My Claude Journey
← Back to the Journey
General AI

Legal Organizations Adopting Artificial Intelligence

What U.S. v. Heppner means for attorneys using AI, the Kovel doctrine workaround that can preserve privilege, and the Data Processing Addendum terms a legal AI vendor must sign before it ever touches client data.

Download the full white paper

AI Legal Software Vendor Requirements Analysis (PDF)— fill in a few details and it’s yours as a PDF.

Regulatory Compliance, Attorney-Client Privilege, and Workflows — a white paper framework for evaluating which AI tools a legal firm or business associate may deploy, under what conditions, and with what contractual and compliance obligations and safeguards.

This white paper is provided for informational and educational purposes only and is not intended to constitute legal, tax, accounting, financial, or other professional advice. Readers should not act or refrain from acting based on any information here without first seeking advice from qualified legal counsel. Receipt of this document does not create an attorney-client relationship, consultant-client relationship, or any other professional relationship.

Opening Statement

This analysis is used to evaluate the landscape of AI tools currently available to legal teams — which tools can be deployed lawfully, under what conditions, and with what safeguards — with the objective of determining the AI software vendor functionality requirements.

The analysis proceeds from a foundational premise that the research has confirmed: no AI tool, regardless of its technical architecture, eliminates an attorney's professional conduct obligations. Vendor technology can reduce risk, simplify compliance, and strengthen privilege arguments — but the obligation to obtain client consent, to supervise AI output, and to verify every citation before filing are obligations of professional conduct, not of vendor selection.

At the same time, vendor selection is far from neutral. The February 2026 ruling in U.S. v. Heppner (S.D.N.Y.) established that attorney-client privilege may be waived when confidential information is shared with an AI platform that lacks contractual confidentiality protections — regardless of attorney intent. That ruling has fundamentally changed the calculus of AI adoption for legal teams. Choosing the wrong tool, or deploying the right tool without a proper Data Processing Addendum, matters.

This document is intended to serve as a practical resource for determining vendor decision requirements in the specific regulatory framework that governs California-licensed attorneys, identifying the questions that must be answered before any tool is deployed with client data, and providing the contractual and procedural templates needed to operationalize compliance once a vendor is selected.

Governing Regulatory Framework

The analysis is conducted against the following California and federal standards, each of which imposes specific obligations on the use of AI tools in legal practice:

AuthorityRelevance to AI Vendor Selection
CA Rule 1.6 — ConfidentialityRequires reasonable measures before sharing confidential client information with any AI vendor. Client consent required. Vendor terms must be reviewed.
CA Rule 3.3 — Candor to TribunalsAI-generated citations must be independently verified before any court submission. Hallucinated citations submitted to a tribunal implicate misconduct rules.
CA Rule 1.5 — Reasonable FeesAI efficiency gains must be reflected in billing transparency. Charging full pre-AI rates for AI-compressed work raises reasonableness concerns.
CA Rule 5.3 — SupervisionAll AI-generated work product must be reviewed by a supervising attorney with the same diligence as paralegal output. Cannot be delegated.
CA State Bar AI Guidance §2.1Four-part vendor assessment test: (1) training data practices, (2) retention periods, (3) third-party sharing, (4) security certifications.
ABA Formal Opinion 512 (2024)Competence requires understanding AI tool limitations. Supervision, confidentiality, and fee transparency obligations apply to AI use.
U.S. v. Heppner (S.D.N.Y. 2026)Privilege may be waived when client data is shared with an AI vendor lacking contractual confidentiality protections. Kovel doctrine is the operative framework.
CCPA §2.3AI vendors processing personal information of California residents require a CCPA-compliant Data Processing Agreement. Deletion rights must be supported.

Analysis Objectives

This analysis is structured around six objectives, each addressing a distinct compliance or operational dimension of AI tool adoption at legal firms.

  1. Establish the Regulatory Baseline. Identify the specific California and federal rules that govern attorney use of AI tools, and map each rule to the concrete vendor selection and workflow decisions it requires.
  2. Assess Vendor Compliance Posture Against the State Bar's Four-Part Test. Evaluate each vendor against the California State Bar Practical Guidance Section 2.1 criteria: training data practices, data retention periods, third-party sharing, and security certifications. Determine contractual commitments.
  3. Evaluate Attorney-Client Privilege Risk for Each Vendor. Apply the Kovel doctrine framework established in U.S. v. Heppner (S.D.N.Y. 2026) to assess which tools, under which deployment conditions, preserve attorney-client privilege when client data is submitted to an AI platform. Identify the contractual and procedural safeguards required to support a privilege argument for each tool.
  4. Assess Document Upload and Redlining Workflow Suitability. For applications that require the upload and AI analysis of actual client documents, such as AI-assisted redlining, what are the conditions of that function — given that client consent and engagement letter disclosure are assumed as baseline protections already in place at a law firm.
  5. Identify the Minimum Contractual Requirements for Compliant Deployment. Define the Data Processing Addendum (DPA) provisions that a legal firm must obtain from any selected vendor before deploying the tool with confidential client data. The DPA should be tailored to California's regulatory framework, addressing training prohibitions, retention, sub-processors, privilege language, security certifications, and audit rights.
  6. Recommend Practical Workflow Protocols for Attorney Adoption. Translate compliance requirements into actionable attorney-facing protocols: prompt practices, matter-level data isolation, citation verification procedures, and supervision sign-off workflows. The goal is to provide the easiest workflow for attorneys while creating a defensible path to compliant AI adoption.

Scope and Assumptions

This analysis assumes that the legal firm has obtained, or will obtain prior to deployment, client consent for the use of AI tools in each matter and that engagement letter disclosure language acknowledging AI-assisted work subject to attorney supervision and confidentiality protocols is in place. These two baseline protections are treated as satisfied throughout the vendor analysis. The remaining analysis focuses on vendor architecture, contractual protections, and attorney workflow as the variables that determine compliance.

United States v. Heppner

A recent court case defining the AI landscape on what is protected under attorney-client privilege and what is not for legal purposes was decided on February 17, 2026. Judge Jed S. Rakoff of the Southern District of New York held that a criminal defendant's written exchanges with a generative AI platform were not protected by attorney-client privilege or the work product doctrine in United States v. Heppner.

The defendant used Anthropic's Claude to prepare reports outlining his defense strategy and potential legal arguments. The government moved to compel production of those AI chat exchanges. Judge Rakoff held that the exchanges were neither privileged nor protected work product. His reasoning ran on three tracks: the AI is not an attorney; communications with a non-attorney generally cannot be privileged; and the confidentiality prong failed on the Terms of Service, because Anthropic's privacy policy at the relevant time stated that user data and prompts could be used for model training and disclosed to third parties.

The Kovel Doctrine Workaround — The Key Legal Framework

The court left one door open. Under the Kovel doctrine, which extends privilege to accountants, translators, and other agents retained by counsel to help render legal advice, Rakoff acknowledged that counsel-directed use of AI on a platform with contractual confidentiality might preserve privilege. Three elements matter for the Kovel workaround to hold: the tool has to be retained by counsel, used under attorney supervision, and bound by contractual confidentiality obligations.

Executing Kovel Doctrine for Legal Firm Vendors

Confidentiality & Privilege Protection. A vendor should state that it has enterprise-grade security, preserves data in a private database instance, and does not train on confidential information — nor do its sub-processors. A vendor positions itself as viable by offering those terms through contractual and technical protections, not just marketing language.

Security Certifications. SOC 2 Type II and SOC 3 certified. SOC 2 Type II confirms a vendor's security controls operated effectively over an independent audit period. SOC 3 is the public-facing version of that audit, available on request without an NDA. Full security documentation, sub-processor lists, and compliance reports should be provided.

Zero Data Retention Architecture. There are three risks specific to legal AI: 1) LLM training on confidential documents, 2) attorney-client privilege exposure from shared vendor infrastructure, and 3) cross-border data handling requirements for global operations. Vendors should address this through zero data retention agreements with LLM providers, encryption at rest, and database-level data segregation.

Mapping Vendor Claims to the Four-Part State Bar Test

State Bar Criterion (Section 2.1)Vendor ClaimYour Verification Step
Data used for training?No — contractually prohibited with LLM providersRequest sub-processor zero-retention contracts from Trust Center
Data retention periodsZero retention claimedConfirm in writing via DPA
Third-party sharingPrivate database instance, sub-processor list availableReview sub-processor list for any gaps
Security certificationsSOC 2 Type II + SOC 3Strong — request current certificates

California Rule 1.6 and ABA Rule 1.6

The obligation under California Rule 1.6 and ABA Rule 1.6 is not vendor-specific — it is a professional conduct obligation that travels with the attorney. Even if a vendor has perfect technical protections, the attorney still must:

  1. Obtain client informed consent before sharing their confidential data with any third party (including AI vendors).
  2. Take reasonable measures to protect that data.
  3. Document that assessment per matter.

No tool — no matter how secure — substitutes for client consent. The tool can make consent easier to obtain and more defensible, but it cannot eliminate the requirement. With consent and an engagement letter in place, legal firms can upload actual client documents for redlining on software tools.

Why a DPA?

The Data Processing Addendum (DPA) obligation isn't about what technology processes the data — it's about the relationship between a legal firm and the vendor as a legal matter. Three frameworks independently require it, regardless of the LLM's architecture:

California Rule 1.6 requires "reasonable measures" before sharing client data with any third party. A signed DPA is the primary evidence of those measures.

CCPA Section 2.3 requires a written service provider agreement before a vendor can process personal information on the firm's behalf.

The Heppner Kovel doctrine requires contractual confidentiality commitments — verbal or implied ones don't satisfy it. The DPA is that contract.

DPA Elements

Core elements of a Data Processing Addendum for a legal AI vendor:

  1. Parties and Relationship Definition. Establishes who is the data controller (the firm) and who is the data processor (the vendor), and confirms the DPA is incorporated into the underlying MSA.
  2. Definitions. Defines key terms precisely: Confidential Client Data, Processing, Sub-Processor, Proprietary LLM, Training Data, Retention Period, and Security Incident. Vague definitions are where vendor compliance gaps hide.
  3. Permitted Purposes and Prohibited Processing. Specifies the exact purposes for which the vendor may process data — and explicitly prohibits everything else, especially using client data to train AI models. This is the most critical clause for legal AI vendors.
  4. Data Retention and Deletion. States the maximum retention period, the firm's right to request deletion of specific matter data, the deletion timeframe, written certification of deletion, and return or destruction of data on termination.
  5. Sub-Processor Controls. Requires a complete sub-processor list, advance notice before adding sub-processors, the firm's right to object, and flow-down of the same confidentiality obligations to all sub-processors.
  6. Attorney-Client Privilege and Kovel Language. Explicitly acknowledges the vendor's role as a counsel-directed agent, commits to confidentiality sufficient to support a post-Heppner privilege argument, and governs how the vendor must respond to government demands for client data.
  7. Security Requirements. Specifies minimum technical safeguards: encryption standards (AES-256 at rest, TLS in transit), access controls, penetration testing, database-level client isolation, and SOC 2 Type II certification.
  8. Security Incident Notification. Requires the vendor to notify the firm within a defined window (typically 48–72 hours) of any breach, with specific content requirements: nature of incident, data categories affected, and remediation steps.
  9. Audit Rights. Gives the firm the right to audit or commission an audit of vendor compliance, with reasonable notice, and requires the vendor to maintain and produce audit logs of all access to client data.
  10. Representations and Warranties. Vendor warrants legal authority to enter the DPA, current SOC 2 certification, accuracy of the sub-processor list, and — critically for AI vendors — that no client data has been or will be used as training data without written consent.
  11. Term, Termination, and Survival. Ties the DPA to the MSA term, specifies which obligations survive termination (prohibited processing, privilege, security, audit), and triggers the deletion/return obligations in the retention clause.
  12. Governing Law. California law, with jurisdiction specified. For a California-based firm this should be explicit given CCPA and California Rules of Professional Conduct applicability.
  13. Exhibit A — Sub-Processor List. A living exhibit naming each authorized sub-processor, their role, data location, and confirmation that training is contractually prohibited. Updated with notice whenever the list changes.

Engagement Letter Modifications

It is recommended that an additional clause be added to initial client engagement letters: an AI Tool Disclosure, which acknowledges the firm's use of AI-assisted tools subject to attorney supervision and confidentiality protocols, and confirms the client's right to raise questions or restrictions regarding AI use on their matter.

Software AI Vendor Requirements

  1. Absolute Training Prohibition. Customer data — including prompts, uploaded documents, and AI-generated output derived from client data — is contractually prohibited from use in training, fine-tuning, evaluating, or improving any AI model. This prohibition must extend to all sub-processors, including any third-party LLM provider. Must appear in the signed DPA, not just marketing materials.
  2. Zero Data Retention. Vendor commits to zero retention of client data after each session ends. No session logs, no prompt history, no uploaded document storage beyond the active session. Where zero retention is not technically feasible, the maximum retention period must be explicitly stated in the DPA and the firm must have the right to demand deletion of any specific matter's data within 24–48 hours with written certification of deletion.
  3. Self-Hosted or Private VPC Deployment Option. There are two methods of deployment: one is self-hosted, the other is a private VPC deployment option. For self-hosted deployments, client data never leaves the firm's own network infrastructure. A cloud vendor with a private database instance, zero-retention sub-processor agreements, and a Kovel-compliant DPA meets the standard equally.
  4. DPA in Place. The DPA must include explicit attorney-client privilege and work product protection language, acknowledging the vendor's role as a counsel-directed agent under the Kovel doctrine. Must include a provision requiring the vendor to resist third-party demands for client data and to notify the firm immediately upon receipt of any subpoena or legal process seeking client data.
  5. Database-Level Client Isolation. Each client matter's data must be isolated at the database level — not just logically separated by access controls — from all other customers' data. This is an architectural requirement, not a policy one. Cross-customer contamination is a material privilege and confidentiality risk.

Appendix

AskJura vs. GC AI Comparison

FactorAskJuraGC AI
Purpose-built for legal✅ Yes✅ Yes
Own LLM (not a GPT/Claude wrapper)✅ Yes❌ Wraps existing LLM
Citation verification built-in✅ Yes✅ Yes
Daily law updates✅ Yes⚠️ Not explicitly stated
Self-hosted/VPC option✅ Yes — strong differentiator❌ No
Heppner/Kovel privilege posture⚠️ Not explicitly addressed publicly✅ Explicitly designed around it
Sub-processor transparency⚠️ DPA required✅ Trust Center published
SOC 2 Type II✅ Claimed✅ Certified
No training on client data✅ Stated✅ Stated
Company maturity⚠️ Earlier stage / pilot phase✅ 1,700+ legal teams
Privacy policy scope for client data⚠️ Deferred to DPA⚠️ Deferred to DPA

This document is a generic compliance-planning reference, not legal advice. Regulatory requirements — particularly around AI use in legal practice — are evolving rapidly; confirm current requirements and consult qualified legal counsel before deploying any AI tool with client data.