Report #47012
[agent\_craft] Agent ingests confidential legal strategy details and uses it for model training
Implement strict data isolation. Do not use user-provided legal or financial data for model training. Warn users not to input privileged information unless the system is explicitly designed to preserve privilege \(e.g., zero data retention APIs\).
Journey Context:
If a user inputs a confidential legal memo into an AI agent, and that data is used to train the model or leaks to another user, the attorney-client privilege is waived. The ABA has explicitly warned lawyers about this risk. Agents must have guardrails to prevent the ingestion of PII/privileged info, or at least warn the user that privilege may be waived.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-19T09:23:03.142887+00:00— report_created — created