The Duty That Shall Not Be Named: The Inversion of Confidentiality


Jun 08, 2026
Podcast Photo

By: Christopher D. Warren

Moral Machine Setlist

The Rules of Professional Conduct were built on a comfortable fiction: that each lawyer is responsible for their own conduct, and that the cleanest path to ethical practice is to read your own rules and follow them. RPC 1.6(a) provides that “a lawyer shall not reveal information relating to representation of a client unless the client consents after consultation,” a duty owed by the lawyer to the lawyer’s own client, executed by the lawyer alone. The work product I send to opposing counsel is typically governed by a protective order and by their independent obligations. That was the architecture, and for most of the profession’s history it was enough.

Generative AI has now broken that architecture.

The Inversion

The current discourse on AI competence treats the using lawyer as the locus of risk. Nearly every published opinion, from the NYC Bar’s first AI opinion through ABA Formal Opinion 512 and New Jersey’s January 2024 Preliminary Guidelines, frames the analysis as if the only lawyer in the room with an AI tool is the one being advised. Be competent per RPC 1.1. Don’t breach RPC 1.6. Supervise your associates under 5.1 and 5.3. Vet your vendor. Read the terms. Do not file hallucinated citations (come on everyone, this isn’t that hard), etc., etc., etc., and so on and so forth.

Useful instructions, all sharing a single blind spot: they assume the material at risk is your own client’s, and that the person deciding how to handle it is you. They ignore the elephant in the room: the attorney who does not know how to use AI and refuses to learn, and I would bet on a heavy overlap between that class of attorney and the published hallucinations, along with their equally unbound and uninformed clients.

Consider the inverse scenario: I produce documents to opposing counsel under a protective order. The production holds my client’s trade secrets, financial records, and internal communications. I have done everything the rules require. I vetted my own tools, trained my associates, and negotiated the order with care. None of it matters, because opposing counsel, or their client, paste-drops the production into a free-tier chatbot to summarize it for a meeting. My client’s confidential information now sits in a training corpus, a retention log, or an inference cache that neither I nor opposing counsel controls, and possibly never will.

No matter how carefully a competent (within the scope of RPC 1.1) attorney protects their client’s confidential information, carelessness on the other side of the v can blow it all open, and there is no mechanism to stop it.

This Is No Longer Hypothetical

For most of this problem’s short history, that scenario was a thought experiment. As of February 2026, it is law.

On February 10, 2026, two federal courts confronted what happens when litigation material is fed into a consumer AI platform. In United States v. Heppner, Judge Rakoff of the Southern District of New York ruled from the bench that a litigant who used a public AI tool to prepare case materials had destroyed any reasonable expectation of confidentiality, because the platform’s own terms permitted it to collect inputs, train on them, and disclose them to third parties. The written opinion followed on February 17. Privilege and work product were both lost. The court reached for no special AI doctrine to get there, relying instead on the oldest rule in the privilege book: voluntary disclosure to a third party who owes you no duty of confidentiality waives the protection.

The same day, in Warner v. Gilbarco, a magistrate judge in the Eastern District of Michigan came out the other way on different facts, holding that a pro se litigant’s use of an AI tool to draft her own filings did not by itself waive work product, because such tools are instruments rather than persons. Reasonable judges can disagree about waiver, and these two did.

Notice the analytical move in Warner, because I think the court got it wrong. The defendants moved to compel the plaintiff’s AI queries and outputs, arguing that feeding litigation material into a public chatbot waived any protection. The court refused, drawing the line that attorney-client privilege and work product are waived differently: privilege falls on disclosure to any third party, but work product falls only on disclosure to an adversary. Because a generative-AI tool is an instrument and not a person, the court reasoned, uploading to it is not disclosure to an adversary, and the protection held.

That “tool, not a person” line is where the analysis breaks down. A public chatbot is not a neutral instrument like a calculator or a word processor; it is a service operated by a third party whose terms reserve the right to retain inputs, train on them, and disclose them onward. Treating the upload as a private act of drafting, rather than a disclosure to the company behind the model and everyone its terms permit, ignores where the data actually goes. Heppner, looking at the same kind of conduct through the privilege lens, saw that plainly. Warner did not, and a producing lawyer in New Jersey should not assume a court here would follow it.

The strongest objection cuts at this article’s premise that the upload itself is the catastrophe. In a Harvard Law Review Blog essay, Elizabeth Guo argues that Heppner’s confidentiality reasoning proves too much: if sending material through a third party that can technically access it destroyed confidentiality, Gmail and iCloud would have destroyed it long ago. She adds that users can opt out of training and retention, that providers de-link inputs, and that a trained model keeps no retrievable transcript, so the paste may not be the irreversible exposure the alarm assumes. I think Heppner was right on its record, but whether the objection wins matters less than the fact that careful readers disagree at all. When two federal judges and a Harvard commentator examine the same technology and reach three answers, the producing lawyer is left to gamble her client’s confidences on facts she cannot see and a forum that has not yet ruled. A protection that contingent is closer to a coin flip than a standard of care, which is the clearest reason to fix the rule in advance, by protective order and advisory opinion, rather than discover it one breach at a time.

That uncertainty is the reason this article exists. The duty a careful lawyer needs already exists; it has simply never been read this way.

The Rules Nobody Reads This Way

The threshold objection is textual, and it is the one every careless adversary will reach for: RPC 1.6 protects my client, not theirs, so why should opposing counsel owe any duty regarding documents I produced to them? On the face of the rule, they do not. But RPC 1.6 was never the only source of the obligation. Four other provisions supply it, and together they close the gap.

RPC 4.4(a). In representing a client, a lawyer “shall not use means that have no substantial purpose other than to embarrass, delay, or burden a third person, or use methods of obtaining evidence that violate the legal rights of such a person.” Feeding an adversary’s protected material into a system that retains it, trains on it, or transmits it to third parties is such a method, and it violates the producing party’s rights under the protective order, under privacy law, and under whatever confidentiality regime travels with the data.

The protective order itself. Where material is designated confidential, the order binds the receiving lawyer directly, and an AI-upload restriction written into that order binds them just as firmly. That restriction is an enforceable term of a court order, backed by the contempt power.

RPC 8.4(d). It is professional misconduct for a lawyer to “engage in conduct that is prejudicial to the administration of justice.” That reaches the lawyer who quietly exposes an adversary’s material to an opaque model in a way the producing party can neither detect nor undo. Discovery runs on the shared confidence that produced material stays inside the case. Defeat that confidence, and the harm runs past carelessness to the integrity of the process the court and the litigants rely on.

RPC 1.1, running back to the careless lawyer’s own client. New Jersey’s RPC 1.1 does not impose the Model Rule’s affirmative competence standard; it prohibits handling a matter with gross negligence and exhibiting a pattern of neglect, and the expectation of technological competence here rests on the January 2024 Preliminary Guidelines and the general duty of diligent representation. A receiving lawyer who mishandles an adversary’s production exposes their own client to sanctions, fee-shifting, and disqualification. So competence and diligence require getting this right. The lawyer who treats the other side’s documents as free data is failing their own client at the same moment they are wronging mine.

New Jersey Has Been Here Before

The strongest answer to the lawyer who says “I owe your client nothing” is that New Jersey rejected that position years before generative AI existed.

RPC 4.4(b) requires a lawyer who receives a document and has reasonable cause to believe it was inadvertently sent to stop reading it, promptly notify the sender, and return it. New Jersey’s rule is stronger than the ABA Model Rule, which requires only that the receiving lawyer notify the sender; New Jersey adds the duties not to read and to return. New Jersey backs that duty with the bluntest remedy available. In Estate of Kennedy v. Rosenblatt, 447 N.J. Super. 444 (App. Div. 2016), the Appellate Division held that a lawyer who reviews the substance of an adversary’s protected file risks disqualification, while a lawyer who merely accesses metadata showing who opened the file, in order to screen for a conflict, does not. That line is the line that matters here: exposure to protected content, not incidental contact with a file, is what triggers the remedy. And the remedy has teeth. In Cavallaro v. Jamco Property Management, 334 N.J. Super. 557 (App. Div. 2000), the court explained, in a case arising under the discovery rule R. 4:14-7(c), that lesser sanctions such as fee or expense awards fail to address the harm of a lawyer’s access and exposure to privileged documents, which is why disqualification is the response when a lawyer improperly obtains an adversary’s confidential material. The discovery rules say the same from the other direction: a party notified that produced information is privileged must return, sequester, or destroy it and stop using it until the claim is resolved. R. 4:10-2(e)(2).

The principle is settled, and the AI scenario is the stronger case for it. RPC 4.4(b), Kennedy, and Cavallaro all govern a lawyer who receives privileged material by mistake, through no fault of the producing side. If New Jersey imposes return-and-notice duties on the lawyer who never asked to receive that material, and disqualifies the one who exploits it, those duties apply with even greater force to the lawyer who takes a production made lawfully and routes it into a system that can neither recall it nor forget it. A generation ago, the careless version of this was reading a misdirected fax, a problem that stayed small, local, and recoverable. The same carelessness today routes protected material into a system whose retention is unilateral, whose training is irreversible, and whose outputs may surface in a stranger’s session that no auditor will ever see. The duty has not changed. What has grown is the radius of the damage an AI-illiterate attorney or their client can do.

The Protective Order Does the Real Work

The Rules supply the backdrop. The enforceable instrument is the protective order, and after Heppner and Warner there is no excuse for treating AI provisions as optional. The provisions worth fighting for:

  • A prohibition on inputting produced material into any AI system that retains inputs, trains on inputs, or shares them with third parties.
  • An approved-tool list limited to enterprise platforms with contractual non-training and non-retention commitments and audit rights.
  • Log-preservation requirements for any permitted AI use, so a forensic record exists if a breach is later suspected.
  • Notice and remediation obligations triggered by any non-conforming input, modeled on the claw-back and breach-notification frameworks the bar already knows.
  • Sanctions language naming AI misuse expressly, so a court need not improvise a contempt theory for what is, in substance, an industrial-scale disclosure.

A protective order that does not address AI is, in 2026, a protective order that does not actually protect and does not satisfy practice requirements for a modern attorney.

The following provision may be adapted to the conventions of any protective order:

Use of Artificial Intelligence

No Receiving Party shall input, upload, submit, or otherwise disclose any material designated “Confidential” or “Highly Confidential – Attorneys’ Eyes Only” under this Order, in whole or in part, into any artificial-intelligence system, service, model, or feature that (a) retains user inputs, (b) uses inputs to train, fine-tune, or otherwise improve any model, or (c) transmits or makes inputs available to any third party. Notwithstanding the foregoing, a Receiving Party may use an artificial-intelligence tool with Protected Material only where the tool is operated under an enterprise agreement that contractually prohibits training on, and retention or third-party disclosure of, the inputs, and the Receiving Party maintains a contemporaneous log identifying the tool, the user, the date, and the Protected Material involved, which log shall be preserved for the duration of this litigation and produced to the Producing Party upon request. Any input of Protected Material that does not conform to this provision shall be treated as an unauthorized disclosure; the Receiving Party shall, within five (5) business days of discovery, notify the Producing Party in writing, identify the material and the system involved, and take all reasonable steps to recall, delete, or sequester the material. A violation of this provision shall be subject to the full range of remedies available for violation of this Order, including sanctions and a finding of contempt.

A Prediction About Reporting

Here I shift from describing the rules to predicting where they go, and I will mark the shift plainly because the prediction is an uncomfortable one: an attorney who does not know how to use AI tools, and will not learn, is edging toward malpractice.

RPC 8.3(a) requires that “a lawyer who knows that another lawyer has committed a violation of the Rules of Professional Conduct that raises a substantial question as to that lawyer’s honesty, trustworthiness or fitness as a lawyer in other respects, shall inform the appropriate professional authority.” Nothing yet says that a lawyer who routinely dumps opposing counsel’s productions into a consumer chatbot crosses that line, and the reflex is to call it carelessness rather than a fitness problem. My prediction is that the reflex will not hold. A lawyer who repeatedly mishandles confidential information through a foreseeable, well-publicized, and now judicially documented failure mode is not merely careless; they are demonstrating a deficiency in competence serious enough that, at some point, the lawyer who watches them do it will have to ask whether 8.3(a) requires picking up the phone. That the failure involves a glowing rectangle and a free-tier subscription will not soften that conclusion for long.

The Architecture Problem

The Rules were drafted for self-contained professional conduct, where the worst a careless adversary could do with your production was misfile it or leave it in a cab or hotel bar. That world is gone. The same adversary can now, in just a few keystrokes and mouse drags, route your client’s confidences into a model whose training is irreversible and whose downstream use is unknowable. Heppner shows the privilege evaporating on contact. Warner shows that work-product protection can survive AI use when the doctrine’s elements are met, but only on facts a producing lawyer cannot count on. The producing lawyer, meanwhile, has no practical way to know the breach happened until it surfaces somewhere it should not.

This is why AI-native firms have already solved the client-side version of this problem. Falcon Rappaport & Berkman, for one, offers its clients a Harvey Shared Space: a secure, confidential environment, governed by the firm, where a client can work with AI on its own matter without routing anything into a consumer tool.

The point is less the sophistication of the tool than the fact that it exists, because the careless paste tends to happen only when no careful alternative is within reach. Keeping AI out of litigation will not solve this, and would not be worth it if it could; that ship has sailed, and the tools are too useful to abandon. Law firms that still haven’t gotten it will eventually implode as talent disappears, and attorneys who are still wrinkling their nose at it and pearl clutching will be out of work. The workable course is to give lawyers and clients a tool that does not create the breach in the first place, which is exactly what a privileged, non-retaining alternative does.

This is why New Jersey needs an advisory opinion, and needs it before the issue is settled by accident in a discovery fight no one planned as a test case. Heppner and Warner show that left to improvise, courts will reach opposite results on the same conduct, and Warner shows they can get it wrong. An advisory opinion can do what case-by-case waiver rulings cannot: state plainly that a lawyer’s duty of care runs to the confidential material of every party whose production passes through their hands, and that routing an adversary’s designated material into a retaining, training, or disclosing AI system breaches it. Such an opinion would also shift the vantage point. The lawyer worth centering is the one whose client is harmed by an adversary who uses AI badly, not the one who uses it well. That is where the Rules are most absent, and where the standard of care is being written in real time, one careless paste at a time.

The duty of confidentiality has always run in one direction, from the lawyer to the client. AI forces us to take seriously a second direction the Rules never named: the duty owed by every lawyer to every other lawyer’s client, by virtue of the plain fact that material moves between us. Until that duty is named, the Rules will keep protecting the lawyers who least need it, and keep leaving exposed the clients who did nothing wrong except be represented by the careful side of the v.

References

Cases

Cavallaro v. Jamco Prop. Mgmt., 334 N.J. Super. 557 (App. Div. 2000) (under the discovery rule R. 4:14-7(c), lesser sanctions such as fee or expense awards inadequately address the harm of a lawyer’s exposure to privileged documents, so disqualification is the appropriate remedy).

Estate of Kennedy v. Rosenblatt, 447 N.J. Super. 444 (App. Div. 2016) (reviewing the substance of an adversary’s protected electronic file can warrant disqualification, while accessing metadata that merely shows who opened the file, in order to screen for a conflict, does not).

United States v. Heppner, No. 25-cr-00503 (JSR), Dkt. No. 27 (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.) (defendant’s use of a consumer AI tool to generate case materials waived attorney-client privilege and work-product protection; ruled from the bench Feb. 10, 2026, with a written opinion following on Feb. 17, 2026).

Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026) (Patti, M.J.) (denying the portion of defendants’ motion seeking the pro se plaintiff’s AI queries and outputs; use of a generative-AI tool did not waive work-product protection because such tools are “tools, not persons” and work-product waiver requires disclosure to an adversary).

Christopher D. Warren is the New Jersey Managing Partner and Co-Chair of the Artificial Intelligence Practice Group at Falcon Rappaport & Berkman LLP. He writes on AI governance and legal ethics at The Moral Machine. He serves on the New Jersey Supreme Court Attorney Ethics Committee (District VI), chairs the Hudson County Bar Association Artificial Intelligence Committee, and serves on the New Jersey State Bar Association Committee on Artificial Intelligence and Data Privacy. The views expressed on The Moral Machine are the author’s own and do not reflect those of the New Jersey Supreme Court Attorney Ethics Committee (District VI) or Falcon Rappaport & Berkman LLP.

DISCLAIMER: This summary is not legal advice, and does not create any attorney-client relationship. This summary does not provide a definitive legal opinion for any factual situation. Before the firm can provide legal advice or opinions to any person or entity, the specific facts at issue must be reviewed by the firm. Before an attorney-client relationship is formed, the firm must have a signed engagement letter with a client setting forth the Firm’s scope and terms of representation. The information contained herein is based upon the law at the time of publication.