Ask most AI vendors if your data is safe and they'll say yes. Your data stays in your accounts. It's encrypted. It's never sold. All true, and all beside the point if you run a law firm.
Because "safe" answers the wrong question. The question that keeps a principal up at night isn't "could someone steal this." It's "could using this cost me privilege." Those are different problems, and a tool can nail the first while quietly creating the second.
I'm not a lawyer, and I won't pretend to explain the doctrine better than yours can. I build and run the systems that sit underneath a firm's day. So I'll stay in my lane and talk about the plumbing, because that's where this goes wrong.
What actually happened
Earlier this year, in United States v. Heppner, a New York federal court ruled on AI and privilege for the first time. A man facing fraud charges had used an AI chatbot to work through his own defence before he was arrested. When investigators seized his devices, his lawyers argued those AI conversations were protected. The court said no. Privilege depends on a confidential conversation with a licensed lawyer who owes you a duty, and an AI is none of those things. The chats weren't privileged. They were discoverable evidence.
That case was about one person and his own AI use. But it drags a bigger question into the light for any firm. The moment a matter leaves the privileged relationship and gets handed to an outside service, one that sits apart from you and your client, and may keep whatever it's given, you're on new ground. Not because anyone broke in. Because of what the tool quietly does with the file after it's handed over.
Security keeps data in. Privilege keeps matters apart
The distinction, from the systems seat:
Security is about keeping your data from leaving. Locks, encryption, access, the stuff every vendor talks about. Important, and table stakes.
Privilege is about how your data is handled once it's inside. Whose eyes and which systems touch a matter. Whether one client's file can end up in the context of another's. Whether there's a record of what happened to it. A tool can keep every byte inside your walls and still mix your matters together in a shared model, or leave you with no way to show a court what touched a file. Safe, and still a problem.
The three things worth checking on any tool you use
You don't need me for this. You can check it yourself this week.
First, read the retention line in the terms. Find where it says what the service does with the data you give it, and for how long. If it retains your inputs, or uses them to improve the product, that's the retention problem, and it's exactly what you don't want happening once a matter has left your walls. This one clause matters more than the whole marketing site.
Second, ask whether your matters are actually kept apart. When your team runs two different clients through the same tool, is each matter walled off, or is it all going into one shared space? If nobody can answer plainly, treat the answer as no.
Third, ask what the record looks like. If you ever had to show exactly what the system did to a file, and when, could you? If there's no log, there's no answer, and "we're not sure" is not a sentence you want to say about a client's matter.
What good plumbing looks like
A system that respects privilege starts from a few boring habits. Each matter runs in its own walled space, so one client's files never sit inside another's. The system starts with access to nothing and only gets what you grant it, for the matter you grant it. And every action is logged, timestamped and yours to export, so the record exists before you ever need it.
None of that is clever. It's just discipline, built in from the start instead of bolted on after a scare. Boring is the point. Boring is what holds up.
The honest version
I sell systems, not legal advice. So, straight talk: most firms have no idea which of their files are exposed through the tools they already use, because nobody's read the retention terms and nobody's asked whether the matters are kept apart. That's not a failing. It's just not anyone's job until it's suddenly everyone's problem.
It can be checked. That's the good news. Take an afternoon, or let me take a look at where your admin data actually flows and what your tools retain. No pitch, no jargon, just a plain map of your exposure and what to close first.
Your own lawyer will always have the final word on privilege. My job is to make sure the plumbing under your firm never becomes the reason you need that word.