fr
 Across all four corners of Quebec

Aucun résultat trouvé pour

Home
...
Publications
Solicitor-Client Privilege in the Age of Public AI (Artificial Intelligence) Tools
Publication Business Law Protection of personal information

Solicitor-Client Privilege in the Age of Public AI (Artificial Intelligence) Tools

INTRODUCTION: PRIVILEGE MEETS PUBLIC AI 

Publicly available AI tools are now used by individuals and businesses for drafting, research, analysis and, at times, informal legal guidance. Their growing use is requiring courts to apply established principles of solicitor-client privilege and professional secrecy to new factual settings. 

The central question is whether solicitor-client, attorney-client privilege or professional secrecy is preserved when a client enters confidential facts, legal strategy or legal questions into a publicly accessible AI system. Because privilege depends on confidentiality, such use may place that protection at risk. 

 

THE CORE PRIVILEGE RISK 

The difficulty arises from the nature of the disclosure. Solicitor-client privilege protects confidential communications between lawyer and client made for the purpose of seeking or obtaining legal advice. Public AI platforms are generally operated by third parties, often under terms and technical arrangements that users do not control. Where privileged or sensitive information is submitted to such a platform, a court may characterize the communication as a disclosure outside the protected relationship. 

The relevant issue is not whether AI can assist legal work. It is whether its use preserves the elements of privilege: the protected relationship, the legal-advice purpose and a reasonable expectation of confidentiality. 

 

THE U.S. APPROACH: UNITED STATES v. HEPPNER 

In February 2026, the United States District Court for the Southern District of New York addressed what it described as a question of first impression in United States v. Heppner: whether communications with a publicly available AI platform, made in connection with a pending criminal investigation, were protected by attorney-client privilege or the work-product doctrine. 

The communications consisted of approximately thirty-one documents memorializing exchanges between Bradley Heppner and Claude, a generative AI platform operated by Anthropic. Heppner argued that the documents were protected because they incorporated information learned from counsel, were prepared to facilitate discussions with counsel, and were later shared with counsel. His counsel conceded, however, that he had not directed Heppner to run the Claude searches. 

The court rejected the privilege claim. First, the communications were not between attorney and client because Claude was not a lawyer. Second, the communications were not confidential. The court emphasized that this was not simply because Anthropic’s privacy policy permitted the collection of user inputs and outputs, their use for training, and disclosure to third parties, including in connection with litigation or regulatory matters. Rather, the lack of confidentiality stemmed first from the fact that Heppner chose to communicate sensitive information to Claude, a third-party AI platform outside the solicitor-client relationship. Anthropic’s privacy policy merely reinforced that conclusion by confirming that the information could be accessed, retained, used and disclosed by the platform provider. In these circumstances, the court held that Heppner had no reasonable expectation of confidentiality.  

Third, the communications were not made for the purpose of obtaining legal advice from counsel. The court accepted that this point was closer because Heppner said he used Claude for the purpose of speaking with counsel. But counsel had not directed the use of Claude. The relevant question was therefore whether Heppner sought legal advice from Claude, not whether he later shared Claude’s output with his lawyers. Claude’s own disclaimer that it could not provide legal advice reinforced the court’s conclusion. 

The court also rejected work-product protection. Even assuming that the AI documents were prepared in anticipation of litigation, they were not prepared by or at the behest of counsel and did not reflect counsel’s legal strategy. Heppner had acted on his own. The fact that the documents later affected counsel’s thinking did not convert them into protected work product. 

Heppner is therefore not a general prohibition on AI-assisted legal work. The court expressly left open the possibility that a different result could follow if counsel had directed the client to use the AI platform. In that scenario, the AI tool could be treated more like a tool used by counsel than an outside third party. The decisive features were the absence of counsel’s direction, the absence of confidentiality, and the client’s unilateral use of a public platform. 

 

SOLICITOR-CLIENT PRIVILEGE AND PROFESSIONAL SECRECY IN CANADA 

In Canada, solicitor-client privilege protects communications between lawyer and client where three conditions are satisfied: the communication is between a lawyer and client; it seeks or provides legal advice; and the parties intend it to remain confidential. These requirements reflect the relationship of trust that the privilege is designed to protect. 

In Québec, the protection also rests on an express statutory foundation. Section 9 of the Charter of Human Rights and Freedoms, CQLR c. C-12 recognizes every person’s right to respect for professional secrecy. It prohibits a person bound to professional secrecy by law from disclosing confidential information revealed by reason of that person’s status or profession, even in judicial proceedings, unless the client authorizes disclosure or the law expressly permits it. Courts must ensure respect for that secrecy on their own initiative. 

 

HOW CANADIAN COURTS MAY ANALYZE PUBLIC AI USE 

As a matter of established Canadian law, confidentiality is indispensable. A client’s independent use of a public AI tool would therefore likely create a serious waiver risk, particularly where the platform’s terms permit the provider to collect, retain, train on or disclose user inputs and outputs. If confidential facts or legal strategy are entered into a third-party platform outside counsel’s direction and without effective controls over access, a court may find that the information was disclosed beyond the privileged relationship. 

This analysis is grounded in established Canadian privilege principles, but no Canadian court has yet directly determined whether the use of a public AI platform results in waiver in these circumstances. Privilege may be preserved where AI is used under counsel’s supervision, for a legal-advice purpose and within a confidentiality framework that restricts access to information. In that scenario, AI is closer to a litigation-support tool, translator, researcher or other professional aid than to an outside recipient of privileged communications. 

The distinction is important. Public, unsupervised use points toward waiver. Controlled, lawyer-directed use, supported by appropriate confidentiality safeguards, points toward preservation. Canadian courts would likely focus on control, purpose, confidentiality and the role assigned to the AI tool rather than on the mere fact that AI was used. 

 

CONCLUSION: CONTROL REMAINS KEY 

Public AI tools do not, by themselves, defeat privilege. Their use may do so where confidential information is submitted to a third-party platform outside counsel’s direction and without adequate safeguards. Until Canadian courts address the issue directly, clients and lawyers should proceed on the basis that information entered into a public AI platform may be treated as disclosed to a third party. The broader lesson is familiar: privilege depends on confidentiality, control and the structure of the solicitor-client relationship. 

Other publications
68

Our expertise at your service.

Contact us today to meet with one of our professionals.