📅 Book a 30-min Demo📞 Call/text (571) 293-0242
Legal · AI Course · LEG-1

AI and Attorney-Client Privilege: The Architecture Question

Whether sending client material to a third-party AI service waives privilege — the confidentiality analysis, the reasonable-efforts standard, and the deployment that avoids the question.

Last updated:

The Short Answer

Sending client material to a hosted AI service raises a disclosure question a firm must answer before using it. ibl.ai removes the question rather than mitigating it: the model runs inside the firm's own perimeter, where you own all the code and the data, so privileged material is never disclosed to a third party at all.

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

The full course design is published below — every module, its objectives and hands-on activity, the capstone, and every source it cites.

What is this course about?

Every firm AI conversation eventually reaches privilege, and most stop there. This course works through Rule 1.6 confidentiality applied to a hosted model, the third-party disclosure analysis, what reasonable efforts means for technology under Rule 1.1, and why self-hosting removes the disclosure question entirely rather than mitigating it.

Who is this course for?

  • Managing partners and practice group leaders
  • General counsel and in-house legal leadership
  • Law firm CIOs and innovation officers
  • Risk and ethics counsel

What do I need before starting?

  • Licensed attorney or legal professional
  • No technical background required

What will I be able to do afterwards?

  • Apply Rule 1.6 confidentiality analysis to a hosted AI service
  • Assess whether a specific vendor arrangement creates a disclosure problem
  • Apply the reasonable-efforts standard under the Rule 1.1 technology duty
  • Read AI vendor terms for training rights, retention, and subpoena exposure
  • Determine when client consent is required and obtain it properly

What does each module cover?

1

What does Rule 1.6 require of an AI tool?

40 min

Confidentiality analysis applied to a technology the rule's drafters did not anticipate.

Objectives

  • State Rule 1.6's requirements as applied to technology
  • Distinguish confidentiality from privilege
  • Identify what the rule requires before adoption

Topics

Rule 1.6 scopeConfidentiality versus privilegeTechnology applicationPre-adoption duties

Activity. Apply the Rule 1.6 analysis to a tool your firm currently uses.

2

Does sending material to a vendor disclose it?

50 min

The third-party disclosure analysis and where the answer is genuinely contested.

Objectives

  • Work through the third-party disclosure analysis
  • Identify where authority is unsettled
  • Assess the risk tolerance the analysis implies

Topics

Third-party disclosureAgent and vendor doctrineUnsettled authorityRisk tolerance

Activity. Analyze a hosted AI arrangement under the disclosure framework and state the residual uncertainty.

3

What does 'reasonable efforts' mean for technology?

45 min

The Rule 1.1 technology competence duty and the standard it sets for AI adoption.

Objectives

  • State the technology competence duty
  • Determine what reasonable efforts requires here
  • Document the diligence performed

Topics

Technology competenceReasonable efforts standardDiligence documentationEvolving standards

Activity. Document the diligence for one AI tool to the reasonable-efforts standard.

4

How do you read AI vendor terms?

50 min

Training rights, retention, subprocessors, and what happens if the vendor is subpoenaed.

Objectives

  • Locate and interpret training and retention terms
  • Assess subpoena and legal process exposure
  • Identify terms that are disqualifying for legal work

Topics

Training rightsRetentionSubpoena exposureDisqualifying terms

Activity. Review a real AI vendor's terms and identify every clause creating exposure.

5

When does the client have to consent?

45 min

Informed consent — when it is required, and what makes it informed rather than a formality.

Objectives

  • Determine when consent is required
  • Draft consent language that is genuinely informed
  • Handle a client who declines

Topics

Consent triggersInformed consent standardConsent languageDeclining clients

Activity. Draft client consent language and have a colleague critique it as opposing counsel.

6

What about cross-border and foreign-owned providers?

40 min

Data transfer, foreign legal process, and the additional exposure a non-domestic provider creates.

Objectives

  • Assess cross-border transfer exposure
  • Evaluate foreign legal process risk
  • Determine acceptable provider jurisdictions

Topics

Cross-border transferForeign legal processJurisdictional riskProvider selection

Activity. Assess jurisdictional exposure for two providers in different countries.

7

Why does self-hosting remove the question?

45 min

The architectural argument — no disclosure occurs, so no disclosure analysis is needed.

Objectives

  • Explain why self-hosting eliminates rather than mitigates the issue
  • Assess the operational cost honestly
  • Determine whether the firm can support it

Topics

Elimination versus mitigationOperational requirementsFirm capabilityCost comparison

Activity. Compare a hosted and self-hosted deployment on both exposure and operational cost.

8

Assessing your firm's current tools

50 min

The workshop module: a privilege risk assessment across every AI tool in use.

Objectives

  • Inventory every AI tool in use including unapproved ones
  • Assess each against the privilege framework
  • Produce recommendations for the firm

Topics

Tool inventoryShadow AIFramework assessmentRecommendations

Activity. Inventory and assess every AI tool your firm uses, including the unapproved ones.

What is the capstone project?

Firm-wide privilege risk assessment

Produce a privilege risk assessment covering every AI tool in use at the firm: Rule 1.6 analysis, vendor terms review, consent determinations, jurisdictional exposure, and a recommendation on architecture with honest operational costs.

Deliverable: An assessment a managing partner could act on and ethics counsel would sign.

How are learners assessed?

  • Tool inventory must include unapproved and personal-account use
  • Vendor terms review scored against the disqualifying-clause list
  • Consent language critiqued by a colleague playing opposing counsel

What ships with the course?

Facilitator guide

Session-by-session running order, discussion prompts, and the questions that reliably derail a room.

Learner workbook

Exercises, checklists, and the templates each module's activity produces.

Hands-on lab environment

A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.

Assessment bank

Scenario questions and rubric criteria mapped to each stated learning outcome.

Source bibliography

Every primary regulation and standard cited on this page, linked and dated.

Which AI agents does this course use?

The hands-on modules run against agents already deployable on the ibl.ai platform for legal.

Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

Delivery notes

Binding guidance for anyone preparing and delivering this course.

  • State ethics rules vary and several have issued AI-specific opinions. Localize per jurisdiction and verify current opinions at each revision — this area is moving quickly.
  • Module 2 must be honest that the disclosure analysis is genuinely unsettled. Presenting a confident answer where authority is thin exposes firms that rely on it.
  • Module 8's inventory will find unapproved tool use in every firm. Run it non-punitively or partners will not disclose, and the assessment will be worthless.
  • This course frames analysis; it does not give ethics advice. State that explicitly and recommend ethics counsel review for any firm-wide determination.
  • Module 7 must include the operational cost honestly. Self-hosting removes the privilege question and adds an IT burden many firms cannot carry, and pretending otherwise is a disservice.

Why run AI training on a platform you own?

You own the course, not a licence to it

Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.

Model-agnostic delivery

Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.

No per-seat training licences

Usage-based or self-hosted, so cost tracks actual use rather than headcount.

Deploy anywhere

Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

Frequently asked questions

What does the AI and Attorney-Client Privilege: The Architecture Question course cover?

Every firm AI conversation eventually reaches privilege, and most stop there. This course works through Rule 1.6 confidentiality applied to a hosted model, the third-party disclosure analysis, what reasonable efforts means for technology under Rule 1.1, and why self-hosting removes the disclosure question entirely rather than mitigating it. It runs 5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: Firm-wide privilege risk assessment.

Who should take AI and Attorney-Client Privilege: The Architecture Question?

It is written for Managing partners and practice group leaders, General counsel and in-house legal leadership, Law firm CIOs and innovation officers, Risk and ethics counsel. Prerequisites: Licensed attorney or legal professional; No technical background required.

Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for legal teams that cannot send work to a public AI tool.

How do we get access to AI and Attorney-Client Privilege: The Architecture Question?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

How much does AI training for legal cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

Request access to AI and Attorney-Client Privilege: The Architecture Question

Tell us about your cohort and we will set it up — hosted by ibl.ai, or running against your own deployment, where you own all the code and the data.