Does attorney-client privilege exist when you use ChatGPT or Claude? Should it?
Jacob Robinson sits down with Mike Katz, Partner at Manatt Phelps & Phillips, to examine whether attorney-client privilege, work product or any analogous protection applies when people ask AI chatbots legal questions.
Timestamps:
➡️ 0:00 — Background
➡️ 1:47 — What is attorney-client privilege?
➡️ 2:44 — Policy reasons for narrowing privilege
➡️ 3:30 — The
#186 - AI & Legal Privilege
Executive Summary
This episode explores how attorney-client privilege applies, and often fails to apply, when people use AI chatbots for legal questions. Jacob Robinson and Mike Katz explain the core elements of privilege, the ways it can be lost, and why consumer AI tools like Claude, ChatGPT, and Gemini usually do not qualify for privileged communications. They also examine the U.S. case involving Scott Hennepin, which a judge treated as a first-impression question about AI and legal privilege. Along the way, they discuss work product doctrine, deletion and preservation risks, and how lawyers may still use AI properly within privileged workflows. The episode closes with a broader reflection on how legal practice will evolve as AI becomes a standard tool.
Jacob Robinson: Everyone's talking to an AI chatbot today, but few people realize that they may be creating a discoverable record that can be used in future litigation. How does attorney-client privilege change in an era of AI?
Welcome to the Law of Code. I'm your host, Jacob Robinson. This is the podcast about the legal layer of emerging technology.
In this episode, I'm joined by Mike Katz, a partner at Manatt's Financial Services Group, and we dive into legal privilege: what it is, how it's established, how it's lost, what courts in the U.S. and the U.K. have decided about AI use and privilege, and what else you should know before feeding sensitive information into an LLM chatbot like Claude, ChatGPT, or Gemini.
To prepare for this podcast, I've poured through a lot of your articles, lawsuits, court orders, spoke to top legal experts. I read the terms and conditions for services like Claude. That plus the interview that Mike and I do and the editing that I all do myself took me about 15 non-billable hours. I loved every second of it, and I'm so glad I'm able to do that, thanks to the sponsor of this episode, Day One Law.
They're a boutique corporate law firm that works with Web3 innovators, founders, and startups. They believe in the importance of high-quality legal work, and thankfully for me, this podcast. I'm really grateful to Nick Pullman and his team there. If you do reach out to them, let them know that I say hi.
Now with that said, let's get into the episode on legal privilege and AI.
Anything mentioned in this episode by Jacob Robinson or his guest is not legal advice or investment advice. All opinions are Jacob's and his guest's alone. Nothing discussed today should be relied upon for legal or investment decisions. This show is solely for information and entertainment purposes only. Jacob and his guests are not your lawyers, nor are they investment advisors. Please work directly with a lawyer or investment professional.
Jacob Robinson: Let's start with legal privilege. Walk me through what legal privilege is. It's one of those things that everybody's heard of, but not many people know actually what it means.
Mike Katz: Privilege is the reason you can tell your lawyer whatever you've done, what you're thinking, and that it can stay in the room, and it can stay protected, and it's between you and your lawyer. Without it, clients shade facts, lie, and lawyers then give bad advice because they're not operating on the full truth and the full record. The system would break down without legal privilege.
The Supreme Court, in the famous case of Upjohn, which is the defining case around privilege, framed it as encouraging full and frank disclosure so lawyers can give candid advice and effective representation. That's the baseline of what lawyers want to do, should be doing, and are needed to do for the system to work. But courts still construe privilege narrowly.
Jacob Robinson: Mike makes a really important point about courts considering privilege narrowly. That's something we want. We want that as a policy goal, because if you don't, what you're essentially doing is giving criminals a way to protect themselves from incriminating evidence, where they may be searching Google, they may be using other tools, they may be writing notes about impending cases, and Mike's going to give some great stories about where this has happened.
But I think it's important to keep in mind that privilege isn't something you want to overextend, because now you're giving immunity, essentially, to people who may have done some things that they shouldn't.
We'll go back to the episode, where Mike is about to explain the details of the Upjohn case, which is one of the most important cases when it comes to privilege in the United States, and principles from this case have been imported to jurisdictions across the world.
Mike Katz: In that case, there was a pharmaceutical company. Their general counsel discovered that they may have been bribing foreign officials, and he did the right thing. He did an internal investigation. He spoke to employees. He asked them questions. He took notes. The IRS was investigating the company and subpoenaed all those notes and said these are not privileged. Privilege doesn't apply here. The GC was talking to on-the-ground employees. That's not what privilege is.
And the Supreme Court disagreed. They wrote the opinion saying privilege covers communications between corporate counsel and any employee, not just the control group, the management, the C-suite, at the direction of management for the purpose of securing legal advice.
So Upjohn is the reason corporate internal investigations work the way they do today. It's why you get an Upjohn warning. For people who haven't heard that, I gave a lot of those when I was in-house, where if you're talking to an employee to discuss facts of an issue, you have to say, I represent the company, not you. The company holds the privilege. They can waive it. But the fact that the company has the privilege at all and can do this and operate this way is because of that case.
And there's two types of privilege when it comes to legal privilege. There's the attorney-client privilege, which is communications between you and your lawyer. Also the work product doctrine, which is something that matters in the case involving Claude, and one we'll talk about in a minute, where if an attorney is using some note-taking app or something to prepare for a case, to conduct maybe an investigation that isn't directly tied to something yet, that can also be protected by privilege as well.
Jacob Robinson: Those are important points that we'll cover in detail. But I want to step back a second and say, OK, privilege is important, but number one, how do you establish privilege? Because privilege isn't guaranteed even if the conversation is involving a lawyer, because you could be scheduling a meeting. That might not be privileged. So walk me through how we establish privilege.
Mike Katz: I'm a lawyer. I have conversations with people every day, and they are not all privileged, obviously.
In order to establish privilege, you need three elements.
The first is communication with an actual attorney. Attorney means a licensed lawyer or someone functioning as a lawyer's agent. Your accountant doesn't count. Your buddy who took a negotiations class in undergrad doesn't count. Harvey from *Suits* doesn't count. You have to be an actual lawyer. And again, most relevant to our combo today, a chatbot, a consumer chatbot, Claude in general, ChatGPT, Gemini, whoever, doesn't count.
I will note, and this is something worth noting, that if you have a reasonable expectation that someone is a lawyer, that may count in certain instances. But again, it almost always has to be an actual license.
Jacob Robinson: To interrupt on that point quickly, in the Hennepin case we're going to talk about, the government actually went in and asked Claude whether or not it can give legal advice, and it explicitly disclaims that it is not legal advice, it is not a lawyer. All the consumer chatbots will say this. If you go in and you say, mark up this contract, it'll say, please check with legal counsel. I'm not a lawyer. I cannot provide legal advice, et cetera.
Mike Katz: Element one: actual communication with an attorney.
Element two: confidentiality. The communication has to stay between you and the counsel. If you loop in a third party who isn't part of the team, you're going to blow it. If you forward an email or a memo that was privileged to your business partner who is not a lawyer, you've blown privilege. If you discuss your lawyer's advice on a group Slack channel, you've blown it.
And again, with the chatbots, if they're saying they're training it, they're storing it, they can share it, that's not confidential.
Jacob Robinson: Just to jump on that point too, that's often very obvious if you just look at the terms of service. And there's different terms of service between enterprise contracts, which may not train the LLMs on what you're uploading, compared to the personal ones that most people are using, which often say that we will share this information with government authorities and other people who ask.
Mike Katz: Exactly. There's a reason why consumer Google, consumer AI chatbots, and any of these things, the terms of service are quite clear. They save them, they record it, they train it, they use the data, and they will share data with plaintiffs or under subpoena or with the government.
So you have element one, communication with a licensed attorney, and element two, confidentiality. Then you have the third element, which is it needs to be for the purpose of obtaining legal advice. If you're talking to your lawyer about a business decision, and it has nothing to do with legal, that's not privileged. If you're talking to your lawyer about the next game, that's not privileged. If you're talking to your lawyer and seeking legal advice, yes, that could be privileged if it meets all three elements. So it needs to be a genuine discussion where the primary purpose was legal counsel.
And work product is a bit different. That requires that the material is prepared by or at the direction of counsel. And that's a very important point that comes up in the Hennepin case, where someone uploaded things to Claude not at the direction of counsel, but just because they wanted to know. They actually said that they were uploading these documents to Claude so that they can work with counsel. That's very different than doing it at the behest of counsel, and that's an important distinction that comes up here too.
Jacob Robinson: So now we've got how we establish privilege. What happens when you lose it?
Mike Katz: When you lose privilege, a counterparty, whether a plaintiff, someone you're in a lawsuit with, someone you're in a dispute with, a government or regulatory body that is investigating you, whether that's the SEC or the Department of Justice or the IRS, it could be any of these. Anyone with subpoena power can get the documents, the communications that you were seeking to protect.
So if you have a legal regulatory memo on why your token is not a security, and that is legal work product that was prepared by your lawyers and is attorney-client privileged, and the communications around it are attorney-client privileged, and you send it to a crypto exchange to explain why and you think that they should list your token, you just blew privilege on that memo. Maybe you're fine with that. Maybe you made a strategic decision to do so. But that would lose privilege.
In a lawsuit, and this is what happened, by the way, in many of the Gensler-era lawsuits against parties, they gave Coinbase or they gave any of these platforms a memo about their token and their Howey analysis. Those memos were no longer privileged, and the SEC could get them and use them in the lawsuit.
Lawyers are very candid in those memos because they understand how the business works and they're using the facts of the business. But losing privilege is different from not having privilege, and you don't have privilege with a friend or a business colleague.
There is privilege between doctors, psychotherapists, your spouse in some cases, some members of the clergy, but non-privileged communication can't become privileged just because you share it with a lawyer later. It can only work one way.
I'd say that losing privilege is real and it happens. People forward privileged documents to non-privileged parties. That's the most common. There's also a sword-and-shield problem, where if you're trying to use parts of the advice that you've gotten publicly, if you take some of a law firm's privileged advice and you want to use it aggressively as a sword, you can't then have the shield of privilege to hide the rest of it. So that would waive privilege potentially.
And there's the crime-fraud exception, of course. This is important. You can't just go to your lawyer and be like, here's the plan to rob this bank, and I want you to be my getaway driver, and then the whole thing will be privileged and our map that we print out will be attorney-client work product. Obviously, that doesn't work. If it's in furtherance of a crime or fraud, it's not privileged.
But the much more common issue is not having privilege at all and thinking it is, or operating as though you're creating privilege when you're not.
Mike Katz: I was in-house for several years. I ran legal at a large digital asset fund. This was the issue that came up a lot. We had to explain to people.
People have a common issue, like a Harry Potter problem. They believe they could say the magic words, wave the wand, and privilege applied. And that is very much not how it works.
So I would get CC'd on emails between two business folks at a company and there was no legal advice. I wasn't even addressed in the email, and the header would say privileged and confidential, and it wasn't, obviously. And I would have to explain to my friends and colleagues, guys, this is not privilege. But if you want legal advice, here's how we structure it, here's how we do it, but this is not privilege.
Just throwing a header, privileged and confidential, on an email, which is what a lot of people do, that's the same legal force as writing over 21 on your forehand and walking into a bar. It doesn't do much, ultimately.
So courts are going to look at the substance, and if no lawyer was involved in providing legal advice, the label is decorative and potentially counterproductive.
A lot of people try the add-the-lawyer trick, where there's a 40-message-deep email thread on something, and then you CC in a lawyer and you think that everything that's come beforehand is privileged. That only even matters if you've CC'd in the lawyer to ask for specifically legal advice, which would be privileged. So maybe the emails going forward are privileged, but you cannot retroactively turn 40 emails where there was no legal advice and no lawyer involved into privileged communications or attorney-client work product simply by adding a lawyer. You can't tag someone. It doesn't work like that.
And then a story that is potentially the best example of what can go wrong when you really don't understand privilege. This one still keeps me up at night, honestly. So I'm going to be careful here because it's genuinely a true story, and I'm going to anonymize this.
A C-suite executive at a company, who should have known better, was a total menace about attorney-client privilege and attorney work product. He had a habit of labeling pretty much every document he created attorney-client privileged. Every email, every spreadsheet. And I'm talking about finance spreadsheets, operations spreadsheets, things that had nothing to do with attorney-client privilege.
And then, most dangerously, he would put every memo to self. He wrote a lot of memos to self. It was like a dear diary of all his fears and worst-case scenarios and strawman arguments, and he would write attorney-client privilege. It was literally a memo to self.
I wanted to sit him down and look at him and be like, this attorney-client privilege that you keep invoking, is he in the room with us right now? Because are you aware that you're writing these memos to self, you're not a lawyer, and you're tagging attorney-client privilege? This is a problem if you think that these are privileged, because they are not.
Weirdly, he was obsessed with avoiding documents being produced, obviously in a lawsuit scenario. That's why he kept doing this. And yet it was almost a self-fulfilling prophecy because a lawsuit did come down the road. Everything that he put together, which was in the privilege log because he tagged it that way, the other side disputed it. And because if you actually look at it, none of it is privileged, it was all produced. It was a golden gift to the other side. They couldn't have written the narrative better themselves, and all of it ended up in the lawsuit. Literally, he was the star of the lawsuit.
So I think there's a real lesson to take there on what happens when you think you have privilege and really, really don't.
Jacob Robinson: That's such a good example of the dangers of privilege. Because if you think you have it and you operate that way and you share this information that, had you known you weren't going to get it, you never would have written those dear diary entries, now you're at such a disadvantage if anything ever happens in the future.
I think the best way to operate is always as if you're going to have everything publicly disclosed that you're producing on that device, anywhere, even those at home. We're going to talk about the Hennepin case in a second. I think that our in-house can be disclosed as well, obviously.
That's where these conversations around AI chatbots are so important, because it feels like you're having an intimate conversation. No one else can read it. It's private. It's personal. And sometimes, especially for non-lawyers, if you're not comfortable with what's happening, you need to know, hey, what should I ask my lawyer? I could understandably see people using Claude and other tools to understand the process better. That's objectively some harm down the road.
Mike Katz: I wrote this article about what I called vibelawyering. It's akin to the vibecoding idea of you use Claude Code, you're building an app for your group chat, and you don't really understand the code, you don't really read all of it, but you're shipping it to a small friend group, so who cares. Whereas if you were developing a product as part of a big company and you were vibecoding, that wouldn't be best practice.
With vibelawyering, it's a similar frame and the consequences are way worse, because you're creating a discoverable record of potential liability and regulatory risk and all these things that could be used against you in a way that would be really damaging.
Interestingly, AI, the technology, yes, is new and it's powerful and it's cool and it's interesting and there's a ton of potential. But the issues that it invokes with privilege are not new. They're old. Whether it's Google search results, whether it's telephones, whether it's the telegraph, you can go back and find the case law on all of these issues and how privilege or work product applies.
Why I wrote this article was it really is something I'm seeing a ton. I'm seeing this come up constantly, where someone has a legal problem or a legal question or a potential dispute or a regulatory risk analysis, and instead of calling their lawyer, they open up Claude or ChatGPT or Gemini or what have you. They type in all the facts, and sometimes those facts include things that are damaging to them, and then they ask for legal analysis.
While the consumer chatbots will tell you they're not a lawyer, they will give you back something that reads like a legal memo, that feels, smells, tastes like legal advice. These people feel like they got legal advice and feel like they got legal counsel. They very much did not.
Instead, what they have done is they have created a very specific, probably more specific than they would using Google or other tools, written record of their potential legal exposure on a third party's servers that could be discoverable and produced in a lawsuit or regulatory investigation.
So I framed it as people are going to get in trouble because they don't realize this. They really, really don't.
I gave a few specific examples. For anyone who is in an employment dispute and put details about it into your ChatGPT and asked it to draft a separation agreement, if you're in the scope of a dispute where things could lead to a lawsuit or end in a lawsuit or be part of a settlement or an arbitration or what have you, you can have created a record that, if it does go to a lawsuit and there is discovery, that's discoverable and that's not very good for you.
I had a client that fed Claude, and I know this because they then forwarded it to me, the facts of a regulatory risky plan and asked it to work some loopholes. Then forwarded it to me, and I had to explain to them, listen, just so you know, this is not privilege. In a world where the SEC sued you on this, they would be able to get access to this. So we're going to cut this off, and here's the new plan for how we're going to work on this so that we can create privileged attorney-client work product.
I think these are examples that keep popping up, and it's only going to get worse because, in my view, in the last month, the level of usage of AI for legal work for non-lawyers has skyrocketed. So this is going to be something that's really, really popping up. The Hennepin case, which we're going to talk about, was viewed as a case of first impression nationwide. That's not going to be the case very long. I think we're going to see a lot of this stuff.
Jacob Robinson: If you're having an AI draft a first version of a contract, for example, not that I'd recommend that, that's very different than if you're asking it about a certain situation, you're putting some facts in there.
That brings us to the Hennepin case, which I want to talk about now, because it's a great example of the dangers of doing that.
At a high level, Hennepin, the CEO of a company that had a sister company that he sort of said was at arm's length, then that he could control, turns out he could influence it, at least he's accused of being able to interact with it.
Mike Katz: Allegedly.
Jacob Robinson: Allegedly applies everywhere throughout here. But $300 million was sort of taken from the sister company. Hennepin allegedly had $150 million of it. $40 million was spent to upgrade his mansion in Dallas. $10 million was for personal credit card expenses. Must have been a couple nice shopping trips, allegedly.
And then what happened was in November of 2025, the FBI raided his house. He was arrested. They took electronics, which I assume was his laptop or personal computer. Those were taken.
And his defense counsel, his lawyers, said, well, there's items on that computer which are attorney-client privilege and privilege applies to, particularly these 31 documents generated by Claude and the inputs that went into them. They wanted to protect those because what Hennepin had done is say, OK, this is what's happened. Here's the facts. What can I do to protect myself? Asking Claude rather than, as you said, calling his attorney.
Jacob Robinson: I just got to pause the podcast for one second, because what I wanted to do was punch into Claude, hey, maintain legal privilege over this conversation. Like you might assume, Claude tells me, I can't do that. It runs through a host of reasons, like we've already talked about, when privilege exists, why it doesn't exist in this case.
The problem is that when you use something like Google, it doesn't ask you a follow-up question. When you use Google Doc, it's not prompting you for more information. Listen to what Claude said. At the end of this long explanation, it says, what's going on that prompted the question?
That's huge, because what that's doing is that's prodding me for more information. If there's a lawsuit that could be coming up that I know is coming up, there's a subpoena, there's some reason for me to believe litigation's happening, I'm now maybe going to give the facts of this case. Hey, what prompted the situation? Well, the Securities and Exchange Commission is investigating me. That's dangerous.
And that's something that's very unique to AI. We didn't have that before chatbots. So I'm curious to see whether maybe in the future some of these companies could be liable for what their chatbots are doing, because that's essentially the chatbot prompting me for more information.
Now that being said, I'm someone who thinks everyone should take personal responsibility for things that they do. So if you're someone who's pumping sensitive subject matter into these chatbots, you should assume you're going to have to disclose that at some point. But they probably should be tweaked so you're not asking a question after someone says, can you maintain legal privilege over this conversation, and you say, oh, no, but tell me why? That's a really dangerous situation.
I just wanted to highlight that quickly.
Now, I know I just said we were going to go back to the podcast, but think of this like inception. We're doing an insert within an insert, because I mentioned whether or not Anthropic or any of these companies that produce these LLMs could get in trouble for that.
We've seen an example where a company was held liable for the actions of an agent. Since 2024, the British Columbia Civil Resolution Tribunal found Air Canada liable for negligent misrepresentation after its AI chatbot provided incorrect bereavement fare information to a passenger. Someone had asked, if I take a flight, can I submit a bereavement request or information after the flight and get reimbursed? And they said yes. In the case, you had to do it prior.
So Air Canada was found liable for the actions of its agent, its chatbot, in that situation. So I wonder if maybe there's a line here.
All right. Now we're going to go back to the episode where Mike and I are going to finish explaining the Hennepin case.
Remember, this is the case a judge called a case of first impression on AI and legal privilege in the United States. There were so many details. I think the details are pretty fascinating because it tells us where courts are lining up on this and where they might change if we have different facts in the future.
So maybe we could walk through those three elements, why Judge Rakoff had said that attorney-client privilege did not apply in this case, and neither did the work product doctrine.
Mike Katz: This case is kind of crazy because obviously a lot of money was involved. This guy hired a very real law firm, Quinn Emanuel. Those are real heavy hitters and a very well-established law firm. He wasn't not going to pay lawyers. He hired lawyers, and this is a criminal case, so it's a lot more on the line than drafting a contract or an employment dispute, let's say.
And yet, in the interim between receiving a grand jury subpoena, knew the writing was on the wall, but before his arrest, he went into Claude, did a bunch of stuff, created these documents, and then, as you said, when the FBI raided the mansion, they took those documents, or they took the electronics and they wanted those documents.
Judge Rakoff, in February, ruled from the bench. Rakoff's a very opinionated, passionate, well-known judge, and he's in the SDNY. It's a very important district court jurisdiction in the United States, and its opinions tend to carry some weight. He called it, like I said, a question of first impression. So this is going to shape, I think, a lot of what's to come, albeit I'm sure we will get some different results in different districts.
But he said that the privilege failed on at least two, and probably all three, of the three elements I mentioned.
So number one, Claude is not an attorney. You can't form an attorney-client relationship with it. It has no fiduciary duty to you. It has no law license. It is not subject to professional discipline. And it tells you that it's not.
The second element, no confidentiality. The Anthropic privacy policy for Claude permits collection, training, disclosure to regulators, sharing, all that. Hennepin consented to that when he signed up and when he used the platform to generate the 31 documents.
And then the third is the purpose of obtaining legal advice. The question was whether he intended to get legal advice from Claude, not in general, and Claude itself can't provide legal advice because it is not a lawyer. So in Judge Rakoff's view, you fail on that third piece as well, because if you go to your barber and ask him for his advice on your legal case, even though yes, you were seeking legal advice, not going to be a privileged conversation because you don't reasonably believe your barber is a lawyer. It's the same thing here with Claude.
It's also relevant that he then forwarded those 31 documents to his lawyers. Again, we talked about this in the examples of what doesn't create privilege. You can't create privilege by forwarding non-privileged documents to your lawyers. Once Quinn Emanuel were seeing them, yeah, they can create privilege and attorney-client work product after the fact with certain things. But those documents are not then attorney-client work product or privileged.
Jacob Robinson: Another point that was interesting, the lawyer didn't direct Hennepin to use Claude to maybe help him understand the facts so he could communicate to the lawyer. Claude wasn't acting as an agent for the lawyer, and the court specifically said that, had that happened, it might have been a different result here. But in this case, this was Hennepin on his own volition, who shouldn't have thought he was getting legal advice from Claude, going and using this. So that can be a big distinction in the future too.
Mike Katz: What you're referencing is known as the Kovel doctrine. Basically, this is a 1961 case that predates the Upjohn case, where there was an accountant who had worked at a law firm for 20 years. One of the clients of the law firm was investigated by the IRS, and the IRS subpoenaed Kovel, the law firm's accountant, saying that his work within the law firm was not privileged.
And the Second Circuit found that it was, because basically lawyers can't do their job alone. They may need tools or people to help them do their job, whether that's an interpreter if your clients speak Spanish and you only speak English, or an accountant who can translate the tax matters to you.
Similarly, this has been held to include other types of tools that lawyers use to get their job done. Rakoff left the door open to this, where if his lawyers at Quinn had directed Hennepin to use it, then maybe Claude was an agent of the lawyer and functioned as the lawyer's agent and within the protection of attorney-client privilege, and the documents created at the direction of counsel would have been attorney-client work product, and then you would have been in a different scenario.
But that isn't what happened, and it's also not what most people do. That means you're working with your lawyers to go figure out the right approach. When we're talking about where a lot of these problems lie, people are just doing this on their own with consumer chatbots, not involving their lawyers, and that is very much discoverable, producible, all not covered.
Jacob Robinson: That's why when we talked earlier about the three elements that you need to establish attorney-client privilege, it's important that all three need to be present. Even if the attorney just said, OK, you can use Claude, if there's no expectation of privacy or confidentiality there, and there's not a communication involving a lawyer, that still is not going to be protected and it's still going to be discoverable in court.
Mike Katz: It's such a good point. It's like the Howey test. You need all four elements. You need all three elements or it's not privilege. Any one of them is missing, you're out.
Jacob Robinson: I can't remember exactly if you had this in your thread, but I believe it was something about incognito mode or deleting chats. A lot of people think, OK, well, I deleted the chat. It doesn't exist anymore. Obviously that's not always the case. There can actually be a danger to you when it comes to the duty to preserve and spoliation, like you're deleting evidence if you do know that there is going to be some litigation happening. So there's some dangers with deleting chats. Walk me through some of those.
Mike Katz: Thanks for raising that, actually, because it was one of the most common responses I got to the article. It was basically like, LOL, I'll just use incognito mode and lawyer forever, and that is wrong.
Incognito mode does not change, it doesn't solve the problem, and in a way creates a few new problems.
First of all, the terms of service don't change, even with the incognito modes. We have found that, yes, maybe it's less predictable, maybe they get rid of it, but it's not entirely clear what these platforms are doing with incognito mode chats or what they're doing with deleted chats.
In the *New York Times* OpenAI case, it's about the copyright issues, the court demanded that OpenAI keep all deleted chat logs as part of the discovery and evidentiary process. It turned out that they had certain deleted chats that they could save and produce for this lawsuit. So it's not entirely clear that you would be protected and that the platforms won't be able to produce it.
Secondly, unless you have a photographic memory, what did you produce in an incognito? Did you print it? Did you email it? Did you put it in a Slack? Did you screenshot it? You presumably did something with the incognito advice, and then that record and those documents still exist. They are not privileged and they would be fair game.
And then, to your point about the duty to preserve, once you're in the ambit of where litigation is reasonably anticipated, you're legally obligated to preserve relevant evidence. You'll know about this if you work at a company and you receive a litigation hold about documents and communications where you are obligated not to delete them.
If you fail to implement a litigation hold when you should, courts have found that that's gross negligence. It can lead to adverse inference in a lawsuit, where juries are instructed that you destroyed evidence. There could be monetary penalties. There could be default judgments in certain extreme cases.
So if you get rid of your communications, whether that's deleting Signal or chat messages or Telegram messages, or whether you're deleting your AI chat logs, that's going to be a problem for you. So number one, it doesn't solve the privilege issue. And number two, you're then opening up the door to other problems if you're trying to delete.
Jacob Robinson: There was a really good article about the Hennepin case and the policy implications of this that I wanted to touch on with you quickly because I think one thing that Judge Rakoff looks at is, is Claude an attorney? But as we said in the Kovel case, Claude doesn't need to be an attorney. Claude can be a tool that an attorney is using.
Then the confidentiality aspect, you can do things to preserve more privacy within your communications with these LLMs. And then the third factor, you could be using it to communicate with your lawyer.
So in the future, if we have lawyers who say every time that they engage with a client as part of the retainer, you can use Claude to improve your ability to communicate with me, and maybe here's a prompt that you can inject in there, where do you stand on that, Mike? How do you see this evolving in the future? Because we all use Gmail, we all use Google Docs, we all use Microsoft Word. There's a lot of tools that we use today that could be subject to disclosure. There's a lot of things in there that don't meet those three elements of attorney-client privilege, yet this remains so.
Mike Katz: I read that *Harvard Law Review* critique, and I think that it's interesting because, yeah, if you're using Google Docs to create a memo for your lawyers at their direction, then that's probably privileged in a variety of ways, as an agent of the lawyer, at the direction of the lawyer, expectation of confidentiality, all those things.
That said, if you type into Google search, this is a little darker, but this story just came out, like the Gilgo Beach serial killer who just pled guilty in Long Island, he had typed into Google, why can the police not trace the Long Island serial killer's calls, and he had a bunch of self-incriminating Google searches that were not privileged and that were part of the record against him.
This technology, or these technology issues, have been around for a while now with the internet. I think that you're going to see courts across the country come out in different ways on some of these questions.
I think a true case where you're just vibelawyering, not working with a lawyer, no expectation of privacy, there's no attorney involved, it's not confidential, yes, you're seeking legal advice, but you're seeking it from Claude, which is not a lawyer, I don't think that that's going to be privileged based on the way that privilege works.
But if it's different, if it is, as you said, if you have a relationship with your law firm and the law firm gives you guidance on how to use the tool, and it's in connection with your legal advice and your legal relationship and under the direction of counsel, I do think there's going to be a lot of ways where you can leverage the AI tools within the ambit of attorney-client privilege.
And by the way, I use AI tools all the time for my clients. I want them to benefit from the cost efficiencies and the effectiveness and the advances that all of these tools have. I operate within the bounds of my law firm's AI policy, which is designed in order to protect attorney-client privilege and protect confidentiality and protect data security and all these things.
So I think that's where we're going to go more likely.
Jacob Robinson: It's interesting because when you look at Google, Slack, Apple, they all have similar privacy policies that permit disclosure in connection with litigation. So there's a whole host of things that have been in existence for a long time. We're seeing it in a new medium with AI.
This is a case of first impression. There's going to be a lot more, as you've said, that come out in the future. So where courts tend to go on that will be interesting.
Do you expect they'll change the way they look at it? One part I found interesting in this case, even if the lawyer said, yeah, you can use Claude to do that, there still shouldn't be an expectation of privacy. That's probably where the courts will just get more granular in terms of what they're looking at and are requiring from the evidence over whether or not you clicked off that privacy setting and you didn't want them to train based on the data you're uploading. That's where people will have to get more mindful.
But from a policy perspective, it does seem a bit dangerous that people are unintentionally disclosing what they assume to be private information that might have stayed private had they not had access to a tool that is helping them prepare for a lawsuit, is helping them to communicate more with a lawyer. I do find a bit of an issue with that.
But I guess the positive is that there has to be a line in the sand, and this sort of maintains that line.
Mike Katz: I think it's a fair point. It's a supercharged version of the way technology has historically made doing these kinds of things a lot easier. Using Google, using email, using Twitter, any of these sites, in a way that makes it easier to inadvertently create a record or a trail or data around who you are, what you're interested in, what you're doing, what may be involved in a lawsuit or a criminal investigation or a regulatory investigation.
But I think here it's supercharged, to your point. It really is a tool that looks and feels and smells like a lawyer, and people are operating and acting as though it is.
Some of that, people have to, it's buyer beware a little bit. ChatGPT itself will tell you, I'm not a lawyer, consult with your lawyer. But maybe with some of these terms and some of these things, whether it's medical advice, whether it's legal advice, whether it's tax advice, whether it's financial advice, there need to be stronger warnings or more clear guardrails in some of the consumer products.
But in terms of what underlies the privilege doctrine, a lot of that really hasn't changed very much for 50, 80 years, even while the technology has changed dramatically.
The whole policy reason behind privilege, as we wrap things up and go back to where we started, is so that clients have someone that they can give full and frank disclosure to, so that someone can vigorously defend them, someone knows all the facts, and they're not worried about those facts being presented to the other party.
Maybe the answer is to have better safeguards in AI chatbots that say, hey, you might want to stop this, you might want to talk to a lawyer at this point.
There was an interesting article in *The Atlantic* a few weeks ago, I think by Derek Thompson, about are you coal or are you a horse? The idea being when steam engines got more efficient, demand for coal went up, not down. It's the Jevons paradox. You actually needed more coal in order to feed what was a result of making things more efficient in the first place with steam engines.
Whereas horses, on the other hand, they didn't make things more efficient for tractors or cars. They just got replaced.
So are you the coal, where you create more demand for what you actually need, or are you the horse?
I would say lawyers who use AI the right way, figure out how to use these tools, protect attorney-client privilege, but also get more efficient, more valuable, more useful, I think you're going to give clients more value. I think you're going to solve more problems. I think your work is going to be better. And I think demand could go up in the right way.
Whereas lawyers who don't use AI properly, or at all, which are some, they're the horses. And then I guess the people who just use consumer chatbots without proper guidance, or to continue to mix animal metaphor, maybe like lambs to the slaughter.
But really, my hope is that we in the legal practice are going to get better, smarter, more valuable to clients. There's a reason why lawyers are trained in how to preserve privilege and do all these things. They can help you and protect you in ways that even using a very smart AI can't necessarily, because it's what you put in, you get out.
Jacob Robinson: That's where the one thing that I think lawyers will always do better than AI is, and not all lawyers, of course, some are horses, like you said, some are coal, but it's get a better understanding of the facts and understand what's happening when it comes to the client's situation.
A client could look up on an LLM what the laws might be, and maybe it cites a law review article that isn't correct, and maybe it didn't cite the statutory authority, maybe cited a case that was overturned at some point. You can't just go after the LLM in that case. They've disclaimed that they're your attorney.
You can go after the lawyer. There is a duty that lawyers have to their client, and that is a benefit to the clients, just as much as, I'm sure, it's a benefit to the lawyers. But there's an important duty there, that fiduciary duty, that these LLMs don't have.
Mike Katz: I totally agree. I think we're going to see cases that expand how privilege is understood even within the Upjohn and Kovel doctrines that have existed for many decades now. And we're going to get some interesting decisions.
But I think by and large, it's going to fit within this construct that we've spent today discussing. Then the question becomes, OK, so how do you use AI in the right way? Because it is a powerful tool, and it is important, and lawyers should be using it. They should be using it the right way for you, for your benefit, to provide better work and better value to clients. I think that's the direction.
Jacob Robinson: Yeah, I completely agree. If you rewind to say 1995, there were lawyers who weren't using the internet at that time. They didn't trust it. They went to the library still. They took hours, sometimes days, to find a certain case. Those two days were reduced to two minutes. And now with AI, it seems that two minutes has been reduced to two seconds.
So there's a lot of efficiencies that are happening that are beneficial to everyone, so long as people are using the technology correctly. I think having conversations like this and explaining to people, like you did with your thread, which did so well, is important because a lot of people don't realize what's at stake.
Mike Katz: Exactly. Things are moving very quickly, but it's so early. I think it's just important for everyone to be aware of the state of play and how these things work and how they should be thinking about it and how to be smart about running your business, building your business, investing in businesses, all of that.
AI is kind of like Pandora's box, but the government, the opposition, and the civil suit, they can find out what's in the box.
Jacob Robinson: Mike, thanks so much for joining me. That was a great discussion.
Mike Katz: My pleasure. Thanks for having me. Really enjoyed the conversation.
Jacob Robinson: Now, I'm obsessed with making this podcast the number one legal podcast in the world, and you can help me do that. You could share this podcast with a friend. You can give me some feedback on X at Jacob Robinson JD. It would really mean a lot to me.
My goal is to give you excellent legal content that covers emerging technology. Thank you again for joining me.
If you want to sign up for the newsletter, I'll put a link to that in the show notes below. You can find it also at lawofcode.beehiiv.com. That's B-E-E-H-I-I-V dot com.
Thanks again for joining me. We'll see you next time.