What is this course about?
Every firm AI conversation eventually reaches privilege, and most stop there. This course works through Rule 1.6 confidentiality applied to a hosted model, the third-party disclosure analysis, what reasonable efforts means for technology under Rule 1.1, and why self-hosting removes the disclosure question entirely rather than mitigating it.
Who is this course for?
- Managing partners and practice group leaders
- General counsel and in-house legal leadership
- Law firm CIOs and innovation officers
- Risk and ethics counsel
What do I need before starting?
- Licensed attorney or legal professional
- No technical background required
What will I be able to do afterwards?
- Apply Rule 1.6 confidentiality analysis to a hosted AI service
- Assess whether a specific vendor arrangement creates a disclosure problem
- Apply the reasonable-efforts standard under the Rule 1.1 technology duty
- Read AI vendor terms for training rights, retention, and subpoena exposure
- Determine when client consent is required and obtain it properly
What does each module cover?
What does Rule 1.6 require of an AI tool?
40 minConfidentiality analysis applied to a technology the rule's drafters did not anticipate.
Objectives
- State Rule 1.6's requirements as applied to technology
- Distinguish confidentiality from privilege
- Identify what the rule requires before adoption
Topics
Activity. Apply the Rule 1.6 analysis to a tool your firm currently uses.
Does sending material to a vendor disclose it?
50 minThe third-party disclosure analysis and where the answer is genuinely contested.
Objectives
- Work through the third-party disclosure analysis
- Identify where authority is unsettled
- Assess the risk tolerance the analysis implies
Topics
Activity. Analyze a hosted AI arrangement under the disclosure framework and state the residual uncertainty.
What does 'reasonable efforts' mean for technology?
45 minThe Rule 1.1 technology competence duty and the standard it sets for AI adoption.
Objectives
- State the technology competence duty
- Determine what reasonable efforts requires here
- Document the diligence performed
Topics
Activity. Document the diligence for one AI tool to the reasonable-efforts standard.
How do you read AI vendor terms?
50 minTraining rights, retention, subprocessors, and what happens if the vendor is subpoenaed.
Objectives
- Locate and interpret training and retention terms
- Assess subpoena and legal process exposure
- Identify terms that are disqualifying for legal work
Topics
Activity. Review a real AI vendor's terms and identify every clause creating exposure.
When does the client have to consent?
45 minInformed consent — when it is required, and what makes it informed rather than a formality.
Objectives
- Determine when consent is required
- Draft consent language that is genuinely informed
- Handle a client who declines
Topics
Activity. Draft client consent language and have a colleague critique it as opposing counsel.
What about cross-border and foreign-owned providers?
40 minData transfer, foreign legal process, and the additional exposure a non-domestic provider creates.
Objectives
- Assess cross-border transfer exposure
- Evaluate foreign legal process risk
- Determine acceptable provider jurisdictions
Topics
Activity. Assess jurisdictional exposure for two providers in different countries.
Why does self-hosting remove the question?
45 minThe architectural argument — no disclosure occurs, so no disclosure analysis is needed.
Objectives
- Explain why self-hosting eliminates rather than mitigates the issue
- Assess the operational cost honestly
- Determine whether the firm can support it
Topics
Activity. Compare a hosted and self-hosted deployment on both exposure and operational cost.
Assessing your firm's current tools
50 minThe workshop module: a privilege risk assessment across every AI tool in use.
Objectives
- Inventory every AI tool in use including unapproved ones
- Assess each against the privilege framework
- Produce recommendations for the firm
Topics
Activity. Inventory and assess every AI tool your firm uses, including the unapproved ones.
What is the capstone project?
Firm-wide privilege risk assessment
Produce a privilege risk assessment covering every AI tool in use at the firm: Rule 1.6 analysis, vendor terms review, consent determinations, jurisdictional exposure, and a recommendation on architecture with honest operational costs.
Deliverable: An assessment a managing partner could act on and ethics counsel would sign.
How are learners assessed?
- Tool inventory must include unapproved and personal-account use
- Vendor terms review scored against the disqualifying-clause list
- Consent language critiqued by a colleague playing opposing counsel
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for legal.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Model Rules of Professional Conduct
American Bar Association
Rules 1.1, 1.6, 5.1 and 5.3 analyzed throughout the course.
- Federal Rules of Civil Procedure Rule 26
Cornell Legal Information Institute
Discovery and privilege interaction referenced in the disclosure analysis.
- AI Risk Management Framework
NIST
Structures the vendor diligence documentation in Module 3.
- OWASP Top 10 for LLM Applications
OWASP
Technical exposure paths the diligence must consider.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- State ethics rules vary and several have issued AI-specific opinions. Localize per jurisdiction and verify current opinions at each revision — this area is moving quickly.
- Module 2 must be honest that the disclosure analysis is genuinely unsettled. Presenting a confident answer where authority is thin exposes firms that rely on it.
- Module 8's inventory will find unapproved tool use in every firm. Run it non-punitively or partners will not disclose, and the assessment will be worthless.
- This course frames analysis; it does not give ethics advice. State that explicitly and recommend ethics counsel review for any firm-wide determination.
- Module 7 must include the operational cost honestly. Self-hosting removes the privilege question and adds an IT burden many firms cannot carry, and pretending otherwise is a disservice.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the AI and Attorney-Client Privilege: The Architecture Question course cover?
Every firm AI conversation eventually reaches privilege, and most stop there. This course works through Rule 1.6 confidentiality applied to a hosted model, the third-party disclosure analysis, what reasonable efforts means for technology under Rule 1.1, and why self-hosting removes the disclosure question entirely rather than mitigating it. It runs 5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: Firm-wide privilege risk assessment.
Who should take AI and Attorney-Client Privilege: The Architecture Question?
It is written for Managing partners and practice group leaders, General counsel and in-house legal leadership, Law firm CIOs and innovation officers, Risk and ethics counsel. Prerequisites: Licensed attorney or legal professional; No technical background required.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for legal teams that cannot send work to a public AI tool.
How do we get access to AI and Attorney-Client Privilege: The Architecture Question?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for legal cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.