• PL
Choose your location?
  • Global Global
  • Australian flag Australia
  • Canadian flag Canada (FR)
  • French flag France
  • German flag Germany
  • Irish flag Ireland
  • Italian flag Italy
  • Polish flag Poland
  • Qatar flag Qatar
  • Spanish flag Spain
  • UAE flag UAE
  • UK flag UK

From prompts to agents: How agentic AI challenges legal privilege

20 July 2026
In this article we outline the features and issues related to Agentic AI, a category of AI system that operates differently from the generative AI tools most organisations have previously been using.

Our previous article on Generative AI and confidentiality addressed how the use of generative AI tools can affect confidentiality and, in turn, claims for legal professional privilege. The takeaway point was that confidentiality is a necessary ingredient of privilege, and where that confidentiality is lost, claims to privilege may well also be lost. 

What is Agentic AI?

A conventional generative AI tool - such as ChatGPT and Claude - responds to a human prompt and produces an output. For example, an employee asks it to summarise a document; it produces the summary.

Agentic AI differs in that it refers to AI systems (agents) capable of autonomous, goal driven and adaptive behaviour. An AI agent can pursue objectives with limited human input. To give an example in the context of a dispute:

  • The agent may be asked to prepare a first-stage assessment of the organisation's exposure. The agent will then act autonomously by potentially: accessing files, retrieving relevant documents, pulling legal, internal and external correspondence, considering accounting provisions, and searching internal and external legal memos – all without further instruction.
  • The agent may then autonomously produce outputs: a chronology, a risk summary, a slide deck report, draft questions for external counsel, suggested settlement ranges etc.
  • Finally, the agent may then continue monitoring incoming communications in the background, updating its analysis automatically and escalating any inconsistencies or other issues to the relevant stakeholders.

Unlike generative AI, which produces content within the guardrails of human prompting, agentic AI systems can undertake activities and pursue objectives over time, across the organisation’s legal and operational workflows with minimal or limited human supervision. That is what makes them useful – but it also, from a privilege perspective, raises issues. 

Why Agentic AI presents a different privilege issue

The shift from prompts to agents matters because, whilst privilege remains governed by the same legal principles, its application is likely to change depending on how AI systems are operated in practice. Relatedly, a significant issue for consideration is not only whether privilege may have been lost through the use of Agentic AI tools, but whether privilege can be shown to have arisen in the first place.

The answers to these questions are likely to be influenced less by individual use and more by the organisation’s system design, data control and governance framework. That is a structurally different practical problem which English law has not yet addressed in the context of AI.

Key issues for consideration

Control

An organisation utilising Agentic AI may not fully understand what information was accessed by the autonomous agent or how that information was utilised. In particular:

  • whether that information was commercially sensitive, legally sensitive, or privileged;
  • how that information was processed and what was retained; or
  • the process and analysis by which the outputs were generated.

Unless effective and reliable guardrails are built into the system, the more autonomous the workflow, the more difficult it may be to understand what information has been accessed and how it has then been handled. Accessing sensitive legal and commercial information, and then building it into analysis and output, presents clear risks, not only to privilege.

Dominant purpose

The dominant purpose test broadly requires that a privileged document be brought into existence for the dominant purpose of obtaining legal advice or for use in litigation. Where the document was not created for one of those dominant purposes, it will not be privileged.

Agentic systems can make that assessment more difficult. For example, where an agent is configured to act autonomously, it may be unclear what purpose underpins the material it generates, in spite of the original intention. For example, an AI agent tasked with preparing a project briefing may draw on internal correspondence, risk registers and legal memoranda without any specific instruction to do so. The resulting output may combine commercial reporting and presentational advice with legal commentary and be produced through a process not directly controlled or directed by any individual, much less anyone engaged in the seeking of legal advice or running the litigation.

Privilege claims in respect of this type of blended, multi-purpose output may well be more vulnerable, as it may be difficult to demonstrate that the dominant purpose of the agent-produced document is legal, rather than operational or commercial.

Confidentiality and internal access

As addressed in Part 1, enterprise AI tools generally present a lower confidentiality risk than public AI tools. However, their use does not, in itself, ensure that privilege will always attach.

Agentic systems make this analysis more complex. Where specific agents are integrated within document management systems, shared repositories or emails, the confidentiality of material may be affected if appropriate controls are not in place. In particular, careful attention should be given to the scope of the agent’s data access, whether outputs are written back into shared environments, and what records of prompts, reasoning and activity are retained. In principle, this issue is no different to the privilege risk that applies if too many employees have unrestricted access to servers containing privileged material. Similarly, it may highlight cross-border information access as, say, an Agentic AI given a task in London accesses servers in the US, Singapore and Australia. 

The central question is a practical one: whether confidentiality has in fact been maintained, including through control over the material. Factors such as searchability, automatic sharing and the breadth of internal access permissions may be critical to that assessment, and therefore to whether privilege can be said to have been maintained.

Privilege contamination and waiver risks

As indicated above, Agentic AI may create privilege risks where legal and non-legal data environments are not adequately separated. If an agent is granted broad access across an organisation's systems, it may draw upon privileged legal advice when generating outputs for business users. For example, a member of the commercial team might deploy an agent for an operational purpose, yet the resulting output could reflect or summarise privileged legal advice to which they would not otherwise have had access.

This creates at least two risks. First, the wide dissemination of privileged content beyond the legal function may give rise to arguments that confidentiality has been undermined, potentially affecting the availability of privilege. Secondly, if privileged information finds its way into business records, reports or communications generated for non-legal purposes, parties may later face disputes regarding waiver of privilege, disclosure obligations and the status of AI-generated material. The emerging guidance emphasises the importance of preserving clear boundaries between business and legal workflows, and exercising caution where AI tools have broad access to potentially sensitive and privileged information across the organisation’s systems.

AI output and the expanding record

AI tools can also produce a broad range of potentially disclosable documents, including not only the generated output, but also prompts, chat threads, drafts and verbatim transcripts of meetings.

Much of this material moves without any deliberate act of sharing: distributed automatically to meeting participants, ingested into search indices, or surfaced in e-discovery platforms. The documentary record can widen silently and at a scale that standard document management protocols may not be designed to address.

That output may then itself be distributed in such a way that it could be said to lose privilege, for example, whilst remaining within the organisation, but by being sent outside of the group of individuals that comprise the “client” for the purposes of Legal Advice Privilege. 

Notwithstanding the above issues, the use of Agentic AI is unlikely, without more, to prevent privilege from arising where lawyers retain effective control over the agent’s purpose, scope of access, instructions and outputs, and the system is deployed as part of a legal advice or litigation process. The challenge is more likely to arise where agents operate with broader autonomy or generate outputs serving multiple legal, commercial and operational purposes. 

Practical steps to mitigate risks

Agentic AI provides clear potential for significant efficiency and depth of analysis. The answer to these challenges is not to avoid Agentic AI altogether. It does, however, require deliberate consideration of where it is deployed and how it is governed. In particular:

  • Control access: limit what agents can access across systems and ring‑fence legal or sensitive data (for example, by separating legal-focused agents from general productivity tools).
  • Treat outputs as records: apply the same discipline to AI-generated material as to other sensitive working papers, ensuring that prompts, chat logs and drafts are treated as part of the documentary record.
  • Targeted training: employee training should go beyond the familiar message about not uploading legal advice to public tools, but also turn on what constitutes privileged material and how that interacts with the agentic workflow (with regular refreshes).
  • Agile risk management: be prepared to identify and respond quickly to changes and emerging risks.
  • Guardrails: consider whether limits can be imposed on the agents’ ability to access server areas or to police the use of potentially privileged materials.
  • Living policies: maintain clear, practical AI policies that are regularly updated, rather than static documents.
  • Legal oversight: retain appropriate legal control over agentic workflows, including purpose identification, access rights, write‑back capabilities, and visibility of outputs.

Looking ahead

English law has not yet tested how privilege applies to materials generated by autonomous agents. At the same time, experimentation with Agentic AI by businesses and legal teams is widespread. 

Future disputes will involve challenges to the privilege status of materials generated through AI models. Questions around AI usage and policies will no doubt arise in the disclosure stages of litigation and arbitration. The law in this area is unsettled and the cases that will test it have not yet arrived. Until they do, the prudent approach is to treat Agentic AI as presenting a higher disclosure risk than is yet clearly understood, and to govern it accordingly.

DWF acts for clients in disputes where the use of AI gives rise to issues around privilege, confidentiality and disclosure. If you would like to discuss how these issues may arise in current or anticipated disputes, please contact our experts Richard Twomey or Sarah Deloison. 

This publication is for general information purposes only and does not constitute legal advice. Specific legal advice should be sought in relation to particular circumstances.

Further Reading