AI Privilege Issues: Practical Guidance

by John Jenkins

September 30, 2026

Gunderson Dettmer recently published this client alert addressing the current state of attorney-client and attorney work product privilege protection for information shared with AI tools. The alert addresses recent court decisions implicating AI-related privilege issues and offers some practical guidance for companies seeking to ensure that attorney-client or work product privileges are not inadvertently lost through interactions with AI tools.  Here are some of the key takeaways:

– There is no automatic protection for AI chat history, even if communicated to an attorney. An AI chatbot is not a lawyer. Sending an AI-generated document to counsel does not retroactively protect the underlying chatbot exchange as privileged or work product.

– Protection under the work-product doctrine is not guaranteed even when involving the preparation of litigation materials. Several courts ruled to protect AI-assisted litigation work product, but most of these cases involved self-represented litigants or a state rule that expressly protects materials prepared by a party. Notably, these rulings concern protection under the work-product doctrine, not attorney-client privilege, and do not establish that employees of a represented company may freely use consumer AI tools for sensitive legal matters.

– Enterprise AI terms and account settings may help support confidentiality, but they do not determine privilege or work-product protection on their own. Use of a free or personal account may undermine the confidentiality required for attorney-client privilege. Enterprise controls restricting model training, retention, disclosure and human review may support an intent for confidentiality, but they do not create attorney-client privilege or work-product protection on their own.

– AI prompts and outputs can become evidence against a company. Company AI chats have already been quoted in court as direct evidence of knowledge, motive and intent. They may also be discoverable, subject to preservation obligations and obtained through subpoenas or warrants. Companies should address these risks through internal and external AI policies, including appropriate disclaimers and guardrails.

– Mitigate these risks with deliberate AI governance. Companies should route sensitive AI use through counsel and approved enterprise or legal-first tools, keep privileged, litigation and other high-risk materials out of unapproved tools and meeting assistants, and adopt a written AI Usage Policy with training that reaches founders, executives and board members.