Published May 13, 2026

Attorney-Client Privilege and AI Tools: What Every Litigator Must Know in 2026

nexlaw-knowledge-center
Nexlaw Blog | Attorney and AI Tools Must Know in 2026

In June 2023, Judge P. Kevin Castel of the Southern District of New York sanctioned two attorneys and their law firm after they submitted a legal brief containing six entirely fabricated court cases — all generated by ChatGPT. The case was Mata v. Avianca, Inc. The attorneys did not verify a single citation. When caught, they doubled down and submitted more AI-generated fabrications to the court. Judge Castel fined them $5,000 and found they had acted with subjective bad faith under Rule 11.

That case was about citation hallucination. But the AI risk facing litigators in 2026 goes further — into privilege, confidentiality, and work product protection. Every time confidential client information is entered into a consumer AI platform, a different kind of damage is being done. One that opposing counsel can exploit in discovery. Here is what your firm needs to know.

Consumer vs. Enterprise AI: The Distinction That Protects Your Practice

Not all AI carries the same legal risk. The distinction that matters for privilege and confidentiality is not which tool is most powerful it is whether the platform is built for enterprise legal use and whether attorney supervision is documented.

Factor Consumer AI (Risky) Enterprise AI (Safe)
Data retention Retains inputs for training No retention your data stays yours
Privacy policy May disclose to third parties Contractual confidentiality enforced
Attorney direction Used independently by client Supervised attorney-directed workflow
Reasonable expectation of confidentiality None Preserved
Privilege risk HIGH LOW — enterprise protection
Work Product protection Stripped if no attorney direction Maintained under attorney supervision
Examples ChatGPT, Gemini, consumer platforms NexLaw, SOC 2 certified legal platforms

Here is the complete checklist your firm needs before uploading any client information to any AI platform:

1. Confirm a signed Business Associate Agreement (BAA) is in place  if PHI is involved.

Under HIPAA, any third party processing Protected Health Information must sign a BAA before a single file is uploaded. No BAA, no upload. This applies to PI firms, medical malpractice practices, and any litigator working with medical records.

2. Review the platform's privacy policy for data retention and training terms.

If the policy permits the vendor to retain, review, or train on your inputs — as Anthropic's consumer policy does that platform is not appropriate for privileged legal work. This is not an edge case.

3. Ensure all AI use is at counsel's direction and documented.

This is the single most important procedural step. Document that every AI workflow was initiated and supervised by the attorney of record. Undirected AI use by clients or non-attorney staff is a work product vulnerability.

4. Confirm data isolation — your firm's data must be siloed from other firms.

Cross-firm data visibility is a confidentiality breach waiting to happen. Confirm in writing that your vendor isolates every firm's data completely.

5. Verify SOC 2 Type II certification or equivalent.

Independent security auditing is the baseline for enterprise legal technology. Any vendor that cannot produce SOC 2 documentation should not be processing your client files.

6. Train your team — and your clients.

As reported in The Legal Intelligencer your clients are already typing their case details into consumer chatbots right now. The conversation you need to have at intake is simple: do not use any AI tool to think through your case unless I direct you to. That one instruction could save a case.

How NexLaw Is Built for Privilege and Work Product Protection

NexLaw was built from the ground up for litigation teams. Privilege protection is not a feature — it is the architecture.

No data retention for model training

Your client data is never used to train NexLaw’s models. Not for improvement. Not for research. Not for any purpose beyond delivering your output. What goes in stays yours — contractually guaranteed.

Full data isolation by firm

Every firm’s data on NexLaw is completely isolated from every other firm’s data. There is no cross-firm visibility, no commingling, and no shared model that could surface one firm’s information to another.

Attorney-directed workflows

Every NexLaw workflow is designed to operate under attorney supervision. Outputs are presented for attorney review and verification — not as final work product. The attorney remains in the loop at every stage.

SOC 2 Type II certified and HIPAA compliant

NexLaw operates on SOC 2 Type II certified infrastructure with end-to-end encryption in transit and at rest. For practices handling PHI, NexLaw signs a Business Associate Agreement with every firm before any protected health information is uploaded. Full security documentation is available at nexlaw.ai/trust-center.

ABA Formal Opinion 512 compliant

The American Bar Association extended its cloud-computing framework to generative AI in ABA Formal Opinion 512, requiring lawyers to conduct due diligence on AI vendors and take reasonable steps to safeguard client data. NexLaw’s enterprise architecture is designed to meet that standard.

Mata v. Avianca established one principle that has only become more important since 2023 — AI outputs in legal work require human verification, attorney supervision, and the right platform. The answer is not to stop using AI. It is to stop using consumer AI for legal work and build every workflow on a platform with contractual confidentiality, attorney-directed supervision, and the security certifications that give your clients real protection.

Use AI without risking your clients' privilege

NexLaw is built for enterprise legal security. SOC 2 certified. HIPAA compliant.
Attorney-directed workflows. BAA included. See the difference in 3 days.

Book Your Free 3-Day Demo

Enjoying this post?

Subscribe to our newsletter to get the latest updates and insights.

© 2026 NEXLAW INC.

AI Legal Assistant | All Rights Reserved.

ISO 27001 certified information security management system ISO 27001 Certified
GDPR compliant data protection and privacy standards GDPR Compliant
HIPAA compliant security for sensitive legal and health data HIPAA Compliant
SOC 2 Type II certified security and compliance controls Type II Certified

NexLaw is a SOC 2 Type II compliant platform utilizing AES-256 encryption. Our zero-data retention policy for enterprise users ensures that your work product remains privileged and is never used to train our models.

NEXLAW AI