Gains:
- Ability to transfer the concepts of attorney-client privilege and confidential documents to the use of AI
- Ability to determine which documents can be processed in which tools with a classification scheme
- Ability to implement technical and contractual safeguards that prevent privilege from being impaired
Perhaps one of the most sensitive principles of law is the confidentiality of communication between the lawyer and his client. This confidentiality allows the client to tell his lawyer everything without hesitation and is the basis of a good defense. In the age of artificial intelligence (AI), this principle faces a new threat: entering a privileged or confidential document into an unsecured AI tool can undermine confidentiality, even leading to loss of attorney-client privilege in some cases. In this unit, we will learn to classify confidential and privileged documents, determine which document can be processed in which medium, and establish technical and contractual safeguards that protect privilege.
Let's clarify the terms. A confidential document is a document that must be kept confidential by the institution or client and must not be shared with unauthorized persons. Attorney-client privilege is the principle that communication between a lawyer and a client for legal consultancy purposes is protected and that it cannot be forced to be disclosed in a dispute. Waiver is the loss of this protection by disclosing confidential communications to a third party. Data assurance is a tool's contractual commitments such as not to use data in training, not to store it, not to share it with third parties. Document classification is the labeling of documents according to their sensitivity level.
Why Is Privilege At Risk?
The basis of privilege lies in the protection of confidentiality. When a privileged communication is disclosed to a third party, a court may rule that the communication is no longer considered confidential and therefore the privilege is lost. Entering a privileged document into an unsecured AI tool is technically transferring that document to a third party's (tool provider's) system. If the tool stores, processes, or uses data in model training, this may be considered a disclosure and privilege may become moot.
The second risk is contractual confidentiality: confidentiality commitments signed with the client or counterparty prohibit the document from being entered into unauthorized systems. The third risk is KVKK and data protection obligations (see Unit 9). These three risks are often combined in the same document.
Caution: Encrypting a document or deleting a chat later does not guarantee privilege. What is decisive is the tool in which the document is entered and whether that tool offers data assurance. Privilege is maintained before entering the document-unsecured vehicle.
Document Classification Scheme
The right decision is made not by treating every document the same, but by classifying it according to its sensitivity. A simple three-four step diagram clarifies the question "which document goes where?"
class
example
use of AI
Public/Public
Published legislation, press text
Free in every vehicle
Internal/Confidential
Domestic policy, draft contract
Approved, insured vehicle only
Client secret/Personal
Client file, personal data
Approved tool + masking
privileged
Legal opinion, defense strategy
As a rule, it is not entered; only fully secured certified environment
Your role: an information security/privacy consultant.Label the following document according to a classification scheme:Classes: Public / Internal-Confidential / Client secret-Personal / Privileged.Output: (1) proposed class and its justification, (2) AI usage rule for that class, (3) markup of sections in the document that may be privileged (legal opinion, strategy). When in doubt, apply the "round up to higher class" principle; do not underestimate the document.<document>[document text or description]</document>
Establishing Assurances
Protecting privilege and confidentiality requires both technical and contractual measures. AI is helpful in compiling these measures into a checklist and reviewing relevant clauses in supplier contracts.
Turn the "use of confidential/privileged documents in AI tools" rules into a checklist for our organization's legal team. Include:- Which document class can be processed in which tool (permission matrix).- Default rule for privileged documents: not entered.- Safeguards sought for the approved tool (non-data retention, non-use in education, confidentiality commitment, location/access control).- Masking and minimization steps.- Notification and response steps in case of breach. Write each item in the form of a yes/no check; Mark the areas where "legal approval required" is required.
It is also necessary to have the supplier/tool contract examined: do the terms of use of the AI tool you have chosen really provide these assurances?
Review and table the following AI tool terms of use for privacy:| Topic | Case in condition (quote) | Is it enough | Risk |Look for: data retention period and purpose, use in model training, third party sharing, data location, right to deletion, confidentiality commitment. Is there adequate assurance for a privileged/confidential document? Tell me clearly; If you're not sure, say "legal review required." Writing conclusions without clauses/citations.
Privilege is not just about entering the document into the tool, but also about where the printouts are stored and with whom they are shared. An AI-generated summary or analysis may also be considered privileged; Moving it outside the team, into an unsecured channel, could also lead to exposure. Therefore, the lifecycle of the output must be considered from start to finish.
Map the following AI-powered workflow for privacy/privilege: what privacy risk exists at each step (input document, tool used, output produced, where the output is stored, people viewing the output)? Flag steps that could undermine privilege and suggest mitigations for each (access restriction, secure environment, masking). Provide definitive legal conclusion; Mark "legal approval required".
Weak Prompt / Strong Prompt
Weak prompt: Summarize our legal opinion article. [privileged document affixed to unsecured vehicle]
Result: The privileged defense strategy is exposed to an unsecured third party's system. Even if the task is completed, privilege has become controversial and confidentiality has been damaged.
Strong prompt:[first document classification → If "Privileged", it is not entered as a rule + only fully secured approved environment + necessary parts are masked + vehicle conditions have been previously examined]
Result: Guided by document sensitivity; Privileged content is either not accessed at all or is processed only in an approved environment with proven security.
Decision Flow
Before processing a document with AI, three questions are asked in order: (1) What class is this document in? (2) What means and conditions are required for the class? (3) Can I reduce the risk by masking or minimizing the part I need to enter? For privileged documents, the default response is "do not enter"; Exception is only possible with an environment approved by the institution and whose assurance is proven by contract.
Three Mini Cases
Case 1 — Preservation of privilege. A law firm would summarize its defense strategy memo in a case with AI. The classification prompt labeled the document "Privileged" and showed that the default rule was "no entry." The team never entered the document into the vehicle; instead he worked with a non-exclusive, generalized framework. During the litigation, the opposing party could not claim any disclosure; privilege preserved.
Case 2 — Checking vehicle insurance. One organization was considering processing confidential contract drafts in an AI tool. Vehicle conditions review showed that the vehicle was able to use data in model training and the retention period was uncertain. The organization rejected this tool for confidential documents and moved to a certified enterprise version for which it signed a data assurance agreement. Same job, but this time done without the risk of exposure.
Case 3 — Value of permission matrix. In a legal team, everyone acted differently; Some were entering the client file directly, some were not using it at all. Once the document class-vehicle permission matrix was established, the rules became clear: no privileged document entered, client secret only masked and in the approved vehicle, general document free. In the first quarter, 3 illegal attempts were caught and blocked in advance thanks to the matrix; A documented record of compliance has been established.
Common mistakes
- Entering the privileged document into an unsecured vehicle. The most serious mistake; may violate privilege and confidentiality.
- Not classifying documents. Treating every document the same leaves the sensitive unprotected.
- Not checking vehicle conditions. Assurance cannot be assumed without knowing the tool's data retention/training policy.
- Thinking that encryption/deletion is enough. What is decisive is the tool in which the document is entered; subsequent deletion does not undo the disclosure.
- Making the exception the rule. The default in a privileged document is "do not enter"; Exception occurs only with evidentiary assurance.
- Not institutionalizing the consent matrix. Without written rules, everyone makes their own decisions; Inconsistency and risk arise.
In summary
Confidential and privileged documents are the area that requires the highest attention when using AI. What is decisive is the vehicle in which the document is entered: entering a privileged document into an unsecured vehicle can violate confidentiality and attorney-client privilege. Classify documents by sensitivity, set tool-permission rules for each class, default to “do not enter” on privileged documents, verify the tool's data safeguards from the contract, and apply masking/minimization together. AI produces classification and checklists; The competent professional decides whether a document can be processed or not.
Application task
Define three documents of different sensitivity (one public, one confidential, one privileged, etc.). (1) Label each with a classification prompt and determine the AI usage rule. (2) Produce a document class-tool permission matrix and checklist for your team. (3) Have the conditions of a tool you use examined in terms of confidentiality and evaluate the adequacy of the assurances. (4) Put in writing the "no trespassing" default rule for the privileged document.
checklist
- [ ] Is the document labeled according to its sensitivity class before processing?
- [ ] Has it been determined which tool can be used for each class?
- [ ] Is the default "no trespassing" rule applied to privileged documents?
- [ ] Have the data assurances of the vehicle used been verified from the conditions?
- [ ] Has masking and minimization been applied?
- [ ] Has the document class-tool permission matrix been institutionalized?
- [ ] Are notification/intervention steps defined in case of violation?