What happens to privilege when a law firm uses a third party AI tool?
Privilege is not automatically waived when a firm puts client material into a third party product, and it is not automatically preserved either. The question courts and bar authorities keep returning to is whether the firm took reasonable steps to keep the material confidential, which makes most of the analysis a set of facts a buyer can check before signing rather than argue about afterwards. The AI Legal Index grades 130 legal AI vendors on Privilege and Confidentiality Posture and records three of those underlying facts separately. Across the index, 8 vendors publish a confidentiality position an outsider can verify end to end, 6 of 130 document that retrieval enforces the firm's own access model at query time rather than a second permission system, and 33 of 129 commit in their terms to telling the customer when a third party asks for its data. 79 publish nothing on that last question at all, which means a firm using them would learn about a subpoena to its vendor after the material had already gone.
This page is not legal advice and does not tell a firm whether privilege survives any particular deployment. That answer depends on the jurisdiction, the matter and the facts, and it belongs to the firm and its own counsel. What an index can do is narrow the question to the part a buyer controls, which is the evidence a vendor publishes before anyone signs anything. Three records carry most of that weight: the ethical wall posture, the subpoena notice commitment, and whether the agreement addresses privileged material at all.
Which legal AI vendors sign a confidentiality agreement covering privileged material?
What a vendor signs privately, an index cannot see. What it can grade is whether the agreement a buyer reads before signing addresses privileged and work product material directly, states where client data sits, and says what happens to it. These vendors publish a position an outsider can verify end to end.
What a vendor signs privately, the index cannot see, so what it grades is what the vendor publishes: whether the agreement a buyer can read before signing addresses privileged and work product material directly rather than treating it as ordinary customer content. 8 vendors record an A on Privilege and Confidentiality Posture: Alexi, Casepoint, Eve, Everlaw, GC AI, Noxtua, Patlytics and Solve Intelligence. A further 58 carry substantive published commitments with one real gap, usually a segregation or retention term stated in a trust page rather than in the agreement. 50 make the claim without publishing the document behind it, and 14 publish nothing on the question a buyer can check. A firm can still negotiate a bespoke confidentiality term with any vendor here. The grade records what was on offer without asking.
Substantive disclosure, one real gap
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.Enough published for a buyer to act on, short of the artifact that would settle the question. On this axis the missing artifact is usually a segregation or retention term that lives in a trust page rather than in the agreement itself.
- Alt LegalIP & Patents
- AnkarIP & Patents
- AugustGeneral Legal Assistants
- Billables AILegal Ops & Spend
- Blue JLegal Research
- BrightflagLegal Ops & Spend
- ChamelioContract Review & Drafting
- CheckboxLegal Ops & Spend
- ClearbriefLitigation & eDiscovery
- ClioIntake & Client Development
- CloudLexPlaintiff & Claims AI
- CoCounsel LegalGeneral Legal Assistants
- CosmoLexIntake & Client Development
- DeepIPIP & Patents
- DeepJudgeLegal Research
- DigitalOwlPlaintiff & Claims AI
- DISCOLitigation & eDiscovery
- EvenUpPlaintiff & Claims AI
- FilevinePlaintiff & Claims AI
- HarveyGeneral Legal Assistants
- IPRallyIP & Patents
- IroncladContract Review & Drafting
- JuroContract Review & Drafting
- LeahContract Review & Drafting
- LEGALFLYGeneral Legal Assistants
- LegalOnContract Review & Drafting
- LegoraGeneral Legal Assistants
- Lex MachinaLegal Research
- LexroomLegal Research
- LitemLitigation & eDiscovery
- LitifyPlaintiff & Claims AI
- LuminanceContract Review & Drafting
- MidpageLegal Research
- MyCaseIntake & Client Development
- NeosPlaintiff & Claims AI
- NexlIntake & Client Development
- NextpointLitigation & eDiscovery
- OmnilexLegal Research
- OneTrustRegulatory & Compliance Counsel
- OntraLegal Ops & Spend
- Pre/DictaLegal Research
- QuestelIP & Patents
- RelativityLitigation & eDiscovery
- RevealLitigation & eDiscovery
- SandstoneLegal Ops & Spend
- SecuritiRegulatory & Compliance Counsel
- SirionContract Review & Drafting
- SpellbookContract Review & Drafting
- StenoLitigation & eDiscovery
- Streamline AILegal Ops & Spend
- SupioPlaintiff & Claims AI
- TavrnPlaintiff & Claims AI
- TranscendRegulatory & Compliance Counsel
- VesenceGeneral Legal Assistants
- Vincent AILegal Research
- WordsmithGeneral Legal Assistants
- XakiaLegal Ops & Spend
- XLSCOUTIP & Patents
Which legal AI tools support ethical walls and matter level segregation?
Inherits document system permissionsA firm already pays to maintain walls in its document management system. The question is whether the product inherits that access model per user and per matter at query time, or whether it built a second permission system somebody has to keep in step by hand.
6 of 130 vendors document that retrieval enforces the source document system access model at query time, per user and per matter: Casepoint, CosmoLex, DeepJudge, Harvey, MyCase and Vincent AI. That is the posture that leaves an existing ethical wall intact, because the wall keeps being enforced by the system that already maintains it. 26 maintain their own permission model and document it, which works and moves the burden onto the firm to keep two access models in step. 29 assert segregation in public materials with no published detail on how it is enforced, and 69 publish nothing on walls or matter level segregation. A retrieval layer that indexes the whole corpus and answers from all of it defeats a wall silently, and the failure surfaces as a conflict rather than as an error message.
Full definitions of every value on this signal are on the signals reference, and each vendor profile carries the source and the verification date behind its recorded value.
If a vendor is subpoenaed for a firm’s data, does the firm hear about it first?
Privilege is asserted by the client, not by a software company. A vendor that can be served and can produce client material without telling the firm removes the firm’s chance to move to quash, and may remove any chance of learning the material left at all. A published commitment to notify where lawfully permitted, plus a transparency report showing what has actually been received, is the difference between a stated principle and an operating practice.
Of 129 vendors recorded on this signal, 33 commit in their terms to notifying the customer where lawfully permitted. 17 address disclosure to authorities or in response to legal process while saying nothing about whether the customer is told, which is the combination worth noticing: the vendor has confirmed data can leave and has left the notice question blank. 79 publish nothing either way.
And the finding that took the least work to establish and says the most: not one vendor in the index publishes a transparency report showing what legal process it has actually received. Every other technology sector that holds sensitive customer records produces these routinely. In the sector selling to the profession that invented privilege, the count is zero.
What the index cannot tell you
Three limits, stated plainly, because a low grade here is a statement about disclosure and would be misread as a finding about the product. A negotiated engagement term or a signed confidentiality agreement is a private document, so a vendor that grants a firm exactly what it asked for in a bespoke contract records only what it published. A vendor that answers these questions well in a security questionnaire and publishes nothing grades on the published position. And an absence is dated: it means not located in public sources on the date shown, and a vendor that publishes a term tomorrow is redated the day it does. A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
What none of that changes is the buyer’s position. A commitment that exists only in a sales conversation leaves no artifact, and an artifact is what a firm hands to its own risk committee, its malpractice carrier, or a court asking what reasonable steps were taken.
Every record behind this page carries a source basis and a verification date. Standards and limits are on the methodology page. The training question sits next to this one and is answered on do legal AI vendors train their models on client data, the accuracy side of the same diligence is on which AI legal research tools publish their hallucination or accuracy rates, the professional responsibility duties around all of it are on what the bar rules require before a lawyer uses AI on client matters, the security attestation behind a vendor review is on which legal AI vendors publish SOC 2 or ISO 27001 certification, and the wall question crossed with integration depth is on which AI legal tools integrate with iManage and NetDocuments. The complete vendor set is in the directory.