All posts

Legal

Attorney-client privilege when an AI takes the first call: what attaches, what breaks, what the vendor changes

NeuraVoice··8 min read

A caller dials a personal-injury law firm at 9:47 p.m. The AI voice agent answers. During the next 4 minutes, the caller tells the agent: their version of the accident, a pre-existing back injury, a prior DUI from 2018, and a settlement-floor instinct of $50,000. The conversation ends. The caller never speaks to a lawyer that night.

Was that conversation privileged?

The legal answer is "probably yes" with caveats. The vendor-architecture answer is "it depends on choices the firm did not know it was making." The wrong combination of those two answers is how a firm finds out in deposition that a recording it thought was protected is actually discoverable.

This post is the practical breakdown. What attorney-client privilege requires, how privilege attaches when an AI handles the first call, the three vendor-architecture choices that decide whether privilege survives, and the diligence pass for legal buyers.

This is not legal advice. It is a working overview written for managing partners and intake managers evaluating AI voice vendors.

What privilege actually requires

The attorney-client privilege protects communications between a client (or prospective client) and a lawyer (or the lawyer's agent) made for the purpose of seeking legal advice, with an expectation of confidentiality.

The standard four-part test, adapted from Wigmore on Evidence and codified in most state evidence rules:

  1. The communication is between a client (or prospective client) and a lawyer or the lawyer's authorized agent.
  2. The communication is for the purpose of seeking or providing legal advice.
  3. The communication is made in confidence.
  4. The privilege has not been waived.

Each part of the test interacts with AI voice intake differently. The first part (authorized agent) is the new question. The second and third parts (legal-advice purpose, confidence) usually map cleanly. The fourth part (waiver) is where vendor architecture decides the answer.

Privilege is also distinct from the Rule 1.18 confidentiality duty discussed here. Rule 1.18 is the lawyer's duty to the prospective client. Privilege is the client's right to keep certain communications out of evidence. They overlap, but they are not the same.

The "authorized agent" doctrine and AI intake

Privilege has always extended to communications with the lawyer's authorized agents, not just the lawyer personally. The classic examples: paralegals, legal secretaries, investigators retained by the firm, translators. The case law is thick on each.

The doctrine has a coherent test, often phrased as: an authorized agent is a person (or system) acting on the lawyer's behalf, under the lawyer's direction, for the purpose of facilitating the legal-advice relationship.

Three things determine whether an AI voice intake system meets the authorized-agent standard:

  • Direction. Is the AI configured by the firm, with prompts and behaviors specified by the firm, in service of the firm's intake process? If yes, the AI is acting under the firm's direction. If the AI is a generic answering service the firm did not configure, the agency is weaker.
  • Confidentiality posture. Does the AI handle the call in a way consistent with privilege protection? Is the recording stored under firm-controlled access? Is the data prevented from leaving the firm-vendor relationship? If yes, the agency is strong. If the call data flows to the vendor for training, analytics, or any other purpose, the agency starts to look like a non-agent third-party relationship.
  • Disclosure. Has the firm disclosed to the prospective client that an AI is handling the initial intake on the firm's behalf? Disclosure is not strictly required for privilege to attach, but it is required for the lawyer's professional-conduct duties under Model Rule 5.3 (responsibilities for non-lawyer assistants).

The combination matters. An AI configured by the firm, storing data under firm control, with proper disclosure is much closer to a paralegal taking the first call than to an external answering service receiving the call. The privilege analysis follows.

Three vendor-architecture choices that break privilege

Privilege survival depends on the vendor's architecture. The three choices that matter most:

1. Data retention by the vendor outside the firm-relationship purpose.

If the vendor retains call data, transcripts, or recordings for purposes other than serving the firm (model training, product analytics, cross-customer benchmarking, marketing collateral), the privilege analysis gets harder. The argument that the AI is the firm's authorized agent weakens when the vendor is using the data for vendor purposes that exceed the agency relationship.

The clean vendor commitment: call data is used only to serve the customer's calls, never for model training or vendor analytics that surface across tenants. Anything weaker is a privilege risk.

2. Vendor-employee access to call recordings.

Authorized agents have access to confidential information. So do the vendor's support engineers, ML engineers, and compliance team if the architecture permits. If vendor-employee access is broad and undocumented, the firm has third parties with access to its prospective clients' confidential communications. The agency relationship has effectively been extended without consent.

The clean vendor posture: access is logged, limited to documented support tickets, and never granted by default. The firm should be able to audit who accessed what and why.

3. Cross-tenant data exposure.

Most AI voice vendors run multi-tenant infrastructure. The data is "logically segregated" by tenant. For SOC 2 controls this is fine. For privilege the relevant question is whether anything leaks across tenants: training data, analytics, model fine-tuning, anything. If the vendor uses customer call data to improve a shared model, that model embeds traces of privileged communications from one customer into the experience of every other customer.

The clean architecture: tenant isolation strict enough that no privileged content from Firm A's calls can influence Firm B's calls, even indirectly via shared models.

Waiver and inadvertent disclosure

A third party who participates in a privileged communication usually breaks privilege. Classic example: a friend sitting in on a lawyer-client conversation. The friend's presence destroys confidentiality, which destroys the privilege.

Two AI-specific waiver scenarios worth flagging:

  • Inadvertent disclosure to vendor employees. If a vendor support engineer reviews a call recording without authorization, privilege is at risk. The doctrine of inadvertent disclosure (Federal Rule of Evidence 502, codified or adopted in most states) provides some protection if reasonable steps were taken to prevent disclosure. The firm needs to be able to show those reasonable steps. "We trusted the vendor" is not one.
  • Cross-customer leakage. If Firm A's call data influences a model that Firm B uses, and Firm B is on the opposing side of a matter Firm A is handling, the disclosure is more than inadvertent. It is structural. This is a hypothetical scenario but the architecture exposure is real.

The protective playbook for firms:

  • Sign a vendor agreement that contractually treats the vendor as an authorized agent under the privilege analysis.
  • Verify the vendor's architecture matches the contract: no training, no cross-tenant analytics, logged employee access.
  • Document the architecture in the firm's compliance file.
  • Disclose the AI use to prospective clients at intake.

The combination of contract, architecture, documentation, and disclosure is what gets the firm through a privilege challenge in deposition.

Five questions for vendor evaluation

The diligence pass for privilege protection takes 30 minutes. Five questions:

  1. Will you sign a contractual statement that you are acting as the firm's authorized agent for purposes of attorney-client privilege? The acceptable answer is yes, with reasonable language. A vendor that refuses has not understood the question.
  2. What is your data-use posture for customer call recordings and transcripts? The acceptable answer is "never used for any purpose other than serving the customer's calls, including no training of any model, our own or external."
  3. What is your vendor-employee access policy, and how is it logged? The acceptable answer is access is bounded, documented, ticket-linked, and auditable on customer request.
  4. How is tenant data isolated, including from any shared model layer? The acceptable answer is strict tenant isolation with no shared training, no cross-tenant analytics surfacing across customers, and a documented architecture diagram on request.
  5. Will you support an annual review of these policies with a written attestation? The acceptable answer is yes. A vendor that signs a policy and refuses to attest annually is a vendor whose policy will quietly drift.

If a vendor cannot answer all five in writing, the privilege exposure is the firm's, not the vendor's. The firm is the one a court will ask about reasonable steps.

The summary, in one sentence

If your AI voice intake vendor is configured by your firm, holds data only for your firm's purposes, has logged-and-limited employee access, isolates tenants strictly, and is willing to be treated contractually as your authorized agent, your prospective-client communications during AI-handled intake are very likely privileged. If any of those pieces is missing, you have a privilege exposure that did not exist before you signed the vendor.

For the Rule 1.18 framework that interacts with this analysis, see ABA Model Rule 1.18 and AI voice intake. For the conflict-check workflow that runs alongside, see conflict checks at the intake stage. To see how a privilege-aware architecture runs in a live demo, book a call.

Keep reading

Try it on your own calls

Spin up an agent in 5 minutes. Cancel anytime.

14-day free trial, 60 free minutes, cancel anytime. Bring your own intake script or start from a template. Wire it up to your CRM when you're ready.

Start free trial

Want a guided walkthrough first? Talk to the team.