As AI Tool Use Expands, Questions Arise About Attorney-Client Privilege

Recent court decisions suggest that using consumer artificial intelligence tools for legal guidance could jeopardize privileged communications, but the law remains unsettled.

Using an artificial intelligence tool to get answers to retirement and benefit legal questions could cost a plan sponsor the attorney-client privilege they have always relied on when working with human counsel.

Recent federal court decisions have raised questions about whether communications involving AI remain protected by attorney-client privilege, creating uncertainty for employers, retirement plan sponsors and fiduciaries, all of which are increasingly incorporating generative AI into their day-to-day operations.

Never miss a story — sign up for PLANSPONSOR newsletters to keep up on the latest retirement plan benefits news.

The issue has gained urgency as AI adoption accelerates. A 2025 Mercer survey of 225 plan sponsors found that 67% were actively exploring AI to their plan strategy.

According to Litify’s 2025 “State of AI in Legal” report, 66% of legal professionals reported using ChatGPT, while 42% use Microsoft Copilot and 24% use Google Gemini. Yet 53% said their firms have no formal AI policy, highlighting a gap between the reality of adoption and governance.

While legal experts caution that laws governing AI use are still developing, they broadly agree that organizations should be careful if entering confidential legal information into publicly available AI platforms.

An Important Case Sparks Debate

Much of the discussion on this topic was illuminated by United States v. Heppner, a February decision from the U.S. District Court for the Southern District of New York.

In that case, a criminal defendant independently used Anthropic’s Claude AI agent to analyze his legal situation and generate potential defense strategies before sharing those materials with his attorneys. The court concluded the documents were protected by neither attorney-client privilege nor the attorney work-product doctrine because the AI platform was not an attorney, lacked confidentiality protections and was not used under the direction of counsel.

According to legal commentators, the ruling does not establish a blanket prohibition on using AI in legal matters, but instead reinforces long-standing privilege principles.

In a subsequent decision in Warner v. Gilbarco, a magistrate judge in the U.S. District Court of the Eastern District for Michigan reached a different conclusion on work-product protection, treating AI more like a research tool than a third party.

Together, the differing decisions suggest that courts are likely to examine the specific facts of AI use, rather than adopt a catch-all rule.

“The law is still developing,” says Joseph Lazzarotti, a principal in Jackson Lewis P.C.’s privacy, data and cybersecurity practice.

Enterprise AI May Have Reduced Risk

Lazzarotti says employers should distinguish between consumer AI platforms and enterprise systems operated under contractual confidentiality protections.

For example, in Heppner, the defendant used a consumer-level AI tool and did so of his own accord, not directed by counsel, disclosing information to a third party, “which had no obligation of confidentiality,” according to the court.

At the same time, Lazzarotti notes that many organizations are now using enterprise AI accounts, rather than publicly available consumer tools, which he says could reduce the risk of lost privilege.

“Most companies are using enterprise accounts,” Lazzarotti says. “Assuming the terms of use accurately reflect what’s going on, then they’re not making a disclosure to an unknown third party. An enterprise account would probably not result in a waiver of privilege.”

Questions Remain

For retirement plan fiduciaries, the analysis becomes even more nuanced because attorney-client privilege is already limited in certain Employee Retirement Income Security Act contexts through the fiduciary exception, under which some legal communications regarding plan administration may ultimately be discoverable.

Under the fiduciary exception to attorney-client privilege, retirement plan participants are often entitled to see legal advice given to plan fiduciaries about managing and administering the plan, because the fiduciaries are acting on the participants’ behalf.

However, legal advice obtained by fiduciaries to defend themselves against claims or litigation generally remains protected.

Fred Reish, a counsel at the Ferenczy Benefits Law Center and director of ERISA and fiduciary strategy at Prime Capital Financial, says employers should recognize that simply introducing AI into legal workflows could complicate privilege analyses.

Even within corporate environments, Reish says organizations should not assume AI-generated legal discussions will necessarily receive the same protections as traditional attorney communications.

“Generally speaking, there’s an attorney-client privilege,” he says. “But if it becomes so intertwined with artificial intelligence, it’s going to be more difficult to separate it out. Certainly, [for] anything that’s not contained, you’d lose the attorney-client privilege.”

Reish also notes that legal communications are only privileged when they involve seeking or providing legal advice, meaning many internal discussions remain discoverable, regardless of whether AI is involved.

An Evolving Legal Landscape

Legal observers say neither Heppner nor Warner fully answers how courts will treat enterprise AI platforms used under attorney supervision.

Several legal analyses following the decisions suggest attorney involvement, contractual confidentiality protections and documenting that AI is being used at counsel’s direction may ultimately become important factors in preserving privilege, though those questions remain largely unanswered in court.

It would likely take higher court decisions,  and/or a case more specific to ERISA, to attract greater concern, experts say.

For employers increasingly weaving AI into compliance, governance and legal workflows, that uncertainty means existing privilege rules still matter as much as the technology itself.

“Somebody in the benefits department who’s going onto their personal ChatGPT account could present a risk. So you do have to be careful,” Lazzarotti says.

«