Is Claude Cowork Safe for Legal Work?
This is not legal advice.
Recent decisions of the Federal Circuit and Family Court of Australia (FCFCOA) and related federal jurisprudence reflect a developing body of case law addressing GenAI use in court documents and litigation conduct. The key points emerging are:
- The FCFCOA Appeal Division has expressly warned that entering draft documents into an AI program carries risks including breach of s 114Q, breach of the Harman undertaking, breach of rules concerning subpoena material, and waiver of legal professional privilege. (Mertz & Mertz (No 3) at [15]).
- The FCFCOA Appeal Division has also warned that inputting court documents into an "open AI program" may contravene Pt XIVB restrictions and that inputting documents into a GenAI program that "stores, collates and replicates data" may waive privilege, warranting "extreme caution". (Helmold & Mariya (No 2) at [9]).
- First instance decisions have applied these principles in the context of professional conduct, costs, and referrals to regulators where AI-generated hallucinated authorities were filed and relied upon, and where the Court was misled as to provenance and verification. (Tesar & Szep (No 3) at [23]–[25], [62]–[64]).
These authorities do not (yet) appear to include a definitive Australian holding that privilege was in fact waived on the facts solely because a party used a GenAI tool. However, the appellate guidance is clear that the risk is real, and courts are increasingly alive to the possibility that GenAI use may be treated as a form of disclosure inconsistent with maintaining confidentiality.
1. Family Court / FCFCOA Authorities: AI Use, Privilege Risk, and Pt XIVB Confidentiality
1.1 Helmold & Mariya (No 2) [2025] FedCFamC1A 163
In Helmold & Mariya (No 2), the Appeal Division considered an appeal in parenting proceedings where the self-represented appellant used GenAI to prepare written documents that cited fictitious cases. The Court emphasised that all litigants have a duty not to mislead the Court or opponent, and that reliance on unverified AI-generated research can mislead and waste time. (Helmold at [8]).
Critically for confidentiality and privilege, the Court stated:
"If a person inputs court documents into an open AI program, we consider that this may have the potential to fall foul of the provisions which prohibit communication of an account of proceedings to the public or a section of the public." (Helmold at [9]).
"In a similar vein, input of documents arising out of the proceedings into a generative AI program which stores, collates and replicates data may waive privilege or fall foul of the requirements that certain matters be treated as commercial in confidence. These issues warrant extreme caution." (Helmold at [9]).
This is a direct judicial warning that "open" GenAI use may be treated as a form of communication to the public (or a section of the public) and may also undermine privilege.
1.2 Mertz & Mertz (No 3) [2025] FedCFamC1A 222
In Mertz & Mertz (No 3), the Appeal Division dealt with costs and referrals to professional regulators after AI was used in preparing a Summary of Argument and List of Authorities, resulting in incorrect and misleading references. (Mertz at [1]–[12]).
The Court expressly identified broader risks in family law proceedings, including:
"There is a risk that entering draft documents into an AI program will result in a breach of s 114Q, a breach of the Harman undertaking, breaches of rules in respect of material produced under subpoena and/or give rise to a waiver of legal professional privilege." (Mertz at [15]).
The Court also referred to NSW Supreme Court Practice Note SC Gen 23 (28 January 2025) which prohibits entry into GenAI of information subject to non-publication/suppression orders, the Harman undertaking, subpoena material, or statutory publication prohibitions unless the practitioner is satisfied as to confidentiality and related matters. (Mertz at [15]).
The Court then set out "abundantly clear" propositions: if AI is used to identify authorities or draft submissions/footnotes/chronologies, practitioners must verify accuracy and relevance; AI use does not absolve professional obligations; and safeguards and disclosure must be carefully considered. (Mertz at [17]).
1.3 Tesar & Szep (No 3) [2026] FedCFamC1F 21
In Tesar & Szep (No 3), Brasch J dealt with a threshold hearing adjourned due to a solicitor-advocate filing submissions containing hallucinated authorities and initially misleading the Court about authorship and verification. The Court ordered referral to the Legal Services Commissioner and made indemnity costs orders personally against the solicitor-advocate. (Tesar at [4]–[17], Orders 1–4).
The decision is significant for present purposes because Brasch J expressly "echoed" and endorsed the Appeal Division's warnings in Mertz and Helmold about the risks of GenAI use, including the risk of waiver of privilege and breach of s 114Q / Harman / subpoena restrictions. (Tesar at [24]–[25]).
2. Privilege Waiver Risk: Why GenAI Use Is Being Treated as a Disclosure Problem
The above authorities frame privilege risk in practical terms: if draft documents, affidavits, submissions, or other litigation materials are entered into a GenAI system, the user may be:
- disclosing confidential/privileged information to a third party (the AI provider and/or its subcontractors); and/or
- placing the information into a system that may store, collate, replicate, or otherwise make the information accessible beyond the user's control.
The FCFCOA's repeated emphasis on "open AI programs" and systems that "store, collate and replicate data" indicates a concern that GenAI use may be treated as functionally equivalent to dissemination beyond the privileged relationship, thereby creating a real risk of waiver.
3. Family Law Confidentiality: Risk of Being Treated as "Publication to the Public or a Section of the Public"
Part XIVB of the Family Law Act 1975 (Cth) (including s 114Q) imposes strict limits on communicating to the public an account of proceedings that identifies parties, witnesses, or associated persons, subject to limited exceptions.
The Appeal Division's warning in Helmold that inputting court documents into an "open AI program" may fall foul of Pt XIVB reflects a concern that such input may be characterised as communication to "the public or a section of the public." (Helmold at [9]).
From a risk perspective, this is not limited to intentional publication. If a GenAI tool's architecture, retention settings, or sharing/collaboration features mean that court documents are accessible to persons beyond those permitted by Pt XIVB (or beyond the proceeding), the act of inputting the documents may be argued to be a prohibited communication.
4. Suppression Orders / Non-Publication Orders and "In-Flight" Proceedings (Including Subpoena Material)
The Mertz Court's express reference to suppression/non-publication regimes (via NSWSC Practice Note SC Gen 23) and to the Harman undertaking and subpoena material underscores that GenAI use can intersect with multiple confidentiality constraints beyond family law:
- Suppression/non-publication orders: where a court has restricted dissemination of information, inputting that information into a GenAI tool may be treated as a breach unless strict confidentiality controls are in place. (Mertz at [15]).
- Harman undertaking: material obtained under compulsory court processes is subject to an implied undertaking restricting use to the proceeding; uploading such material to GenAI may be characterised as an impermissible collateral use or disclosure. (Mertz at [15]).
- Subpoena material / restricted release: where documents can only be released with leave of the court or under rules limiting inspection/copying, GenAI ingestion may be inconsistent with those restrictions. (Mertz at [15]).
5. Implications for Claude Cowork
The Context Window
Large Language Models (LLMs) like Claude do not have continuous, long-term memory while running. Instead, they rely on a context window, a temporary "working memory" measured in tokens where 1 token is roughly 4 characters.
Everything the model needs to analyze — system instructions, chat history, files read, terminal outputs, tool calls, and its own previous responses — must fit inside this context window for a single request.
LLM APIs are completely stateless. The server hosting the model forgets who you are the millisecond it finishes streaming a response. It does not "remember" what was said two minutes ago or three turns back. To create the seamless experience of a continuous conversation or agentic workflow (like Claude Cowork), the front-end client must re-transmit the entire conversation history back to the model on every single prompt.
Training Data Opt-Out
For consumer plans (Claude Free, Pro, and MAX), model training options are managed directly in the account settings via the "Help improve Claude" privacy toggle. Under Anthropic's consumer data policies, users who leave this toggle enabled allow their de-identified prompts and completions to be stored for up to 5 years to train future foundation models. Disabling the toggle opts the user out of model training entirely. In contrast, the commercial tiers Claude Team and Enterprise are governed by strict commercial terms where customer inputs and outputs are never used for model training under any circumstances, eliminating the need for manual opt-out toggles.
Chat and Prompt Logs
Chat logs are retained on back-end systems for 30 days before permanent deletion (or deleted immediately if the user manually removes the chat from their history). All chats and any documents attached or cut and pasted into the chat are recorded in the LLM server logs.
All Claude Cowork plans enforce a default 30-day retention window to support operational debugging and trust and safety reviews. For enterprise clients handling proprietary code, intellectual property, or regulated data, qualifying organizations can execute a Zero Data Retention (ZDR) addendum. Under ZDR, prompt and response payloads exist solely in volatile RAM during inference processing and are wiped immediately upon completion, bypassing persistent disk logging altogether.
Even under ZDR agreements, specific compliance and safety carve-outs remain active. Automated real-time safety classifiers evaluate incoming prompts in volatile memory before output generation; if a payload triggers an alert for severe policy violations (such as active cyber threats or extreme harm), that isolated transaction is carved out of ZDR and retained for Trust & Safety review. Furthermore, non-content operational metadata, including token counts, organization IDs, IP addresses, and safety classification scores, is retained separately to maintain system infrastructure, enforce rate limits, and meet statutory reporting obligations.
What Does All This Mean for Legal Practitioners?
Training Data
If a legal practitioner inputs client-confidential facts, draft pleadings, or privileged advice into an AI tool that uses customer inputs for model training, those prompts can be absorbed into the model's parameters. Through iterative training, specialized prompt extraction, or safety evaluations, aspects of that information could theoretically be surfaced to third parties.
Legal practitioners using the Claude Cowork free, Pro and MAX consumer plans must ensure that the training data opt-in is disabled or, alternatively, sign up to the Claude Team or Enterprise plans. Opting out and/or relying on terms in the Team and Enterprise plans that contractually forbid model training and unauthorized third-party sharing establishes that the legal practitioner took reasonable, affirmative measures to preserve client confidentiality, thereby protecting against an inadvertent waiver of privilege.
Chat Logs
All logs, conversation histories, and database payloads stored by Anthropic are encrypted at rest using AES-256 GCM (Advanced Encryption Standard with 256-bit keys). Encryption at rest protects data against physical disk theft, unauthorized hardware access, or raw infrastructure breaches at the cloud datacenter level. Encryption at rest prevents unauthorized external actors from reading raw storage. However, when an authorized application or an authorized employee with system-level access queries the database, the storage system decrypts the data using the managed keys and presents it in plaintext.
Can Anthropic employees access the chat logs during the 30-day storage period?
Yes, under certain conditions. Anthropic operates under a policy of restricted access governed by internal compliance, SOC 2 Type II controls, and ISO 27001 security standards. Employees cannot freely browse, search, or read user conversation logs for general interest or curiosity.
Anthropic's security framework and Privacy Policy restrict human access to customer conversation logs to specific, justifiable operational and legal scenarios:
- Trust & Safety / Policy Violations: If an automated real-time safety classifier flags a prompt for potential severe breaches of usage policy (e.g., exploitation, illegal acts, or cyber threats), authorized Trust & Safety team members may review the flagged content to evaluate platform safety.
- Technical Support & Debugging (User-Initiated): If a user or enterprise client opens a support ticket or reports a bug, Anthropic engineers may access specific session logs only after obtaining the user's explicit consent or authorization.
- Legal Process & Compulsory Demands: Anthropic personnel will access and produce stored logs if compelled to do so by a valid legal process — such as a court order, search warrant, grand jury subpoena, or statutory government mandate.
- Security & System Integrity Maintenance: A narrow subset of cleared infrastructure engineers may access system-level logs during active security incidents, breach investigations, or critical infrastructure outages under strict audit logging.
When an authorized Anthropic employee does access customer logs:
- Role-Based Access Control (RBAC): Access is limited to specific staff members with role-based entitlements; general staff have no access.
- Justification & Access Requests: Employees must submit a documented business or safety justification to temporarily elevate access privileges (Just-In-Time access).
- Immutable Audit Logging: Every human read operation on customer log databases is recorded in immutable, monitored audit logs. Unauthorized or unjustified access attempts trigger internal security alarms and constitute grounds for termination and legal action.
Is Anthropic a Data Processor?
Anthropic operates under the exact same legal, technical, and regulatory framework as traditional cloud storage providers (Microsoft OneDrive, Dropbox, AWS) and specialized legal technology platforms (Clio, LEAP).
When a legal practitioner uses Claude (under commercial terms or with model training opted out), Anthropic acts legally as a Data Processor (or service provider). Under this relationship, Anthropic employees are bound by the same structural and contractual restrictions that protect litigation privilege across the legal tech industry.
Standard legal principles establish that disclosing confidential communications to a third-party technology vendor solely for processing or storage under a strict obligation of confidentiality does not waive legal professional privilege. The vendor acts as an extension of the practitioner's administrative infrastructure.
How Does Claude Cowork Compare to Microsoft Outlook 365 in the Context of Legal Professional Privilege?
Legal firms commonly host their email system on the Microsoft Outlook 365 Cloud platform. Microsoft support engineers, system admins, and developers do not have permanent administrative rights or access to customer mailboxes, Exchange databases, or tenant accounts. If an issue requires human engineer intervention, the engineer must request temporary, time-limited elevated access via automated internal workflows. Access requires internal manager approval, is locked to a specific support ticket, and expires automatically. Under these conditions a Microsoft employee may access a law firm's email without the permission or knowledge of the law firm.
If a firm enables Customer Lockbox in Microsoft 365, the access workflow requires an extra step: the law firm's designated admin must explicitly click "Approve" in the admin portal before the Microsoft engineer is granted access. If the firm ignores or denies the request, access is blocked automatically. However, Customer Lockbox requires E5 / Compliance Add-ons: it is not available in basic SMB plans (like Business Premium or E3). It requires Microsoft 365 E5 or specialized E5 Compliance / Information Protection & Governance add-ons. An estimated 5% of boutique/small practices (<50 users) switch on Lockbox because most small firms are on lower-tier licensing. An estimated 15–25% of mid-market firms (50–200 users) switch on Lockbox. An estimated ~40–50% of BigLaw/enterprise firms (500+ users) switch on Lockbox. Customer Lockbox is set to off by default.
Microsoft can be served a warrant or subpoena demanding access to MS Outlook 365 email databases hosted on Microsoft Azure cloud servers. Under the CLOUD Act, US authorities can compel data held by a US provider regardless of where it physically sits, and a non-disclosure order can bar Microsoft from telling you. Microsoft's policy is to redirect requests to the enterprise customer and to challenge indefinite gag orders. In or around 2016, Microsoft revealed it was subject to 2,600 US Federal Court secrecy orders relating to subpoenas targeting Microsoft customers over a single 18-month period.
What About Double Key Encryption for Microsoft Email?
Microsoft does offer Double Key Encryption (DKE) whereby two private keys are required, one managed by Microsoft in Azure, and a second key held strictly by the organization. To encrypt or read a DKE-protected email, both keys are required. If either key is missing, the email remains unreadable ciphertext. The Customer Key is generated, stored, and managed entirely within the client's own infrastructure, typically on an on-premises web server, a private local datacenter, or a third-party Hardware Security Module (HSM) completely isolated from Microsoft Azure.
Because Key 2 never touches Microsoft's cloud or disk infrastructure, Microsoft has no technical capability to decrypt the email. If Microsoft receives a government warrant, search order, or subpoena for Exchange Online mailbox data, any DKE emails returned will be completely unreadable ciphertext. Microsoft cannot comply with a decryption demand because it does not possess the second key.
Double Key Encryption (DKE) industry usage benchmarks and Microsoft's official architectural guidelines indicate that adoption is very low — less than 1% to 2% of Microsoft's total enterprise customer base.
The main reason adoption remains locked to a tiny niche comes down to licensing costs (requires top-tier Microsoft 365 E5) combined with the severe operational trade-offs required to host and maintain a custom, on-premises or private-cloud key service. While DKE provides absolute data sovereignty, it disables almost all server-side M365 functionality because Exchange Online cannot read the contents of the email. Because Exchange Online and Microsoft 365 cloud services are completely blind to the actual text content of a DKE email or document, applying DKE disables almost every automated cloud productivity, search, compliance, and AI tool in the Microsoft ecosystem. For example, Microsoft Copilot is strictly blocked from analyzing, summarizing, or interacting with DKE-encrypted emails or attachments — even if you open a DKE document in desktop Word or Outlook, Copilot features inside those apps are automatically disabled. Exchange Online Protection (EOP) cannot inspect the email body or attachments for malicious code, phishing links, or malware.
Conclusion
Evaluated through the lens of cybersecurity risk management, using Claude Cowork with training data opt-outs enforced offers a significantly smaller data exposure surface than maintaining a standard Microsoft 365 Outlook environment.
In Outlook 365, a law firm's mailboxes typically store decades of cumulative, highly confidential client correspondence, privileged advice, and unencrypted attachments permanently at rest on cloud servers, creating an enormous, attractive target for subpoena demands, business email compromise (BEC), and retrospective data breaches.
By contrast, an agentic task execution in Claude Cowork operates on ephemeral, short-term data flows: once training opt-outs are active, the session payload is bound to a strict 30-day operational retention window (or erased instantly under Zero Data Retention) before being permanently purged. Consequently, even in the worst-case scenario of an infrastructure compromise or legally compelled disclosure order, an adversary or court order targeting Anthropic can only harvest a tiny, temporary slice of recent working context, whereas a compromised Outlook environment exposes a firm's entire historical catalog of legal secrets.