10 min read

Tool or Third Party: The AI Privilege Test Your Vendor Cannot Pass for You

## Tool or Third Party: The AI Privilege Test Your Vendor Cannot Pass for You **THE TECHNOLOGY BLIND SPOT** Catherine read the Bloomberg headline at 6:42 in the morning, before the partners’ meeting. A federal judge in Manhattan had stripped privilege from thirty-one documents because a criminal defendant had used Anthropic’s consumer Claude product to draft them. Two weeks earlier, a magistrate judge in Detroit had reached the opposite conclusion on materially similar facts. Six weeks after that, a magistrate in Colorado had refused both extremes and written a contractual safeguard test directly into the protective order. She forwarded all three opinions to her IT director with one question: which one applies to us? The reply came back at 9:14: “Checking with the vendor.” Jed Rakoff in the Southern District of New York, Anthony Patti in the Eastern District of Michigan, and Maritza Dominguez Braswell in the District of Colorado examined the same generative-AI technology in the first quarter of 2026 and reached three different conclusions about what it is. Rakoff held that Claude was a third party. Patti held that ChatGPT was a tool. Braswell held that the AI was potentially either, depending on what the vendor’s contract said. Three federal courts. One question. No agreement. That question now sits at the door of every law firm using AI for substantive legal work: when does an AI system function as a tool that preserves privilege, and when does it function as a third party that destroys it? No appellate court has answered. No bar association has supplied an analytical framework adequate to the question. **The framework attorneys need to apply Thursday morning arrived this month.** **Sixty Years of Doctrine, One New Question** The attorney-client privilege has tolerated third parties since 1961. *United States v. Kovel* extended the privilege’s protective circle to accountants, translators, investigators, and other agents whose involvement is “reasonably necessary” for competent legal advice. The doctrine has worked for sixty years on three structural assumptions: the third party operates under attorney direction, performs work necessary for the legal advice, and maintains the confidentiality of the communication. Generative AI breaks the third assumption. A consumer AI vendor’s terms of service typically authorize the vendor to retain user inputs, train its models on those inputs, and disclose data to governmental authorities and other third parties. The vendor has independent commercial interests in the substance of every query the attorney enters. A translator who simultaneously published every translation would destroy privilege regardless of attorney direction. The same logic applies to a platform whose terms authorize training and disclosure. The three federal courts disagreed because they reasoned from different starting points. Rakoff treated Claude as an entity that receives information, processes it independently, and operates under terms serving the vendor’s interests. He cited Professor Ira Robbins’s framework, which holds that recognized privileges require “a trusting human relationship” with a licensed professional subject to discipline. Patti treated ChatGPT as subordinate to the user’s strategy, focusing on functional use rather than vendor architecture. Braswell treated the AI as potentially either, depending on contractual safeguards. None of the three articulated a general test for distinguishing the categories. That classification, tool or third party, is the question. The doctrine has not yet supplied the answer. **The Four Dimensions** Published in April 2026 by Alexis Austin Litle, Esq., me, and Deepankar Das, the AI Legal Reference Model proposes a ten-factor test organized around four analytical dimensions. The dimensions, not the individual factors, do the doctrinal work. A managing partner running a Thursday-morning audit can ask one question per dimension and identify within an hour whether the firm’s primary AI tool sits closer to “tool” or “third party” classification. Figure 1: ALRM Simplified Waiver Framework. Source: Austin Litle, Morris & Das (Apr. 2026), https://dx.doi.org/10.2139/ssrn.6546398. The first dimension is the attorney-agency relationship: who directs the AI’s work and who takes professional responsibility for the output. An AI used at counsel’s direction, supervised under Rule 5.3, with the attorney accountable under Rule 1.1, sits inside the privilege perimeter. An AI used by a client independently, with the attorney unaware of the use, sits outside it. Heppner failed this dimension at the threshold. The defendant generated the disputed documents on his own. Contractual architecture is the second: what the vendor’s contract says about training, retention, confidentiality, and disclosure. This is the dimension Judge Braswell wrote into the Morgan protective order. A platform contractually prohibited from training on firm inputs, contractually bound to maintain confidentiality, and contractually obligated to delete on request, sits closer to tool. A platform whose default terms reserve training rights and authorize governmental disclosure sits closer to third party. System architecture is the third: how the AI is built. Systems whose outputs are constrained to retrieved or cited source material occupy different doctrinal ground than systems generating ungrounded text through stochastic prediction. Three formal impossibility proofs published in 2024 and 2025 establish a hard limit. No large language model that retains a random-generation step can avoid hallucination. Scale and prompting do not fix it. The mathematics is settled. The doctrinal consequence is not. Review mechanism is the fourth: whether the attorney conducted meaningful, documented review or filed a draft after twelve seconds of glance. The Sixth Circuit answered the floor in United States v. Farris on April 3, 2026. Staff-level verification does not satisfy the supervisory standard Rule 5.3 requires. The attorney had directed a non-attorney staff member to upload case documents to Westlaw’s CoCounsel platform and worked in the resulting file without personally verifying citations. The court forfeited his Criminal Justice Act compensation for the appeal, referred him to the Kentucky Bar, and ordered his immediate removal from the case with appointment of replacement counsel. Factor 10 of the framework is the documentation that survives such an inquiry. **What Opposing Counsel Files Next** The framework’s ten open questions are not academic. Each one is a motion opposing counsel can draft today against a firm whose deployment matches the predicted third-party side of the analysis. Six months from now, the questions return as discovery requests. Twelve months from now, as published opinions. Figure 2: ALRM Waiver with Open Judicial Questions. Source: Austin Litle, Morris & Das (Apr. 2026), https://dx.doi.org/10.2139/ssrn.6546398. Eight of the ten questions resolve toward third-party classification with high confidence. Six are the predicted losses Catherine should expect to defend. Two split on the fact pattern. Two resolve toward tool. Each prediction names a procedural test an attorney can apply in either direction: defensively, against motions opposing counsel will file; offensively, against an adverse party whose own AI deployment fails the framework. Attorney-directed use of consumer AI (Question A). A partner directs an associate to draft motion outlines in ChatGPT. The associate complies. Opposing counsel moves to compel the prompt history on grounds that ChatGPT’s terms reserve training and disclosure rights. The framework predicts attorney direction does not cure contractual exposure. Procedural test: confirm both that counsel directed the use and that the vendor contract bars retention, training, and disclosure. If either fails, the protective frame fails with it. Opt-out training toggles (Question B). The firm’s enterprise tier disables training on inputs. The vendor still retains, hosts, and processes inputs through its infrastructure. The framework predicts the toggle is insufficient because it addresses one stage of the data lifecycle and ignores the rest. Procedural test: the contract must bar retention, processing, AND disclosure, not only training. Anything narrower leaves the lifecycle exposed. Multi-agent AI chains (Question D). The agent the firm deployed last quarter routes prompts through three subprocessors before returning a response. Each subprocessor operates under separate terms. The framework predicts each link is analyzed separately, with the weakest link controlling. Procedural test: all subprocessor terms must be read and verified. The unverified link is the link opposing counsel will target. AI memory across matters (Question E). The associate’s AI retains context across sessions to improve responses. Memory crosses two unrelated matters. The framework predicts cross-session memory transforms the tool into a shared repository, weighing toward third-party classification. Procedural test: memory must be disabled, or scoped per-matter with documented separation. The Oregon State Bar’s Formal Opinion 2026-208 stated the consequence directly: confidentiality due diligence “must reach beyond the policies of the company that offers the chatbot service.” Judicial use of consumer AI (Question F). A judge uses a consumer AI to draft a memorandum in chambers. The framework predicts deliberative privilege is violated when consumer AI exposes judicial deliberations through retention terms. Two procedural tests apply, scaled to firm posture. For sophisticated counsel: appellate practice, amicus participation in test cases, or funded research advances the question through institutional channels rather than direct trial-level confrontation. For trial counsel: build the appellate record on the underlying defect, fabricated authority, miscited rule, or internal inconsistency, and let the reviewing court reach the AI question. Direct trial-level inquiry against a sitting judge requires evidentiary basis specific to the proceeding under Rule 8.2(a). The question is not yet ripe for routine motion practice. Common-interest defense plus shared AI (Question I). Three co-defendants agree to use a shared AI tool. The platform is shared. The legal interest may not be. The framework predicts a shared vendor is not a shared legal interest. Procedural test: the AI must be scoped to the joint defense, and each defendant must be a contractual party to the vendor agreement. Two questions split on the fact pattern. Question C (Warner beyond pro se litigants) and Question G (AI-assisted testimony preparation) depend on whether the AI was used by counsel for prompts or by the witness for substance. The line matters because witness use exposes the underlying substance to discovery. The remaining two questions resolve toward tool. Question H (adverse inference for platform selection) and Question J (inadvertent subprocessor disclosure, if the attorney was diligent) preserve protection where counsel acted reasonably. The diligence standard is the test. The documentation is the proof. Each prediction generates two procedural moves. Defensively, identify which factor in the firm’s current deployment fails the predicted direction, and close the gap contractually before opposing counsel files. Offensively, in litigation against an adverse party using AI, identify which factor their deployment fails, and pursue a discovery request, motion to compel, or evidentiary objection that puts the question in front of the court. Which question resolves first is unknown. Motion calendars are not. **The Architectural Alternative** Only one deployment model eliminates third-party exposure across all ten factors: firm-proprietary AI operating inside the privilege perimeter. Not because firm-proprietary AI is better at the underlying task. Because it removes the vendor as an external party with commercial rights in the data. That is the framework’s central architectural finding. A reasonable objection follows. Firm-proprietary AI is not feasible for every solo and small firm, and contractual architecture, the second dimension, is the next-best position for firms that cannot deploy proprietary infrastructure. Morgan’s contractual safeguard test, applied as a supervisory floor, gets a small firm to a defensible “reasonable steps” position under FRE 502(b). The framework’s authors acknowledge this directly. What the objection cannot do is rewrite the legal test. Privilege has always turned on the totality of circumstances, not on a single label. Bright-line rules, “all consumer AI is third party, all enterprise AI is tool,” fail because vendors relabel consumer tiers as enterprise without changing the underlying architecture. Stanford’s research is direct. Commercial legal AI tools marketed as “hallucination-free” produce wrong information between 17 and 33 percent of the time. A rule that treats platform tier as dispositive would protect privilege for tools that fail at this rate. A second pressure point bears watching. Cyber insurance underwriters writing AI endorsements are reading the same federal opinions managing partners are reading. They are reading the same state bar opinions. The next renewal cycle is the first place the framework’s doctrinal trajectory will hit the firm in dollars: through an AI exclusion the broker did not flag, or a coverage gap the underwriter prices on the basis of factors the firm has not documented. The firm that can produce a written record of attorney direction, vendor contractual safeguards, system architecture, and review documentation occupies a different position at renewal than the firm that can produce a SOC 2 attestation and a vendor’s marketing deck. **Thursday Morning** The framework is free on SSRN. Print Table 1 (Alexis Austin Litle, JD Morris & Deepankar Das, The AI Legal Reference Model (ALRM): A Ten-Factor Doctrinal Framework (Apr. 2026), https://dx.doi.org/10.2139/ssrn.6546398.). For the firm’s primary AI tool, run one diagnostic per dimension before the next associate meeting. Contractual architecture: confirm whether the firm’s contract with the vendor prohibits training on inputs. Attorney-agency and review mechanism: confirm whether associates and paralegals are using the tool under attorney direction with documented review, or whether the AI is generating drafts that go to clients with twelve-second sign-off. System architecture: confirm whether the system retrieves from a verified corpus or generates ungrounded text. If the four answers do not converge toward tool classification, the firm carries third-party exposure under the framework, which is to say, under the doctrinal trajectory the next motion to compel will travel. The fix is contractual architecture before it is anything else: pull the vendor master agreement, look for two clauses, one barring training on inputs and one barring third-party disclosure except where essential to service delivery, and then confirm that the vendor is contractually obligated to delete firm data on request. If the vendor’s terms of service reserve training rights, the firm carries third-party exposure. If the vendor’s terms authorize disclosure to governmental authorities, the firm carries third-party exposure. If the vendor’s terms do not obligate deletion on request, the firm carries third-party exposure. If the firm’s primary AI tool is a consumer AI, the firm carries third-party exposure. If the firm’s primary AI tool is an enterprise AI, the firm carries third-party exposure unless the vendor’s contract prohibits training on inputs, prohibits disclosure to governmental authorities, and obligates deletion on request. If the firm’s primary AI tool is a firm-proprietary AI, the firm carries no third-party exposure. This is the only architectural alternative that eliminates third-party exposure across all ten factors. If the firm carries third-party exposure, the firm should consider whether to: 1. **Switch to a firm-proprietary AI.** This is the only architectural alternative that eliminates third-party exposure across all ten factors. 2. **Switch to an enterprise AI with contractual safeguards.** This is the next-best position for firms that cannot deploy proprietary infrastructure. Morgan’s contractual safeguard test, applied as a supervisory floor, gets a small firm to a defensible “reasonable steps” position under FRE 502(b). 3. **Continue using the current AI with a litigation hold.** This is the least desirable option, as it leaves the firm vulnerable to motions to compel and evidentiary objections.

Originally published on LinkedIn Newsletter: The Technology Blind Spot

Leave a Reply

Discover more from The Technology Blind Spot

Subscribe now to keep reading and get access to the full archive.

Continue reading