Back
Image Alt

The Singapore Law Gazette

AI Prompts and the Fragility of Legal Professional Privilege

Abstract: This article examines how generative AI may undermine legal professional privilege under Singapore law. It argues that prompts and exchanges with AI systems are unlikely, by themselves, to attract legal advice privilege because they are not communications with legal advisors, and may instead be treated as research or internal deliberation. The article also considers whether inputting privileged or confidential material into AI tools may waive legal professional privilege, depending on the system’s design, provider access, and terms of use. It concludes that organisations should adopt safeguards, favour controlled enterprise systems, and limit sensitive inputs to reduce disclosure risk.

An office worker copies a draft clause into an AI assistant to “sense-check the language”. It is faster than emailing the legal department, and more convenient than setting up a call. As legal counsels may begrudgingly admit, the answer may even be close to the answer she needs. Thousands, if not millions, of office workers across the world and in Singapore are already doing the same.

But in the process, confidential details are fed to the assistant. Negotiating positions, trade secrets, personal data, and secrets worth a pretty penny to the other side should these details happen to escape. Or, in the cold light of litigation, the office worker has written admissions, weaknesses that could turn the decision of a case if brought before an arbitrator or judge, or even a criminal conviction.

At the point of entry, the information may no longer remain confined. Your garden variety Generative AI assistant (ChatGPT, Claude, Deepseek, to name a few) is not a legal adviser, and the service provider (OpenAi, Anthropic) could be a third-party.

Where does that information go? Was anything just disclosed to a third party that cannot be taken back? Could those chat logs, in time, become material that is demanded in court, in regulatory proceedings, or by way of subpoena?

This article examines the direct and uncomfortable collision between legal professional privilege and the use of generative AI, focusing on two key questions:

  1. Whether privilege applies to AI interactions at all; and
  2. Whether the use of AI systems may inadvertently result in the waiver of privilege.

A BRIEF RECAP

In Singapore, legal professional privilege (“Legal Professional Privilege”) comes in two forms:

  1. “Legal Advice Privilege” – Which protects confidential communications between a legal adviser and her client for the dominant purpose of providing legal advice; and
  2. “Litigation Privilege” – Which protects communications (not necessarily confidential) between a client (or his legal adviser) and another person made in contemplation of, and for the dominant purpose of, legal proceedings.

Legal advisors in this context refer to advocates and solicitors, as well as in-house legal counsel.

EFFECTS

Legal Advice Privilege and Litigation Privilege may in principle be invoked to resist applications for discovery, search orders, or orders to attend court or produce documents in both civil and criminal courts as well as in arbitration proceedings. It is also accepted that legal professional privilege can be asserted outside the courtroom, such as to resist disclosure of material to regulators who would otherwise have the power to compel the production of such materials.

Privilege is often conflated with the related concept of confidentiality, but the two concepts operate differently. For instance, confidential information may still have to be disclosed in legal proceedings pursuant to discovery obligations, production orders, or pursuant to regulatory requirements, whereas communications subject to a successful claim of privilege will be more resistant.

APPLICATION

Legal Professional Privilege is not absolute, and only arises where specific requirements are satisfied.

Legal Advice Privilege protects confidential communications between a client and lawyer made for the purpose of seeking or giving legal advice, including communications through an agent for that purpose. Not every communication with a lawyer is privileged. Communications made for business, commercial, or accounting purposes generally fall outside its protection. Further, Legal Advice Privilege usually does not extend to communications between a client and non-legal advisers, even if those communications are intended to assist the lawyer in giving advice.

By contrast, Litigation Privilege applies where litigation is reasonably contemplated and the communication or document was created for the “dominant purpose” of that litigation. Unlike Legal Advice Privilege, qualifying Litigation Privilege can extend to communications with third parties, such as the parties’ accountants or investigators engaged in connection with the subject matter of the dispute.

Take for example, where an accountant prepares financial materials for a client to be sent to a lawyer for legal advice. Under existing law, the communications between the client and accountant, would generally not be protected by Legal Advice Privilege. However, if the same communications and the materials were prepared for the dominant purpose of anticipated litigation for which there was reasonable prospects, they may be protected by Litigation Privilege.

A document not originally created for the purpose of seeking legal advice does not automatically become privileged merely because it is later sent to legal advisors, this would then turn on the purpose for which the originals were created.1RB Investments Pte Ltd v Kardachi, Jason Aleksander (2024) 4 SLR 229 at (28)

THE AI COMPLICATION

1A: AI Assistant Queries are Not “Communications”

Legal Advice Privilege and Litigation Privilege apply to communications. Privilege does not extend to other activities, such as a client’s own research, internal deliberations, or fact‑gathering exercises, unless it was intended to, and subsequently was embodied in a qualifying privileged communication.2RB Investments Pte Ltd v Kardachi, Jason Aleksander (2024) 4 SLR 229, at (28) Accordingly, activities such as reading, investigating, or querying a system are by themselves, not privileged.

While this issue has not been directly addressed by the Singapore courts, advice generated by an AI assistant independently of a legal adviser is unlikely to attract legal advice privilege under existing principles. Conversations with AI systems may therefore be disclosable in legal proceedings or regulatory requests. Just like records of internet search histories, AI prompts may not attract privilege as they are more properly characterised as research rather than protected communications.

It is worth noting however, that the resulting communication with counsel may attract protection if the requirements for privilege are satisfied.

1B: Was it for the Purpose of Seeking Legal Advice / the Dominant Purpose of Litigation?

The position is more nuanced in circumstances where AI is used as part of the process of engaging legal counsel. For instance, a client may use an AI assistant to obtain a preliminary understanding of an issue, refine their thinking, or formulate questions for their lawyers. In such cases, the final draft document communicated to counsel for the purpose of obtaining legal advice may attract privilege.

In practice, however, interactions with AI assistants often resemble “thinking aloud”. A client may explore ideas, test arguments, or canvass possibilities, only later deciding to seek legal advice. Multiple purposes, or even multiple staff or teams may be involved in the conversation.3Tet Yung, Chin “Extending the Scope of Legal Advice Privilege” (2007) 19 SAcLJ This makes it difficult to delineate which parts of the interaction were genuinely for the purpose of obtaining legal advice or for the dominant purpose of litigation, as opposed to general inquiry or self-directed analysis.

A related issue arises where a client inputs legal advice received from legal counsel or a third party into an AI system. If the resulting output is not generated for the purpose of obtaining legal advice, but rather for further processing or application, such outputs might fail to attract legal advice privilege, as they do not form part of a confidential solicitor-client communication made for that purpose. They may still qualify for litigation privilege if the further processing can be successfully attributed to litigation.

2. Are Your Conversations with AI (Inadvertently) Waiving Privilege?

A key concern with the use of AI tools is whether information uploaded into the system is, in substance, disclosed to a third party in a manner inconsistent with maintaining confidentiality, and whether that would amount to a waiver of legal professional privilege.

As privilege presupposes confidentiality, privileged communications must be treated confidentially and protected against unauthorised access or wider dissemination. That said, disclosure to a third party does not automatically waive privilege. Courts have long recognised that privilege may survive (i) limited, controlled or selective disclosure; (ii) disclosure connected with legal retainer or anticipated litigation, including disclosure to relevant third parties, parties having a legitimate interest in receiving the information, and/or parties with a common interest;4Motorola Solutions Credit Co LLC v Kemal Uzan and others (2015) SGHC 228, (16). and (iii) communications with third parties for the dominant purpose of litigation under litigation privilege.

Internationally, routine storage or transmission (for example, emails stored in the cloud) are not generally treated as disclosure to a third party for privilege purposes, because the service provider functions as a mere passive intermediary. Greater difficulty arises where AI providers do more than store or transmit information, such as analysing inputs, generating outputs, retaining prompts, or using inputs for model training.

The emerging international authorities suggest that much may depend on the nature of the AI system and the provider’s terms of use. In United States v Heppner5United States v. Heppner, No. 25 Cr. 503 (JSR), 2026 BL 52143 (S.D.N.Y. Feb. 17, 2026), the court scrutinised the AI Provider’s terms of service which allowed it to collect inputs, share them with third parties and use them to train its models finding that there was no reasonable expectation of privacy. Similarly, in UK v Secretary of State for the Home Department,6UK v Secretary of State for the Home Department (2026) UKUT 81, (21). the tribunal observed that uploading confidential material into an open AI system (such as ChatGPT) may, in substance, resemble placing it into the public domain whereas closed enterprise systems (such as Microsoft Copilot) may present a stronger argument for preserving confidentiality. The reasoning is appealing, as the deliberate use of closed enterprise systems, which often process AI operations within segregated or private data environments controlled by the provider, may support the argument that the user’s conduct is consistent with maintaining confidentiality and preserving privilege.

The Singapore apex court has suggested, albeit without deciding the issue, that the applicability of legal advice privilege should turn principally on the “dominant purpose” of the communication rather than rigid distinctions such as timing or the involvement of third parties.7Skandinaviska Enskilda Banken AB (Publ), Singapore Branch v Asia Pacific Breweries (Singapore) Pte Ltd and Other Appeals (2007) SGCA 9, (62). In the meantime, an equally relevant and increasingly common question is whether the growing day-to-day use of AI systems may inadvertently result in the waiver of privilege. How a Singapore court ultimately resolves the tension between AI use and privilege remains to be seen, but the emerging international jurisprudence suggests that much will turn on the degree of control retained over the information and the nature of the AI provider’s access to it.

Plan B: Are There Other Means of Resisting Disclosure?

Assuming privilege is not upheld, hope is not lost. Even where privilege does not apply (or has been inadvertently waived), it does not follow that every AI interaction must be disclosed. When a party in litigation seeks disclosure from an adverse party in order to support its claim (“Discovery”), the requesting party must still satisfy the court that the requested document is relevant and material to the issues in dispute,8Rules of Court 2021, Order 11, Rule 3(1)(b). and that it is within the disclosing party’s possession, custody, or control. Since the introduction of the Rules of Court 2021, Discovery in Singapore has become more targeted and proportionate, moving away from the broader “train of enquiry” approach under the Rules of Court 2014.9Rules of Court 2014, O. 24, r. 5(3)(c). Under the current framework, the requested documents must be “material” to the issues in the case.10Rules of Court 2021, O. 11 r. 2(1) ; Cachet Multi Strategy Fund SPC on behalf of Cachet Special Opportunities SP v Feng Shi and others (2024) SGHCR 8, (29) – (30) Discovery is not intended to permit “fishing” into a party’s internal reasoning or exploratory thought processes.

This may limit attempts to obtain AI chat histories, or even AI generated documents, particularly where requests are framed broadly rather than tied to specific pleaded issues.11The Michigan District Court in Warner v. Gilbarco, Inc . et al No. 2:2024cv12333 declined to order discovery of plaintiff’s use of AI in connection with the litigation, finding that the requests were essentially a fishing expedition. Further, where a person uses disappearing chats, the material may no longer remain within the user’s power, possession or control, leaving an opposing party with the considerably harder task of seeking disclosure directly from the AI provider itself.

Outside of court, where a third party has come into possession of confidential information in circumstances where the confidential nature of such information is clear to him, the third party continues to owe an obligation of confidentiality.

Safeguards You Can Implement Today

Users should pay particular attention to whether inputs are retained, used for model training, shared with third parties, or subject to human review. As a general rule, the more closed and enterprise-controlled the system, the lower the risk of inadvertently waiving privilege may be. Organisations should therefore:

  1. Prefer enterprise platforms with clear contractual safeguards and restricted data use policies over open or consumer-facing AI tools;
  2. Implement internal protocols which clearly limit what employees may upload into such systems, especially sensitive facts or limiting identifiable detail, and especially where legally privileged or confidential material is involved; and
  3. Enact (or extend existing) PDPA/GDPR governance frameworks by reinforcing core data protection practices such as data exposure minimisation, access controls, and vendor due diligence to cover AI use cases.

Ultimately, privilege turns on the substance and treatment of the document. The relevant question is whether the nature of the document and the user’s conduct remains consistent with maintaining confidentiality, having regard to the choice of tools and workflows. Lawyers should therefore guard against the false sense of privacy these AI tools may create, and guide clients accordingly as the law continues to evolve, because in this space, the line between convenience and disclosure, and between assistance and exposure, is often thinner than it appears.

This article was primarily authored by Gilbert Chng and Sue Lyn Cheang, with guidance and input from Sharon Chong.

Endnotes

Endnotes
↑1 RB Investments Pte Ltd v Kardachi, Jason Aleksander (2024) 4 SLR 229 at (28)
↑2 RB Investments Pte Ltd v Kardachi, Jason Aleksander (2024) 4 SLR 229, at (28)
↑3 Tet Yung, Chin “Extending the Scope of Legal Advice Privilege” (2007) 19 SAcLJ
↑4 Motorola Solutions Credit Co LLC v Kemal Uzan and others (2015) SGHC 228, (16).
↑5 United States v. Heppner, No. 25 Cr. 503 (JSR), 2026 BL 52143 (S.D.N.Y. Feb. 17, 2026)
↑6 UK v Secretary of State for the Home Department (2026) UKUT 81, (21).
↑7 Skandinaviska Enskilda Banken AB (Publ), Singapore Branch v Asia Pacific Breweries (Singapore) Pte Ltd and Other Appeals (2007) SGCA 9, (62).
↑8 Rules of Court 2021, Order 11, Rule 3(1)(b).
↑9 Rules of Court 2014, O. 24, r. 5(3)(c).
↑10 Rules of Court 2021, O. 11 r. 2(1) ; Cachet Multi Strategy Fund SPC on behalf of Cachet Special Opportunities SP v Feng Shi and others (2024) SGHCR 8, (29) – (30)
↑11 The Michigan District Court in Warner v. Gilbarco, Inc . et al No. 2:2024cv12333 declined to order discovery of plaintiff’s use of AI in connection with the litigation, finding that the requests were essentially a fishing expedition.

Senior Associate
RHTLaw Asia LLP

Gilbert Chng is a Senior Associate at RHTLaw Asia LLP and is dual qualified in Singapore and the UK, practising in corporate advisory, funds and private wealth.

Associate (Foreign-qualified)
RHTLaw Asia LLP

Sue Lyn Cheang is an Associate (Foreign-qualified) at RHTLaw Asia LLP, with extensive experience in civil and criminal disputes.

Partner, Head of Litigation & Dispute Resolution Practice
RHTLaw Asia LLP

Sharon Chong is the Head of the Litigation & Dispute Resolution Practice and Partner at RHTLaw Asia LLP, with extensive experience in corporate and civil disputes.