff and treated as a question of first impression, a represented defendant had used a consumer AI assistant on his own initiative to generate documents that he later shared with counsel. The court found that neither privilege nor work product protected the material, and the reasoning tracks the framework above almost node for node. The threshold problem was that the communications were not with an attorney. The tool is not a lawyer and cannot furnish legal advice, so the exchange was never the lawyer-client communication the privilege exists to protect. The confidentiality analysis only deepened the hole. The material had been shared outside the attorney-client relationship, and the platform's own terms let the operator collect, retain, and disclose what it received, which is the contract layer doing much of the work. The court declined to treat the tool as a privileged intermediary under United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), the doctrine that extends privilege to a translator or an accountant whose help counsel needs in order to serve the client, because the assistant was not necessary to counsel's understanding and, most importantly, had been engaged by the client alone rather than at counsel's direction. Heppner, 820 F. Supp. 3d at 297. And privilege could not attach after the fact, so handing the output to a lawyer later did not reach back and protect what had already been disclosed. Work product failed for a related reason, that the documents had not been prepared by counsel or at counsel's direction. Id. at 297-99.

In Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629 (E.D. Mich. 2026), decided the same week, a self-represented plaintiff had leaned heavily on a public chatbot to prepare her case, and the defense moved to compel everything about that use. The decision is a magistrate judge's discovery order, and the court disposed of the motion as untimely before it reached the AI question at all. It reached the question anyway, and on that alternative ground held the work product protection intact. As a pro se litigant the plaintiff was her own counsel, so materials she prepared for trial could qualify as work product, and the defense's waiver theory, that sharing with the chatbot was disclosure to a third party, ran into the work product standard rather than the privilege standard. Disclosure to a third party can waive privilege, the court reasoned, but work product is waived only by disclosure to an adversary or in a manner likely to deliver it to one, and generative AI programs are, in the court's phrase, tools, not persons. Using one had not placed the material in the opponent's path. Warner, 820 F. Supp. 3d at 634.

The instinct to read these as contradictory results is worth resisting, because the more exact reading is that they are consistent applications of two doctrines with different waiver rules. Heppner lost on privilege because privilege breaks on outside disclosure, and a consumer tool with non-confidential terms is the outside. Warner kept work product because work product breaks on adversarial disclosure, and a chatbot, whatever else it is, was not the adversary. The variables that moved the outcomes are exactly the ones the framework predicts should matter: which protection was asserted, whether the use was directed by counsel, and what the tool's terms allowed. The technology was nearly identical in both. The law diverged because the questions did. It is worth noting that Heppner itself reached for Kovel on the way to its result, gesturing at the same open door this essay returns to at the end. The court allowed that a tool used at counsel's direction might one day be argued inside the doctrine, though this defendant was nowhere near that case. Heppner, 820 F. Supp. 3d at 297.

The clause that decides it

The single feature that most often determines which way any of this goes is the one least likely to have been read by anyone in the matter, and here I will speak from the deployments directly rather than in the abstract. When I stand up one of these systems, the document that governs whether client confidentiality survives is not a brief and not an engagement letter. It is the service agreement and the data-handling terms between the firm and the vendor. Those terms fix whether inputs are retained and for how long. They fix who at the vendor may access them, whether they feed model training, which subprocessors touch them, and what happens to all of it when the contract ends. That agreement, and the tier of service it reflects, does more to fix the privilege outcome than anything that happens in the legal analysis. And it is routinely signed by procurement or IT, on a timeline that has nothing to do with the matters that will later run through it, and read afterward by neither the lawyers who will rely on it nor the clients whose confidences depend on it.

This sits awkwardly against the way the profession pictures confidentiality being protected. The working model is that a diligent lawyer, exercising judgment, keeps the client's confidence. The mechanism that actually keeps or loses that confidence, inside a deployed system, is a data-retention clause negotiated well out of sight of the practice of law, at a layer of the stack the doctrine never contemplated because the doctrine predates the stack. The confidentiality that privilege presupposes has been relocated into an infrastructure decision, and the people making that decision are frequently not the people the duty runs to.

Three failure surfaces, not one

There is a further complication that the case law, focused as it is on evidentiary privilege, only partly brings to the surface, and it matters because it means that passing the privilege test is not the same as being safe.

The evidentiary privilege is one question. The ethical duty of confidentiality is a second, and a broader one. Under Model Rule 1.6, as Formal Opinion 512 works it through for these tools, a lawyer's duty runs to all information relating to the representation, not only to privileged communications. It obligates the lawyer to understand how a given tool handles client data, to secure the client's informed consent where the tool's use calls for it, and, under Rule 5.3, to supervise the vendor as a nonlawyer assistant. That opinion also warns that consent of this kind cannot be manufactured out of boilerplate buried in an engagement letter, which is the shortcut most firms will reach for first. Work product is a third question again, with its own adversary-focused standard.

The three do not move together, and that is the point. A deployment can preserve the evidentiary privilege, because it runs on an enterprise tier with genuine confidentiality terms, and still breach the ethical duty, because the lawyer never understood the data handling or obtained any meaningful consent. A deployment can waive privilege while leaving opinion work product standing. And a lawyer can expose client information in a way that satisfies every evidentiary test and still violates Rule 1.6, because that information was protected as a matter of professional duty whether or not it would ever have been privileged in a courtroom. Treating these as one question, which the shorthand of "does AI waive privilege" quietly encourages, is how a firm talks itself into confidence that it has cleared a bar it never actually tested against.

What has not been decided

Most of the privilege exposure in a deployment is, in principle, designable. Enterprise agreements with zero retention, use that is directed by counsel, confidentiality terms that are documented rather than assumed, and consent that is real rather than boilerplate all move a system a long way toward preserving what the doctrine protects. That is worth doing, and it is not where the difficulty is. The difficulty is in the questions the 2026 cases open without closing, and those are the ones worth carrying around unresolved rather than answering too quickly.

There is the question of where the line actually falls, for work product, between a tool that functions as a safe intermediary and a tool that substantially increases the likelihood of adversarial access. A private, contractually bound enterprise model and an open public chatbot are the easy poles. The deployments most firms actually run sit somewhere in the middle, on terms that permit some retention and some access under some conditions, and no one yet knows how much permitted exposure it takes to turn a helpful tool into a waiver.

There is the question of whether a properly constructed deployment could ever qualify as a Kovel intermediary and extend the privilege rather than break it, if the tool were genuinely necessary to counsel's work and used at counsel's direction under real confidentiality. The courts so far have rejected that argument on facts where those conditions were plainly absent, and Heppner went out of its way to leave the door open. They have not yet been handed a deployment engineered specifically to satisfy them, and it remains open whether a doctrine built for human translators and accountants will stretch to accommodate a model or refuse to.

There is the question of the waiver safety net. Federal Rule of Evidence 502 protects a holder against waiver flowing from an inadvertent disclosure, provided the holder took reasonable steps to prevent it and to correct it. But routing a document to a vendor is a deliberate act rather than an inadvertent one, which leaves it genuinely unsettled whether the rule that rescues a lawyer who accidentally produces a privileged file offers anything at all to a lawyer who intentionally fed one into a system without understanding where it would travel.

There is the question of which standard the profession will actually organize itself around, the evidentiary or the ethical, given that they can be satisfied independently. It is possible to build systems that pass in court and still fail the client, and it is possible to comply with the ethics rules in a way that is procedural rather than real, a signed consent form standing in for an actual understanding. Which of those becomes the operative standard will be settled less by doctrine than by what firms, regulators, and clients decide to demand.

And underneath all of them is a question the waiver framework does not reach, because it is not a waiver question at all. Privilege and confidentiality are legal proxies for something the client actually cares about, which is the expectation that what they tell their lawyer stays between them and their lawyer. A deployment can satisfy every doctrinal test and still change the honest answer to that expectation, because the material now moves through systems the client never pictured and never agreed to, governed by terms the client never saw. Whether a lawyer owes the client a say in that, before the document ever leaves the room, is a question the cases have not yet been asked.