Est.

Attorney-Client Privilege and AI: Which Deployment Models Actually Satisfy Bar Ethics Rules

Consumer AI tools' standard terms make client data retention indefensible under ethics rules.

Editor-at-Large · · 11 min read
Cover illustration for “Attorney-Client Privilege and AI: Which Deployment Models Actually Satisfy Bar Ethics Rules”
Private AI Use Cases and Configuration · October 5, 2026 · 11 min read · 2,466 words

Whether a lawyer can use a given AI tool ethically depends less on what the lawyer intends to do with it than on how the tool is built: where data travels, who can access it, and whether the vendor's business model depends on retaining or training on client inputs. That sounds technical, but it is the legal fact under Rule 1.6 and Rule 1.1 for any attorney who types client information into a generative AI system. This piece maps three deployment architectures, consumer-grade tools, enterprise agreements, and on-premise or private deployment, against the specific rule requirements each one must satisfy. The goal is a practical framework for evaluating a tool before client data ever reaches it, not a general caution about AI risk. A firm's internal policy, however well drafted, cannot substitute for understanding what the software itself does with the information it receives.

Rule 1.6, Rule 1.1, and client data entering an AI system

Rule 1.6 prohibits the unauthorized disclosure of information relating to the representation of a client, and that prohibition applies regardless of the medium carrying the information, whether paper, email, or a prompt window. Under the dominant reading of current ethics guidance, inputting client information into a tool whose terms permit retention, training, or third-party disclosure counts as a disclosure to a third party, whether or not the lawyer meant it that way. ABA Formal Opinion 512 requires lawyers to have adequate safeguards so that data entered into a generative AI tool is not susceptible to unauthorized disclosure. Where those safeguards are absent, the opinion requires informed client consent specific enough that the client actually understands what is happening to their information, and a line in a boilerplate engagement letter does not meet that bar.

Rule 1.1 supplies the competence half of the analysis. ABA Formal Opinion 512 treats understanding a generative AI tool's data practices, specifically how it stores inputs, and whether the vendor trains its models on that data, as a baseline component of technological competence. A lawyer using a tool has to know what kind of system it is, what data the system can see, and where that system tends to fail, in the same way a lawyer handling physical files has to know who has a key to the cabinet. Rules 5.1 and 5.3 extend these obligations past the individual lawyer: a firm's AI policy has to address generative AI directly, and supervising attorneys remain on the hook for how associates, paralegals, and other nonlawyer staff use these tools, even when that use happens outside the firm's own systems.

Both duties converge on a single question that resolves whether a given tool is defensible. Rule 1.6's safeguard requirement and Rule 1.1's competence duty both ask whether a lawyer can verify that the AI system is architecturally incapable of unauthorized disclosure, and its terms of service promising good behavior is not enough. A platform built on privacy-preserving architecture from the start, where client inputs never become accessible to the vendor for training or for other customers' outputs, satisfies that verification question more reliably than a tool that relies on a settings toggle or a contractual promise layered on top of an architecture designed without confidentiality as a priority.

The court split on whether using a consumer AI tool discloses privileged information to a third party

Courts are now confronting a question the ethics opinions raised in the abstract: is a consumer AI platform a neutral tool, comparable to a word processor, or is it a third party whose access to user inputs defeats privilege the moment a lawyer or litigant types something into it? The answer different courts have reached depends heavily on the specific platform's privacy policy and its underlying architecture. The split is a direct consequence of how differently these tools are built and documented.

On February 10, 2026, two federal courts ruled on this question the same day, and they reached opposite results. In the Southern District of New York, Judge Jed S. Rakoff held in United States v. Heppner that defendant Bradley Heppner's written exchanges with the consumer version of Claude were protected by neither attorney-client privilege nor the work product doctrine. Rakoff's bench ruling, later issued in writing on February 17, 2026, rested on three independent grounds: Claude is not a lawyer, so no attorney-client communication ever occurred; the platform's privacy policy defeated any reasonable expectation of confidentiality; and Heppner's purpose in using the tool was not to obtain legal advice from a system that disclaims the capacity to give it. Rakoff left a door open, however, acknowledging that the outcome might have differed had Heppner's own counsel directed him to use Claude as part of the representation, a scenario that raises the unresolved question of whether an AI system can function as a lawyer's agent under the right conditions. By May 7, 2026, a federal jury found Heppner guilty, and prosecutors introduced his unprivileged consumer AI prompts as evidence at trial.

Gilbarco, Inc.* There, a pro se litigant had used ChatGPT to answer legal questions and draft filings while representing herself, and the court held that her queries were protected by the work product doctrine. The court's reasoning treated disclosure to ChatGPT as fundamentally different from disclosure to a litigation adversary, describing AI systems as "tools, not persons, even if they may have administrators somewhere in the background," and concluding that the materials reflected the plaintiff's own litigation thought process.

Subsequent rulings have continued to turn on the same architectural and contractual details. In Morgan v. Morgan, an order on a motion to amend a protective order, the court wrote its own AI-specific provision: confidential information could not be entered into any AI platform unless the provider was contractually barred from using inputs for model training or from disclosing them to third parties except where necessary to deliver the service, and unless users retained the ability to delete all confidential data on request. That provision tracks the Warner outcome closely and signals that contractual data protections, not just the nature of the tool in the abstract, are what courts increasingly treat as decisive. In Texas, a June 3, 2026 ruling by Judge Grant Dorfman in the Texas Business Court case Tate* held that ChatGPT conversations prepared in anticipation of litigation fall within the state's work-product rule, Texas Rule of Civil Procedure 192.5(a)(1), reasoning that work product protections are typically waived by disclosure to an adversary, and sharing material with an AI tool does not fit that category.

The deployment model a lawyer or litigant chooses is frequently the fact the ruling turns on.

Consumer-grade AI tools' default data practices make confidential use indefensible under current ethics guidance

Free or personal-tier consumer AI tools are broadly unsuitable for handling client confidences under the dominant reading of current ethics guidance, because their standard terms of service do not guarantee confidentiality and often permit the vendor to train on whatever a user types in. When a lawyer pastes client information into a consumer-grade tool, the platform's privacy policy typically offers no contractual commitment to confidentiality, no prohibition on using that input for model training, and no guaranteed right to have the data deleted. Each of those three protections is something current ethics guidance treats as a baseline requirement before client information can safely enter a generative AI system, and consumer tools, by design, tend to offer none of them.

Heppner illustrates the consequence concretely. The consumer Claude platform's own terms were enough, in Judge Rakoff's analysis, to defeat any reasonable expectation of confidentiality in what Heppner typed into it, and the communications that resulted were introduced against him at trial once the jury returned its guilty verdict on May 7, 2026. That outcome did not depend on Heppner's subjective belief that his conversations were private. It depended on what the platform's architecture and policies actually permitted the vendor to do with his input.

The risk compounds when firms respond to this uncertainty by banning AI and failing to offer an approved alternative. Lawyers under deadline pressure, lacking a sanctioned tool, sometimes turn to free consumer platforms on personal devices, and once that happens, the firm has no visibility into where client data has gone. People often call that dynamic shadow AI usage, and it does not just create Rule 1.6 exposure for the individual lawyer. It layers a supervisory failure under the rules governing partner and managerial responsibility on top of the underlying confidentiality breach, since the firm can no longer attest to what systems its own people are using or what those systems do with the information they receive.

Enterprise agreements and purpose-built legal AI products move meaningfully up the architecture ladder from consumer tools. For lawyers asking whether there is a version of a familiar AI assistant where client data does not become training material, this is the first tier where the answer starts to be yes, with conditions. If a contract bars the vendor from training on user inputs and guarantees deletion on request, it substantially cuts the Rule 1.6 confidentiality risk that consumer tools carry by default. They do not eliminate that risk, and no court has yet ruled that enterprise-tier AI definitively preserves attorney-client privilege or work product protection.

What these agreements genuinely provide is a contractual basis for an argument that did not exist before: a commitment to confidentiality specific enough to support an arguable reasonable expectation of privacy in the communication, which is the threshold both the ethics opinions and several of the courts discussed above are actually applying. The NYC Bar's report and the protective order in Morgan both single out the same two contractual terms as the variables that matter most, a prohibition on training and an enforceable right to delete, and lawyers evaluating an enterprise product should look specifically for those two provisions.

What these agreements do not provide is certainty. No appellate court has yet addressed the enterprise-tier scenario directly, so the doctrinal question of whether an AI platform functions as a neutral tool or as a third party whose involvement defeats privilege remains open for enterprise deployments just as it does for consumer ones. A further risk persists even inside well-contracted enterprise and firm-hosted systems: where a platform has self-learning features, one client's information used to prompt the system can, in principle, influence outputs generated for a different client's matter, a cross-contamination risk that could breach confidentiality without either lawyer ever realizing it happened. So when courts weigh whether a platform operates as a tool or a third party, they are, in effect, evaluating its deployment architecture directly: a system engineered so that user inputs never train the underlying model or feed vendor analytics presents a different disclosure profile than one whose business model depends on retaining and learning from that data. Confidant AI is one example of a platform built around that distinction, structured so that client inputs are not used to train the underlying model or shared for vendor analytics, which places it in the category of tools the courts' own reasoning treats more favorably, though the unresolved appellate question applies to it as it does to every enterprise product in this tier.

On-premise and private LLM deployment as the strongest architectural argument for Rule 1.6 compliance

Diagram: Three Deployment Architectures, Three Risk Profiles. Visualizes: Visualize a ranked spectrum of three AI deployment architectures mapped against their Rule 1.6 compliance strength.

For a lawyer asking whether there is an AI assistant they can use without handing their data to an outside company at all, on-premise and private LLM deployment is the most direct answer available under current ethics guidance, because it removes third-party disclosure entirely rather than managing it contractually. When the model runs on infrastructure the firm itself controls, client data never traverses an external vendor's servers, and no outside operator sits anywhere in the processing loop. That is a structural fact about where the data physically sits, not a policy commitment that depends on a vendor's continued good behavior.

A recent Oregon formal opinion draws a distinction that matters here: in closed systems, a model runs on hardware the firm owns, inside the firm's own environment, but in other systems data leaves the firm's control by definition. In the former, data physically cannot leave, which answers the exact question Judge Rakoff's reasoning in Heppner and the ABA's ethics guidance both turn on: can the lawyer verify, rather than merely hope, that the information stays confidential.

Some on-premise AI products operate in this category, built on the premise that privacy has to be designed into the system from the ground up rather than bolted onto a cloud architecture afterward, so that client data remains inside boundaries the firm controls rather than passing through a third-party cloud provider's infrastructure. For a firm that needs AI capability without accepting the surveillance and disclosure risk that comes with sending data to an outside server, choosing this architecture is a deliberate, earned decision grounded in how the system is built.

On-premise deployment does not, on its own, resolve every ethical question a lawyer faces in using AI. It removes the architectural basis for third-party disclosure, but it does not remove the need for human review of outputs, firm-level governance over how the tool gets used, or the ongoing supervisory obligations Rules 5.1 and 5.3 impose on how subordinate lawyers and nonlawyer staff actually use the system day to day. On-premise architecture is a defensible foundation, not a substitute for judgment.

State bar opinions layering additional requirements on the ABA baseline for multi-jurisdiction firms

ABA Formal Opinion 512 sets a floor, and several state bars have already built stricter or more specific requirements on top of it. A deployment choice defensible in one jurisdiction may fall short in another. If firms practice across state lines, they cannot assume that satisfying the ABA's baseline guidance closes the inquiry everywhere they have lawyers licensed.

Florida Bar Opinion 24-1 places the research burden squarely on the individual lawyer, requiring affirmative investigation into an AI provider's data retention practices, its data sharing arrangements, and whether it uses self-learning features, before any client information touches the tool. The opinion does not allow a lawyer to rely on a vendor's own representations without independently confirming them. The New York City Bar's Formal Opinion 2025-6, issued in December, addresses related ground in the context of recording, transcribing, and summarizing client conversations with AI tools, a use case the Bar's later August 2026 opinion extended to non-client conversations as well, requiring consent from all parties to a call before any AI-assisted recording takes place.

For a firm operating in Florida, New York, and other jurisdictions simultaneously, these layered requirements mean the architectural standard this piece has traced from Rule 1.6 through on-premise deployment has to be reassessed against each state's specific guidance, with the lawyer, not the vendor, carrying the burden of confirming that the chosen architecture actually meets it.

Sources

  1. The Intersection of Artificial Intelligence, Privacy, and Privilege
  2. Formal Opinion 2026-2: Ethical Use of AI for Recording, Transcribing, and Summarizing Non-Client Conversations
  3. 2025 Edition FORMAL OPINION NO 2025-205 ARTIFICIAL INTELLIGENCE TOOLS Facts:
  4. Formal Opinion 2025-6: Ethical Issues Affecting Use of AI to Record, Transcribe, and Summarize Conversations with Clients
  5. United States v. Heppner Harvard Law Review

More in Private AI Use Cases and Configuration