Mid-year review: how generative-AI is reshaping litigation and privilege in Australia, the UK and the US
Generative AI is changing the way litigation is conducted, raising new questions about what constitutes waiver of legal professional privilege, the maintenance of client confidentiality and the responsible use of AI in legal practice.
As courts and regulators respond to these issues, understanding how legal professional privilege operates, and how to avoid waiver, has become increasingly important. Legal professional privilege is a fundamental protection recognised in Australia, the UK and the US. In Australia and the UK, it applies to confidential solicitor-client communications made for the dominant purpose of giving legal advice or for use in existing or anticipated litigation.
It has two limbs: legal advice privilege and litigation privilege. In Australia, these are codified in sections 118–119 of the Evidence Act 2008 (Vic) and Evidence Act 1995 (Cth) and also exist at common law.
In the US, the equivalent protections are attorney-client privilege and the work product doctrine. Attorney-client privilege covers confidential communications made for the purpose of obtaining or providing legal advice, while work product protection extends to materials prepared in anticipation of litigation, including both tangible and intangible work product.
With the commencement of the new financial year, we reflect on the evolving AI landscape both in Australia and abroad, including the major breakthroughs happening worldwide with respect to the effect of AI on litigation, legal professional privilege and client confidentiality, with a spotlight on shifts in the UK and US.
Key takeaways
- Courts in Australia, the UK and the US are increasingly focused on how generative AI affects litigation, legal professional privilege and client confidentiality.
- Australian courts have moved quickly to issue practice notes and guidance on AI use, but there is limited case law that assesses when the use of AI waives legal professional privilege.
- A consistent theme is emerging: public AI tools carry higher privilege and confidentiality risks than closed or enterprise systems.
- Courts users remain responsible for verifying AI-generated material before relying on it in court and may be met with professional consequences with the misuse of AI.
- Overseas decisions, particularly in the US, show that privilege outcomes may depend on how AI is used in the circumstances, whether legal supervision is involved and the terms and conditions of the specific platform used.
AI in Australia
Recent Australian cases have highlighted instances of lawyers and litigants filing AI‑generated ‘hallucinations,’ including false citations and relying on incorrect or non-existent materials.
Most recently, on 1 July 2026, the Federal Circuit and Family Court handed down its decision in Ba v Sterling Parts Australia Pty Ltd [2026] FedCFamC2G 1245, describing the dispute as ‘…a cautionary tale about the dangers of befriending Artificial Intelligence (AI)-powered chatbots who masquerade as legal advisors.’ In circumstances where the applicant had relied on evidence that did not exist, the court cautioned that ‘AI is not a legal advisor, it owes no duty to the Court or the administration of justice and owes no duty to act in the best interests of [the applicant] or to observe regulatory or ethical standards, including in its engagement with other practitioners and parties.’
While courts continue to address the serious consequences of this type of conduct, there has been far less judicial consideration of how AI use may affect legal professional privilege.
Although no authoritative ruling has yet emerged in Australia, recent decisions suggest that uploading documents to AI tools could amount to a waiver of privilege. Most judicial commentary has arisen in courts with higher rates of self‑represented parties, such as the Federal Circuit and Family Court, where reliance on AI is more common.
This is unsurprising given the growing number of self-represented litigants turning to AI to navigate a legal system that is often cost prohibitive. Total cases lodged with the Fair Work Commission have surged by more than 70 per cent over the past three years, with more than 55,000 claims expected this financial year.
The face of litigation is shifting as a result, with self-represented litigants gaining access to free tools that enable them to more readily access what they need to commence proceedings with AI, which is especially appealing to litigants who do not speak English as their first language. While AI has certainly assisted accessibility, formal claims based on hallucinated legal provisions can impose significant costs on defendants and place unnecessary strain on the judiciary.
While the use of AI in litigation continues to grow, Australian courts have not yet had the opportunity to resolve these issues. Nor have Australian courts squarely considered the impact of AI on protecting client confidentiality and maintaining legal professional privilege. That said, two 2025 decisions of the Federal Circuit and Family Court of Australia illustrate the courts’ growing concern regarding the use of generative AI in legal practice, particularly in relation to accuracy, confidentiality, and privilege.
Key Australian decisions
In Helmold & Mariya (No 2) [2025] FedCFamC1A 163, the Full Court dismissed an appeal concerning parenting orders but took the opportunity to comment on deficiencies in the appellant’s materials. The Notice of Appeal contained incorrect and untraceable authorities, which the court attributed to the use of generative AI. In response, the court endorsed recent judicial warnings about AI use and emphasised practitioners’ professional obligations to verify all material filed. Notably, the court observed that inputting court documents into open AI systems may breach statutory prohibitions on publication, undermine confidentiality obligations, and potentially waive legal professional privilege. The court cautioned that the convenience of AI cannot displace the need for independent scrutiny and professional judgment.
These concerns were reinforced in Mertz v Mertz (No 3) [2025] FedCFamC1A 222. The court addressed the use of AI by legal representatives in preparing submissions and authorities that contained erroneous references. It reiterated the risks identified in Helmold, including potential breaches of statutory confidentiality provisions, the Harman undertaking, and waiver of privilege where documents are entered into AI systems. Reflecting the seriousness of these issues, the court referred the practitioners’ conduct to the relevant professional regulatory bodies.
Together, these decisions signal a clear judicial expectation that AI tools be used cautiously and in compliance with professional and ethical obligations. They warn that careless or untested reliance on AI-generated material may expose practitioners to significant professional consequences, particularly where issues of confidentiality and privilege arise.
Australian courts' guidance on AI
These decisions have been followed by a wave of practice notes and judicial guidance issued by Australian courts throughout 2026 in response to the growing use of generative AI in legal proceedings.
Victoria has been at the forefront of these developments. Central to many of them is the Victorian Law Reform Commission’s ‘Artificial Intelligence in Victoria’s Courts and Tribunals: Report’ (VLRC Report), tabled in Parliament in February 2026, which we discussed in our Smarter Lawcast podcast series, ‘AI and legal professional privilege’. The VLRC Report was the first inquiry by an Australian law reform body into the use of AI in courts and tribunals. It proposed eight guiding principles and made 30 recommendations regarding the safe and responsible use of AI.
In April 2026, the Federal Court of Australia released its ‘Use of Generative Artificial Intelligence Practice Note (GPN-AI)’, the court’s first comprehensive statement on the use of generative AI in proceedings (see our previous article, ‘Federal Court releases Use of Generative AI Practice Note: key guidance for using AI in proceedings’). The Practice Note recognises the potential benefits of generative AI while drawing a clear distinction between ‘open’ or ‘public’ tools and ‘closed’, enterprise systems. It also reflects the VLRC Report’s recommendations, particularly regarding the risk of inadvertently waiving privilege through the use of public AI tools. This Practice Note represents the Federal Court’s early adoption of the Commission’s findings.
The Supreme Court of Victoria followed in May 2026, releasing Practice Note SC Gen 25 and separate Judicial Guidelines for judicial officers (see our previous article, ‘Supreme Court of Victoria issues AI guidelines for court users and judicial officers’). Building on the Federal Court’s approach, the Practice Note more strongly adopted the Commission’s eight guiding principles and formally defined ‘generative AI’, ‘public AI’ and ‘closed AI’ as distinct subcategories, extending scope to cover lawyers, litigants, and witnesses. Non-compliance carries real consequences: the court may take a failure to comply into account when exercising its case management and costs powers, and lawyers who rely on unverified AI outputs risk referral to the Victorian Legal Services Board and Commissioner.
Shortly afterwards, the Federal Circuit and Family Court of Australia (FCFCOA) issued its ‘Practice Direction: Use of Artificial Intelligence (PD-AI)’ (see our previous article, ‘Federal Circuit and Family Court of Australia issues Practice Direction on the use of AI: what court users need to know’). Building on the court’s decisions in Helmold and Mertz, the Practice Direction moves from judicial warning to formal regulation, prohibiting the input of confidential or privileged information into public AI tools and imposing strict requirements relating to discovery, disclosure orders, suppression orders and subpoenas.
Most recently, in June 2026, the County Court of Victoria released Practice Note PNCCV 1-2026 and accompanying Judicial Guidelines (see our previous article, ‘County Court of Victoria issues guidance on the use of AI in Court proceedings’). Consistent with the approaches adopted by the Supreme Court of Victoria and the Federal Court, the Practice Note adopts definitions of ‘public AI’ and ‘closed AI’ and drew on the Commission’s eight guiding principles. It also expressly warns that reliance on unverified AI outputs may result in referral to the Victorian Legal Services Board and Commissioner and personal costs orders.
Taken together, these four instruments demonstrate a clear and growing consensus across Australian courts. Three themes consistently emerge:
courts are distinguishing between public and closed AI tools, with stricter controls applying to public platforms;
court users remain ultimately responsible for verifying AI-generated content; and
the VLRC Report provides the fundamental principles-based framework underpinning much of the emerging guidance.
In the five months since the VLRC Report was tabled in Parliament, four Australian courts issued formal guidance on the use of generative AI. It remains to be seen whether other courts and tribunals will adopt similar approaches, and whether broad structural reforms recommended by the Commission, including the establishment of a cross-jurisdictional technology and innovation committee, will ultimately be implemented.
To see where Australia may be heading next, it is helpful to consider how courts in the United Kingdom and the United States are considering the use of AI in litigation and its impact on legal professional privilege.
AI in the United Kingdom
Like Australia, the United Kingdom is beginning to confront the impact of generative AI on litigation, legal professional privilege and client confidentiality. While the law is still developing, recent judicial decisions and court guidance provide useful insight into how UK courts are approaching these emerging issues.
Key UK developments
As in Australia, there is still relatively limited judicial commentary in the United Kingdom directly addressing legal professional privilege, and the potential waiver of that privilege in the context of AI.
A significant, recent decision is UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), where the Upper Tribunal (Immigration and Asylum Chamber) concluded that uploading client material into open-source AI tools is to place this information on the internet in the public domain, and thus to breach confidentiality and waive privilege. By comparison, closed source AI tools that do not place information in the public domain were found to pose less risk.
While this case primarily concerned AI-generated hallucinations and professional conduct, its comments on privilege signal a cautious and restrictive approach to the use of AI.
Overall, the UK position continues to evolve, with courts only beginning to grapple meaningfully with these issues.
Most recently, in June 2026, a HR consultant in England successfully used an AI law firm to assist in court proceedings. Reported to be the first successful case involving an AI lawyer, the matter illustrates how AI is beginning to reshape access to legal services and litigation. It also restates the potential for AI to assist individuals who may otherwise find legal costs prohibitive to commencing proceedings.
UK court guidance on AI
The UK’s Court and Tribunals Judiciary ‘Artificial Intelligence (AI) Guidance for Judicial Office Holders’ (October 2025) reflects many of the same concerns now embedded in Australian court guidance.
The guidance emphasises that information entered into public AI tools should be treated as effectively disclosed, highlights the risks of hallucinations and bias, and makes clear that relevant AI users remain personally responsible for verifying AI-generated material before relying on it.
More recently, in late June and early July 2026, there have been two updates from UK courts regarding the use of AI, including to assess the temperature of prospective change. Firstly, the Civil Justice Council (CJC) established a working group examining the use of AI by legal representatives in preparing court documents. While its final report is expected later in 2026, a brief update on the consultation findings was released in late June indicating the group's 'emerging direction of travel', including working towards 'introducing proportionate transparency in relation to expert evidence' and 'recognising the distinct and evolving challenges posed by litigants in person.'
On 1 July 2026, the Technology and Construction Court (TCC) Guide 2026 was released, which also addressed the use of AI, including to stress personal responsibility for its use as well as professional obligations to ensure accuracy.
These themes closely align with the Australian framework, particularly the risks associated with the use of public AI tools, the emphasis on independent verification of outputs, and the non-delegable nature of professional responsibility including the maintenance of client confidentiality.
One key difference, however, is the structure and regulatory approach. Australian courts have moved toward detailed, enforceable practice notes that apply broadly to court users and explicitly differentiate between categories of AI systems. By comparison, the UK guidance remains more advisory, framed more so as guidance rather than formal procedural requirements, noting this may shift with the release of the CJC final report and recommendations as to the use of AI later this year.
While the two jurisdictions are converging on many of the same underlying principles, they differ in how those principles may operate and be enforced in practice.
AI in the United States
Compared with Australia and the United Kingdom, the United States is experiencing a particularly active period of judicial consideration of the use of AI and its impact on privilege and confidentiality.
A growing body of case law illustrates differing approaches to how courts characterise AI tools in the context of privilege. Some courts have treated AI platforms as ‘third parties’ capable of breaking confidentiality, while others have viewed them as ‘tools’ analogous to more traditional litigation aids.
Key US decisions
Earlier this year, the Southern District of New York decided United States v Heppner 1:25-cr-00503(JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026). The court held that materials generated using a public AI platform were not protected by privilege and must be produced, emphasising that the defendant had disclosed information to a ‘third party’ under terms allowing data use and retention. The court’s reasoning focused heavily on the absence of counsel direction in using the AI tool, and the non-confidential terms of the platform, concluding that using an AI service of this nature was treated as inconsistent with maintaining confidentiality.
Just days later, however, the Eastern District of Michigan reached a different conclusion in Warner v Gilbarco Inc. No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026), finding that a self-represented litigant’s AI-assisted materials could be protected as work product privilege. The court determined that being self-represented, the plaintiff was in effect acting as her own counsel in preparing materials in anticipation of litigation, and characterised the AI utilised as a ‘tool, not a person’, and therefore not a third party for waiver of privilege purposes.
This approach has since influenced other decisions, including Morgan v. V2X, Inc. Civil Action No. 25 – cv – 01991 – SKC – MDB. (D. Colo. March 30, 2026), where the court reinforced that AI interactions do not automatically compromise work product protections, particularly where the materials reflect litigation preparation. In that instance, partial disclosure of the AI platform used to upload and review any confidential information was granted to ensure transparency regarding whether confidentiality had been compromised, though with a carve out for information that would reveal the self-represented litigants’ mental impressions or legal strategy.
Following Warner, Heppner and Morgan, US courts appear to be moving towards more functional, risk-based approach to AI use in discovery. Increasingly, the question is not whether AI use itself defeats privilege, but how the technology is used and in what context.
Decisions such as Jeffries v. Harcros Chemicals Inc. Case No. 25-2352-KHV-ADM demonstrate the growing concern about the discovery risks associated with public AI tools. Courts have recognised that uploading material, even if not confidential, may distort disclosure practices and create irreversible dissemination risks, given the difficulty of retrieving or deleting data once ingested by AI. Rather than imposing blanket prohibitions, courts have favoured targeted safeguards through protective orders.
At the same time, courts continue to recognise that AI can serve as a legitimate litigation tool. In Tym v Cerno, Flannery & New Mexico Health Care Authority 1:25-cv-00498-JCH-JMR, the District Court for the District of New Mexico accepted that AI prompts may constitute protected work product where they reflect litigation preparation. Similarly, in Littiece Jones v Delta Air Lines, Inc. Case No. 2:24-cv-11224, the District Court for the Eastern District of Michigan prohibited real-time AI use in depositions to preserve the integrity of testimony.
Two further significant decisions were recently handed down in this space in June 2026. In Tate Group Automotive v Legacy Automotive Capital Cause No. 25-BC11B-0020 (Business Court of Texas, Eleventh Division), the Texas Business Court aligned with Morgan and Warner, finding that AI use does not waive work product unless disclosure is made to an adversary or meaningfully increases the risk that material will reach an adversary, while still requiring transparency around what materials were shared with AI.
Similarly, in Asini v Hayward 2026 NY Slip Op 26086 (New York Supreme Court, Nassau County), the New York Supreme Court went further in protecting AI-assisted preparation, quashing a subpoena for ChatGPT records and treating such interactions, particularly by a self‑represented litigant, as analogous to confidential, strategy‑driven work product.
While the United States has not seen the same rapid proliferation of formal court-issued practice notes as Australia, this growing body of case law reflects an increasingly nuanced and context-specific approach to the use of AI in litigation.
Where Australian courts have moved quickly to codify these principles into prescriptive, enforceable practice frameworks (often expressly distinguishing between public and closed AI), US courts are developing the law incrementally through judicial decisions. The result is an emerging convergence in principle, particularly around risk, supervision, and confidentiality, even as the mechanisms of regulation diverge, with Australia favouring regulation and guidance, while the US continues to refine its approach through judicial decision-making.
An emerging risk-based approach
What emerges from this line of US authority is a clear trend toward increased judicial engagement with the practical realities of AI use in litigation. Courts are beginning to interrogate platform terms of use, data retention practices, and the role of legal supervision in determining whether privilege is maintained or waived. As explored further in our article, ‘Managing legal privilege risks in the age of generative AI’, these factors are becoming central to any privilege analysis, particularly where information is uploaded to third-party systems.
The practical implications for lawyers and clients are significant. As discussed in our article, ‘When using AI risks waiving legal professional privilege’, even well-intentioned use of AI can carry real waiver risks if confidentiality is compromised. The differing outcomes in Heppner and Warner demonstrate that, particularly in the US, outcomes may turn on subtle factual distinctions, including whether AI was used under legal direction, whether the tool is open or closed, and how courts characterise the technology itself.
What’s next for AI, litigation and legal professional privilege?
The pace of progress in this space shows no sign of slowing. While courts are increasingly grappling with the implications of generative AI, the law is only just starting to catch up, and questions around privilege, confidentiality and disclosure are likely to keep evolving.
Until greater consistency emerges, practitioners should adopt a cautious approach when dealing with privileged material in litigation, as well as in practice more broadly.
While the UK has taken a cautious judicial approach, and US courts continue to explore competing frameworks, there is no settled international consensus. In Australia, courts have moved swiftly to offer guidance, with four formal instruments issued in the first half of 2026 alone, each building on the VLRC Report’s principles-based framework. Yet, authoritative judicial rulings on privilege in the AI context remain limited, and many questions of enforcement and interpretation have not yet been tested.
Practitioners cannot wait for the law to fully settle before taking a considered and cautious approach to their own use of AI in legal practice.
As these issues inevitably come before Australian courts, it will be interesting to see whether (divergent) paths trodden before us by our friends in the US and UK influence the development of Australian law.
This is an area that will continue to evolve, and one that practitioners should watch closely.
This article was prepared with assistance from Nikki Young and Marcus Jones, Law Graduates.
If you would like further insights on these issues, listen to our Smarter Lawcast podcast series, AI and legal professional privilege, hosted by Catie Moore and Lauren Separovich. The series explores and compares the evolving position both in Australia, and internationally.
Contact

