How pasting a brief into a consumer chatbot can waive privilege
It is Tuesday afternoon, the directions hearing is Thursday, and the brief runs to several hundred pages. The junior solicitor opens a free chatbot on a personal account, pastes in the chronology, the without prejudice correspondence and two paragraphs of counsel's advice, and asks for a summary. The summary is good. Nobody mentions it again until the other side's solicitor asks, on affidavit, what steps were taken to preserve the confidentiality of the documents over which privilege is claimed.
That is the real shape of the problem. The risk is not that the chatbot says something silly in court. The risk is that the act of putting privileged material into a system you do not control, on terms you did not read, is later characterised as conduct inconsistent with maintaining confidentiality. Privilege is not a label you attach to a document. It is a status the communication holds, and confidentiality is the thing holding it up.
No Australian court has yet decided a case squarely on whether use of a consumer chatbot waives privilege. That is not comfort. It means the first firm to argue it will be arguing from scratch, on its own file, at its client's expense.
Privilege lives or dies on confidentiality
Sections 118 and 119 of the Evidence Act 1995 (Cth), and their state equivalents, protect confidential communications made for the dominant purpose of legal advice or for use in litigation. The common law equivalent works the same way. The word carrying the weight in that sentence is confidential. Strip the confidentiality and there is nothing left for the privilege to attach to.
Waiver under section 122, and at common law following Mann v Carnell, turns on inconsistency. The court asks whether the conduct of the party holding the privilege is inconsistent with maintaining the confidentiality of the communication. Intention is not the test. A solicitor who genuinely believed the chatbot was private has not answered the question, they have only explained why they did not think about it.
There is a respectable counter-argument, and it is worth knowing. Disclosure to a service provider bound by obligations of confidence has never been treated as waiver. Nobody suggests privilege dies because a copying bureau handled the brief or because the firm's IT provider can technically reach the file server. The difficulty is that the analogy holds only where the provider is genuinely bound. On a consumer tier, the terms often permit retention, human review and use of the content to improve the product. That is not a copying bureau.
What happens to the text after you press enter
Most practitioners picture the prompt going into a black box and the answer coming back out. What actually happens is more like sending a fax to a company you have never dealt with, in a jurisdiction you have not checked, which keeps a copy indefinitely.
The specifics vary by vendor and by tier, and they change. The point is that on a free or consumer plan the default settings are built for a general audience, not for a firm holding other people's secrets under a professional duty. You are relying on a default that the vendor can alter with a terms update.
How the damage actually lands, worst first
Waiver is the headline risk but it is not the only one, and it is not always the one that hurts first. The list below is ordered by how badly each outcome affects the client and the practitioner.
Note that the second item bites even if you win the privilege argument. Once the other side knows privileged material went into an external system, they have a line of inquiry, and answering it means producing evidence about your own file handling.
Removing the names does less than you hope
The most common workaround is to strip identifiers before pasting: swap the client for Company A, the director for Person B, keep everything else. It feels responsible. It is weaker than it looks, for two reasons.
First, matters are identified by their facts, not their names. A dispute over a specific development site, a specific insolvency, a specific employment termination with a distinctive set of dates is identifiable to anyone in the market, and often to a model with search access. Second, and more fundamentally, privilege protects the substance of the communication. Disclosing counsel's reasoning with the parties renamed is still disclosing counsel's reasoning. Anonymisation addresses a privacy risk, not a privilege risk.
Run the questions below before anything leaves the firm. They take a few minutes and they are the file note you will want later.
A rollout that survives a discovery fight
Banning AI outright does not work. People use it anyway on their phones, and you lose the ability to see it. A controlled rollout with a written record beats an unenforceable prohibition, and it gives you something to point at when asked what steps the firm took.
Check the current position of the courts you appear in as part of this. The Supreme Courts of New South Wales and Victoria, among others, have issued directions and guidance on generative AI in litigation, including restrictions on its use for affidavits and expert material, and disclosure expectations. Those documents are updated, so read the live version rather than a summary.
- Firm-wide email: no client material into personal or free accounts, effective immediately
- Ask everyone, without blame, which tools they have used and on which matters
- Quarantine any matter where privileged material may have gone into a consumer tier and get advice before the issue is raised by someone else
- Move to business or enterprise terms with no training on your content and defined retention
- Get a written data processing agreement and confirm hosting location
- Decide whether your engagement terms and privacy policy need updating, and whether specific matters warrant client consent
- One page policy covering approved tools, prohibited uses and the verification requirement
- Maintain a register of approved tools with the date each set of terms was last reviewed
- Verify every authority against the primary source before it goes near a document that leaves the office
- Quarterly re-read of vendor terms and of the practice notes in your jurisdictions
- Spot check prompts against the policy in the same way you spot check trust records
- Revisit the policy whenever a vendor changes defaults or the firm adds a tool
What a defensible tool looks like
The commercial answer is straightforward once the risk is clear. You want a contractual commitment that your content is never used to train a model, a defined and short retention period, hosting you can point to, per-user access controls and an audit log that shows who asked what. Those five things convert an uncontrolled disclosure into the ordinary use of a confidential service provider, which is the ground privilege has always stood on.
You also want the answers to be checkable. A tool that gives you a confident paragraph with no source is a liability, because the verification burden lands on you either way. Citations that link to the actual legislation or judgment let you confirm the point in seconds instead of rebuilding the research from scratch. Legal Brain was built for Australian practice on that basis, with material kept out of model training and every answer tied back to the primary source.
None of this removes the duty to check. The tool does not appear in court, you do. But there is a difference between a practitioner who used a controlled system under a written policy and verified the output, and one who pasted a brief into a free chatbot on a Tuesday afternoon. The first is doing the job properly. The second is one interlocutory application away from a very bad week.
Frequently asked questions
Does using ChatGPT waive legal professional privilege in Australia?
There is no Australian decision holding that it does, and use of a properly contracted service provider bound by confidentiality should not waive privilege. The risk sits with consumer tiers where the provider may retain your content, allow human review, or use it for training, because that can undermine the confidentiality privilege depends on. Waiver at common law and under section 122 of the Evidence Act turns on whether your conduct was inconsistent with maintaining confidentiality, not on what you intended.
Is it safe to use AI on a client matter if I remove the names?
Removing names reduces privacy risk but does very little for privilege. Matters are identifiable from their facts, and privilege protects the substance of the communication, so disclosing the reasoning with the parties renamed is still disclosure. Treat de-identification as a useful extra step, never as the control that makes the tool safe.
Do I have to tell my client that I used AI on their matter?
There is no single national rule, so check your engagement terms, your professional indemnity insurer's requirements and any relevant court practice note. As a practical matter, if the tool receives confidential client material, the safer course is to address it in the costs agreement or engagement letter and to obtain specific consent for sensitive matters. Silence is the position hardest to defend if it comes up later.
Can the other side subpoena my AI chat history?
Your prompts and the responses are records created in connection with the matter, so they are capable of being the subject of discovery or a subpoena, and the vendor may hold its own copy that is beyond your control. Privilege may still be claimed over them, but you will be arguing that point on your own file. Keeping privileged material out of systems you cannot control avoids the fight entirely.
Two quick questions
No score is stored. Pick an answer to see why it is right.
-
1What is the test for waiver of privilege in Australia?
Following Mann v Carnell, and reflected in section 122 of the Evidence Act, waiver turns on inconsistency between the conduct of the party and maintaining confidentiality. Subjective intention is not the question, which is why a practitioner who did not think about where the text was going has not answered it.
-
2Which step does most to reduce the privilege risk of using AI on a client matter?
Only the contractual position changes what the provider may lawfully do with your material, which is what puts the arrangement in the same category as any other confidential service provider. Anonymisation, private browsing and deleting the chat do nothing about retention, human review or training on the vendor's side.
Research Australian law without handing over client data
Legal Brain searches Australian legislation and case law, shows you the source behind every answer, and anonymises client-identifying detail before anything reaches a model.