Privilege within an AI Inbox: how litigators are actually handling it

A dozen quick questions on AI confidentiality practices, vendor terms of service, internal access controls, AI agents, and data retention — built for litigators and trial lawyers, answered anonymously, results shared in the next VEGA newsletter. This survey is fully anonymous — no identifying data is being collected. It is intended for litigators, trial lawyers, and in-house counsel. It asks nothing about your firm, your matters, or you personally — only about your AI practices and policies with a eye towards attorney-client privilege and the work-product doctrine.

Aggregate results and summarized comments will be provided in an upcoming VEGA compliance newsletter for the broader audience. This survey assumes you are familiar with the United States v. Heppner (S.D.N.Y. Feb. 2026), and some recent guidance on AI from the ABA and the NYC Bar Association. These and other resources are available upon request, of course.

Question 1 of 12*

Have you personally read the terms of service or data-processing terms for the AI tools your team uses (Harvey, Claude, ChatGPT, Copilot, etc.)?

ABA Formal Opinion 512 places the burden on the lawyer to understand how a GAI (Generative Artificial Intelligence) tool handles data — boilerplate engagement-letter consent isn't enough. Reading the terms is step one.

Clear selection
Question 2 of 12*

Do you allow any AI agent or assistant to read, sort, draft, or act on your email inbox or document folders?

Inbox- and folder-connected agents see privileged correspondence by design. If that agent's provider can train on or retain that content, every privileged email it touches is potentially exposed.

Clear selection
Question 3 of 12*

Before turning on a workplace AI assistant (e.g., Microsoft Copilot), has your firm reviewed what that tool can already see across your email, Teams, OneDrive, and SharePoint?

Workplace AI assistants don't get separately granted access — they inherit whatever permissions already exist in the environment. Years of accumulated "permissions debt" (stale access from closed matters, departed staff, old project channels) becomes instantly queryable in natural language the moment the assistant goes live, including documents users technically have access to but were never meant to surface, like partner compensation memos or internal leadership deliberations.

Clear selection
Question 4 of 12*

An AI agent wired into your firm's inbox, calendar, and file share doesn't wait to be asked — it can surface years of matter files, expert communications, and consultant work product the moment someone points it at a broad question. Do you believe that kind of agentic access into the inboxes of your testifying experts and retained consultants is a potential privilege problem?
Clear selection
Question 5 of 12*

Do you require zero data retention (ZDR) from your AI provider before using it on client or case matters?

Most providers' default terms retain prompts (often days to weeks) for ‘safety’ screening by humans before deletion, separate from any training opt-in. ZDR agreements remove even that window.

Clear selection
Question 6 of 12*

If you don't require ZDR, what retention period are you comfortable accepting from a provider for prompts and outputs?

Standard consumer and even some enterprise tiers retain data for screening purposes before deletion, unless ZDR or an enterprise data processing addendum overrides it.

Clear selection
Question 7 of 12*

Does the possibility that a provider could be subpoenaed for your prompts and AI-generated documents concern you?
Clear selection
Question 8 of 12*

Would your AI usage change if you were litigating a matter involving violent or sexual conduct allegations?

Most providers apply heightened safety screening to content flagged as violent or sexual, which can mean longer retention or additional human-reviews of that material, threatening privilege.

Clear selection
Question 9 of 12*
Is your firm or team's AI use formally documented as counsel-directed (e.g., a written policy naming approved tools and instructing staff and clients accordingly)?

Post-Heppner, courts have signaled that counsel-directed use under a Kovel-type arrangement, on a platform with enforceable confidentiality, is a strong path to preserving privilege. Self-directed client use of consumer AI is the weakest.

Clear selection
Question 10 of 12*
Do you obtain informed client consent before using AI tools on that client's confidential information?

ABA Formal Opinion 512 speaks to a client’s adequate, informed consent and the lawyer’s explanation of the material risks of the specific AI use to the client.

Clear selection
Question 11 of 12*
If opposing counsel's expert ran your client's produced discovery through a consumer AI tool that trains on inputs by default, would you move to stop it — or is that just how document review works now?
Clear selection
Question 12 of 12*
What is your single biggest unresolved concern about AI and privilege right now?

This one's open-ended on purpose — pick the closest fit and use the comment field to add detail.

Clear selection
Comments

(Optional)

Clear selection