Blog Ethics & Compliance

Attorney-Client Privilege and AI Document Review: What Rule 1.6 Actually Requires

ABA Model Rule 1.6 requires competent measures when using technology that processes client data. Here's what that actually means for AI review tools.

Legal brief pages with attorney notation marks, confidential theme

When a law firm uploads client documents to an AI review platform, two questions arise simultaneously. The first is a privilege question: does passing those documents through a third-party system risk waiving attorney-client privilege or work product protection? The second is an ethics question: what does the firm's confidentiality obligation under Model Rule 1.6 require before they do it?

These questions get conflated in practice, and conflating them produces bad answers to both. The privilege analysis and the Rule 1.6 analysis are distinct inquiries that reach different issues. Getting them right requires keeping them separate.

The Privilege Question: Disclosure to Necessary Third Parties

Attorney-client privilege protects confidential communications between attorney and client made for the purpose of seeking or giving legal advice. Work product protection shields materials prepared by or for a party in anticipation of litigation. Both protections can be waived through voluntary disclosure to third parties who aren't within the scope of the protection.

The legal framework for whether disclosure to a service provider waives privilege is well-established: disclosure to a third party who is an agent of the attorney or who is necessary to the rendering of legal services does not constitute waiver. Courts have applied this framework to support staff, contract attorneys, litigation support vendors, and — in the cases that have addressed the question — technology platforms used in legal work.

The practical implication: transmitting client documents to an AI document review platform operated as a legal services vendor, subject to a contractual confidentiality and data protection agreement, is generally analyzed the same way as transmitting those documents to an outside vendor for processing. The vendor relationship, the purpose of disclosure (rendering legal services), and the contractual protections define whether privilege is maintained. The technology involved doesn't change the legal framework — it just changes how carefully you need to review the vendor agreement.

This is not a categorical green light. A firm that uploads client documents to a general-purpose AI assistant that trains on user-submitted content is in materially different territory than a firm using a purpose-built legal platform with explicit contractual prohibitions on data use for training. The privilege analysis cares about the nature of the disclosure and the controls governing it, not just the label on the technology.

What Rule 1.6(c) Actually Requires

ABA Model Rule 1.6(c) requires that lawyers "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." Comment 18 to Rule 1.6, added when the ABA amended the rule to address electronic communications, makes explicit that this applies to the use of technology: when transmitting client information, lawyers must make reasonable efforts to prevent unintended disclosure, taking into account "the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely affect the lawyer's ability to represent clients."

Comment 18 also references the competence standard of Rule 1.1, specifically including competence in "the benefits and risks associated with relevant technology" as part of what the duty of competence requires.

The standard is "reasonable efforts" — not perfection, not zero risk, not the highest available level of protection regardless of cost. That reasonableness framing matters for how firms think about AI review tools. The obligation isn't to refuse to use any technology that presents any privacy risk. The obligation is to make reasonable, proportionate efforts to protect client information given the specific context.

What "reasonable efforts" looks like in practice

State bar ethics opinions on technology use have applied the Rule 1.6 framework to cloud computing, e-discovery platforms, and — in more recent opinions — AI-assisted legal tools. The consistent thread across those opinions is that "reasonable efforts" involves:

  • Evaluating the vendor's data security practices before use — not just reading the marketing materials, but reviewing security documentation, SOC 2 reporting, and contractual provisions that specifically address data isolation, access controls, and training data use
  • Ensuring the service agreement includes confidentiality obligations that are at least equivalent to what the firm owes the client
  • Considering whether the sensitivity of the specific documents warrants additional precautions beyond the baseline
  • Maintaining supervision over the output — the Rule 1.6 analysis doesn't stop at upload; the firm is responsible for the accuracy and reliability of what the technology produces

We want to be precise about something here: the reasonableness analysis is genuinely contextual. A firm using an AI tool to review routine commercial contracts for standard clauses is operating in different territory than a firm uploading privileged litigation strategy documents or sensitive financial information. The same tool, used in those two contexts, may require different pre-use diligence.

The Supervision Obligation Under Rule 5.3

Model Rule 5.3 requires that lawyers with supervisory authority over non-lawyers make reasonable efforts to ensure that the non-lawyer's conduct complies with the Rules. A 2024 ABA Formal Opinion addressed the application of Rule 5.3 to AI tools used in legal practice, concluding that lawyers have a supervisory obligation with respect to AI output — they cannot simply accept AI-generated content as accurate without appropriate verification.

For document review, the Rule 5.3 question is how to structure attorney oversight of AI-flagged provisions. The appropriate supervision model depends on what the AI is doing. When a tool is identifying and extracting specific clause types — flagging change-of-control provisions, indemnity caps, auto-renewal dates — the supervision question is: are the flags accurate, complete, and presented in a way that allows the reviewing attorney to make an independent judgment?

This is different from asking whether the attorney re-reads every document the AI has reviewed. Supervision doesn't require redundancy — it requires a genuine quality check that would catch material errors. In practice, that typically means reviewing a sample of flagged and unflagged documents to validate the system's accuracy, having a clear understanding of what kinds of clauses the system is designed to catch (and not catch), and maintaining the professional judgment layer that interprets what a flagged provision means for the specific transaction.

Confidentiality Provisions in Vendor Agreements: What to Look For

The contractual review that Rule 1.6's reasonableness standard implies is more specific than many firms currently apply. The questions that matter most:

  • Training data prohibition. Does the vendor explicitly agree not to use client documents uploaded to the platform to train or fine-tune AI models? This provision is now standard in purpose-built legal AI tools; its absence in a vendor agreement is a meaningful signal.
  • Data isolation. Are client documents processed in isolated environments, or are they commingled with other clients' data in ways that create cross-contamination risk? Multi-tenant architecture is common and generally acceptable; the question is whether adequate logical separation exists.
  • Subprocessor disclosure. When the vendor uses subprocessors (cloud infrastructure, AI model providers, etc.), are those subprocessors identified and are their data handling obligations contractually equivalent to the vendor's?
  • Retention and deletion. What does the vendor do with uploaded documents after the processing task is complete? Clear contractual provisions on document deletion and data retention limits are reasonable to require.
  • Breach notification. If there is a security incident involving client data, what is the vendor's notification obligation and timeline? The typical standard is 72-hour notification to the client firm, which can then assess its own reporting obligations.

None of these provisions guarantee zero risk. What they do is create a contractual framework that satisfies the "reasonable efforts" standard under Rule 1.6 for a firm that has reviewed them and found them adequate. The due diligence itself — reading the agreement, asking the questions, getting answers — is what makes the use of an AI tool professionally defensible.

Practical Framework for Pre-Deployment Review

Before a firm deploys an AI document review tool for client matters, we recommend walking through the following:

  1. Classify the document sensitivity level. The Rule 1.6 reasonableness analysis requires proportionality. Documents containing trade secrets, M&A strategy, or highly sensitive personal information warrant more diligence than routine commercial contract review.
  2. Review the vendor's security documentation. Request and review current SOC 2 Type II reporting or equivalent. If the vendor can't provide it, that's a data point about their security posture.
  3. Audit the DPA/MSA for the key provisions. The five questions above are the baseline. Missing provisions should be raised with the vendor before use, not after.
  4. Document your diligence. The Rule 1.6 standard is "reasonable efforts." Having a written record of the diligence you performed protects the firm if the use of AI tools is ever questioned in an ethics context.
  5. Build the supervision structure before first use. Decide in advance how the firm will review AI output — what sample rate, what quality check process, what escalation path when flags seem inconsistent. Don't improvise this on a live matter.

The firms we've worked with that have this framework in place before deployment are the ones that are actually using AI review tools productively. The firms that treat ethics compliance as an afterthought are the ones who either avoid the tools entirely (leaving efficiency on the table) or use them without adequate oversight (creating real professional risk). The professional framework is what makes confident use possible.