Does ChatGPT Have Attorney-Client Privilege?

No. ChatGPT chats are not protected by attorney-client privilege. The privilege covers confidential communications between a client and a lawyer made to get legal advice. A chatbot is neither your lawyer nor your client, so the relationship that triggers privilege never forms. Worse, typing privileged facts into a third-party tool can waive privilege you already had. OpenAI is also under a court order to preserve user logs, so a deleted chat is not really deleted. This is general information, not legal advice. Checked June 2026.

TL;DR

ChatGPT data controls

  • Privilege does not attach. It protects lawyer-client communications, not a user talking to software. OpenAI is a vendor, not your counsel.
  • Pasting privileged facts risks waiver. Sharing a confidence with a third party can break the privilege you held over those facts.
  • Work-product is narrower than people think. Some prompts may qualify, but the protection is weaker and easier to lose than privilege.
  • Delete does not mean deleted. A federal court ordered OpenAI to preserve output logs, including chats users tried to delete (CourtListener, 2026).
  • Sam Altman agrees there is no AI privilege. He said users have no legal confidentiality and OpenAI can be forced to produce chats (TechCrunch, 2025).
  • The fix is a relationship and a posture, not a toggle. Use a tool with the right contract, and even then mind how you use it.
Quick check

Why does attorney-client privilege not attach to a ChatGPT chat?

The short answer, and why it matters

A lawyer asked us a sharp version of this question. If I run a fact pattern past ChatGPT instead of a junior associate, is that conversation privileged? It is not. The model is not a member of the legal team. It is a service run by a company that can be subpoenaed.

Privilege is a relationship and a duty. It is not a privacy setting you flip on. That framing decides almost every answer below.

This post covers the privilege and discovery angle. For the data-and-training side (which plans train on your inputs), see is ChatGPT confidential for legal work. For the underlying ethics rules, see our ABA Formal Opinion 512 guide.

Why privilege does not attach

Attorney-client privilege has a tight definition. It protects a communication that is confidential, between a client and an attorney, made for the purpose of seeking or giving legal advice. Strip out any element and the privilege fails.

ChatGPT fails the first two elements at once. There is no attorney on the other end. There is no client relationship with a software vendor. You are talking to a product, the same way you might talk to a search engine.

There is a second problem on top of the first. Privilege also requires confidentiality. When you hand information to a third party outside the privileged circle, you generally break the confidentiality the privilege depends on. Typing into a consumer chatbot is exactly that kind of disclosure.

The waiver problem

Here is the part that should worry litigators most. You can lose privilege you already had.

Say a client tells you something in confidence. That communication is privileged. Now you paste it into ChatGPT to draft a memo. You have shared a privileged confidence with a third party that is not covered by the privilege. Depending on the facts and the jurisdiction, that can waive the protection.

Waiver is rarely the lawyer's intent. It is a side effect of convenience. The faster the tool, the easier it is to forget that the screen is a pipe to someone else's servers.

This is why the safe move is to keep client-identifying facts out of any tool whose terms you have not confirmed. Anonymize first, or use a tool built for legal data. We map where those inputs travel in where your legal AI data actually goes.

What about work-product?

The work-product doctrine is the natural fallback question. It protects materials a lawyer prepares in anticipation of litigation. So is your ChatGPT research session work-product?

Maybe, in part. If you are using the tool to develop your legal theory or trial strategy, the resulting analysis may carry work-product protection as your mental impressions. But the protection is narrower and weaker than privilege. Opposing counsel can sometimes overcome it by showing substantial need.

Work-product also does not cure the disclosure problem. Sharing your strategy with a third party can still waive the protection, and the same retention issues apply. Treat it as a thin backstop, not a shield. If you would not email the prompt to opposing counsel, do not assume a doctrine will hide it.

Delete is not deletion: the discovery angle

This is the angle most "is ChatGPT private" posts miss. Even if privilege were not the issue, your chats may be sitting in storage that a court can reach.

In the copyright case brought by The New York Times and other news organizations against OpenAI, a federal magistrate judge entered a preservation order. The May 13, 2025 order directed OpenAI to "preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court" (CourtListener, 2026). A later order directed OpenAI to produce 20 million deidentified consumer logs.

Read that operative phrase again: data that would otherwise be deleted. The order captures chats users tried to delete and chats where history was turned off. The news plaintiffs have since asked the court to dig into millions of deleted logs (Ars Technica, 2026). As of June 2026 the dispute is still active, so confirm the current status before you rely on any specific detail.

OpenAI's own CEO made the point in plain language. On a July 2025 podcast, Sam Altman said there is no legal confidentiality when you talk to ChatGPT, and that in a lawsuit OpenAI could "be legally required to produce those conversations" (TechCrunch, 2025). He has floated a future concept of "AI privilege," but it does not exist in law today. A legal analysis from Artificial Lawyer reached the same conclusion: standard ChatGPT carries no legal privilege (Artificial Lawyer, 2025).

What this means in practice

Put the pieces together and the practical rule is simple. A consumer chatbot is the wrong place for facts you would fight to keep out of discovery.

The risk is not theoretical exotica. It is the everyday habit of pasting a real clause, a real party name, or a real fact pattern to save ten minutes. That habit creates a record outside your control and may waive a protection your client is counting on.

None of this means lawyers should avoid AI. It means matching the tool to the duty. A general consumer product and a tool with a signed data agreement are different animals, even when the underlying model is similar. The companion piece ChatGPT for lawyers covers which tasks are safe and which are not.

How to keep privilege intact while using AI

ABA Formal Opinion 512, issued in July 2024, applies the existing confidentiality duty under Model Rule 1.6 to generative AI. It asks lawyers to understand a tool's data handling, guard against exposure to third parties, and get informed client consent before entering confidences where exposure is possible. Use this checklist as a starting point, and follow your own state bar rules.

  • Do not paste client-identifying facts into consumer tools. Names, parties, contract terms, and specific facts stay out unless the terms are confirmed.
  • Anonymize before you prompt. Strip identifiers and deal-specific details if you must use a general tool.
  • Use a tool with a written data agreement. A DPA and a no-train clause are contract terms, not a settings toggle. Confirm the current terms yourself.
  • Confirm retention and deletion. Ask how long data is kept and whether deletion is real or just hidden from your view.
  • Get informed client consent where it counts. Boilerplate in an engagement letter is not enough under ABA 512 for sensitive matters.
  • Match the tool to the sensitivity. Privileged or high-stakes material may need a tool built for legal data, or no tool at all.
  • Keep a clean record. Note what you put in, which tool, and under what terms, so you can answer if anyone asks later.

The verdict

ChatGPT does not have attorney-client privilege, and it will not get one from a settings change. Privilege flows from a lawyer-client relationship and a duty of confidentiality, neither of which exists between a user and a software vendor. Pasting privileged facts can waive protection and creates a discoverable record, made worse by a standing order that tells OpenAI to keep logs you tried to delete.

The safer path is a tool with the right contractual posture, and even then privilege depends on how you use it. Vaquill AI is a legal AI suite for in-house counsel built on that posture. It takes a no-train stance on your matter data and gives source-linked answers over real US opinions and statutes. The data terms are written for client work, not a general consumer audience. The tool is not magic. The discipline of anonymizing, confirming terms, and getting consent still belongs to you.

FAQ

Does ChatGPT have attorney-client privilege? No. Privilege protects confidential communications between a client and a lawyer for legal advice. A chatbot is not your lawyer, so the relationship that creates privilege never forms.

Can pasting privileged information into ChatGPT waive privilege? Yes, it can. Sharing a privileged confidence with a third party outside the privileged circle can break the confidentiality the privilege depends on, which may waive the protection.

Is my ChatGPT research protected as work-product? Sometimes, in part. Analysis reflecting your legal strategy may carry work-product protection, but it is weaker than privilege, can be overcome by substantial need, and can still be waived by disclosure.

If I delete a ChatGPT chat, is it gone? Not necessarily. A federal court ordered OpenAI to preserve output log data that would otherwise be deleted, including deleted chats. As of June 2026 the litigation is ongoing, so check the current status.

What is "AI privilege"? It is a concept Sam Altman has proposed, suggesting AI conversations should get confidentiality like a talk with a lawyer or doctor. It does not exist in US law today, and current chats are not privileged.

Can opposing counsel get my ChatGPT logs in discovery? If the logs exist and are relevant, they can be reachable through subpoena or a court order. The NYT v. OpenAI orders show that retained chat logs, including deleted ones, can become discovery targets.

Does using ChatGPT Enterprise create privilege? No. Better data terms reduce training and retention risk, but they do not create an attorney-client relationship. A business plan helps with confidentiality and contract posture, not with the legal definition of privilege.

How do I use AI without risking privilege? Keep client-identifying facts out of consumer tools and anonymize when you can. Use a tool with a written data agreement, and get informed consent where the matter is sensitive, per ABA Formal Opinion 512.

Sources

Last updated: June 2026.

Legal AI that reads your documents and knows the law.
Ask a legal question, review a contract, or search thousands of your files. Every answer shows where it came from. 7-day free trial, no card.
12 min read

New legal AI guides, weekly.

Arshita Anand

Arshita Anand

Co-Founder & CEO · Attorney

Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.