[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83968-en":3,"doc-seo-83968-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83968,687197207639,"Asher","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Privilege and Confidentiality in Generative AI Workflows","Generative AI systems process client data through three distinct channels: training-based parameter memorisation, the live context window, and retrieval-augmented generation (RAG) via knowledge databases. Each channel produces different, often counter-intuitive confidentiality and legal professional privilege risks that require tailored governance responses. Drawing on leading UK and US privilege decisions and recent computer science research, the article explains these data modes for practitioners and links them to evolving information governance standards, negligence benchmarks, and solicitors’ regulatory duties in England and Wales.","Privilege and confidentiality in generative AI workflows  \nVáclav Janeček, University of Bristol Law School  \nThomas Melham, University of Oxford, Department of Computer Science  \nAcknowledgment. This article arose out of Dr Janeček’s research at the IGSG-CNR in Florence (Leverhulme International Fellowship) and the authors’ interdisciplinary teaching for the Oxford LawTech Education Programme.  \nAbstract. Generative AI (GenAI) systems store and process client data in three distinct ways: in the model’s parameters through training and memorisation, in the context window during a live session, and in knowledge databases for retrieval-augmented generation (RAG) . Each mode creates different and often counter-intuitive risks to confidentiality and legal professional privilege, and each calls for specific governance responses. Drawing on the first English and American decisions to address privilege and generative AI, UK and Munir v Secretary of State for the Home Department and United States v Heppner, on the orthodox privilege authorities against which those decisions must be read, and on recent computer science research, we explain the three modes of data storage and processing in terms accessible to practitioners and analyse the legal consequences of each. We then situate the analysis within the regulatory framework governing solicitors in England and Wales and within the ordinary principles of professional negligence, arguing that the standard of effective information governance (and with it the benchmark against which negligence and misconduct will be measured) is changing. Although we write primarily for SRA-regulated practitioners, our data-governance analysis is framed to extend to any jurisdiction in which the protection of privilege or professional secrecy depends on demonstrable confidentiality. The ultimate aim of this article is to help legal services professionals understand salient data leakage risks in GenAI systems and thereby facilitate amore responsible deployment of GenAI on client data and other sensitive material.  \nIntroduction  \nThe familiar phrases—‘rubbish in, rubbish out’ and ‘bias in, bias out’—capture a basic truth: the capabilities of AI systems, and of large language models (LLMs) in particular, are closely tied to the quality of the data from which they are built and to which they are given access. But the relationship between data and generative AI runs deeper than output quality, and it is this deeper relationship that should concern the legal profession. Wherever client data goes, the lawyer’s professional obligations go with it. And in generative AI systems, data moves in ways that are often invisible by design.  \nIn this article, we examine three distinct ways in which data—including confidential client data and personal data—is stored and processed in generative AI systems: (1) model memorisation;  \n(2) the context window; and (3) retrieval-augmented generation (RAG) . In relation to each, we identify data privacy and confidentiality risks that are easy to miss even for technically informed users and explain what practitioners can do about them in day-to-day work—with a view to maintaining data confidentiality and protecting legal privilege that may pertain to the data.  \nThe headline message is twofold. First, the risks are manageable, but only if one understands the difference between the three modes of data processing. A lawyer who cannot distinguish between data that is ‘baked into’ a model, data that transits a provider’s infrastructure during a session, and data that persists in a vector database, cannot make sound judgements about confidentiality, privilege or data protection compliance. Second, because generative AI systems pose new and unintuitive data leakage risks, information governance protocols need to be adjusted accordingly: the standard of what counts as effective data governance—and, by extension, what a reasonably competent practitioner must do to protect privileged and conf","cbCaifPoRo0WFs5r","https://ap.wps.com/l/cbCaifPoRo0WFs5r","pdf",579983,3,1,26,"English","en",105,"# Introduction\n## Three Modes of Data Processing\n## Headline Message and Governance Implications\n## Legal Context (Late 2025–Early 2026)\n## Terminology: Consumer- vs Enterprise-Grade Tools","[{\"question\":\"How does a generative AI model store and use client data in ways relevant to confidentiality?\",\"answer\":\"The article identifies three modes: model memorisation through training, the context window during a live session, and persistence in retrieval systems used for RAG. Each mode can create different confidentiality and privilege risks.\"},{\"question\":\"Why must lawyers distinguish between the three data-processing modes?\",\"answer\":\"Sound judgements about confidentiality, privilege, and compliance depend on understanding whether data is baked into a model, transits provider infrastructure during a session, or persists in a vector database. Without that distinction, information-governance decisions become unreliable.\"},{\"question\":\"What recent legal developments highlighted new disclosure and privilege risks when using AI tools?\",\"answer\":\"The Upper Tribunal warned that uploading confidential client documents to consumer-grade AI tools can breach confidentiality and waive privilege. Separately, US v Heppner held that consumer-grade chatbot interactions were not protected by attorney-client privilege or work product, and a High Court speech stressed that confidentiality cannot be assumed when public AI systems are used.\"}]",1784191726,66,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"privilege-and-confidentiality-in-generative-ai-workflows","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/privilege-and-confidentiality-in-generative-ai-workflows/83968/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"How does a generative AI model store and use client data in ways relevant to confidentiality?","Question",{"text":75,"@type":76},"The article identifies three modes: model memorisation through training, the context window during a live session, and persistence in retrieval systems used for RAG. Each mode can create different confidentiality and privilege risks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why must lawyers distinguish between the three data-processing modes?",{"text":80,"@type":76},"Sound judgements about confidentiality, privilege, and compliance depend on understanding whether data is baked into a model, transits provider infrastructure during a session, or persists in a vector database. Without that distinction, information-governance decisions become unreliable.",{"name":82,"@type":73,"acceptedAnswer":83},"What recent legal developments highlighted new disclosure and privilege risks when using AI tools?",{"text":84,"@type":76},"The Upper Tribunal warned that uploading confidential client documents to consumer-grade AI tools can breach confidentiality and waive privilege. Separately, US v Heppner held that consumer-grade chatbot interactions were not protected by attorney-client privilege or work product, and a High Court speech stressed that confidentiality cannot be assumed when public AI systems are used.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]