Watch: What General Counsel and Business Leaders Need to Know

  • Open-Source AI Puts Privilege at Risk: Communications with open-source artificial intelligence (AI) platforms lack the attorney involvement and confidentiality that privilege requires. Courts are ordering the disclosure of both prompts and outputs when these elements aren’t satisfied, as the exchanges are with non-attorney third parties rather than counsel.
  • AI Creates a False Sense of Confidentiality: While AI interfaces may appear closed to the company’s own system, information typed into open platforms is used to train the AI itself, creating a false sense of confidentiality. Unsupervised employee use is a big risk.
  • Early Counsel Involvement Is Essential: Counsel should supervise and direct the use of AI tools, and closed or enterprise-level systems should be deployed instead of open platforms. In-house counsel’s early involvement is vital to establishing privilege protection when disputes are reasonably foreseeable, since attempting to claim privilege after information is already created is ineffective.

In this episode of Speaking of Litigation®, Epstein Becker Green attorneys Gianna Costello, Daniel J. Dwyer, and Adam Paine analyze how courts are applying the traditional attorney-client privilege and work product doctrine to AI-generated materials and communications, and address the practical steps in-house counsel must take when employees are using AI in litigation-related work.

Transcript

[00:00:05] Gianna Costello: Today on Speaking of Litigation, we're discussing the traditional elements of attorney-client privilege and work product doctrines, and discussing practical guidance for discoverability of litigation documents where AI is implicated. Hello, everyone. I'm your host, Gianna Costello. I'm an attorney in Epstein Becker Green's litigation practice, and I'm based out of our Boston office.

[00:00:29] Gianna Costello: In litigation, essentially all documents and communications are potentially subject to discovery and must be produced to an opposing party unless a privilege protects a document or communication from disclosure. Understanding the traditional elements of attorney-client and work product privilege, and the potential consequences of using AI tools, is important to protect yourself and your company from a disastrous waiver of privilege and compelled disclosure of sensitive strategic information, communications, and analysis. Joining our discussion today are Daniel Dwyer, who is a member of the firm here with me in our Boston office. Dan brings over 25 years of commercial litigation experience. Hi, Dan. Thank you for joining.

[00:01:09] Adam Paine: Morning.

[00:01:10] Gianna Costello: Adam Paine, also a member of the firm in our Boston office, also joins us today. Adam's practice ranges across a broad range of commercial disputes in state and federal courts.

[00:01:20] Gianna Costello: Hi, Adam.

[00:01:20] Adam Paine: Hi, Gianna. Thank you. Hi, Dan.

[00:01:22] Gianna Costello: To start today, we'll have a general discussion of attorney-client privilege and work product privilege. Dan, I'll start by asking you to review the basic elements of attorney-client privilege.

[00:01:33] Daniel Dwyer: Sure. Before I touch on the elements, though, I'd like to emphasize in the beginning a point that you mentioned, a little more emphatically. Everybody should begin with the assumption that everything is discoverable. It's a scary point, but it's worth remembering. The good news is that it's not discoverable if you can put it in the attorney-client privilege, and that that's doable, but you always must do it. There are competing policies running beneath the mechanics of the privilege.

[00:02:05] Daniel Dwyer: One is for free discovery of all relevant facts and the necessity of those for a court or a jury to be able to review in order to render a just verdict. And the other, of course, is to the competing policy, is to enable clients to make full disclosure to legal counsel of all relevant facts that will help counsel render fully formed legal advice. So there's a natural tension there between the policies, and the default is that everything is discoverable unless you put it in the privilege in the first place and not let it out. Now, the way to do that is to conduct yourself in accordance with the elements of the privilege. The privilege protects disclosure of communications, one, between a client and its attorney, two, that are intended to be and in fact were confidential, and three, for the purpose of obtaining or providing legal advice.

[00:03:03] Daniel Dwyer: Scrupulously following those elements will keep your communications privileged. But for example, if somebody outside the privilege is in the room or on the phone with you and your lawyer or client during the communication in the first place, it was never privileged. And second, if you have a communication that is privileged in the first place and disclose it to somebody who was outside the privilege later, there's very good grounds for opposing counsel to argue that you've waived the privilege, which can have disastrous results. We won't detail them now, but the point is that it's more than one little communication that you happen to leak outside the privilege that can be discovered, so you must be vigilant at all times to protect these communications and keep them privileged.

[00:03:50] Gianna Costello: So can you explain to us when communications are protected by the privilege versus when they aren't protected by the privilege, and how you maintain that attorney-client privilege?

[00:04:00] Daniel Dwyer: Well, I think they're privileged in the first place, again, just by conforming and realizing, being conscious of the elements. You must have a communication between client and attorney or the representatives of those people. It has to be about legal advice. It can't be about any old thing. And it has to be confidential in the first place and kept confidential, as I said. Under the heading of things that are not about legal advice, there are certain facts that get communicated back and forth, and those are not privileged in the first instance. In other words, if I'm a client and I have a letter from someone to me and I send it to you, Gianna, who is my lawyer, if I forward it to you in an email, and in my email I have a lot of commentary, my commentary for you is privileged and non-discoverable.

[00:04:51] Daniel Dwyer: But the letter itself or whatever it may be is not privileged. That is a discoverable item. And I've seen plenty of instances where people would like to throw the cloak of privilege over something that wasn't privileged in the first place because they were sending it to their lawyer, and it doesn't work. So those are generally the things that come up as, you know, what's within and what's without the privilege and whether you can keep it that way.

[00:05:18] Gianna Costello: Are there any exceptions to when disclosure to a third party doesn't destroy attorney-client privilege?

[00:05:24] Daniel Dwyer: Yes, but they're rare, and these two are, courts guard against overuse of privilege arguments in this area. The area I'm speaking of is generally referred to as the Kovel doctrine, and the Kovel doctrine allows a non-party to the privilege, that is not a client and not the lawyer and not the representative of either, to be the third person in the, a privileged communication, if the third person's participation is necessary for the rendering of legal advice, and the necessity as opposed to the utility or advisability is crucial, and this is studied in a lot of cases that examine the Kovel doctrine. You can't bring a third party in who was helpful for one reason or another and then say, "Well, that person's the third party protected by the Kovel doctrine, and we haven't committed a waiver."

[00:06:25] Daniel Dwyer: You have committed a waiver unless the person was necessary to the rendering of advice. For example, a tax accountant who is translating essentially tax realities and tax talk into ordinary English as most people understand it is someone whose participation has been held to be privileged but they have to be doing, as I say, the translating. In fact, some of the cases, a lot of the cases, use the word translating as such. Naturally then, a translator, literally a translator, someone who translates from one language to another so that the lawyer can render advice to a non-English-speaking client, the presence of that person will not waive the privilege.

[00:07:09] Daniel Dwyer: But in other contexts that are not language translations, courts use the analogy of language translations to emphasize the centrality and necessity of the third person's presence for the third person's presence not to violate the privilege.

[00:07:26] Gianna Costello: So now let's transition to talking about work product privilege. Could you walk us through the basic elements of work product privilege?

[00:07:33] Daniel Dwyer: Work product privilege is, or it pertains to materials prepared by or at the direction of counsel in anticipation of litigation rather than in the ordinary course of business. The policy here is that, like the privilege, it allows lawyers to develop legal theories that can help their clients be well-represented. There's sort of an asterisk. Although it's called the attorney work product doctrine generally, you don't necessarily have to be an attorney to be the person who works with the clients to formulate strategy or prepare these materials. Certain types of people, like an insurer, an indemnitor, and other strict categories, I don't wanna go too far down the representative branch of this analysis because it may vary a bit from jurisdiction to jurisdiction, but it's also generally consistent from jurisdiction to jurisdiction. So that's what will keep your material privileged under the work product doctrine.

[00:08:35] Gianna Costello: So Adam, how does attorney-client privilege apply to in-house counsel?

[00:08:39] Adam Paine: The key thing to understand for in-house counsel is that the client in the relationship is the company. It's the entity itself, not specific employees. So communications between employees and an in-house or outside counsel are going to be analyzed under the same privilege elements that Dan was discussing. Are they confidential communications between, with an attorney? Are they for the purpose of seeking or rendering legal advice? And are they, you know, kept confidential within the relationship?

[00:09:13] Gianna Costello: What about documents prepared by in-house counsel? Are those protected by any privilege?

[00:09:18] Adam Paine: Usually, yes. Documents in-house counsel prepares, a legal memo, a risk assessment, litigation strategy, are protected by either attorney-client privilege or work product protection, so long as they satisfy the elements that we've been discussing. Documents or materials prepared at counsel's direction to assist in the preparation of litigation strategy or assess legal risk with litigation ongoing or foreseeable will be protected from disclosure under the work product doctrine. Materials can be disclosed or distributed within the company to employees who have an interest and a need to know the information, but should not be freely distributed to everyone in the company.

[00:10:00] Adam Paine: That increases the practical risk that materials could be disclosed outside of the company, and courts may consider documents that are freely disclosed through the entire company as not confidential sufficient to satisfy the confidentiality prong of the protections.

[00:10:18] Gianna Costello: I think we all know that in-house counsel go beyond the role of legal counsel and often also act as business partners and advisors. So how do those two roles affect what's covered by attorney-client or work product privilege?

[00:10:32] Adam Paine: Certainly. In-house counsel walking the line between business advisor and legal advisor creates a genuine risk that documents or communications won't necessarily be protected by the privilege. The attorney-client privilege is only going to attach when the communication is for the purpose of seeking or providing legal advice. The communication to in-house counsel for business guidance or business strategy is not going to be privileged for that reason. It's failing to satisfy that element. So the counsel needs to, to ask themselves, is this document, is the true purpose of this communication or this document the provision of, of legal advice?

[00:11:16] Adam Paine: If so, the attorney-client privilege will attach and protect that document from disclosure should litigation arise. If it's purely operational, strategic business advice, then that information will not necessarily be privileged. If there is legal analysis and legal advice intermingled within the strategic or operational business guidance, the legal advice can be redacted out should litigation arise and the document need to be produced, but there runs a real risk that business advice intermingled with legal advice will subject that document to disclosure.

[00:11:52] Gianna Costello: So what about things like emails and internal messages like Slack or Teams messages? If I am sending an email and I copy an attorney, an in-house counsel on that email, is that enough to invoke the privilege?

[00:12:06] Adam Paine: No. Simply copying legal counsel is not going to automatically cloak that email or communication with privilege. The emails or any sort of communication, instant messaging, Teams, Slack, chat, anything like that, email, still need to satisfy the elements of the attorney-client privilege. So the content and structure of it is crucial. As long as the communication satisfies the elements of being for the purpose of seeking or providing legal advice or referencing the work product doctrine if the communication is in the context of preparing for litigation, that communication could be protected, but simply copying an attorney is not sufficient to invoke the privilege.

[00:12:52] Gianna Costello: And what about Google searches? Are those protected by any privilege, and are they typically discoverable?

[00:12:58] Adam Paine: Generally, Google searches or internet search history could be discoverable. They're exchanges that are not with an attorney. It's with a third party company with no obligation to keep that information, your search history, confidential. As the communication is not with an attorney, it's not gonna satisfy the elements. So you know, courts could and do order the production of internet search histories. Here in Massachusetts, within the last year or so, we saw the Karen Read case where Google search histories became widely discussed evidence in the case.

[00:13:40] Gianna Costello: Okay, so transitioning to more of a hot topic, artificial intelligence, how have courts been analyzing the discoverability of documents that might be protected by one of these privileges that are created with the assistance of AI? Dan, maybe you could answer this one?

[00:13:59] Daniel Dwyer: Sure. Courts have been analyzing this issue under traditional principles and the attorney-client and work product privilege doctrine generally, and that seems to me a very, very sound way to proceed. The common law principles, they sound textbook-y, but they really have a lot of vitality and utility and common sense, and new things come along to test them all the time and this is another. If you take a scenario, and I think we'll come a little more to this, but if you take a scenario in which somebody puts prompts into an open AI that is not a closed system and is not the lawyer's closed system, into an open-source generative AI, the prompts and what comes out of it may well be deemed discoverable because it's not a communication with a lawyer. Somebody may think it's confidential, but it's, with respect to open-source software, it's not confidential. In fact, the information you type in is being used to help the AI teach itself better. And even if it's used, the inquiries are for the purpose of thinking about one's case, they're not really for the purpose of obtaining or providing legal advice.

[00:15:11] Daniel Dwyer: So I don't wanna state a categorical proposition that all of this stuff is gonna be discoverable, but I began everything I said today with a warning that by default, things begin as discoverable, and you have to get them within the privilege. And this is an area that's very, very fraught for people who think they can freely use AI and never have anybody know.

[00:15:32] Adam Paine: Yeah, jumping in, the challenge isn't that AI has the same risks of disclosure that we've been discussing, you know, disclosure to a third party potentially waiving the privilege. It stress tests every element because of almost the nature of the AI tool. It seems like a chat that's closed to your, to your computer, to your system that, you know, it lures people into a false sense that they're communicating confidentially, and that's just not the case.

[00:16:03] Adam Paine: They're also not communicating with an attorney. They're creating a record, a log of a chat, effectively a chat function with a tool that's not an attorney. So as Dan said, as courts analyze these cases, and they're quickly evolving, and it's such a new and developing area of law, so there aren't too many cases on the topic out there. But as we're seeing, courts are analyzing these exchanges under the traditional framework, and if exchanges don't satisfy all three elements or can fit into the work product doctrine, courts are ordering the disclosure of AI prompts, the inputs that people are using, as well as the, you know, the output that the AI chat is delivering back to the user.

[00:16:52] Gianna Costello: So as a general rule, would you say AI is usually protected by the privilege?

[00:16:57] Adam Paine: So generally, exchanges with an AI tool are not gonna satisfy the elements of the attorney-client privilege. Potentially there may be work product protection for the use of an AI tool if it satisfies those elements. Some courts, specifically in the district of Colorado and Michigan, have concluded that pro se litigants who have used AI tools to assist in their own representation, their representation of themselves, rather, their use of an AI tool satisfies work product protection and they were not ordered to disclose their input and output they received from an AI tool.

[00:17:38] Adam Paine: Other courts recently in Massachusetts have concluded that the use of an AI tool without the direct involvement, oversight, direction of an attorney is not protected as work product. If a client is using an AI tool on their own volition and not for the purpose of communicating with their attorney, those exchanges are not protected.

[00:18:02] Gianna Costello: Dan, a few minutes ago you told us about the Kovel doctrine and explained how sometimes there's an exception where you can communicate with a third party and have those communications maintain their protected status. Do you think that AI communications could be protected there?

[00:18:20] Daniel Dwyer: Generally, no, because as transformative and fascinating as AI may be, we had lots and lots of lawsuits before we had it, which means that AI is not necessary, the use of AI is not necessary the way the presence of a translator or a particularly skilled consultant of one kind or another is necessary for the rendering of legal advice.

[00:18:46] Daniel Dwyer: You don't need to have AI in order to to be represented. Adam touched upon its protection under the work product doctrine, and that's of course, it depends on the satisfaction of the criteria of the work product doctrine. So if an attorney uses any one of the products that are available to an attorney, closed systems, an AI product, I mean, of course, then, then, well, that falls within the work product privilege because it satisfies all the elements. So the work product privilege can apply to cover these things, but it doesn't necessarily apply, and the communication with AI as an elementary matter, the communication with AI is not like a communication with a translator who is helping you speak with your own attorney.

[00:19:39] Gianna Costello: We know that many companies are adopting generative AI systems, and in many places employees are using AI whether or not they're encouraged to do so by their employers. Do you have any advice for in-house counsel who are navigating this field?

[00:19:56] Adam Paine: Definitely. The first biggest risk is unsupervised use of AI, and as litigators, particularly in the context of when a dispute is developing or reasonably foreseeable, the first step needs to be engaging counsel, either in-house or outside counsel, to supervise and direct the use of an AI tool, not simply uploading documents or prompts into an AI tool for litigation strategy or guidance.

[00:20:27] Adam Paine: That use needs to be specifically directed by counsel. Second, technology selection matters. We've talked about the open nature of certain AI tools. A closed or an enterprise-level system is critical to ensuring that the exchanges with an AI tool are gonna satisfy the confidentiality prong. That so long as the exchanges are closed internally to the company or the user and not being fed back into the system, that'll maintain the confidentiality requirement and avoid waiving attorney-client privilege or work product protection on the, on that confidentiality prong.

[00:21:12] Gianna Costello: So what I'm hearing is that case law on this topic is limited, and that courts are tending to apply the traditional framework, and if communications or work product does not satisfy all of the elements, courts may compel disclosure of these documents. Dan, I have one last question for you. How should companies respond when law firms ask permission to use AI in their cases?

[00:21:35] Daniel Dwyer: Positively. For all the warnings we've been giving about discoverability, AI itself is a fantastic tool, and law firms have closed systems generally. Their lawyers are getting better and better at using it for the client's benefit. And so long as all the privilege things we've been discussing remain satisfied, it's much to the client's benefit that their lawyer is able to employ AI in refining or thinking through the legal strategy.

[00:22:07] Daniel Dwyer: If I could, I'll add one point directed not to the company as a client, but to company counsel, that is in-house counsel, which is my recommendation would be that if you are aware of something that might bubble up into a controversy or litigation, get involved quickly. I'm not saying you have to get minutely involved quickly, but your presence is vital to the creation of the attorney-client privilege, and generally to the satisfaction of the work product doctrine. So don't wait for a lot of discoverable information to be created before you then get involved and throw the privilege over everything.

[00:22:50] Gianna Costello: Adam, have you seen AI communications being sought as discovery in active litigation?

[00:22:54] Adam Paine: Absolutely, and it's increasing. We're seeing opposing counsel specifically request all documents created with AI assistance, all prompts sent to all platforms, communications with platforms like ChatGPT or Claude.

[00:23:07] Adam Paine: So it's critical to know, as an in-house counsel, what AI tools are being used, by whom, where, and why, so should litigation or a dispute arise and opposing party seeks exchanges with an AI tool in discovery, there are no surprises of where those tools are used. Recently in Massachusetts, there was a case where the opposing party sought disclosure of communications that had been redacted in discovery, and they did not know that the reason for the redaction is that the party and his romantic partner were using an AI tool to assist them in litigation.

[00:23:44] Adam Paine: And when the party seeking the disclosure filed a motion to compel, the withholding party's opposition actually disclosed, "Oh, it's because this was created with the use of AI," and tried to use that as a justification for withholding the documents. So the court concluded that simply using AI did not invoke any sort of work product protection or attorney-client privilege, and ordered the disclosure of all those materials.

[00:24:09] Adam Paine: So as companies and organizations expand their use of AI tools and learn about all the capabilities, it's imperative for in-house counsel to maintain a level of awareness of how these tools are being used and where and why, to ensure … to avoid any sort of misstep should litigation arise.

[00:24:30] Gianna Costello: Thanks for watching and listening. Please subscribe to Speaking of Litigation on YouTube or wherever you get your podcasts.


In Case You Missed It

Powerful Tool, but Not an Attorney: Massachusetts Court Rejects Work Product Protection for AI-Generated Documents, Commercial Litigation Update

ABA and FWA: Providers Operate in a High-Risk Environment, Commercial Litigation Update

Harnessing AI in Litigation: Techniques, Opportunities, and Risks, Speaking of Litigation Podcast

About Speaking of Litigation

For executives and in-house counsel—before, during, and after a dispute. No business likes litigation, but almost every business faces it. Speaking of Litigation® delivers practical intelligence to help you make better decisions when it matters most. Part of the Epstein Becker Green Insights Network.

Email Notifications

Sign Up Here

Follow Us

Never miss an episode! Subscribe to Speaking of Litigation on your preferred platform:

Amazon Music      Apple Podcasts      Overcast      Pandora      Spotify      YouTube

Also on Audible |  Deezer |  Goodpods |  iHeartRadio | PlayerFM |  Pocket Casts | YouTube Music

Back to Series
Jump to Page
Advanced Search ›

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.