The status of legal professional privilege has been under the spotlight in 2026, particularly through the proper and improper use of Artificial Intelligence (AI) in litigation. There have been some notable decisions and opinions, both in the UK and across the Atlantic.
In this article, Tim Constable and Samuel Norman analyse recent case law on this subject, the implications of these decisions, and some key considerations to avoid losing legal professional privilege when using AI.
English legal professional privilege: a summary
Legal professional privilege entitles a party to withhold evidence from production to a third party or the court. There are two types of legal professional privilege:
- Legal advice privilege – Confidential communications between lawyers and their clients made for the dominant purpose of seeking or giving legal advice; and
- Litigation privilege – Confidential communications between lawyers and their clients, or the lawyer or client, and a third party, which come into existence for the dominant purpose of being used in connection with actual or pending litigation.
Confidentiality is an essential requirement of legal professional privilege, as a loss of confidentiality will result in privilege being waived. The issue has arisen because open-source AI (which is generally free of charge to the consumer) is used to train AI large language models and is therefore not confidential. The same problem arises in the use of some data transfer apps.
Incidentally, in our view, the same considerations do not apply without prejudice privilege, which is not dependent on confidentiality and therefore should be less susceptible to waiver through AI use, for example in mediations.
We look at two cases on both sides of the Atlantic, which suggest the same conclusion; use of open-source AI will destroy confidentiality and thus waive privilege: (1) UK (Munir) v Secretary of State for the Home Department UKUT 81 [2026] (IAC) and (2) United States of America v Bradley Heppner 25 Cr.503 (JSR).
UK (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC)
In UK (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC), these proceedings arose from two judicial review cases heard separately but encompassed in one judgement by the Upper Tribunal.
- In the first case, a regulated immigration advisor “unknowingly” used fictitious case law when drafting an application for permission to appeal to the Upper Tribunal. The advisor initially said that the reference was the result of human error but later accepted that the case was an AI creation which occurred unknowingly through the inadvertent use of the Google search AI function. The advisor also put draft client emails and Home Office decision letters into ChatGPT. Following this, the advisor reported themselves to the SRA. The tribunal indicated that they would have reported the advisor had they not reported themselves.
- In the second case, a solicitor/compliance officer had included references to fictitious case law and authorities in drafting grounds for judicial review of an immigration decision. The officer explained that the grounds had been drafted by a part-time trainee lawyer who was working at the firm under his own supervision and that the grounds were based on an outdated precedent. The tribunal eventually referred the officer to the SRA.
In its decision, the tribunal acknowledged that the use of legal AI programmes by properly trained professionals was a step forward in legal practice for properly focused legal research and large disclosure exercises (in some cases).
However, the judge found that uploading client emails and Home Office decision letters into open-source AI tools, such as ChatGPT, constituted placing information into the public domain, ultimately breaching client confidentiality and therefore waiving legal privilege.
The tribunal made a clear distinction between these open-source AI tools and Enterprise licenced AI tools, such as Microsoft Copilot 365, where confidentiality is contractually protected. With open-source AI tools these retain, store, and take user inputs for model training, increasing the risk of breaching client confidentiality and therefore waiving legal privilege.
In contrast, closed-source tools are less likely to run this risk as they often do not store or use user inputs. Instead, they offer additional contractually guaranteed controls around data retention and security.
This developing English case law also reflects a speech by Sir Colin Birss (Chancellor of the High Court) on 22 April 2026, in which he shared his views on the use of AI systems and whether legal professional privilege attaches to them, citing the Munir decision. He commented that confidentiality is a prerequisite to privilege, so legal professional privilege is unlikely to attach to exchanges with public AI systems because they are not confidential.
Despite Upper Tribunal decisions not being binding on the High Court, on current trends it would be surprising if any subsequent authority differed from this approach, unless the Civil Procedure Rules are specifically amended.
United States of America v Bradley Heppner 25 Cr.503 (JSR)
It appears that a similar approach may be taken in at least some States of the US. In United States of America v Bradley Heppner 25 Cr.503 (JSR), a New York court considered the issues discussed, and found that an individual’s communications with a public, open-source AI platform (Claude), were not protected by US attorney-client privilege.
The defendant was charged with various counts of fraud, and FBI agents seized numerous documents and electronic devices from his home, including communications with the AI tool outlining his defence strategy which had been shared with his legal counsel.
The defendant argued that the communications were privileged, as he had input them into the AI tool for the dominant purpose of his dealings with the legal counsel. The court found otherwise, citing the following reasons:
- Firstly, the documents were not communications between a lawyer and client. The judge set out that privilege requires a “trusting human relationship” which could not exist between a user of an AI tool and the tool itself.
- Secondly, the communications were not confidential. This is because the terms of the AI tool made it clear that data inputted would be used for training and could be disclosed to third parties.
- Finally, the individual’s communication with the AI tool was not for the purpose of obtaining legal advice. This is because his lawyer did not direct him to use the AI tool, and the tool specifically warns that it cannot provide legal advice. Even though he eventually shared the communications with his lawyer, it is established in the US that non-privileged communications do not become privileged after being shared with a lawyer.
Practical steps for lawyers (and clients) to take
Confidentiality is a prerequisite to legal professional privilege; when confidential information is uploaded to open-source AI tools, it loses its confidentiality, and in turn, is no longer privileged.
As a result, practitioners should consider the following steps to protect the confidentiality of client information and ensure that its privilege is upheld:
- Users of AI tools should always exercise caution before using them, especially when uploading client information and documents into them.
- Users of AI should avoid uploading confidential information into open-source tools and should always check the terms of service and data retention controls of licensed enterprise tools before uploading confidential information, to ascertain how the information might be used by the AI tool.
- Practitioners should ensure that all staff are trained on the use of AI and the parameters that exist around the legal professional privilege of client information, and how easily this can be lost.
- Anyone carrying out legal research or drafting through AI must undertake checks to ensure the information produced is correct.
- This is not just an issue for lawyers; clients should also be aware of the risks associated with using open-source AI in their own legal research for their own cases.
- The general approach should be to use licensed Enterprise AI which contractually guarantees confidentiality, such as Microsoft Copilot 365.
A similar issue arises with the increasing use of freely available data transfer apps, some of which are also used to train open-source AI. This is the subject of our next article in this series.
How can we help?
For further information about issues raised in this article, please contact a member of our Commercial Disputes team.