Where Did Your Prompt Go? AI Terms of Use and the Survival of Privilege
Intellectual Property & Technology
|
September 8, 2026
Author(s)

A prompt typed into a chatbot does not vanish when the window closes. Where it travels next and who may read it are set not by the lawyer's intention but by the provider's terms. On those terms may hinge the survival of legal professional privilege (LPP). The risk is no longer hypothetical in other common law jurisdictions. In UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid),[1] the UK Upper Tribunal observed that uploading confidential documents into a publicly available AI tool such as ChatGPT would place the information in the public domain, breaching client confidentiality and waiving legal privilege.

No reported Hong Kong decision appears to have considered privilege in AI prompts, chat histories or outputs. Yet the use of AI in the legal setting is increasingly prevalent. A prompt may contain legal advice, witness evidence, litigation strategy, personal data or commercial secrets. When the question reaches the Hong Kong courts, the analysis is unlikely to begin with the prompt. The starting point may be the terms on which the tool was supplied. 

Those terms are often accepted as part of registration or continued use but may receive little attention in day-to-day application. For present purposes, the key point is that the terms record what the provider may do with the material entered, and that is the question the confidentiality analysis examines. 

When a subjective expectation of confidentiality is not enough

Under Hong Kong law, LPP is a substantive right protected under Article 35 of the Basic Law[2] and an absolute right that does not involve a balancing of interests. [3] That constitutional standing, however, is not what is in issue when client material is entered into a consumer AI tool. Two questions arise instead. The first is whether the confidentiality on which privilege depends survived entry into the tool at all. The second, where privileged material has in fact been disclosed, is whether that disclosure waived privilege and, if so, whether the waiver was complete or confined. Privilege is not lost unless intentionally waived by the holder, and a full waiver is not lightly inferred; whether the holder has waived, and the scope of any waiver, is assessed objectively from all the circumstances, in particular what was expressly or impliedly communicated and what the parties must or ought reasonably to have understood.[4] 

That principle carries particular weight in this context. A lawyer entering client material into a consumer chatbot may subjectively intend to preserve complete confidentiality. Viewed objectively, however, the material has been transmitted to a commercial provider on that provider’s standard terms. Those terms, which the user accepts expressly or by conduct, are important evidence of the basis on which the material was provided. They may therefore be decisive on both questions, whether confidentiality was lost and whether any waiver was limited or at large.

When material enters the legal advice process

CITIC Pacific Ltd v Secretary for Justice and Commissioner of Police (No 2)[5] distinguishes pre-existing documents from material brought into existence as part of the process of obtaining legal advice. A document created in the ordinary course of events does not become privileged merely because it is later sent to solicitors, but information processed and reduced into documentary form for the dominant purpose of obtaining legal advice may form part of the protected legal advice process.

The distinction is relevant to AI-assisted work. Work performed on an approved enterprise system by a solicitor or supervised legal team, for example organizing documents, preparing a chronology or summarising factual material for counsel, may form part of that process. Where the same material enters an unapproved tool under terms permitting retention, model training, human review, third-party routing or overseas processing, the difficulty is no longer whether the output is privileged, but whether the confidentiality on which privilege depends survived the input.

The criteria for limited waiver 

Whether a disclosure waives privilege at large, or only to a limited extent, turns on the recipient, the purpose and the surrounding circumstances. Hong Kong recognises such limited waiver. In CITIC Pacific Ltd v Secretary for Justice, the Court of Appeal held that privileged material provided to the Securities and Futures Commission (SFC) for a defined regulatory investigation was disclosed for that purpose only, and privilege was preserved against the rest of the world[6]. The reasoning was fact sensitive. The disclosure was made to the SFC, for the purpose of its investigation, and the Court considered the surrounding circumstances in deciding whether the waiver was limited. Those matters provide a useful lens for considering disclosure into consumer AI tools.

The contrast with consumer AI is obvious. Depending on the applicable terms, the relevant recipient may not be limited to the visible platform operator, but may include affiliates, contractors, reviewers, sub-processors or underlying model providers. The purpose may also extend beyond the client’s legal matter to service improvement, safety review, model training or other provider purposes. Where the terms reserve rights of retention, review or onward processing, it may be harder to characterize the disclosure as limited in the CITIC Pacific sense. Nor can a practitioner readily fall back on the principles governing inadvertent disclosure. Entering a prompt into a tool supplied on standard terms is deliberate conduct, even if the terms were not read. Whether that disclosure waived privilege, and the scope of any waiver, will be assessed by reference to the surrounding circumstances, including the terms governing the tool.

Whether the provider is an instrument or a third party

Not every disclosure to a third party defeats confidentiality. Privileged material passes routinely through translators, document processors and other agents who act as mere instruments of the lawyer’s work. Whether an AI provider belongs in that category, however, is not answered by analogy. It is answered by the contract and the actual deployment. An enterprise deployment or API arrangement under negotiated terms, with confidentiality undertakings, training disabled and no human review, may be closer to the ordinary service-provider arrangement. Consumer terms reserving rights to retain, train on or review inputs point in the other direction.

Sir Colin Birss, Chancellor of the High Court of England and Wales, has drawn the same distinction in a 2026 keynote speech on legal professional privilege in the age of AI. He observes that AI does not alter the legal tests for privilege, and that secure systems may be different from public or third-party systems.[7] Although the speech is not binding authority, it is useful because it reflects a judicial view that the dividing line lies in the arrangements under which the tool operates rather than in the technology itself.

What lawyers should check in consumer AI terms

  • Training rights. If prompts, uploads or outputs may be used to improve or train models, it will be harder to say that client material remained within a confidential and controlled legal advice process.
  • Retention. Firms should know whether deletion is immediate, whether a retention period continues in chat history, safety logs or backups, and whether retained material remains accessible.
  • Human review. Terms permitting provider staff, contractors or reviewers to examine prompts may matter to any asserted expectation of confidentiality.
  • Third-party routing. Wrapper platforms and multi-model tools may pass prompts to external model providers, infrastructure providers or bot developers.
  • Account type. Consumer, business, enterprise and API arrangements may carry materially different data-use commitments.
  • Data location. Tools hosted or operated outside Hong Kong raise additional questions about where prompts, files and chat histories are stored, processed or accessed.

As at 26 June 2026, major platforms take different approaches. The summaries below are indicative only. Terms change frequently and the current versions should always be checked.

Consumer AI tools & Key data-use risks

OpenAI – ChatGPT: Inputs may be used to improve models unless users actively opt out. [8] Chats in “Temporary Chat” mode will not appear in history, create memories or be used to train models.

Anthropic – Claude: If users allow chats or coding sessions to be used to improve Claude, Anthropic says such data may be retained for up to five years.[9]

Google – Gemini: Gemini expressly warns users against inputting confidential information. Chats reviewed by human reviewers may be retained for up to three years, even after deletion.[10]

Poe and other wrapper platforms: Poe explains that its bots are powered by third-party companies using large language models.[11] Wrapper platforms may involve additional data flows to third-party model providers and developers, including chat contents and uploaded photos or documents.

DeepSeek: DeepSeek’s privacy policy states that user inputs, prompts, uploaded files, feedback and chat history may be collected, and that personal data may be processed and stored in the People’s Republic of China.[12]

xAI – Grok: xAI’s consumer terms state that logged-in users can select whether User Content is used for product development or model training, and that deleted User Content may take up to 30 days to be queued for deletion.[13]

These differences are why a generic “approved AI use” policy is insufficient. Lawyers should identify the specific tool, account type, settings and permitted use cases.

Governance and the retainer

The regulatory direction is consistent with this terms-led approach. The Law Society’s 2025 circular[14] and the Privacy Commissioner’s Checklist on Generative AI[15] both treat prompts and outputs as material that may pass outside the firm’s control once entered, and direct firms towards internal policies, risk assessment and data-security controls. Those measures reach only the firm’s side of the retainer. Engagement letters should address the use of AI on both sides, because a firm’s controls may be undermined if the client independently feeds the same material into an uncontrolled system.

Where the prompt goes

When the first Hong Kong case arrives, the determinative question may concern the input as much as the output, namely whether confidentiality survived entry into the system. That question may fall to be answered by reference to the terms governing the tool. Those terms decide where the prompt goes, whether it is kept, trained on, reviewed, or sent elsewhere. The CITIC Pacific line of authority suggests different outcomes for controlled environments operating under negotiated terms and consumer tools operating under standard ones.

The risk lies less in the technology than in unmanaged disclosure into systems that were never designed to preserve the confidentiality on which legal advice depends. When that risk materializes, the decisive document may not be the prompt. It will be the terms of use under which the prompt was sent.

The views expressed are the author's own and this article is general information, not legal advice.


 

[1]UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC) at [21], [60]. The judgment determined two matters heard together, the second being R (on the application of Munir) v Secretary of State for the Home Department. The Tribunal made its observations on confidentiality and privilege in its discussion of the first matter, in which an adviser had uploaded client correspondence and Home Office decision letters to ChatGPT. The Tribunal also noted at [21] that closed source tools which do not place information in the public domain may be used for tasks such as summarising without these risks.

[2]Basic Law of the Hong Kong Special Administrative Region, Article 35, which protects the right to confidential legal advice, access to the courts, choice of lawyers, timely protection of lawful rights and interests, and judicial remedies.

[3]CITIC Pacific Ltd v Secretary for Justice and Commissioner of Police (No 2) [2016] 1 HKC 157; [2015] 4 HKLRD 20 at [31], [36]–[38]; Secretary for Justice v Florence Tsang Chiu Wing (2014) 17 HKCFAR 739 at [27]–[29].

[4] CITIC Pacific Ltd v Secretary for Justice [2012] 4 HKC 1 at [52], [56].

[5]CITIC Pacific Ltd v Secretary for Justice and Commissioner of Police (No 2) [2015] 4 HKLRD 20; [2016] 1 HKC 157 at [42]–[45] and [52]–[54].

[6]CITIC Pacific Ltd v Secretary for Justice [2012] 4 HKC 1; [2012] 2 HKLRD 701 at [5], [7], [17], [54], [56], [73]–[76]. The Court of Appeal recognised partial waiver of privilege in Hong Kong and held that disclosure of privileged documents to the SFC for a defined investigation did not necessarily waive privilege against the world.

[7] Sir Colin Birss, Chancellor of the High Court, “Legal Professional Privilege in the Age of AI”, keynote speech to the City of London Law Society, 22 April 2026. See https://www.judiciary.uk/speech-by-the-chancellor-of-the-high-court-legal-professional-privilege-in-the-age-of-ai/ 

[8]OpenAI says users can opt out of default training through their privacy portal by clicking on “do not train on my content”. See https://openai.com/policies/how-your-data-is-used-to-improve-model-performance/ 

[9]Anthropic says users may choose whether chats or coding sessions are used to improve Claude, and that where users allow such use, data may be retained for up to five years; otherwise, the existing 30-day retention period continues. See https://www.anthropic.com/news/updates-to-our-consumer-terms 

[10]Google’s Gemini Apps Privacy Hub warns users not to enter confidential information they would not want a reviewer to see or Google to use to improve services, and notes that some data may be retained for up to three years. See https://support.google.com/gemini/answer/13594961?hl=en 

[11]Poe explains that its bots are powered by third-party companies using large language models. See https://help.poe.com/hc/en-us/articles/19944206309524-Poe-FAQs 

[12]DeepSeek’s privacy policy says it may collect prompts, uploaded files, photos, feedback and chat history, and that personal data may be processed and stored in the PRC. See https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html 

[13]xAI’s consumer terms further suggest that users can access the service without logging in, and in such cases and to the extent permitted, users grant xAI full rights to use any data provided to or obtained from the Service for product development and model training. See https://x.ai/legal/terms-of-service 

[14]The Law Society of Hong Kong, Circular 25-824 (December 2025), enclosing the Professional Indemnity Scheme Risk Management Bulletin, Issue No. 15, “Generative AI in Legal Practice – Risks and Tips”. See https://www.hklawsoc.org.hk/-/media/HKLS/pub_e/circular/2025/25-824a1.pdf 

[15]Office of the Privacy Commissioner for Personal Data, “Checklist on Guidelines for the Use of Generative AI by Employees”, March 2025. The checklist is intended to help organizations develop internal policies or guidelines for employee use of generative AI at work while complying with the Personal Data (Privacy) Ordinance. See https://www.pcpd.org.hk/english/resources_centre/publications/files/guidelines_ai_employees.pdf 

 

This article, by our Trainee Solicitor Christy Hui, first appeared in the June 2026 issue of the Hong Kong Lawyer, the official journal of The Law Society of Hong Kong.

 

Document Download

< Back to previous page