Insights

The Rules of Privilege Still Apply When Lawyers use AI

Does using AI put attorney-client privilege at risk? Harvey CLO John LaBarre explains why the rules haven’t changed, what is different in practice, and how both the platform and a legal team’s use of it can affect privilege.

by John LaBarre•Sep 25, 2026

When I talk with legal leaders about AI, privilege is usually one of their first questions, and a fair one. Lawyers are being asked to put their most sensitive information into new technology, and they want confidence that it will not weaken protections they have relied on in the past.

The reassuring part is that the situation is a familiar one. Lawyers already worked through the same worry with email, cloud storage, e-discovery platforms, and the other tools that are now simply part of how legal work gets done. Using technology to handle client information does not waive privilege, so long as lawyers take reasonable steps to keep that information confidential. AI is no different in principle, but the details matter, and what counts as reasonable depends on the tool. A consumer chatbot and an enterprise legal AI platform handle information in very different ways, and those differences should be central to any privilege conversation.

Before considering what those platform differences mean in practice, it helps to be precise about what “privilege” means. The shorthand covers two related but distinct protections: attorney-client privilege and the work product doctrine. The two protect different things and follow different waiver rules, so treating them as one blurs the analysis. We recently published a white paper at Harvey, Attorney-Client Privilege and the Work Product Doctrine in the Age of Legal AI, that explains how the two protections differ, how courts are beginning to approach AI, and what those early decisions signal.

The larger takeaway is that protecting privilege and attorney work product is a shared responsibility. Technology providers have to build systems that support confidentiality and are consistent with maintaining privilege, and legal teams have to use those systems with the same care they bring to every other part of their work.

The Existing Rules Apply to AI

One reason conversations about AI and privilege become confusing is that “privilege” is often used as shorthand for multiple protections. Attorney-client privilege protects confidential communications made for the purpose of seeking or providing legal advice. The work product doctrine protects materials prepared in anticipation of litigation, including factual compilations and a legal team’s mental impressions, conclusions, and legal theories.

The distinction matters because the two protections follow different waiver rules. Privilege is narrow and can be lost when a communication is shared outside the circle necessary to provide legal advice. Work product is generally more durable and is typically waived only when material is shared with an adversary or in a way that makes it substantially more likely an adversary will receive it.

“The laws of privilege haven’t changed. AI isn’t such a different technology that it changes how we should analyze these questions.”

AI does not change those standards. Adding a lawyer to an email doesn’t “automagically” make it privileged, and the mere act of putting information into a legal AI platform doesn’t necessarily transform that information into something that is privileged. The analysis still depends on the purpose of the work, the information involved, who can access it, and how confidentiality is maintained.

Early court decisions are applying these familiar questions rather than creating an entirely new framework. In United States v. Heppner, for example, the court held that a defendant’s exchanges with a publicly available version of Claude were not privileged because he used the tool independently of counsel and the applicable privacy policy did not support a reasonable expectation of confidentiality. The decision illustrates the broader point: AI introduces new facts to consider, but the underlying principles remain the same. One of the most important facts is how the platform handles the information entrusted to it.

The AI Platform Matters

Two AI tools can use similar underlying models while handling customer information very differently. What matters is the full set of terms, controls, and practices around that information. A consumer AI tool may operate under terms that allow data to be retained, reviewed by humans, or used for training. An enterprise legal AI platform can put contractual and technical protections in place to prevent those uses Harvey, for example, falls into the latter category.

Legal leaders evaluating AI tools should understand what happens to information once it enters a platform: whether it is retained, used to train models, reviewed by people, or accessible to third parties. At Harvey, our agreements with model providers prohibit training on customer data, retention beyond the ephemeral processing needed to generate an output, and human review of customer content. We apply the same scrutiny to subprocessors that may access customer information.

“We don’t know what someone is uploading to :Harvey:. By design, we treat all customer content as if it’s highly confidential.”

We don’t know what someone is uploading to Harvey. It could be a public document, a privileged communication with a client, or a recipe for key lime pie. Because we don’t know what our customers are entering into Harvey, we made the only design choice that made sense for a tool intended to be used by lawyers: we treat all customer content as if it’s highly confidential. This principle doesn’t make every input privileged, but, because it is foundational to how we built Harvey, it supports the confidentiality that privilege requires.

Privilege is a Shared Responsibility

Platform protections are essential, but they address only one side of the privilege analysis. Privilege also depends on context and conduct. As Harvey’s CLO, I also serve as an executive and board member. Sometimes I’m giving legal advice; other times I’m contributing as a business leader. Having a lawyer in the room, on an email, or in a Slack channel doesn’t make every conversation privileged. The purpose of the communication still matters.

The same is true when legal teams use AI. Harvey is designed to maintain the confidentiality of customer information, but the platform can’t turn business advice into legal advice or preserve privilege after information is shared outside the appropriate group. Users still need to consider why they are using the tool, who has access to the work, and where the resulting information goes.

In this way, protecting privilege is a shared responsibility. Technology providers like Harvey must put the right contractual, technical, and access protections in place. Legal teams must use those systems with the same care they apply to email, document repositories, and other tools that are core to legal work. A well-designed platform can make that discipline easier to maintain, but privilege is not a setting that any vendor can simply switch on.

That shared responsibility becomes more complex when AI can take actions and move information across the tools a legal team uses.

Agents Raise new Questions About Access and Control

AI agents introduce a practical question for privilege: where can protected information go when an agent can share it or act across other tools?

A lawyer may use an agent to help research or analyze part of a complex legal question, much as they would delegate work to an associate. When that work is done under the lawyer’s direction to help provide legal advice, the agent’s involvement doesn’t automatically defeat privilege. The lawyer still needs to set clear boundaries around who can receive the information, which systems the agent can access, and when it must ask for approval.

Technology providers must make those limits clear and enforceable. Legal leaders need clear answers about which actions an agent can take autonomously, which require human review, and which systems it can reach.

As agents gain more autonomy and connect to more systems, legal teams must pay closer attention to where protected information can go and what an agent can do with it. The broader principle remains the same: protecting privilege depends on both technology designed to support confidentiality and the choices legal teams make about how it is used.

For a closer look at how attorney-client privilege and work product apply to enterprise legal AI, including what early court decisions can tell us, read our white paper, Attorney-Client Privilege and the Work Product Doctrine in the Age of Legal AI.