The question is narrow but consequential: what must be in place before an organization uses artificial intelligence to analyze, summarize or route information protected under attorney-client privilege? The answer requires governance decisions that fall outside conventional IT security and outside conventional legal practice. Someone must decide what the vendor may retain, who may access outputs, how the system logs use, and what happens when the tool produces an incorrect summary that counsel relies upon. Without clarity about who makes those decisions and what standards govern them, the organization assumes risk it has not measured.

Why This Matters Now

AI tools marketed for legal document review, contract analysis, discovery assistance and case management are widely available and attractive. They promise speed, cost reduction and pattern recognition at scale. General counsel and law firm leadership are evaluating whether to adopt them.

The business risk is not that the technology fails to work. The risk is that using it changes the conditions under which privilege attaches or is preserved. Privileged communications shared with a third party under circumstances that do not maintain confidentiality may lose their protected status. An AI vendor that retains inputs to improve its model, or that permits its staff to review flagged content, may be such a third party. If privilege is waived inadvertently, opposing counsel may compel disclosure of communications the organization believed were protected.

A second risk is evidentiary. If the AI system produces a summary or classification that counsel relies upon, and that output is incorrect or incomplete, the organization may make a strategic decision based on flawed information. If that decision leads to disclosure of privileged material or failure to produce required documents, the consequences can include sanctions, adverse inference instructions, or waiver findings.

These are governance problems, not technology problems. The questions that determine risk are: who decided the vendor's acceptable use terms were adequate? Who verified that the system does not use inputs for model training? Who confirmed that access logs are sufficient to reconstruct what was reviewed? Who owns the decision to rely on AI-generated summaries in privilege review? If no one can answer those questions clearly, accountability is absent.

What Controls Must Be Established

Vendor Agreements and Data Handling

Before privileged material enters an AI system, the vendor agreement must address data retention, use and access. The following terms are baseline requirements, not optional enhancements:

  • **No use of inputs for training or model improvement.** The agreement must prohibit the vendor from using submitted documents, queries or outputs to train, refine or improve any AI model, whether for the customer's benefit or for other customers.
  • **No human review of content without explicit authorization.** Vendor personnel must not access submitted materials except under defined circumstances that the customer approves in advance, such as troubleshooting a specific technical failure upon request.
  • **Immediate deletion upon termination or request.** The customer must be able to require deletion of all submitted data, and the vendor must confirm deletion within a defined period.
  • **Subprocessor disclosure and approval rights.** If the vendor uses subcontractors to process data, the customer must know who they are and have the right to object before data is shared.
  • **Audit rights.** The customer must have the contractual right to audit the vendor's data handling practices or to require an independent attestation of compliance with agreed terms.

These terms are business decisions, not technical specifications. They require legal judgment about what risks are acceptable and what the vendor's operational realities permit. If the vendor will not agree to these terms, the decision to proceed anyway is a governance decision that should be documented and approved by someone with authority to accept the risk.

Access Control and Logging

Preserving privilege requires knowing who accessed what, and when. AI systems must log user activity in a way that supports privilege claims if challenged. The organization should establish the following before processing privileged material:

  • **User authentication and role-based access.** Only individuals with a legitimate need to access privileged communications should be able to submit documents to the AI system or view outputs. Access should be tied to identity, not shared credentials.
  • **Audit trails of queries and outputs.** The system should log what documents were submitted, what questions were asked, what summaries or classifications were produced, and who reviewed them. These logs are evidence of care in maintaining confidentiality.
  • **Retention of logs consistent with litigation hold obligations.** If the organization is under a litigation hold, logs of AI system use may be relevant evidence and must be preserved accordingly.

Many AI tools do not provide this logging by default. Some do not provide it at all. If the tool cannot produce an audit trail that demonstrates confidentiality was maintained, the organization should consider whether that limitation is acceptable before processing privileged material.

Review and Validation Protocols

AI outputs are probabilistic, not deterministic. A generative AI system may produce a summary that omits key facts, introduces information not present in the source document, or mischaracterizes the substance of a communication. If counsel relies on that output without verification, the organization assumes the risk of decisions based on incorrect information.

Before AI is used for privilege review or legal analysis, the organization should establish protocols that define:

  • **What level of verification is required before relying on AI outputs.** Will every AI-generated summary be reviewed against the source document? Will a sample be reviewed? What qualifies as sufficient verification?
  • **Who is qualified to perform that verification.** Is it an attorney? A supervised paralegal? Someone with subject matter expertise in the underlying dispute?
  • **What happens when an error is detected.** If the AI produces an incorrect summary, is that logged? Is the vendor notified? Is the error rate tracked and reviewed periodically?
  • **When AI outputs may be used without additional review.** Are there tasks where AI-generated classifications or summaries are considered sufficiently reliable to act upon without human verification, and if so, what justifies that determination?

These are judgment calls. They require someone with legal expertise to assess the risk of error in context. They also require documentation, so that if a privilege determination is later challenged, the organization can demonstrate that it exercised care.

Who Owns These Decisions

The question of accountability is the difficult one. The general counsel owns the privilege determination. The chief information officer or chief information security officer may own vendor risk management and access control policy. The chief compliance officer may own regulatory positioning if the organization operates in a sector with specific data handling requirements. But the decision to use AI for privileged material sits at the intersection of all three, and none of them typically owns the decision end-to-end.

Adequate ownership requires a single executive who can answer the following:

  • What vendor terms are acceptable, and who approved them?
  • What access controls are required, and who verified they are in place?
  • What validation protocols apply, and who is accountable for compliance with them?
  • What happens if the AI produces an incorrect output that counsel relies upon, and who decides whether to disclose that error?
  • If privilege is challenged, who assembles the evidence that confidentiality was maintained?

If no one can answer those questions, the organization has a governance gap. The gap does not mean the AI tool should not be used. It means the decision to use it has not been made deliberately, with accountability for the consequences.

This is the gap that [virtual CISO leadership](/vciso/) addresses in the broader cybersecurity context: executive accountability for risk decisions, vendor positioning, governance structure and regulatory interpretation. The same gap exists for AI applied to privileged communications. Someone must own the strategy, translate legal and technical requirements into operational controls, and report to leadership on whether those controls are effective.

The Broader Context: AI and Emerging Technology Governance

The use of AI to process attorney-client privileged material is one instance of a larger governance challenge: how organizations make decisions about emerging technologies that create new risks or change the conditions under which existing controls apply.

Frameworks such as the NIST Cybersecurity Framework and the NIST Privacy Framework provide structure for identifying and managing risk, but they do not resolve the question of who decides. The Cybersecurity Framework organizes risk management into functions—Govern, Identify, Protect, Detect, Respond, Recover—but it does not specify who inside the organization is accountable for those functions when the risk spans legal, technical and compliance domains. The Privacy Framework provides a structure for managing privacy risk through enterprise risk management, but it assumes governance roles are already defined.

AI governance for privileged communications requires someone to integrate legal judgment, technical controls and vendor risk management into a coherent decision-making process. That integration is an executive function, not a staff function. It cannot be delegated to IT, to outside counsel or to a cross-functional committee without a clear owner.

What Leadership Should Do Next

If your organization is evaluating AI tools for legal document review, contract analysis or case management, the following steps establish accountability before deployment:

  • **Identify who owns the decision.** Before any privileged material is processed by an AI system, assign a single executive accountability for vendor terms, access controls, validation protocols and evidence of compliance. Document that assignment.
  • **Review vendor agreements against privilege requirements.** Confirm that the vendor agrees not to use inputs for training, that human access to content is restricted and logged, and that data can be deleted upon request. If the vendor will not agree to those terms, document the decision to proceed and the rationale.
  • **Establish logging and access control requirements.** Define what audit trails are necessary to demonstrate that confidentiality was maintained. Verify that the AI system can produce those logs before processing privileged material.
  • **Define validation protocols.** Decide what level of verification is required before relying on AI outputs for privilege determinations or legal analysis. Document the protocols and assign accountability for compliance.
  • **Test the controls before deployment.** Process a small set of non-privileged documents through the AI system. Verify that access controls work as intended, that logs capture the required information, and that outputs can be validated according to the defined protocol.

If your organization lacks the internal resources to establish these controls, or if accountability for AI governance is unclear, a confidential consultation can clarify what ownership looks like, what controls are adequate, and how to position the decision for board or executive leadership. Heights Consulting Group provides virtual CISO leadership for organizations that need executive accountability for technology risk decisions, including AI governance. If that describes your situation, you are welcome to a single confidential conversation to determine whether structured governance would serve your needs. Contact Heights directly to arrange it.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: AI and Emerging Technology Governance

Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.

Read about AI and Emerging Technology Governance