Strictly Educational – Not Legal Advice

1. AI and Waiver of Privilege

This article addresses a single question of increasing practical significance for Federal Court litigants: when a party uploads privileged or confidential case-preparation material to a generative AI platform, does Australian law treat that act as a waiver of privilege, and does that outcome align with the approaches taken in the United Kingdom and the United States?

The question is especially significant for self-represented litigants. Section 120 of the Evidence Act 1995 (Cth) extends a specific statutory protection to unrepresented parties in respect of confidential communications and documents made for the dominant purpose of preparing for or conducting proceedings. Unlike legal advice privilege (s 118) and litigation privilege (s 119), s 120 does not depend on a lawyer-client relationship. It is the primary and in many cases the only privilege available to a self-represented litigant.

The question of whether AI disclosure waives that protection is not settled in Australian authority. No Federal Court judgment has squarely addressed it. Recent cases in the UK and US such as R (on the application of Munir) v Secretary of State for the Home Department [2026] UKUT 00081 (IAC) and United States of America v Bradley Heppner, 25 Cr. 503 (JSR) represent, as at April 2026, the most developed judicial treatments of the AI/privilege intersection in comparable common law jurisdictions. This memorandum assesses the extent to which those approaches are consistent with what Australian law would likely produce under ss 120 and 122.

2. The Australian Statutory Framework — ss 120 and 122

2.1 Section 120 — Protection for Self-Represented Parties

Section 120(1) of the Evidence Act 1995 (Cth) provides that evidence is not to be adduced if, on objection by an unrepresented party, the court finds that adducing it would disclose:

  • (a) a confidential communication between the self-represented party and another person; or
  • (b) the contents of a confidential document prepared by the party or at their direction or request;

where the communication or document was made or prepared for the dominant purpose of preparing for or conducting the proceeding.

Three elements must be satisfied: (i) confidentiality; (ii) the communication or document falls within the defined categories; and (iii) dominant purpose of litigation preparation. The protection is framed as an exclusionary rule — evidence "is not to be adduced" — which means it is an evidentiary protection at the point of tender, not an absolute immunity from production or disclosure.

The protection is not "legal advice privilege" or "litigation privilege" in the traditional sense because it does not require a lawyer. However, it operates by functional analogy: it recognises that a party preparing their own case must be able to do so with some degree of confidential space.

2.2 The Confidentiality Requirement

"Confidential" is defined in s 117 to mean made or prepared under an express or implied obligation not to disclose the contents. This definitional requirement is important: if the channel through which a communication is made does not carry an obligation of confidentiality on the recipient, the protection under s 120 cannot arise in the first place. A communication is not "confidential" for s 120 purposes merely because the party intended it to be private.

2.3 Section 122 — Loss by Inconsistent Conduct

Section 122 is the primary mechanism by which the protection conferred by ss 118–120 is lost. Its operation is as follows:

Section 122(1) — Consent: The protection does not prevent adducing evidence given with the consent of the client or party.

Section 122(2) — Inconsistency: Subject to s 122(5), the protection does not prevent adducing evidence if the client or party has acted in a way that is inconsistent with objecting to the adducing of the evidence because it would disclose material of the kind protected by ss 118, 119 or 120. The reference to s 120 is express: a self-represented litigant faces the same inconsistency-based waiver as a represented party.

Section 122(3) — Deemed inconsistency: Without limiting s 122(2), inconsistency is deemed to occur if:

  • (a) the party knowingly and voluntarily disclosed the substance to another person; or
  • (b) the substance was disclosed with the express or implied consent of the party.

Section 122(5) — Safe harbours: A party is not taken to have acted inconsistently merely because the substance was disclosed:

  • (a)(i) in the course of making a confidential communication or preparing a confidential document;
  • (a)(ii) as a result of duress or deception;
  • (a)(iii) under compulsion of law; or
  • (c) to a person with whom the party had a common interest relating to the proceeding.

2.4 The Mann v Carnell Principle

In Mann v Carnell (1999) 201 CLR 1, the High Court held that waiver of privilege turns on inconsistency between maintaining the privilege claim and the conduct of the party. The test does not require subjective awareness that privilege is being waived. A party can waive privilege by conduct that is objectively inconsistent with maintaining confidentiality, even if they did not intend to do so. The question is whether the conduct of the party, viewed objectively, is inconsistent with the maintenance of the confidentiality which the privilege is intended to protect.

This principle operates through s 122(2) and sits as the organising concept for the waiver analysis in Australian courts.

3. How ss 120/122 Apply to AI Disclosure

3.1 Step 1 — Is the AI Platform an "Another Person" under s 122(3)(a)?

When a self-represented litigant inputs case-preparation material into a generative AI platform operated by a third-party vendor (such as Anthropic operating Claude), the following occurs:

  • The material is transmitted to the vendor's servers
  • The vendor's terms of service govern how the material is retained, processed, and potentially shared
  • The vendor may retain the material for quality assurance, trust and safety, training, or regulatory compliance purposes
  • The vendor's privacy policy may expressly reserve the right to disclose to government or regulatory authorities

The vendor is plainly an entity distinct from the party. On any reasonable construction, disclosure to that vendor's platform is a disclosure to "another person" within s 122(3)(a). The party who inputs the material does so knowingly and voluntarily — they chose to use the platform and agreed to its terms. Section 122(4) (the employee/agent carve-out) would not apply because the AI vendor is not an employee or agent of the party in any legally relevant sense.

3.2 Step 2 — Is the Confidentiality Requirement Satisfied?

For s 120 to protect the material in the first place, the communication must be "confidential" — made under an obligation not to disclose. If the AI platform's terms of service do not impose a genuine obligation of non-disclosure, the communication is not confidential for s 120 purposes, and the protection never arises.

If the material was already privileged before it was input into the AI platform, it does not follow that the AI communication inherits that privilege. The question is the confidentiality of the AI communication itself, not the original document.

Where the platform's privacy policy expressly reserves rights to retain, share, or train on inputs, the confidentiality requirement is not satisfied in respect of the AI communication. This means the s 120 protection does not extend to the AI conversation itself, though the original document may retain its protection separately — but only if it has not been disclosed in a manner inconsistent with confidentiality.

3.3 Step 3 — Inconsistency under s 122(2)

Even if the original material was protected by s 120 before being input into the AI platform, the act of inputting may constitute conduct inconsistent with maintaining confidentiality under s 122(2). Applying Mann v Carnell, the question is whether inputting the material into a platform that does not guarantee confidentiality is objectively inconsistent with the maintenance of the confidentiality that s 120 is designed to protect.

If the platform's terms permit the vendor to access, retain, or share the material, the answer is almost certainly yes. The party has placed the substance of the material outside their control and into the hands of a third party who is not subject to any relevant privilege obligation.

3.4 Step 4 — Is There a Safe Harbour under s 122(5)?

Section 122(5)(a)(i): A party is not taken to have acted inconsistently merely because the substance was disclosed in the course of making a confidential communication or preparing a confidential document. This is the most viable argument for an AI user. If the AI platform is an enterprise tool operating under a contract that (1) prohibits the vendor from using inputs for model training, (2) imposes express confidentiality obligations on the vendor, (3) limits human access to the content, and (4) provides for deletion of data upon request, then there is a credible argument that using the platform to prepare a document is making a confidential communication within s 122(5)(a)(i). The communication is within a controlled, confidential channel analogous to a legal research service operating under confidentiality obligations. This analysis mirrors the "limited waiver" reasoning in Expense Reduction Analysts Group Pty Ltd v Armstrong Strategic Management and Marketing Pty Limited [2013] HCA 46. Waiver can be imputed by law (even if not intended) where the party's actions are plainly inconsistent with maintaining the confidentiality which privilege protects.

However, if the platform is a public tool where the vendor's terms permit training use and broad data retention, the s 122(5)(a)(i) argument fails. The communication is not made within a confidential channel.

3.5 The Conclusion under Australian Law

Under ss 120 and 122:

  1. Inputting s 120-protected material into a public AI platform (no confidentiality controls, training use permitted) will in most cases satisfy s 122(3)(a) and (b) as "knowing and voluntary" or consent-based disclosure to another person; will constitute conduct inconsistent with maintaining confidentiality under s 122(2) applying Mann v Carnell; and will not attract any s 122(5) safe harbour. The s 120 protection will be lost.
  2. Inputting the same material into a closed enterprise AI platform (contractual confidentiality, no training use, limited human access, deletion controls) may satisfy the s 122(5)(a)(i) safe harbour if the confidentiality of the communication can be established. The protection may be preserved, but this is fact-sensitive and not assured.
  3. In either case, the AI conversation itself will not be protected by s 120 because it is not made under an obligation of non-disclosure in the relevant sense where the vendor's terms permit retention and sharing.

4. The UK Approach — R (on the application of Munir) v Secretary of State for the Home Department [2026] UKUT 00081

The Tribunal in UKUT 00081 approached the AI/privilege question categorically rather than through a structured doctrinal test. Its core chain of reasoning was:

Open-source AI tool → public domain placement → breach of client confidentiality → waiver of legal privilege → mandatory ICO referral.

The Tribunal did not engage with a multi-step analysis of the kind that s 122 requires. It treated the act of uploading to an open-source AI tool as self-evidently equivalent to placing material in the public domain. Once in the public domain, confidentiality is destroyed, and privilege is waived.

The Tribunal also named Microsoft Copilot as a safer alternative for summarisation tasks, on the basis that it does not place information in the public domain. The Court held that supervisors who fail to prevent junior fee-earners from using AI hallucinations are likely to be more culpable than the junior who produced the error.

5. The US Approach — United States of America v Bradley Heppner, 25 Cr. 503 (JSR)

Rakoff J in Heppner addressed the question from the opposite direction: not whether uploading destroys existing privilege, but whether AI conversations can attract privilege in the first place. The Court held they cannot, for three independent reasons under the Second Circuit's three-element attorney-client privilege test (United States v Mejia, 655 F.3d 126 (2d Cir. 2011)):

First — no attorney: Claude is not an attorney. There is no attorney-client relationship between a user and an AI platform. Privilege requires "a trusting human relationship with a licensed professional who owes fiduciary duties and is subject to discipline."

Second — no confidentiality: The AI Documents were not confidential for two reasons: (a) communicating with a third-party platform in itself destroys confidentiality; and (b) Anthropic's privacy policy expressly reserves the right to collect inputs, use them for training, and disclose them to government regulatory authorities. The policy placed Heppner on notice that no reasonable expectation of confidentiality existed.

The Court explicitly addressed the argument that material which Heppner had received from counsel — and then fed into Claude — might retain its privileged character.

But even if certain information that Heppner input into Claude was privileged, he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party.

This is direct US authority for the proposition that feeding already-privileged information into Claude constitutes waiver.

Third — not for purpose of legal advice from Claude: Heppner created the documents on his own initiative, without being directed by his lawyers. The purpose of communicating with Claude was not to obtain legal advice from Claude.

The Court left open one significant question: had counsel directed Heppner to use Claude as a research tool, the communications "might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent within the protection of the attorney-client privilege." This question was not decided.

Work product doctrine also failed on two grounds: the documents were not prepared at the behest of counsel, and they did not reflect counsel's litigation strategy at the time of creation.

6. Comparative Assessment: Similarities and Divergences

6.1 Core Convergence — The Third-Party Principle

Despite operating through different doctrinal frameworks, all three jurisdictions converge on the same foundational proposition:

Sharing information with a publicly accessible AI platform is equivalent to sharing it with an unrelated third party. Where confidentiality is lost, privilege is waived or cannot attach.

6.2 Intention Is Irrelevant in All Three Systems

A consistent thread across all three frameworks is that the subjective intention of the party is irrelevant to the waiver analysis:

  • In Mann v Carnell and s 122, "inconsistency" is assessed objectively — it does not require that the party knew they were waiving privilege.
  • In UKUT 00081, the appellant did not intend to breach client confidentiality when decision letters were uploaded to ChatGPT; the Tribunal held the breach occurred regardless.
  • In Heppner, Heppner intended the AI Documents to be private preparation tools for trial; Rakoff J held this was immaterial — "non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel".

This convergence matters for Australian self-represented litigants: a genuine belief that the AI tool is private, or that the material will be used only for legitimate case preparation, does not prevent the loss of s 120 protection if the platform's terms do not support confidentiality.

6.3 The Confidentiality Requirement — Parallel Structure

The three systems approach confidentiality through different analytical lenses, but reach the same place:

  • Australian law: The confidentiality requirement in s 117 requires an obligation of non-disclosure. If the platform's terms do not impose such an obligation, the s 120 protection cannot arise for the AI communication; and if existing protection is undermined, s 122(2) provides the waiver mechanism.
  • UK law: Client confidentiality (a professional obligation) is destroyed by public domain placement.
  • US law: Anthropic's privacy policy is the specific legal instrument that destroys confidentiality by placing Heppner on notice that the platform is not a confidential repository.

The Heppner analysis is the most granular. By making the platform's own privacy policy the operative instrument of disclosure, Rakoff J provided a tool that is directly transferable to Australian proceedings: Anthropic's privacy policy applies to Australian users of Claude on the same terms. A court applying Heppner reasoning in the Australian context — as persuasive authority — would reach the same conclusion about Claude.ai conversations.

6.4 The Safe Harbour Question

All three systems recognise a distinction between public AI tools and closed enterprise AI tools with genuine confidentiality controls:

  • Australia: Section 122(5)(a)(i) provides a safe harbour where disclosure occurs in the course of making a confidential communication. A closed enterprise AI tool with appropriate contractual controls (no training use, limited human access, deletion rights, confidentiality obligations) can satisfy this.
  • UK: The Tribunal specifically identified Microsoft Copilot (deployed in a ringfenced environment) as a safer alternative that does not place information in the public domain.
  • US: Heppner implicitly recognises the distinction: the confidentiality failure turned on Anthropic's specific privacy policy terms for the public Claude AI agent. A platform that genuinely does not collect, retain, or share user inputs would be analytically different.

The practical guidance is consistent across all three jurisdictions: enterprise AI deployed under appropriate contractual protections presents lower risk, but is not risk-free.

6.5 The Counsel-Direction Distinction — Unique to Heppner

Heppner raises a question that has no direct counterpart in the UK case or the GPN-AI Practice Note: whether AI use directed by counsel occupies a different privilege position from unilateral client use.

This question has an Australian analogue in the requirements for litigation privilege (s 119): the protection extends to communications made for the dominant purpose of preparing for litigation, and is most readily attracted where a legal representative has directed the creation of the document. A document created on the client's own initiative, without a lawyer's direction, is more vulnerable to the argument that it does not attract litigation privilege.

  • AI output created by a self-represented litigant on their own initiative: no litigation privilege (no legal representative directing the work); s 120 protection potentially available but waivable under s 122.
  • AI output created by a represented party at the direction of a lawyer who controls the inputs and outputs: stronger argument for litigation privilege under s 119, potentially on an agency theory, subject to the confidentiality requirement still being met.

7. Conclusions and Practical Implications

7.1 Summary of Findings

The three frameworks — Australian (ss 120/122), UK (UKUT 00081), and US (Heppner) — are substantially aligned on the following propositions:

  1. Uploading privileged or confidential material to a public AI platform destroys the confidentiality that is the foundation of privilege protection. The legal mechanism differs (inconsistency under s 122 in Australia; public domain in the UK; privacy policy analysis in the US), but the practical result is the same.
  2. Subjective intention is irrelevant. The party's belief that the material is private, or that they are using AI only for legitimate purposes, does not prevent the loss of protection.
  3. Closed enterprise AI tools with genuine contractual confidentiality controls present lower — but not zero — risk. Section 122(5)(a)(i) in Australia, the Microsoft Copilot guidance in the UK, and the implicit contrast in Heppner all point in the same direction.
  4. AI conversations do not attract privilege merely because the user intended to share the outputs with a lawyer. Non-privileged material is not converted into privileged material by subsequent disclosure to counsel.
  5. Lawyer-directed use may attract protection in some circumstances, but this question is not settled.

8. What Is the Key Test?

If a member of the public can, by use of detailed and accurate prompts, retrieve your confidential/privileged content from a public AI system, then (as a practical matter) confidentiality has been destroyed and privilege is very likely gone. This is the key test.

In ENRC v Dechert LLP & ors (2022) EWHC 1138 at [670(3)], Mr Justice Waksman considered that if a solicitor and their client were to engage in a conversation on a crowded train whereby the surrounding public can hear their conversation, the inference "must be that there was no intention to treat it as confidential; the same would obviously apply if the advice was published".

At present, there is no case law which provides a definitive answer to the question of whether inputs into public AI systems could be confidential. However, there are helpful cases on other scenarios which may be relevant by analogy.

In the (non-binding but persuasive) Singaporean case of HT SRL v Wee Shuo Woon (which considered English case law), the court was asked to determine whether information which was published on Wikileaks as a result of a data breach could still be regarded as privileged and confidential, given that the information had entered the public domain. The Singaporean court held that just because information became public (in this case, part of a 500GB data leak), that did not mean that it would have actually been accessed by the public at large.

That notwithstanding, applying the reasoning of the Singapore court, confidential information inputted into a public AI system may not lose its confidential character (and therefore, its ability to benefit from the protections of LPP), as the inputs may not be accessible to other users of the system, or only accessible in very limited circumstances. In other words: confidentiality is theoretically but not practically lost.

Any challenge to litigation privilege where a lawyer enters confidential information into an AI LLM would need to prove the confidential information was accessible to the public.