Client AI Use and the Waiver of Privilege: What Canadian Litigators Need to Know
By Laith Sarhan
Data Protection & Cybersecurity
Your client is talking to ChatGPT about your advice.
Not hypothetically. Clients facing litigation are pasting your opinions into consumer AI tools to "double-check" them, asking chatbots to anticipate the other side's arguments, and inviting AI notetakers onto your calls. Somewhere in your file right now, a privileged communication may already be sitting on a third party's server.
In February 2026, a U.S. federal court held that a criminal defendant who used Anthropic's Claude to analyze his case had no privilege over the resulting documents—and, worse, that he had waived privilege over the underlying advice from his own lawyers by feeding it to the chatbot. No Canadian court has ruled on the question yet. When one does, it will apply a doctrinal framework that differs from the American one in ways that matter.
This post maps the risk for Canadian litigators: how our privilege law would likely analyze a client's AI use, what is happening in the U.S., and the specific steps to take now—starting with your retainer language.
The Two Privileges and the One Rule That Matters
Canadian law protects litigation-related communications through two distinct privileges, and the distinction does real work in the AI analysis.
Solicitor-client privilege protects confidential communications between lawyer and client for the purpose of seeking or giving legal advice. It is a substantive rule of law, not a mere rule of evidence (Descôteaux v. Mierzwinski, [1982] 1 S.C.R. 860), and it "must be as close to absolute as possible" (R. v. McClure, 2001 SCC 14 at para. 35). The Supreme Court has recognized only narrowly guarded exceptions—public safety and the right to make full answer and defence (Ontario (Public Safety and Security) v. Criminal Lawyers' Association, 2010 SCC 23). Confidentiality is its sine qua non.
Litigation privilege is a different animal. It exists to create a "zone of privacy" in relation to pending or apprehended litigation (Blank v. Canada (Minister of Justice), 2006 SCC 39). Three features of Blank matter here:
- Litigation privilege is not restricted to solicitor-client communications. It contemplates communications between a solicitor and third parties—and, for unrepresented litigants, between the litigant and third parties.
- It arises and operates even in the absence of a solicitor-client relationship, and applies to all litigants, represented or not.
- Confidentiality is not an essential component of litigation privilege in the way it is for solicitor-client privilege (para. 32).
Lizotte v. Aviva Insurance Company of Canada, 2016 SCC 52 confirmed that litigation privilege is a class privilege: once the dominant-purpose test is met, non-disclosure is presumed, subject to clearly defined exceptions rather than case-by-case balancing. It can be asserted against third parties, not just adversaries.
And the one rule that frames everything below: privilege belongs to the client. Only the client can waive it, expressly or by conduct. Which means your client can compromise it unilaterally—without telling you, from their phone, at 11 p.m.
How Waiver Actually Works in Canada
The classic waiver fact pattern is voluntary disclosure of a privileged communication to a third party. But Canadian courts have consistently rejected bright-line, categorical waiver rules. The analysis is functional: What was the client's intent? What was the expectation of confidentiality? What does fairness require? Disclosure to or through a third party does not automatically equal waiver.
Three doctrines soften the edges:
Limited waiver. Disclosure for a specific, bounded purpose does not necessarily waive privilege as against the world. The leading case is Philip Services Corp. (Receiver of) v. Ontario Securities Commission (2005), 77 O.R. (3d) 209 (Div. Ct.), which recognized limited waiver where privileged documents were provided to an auditor for the audit function. Privilege is not lost simply because of a required, purpose-limited disclosure.
Common interest privilege. Privileged communications shared with parties who share a common interest in litigation retain their protection—the doctrine protects against waiver, rather than creating a freestanding privilege (Sable Offshore Energy Inc. v. Ameron International Corp., 2015 NSCA 8).
Necessary intermediaries. Canadian law has long accommodated third parties who facilitate the advice relationship—translators, technical experts, accountants—without defeating privilege, on the footing that they are functionally part of the communication.
That last doctrine frames the question Canadian courts will eventually answer: is a client's AI tool functionally a translator—a private instrument the client uses to think through the litigation—or is it a stranger on the subway? The answer will not turn on the technology. It will turn on the terms of service, the client's purpose, and who directed the use.
Would Heppner Come Out the Same Way Here?
In United States v. Heppner, No. 25-cr-00503-JSR, 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), Judge Rakoff held that 31 documents a defendant generated using the consumer version of Claude were protected by neither attorney-client privilege nor the work product doctrine. Run the same facts through Canadian doctrine and you get a more textured picture:
Solicitor-client privilege: likely the same result, different reasoning. A chatbot is not a lawyer, and communications with it are not solicitor-client communications. A Canadian court would add the confidentiality analysis: where the platform's terms permit it to retain inputs, train on them, and disclose them to third parties including government authorities, the expectation of confidentiality is hard to sustain. But note the functional pivot—a client using an enterprise-grade tool with no-training, no-retention terms, in the privacy of their own home, to organize questions for counsel looks much less like "disclosure to a third party" and much more like private preparation. Canadian courts assess waiver by function and fairness, not by category.
Litigation privilege: genuinely divergent. The American work product doctrine, as applied in Heppner, asked whether the materials were prepared "by or at the behest of counsel" and reflected counsel's strategy. Canadian litigation privilege asks a different question: was the document created for the dominant purpose of litigation, pending or reasonably apprehended? It does not require counsel's direction, it expressly covers unrepresented litigants preparing their case, and it extends to third-party communications. A client's own AI-assisted litigation preparation could fit within Blank and Lizotte in a way it could not fit within Judge Rakoff's work product analysis.
The waiver sting: maps directly onto Canadian law. The most dangerous part of Heppner was footnote 3. Because the defendant had input information he learned from his attorneys into Claude, the court held he had waived privilege over those underlying attorney-client communications—"just as if he had shared it with any other third party." That is orthodox waiver analysis, and a Canadian court could reach the same conclusion: pasting your lawyer's advice into a consumer AI tool is the client's own disclosure of a privileged communication outside the relationship, inconsistent with the confidentiality on which the privilege depends.
Three fact patterns where Canadian doctrine probably will not save the client:
- Consumer platform, permissive terms. The provider trains on inputs, retains logs, and reserves disclosure rights. Confidentiality expectation fails under any functional analysis.
- Privileged advice pasted in. The AI output is secondary; the waiver of the underlying advice is the real loss.
- No litigation nexus. Casual curiosity about "my legal situation" months before any apprehended claim fails the dominant-purpose test and the "for the purpose of legal advice" test alike.
What's Happening in the U.S.
Two federal decisions issued within a week of each other in February 2026 frame the American debate.
Heppner (S.D.N.Y.): no privilege, no work product. The defendant, under investigation and later indicted for securities and wire fraud, used consumer Claude on his own initiative to generate defence-strategy documents, some incorporating what he had learned from counsel. Judge Rakoff's opinion identified three failures: Claude is not an attorney—privilege presupposes a "trusting human relationship" with a licensed professional; the communications were not confidential given Anthropic's terms permitting training use and third-party disclosure; and the purpose was not to obtain legal advice from Claude. Later sharing the outputs with counsel did not help—non-privileged materials are not "alchemically changed" into privileged ones by transfer to a lawyer. And per footnote 3, the waiver reached the underlying advice.
Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 10, 2026), 2026 WL 373043: the opposite result. A self-represented employment plaintiff used ChatGPT to help prepare her filings. The court refused to compel production, holding the materials protected as work product: Rule 26(b)(3) protects materials prepared by "another party," not only those prepared at counsel's direction, and work-product waiver requires disclosure to an adversary or in a manner likely to get the material into an adversary's hands. Generative AI programs, the court wrote, are "tools, not persons"—treating them as waiver-triggering third parties would nullify work product protection in modern drafting environments.
The split is less confusing than it looks. The distinguishing variables are consistent: who directed the AI use (counsel or the client alone) and what the platform does with the data (consumer terms or confidential enterprise terms).
Two more U.S. developments belong on your radar:
- New York Times v. OpenAI (S.D.N.Y.): In May 2025, Magistrate Judge Wang ordered OpenAI to preserve all consumer ChatGPT output logs—including chats users had deleted—overriding its standard deletion policies. In November 2025, the court ordered production of 20 million de-identified chat logs to the plaintiffs; Judge Stein upheld the discovery orders on January 5, 2026. The lesson for privilege analysis is structural: on a consumer platform, the data persists, and courts can reach it.
- Ethics guidance: ABA Formal Opinion 512 (July 2024) directs lawyers to understand how AI tools handle data and to obtain clients' informed consent before inputting client confidences—boilerplate engagement-letter consent is not adequate. State bars (Florida Opinion 24-1; the State Bar of California's practical guidance) are aligned.
It's Not Just Chatbots
Fixating on a client typing into a chatbot misses half the attack surface.
AI notetakers are the quieter problem. Otter, Fireflies, Zoom AI Companion, and their kin join calls as silent third-party participants, stream audio to external servers, and produce transcripts that are permanent, unreviewed, and producible records. If a client's notetaker bot joins your next privileged call, you have a third party in the room and a transcript sitting in a vendor's cloud. No court has yet pierced privilege over an AI notetaker, but discovery demands for these transcripts are coming.
Platform terms are the new waiver battleground. The entire confidentiality analysis now runs through contract: Does the provider train on inputs? Retain logs after deletion? Reserve disclosure rights to authorities? Is this a consumer tier or an enterprise deployment with zero-retention and no-training commitments? Counsel assessing a client's past AI use—or selecting the firm's own tools—needs answers to those questions in writing.
Canadian courts are already engaged with AI. The Federal Court's December 2023 notice requires transparency about AI use in court proceedings; Zhang v. Chen, 2024 BCSC 285 made costs consequences real for AI-hallucinated citations. The next step is predictable: opposing counsel asking in discovery whether your client used a chatbot to discuss or analyze the lawsuit—the same path social media took into standard discovery practice.
Regulators have flagged the risk. The Law Society of B.C.'s Guidance on Professional Responsibility and Generative AI (October 2023) advises omitting client-identifying information from prompts, obtaining fully informed client consent before using such tools with client information, and expressly warns of "potential arguments regarding waiver," noting the law of privilege for generative AI tools "is in an early stage." The CBA, the Law Society of Ontario, and the Law Society of Alberta have issued guidance to similar effect. The Office of the Privacy Commissioner of Canada has had ChatGPT under formal investigation since 2023.
The Litigator's Protocol
Until a Canadian court rules, the working assumption for client counselling should be the conservative one: self-initiated AI chats on consumer tools are not private, not privileged, and potentially producible. Five concrete steps:
1. Fix your retainer language now. Address the client's use of AI up-front. Language along these lines:
Client-Side Safeguards and Privilege. To safeguard solicitor-client privilege and prevent accidental waiver of confidentiality, you agree not to input our formal advice, drafts, or sensitive matter details into public consumer AI tools. You also agree that the deployment of any automated AI-driven transcription, notetaking, or conversational recording bots on our communications requires our explicit, advance consent, as the summaries and recordings they generate are permanent, discoverable records that can compromise the privilege protecting our communications.
2. Give the client instruction at intake, in plain language. Do not paste our advice, drafts, or matter details into consumer AI tools. Do not let AI notetakers or recording bots join our calls. If you want to organize your thoughts, do it offline—or pick up the phone. Clients often turn to AI because they are confused or because the advice was not what they wanted to hear; making room for questions is a privilege-control measure.
3. Discipline the firm's own use. If AI touches the file, keep it counsel-directed, on enterprise-grade or zero-retention tooling, and document that direction contemporaneously. Heppner and Warner both turn on who controlled the use and what the platform did with the data. Build your record before you need it.
4. Build AI into discovery readiness. Expect AI-related correspondence and chatbot outputs to be listed in schedules to affidavits or lists of documents; add "AI use" to your examination question plans (platforms used, what was inputted, what was shared and with whom); extend litigation-hold instructions to chatbot accounts and notetaker transcripts; and decide in advance how AI-assisted materials will be described on your privilege log.
5. Triage past use without compounding it. If a client has already used a consumer tool on the matter, assess what was inputted, under what terms, and what litigation purpose existed. Do not compound the problem by summarizing the AI outputs into new privileged channels without analysis—and preserve the materials, because spoliation arguments follow quickly once AI use is on the record.
Canada vs. U.S.: Quick Reference
| Question | Canada | United States |
|---|---|---|
| Client's own AI chats protected? | Untested. Litigation privilege argument available under Blank/Lizotte if dominant purpose is litigation; solicitor-client privilege unlikely | Heppner: no (consumer tool, no counsel direction). Warner: yes, as work product (self-represented litigant) |
| Privileged advice pasted into AI | Real waiver risk under functional, fairness-based analysis; no bright-line rule | Heppner fn. 3: waiver of the underlying communications held |
| Counsel-directed use on enterprise tooling | Strongest position under both privileges; aligns with LSBC/CBA guidance | Most likely protected under the logic of both decisions |
| AI notetaker on a privileged call | Untested; confidentiality analysis would scrutinize vendor terms | Untested; bar commentary flags third-party waiver risk |
| Consumer platform logs reachable by courts | Untested, but platform data holdings are producible third-party records | NYT v. OpenAI: mass preservation and production orders over user logs |
Bottom Line
Privilege is not dead in the age of AI, but it has a new attack surface, and the client holds the knife. The confidentiality analysis that has always driven waiver now runs through terms of service most clients have never read. Canadian doctrine—with its functional waiver analysis and a litigation privilege that does not depend on counsel's direction—may ultimately prove more accommodating of client AI use than Heppner suggests. But "may" is not a litigation strategy.
Get the retainer language in place. Give the client the instruction. Control the tools. And assume that anything your client typed into a chatbot about the case is something you may one day see again—on the other side's production list.