By Brian Jones

Artificial intelligence (“AI”) is reshaping work for companies of all sizes. Used properly and securely, AI can offer improved efficiency and higher productivity. But if used without appropriate safeguards and training, AI could expose confidential information and jeopardize the attorney-client privilege. Because there are numerous built-in or freely available AI services on everything from laptops to phones to even Zoom and Teams, companies that have not formally adopted an AI platform may still have personnel using AI without security or oversight.

What’s the risk? Many AI platforms—especially the free ones—automatically store user data and train their models on that data unless the user specifically opts out. That data could include sensitive corporate financial information, intellectual property, trade secrets, and even attorney-client communications. Once that information is uploaded into an AI platform, it could be discovered by a competitor or opponent in litigation. While many AI platforms say their product won’t reveal the data it was trained on, clever users have found ways to get some platforms to do just that.

In general, the voluntary disclosure of privileged or confidential information to a third party can cause such information to lose its protection. This most frequently happens when, for example, someone forwards an attorney-client communication to someone who is outside the sphere of privilege, or when an employee shares the secret formula with a competitor. So, if an employee uses a free AI service that is under no obligation to keep information confidential, any information shared with that AI could be considered voluntary disclosure to a third party, and that information could lose its legal protections.

No court in the United States has found that putting otherwise confidential or privileged information into an AI platform caused the information to lose its protected status—yet. The absence of case law on this point is not surprising because AI platforms are, judicially speaking, a very new technology, and many lawyers have not yet started seeking discovery about AI usage. But they undoubtedly will, and at some point soon, a court will have to address this issue. Until the law is sorted out, however, the safest practice is to assume that any disclosure to a third party that is not under a confidentiality obligation will result in the loss of legal protection.

What should a company do? Step one is to ensure that any AI services contractually warrant that all uploaded information will be treated as confidential and not used to train the AI model. This often requires a paid tier of service that allows enterprise grade administrative controls that can limit what data the AI is allowed to access. Courts in other contexts have routinely found that contractual assurances of confidentiality can maintain legal protection when information is sent to third-party service providers, and that is likely to be the outcome in the AI context as well. The terms of AI service contracts can be convoluted, however, so it’s important to have knowledgeable legal counsel review those contracts to ensure that the data protections align with the needs of the business as well as the company’s other data protection obligations.

Step two is more difficult. Companies must ensure that employees receive adequate training about the risks of information sharing, and not just with AI. This requires clear and concise data protection policies coupled with frequent and timely reminders of best practices for employees. Best practices change over time, of course, so this represents a long-term commitment of time and resources, but it’s also the most-effective way of avoiding the loss of legal protections for confidential or privileged information. And since AI is now so widely available, providing a secured platform for employee usage helps avoid the temptation to use free or unsecured platforms that could jeopardize the protection of company information.

The final step is to enlist the services of knowledgeable legal counsel to help navigate the constantly evolving landscape of data privacy regulation at the state and federal level, including AI. For tailored guidance on data governance or to review your organization’s AI practices, please contact Brian Jones at b.jones@boselaw.com.