Legal professional privilege protects confidential communications between a lawyer and client made for the dominant purpose of legal advice or litigation. It depends on confidentiality being maintained — which is why entering privileged material into a generative AI tool is a question about privilege, not just about data security. The NSW Supreme Court has now addressed this directly: Practice Note SC Gen 23, in effect since 3 February 2025, warns that data entered into a generative AI program may be used to train the underlying model, with consequences for privilege among other things.
What does SC Gen 23 actually say?
The Practice Note was developed after review of comparable guidance in other jurisdictions and consultation with the NSW Bar Association and the Law Society of NSW. Several provisions matter here.
On confidentiality and privilege, it cautions practitioners that information entered into a generative AI program may be used to train that program's large language model, potentially making confidential information available to others — with consequences for legal professional privilege.
On restricted material, certain categories of documents and information must not be entered into a generative AI program unless the practitioner is satisfied the information will remain within the controlled environment of the technology provider: not made public, used only in connection with the proceeding, and not used to train the AI or any large language model. Material subject to the implied undertaking and documents produced on subpoena are given as examples.
On evidence, generative AI must not be used to generate the content of affidavits, witness statements, character references, or other material intended to reflect a deponent's or witness's evidence or opinion. Using it to draft any part of an expert report requires prior leave of the court.
On verification, practitioners must verify that every citation, authority, case and legislative reference exists and is accurate — and that verification cannot itself be done with a generative AI program.
The Federal Court has its own practice note on generative AI (GPN-AI), and other jurisdictions have issued their own guidance. If you practise across states, the applicable rules are not uniform.
Why does privilege turn on where the data goes?
Privilege attaches to confidential communications. Its continued existence depends on that confidentiality being maintained — disclosure to a third party can waive it, and once waived it is generally not recoverable.
The question with a public AI tool is therefore not "is this vendor trustworthy" but "what happens to the material after it leaves the firm". Several things can be true at once and each is a distinct risk: the content may be retained; it may be used to train a model; it may be accessible to the provider's staff for abuse monitoring or quality review; it may be stored in a jurisdiction whose authorities can compel access.
The honest position is that whether a particular disclosure waives privilege in a particular case is a legal question with a fact-specific answer — one for your firm's own advice, not a blog post. What is clear is the direction of the Court's concern: SC Gen 23 puts the onus on the practitioner to be satisfied the material stays in a controlled environment before it goes in. Satisfaction requires knowing where it goes, and a consumer AI tool's terms of service are not usually enough to establish it.
What does the Privacy Act add?
A second, independent layer of obligation that applies whether or not privilege is in play.
The OAIC's guidance on privacy and the use of commercially available AI products, updated in October 2024, makes clear that privacy obligations attach to personal information entered into an AI system as well as to output that contains personal information. Pasting a client's affidavit into a chatbot is a use of their personal information, and the APPs apply to it.
Where the AI provider is offshore, APP 8 and s 16C of the Privacy Act matter: an entity that discloses personal information to an overseas recipient must take reasonable steps to ensure the recipient does not breach the APPs, and is accountable for acts of that recipient that would breach them. Accountability does not travel with the data. It stays with your firm.
Matter files also routinely contain sensitive information — health, criminal record, sexual orientation, religious beliefs — which attracts higher protection again.
Is the risk theoretical?
Not especially. The OAIC recorded 1,205 data breach notifications in 2025, an all-time high, with 716 attributable to malicious or criminal activity. Legal, accounting and management services accounted for 81 notifications, placing the sector among the top five by volume.
Those figures are about breaches generally rather than AI specifically, and it would be dishonest to present them as evidence of AI-caused incidents. What they establish is narrower and still relevant: professional services firms are actively targeted, and every additional system holding privileged material is another place it can be taken from. The relevant question when adding an AI tool is not only "will this vendor misuse my data" but "how many more copies of privileged material now exist, and where".
What are the practical options?
Four, in rough order of exposure.
Consumer AI tools on free or standard consumer terms. The highest exposure. Content may be retained and used for training by default. For privileged material, this is the arrangement SC Gen 23 is most obviously warning about.
Enterprise AI with contractual protections. Enterprise agreements from major providers typically commit to not training on customer data and offer data-residency and retention controls. This is a genuine improvement and it is where most firms reasonably land. It rests on contract and on the provider's continued compliance, and material still leaves the firm's network.
Private cloud deployment. Models running in your own cloud tenancy. Stronger isolation; still a data centre you do not physically control, and still a cross-border question unless the region is Australian.
On-premises inference. Models running on hardware inside the firm's own network. The material never leaves. The practitioner's satisfaction that information stays in a controlled environment is verifiable by inspection rather than by reading terms of service — the environment is a machine in your comms cabinet. This is the architecture behind LegalBox, and its advantage here is specifically evidentiary: you can demonstrate the boundary rather than assert it.
The trade-offs are real and worth stating plainly. On-premises means capital cost, hardware you have to house and maintain, and models that are typically smaller than the largest frontier systems. For work where privilege is the binding constraint, firms increasingly judge that trade acceptable; for general drafting where no confidential material is involved, it may be unnecessary.
What should a firm do now?
Start with a policy, not a tool. Practitioners are entering material into AI tools whether or not the firm has decided they may, and an unwritten policy is being written by whoever is busiest.
Then classify. Not all firm work is privileged and not all of it is sensitive. Research on a general point of law is materially different from a client's brief. A workable policy distinguishes them explicitly rather than banning everything and being ignored.
Then match the tool to the classification: public tools for genuinely non-confidential work, and something with a verifiable boundary for anything privileged.
Then verify everything regardless. SC Gen 23 requires practitioners to confirm every citation and authority exists and is accurate, and expressly says this cannot be done with a generative AI program. Fabricated citations have produced real consequences for practitioners in several jurisdictions.
And keep a record of which tool was used for what. If privilege is ever contested, the firm's ability to describe its handling of the material is part of the answer.
Want to see what on-premises actually looks like?
If your firm handles privileged material and you want AI that never sends it anywhere, it is worth seeing the architecture. Book a discovery call and we will walk through how LegalBox runs models inside your own network, on hardware you own, with zero network egress your IT team can verify themselves.
Sources
- Supreme Court of New South Wales, Practice Note SC Gen 23 — Use of Generative Artificial Intelligence (in effect 3 February 2025), and the Court's generative AI page
- Federal Court of Australia, Practice Note GPN-AI: Use of Generative Artificial Intelligence
- Law Council of Australia, Artificial Intelligence and the Legal Profession
- OAIC, Guidance on privacy and the use of commercially available AI products (October 2024)
- OAIC, APP 8: Cross-border disclosure of personal information
- OAIC, Data breach notifications increase to all-time high in 2025
This article is general information about technology choices, not legal advice. Whether privilege is waived in any particular circumstance is a legal question that depends on the facts. Practice notes differ between courts and jurisdictions — check the ones that apply to your matters.

