Answer · Updated August 2026
Can attorneys use ChatGPT or Microsoft Copilot without waiving privilege?
Direct answer
Yes — with controls. The privilege risk comes from feeding client information into tools whose terms allow training on your inputs or human review of conversations. Use enterprise or business tiers with contractual no-training guarantees, disable chat-history features where possible, strip client identifiers before prompting, and adopt a written firm AI policy. Consumer free tiers should never see privileged material.
Where the risk actually comes from
Privilege protects confidential communications between lawyer and client. Routing client facts through a third-party system does not automatically waive privilege — but the analysis depends on confidentiality being preserved. The practical risks are contractual (does the vendor train on inputs or retain prompts?), technical (who at the vendor can review conversations?), and human (a well-meaning associate pasting a privileged memo into a free-tier chatbot).
The safe-configuration checklist
Baseline controls most firms adopt before greenlighting AI tools:
- Enterprise or business tiers only, with written no-training and data-retention terms
- SSO enforcement and per-user access controls, so usage is attributable and auditable
- Chat history and model-improvement settings reviewed and disabled where the tool allows
- A redaction habit: strip party names, deal terms, and identifiers from prompts by default
- Verification duty: AI output is a draft; citation and fact-checking remain the lawyer's job
What a written firm AI policy should say
Keep it short enough to be followed: which tools are approved, which data classes may never be entered, how prompts are anonymized, who reviews vendor terms annually, and how incidents (an accidental paste) get reported. Several state bars have issued AI guidance, and clients increasingly ask about AI handling in outside-counsel guidelines — a written policy turns an awkward questionnaire into a two-line answer.
Related questions
Does using AI violate ABA Model Rule 1.6?
Not inherently. Rule 1.6(c) requires reasonable efforts to protect confidentiality, which is exactly what the controls above represent: vetted vendors, contractual protections, and internal policy. Uncontrolled consumer-tier use is the exposure.
What about court rules on AI use?
A growing number of judges require disclosure or certification of AI use in filings, and sanctions for fabricated AI citations are now well documented. Competence and verification duties under Rules 1.1 and 5.3 apply regardless of which tool produced the draft.
Should AI vendors appear in our security assessments?
Yes. AI tools with access to email, documents, or matter data are part of your attack surface — third-party OAuth grants and integrations should be reviewed like any other vendor connection.
