When people in an organisation use AI tools such as ChatGPT or Claude, where their providers may unrestrictedly use prompt content, there is a risk that confidential communications with external lawyers can lose their legal protection.
A Netherlands court in Rotterdam ruled that entering information into an unmanaged AI system can be treated as disclosing it since third parties may gain access to this material, which would otherwise be shielded from disclosure.
The issue
When a company engages an external lawyer, their communications are legally protected under legal professional privilege (verschoningsrecht). Under Dutch law, this privilege attaches to the external lawyer, not to the client or the organisation. The Dutch court ruling confirmed that if anyone in the organisation compromises the confidentiality of those communications, including by using a consumer AI tool, this protection can be lost.
Rotterdam decision
On 12 June 2026, a judge at the Rotterdam District Court (ECLI:NL:RBROT:2026:9319) ruled on the following case. During a criminal investigation, investigators reviewing seized devices discovered that a suspect had used ChatGPT to draft a message intended for his lawyer. The suspect had typed his instructions into ChatGPT and asked it to generate a response to send to his legal counsel.
The examining magistrate held (emphasis added): "Legal professional privilege is based on the principle that the societal interest in establishing the truth in legal proceedings must yield to the societal interest that everyone should be able to freely and without fear of disclosure consult the relevant professionals for assistance and advice. An external AI system, such as OpenAI, of which ChatGPT is a product, stores both the inputted and generated information and may subsequently use it for purposes such as training the AI model. Entering (potentially) privileged information into ChatGPT, as well as having a text generated that is intended for a privilege holder, can be regarded as disclosing such information. This breaches the confidentiality of the information. The consequence is that the information loses its confidential character and therefore, where applicable, can no longer be classified as privileged information."
The result is that the ChatGPT conversations lost their protected status and were handed over to the prosecution.
Implications
This is a first-instance decision, and another judge could reach a different conclusion. The court’s reasoning builds directly on Supreme Court’s case-law. In its ruling of 25 November 2016 (ECLI:NL:HR:2016:2686), the Supreme Court held that documents ‘intended’ for a lawyer can be protected even before they are shared: the ‘destination’ of the information is sufficient. The Rotterdam court applied the same principle from the opposite direction. If the information has already been disclosed to a third party (i.e. provider of ChatGPT) the intended destination is no longer pertinent. The confidentiality on which privilege depends has been broken before the communication ever reaches the lawyer.
In short, the 2016 ruling expanded privilege by looking at where information was going. The 2026 decision limits it by looking at where information has been. The decision should be seen as existing legal principles applied to new technology and may well be upheld on appeal.
Why this matters for your organisation
Although this case arose in a criminal investigation, the principle applies equally to civil and regulatory proceedings, and is not unique to the Netherlands. Wherever legal professional privilege plays a role, the unrestricted use of AI tools creates the same risk. Any jurisdiction that protects lawyer-client confidentiality must grapple with the question of whether entering privileged information into an AI tool constitutes disclosure.
The risk is concrete and applies across the organisation, such as in the following examples:
- civil and regulatory proceedings, where opposing parties or regulators (e.g. AFM, ACM, DNB, Dutch Data Protection Authority) may argue that AI-processed communications are no longer privileged, whether in the context of disclosure claims, evidence seizure orders, or regulatory investigations;
- internal investigations and due diligence processes, where employees may use AI tools to prepare or discuss legal matters without realising the implications of privilege.
As a result, if anyone in your organisation uses a publicly available AI tool to prepare communications for external counsel, there is a real risk that those communications lose their privileged status. Your AI governance framework is no longer just an IT or compliance matter, but could affect your legal position.
What your organisation should do
- Ban the use of unauthorised AI tools, especially for anything related to legal advice. Tools that do not meet specific business required protections and standards such as ChatGPT and similar AI tools must not be used to draft, discuss or prepare communications with external lawyers. This applies across the organisation, not just to the legal department.
- Update your AI use policy to address privilege risk and document your safeguards. Many AI policies focus on data protection and IP, but few address the risk to legal professional privilege. Your policy should explicitly state which AI tools are approved for use in connection with legal matters, the channels that communications with external lawyers must take place, and the information that should be given to employees about this. Document these safeguards since the Supreme Court has indicated that courts may consider whether a privilege holder has taken appropriate measures to protect confidential communications.
- If you want to use AI for legal work, choose an enterprise solution and verify the contract. Enterprise AI solutions, AI systems that meet specific business standards, typically keep data in a separate environment and do not use it for training. But “enterprise” does not automatically mean “safe”. Hence, companies are advised to ensure that the AI procurement process of each includes a privilege-risk assessment, which answers the following questions. Does the provider offer legally binding guarantees that input data will not be stored or used for training? Are these guarantees contractual, or merely policy statements that can be changed unilaterally?
- Coordinate with external counsel. Agree on which communication channels are secure and which precautions are appropriate.
For more information on this topic, contact the authors or your local CMS legal expert.