Using Consumer-grade AI May Well Waive Privilege [Lawyer]

20-08-2026

If you are a lawyer and you are using a USD20 per month consumer-grade AI app, chances are, giving it your clients' papers or information waives privilege.

In the UK, the Upper Tribunal in Rex (Munir) v Secretary of State for the Home Department [2026] 4 WLR 37; [2026] UKUT 81 (IAC) stated:

"We also observe that to put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and thus any regulated legal professional or firm that does so would, in addition to needing to bring this to the attention of their regulator, be advised to consult with the Information Commissioner’s Office. Closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks." (at paragraph 21)

"Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and any such conduct might itself warrant referral to the regulatory body and should, in any event, be referred to the Information Commissioner’s Office." (at paragraph 60)

The use of the phrase "open source" is most likely incorrect, and to say that using an AI tool "is to place this information on the internet in the public domain" is imprecise. But the tenor of the passages is clear.

See also the US case of United States v Heppner, in which the Court held that AI chats between a criminal defendant and a specific Claude app were not privileged. The reasoning included reliance on the specific written privacy policy / terms of conditions of the AI tool:

"Second, the communications memorialized in the AI Documents were not confidential. This is not merely because Heppner communicated with a third-party AI platform but also because the written privacy policy to which users of Claude consent provides that Anthropic collects data on both users' "inputs" and Claude's "outputs," that it uses such data to "train" Claude, and that Anthropic reserves the right to disclose such data to a host of "third parties," including "governmental regulatory authorities." (pdf p. 6)

In Hong Kong, as of date, there does not appear to be a published Judgment on AI tools and privilege.

To my fellow lawyers, maximum caution is advised. Questions of privilege aside, you would not want your client's privileged and confidential information (even if it is often anonymized by the labs during training) permanently inscribed into the collective memory and intelligence of the forever future. As to privilege, there is a degree a uncertainty as to how principles of waiver would apply, particularly as the degree of data security in terms of service is on a spectrum. For instance, there could be:

  1. Consent to train the large language model on your inputs/outputs, sometimes with an option to opt-out.
  2. Data retention for, say 30 days. Consent for human review if there was automated flagging for potential abuse.
  3. Zero data retention (except for temporary caching in ephemeral memory).
  4. Zero data retention being represented in the app's settings, but the terms of service disclaiming that any representations are made.