Confidentiality

How pasting a brief into a consumer chatbot can waive privilege

By Michael Nadalin, Founder, Market Lead · 31 July 2026 · 8 min read

It is Tuesday afternoon, the directions hearing is Thursday, and the brief runs to several hundred pages. The junior solicitor opens a free chatbot on a personal account, pastes in the chronology, the without prejudice correspondence and two paragraphs of counsel's advice, and asks for a summary. The summary is good. Nobody mentions it again until the other side's solicitor asks, on affidavit, what steps were taken to preserve the confidentiality of the documents over which privilege is claimed.

That is the real shape of the problem. The risk is not that the chatbot says something silly in court. The risk is that the act of putting privileged material into a system you do not control, on terms you did not read, is later characterised as conduct inconsistent with maintaining confidentiality. Privilege is not a label you attach to a document. It is a status the communication holds, and confidentiality is the thing holding it up.

No Australian court has yet decided a case squarely on whether use of a consumer chatbot waives privilege. That is not comfort. It means the first firm to argue it will be arguing from scratch, on its own file, at its client's expense.

Privilege lives or dies on confidentiality

Sections 118 and 119 of the Evidence Act 1995 (Cth), and their state equivalents, protect confidential communications made for the dominant purpose of legal advice or for use in litigation. The common law equivalent works the same way. The word carrying the weight in that sentence is confidential. Strip the confidentiality and there is nothing left for the privilege to attach to.

Waiver under section 122, and at common law following Mann v Carnell, turns on inconsistency. The court asks whether the conduct of the party holding the privilege is inconsistent with maintaining the confidentiality of the communication. Intention is not the test. A solicitor who genuinely believed the chatbot was private has not answered the question, they have only explained why they did not think about it.

There is a respectable counter-argument, and it is worth knowing. Disclosure to a service provider bound by obligations of confidence has never been treated as waiver. Nobody suggests privilege dies because a copying bureau handled the brief or because the firm's IT provider can technically reach the file server. The difficulty is that the analogy holds only where the provider is genuinely bound. On a consumer tier, the terms often permit retention, human review and use of the content to improve the product. That is not a copying bureau.

What practitioners assume, and what actually applies
Privilege attaches to the document
Privilege attaches to a confidential communication, so losing confidentiality can lose the claim
I never intended to waive anything
Waiver is judged on whether the conduct is inconsistent with confidentiality, not on intention
It is just a tool, like a photocopier
A copier does not retain your text, route it to reviewers, or reuse it under terms you clicked past
Only the client can give up privilege
The privilege is the client's, but a solicitor acting within authority can waive it on their behalf
Nobody will ever know what I typed
Prompt histories are records about the matter, and the vendor holds a copy you cannot recall
Five beliefs that come up in every conversation about AI and privilege, and the position that governs.

What happens to the text after you press enter

Most practitioners picture the prompt going into a black box and the answer coming back out. What actually happens is more like sending a fax to a company you have never dealt with, in a jurisdiction you have not checked, which keeps a copy indefinitely.

The specifics vary by vendor and by tier, and they change. The point is that on a free or consumer plan the default settings are built for a general audience, not for a firm holding other people's secrets under a professional duty. You are relying on a default that the vendor can alter with a terms update.

The life of a pasted brief
Second zero
The text leaves your device and lands on a third party's infrastructure, frequently offshore
Immediately after
The exchange is stored against your personal account and stays retrievable in chat history
Days
On many consumer tiers a sample of conversations can be routed to human reviewers for safety and quality work
Weeks
Where training on user content is enabled by default, the material can feed model improvement
Months
Retention schedules, backups and the vendor's own legal process exposure continue after you close the tab
At discovery
Your prompt history is a record created about the matter, and your opponent can ask what was disclosed and to whom
The typical path of privileged text on a consumer tier. Details differ by vendor, the direction of travel does not.

How the damage actually lands, worst first

Waiver is the headline risk but it is not the only one, and it is not always the one that hurts first. The list below is ordered by how badly each outcome affects the client and the practitioner.

Note that the second item bites even if you win the privilege argument. Once the other side knows privileged material went into an external system, they have a line of inquiry, and answering it means producing evidence about your own file handling.

Consequences, ranked
The privilege claim fails
The communication loses its confidential character or the disclosure is found inconsistent with maintaining it, and the material becomes available to the other side
Worst
Satellite litigation about your own conduct
Affidavits, cross-examination and interlocutory argument about what was pasted where, paid for by the client and fought instead of the actual case
Severe
A notifiable data breach
Sending identifiable client information to a system without a proper agreement can trigger obligations under the Privacy Act and a report to the OAIC, plus notice to the affected people
Regulatory
A conduct complaint
Rule 9 of the Australian Solicitors' Conduct Rules requires confidentiality of client information, and the fact that a machine received it is not an exception
Professional
Adverse costs and lost time
Adjournments, wasted costs applications and the internal cost of an audit of every matter the tool touched
Expensive
Ordered from the outcome that does the most damage to the client's position down to the one you can usually absorb.

Removing the names does less than you hope

The most common workaround is to strip identifiers before pasting: swap the client for Company A, the director for Person B, keep everything else. It feels responsible. It is weaker than it looks, for two reasons.

First, matters are identified by their facts, not their names. A dispute over a specific development site, a specific insolvency, a specific employment termination with a distinctive set of dates is identifiable to anyone in the market, and often to a model with search access. Second, and more fundamentally, privilege protects the substance of the communication. Disclosing counsel's reasoning with the parties renamed is still disclosing counsel's reasoning. Anonymisation addresses a privacy risk, not a privilege risk.

Run the questions below before anything leaves the firm. They take a few minutes and they are the file note you will want later.

Five questions before a prompt leaves the firm
1
Which tier is this, exactly
Free, personal paid, business or enterprise are different contracts with different defaults. A colleague's personal login is not the firm's account.
2
Read the retention and training terms, not the marketing page
You want a written commitment that inputs are not used for training and are retained for a defined, short period or not at all. Screenshot it and diarise a review.
3
Where does the data sit, and who can compel it
Offshore hosting exposes the material to foreign legal process. If the vendor can be compelled to hand over your prompts, so can your client's secrets.
4
Assume anonymisation fails
Ask whether you would be comfortable if the de-identified prompt were read aloud in court next to the file. If not, it is not de-identified enough.
5
Who signs off, and where is it recorded
Name the partner responsible for approved tools and keep a register. An unwritten policy is indistinguishable from no policy when it is tested.
A short standing test. If any answer is unknown, the material does not go in.

A rollout that survives a discovery fight

Banning AI outright does not work. People use it anyway on their phones, and you lose the ability to see it. A controlled rollout with a written record beats an unenforceable prohibition, and it gives you something to point at when asked what steps the firm took.

Check the current position of the courts you appear in as part of this. The Supreme Courts of New South Wales and Victoria, among others, have issued directions and guidance on generative AI in litigation, including restrictions on its use for affidavits and expert material, and disclosure expectations. Those documents are updated, so read the live version rather than a summary.

Eight weeks to a defensible position
Week 1
Stop the exposure
  • Firm-wide email: no client material into personal or free accounts, effective immediately
  • Ask everyone, without blame, which tools they have used and on which matters
  • Quarantine any matter where privileged material may have gone into a consumer tier and get advice before the issue is raised by someone else
Weeks 2 to 4
Choose the tier and paper it
  • Move to business or enterprise terms with no training on your content and defined retention
  • Get a written data processing agreement and confirm hosting location
  • Decide whether your engagement terms and privacy policy need updating, and whether specific matters warrant client consent
Weeks 5 to 8
Train, register, record
  • One page policy covering approved tools, prohibited uses and the verification requirement
  • Maintain a register of approved tools with the date each set of terms was last reviewed
  • Verify every authority against the primary source before it goes near a document that leaves the office
Ongoing
Review, because the terms move
  • Quarterly re-read of vendor terms and of the practice notes in your jurisdictions
  • Spot check prompts against the policy in the same way you spot check trust records
  • Revisit the policy whenever a vendor changes defaults or the firm adds a tool
A staged plan sized for a small to mid-sized firm. Each phase produces a document you can rely on later.

What a defensible tool looks like

The commercial answer is straightforward once the risk is clear. You want a contractual commitment that your content is never used to train a model, a defined and short retention period, hosting you can point to, per-user access controls and an audit log that shows who asked what. Those five things convert an uncontrolled disclosure into the ordinary use of a confidential service provider, which is the ground privilege has always stood on.

You also want the answers to be checkable. A tool that gives you a confident paragraph with no source is a liability, because the verification burden lands on you either way. Citations that link to the actual legislation or judgment let you confirm the point in seconds instead of rebuilding the research from scratch. Legal Brain was built for Australian practice on that basis, with material kept out of model training and every answer tied back to the primary source.

None of this removes the duty to check. The tool does not appear in court, you do. But there is a difference between a practitioner who used a controlled system under a written policy and verified the output, and one who pasted a brief into a free chatbot on a Tuesday afternoon. The first is doing the job properly. The second is one interlocutory application away from a very bad week.

Frequently asked questions

Does using ChatGPT waive legal professional privilege in Australia?

There is no Australian decision holding that it does, and use of a properly contracted service provider bound by confidentiality should not waive privilege. The risk sits with consumer tiers where the provider may retain your content, allow human review, or use it for training, because that can undermine the confidentiality privilege depends on. Waiver at common law and under section 122 of the Evidence Act turns on whether your conduct was inconsistent with maintaining confidentiality, not on what you intended.

Is it safe to use AI on a client matter if I remove the names?

Removing names reduces privacy risk but does very little for privilege. Matters are identifiable from their facts, and privilege protects the substance of the communication, so disclosing the reasoning with the parties renamed is still disclosure. Treat de-identification as a useful extra step, never as the control that makes the tool safe.

Do I have to tell my client that I used AI on their matter?

There is no single national rule, so check your engagement terms, your professional indemnity insurer's requirements and any relevant court practice note. As a practical matter, if the tool receives confidential client material, the safer course is to address it in the costs agreement or engagement letter and to obtain specific consent for sensitive matters. Silence is the position hardest to defend if it comes up later.

Can the other side subpoena my AI chat history?

Your prompts and the responses are records created in connection with the matter, so they are capable of being the subject of discovery or a subpoena, and the vendor may hold its own copy that is beyond your control. Privilege may still be claimed over them, but you will be arguing that point on your own file. Keeping privileged material out of systems you cannot control avoids the fight entirely.

Check your understanding

Two quick questions

No score is stored. Pick an answer to see why it is right.

  1. 1What is the test for waiver of privilege in Australia?

  2. 2Which step does most to reduce the privilege risk of using AI on a client matter?

Research Australian law without handing over client data

Legal Brain searches Australian legislation and case law, shows you the source behind every answer, and anonymises client-identifying detail before anything reaches a model.

Request early access