Author: Clearon AI

  • Your AI Prompts May Not Be Privileged

    Your AI Prompts May Not Be Privileged

    Lawyers and business teams are increasingly using AI to think through legal and risk questions.

    That does not automatically make the prompt, output, or workflow privileged.

    The practical risk is simple: if people put sensitive legal analysis into the wrong AI environment, they may create a discoverable record instead of a protected one.

    This is a privilege, confidentiality, and workflow problem showing up in a new tool.

    The key practical point

    There is a major difference between:

    • a public or lightly controlled AI tool
    • and an enterprise environment with negotiated controls, restricted retention, and clear terms that do not permit your prompts or data to be used to train models for other users

    That distinction should be doing a lot of work in legal AI policy.

    If the tool is not enterprise-approved, if the data controls are unclear, or if the provider can use prompts to improve models for others, legal teams should assume the risk is much higher.

    What not to do

    • Do not paste live dispute facts, investigation details, board communications, draft legal theories, or regulator-response strategy into a casual AI tool.
    • Do not assume a prompt is protected just because it relates to legal advice.
    • Do not let employees use consumer AI tools for sensitive legal work without tool-specific approval.
    • Do not treat “internal” and “privileged” as if they mean the same thing.
    • Do not rely on vague vendor marketing about privacy or security. Check the actual enterprise terms, retention settings, training terms, and admin controls.

    What to do instead

    • Use an enterprise AI environment with contractual controls and settings that prevent your prompts and data from being used to train models for other customers or the public service.
    • Limit legal-use cases to approved tools and approved users.
    • Create a short list of off-limits prompt categories, including litigation strategy, privileged investigation facts, deal-sensitive issues, and regulator-response planning.
    • Require lawyer involvement when the purpose of the workflow is legal advice.
    • Know what records the tool keeps, where they are stored, who can export them, and how long they remain available.

    What recent cases make clear

    Recent attention to cases like United States v. Heppner has put a spotlight on a basic point many organizations still blur: a communication can feel private and still fail privilege requirements.

    In Heppner, Judge Rakoff held that AI-generated materials created through Claude were not protected by attorney-client privilege or the work-product doctrine because the defendant disclosed information to a third-party platform and the materials were not prepared by counsel or at counsel’s direction.

    Different cases can come out differently, and courts are not applying a one-line rule that all AI prompts are discoverable or all AI-assisted work loses protection.

    But that is not a reason for comfort. It is a reason to stop assuming the facts will break your way.

    A useful default rule

    If a prompt would be uncomfortable to hand to an opposing lawyer, regulator, or prosecutor later, it should not be casually entered into an unstructured AI workflow.

    That rule is not perfect, but it is much better than assuming “we were just using AI to think.”

    The takeaway for legal teams

    The real issue is not the model by itself. It is whether the workflow, tool, and contract structure are good enough to support sensitive legal use.

    Clearon AI’s recommendation is not to ban AI for legal work. It is to make sure legal AI use happens inside the right workflow.

    • approve an enterprise AI environment with terms and settings that protect sensitive prompts and do not allow them to train models for other users
    • block consumer or unapproved tools for privileged, litigation, investigation, and regulator-response work
    • limit sensitive legal prompting to approved users and defined use cases
    • give employees concrete do-and-don’t rules instead of vague policy language
    • treat prompt security, retention, and export controls as part of legal workflow design, not an afterthought

    In law, workflow mistakes have a nasty habit of becoming exhibits.

  • The EU AI Act Priorities Just Shifted Again

    The EU AI Act Priorities Just Shifted Again

    The EU AI Act story in 2026 is no longer about one looming deadline.

    It is about figuring out what moved, what did not, and where legal teams should spend compliance time first.

    “The AI Act was delayed” is too sloppy to be useful.

    Recent reporting indicates that the European Parliament and Council reached agreement on amendments that would postpone some major obligations, especially around high-risk AI uses and watermarking timing, while the European Commission also published draft guidance on transparency obligations that still begin this year.

    So the practical question is not whether the AI Act matters less. It is where the immediate compliance pressure now sits.

    It is what still appears to hit in 2026 and what can likely be sequenced later.

    The short version

    Here is the cleanest practical read based on current reporting:

    What did not move

    • core transparency obligations still appear set for August 2, 2026
    • disclosure expectations for AI systems that interact with people
    • related user-facing design and notice questions
    • the need to review where AI-generated or AI-manipulated content appears in products and workflows

    What moved later

    • AI-generated content transparency and some watermarking-related timing reportedly moves to December 2, 2026
    • Annex III high-risk AI systems reportedly move to December 2, 2027
    • Annex I product and product-safety high-risk AI systems reportedly move to August 2, 2028

    That does not mean companies can relax.

    It means they should stop treating every AI Act obligation as if it lands on the same day.

    What stayed on the 2026 calendar

    The biggest mistake legal teams can make here is hearing “delay” and translating it into “not urgent.”

    That would be a bad read.

    Even with the reported changes, core transparency obligations still appear positioned to matter starting August 2, 2026.

    For many organizations, that means focusing now on systems that interact directly with users and making sure disclosures are not buried in terms or documentation nobody reads.

    In plain English, companies should be asking:

    • Where are users directly interacting with AI systems?
    • Is the disclosure clear in the interface itself?
    • Are we treating different user groups appropriately?
    • Do any product flows involve AI-generated or AI-manipulated content that raises separate transparency issues?
    • Are product, legal, compliance, and design teams aligned on what the user actually sees?

    That is practical work. Not compliance cosplay.

    What legal teams should do now

    This is the moment for reprioritization, not celebration.

    A practical checklist:

    • map AI systems that directly interact with users
    • identify where AI-generated or AI-manipulated content appears
    • review interface-level disclosures instead of relying on buried policies
    • separate immediate 2026 transparency work from later high-risk build-out
    • revisit vendor diligence questions and contract language in light of the updated timing
    • give business teams a clearer timeline so “delay” does not become an excuse for doing nothing

    For in-house teams, this is also a communications problem.

    If the business hears only that the EU delayed the AI Act, the organization may under-resource work that still appears likely to happen this year.

    That misunderstanding can create more risk than the original deadline pressure.

    The bigger lesson

    The EU AI Act is becoming a sequencing challenge.

    That means the winning move for legal teams is not just knowing the rules. It is knowing the order in which the rules matter.

    That is what good AI governance looks like in practice.

    Not panic.
    Not delay theater.
    Just disciplined prioritization.

    The AI Act still matters in 2026.

    The real question now is which part of it is knocking first.

    One caution, though: because this area is moving through amendments, guidance, and implementation detail at the same time, legal teams should confirm the latest official timetable before treating any one summary as the final word.

  • Anthropic Pushes Further Into the Legal Workflow Layer

    Anthropic Pushes Further Into the Legal Workflow Layer

    Anthropic's latest legal AI release looks like more than a product update.

    On May 12, the company rolled out a broader legal package for Claude that reportedly includes 12 legal practice-area plug-ins, more than 20 integrations with legal and adjacent platforms, and tighter workflow support across Microsoft 365. Public reporting suggests the package is aimed at law firms, in-house teams, and other legal users. It also suggests Anthropic wants Claude closer to the legal workflow layer.

    The competitive question is shifting.

    It is becoming less about which model writes the best draft in isolation and more about which company can sit inside the legal workflow itself.

    Anthropic's latest move looks like an effort to push Claude further in that direction.

    From general legal help to practice-specific workflows

    Anthropic had already entered the legal workflow conversation earlier this year with a general legal plug-in for Claude Cowork. This new release appears to go further by organizing legal work around more specific workflows and user types.

    Public reporting describes plug-ins aimed at commercial, corporate, privacy, regulatory, litigation, employment, product, and AI-governance work, along with tools for law students, clinics, and legal builders. The point is not simply that Claude can answer legal questions. The point is that Anthropic is trying to package legal work into more structured, agentic flows that can move across applications and systems.

    That is significant because lawyers do not work in a single interface. They work across Word, Outlook, document management systems, diligence platforms, e-discovery tools, contract systems, research resources, and internal knowledge sources. A system that carries context across those environments becomes much more useful than a model that only produces polished text in a chat window.

    This deserves law-firm attention

    For law firms and legal departments, the strategic implication is pretty straightforward: foundation-model companies are moving closer to the lawyer.

    That puts pressure on legal AI vendors whose main value is wrapping a frontier model with prompts, UI, and light workflow features. It does not mean those vendors disappear. It does mean they will need to show real differentiation — authoritative sources, traceable outputs, stronger governance, better matter-specific workflows, deeper institutional knowledge integration, or more defensible professional use.

    For in-house legal departments, the implications may be even more immediate. A system that can help with first-pass contract review, playbook-based redlines, privacy and regulatory issue spotting, and better organization of matter context could allow internal teams to handle more work before involving outside counsel. That does not mean outside firms become less important. It means the handoff may change. Instead of sending out broad, early-stage requests, in-house teams may increasingly use AI-assisted workflows to narrow the issues, improve initial drafts, and escalate more selectively. If that happens, the impact will not just be productivity. It will be a shift in how legal spend is allocated and where legal work gets done.

    That is especially clear in the Thomson Reuters response. Thomson Reuters announced a Claude integration for CoCounsel Legal and emphasized “fiduciary-grade” legal AI, authoritative content, traceability, and trusted professional standards. That framing is telling. It suggests the market is sorting into two overlapping but distinct layers:

    • general-purpose AI for speed, drafting, and exploratory work
    • professional-grade legal systems for authoritative, high-stakes work

    Those are not the same thing, and lawyers should not pretend they are.

    A useful tool is not the same thing as a defensible workflow

    That is the biggest caution here.

    Better plug-ins and more integrations do not automatically solve legal governance. Earlier reporting on Claude Cowork noted that Anthropic’s own support materials warned against using Cowork for regulated workloads because certain activity was not captured in compliance APIs, audit logs, or data exports. Even as Anthropic’s legal tooling gets more capable, firms still need to ask the boring-but-critical questions:

    • Where does the data go?
    • What can be logged and audited?
    • What is retained?
    • What can be supervised?
    • Which tasks are appropriate for AI drafting assistance, and which require a more controlled system?

    Those questions matter more than the demo.

    What this likely means next

    Anthropic’s release does not prove that specialized legal tech is finished. It does suggest that the legal tech stack is being reshaped from below. Foundation-model companies no longer seem content to remain behind the scenes while others own the workflow layer.

    For lawyers, the right response is neither panic nor dismissal. It is disciplined evaluation.

    The firms that benefit most from this shift will not necessarily be the ones that buy the most AI tools. They will be the ones that build the best workflows around them — with clear review standards, source verification, confidentiality guardrails, and realistic decisions about where general-purpose AI is enough and where it is not.

    Anthropic’s latest legal release is important not because it settles the legal AI race.

    It is important because it makes the real competition harder to miss.

    Practical guide: Legal AI Workflows: A Governance Checklist for Legal Teams