In Brief:
Generative AI tools such as ChatGPT, Claude, Gemini and Copilot are increasingly being used to help with legal problems, including by people already involved in or anticipating disputes. But if you put confidential information into an AI platform, can you still claim legal privilege over that information, your prompts or the resulting outputs if they later become relevant to court proceedings?
New Zealand courts have not yet considered the issue, while emerging decisions from the US and UK point in different directions. This article looks at how New Zealand's existing rules of legal privilege might apply to generative AI, the potential implications for discovery and preservation of AI conversations, and some practical steps businesses and individuals can take to reduce the risk while the law catches up.
Generative artificial intelligence tools like ChatGPT, Claude, Gemini and Copilot are increasingly used by clients seeking to better understand and participate in matters being handled by their lawyers, and by businesses and individuals hoping to manage legal matters themselves. We now often see clients use AI as part of working with us and / or who have used AI to get some way with a legal matter themselves before we are engaged.
Using these tools for legal work can add real value. But used carelessly, they can also create risk.
One of those risks is if that use is protected by, or conversely, risks losing, legal privilege. That is, if confidential information about a legal matter is entered into an AI platform, could that information, the prompts used to generate it, or the AI's responses, later have to be disclosed in court proceedings?
As of the date of this article this question has yet to be answered by the New Zealand courts. Overseas, however, courts in jurisdictions such as the United States and the United Kingdom have begun considering it, with developing first-instance decisions that provide some guidance but no settled answer. This article examines those emerging authorities through the lens of New Zealand law and offers some practical suggestions for reducing the risk while the law continues to evolve.
At its most basic level, legal privilege is a right to refuse to disclose something.
This of course is to underexplain matters. As with most legal concepts, privilege has its complexities, exceptions and nuances. But to keep it simple, for the purpose of this article we will simply look at how certain privileges are now codified in the Evidence Act 2006.
The principal categories of privilege relevant to most civil legal matters include:
A common requirement for something to qualify for s54 and s57 privilege protections is confidentiality. Relevant communications must generally have been intended to be confidential. Further protections under s57 also exist for confidential documents prepared, or caused to be prepared, by a person in connection with an attempt to mediate the dispute or to negotiate a settlement of the dispute.
Litigation privilege under s56 does not have a confidentiality requirement, but instead requires that the communication or information was created for the dominant purpose of preparing for, or conducting, a proceeding or apprehended proceeding.
But regardless of whether confidentiality is an inherent element of the privilege in question, privilege can be waived (amongst other ways) if the person holding it, or anyone with the authority of that person, voluntarily produces or discloses, or consents to the production or disclosure of, any significant part of the privileged communication, information, opinion, or document in circumstances that are inconsistent with a claim of confidentiality.
Maintaining confidentiality is therefore key to establishing most, and maintaining all, of these different types of privilege.
There are several arguments about why gen-AI use may cause problems for privilege.
The most common of these tends to be framed around a view that unlike, say, sending an email to your lawyer, using a generative AI system to obtain legal advice is somehow inherently different.
First, to get the obvious out of the way, to attract solicitor client privilege under s54 of the Evidence Act you need to request legal services from a “legal advisor”, and gen-AI tools are simply not a “legal advisor” as that term is defined under the Evidence Act. As such, communications with gen-AI about legal advice will be very unlikely to attract solicitor client privilege under s54 of the Act.
Second, several judges in the USA and UK (such as UK and R (on the application of Munir) v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) and United States v Heppner, No 25) have now determined that use of gen-AI in situations that involve communicating with a technology platform operated by a third party can be inconsistent with the confidentiality required to obtain and maintain other kinds of privilege.
Under this view:
Reasons judges have taken this position have included factors like if the platform’s terms and disclosure arrangements permit third party access to material submitted to or generated by the AI model in question, including things like if the model trains on inputted data, and the extent that terms allow prompts and outputs to be accessed or disclosed by the platform.
This shows that the issue with Gen-AI use and privilege isn’t something inherent to AI use itself. Rather, it is simply the consequence of applying age-old rules about what is required to claim and maintain confidentiality to the AI age. Under this view, using some AI platforms is no different to posting your confidential documents in a shop window. In such circumstances there can be no reasonable expectation of confidentiality. But other AI platforms restrict access to and use of your data, and in such cases, there seems no good reason why confidentiality (and therefore privilege) shouldn’t be maintained.
But there are now also several decisions in the US (such as Warner v Gilbarco, Inc, No 2, Morgan v V2X, Inc, No 1, Assini v Hayward and Tate Group Automotive, LLC v Legacy Automotive Capital, LLC) that have taken what is arguably a more nuanced approach to AI use and privilege, recognising that even where a gen-AI platform may allow the theoretical right for the platform or third parties to access or use data, practically it may be unrealistic to expect that to occur in a manner that creates any real risk to confidentiality. As such, they suggest there may be little to distinguish communications with most AI platforms from communications through or with other digital platforms or tools (like using Google products such as GMail) where no question of waiver of confidentiality would ever be thought to arise, even with platforms that might in theory train on or disclose data or have administrators with the ability to access this.
This approach would not necessarily help someone trying to establish privilege for legal advice from an AI without a lawyer in the loop, but arguably, it may suffice to establish the confidentiality necessary for other privileges mentioned above, like litigation and negotiation privilege, or the kind of privilege recognised in Simunovich.
Because no New Zealand court has yet considered this issue directly, any answer is necessarily speculative.
Nevertheless, there are reasons to think that New Zealand courts will consider many AI-assisted legal tasks to fall within the protections contained in the Evidence Act.
That will be most clearly the case where work is directly captured by litigation or negotiation privilege and when the platform being used operates under terms and in an environment that limits the legal and practical right of the platform to use, access and/or disclose inputs and output.
But even then, until New Zealand Courts tackle the question of what exactly constitutes waiver of confidentiality in this context, a precautionary approach would be to assume that anything that goes into or comes out of an AI platform may be disclosable. This means that it may be unwise to communicate anything to a gen-AI platform (or to ask the platform to generate anything) that you wouldn’t want to come out in open court, let alone to tell Claude or Grok your deepest darkest legal secrets. Conversely, your human lawyer is (for the most part) legally obliged to keep such matters confidential and has the backing of the Evidence Act to ensure they can do so.
In passing, it is worth noting that even if privilege ultimately survives the use of AI, prompts and generated material may still have to be identified in proceedings under rules of discovery and disclosure, which in some situations require relevant privileged material to be listed in affidavits of documents (even if they do not have to be handed over for inspection).
As part of this, it is also important to note that discovery obligations require parties to preserve relevant documents once litigation is reasonably contemplated. Given the broad definition of "document", it is probable that relevant AI conversations will be caught by this requirement.
Finally, court rules generally require that documents disclosed to a party as part of discovery should only be used for the purpose of the proceedings in which they are discovered and copies should not be made available to any other person. Noting US courts have observed gen-AI platforms are tools, not people, there is still a degree of caution that needs to be exercised when uploading discovered documents to AI platforms given these restrictions, and again, although some cases overseas have touched on this issue, it is yet another AI use case that has yet to be tested in New Zealand.
Until the law develops further, caution is warranted.
If you are involved in an existing dispute, or one is reasonably foreseeable:
In short, AI is an increasingly valuable tool for lawyers, clients and lay litigants alike. However, the law governing privilege developed long before generative AI existed, and its application in this area remains uncertain. Uncertainty creates risk.
If your business or organisation is using AI for legal matters or matters that may one day be subject to legal dispute, obtaining advice before sharing confidential information may avoid difficult privilege issues later.
The litigation team at GCA Lawyers regularly advises on legal privilege, discovery obligations and complex dispute strategy. If you are uncertain whether your proposed use of AI could affect privilege, we would be pleased to discuss your circumstances before potentially sensitive information is disclosed.


