AI and attorney-client privilege.
A plain-English guide for law firms and in-house counsel.
The value of a legal AI is that it reads and reasons over your most sensitive material: privileged memos, deposition transcripts, deal documents, investigation files. That is also the risk. The moment privileged work is pasted into a public or cloud AI tool, it leaves the firm and lands with a third party you do not control. This is a guide to what that actually exposes, what an on-premise AI changes, and how to tell the difference.
The cloud problem, stated plainly
A public AI tool is a service running on someone else's servers. When a lawyer types into it, the text travels out of the firm to that vendor, where it may be logged, retained for a period, reviewed by staff or contractors, sub-processed by other companies, or used to improve the vendor's systems. Enterprise agreements narrow some of this, but the underlying shape does not change: the privileged material has left your control and now sits, at least transiently, somewhere you cannot inspect.
Does that waive privilege?
Whether disclosure to an AI vendor waives attorney-client privilege is a fact-specific legal question, and the law is still developing. We are not going to hand you a settled answer, because there is not one yet. What we will say is narrower and safe: sending privileged material to a third party creates an argument that did not exist before, and a conservative posture avoids creating it. If the material never leaves the firm, there is no disclosure to a third party to litigate over in the first place.
Discovery and retention are the quieter risk
Waiver gets the headlines, but the steadier exposure is retention. Anything stored by a vendor becomes a potential source of discovery, a target for a subpoena, and one more place a breach can reach. A firm that cannot say where its privileged prompts and documents are held, for how long, and who can read them, has taken on a records-management problem it did not have before, on behalf of every client whose matter passed through the tool.
What on-premise changes
An on-premise AI flips the direction of the data. The model runs on a system that sits inside the firm's own control, and prompts and documents are read and answered right there, with no outbound path to a vendor. Nothing is logged elsewhere, retained elsewhere, or available to anyone outside the firm, because nothing leaves. The privilege question does not get easier to argue; it stops arising, because there is no third-party disclosure to argue about.
How to evaluate a claim like this
Do not take "private" on faith. Ask a vendor three concrete questions. Where is the model actually running, on our hardware or theirs? Is there any outbound network path once it is installed, and can we watch it? After you set it up, who retains access, including you? The honest test is physical: a genuinely isolated system keeps answering with the network unplugged, and a demonstration anyone in the room can run beats any assurance on paper. See exactly what a Garnet build can and cannot see and, for the strict cases, what air-gapped actually means.
The honest tradeoffs
An on-premise system is not free and is not magic. It is a real build that has to be sized, installed, and kept working after the person who set it up moves on, and updates arrive deliberately rather than streaming in. It does not, by itself, discharge a firm's broader security and ethical obligations; those still belong to you. What it does is remove the single largest new exposure that cloud AI introduces, so the remaining work is the ordinary diligence a firm already knows how to do. For an honest side-by-side of commissioning a build against assembling one yourself, see build versus buy.
How a commissioned build gets there
Standing up a private AI a firm would stake privileged work on is an engineering project: sizing and sourcing the system, tuning a capable local model to legal work, hardening the boundary so nothing phones home, and building something durable. A Garnet build is a private AI installed on a dedicated system inside your office, network-isolated by default, with no standing access for anyone, including us, after handover. For the way this is scoped for firms and in-house teams, see on-premise AI for law firms and in-house teams, and for the underlying document work, confidential document review.
Commissioned; scoped and priced individually. A conversation, not a checkout.