Article / 22 Sep 2026
AI tools, confidentiality and legal privilege: consumer AI vs enterprise AI services
Insight shared by:
AI is now a routine feature of the modern business environment. From drafting documents and analysing data to streamlining workflows, AI tools offer significant opportunities for businesses to improve efficiency and productivity. However, alongside these benefits come a number of legal and regulatory risks that must be carefully managed.
One of the most widely discussed legal concerns surrounding the use of AI is the phenomenon of “hallucinations”, whereby AI systems generate inaccurate or entirely fabricated information. Courts have already begun to consider the implications of such errors, and the body of case law in this area continues to grow. However, a potentially significant risk that has received far less judicial attention is the impact that AI may have on legal professional privilege. This article builds on our previous piece, AI tools, confidentiality and legal privilege: what clients need to know, by examining how the use of different AI tools can affect the confidentiality required to maintain privilege.
Legal professional privilege is a legal right that protects certain confidential communications between a client and their lawyer from disclosure. Confidentiality is fundamental to that protection: if it is lost, privilege may also be lost or waived.
As such, an important question arises: how can confidentiality be maintained when using AI?
The Tribunal’s observations in UK v Secretary of State for the Home Department
As this is a continuously developing area, there is limited judicial interpretation in the UK as to how the use of AI affects legal privilege.
That said, the judgment in a recent immigration law case gives us useful insight as to how courts will interpret this issue in the future. In UK v Secretary of State for the Home Department, the Upper Tribunal (Immigration and Asylum Chamber) considered (amongst other issues) the use by legal representatives of AI tools and the risks of hallucinated legal authorities. The facts of the case are not particularly important here, and mirror many of the recent cases surrounding AI hallucinations in the legal sector. However, while not central to the Court’s decision, the judgment included important comments on the impact of AI on legal professional privilege.
The following is an extract from the judgment:
“We also observe that to put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and thus any regulated legal professional or firm that does so would, in addition to needing to bring this to the attention of their regulator, be advised to consult with the Information Commissioner’s Office. Closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks.”
The Tribunal’s oversimplification
While the Tribunal highlights the importance of understanding how an AI system handles confidential information, it provides a potentially dangerous oversimplification of the issue.
The problem is not necessarily information being placed in the “public domain”, but rather the potential loss of confidentiality (and therefore privilege) arising from disclosure to a third party, in this context the AI provider. It is therefore essential for lawyers and clients to understand the tools they are using and whether they provide a sufficiently robust framework to preserve confidentiality.
The Court in UK v Secretary of State for the Home Department differentiates between open-source and closed-source models. However, this is not the crucial distinction to be made here.
“Open-source” refers to whether the underlying model architecture or code is made publicly available, not how user data is processed or stored. By contrast, many widely used systems, including both ChatGPT and Microsoft Copilot, are proprietary, closed-source models. As such, the Tribunal’s distinction does not accurately reflect the technical meaning of the terms “open-source” and “closed-source”, but more importantly, the fact that a model is closed-source does not mean that it is safe to use in terms of confidentiality.
The important distinction: consumer vs enterprise AI services
The real question, therefore, is how a specific system handles, stores and uses the confidential information it receives. This will depend on a range of factors, including the contractual terms governing the service, the provider’s technical architecture, data segregation controls, retention policies, and wider regulatory and compliance framework.
Types of AI services can broadly be separated into two categories: consumer-level and enterprise-level offerings.
Consumer-level AI services are the tools that the general public can access. They are widely available and typically offered via free or low-cost subscriptions that enable day-to-day use (e.g. ChatGPT, Claude, Gemini, Copilot). In many of these offerings, user inputs may be retained and, depending on settings and the specific product tier, may be used to ‘train’ models. For that reason, they likely lack the necessary assurances required to safely process privileged or confidential legal material.
Enterprise-level (or business-tier) services, on the other hand, are specifically designed for organisational use and typically include contractual commitments that the provider will not use customer data to train underlying models, together with enhanced data protection, access controls, and audit capabilities. These include Copilot for Microsoft 365, ChatGPT Enterprise, Claude for Work, and Gemini Enterprise.
As you will note, these are often different versions of the same tool but understanding the distinction between consumer-level and enterprise-level services is crucial in determining whether confidentiality, and as a result privilege, is maintained.
It is important to note that simply because a tool is the “paid version”, does not mean it is safe in this context. For example, subscriptions such as ChatGPT Plus or Claude Pro may offer enhanced functionality but do not generally provide the same contractual and data-handling protections as enterprise-grade offerings and, as such, are still considered consumer-level services.
When thinking about how confidentiality is preserved in these circumstances, a helpful analogy is email. Legal professional privilege has long coexisted with email, despite communications being transmitted, stored and processed by third-party providers such as Microsoft or Google. Privilege is not lost because those providers act as confidential service intermediaries rather than independent recipients of the information.
Enterprise-level AI services are intended to operate in a similar way. Through contractual confidentiality obligations, restrictions on the provider’s use of customer data, and Data Processing Agreements, the provider is intended to process information on the customer’s behalf, rather than using that information for its own independent purposes.
The Tribunal in UK v Secretary of State for the Home Department therefore oversimplifies the issue: Copilot is not inherently safe in relation to confidentiality and privilege; rather, it is the enterprise-level service “Copilot for Microsoft 365”, operating within an appropriate contractual and technical framework, that is capable of preserving confidentiality and privilege.
Other considerations
Although there is currently limited judicial guidance from UK courts on this issue, recent case law from the United States provides useful support for the analysis above.
In United States v Heppner, the Court held that documents generated by a criminal defendant using a consumer-level AI chatbot, Claude in this case, were not protected by attorney-client privilege. In particular, the Court focused on Claude’s privacy policy, which they held did not give rise to a “reasonable expectation of confidentiality”, as the AI provider retained user data. The Court also made the interesting observation that, while the defendant’s interactions with Claude did not amount to communications with counsel for the purposes of privilege, the position may have been different had the tool been used at the direction of the defendant’s lawyer. In those circumstances, it suggested the tool may have operated “akin to a highly trained professional” acting as an agent of the lawyer within the scope of privilege.
While the US concept of attorney-client privilege does not map directly onto the UK framework, the decision, nevertheless, provides helpful insight into how courts are likely to approach the question. It reinforces the central importance of confidentiality: where appropriate protections are not in place, privilege is unlikely to be maintained. Clients should therefore exercise caution when inputting confidential information into AI tools and, where there is any uncertainty, refrain from doing so.
A similar note of caution has been sounded judicially in England and Wales. Sir Colin Birss, Chancellor of the High Court, in a speech to the City of London Law Society, observed:
“Now confidentiality has always been a pre-requisite for the attraction of the privilege, so even if one did extend the concept of the privilege to include advice from AI, on the current approach, it would not seem to attach to the interactions with these public AI systems because they do not appear to be confidential.”
Overall, it should not be assumed that all AI tools can be used interchangeably for confidential or privileged work. Before inputting sensitive information into any AI system, businesses should understand which version of the tool is being used, review the applicable contractual terms and privacy settings, and ensure that appropriate policies and governance measures are in place.
As with all aspects of AI, this remains a rapidly evolving area, and further judicial and regulatory developments are likely in the near future. This is an area that will require ongoing scrutiny as both the technology and its legal treatment continue to develop.
This insight was co-authored by Luca Hoffman.
Get in touch
For more information on this topic or any relating, contact our experts below or meet our team here.