No. 2026-01 · Founding cohort · now evaluating firms

Will an AI Keep Your Privilege?

By The Jubal Team9 min read


Start with the nightmare, because it's the one that actually keeps people up. You run a client's documents through an AI to think through strategy. Two years later, opposing counsel serves a discovery request and argues that everything you typed into that tool, and everything it handed back, is fair game. Did you just draw them a map of your own case? For a small firm, that isn't a thought experiment you can wave off. That's the whole ballgame.

So let's start where the worry lives, figure out what actually determines the answer, and only then get to the practical part: the documents a serious vendor should hand you, and why each one is there.

The real question isn't "am I allowed." It's "do I stay privileged."

Here's the part the headlines gloss over. AI prompts and outputs are electronically stored information, the same as email or a Word file. Which means that once litigation is reasonably anticipated they fall under a litigation hold, and if they're relevant and not privileged, the other side can ask for them. There is no special exemption that kicks in just because a robot was involved.

But "not privileged" is carrying an enormous amount of weight in that sentence, and the early cases cut a clean line through it. The line comes down to who is using the tool, and whether the tool keeps what you put into it confidential.

On the protected side: when a lawyer writes prompts as part of legal strategy, courts have treated those prompts and the answers they produce as work product, often opinion work product, which gets the strongest protection there is because it lays bare the attorney's thinking. That's what happened in Tremblay v. OpenAI (N.D. Cal. 2024), where the court reasoned that a lawyer's prompts are essentially questions loaded with counsel's judgment about how to attack a problem. A second court in the Northern District of California saw it the same way in the Concord Music Group v. Anthropic litigation. Put plainly, using a capable AI to build your case looks a lot like the old-fashioned protected work of preparing for trial.

On the other side sits United States v. Heppner (S.D.N.Y. 2026), and it's the story every firm should keep in mind. A defendant used a public consumer chatbot, on his own, to draft material about his defense, then handed it to his lawyer. Judge Rakoff held that none of it was privileged or work product. Two facts did the damage: the client made it himself without his attorney directing the work, and the consumer tool's own terms said the inputs weren't confidential. Feeding the tool, in other words, counted as handing your information to a stranger, which breaks confidentiality. The court even paused to note the result "may have been different" if the user had relied on an enterprise tool that kept its inputs confidential.

Read those cases side by side and the lesson is a formula. Protection depends on how, why, by whom, and under what conditions the AI gets used, and on whether the tool is contractually obligated to keep your inputs confidential. So the question was never really "AI, yes or no." It was always "what does this particular tool, and the contract behind it, actually promise about my clients' data." And that's a question you answer by reading.

And yes, the rules let you do this

Notice what didn't make the worry list: permission. No ethics rule forbids a lawyer from using generative AI. The American Bar Association said as much in Formal Opinion 512 (July 2024), and the state bars that have weighed in haven't contradicted the core of it. What the rules ask for isn't abstinence, it's care. Use the tool competently, meaning understand what it can and can't do. Keep client information confidential. Supervise its output the way you'd supervise a first-year. Verify before you file. Bill reasonably.

One line from Opinion 512 is worth taping to your monitor: boilerplate consent buried in an engagement letter is not enough. If client confidences are going into a third-party AI, the client ought to actually understand that and agree to it. That's a habit more than a feature, but the tool you pick will make the habit either easy or impossible to keep.

So the rules say go ahead, carefully. And "carefully" turns out to be the same formula the discovery cases handed us: it all comes back to what the tool, and its contract, guarantee about your clients' data.

The paperwork, and why each piece is there

When you bring on a serious legal AI, you shouldn't get one "Terms of Service" and a checkbox. You should get a small stack of agreements that fit together, the same architecture the established players like Harvey and Legora publish in the open. Here's what each one is and the firm interest it's protecting.

The Master Agreement is the spine, sometimes called the MSA or platform agreement. It grants the license, sets the term and the fees, and parcels out the big risks: warranties, liability caps, indemnities, what happens when you walk away. It's also where you want an explicit professional-responsibility provision, the part that says the tool is software and not a law firm, it doesn't give legal advice, and you remain responsible for supervising and checking its work. That disclaimer sounds like it's protecting the vendor, but it's quietly protecting you too. It's the contract's version of your Rule 5.3 supervision duty, and it keeps the human lawyer exactly where the privilege analysis wants her, in charge.

The Data Processing Addendum, the DPA, is the document a firm should read first, and the one that matters more than any other in the stack, because it governs your clients' data. A strong DPA says in writing that you are the controller of that data and the vendor is only your processor; that your data is never used to train models; that it stays in a defined region, which for a U.S. firm means the United States; that it's deleted or handed back when you leave; and that you'll be told about a breach inside a set window. This is the document that turns "we keep your inputs confidential" from a slogan into a promise you could actually enforce, the very thing that was missing in Heppner.

The Business Associate Agreement, the BAA, only matters if your matters touch protected health information, which covers personal injury, employment, healthcare, and some insurance work. If yours do, you need one, and a vendor can only offer it if its own infrastructure is covered upstream. Worth asking about early even if it isn't a day-one concern.

The Security Addendum is the technical muscle behind the DPA's promises: encryption at rest and in transit, access controls, how one firm's data is walled off from another's. Read it next to the vendor's SOC 2 Type II report and ISO 27001 certification, which are table stakes now, and increasingly ISO 42001, the newer standard built specifically for managing AI systems.

The Sub-processor list names the outside parties the vendor leans on to run the service, its cloud provider and its model provider, usually with a promise to give you advance notice before adding new ones. Read it. A short, transparent list, say a single cloud provider running the AI models inside its own walls, tells a cleaner confidentiality story than a long roster of separately contracted AI vendors.

The Acceptable Use Policy and the Privacy Policy round it out. The AUP sets the rules of the road for your people; the Privacy Policy covers personal data and is usually public. Neither is thrilling, but both should line up with everything above, with no quiet carve-out letting the vendor mine your usage.

And if you're piloting before you commit, which you should, a good vendor papers the trial separately so your pilot data gets the same protection as production from day one.

What "good" looks like, in a sentence

Lay those documents out and you're really looking for a consistent answer to one question: does this tool make privilege easier to keep, or harder? The green flags are concrete, and they should be in writing rather than on a webpage. Your data isn't used to train anyone's model. It stays in your country. It's encrypted, walled off per firm, and fully deletable on your say-so. Breaches come with prompt notice. The security posture is audited by someone independent. And nothing anywhere in the stack chips away at the plain truth that the lawyer, not the software, is the one practicing law.

How we think about it at Jubal

We built Jubal for small firms precisely because the Heppner trap is so easy to stumble into with consumer tools and so avoidable with a bit of design. The work is attorney-directed over a closed matter, so what you produce reflects your strategy and sits squarely in the work-product frame. Documents are encrypted, kept in the United States, and handled under commercial terms that don't train models on your data, with each firm and each matter walled off from every other. The agent runs locally over your own files, you control how long things are kept, and when you're done with a matter you can delete it and its data for good. The point of all of it is the same: the tool should help you keep privilege, not quietly waive it.

That's also why we're happy to hand over the paperwork and walk it line by line. The firms that ask the toughest questions about discoverability turn into our best clients, because once the answers are in writing, the worry shrinks back into what it always should have been: a faster way to do excellent work.


This is general information, not legal advice, and it doesn't create an attorney-client relationship. Confirm your obligations under your own jurisdiction's rules of professional conduct. Authorities referenced: ABA Formal Opinion 512 (2024); ABA Model Rules 1.1, 1.4, 1.5, 1.6, 3.3, 5.1, 5.3; Tremblay v. OpenAI (N.D. Cal. 2024); Concord Music Group v. Anthropic (N.D. Cal. 2025); United States v. Heppner (S.D.N.Y. 2026).