Privilege is a routing question
The profession spent early 2026 arguing about one scenario in federal court: a litigation strategy memo — classic work product — gets pasted into an AI tool to "tighten it up." Opposing counsel finds out in discovery and argues that handing the memo to a third-party platform destroyed the confidentiality that work-product protection presupposes. Is the protection gone?
The honest answer is: unsettled, and now court-tested. Three early-2026 federal decisions on overlapping facts split on the question. In United States v. Heppner, disclosure to a third-party AI platform was held to destroy that confidentiality; enterprise tools with no-training and confidentiality commitments are analyzed differently, and commentators recommend Rule 502(d) orders and ESI-agreement coverage as mitigation. So the correct way to teach this is exactly how you'd brief it: a live, court-recognized risk whose outcome depends heavily on which tool and under what terms — which means it's a routing question, and routing questions can be answered in advance.
The professional floor was already written. ABA Formal Opinion 512 (July 29, 2024) mapped generative-AI use onto the Model Rules: competence including technological competence (Rule 1.1), client communication (Rule 1.4), reasonable fees — you bill time actually spent, not the time AI saved you (Rule 1.5) — confidentiality with informed consent, where boilerplate consent is inadequate (Rule 1.6), candor toward tribunals (Rule 3.3), and supervision of both people and tools (Rules 5.1/5.3). Florida Bar Opinion 24-1 added the state-level pattern: generative AI is permitted with reasonable confidentiality precautions, informed client consent recommended before confidential disclosure to a third-party tool. Your state has or is writing its own opinion — verify it by name before you rely on it; secondhand lists of state guidance age badly.
Now the practical failure mode. The moment privilege protection actually gets risked is not a policy meeting — it's 11pm before a deadline, when a tired associate with a strategy memo and a chat window makes a one-second decision from habit. Any rule that must be remembered at that moment will eventually be misremembered. So the rule gets made once, by counsel, in daylight, and written as a table:
- Every tool the team touches gets classified before use: cleared or not, trains on inputs or not, who cleared it and when. That's Op. 512's Rule 1.6 vetting, cached as data.
- Every request classifies its content: privileged (attorney-client communications, work product), client-confidential, or neither. Two booleans, decided by looking at the document, not the deadline.
- The router does the rest. Privileged material moves only through a cleared, no-training tool — and even then it gets logged and flagged for Rule 502(d) coverage. Confidential material never enters an uncleared tool. The 11pm decision becomes a lookup.
One boundary before the code, for the non-lawyers this path also serves: these rules govern assisting legal work under attorney supervision. Using AI to produce legal advice for others without a license is unauthorized practice of law — a statutory line, not an etiquette one. The router can enforce tool hygiene; it cannot make anyone licensed.