AI Privilege: Code May Matter More Than Courts
TL;DR
Background: OpenAI CEO Sam Altman has called for an “AI privilege,” arguing that users often confide in AI services much as they do in doctors, lawyers, or therapists. Yet ordinary AI chats generally receive no comparable legal protection. Courts may therefore order their disclosure when they are relevant to a lawsuit, whether the user is a party or the provider itself becomes a target, as in New York Times v. OpenAI.
But… Critics say the proposal is premature and does not fit neatly within established privileges, which usually protect defined professional relationships backed by duties of confidentiality and institutional accountability. AI providers are not lawyers or therapists, and the case for shielding their records weakens when they can freely access, retain, or reuse chats for training, advertising, or other business purposes. Any new privilege would also need rules governing its scope, waiver, abuse, and exceptions for fraud, imminent threats, and public safety.
Moreover… Technical design may offer a more immediate safeguard. Private-cloud systems and trusted execution environments (TEEs), which isolate data while it is processed, can allow providers to run AI services without seeing or retaining the user’s unencrypted conversation. That protection is incomplete, especially when copies remain on the user’s device or data leaves the protected environment. Still, what a provider genuinely cannot access, it generally cannot be compelled to hand over.
KEY TAKEAWAYS
Chats on the Record
Ordinary consumer chats with AI systems generally receive no evidentiary privilege. That means courts may order their disclosure during discovery—the pretrial process for obtaining relevant evidence—so long as the request is sufficiently relevant and not unduly burdensome. In New York Times v. OpenAI, for example, OpenAI was ordered to produce millions of de-identified ChatGPT conversations, most belonging to users with no connection to the case.
The same risk arises in everyday disputes. Chats about a divorce, employment claim, business deal, or possible lawsuit may be sought from the user, the provider, or both. Privacy laws, redactions, and court orders limiting further disclosure can reduce the damage. They do not provide the broad shield that privilege does.
Not Every Confidence Counts
Evidentiary privileges are narrow exceptions to the general rule that courts should have access to relevant evidence. As Ira Robbins argues, established privileges typically protect socially valuable relationships supported by professional duties, a defined purpose, confidentiality rules, and institutional accountability.
Ordinary AI providers do not neatly fit that model. They are not lawyers or therapists, owe no comparable professional duties, and may reserve broad rights to access, store, or reuse chats. AI services also range from search tools and writing assistants to medical and legal applications, making a single rule difficult to design.
Personal expectations are not enough. Diaries and conversations with friends may be deeply intimate, but courts can still compel their disclosure. Even a contractual promise of confidentiality may not create a legal privilege.
Existing doctrines may nonetheless protect some AI-assisted work. A lawyer’s use of AI while representing a client, for example, may fall within ordinary attorney-client privilege if confidentiality is properly maintained.
The status of a litigant’s own AI-assisted preparation is less clear. The work-product doctrine generally protects materials prepared for litigation from disclosure. In United States v. Heppner, a court denied protection for a represented defendant’s independent exchanges with Claude. In Warner v. Gilbarco and Morgan v. V2X, courts protected AI-assisted work by self-represented litigants.
These fact-specific rulings may help shape the law of privilege as it applies to AI, but they do not create a general privilege for AI conversations.
The Privilege Puzzle
Any AI privilege would need a workable scope. Would it cover every conversation, or only defined uses such as legal, medical, or therapeutic guidance? Lawmakers would also need rules for mixed-purpose chats, stored memories, and records of actions taken by AI agents.
The privilege would presumably belong to the user, just as attorney-client privilege belongs to the client. The provider’s role is less obvious. Should it merely preserve the records, or should it be able—or required—to assert the privilege on the user’s behalf?
Provider access creates an even larger problem. It is hard to justify keeping chats from courts and opposing parties while allowing the AI company to examine them for training, advertising, or other commercial purposes. A credible privilege might therefore require providers to be technically unable—or legally forbidden—to access protected conversations.
No privilege could be absolute. It would need rules for waiver, fraud or criminal activity, imminent threats, and public safety. Health care shows how complicated those distinctions can become. The Health Insurance Portability and Accountability Act (HIPAA) protects certain health information held by certain organizations, but it still permits disclosure under court orders and qualifying subpoenas. Communications with psychotherapists may receive a separate evidentiary privilege. Even in a mature legal regime, protection depends on who holds the information, what the record contains, and why someone wants it.
A broad AI privilege could also invite abuse. Users might route otherwise discoverable material through an AI simply to place it behind a legal shield—a kind of privilege laundering.
Can’t Disclose What You Can’t Access
Technical safeguards can provide a practical substitute for legal protection. When a conversation is processed on the user’s device or inside a properly designed TEE, and the provider neither keeps nor can read the unencrypted text, the provider cannot hand it to opposing lawyers, law enforcement, attackers, or curious employees. No new legal doctrine is required.
The substitute is incomplete. A copy stored on the user’s device may still be obtained from the user. Information sent outside the protected system—for persistent memory, external tools, human safety review, or account history—may remain accessible to the provider. Companies could also weaken voluntary safeguards later, whether for business reasons or under government pressure.
Technical design may nevertheless shape future legal rules. Verifiable limits on provider access and reuse could support a reasonable expectation of confidentiality and strengthen the case for narrow legal protection.
The immediate advantage is simpler: What a provider genuinely cannot access, it generally cannot be ordered to produce.
For more on this issue, see the June 2026 ICLE webinar “‘AI Privilege’ or Why and How Should Our Chats with AIs Be Legally Protected?”