AI, attorney-client privilege & work product: what the 2026 cases say
Using AI for legal intake does not, by itself, waive attorney-client privilege, as long as the AI acts as the firm's own agent under the firm's direction, the way a receptionist or intake paralegal does. What creates risk is a consumer chatbot a person uses with no lawyer involved. The safeguards are no training on client data and short retention, with firm-specific isolation and redaction configured and validated during the signed implementation, plus a human attorney reviewing every matter.
Privilege protects the conversation, not the crash
Start with the distinction that decides most of these questions. Attorney-client privilege protects the confidential communication between a client and their lawyer. It does not protect the underlying facts. The date of the collision, the intersection, and the injuries are discoverable no matter how they were first written down. So the honest goal is never to pretend the facts are secret. It is to make sure the privileged communication stays privileged, and to minimize what is stored about it.
What the 2026 cases actually held
Two early 2026 decisions drew the line in the same place, and a third showed the cost of getting it wrong.
The court held that a party's use of an AI platform did not waive work-product protection, reasoning that "AI platforms are tools, not persons." This is the favorable side of the split, and a firm-directed, confidential-tier deployment with human review sits on stronger footing still.
Consumer-tier AI documents got no privilege or work-product protection. But the court's dictum is the roadmap: lawyer-directed AI "might function akin to a highly trained professional who may act as a lawyer's agent within the privilege." That is the agent theory, applied to AI.
A consumer AI product allegedly gave legal advice and told a user to fire her lawyer, drawing unauthorized-practice and product-liability allegations. The lesson is the guardrail we build around: intake only, no legal advice, a human attorney in the loop.
The Kovel agent doctrine is the through-line
The reason the favorable reasoning works is decades old. Under In re Kovel, 296 F.2d 918 (2d Cir. 1961), a lawyer's confidential communications stay privileged when they pass through the lawyer's agent, in that case an accountant, because the agent is functioning as part of the legal team rather than an outside party. A firm-directed intake assistant is meant to fill exactly that role: the front desk, held to the firm's rules, not a stranger the client confides in.
The ethics rules point the same way
ABA Formal Opinion 512 (July 29, 2024) warns that self-learning AI tools can require client informed consent, because client data may train the model. Vetted Cases uses non-self-learning, no-training providers, which avoids that consent trap. The related duties are familiar ground: the duty to prospective clients under Model Rule 1.18 and ABA Opinion 492, confidentiality under Rule 1.6, supervision of non-lawyer assistants under Rule 5.3, technology competence under Rule 1.1 cmt. 8, and the inadvertent-disclosure protections of Fed. R. Evid. 502(b).
Legislators are moving too. New York S.B. S7263 (2025 to 2026 session) would create a private right of action against chatbot "proprietors" that deliver professional advice, along with an AI-disclosure duty. It advanced to a third reading on March 4, 2026, and is not yet enacted, but it signals where the duty to disclose and to not give advice is heading.
How Vetted Cases is built to preserve privilege
Because privilege is ultimately decided by a court, we treat these as belt-and-suspenders safeguards rather than a promise:
This article is general information, not legal advice, and the law here is developing quickly. It does not create an attorney-client relationship. Evaluate your own obligations with your own counsel. We do not name our underlying technology vendors on public pages.
Privilege and AI intake, answered
Does using AI for legal intake waive attorney-client privilege?+
Not on its own, when the AI acts as the firm's own agent under the firm's direction, the way a receptionist or intake paralegal does. A consumer chatbot a person uses with no lawyer involved is a different story. The safeguards are no training on client data and short retention, with firm-specific isolation and redaction configured and validated during the signed implementation, plus human attorney review of every matter.
Does privilege cover the facts a caller shares?+
No. Privilege protects the confidential communication with the lawyer, not the underlying facts. The crash, the date, and the injuries are discoverable by other means. That is why the goal is to minimize what is stored, not to claim the facts themselves are secret.
Is AI legal intake confidential and HIPAA-conscious?+
Vetted Cases uses enterprise, no-training voice and language providers under contractual data-protection terms, keeps only what is needed for a short time, configures and validates firm-specific isolation and redaction during each signed implementation. A BAA can be arranged during implementation when required. These are belt-and-suspenders safeguards, not a guarantee, because privilege is ultimately decided by a court.
What is the Kovel agent doctrine?+
Under In re Kovel, 296 F.2d 918 (2d Cir. 1961), a lawyer's confidential communications can stay privileged when they run through the lawyer's agent, such as an accountant or, by extension, a firm-directed intake assistant, because that agent functions as part of the legal team rather than an outside party.
Does ABA Opinion 512 affect AI intake?+
ABA Formal Opinion 512 (2024) flags that self-learning AI tools can require client informed consent, because client data may train the model. Vetted Cases uses non-self-learning, no-training providers, which avoids that consent trap.
Confidentiality questions from your counsel? Bring them.
Book 20 minutes and we will walk your team through the architecture, the retention settings, and any required BAA, in plain terms.
Book a confidentiality walkthrough →