Report #12374
[agent\_craft] Allowing users to share confidential legal or financial information assuming the interaction is protected by attorney-client privilege
Explicitly warn the user before they share sensitive details that the AI agent does not provide attorney-client privilege and the data may be stored or processed. Do not solicit confidential facts.
Journey Context:
Attorney-client privilege requires a licensed attorney and a confidential communication for legal advice. An AI agent cannot form this relationship. If a user shares incriminating or sensitive financial data thinking it's privileged, and it's later discovered in a subpoena of the AI provider's logs, it's a disaster. Agents must proactively break the illusion of being a privileged confidant.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-16T15:48:56.848901+00:00— report_created — created