Legal professional privilege and AI: where the real risk sits.

For a managing partner, the question that matters is where the risk to privilege actually sits. The answer is more specific than most commentary suggests: transmission and third-party access.

General information only. This guide is not legal advice and is not a substitute for advice about your specific obligations. Verify positions against the primary sources linked throughout, and take professional advice where it matters.

Privilege and confidentiality are different things

Client legal privilege under the Evidence Act 1995 (Cth) and its common law counterpart protects confidential communications made for the dominant purpose of legal advice or litigation. Confidentiality is broader: rule 9 of the Australian Solicitors' Conduct Rules binds practitioners to keep client information confidential regardless of whether privilege attaches. AI use can put pressure on both, but through the same mechanism: disclosure beyond the circle of confidence.

What the regulators have actually said

This is no longer speculative territory. In December 2024, the Law Society of NSW, the Victorian Legal Services Board and Commissioner and the Legal Practice Board of Western Australia issued a joint statement on AI in legal practice, stating that practitioners cannot safely enter confidential, sensitive or privileged client information into public AI chatbots (joint statement, VLSB+C). The Law Society of NSW followed with a solicitor's guide to responsible AI use (Law Society of NSW), and several supreme courts have issued practice notes restricting AI use in evidence preparation. The direction is consistent: the duty of confidentiality applies to AI exactly as it applies to any other disclosure. Our plain-English series on the regulators’ guidance covers each obligation in detail.

Where waiver risk actually arises

Privilege depends on confidentiality being maintained. The contested question for cloud AI is whether transmitting privileged material to a service provider, on the provider's terms, with the provider's retention and access rights, is consistent with maintaining it. Enterprise agreements improve the position; they do not make the transmission disappear. For a no-egress unit the question does not arise, because no third party receives the communication at all.

Questions to put to any AI vendor

Where is our material processed?

Not stored: processed. Storage residency and inference location are different answers, and vendors often give the first when asked the second.

Who can access prompts and outputs?

Support staff, abuse review, subpoena response. Ask for the list of humans and legal processes that can reach your content.

What law governs the relationship?

Several major providers contract Australian customers under foreign law. Read the governing law clause before relying on the privacy clause.

What is retained, and for how long?

Zero-retention options exist at some vendors; defaults usually retain something. Get the default in writing.

Can the answer be verified?

Certifications attest to process. Ask what your firm could independently inspect. For on-premise deployment the answer is: the unit itself.

The practical takeaway

Nothing in the current guidance says a law firm cannot use AI. All of it says the confidentiality analysis cannot be outsourced to a vendor's marketing page. Firms are resolving the tension in one of two defensible ways: strict no-client-data policies for cloud tools, or moving the AI inside the building so the productive path and the compliant path are the same path. Our law firm page covers what the second option looks like in practice.

Common questions

Can our firm use ChatGPT at all?
For general research and drafting containing no client information, many firms permit it with verification requirements. The regulators' joint statement draws the line at confidential, sensitive or privileged client information in public AI tools. The hard problem is enforcement under deadline pressure, which is a policy problem more than a technology one.
Does using an enterprise AI tier protect privilege?
It improves the contractual position: no training on your data, better retention terms, admin controls. The structural fact remains that privileged material is transmitted to and processed by a third party, and that is the fact a privilege analysis has to grapple with.
Is on-premise AI automatically privileged-safe?
It removes the third-party transmission question, which is the distinctive AI risk. Ordinary confidentiality discipline still applies: access controls, supervision and verification of outputs remain your firm's responsibility.

See Dominion answering from your own documents.

A demonstration takes 30 minutes, uses no client data, and comes with no obligation.

Book a demo