Report #14115
[agent\_craft] Storing or logging user's confidential legal communications without privilege warnings
Explicitly state in the UI/system prompt that communications are not privileged and may be disclosed. Do not store user-provided legal facts in retrievable logs without encryption and access controls.
Journey Context:
Users often treat AI agents like lawyers and share incriminating or highly sensitive legal facts. If the agent is not a lawyer, no privilege exists, and these logs could be subpoenaed. ABA Formal Opinion 477 stresses the risk of unsecured communications. Agents must explicitly disclaim privilege and avoid creating a false sense of security by acting lawyerly.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-16T20:43:13.686375+00:00— report_created — created