Plainstart Back to the kit

Article

AI and Privileged Material: A Practice Management Question First

There is a practice management problem sitting inside most small firms right now, and it has nothing to do with whether AI is good or bad for legal work. The problem is simpler: staff are probably pasting matter material into AI tools, and the firm has probably not decided whether that is acceptable.

This article does not answer the privilege question. It does not tell you what your obligations are, and it is not legal or professional advice. Your regulator and your own professional obligations govern that. What this article does is lay out the operational side: what to look at, what to establish, and what you can put in place this week.


The Moment of Entry Is the Moment That Matters

When someone pastes a client document into an AI tool, something has already happened. The material has left the firm's environment. Whether it stays there, who can see it, whether it is used to train a model, and whether it can be retrieved later are all questions that depend entirely on the tool and the plan the firm is using.

The moment of entry is the moment that matters operationally because after that moment, the firm's control depends on the tool provider's terms, not on the firm's own infrastructure.

This is not a technology problem. It is a data handling problem, and data handling is a practice management responsibility.

Most people pasting material into an AI tool are not thinking about this. They are solving a problem in front of them. Drafting a letter. Summarising a long document. Finding the right phrase. The speed and usefulness of the tool makes the boundary invisible. That is precisely why the firm has to make the boundary visible before the paste happens, not after.


What You Can Actually Establish About a Tool's Behaviour

The first practical step is finding out what the tools your staff are using actually do with input data. This is knowable. It requires reading documentation, not trusting the brand.

Here is what to look for:

Retention period. Does the tool store inputs? For how long? Is that period configurable? Some enterprise plans allow zero retention. Consumer plans often do not.

Training use. Is input data used to improve the model? Many consumer tiers use inputs for training by default. Many business or enterprise tiers opt out of this. The difference is real and material.

Who can access inputs. Can the provider's staff access what is entered? Under what circumstances? What does the terms of service actually say?

Where data is processed and stored. The provider's servers may be in a jurisdiction different from your clients'. Whatever privacy rules apply where you operate vary by jurisdiction and are worth checking with an adviser who knows your situation.

Deletion on request. Can you have specific inputs deleted? Is there a process for this?

None of these answers require a technical background. They require reading the provider's documentation, their terms of service, and their data processing agreement if one is available. For enterprise plans, these agreements are usually negotiable. For consumer plans, they usually are not.

If a tool's documentation does not answer these questions clearly, that absence of clarity is itself an answer worth noting.

The goal is a short factual summary: for each tool the firm uses or allows, what does it actually do with what goes into it. This can be done by one person in a day. It is not a project. It is a reading exercise.


Popularity Is Not a Proxy for Appropriateness

The most common AI tools are popular because they are good at the general task. They are not designed for the specific data-handling requirements of a law firm, and their consumer defaults reflect a general-purpose audience.

A tool being widely used in the profession says nothing about whether it is appropriate for a specific category of material at your firm. A tool being used by large firms says nothing about whether their data handling arrangements match yours, because they have almost certainly negotiated enterprise agreements with terms that consumer users do not get.

The question is not: is this tool generally acceptable? The question is: what does this specific plan, with these specific terms, do with the specific category of material we are considering putting into it?

That question is firm-specific and matter-type-specific. No article, no industry survey, and no conference panel can answer it for you. Only the tool's documentation and your own professional obligations can.


What a Firm Can Put in Place This Week

You do not need a finished policy to start reducing risk. You need a small number of clear rules that staff understand and can follow.

Here is a practical sequence for this week:

Day one. Ask staff directly what AI tools they are using for work. Do not assume the answer. People use personal accounts on personal devices. People use tools the firm has not issued. The answer to "what are we using" is often larger than the firm expects.

Day two. For each tool identified, find the data handling documentation and answer the questions above: retention, training use, access, location, deletion. Write it down in plain language, even if that document is only a page.

Day three. Make a provisional category decision. Before a full policy exists, a firm can set a simple rule: no client material above a certain sensitivity threshold goes into any tool without explicit sign-off. The threshold can be defined by matter type, by client category, or by the nature of the material. Define it simply enough that a junior staff member can apply it without asking.

Day four. Tell staff. Verbally, in writing, in whatever channel the firm actually uses. A rule no one knows about does not exist.

Day five. Decide how staff should flag a question if they are unsure whether something falls within the rule. The question "can I put this in?" should have somewhere to go. If it has nowhere to go, staff will guess.

This is not a substitute for a proper policy. It is a holding position that reduces the most likely harm while the firm works on something more complete.


A Worked Example: One Firm, One Category

A five-person litigation firm noticed that staff were using a popular AI assistant for drafting. The partners had not discussed it. No one had said it was permitted or prohibited. It had simply started happening.

The managing partner decided to start with one category: anything containing witness statements or instructions from clients in active matters.

She read the documentation for the tool staff were using. It was a consumer account. Input data was used for model training by default. There was no enterprise agreement. She confirmed this in a page of notes.

She set one rule: nothing from an active matter file goes into that tool on a consumer account, full stop. Not for drafting, not for summarising, not for any purpose.

She told staff this verbally in a short meeting. She followed up in writing on the same day. She said the firm would work out a broader policy over the following month, and that in the meantime this was the rule for this category.

She did not call it a policy. She did not wait for a policy. She made one clear decision about one clear category and communicated it.

That is a practice management decision. It took one meeting and one email.


What Comes Next

A proper approach to AI data handling in a law firm needs more than one rule for one category. It needs a written usage policy, a way to evaluate tools before staff start using them, and clear guidance that is reviewed as tools change.

If you want a starting point, Plainstart publishes a free AI usage policy template built for professional services firms. It is plain language, editable, and designed to be adapted rather than adopted wholesale.

The policy question does not replace the professional obligations question. Your regulator sets what is required of you. Your engagement letters, your client contracts, and your professional body's standards all bear on what is appropriate. This article, and any template, is general guidance only. It is not professional advice, and it does not substitute for advice from someone who knows your firm, your jurisdiction, and your specific situation.

The practice management part, though, you can start on today.


This article is general guidance on practice management and data handling. It is not legal advice, professional advice, or a statement of your obligations. Your professional obligations are governed by your regulator and your own professional rules. Seek appropriate advice for your specific situation.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator