Can Your Firm Put Subpoenaed or Privileged Documents Into an AI Tool?
Last updated 18 September 2026 · 7 min read
Direct Answer
For material produced on subpoena, subject to a suppression or non-publication order, the implied Harman undertaking, or a statutory publication prohibition, NSW Supreme Court Practice Note SC Gen 23 restricts use of generative AI. The practitioner must be satisfied that the material stays in a controlled environment subject to supplier confidentiality restrictions, is used only for the proceeding except where the note permits otherwise, and is not used to train the AI program or any large language model. The controlled environment must prevent public availability and model training. Privileged material is not automatically covered by this paragraph solely because it is privileged; separate confidentiality and privilege duties still matter. Check the equivalent direction for the court handling the matter.
Detailed Explanation
Generative AI tools are increasingly used in legal practice for drafting, summarising, and reviewing documents — but a category of material handled by litigation lawyers carries restrictions that predate AI and that courts have now explicitly extended to cover it. If your firm is putting documents into ChatGPT, Claude, Copilot, or a legal-specific AI tool as part of preparing a matter, and any of that material was produced on subpoena, is subject to a suppression or non-publication order, falls under the implied Harman undertaking, or is covered by a statutory publication prohibition, a specific court rule now governs whether that's permitted at all.
The Harman undertaking, for context, is the long-standing principle that a party who obtains a document through compulsory court process (like discovery or a subpoena) can only use it for the purpose of that proceeding — not for any other purpose — unless the court grants leave otherwise. Putting subpoenaed material into a generative AI tool, where the tool's owner may retain, log, or use the input in ways beyond the litigation itself, is squarely the kind of "other purpose" the undertaking was designed to prevent, which is exactly why courts have now written a specific AI-era rule addressing it directly rather than leaving it to be inferred from a decades-old principle.
What the Rule Actually Says
The NSW Supreme Court's Practice Note SC Gen 23, in force since 3 February 2025, states that material in the restricted categories must not be entered into a generative AI program unless the practitioner is satisfied that: (1) it remains within the platform's controlled environment, with supplier confidentiality restrictions preventing public availability and model training; (2) it is used only in connection with that proceeding, subject to the note's stated legal and law-enforcement exceptions; and (3) it is not used to train the AI program or any large language model. These are the conditions in paragraph 9A, not simply a general promise that the vendor will not train on data.
The practitioner must be satisfied on all these points, not just rely on marketing claims. A business or enterprise plan with written controls may be a better candidate than a free consumer account, but no plan is automatically compliant. Check permitted use for the particular proceeding as well as confidentiality, public access and training terms.
The practice note carves out routine, non-substantive uses: transcription and translation of a conversation, spell and grammar checking, and formatting are all explicitly outside the restriction, because these don't involve the AI tool substantively processing or reasoning over the restricted content's meaning in the way drafting or analysis does.
Where This Rule Applies
This started as a Supreme Court of NSW practice note, but it hasn't stayed there. Equivalent rules have been adopted by the NSW District Court, the NSW Local Court, the Land and Environment Court, and the NSW Civil and Administrative Tribunal (NCAT) through its own procedural direction. A firm practising across these NSW courts and tribunals needs to apply the same controlled-environment test regardless of which one a specific matter sits in. If your firm also practises in other states, or in federal jurisdictions, check the current position separately — a rule adopted in NSW is not automatically in force elsewhere, and assuming otherwise is a compliance risk of its own.
What This Means in Practice
- Identify which of your firm's matters actually involve subpoenaed, suppressed, Harman-undertaking, or statutorily prohibited material. Not every matter does — this rule is specific to these categories, not a blanket ban on AI use in litigation generally.
- Check what AI tools staff are actually using on those matters, and on what plan. A free consumer account and a business-tier account from the same vendor can have entirely different training-use terms — the practice note's test turns on the specific configuration in use, not the vendor's name.
- Get written answers about supplier confidentiality, public access, permitted use, training and retention for the specific plan. Confirm the material will be used only for the proceeding except where paragraph 9A permits otherwise.
- Set a firm-wide policy naming which AI tools and plans are approved for use on matters involving restricted material, rather than leaving the judgement call to each practitioner ad hoc. This is both a better compliance outcome and a fairer position to put individual lawyers in.
- Keep transcription, translation, and formatting uses clearly separated from substantive drafting and analysis uses in how staff think about this, since only the latter falls under the restriction.
Things to Consider
- This sits alongside, not instead of, general confidentiality and privilege obligations. See does putting client data into AI tools violate professional confidentiality or privilege obligations for the broader professional-obligations framework this court-specific rule adds a sharper, mandatory layer on top of for litigation matters specifically.
- Vendor plan and configuration is the actual compliance lever here, not the AI tool's brand name. See how do you evaluate an AI vendor's data processing agreement for what to actually check in a DPA before concluding a specific tool meets the controlled-environment test.
- Automated redaction or tokenisation doesn't automatically solve this. Stripping identifying details from a document before it reaches an AI tool addresses a different risk (identifiability) than the practice note's concern (unauthorised use and training on compelled or restricted material) — see how do you strip sensitive data out of a document before it reaches a cloud AI model for that separate technique, and don't treat it as a substitute for confirming the underlying training-use and retention terms.
- This is a fast-moving area of court practice. Courts have shown they're willing to issue and revise generative-AI-specific rules quickly as the technology and its litigation risks become clearer — check the current, in-force version of any relevant practice note before relying on the specifics summarised here.
Common Mistakes
- Assuming a general firm AI policy already covers this. A policy written around confidentiality and client data broadly may not specifically address the narrower, court-mandated categories (subpoenaed material, Harman undertaking material, suppression orders) this practice note targets — check that your policy actually names these categories explicitly.
- Treating a reputable vendor as enough. Paragraph 9A also requires proceeding-limited use, subject to its stated exceptions. Check all conditions for the specific plan and matter.
- Applying the restriction to every AI use in litigation, when it's actually scoped to specific material categories. Overcorrecting by banning AI tools from litigation work entirely wastes a legitimate efficiency tool where no restricted material is involved — scope the policy to the actual categories the practice note names.
- Missing that the rule has spread beyond the Supreme Court. A firm that checked this rule when it first applied only to Supreme Court matters may not have updated its policy to reflect the District Court, Local Court, Land and Environment Court, and NCAT adopting equivalent positions.
- Not revisiting the policy as the practice note is reviewed or updated. Courts have already shown a willingness to revisit these rules — a policy written against an earlier version can drift out of date without anyone noticing until it matters.
Frequently Asked Questions
- Does this rule apply outside the NSW Supreme Court?
- Yes, in NSW at least. The NSW District Court adopted an equivalent practice note, as have the NSW Local Court, the Land and Environment Court, and NCAT through its own procedural direction. If your firm practises across jurisdictions, check the current position for each court and tribunal separately rather than assuming one state's rule applies everywhere or that other Australian jurisdictions have adopted an identical position.
- What counts as a 'controlled environment' that satisfies the practice note?
- The practice note does not approve named products. The practitioner must be satisfied that the information stays within a controlled environment under supplier confidentiality restrictions preventing public availability and model training, is used only in connection with the proceeding except for the note's stated exceptions, and is not used to train the AI program or another large language model. Check the specific tool, plan and terms rather than its brand name.
- Are basic tools like AI-assisted spell-check or transcription covered by the restriction?
- No — the practice note carves out generative AI used only for transcription, translation, spelling and grammar checking, and formatting. The restriction targets generative AI programs performing substantive analysis or drafting on the restricted categories of material, not routine editing-assistance features.
- Is the NSW Supreme Court reviewing or planning to change this practice note?
- The Court has previously conducted a review process on the practice note's operation. Check the Supreme Court of NSW's own generative AI page for the current, in-force version before relying on any specific paragraph, since a practice note can be updated and a firm should always work from the version currently in effect.
References
Related Questions
How Do Law Firms Automate Conflict Checks and Matter Intake?
Law firms automate conflict checks by searching every new party against a firm-wide conflicts database before opening a matter, then automating intake.
Is It Safe to Put Company Data into AI Tools?
It depends on the data, the plan, and the vendor's terms. Business/enterprise AI plans typically differ from free consumer tiers — here's how to check safely.
Does Putting Client Data Into AI Tools Violate Professional Confidentiality or Privilege Obligations?
Professional confidentiality and privilege duties (legal, medical, financial) can be stricter than general data-protection law when using AI tools.
How Do You Strip Sensitive Data Out of a Document Before It Reaches a Cloud AI Model?
Redaction or reversible tokenisation can strip sensitive fields out of a document before it ever reaches a cloud AI model — here's how the mechanism works.
How Do You Evaluate an AI Vendor's Data Processing Agreement?
Before adopting an AI tool, check its DPA for subprocessors, data residency, retention, training defaults, and certifications — here's what to look for.
Can a Practice Use an AI Scribe Without Patient Audio Leaving Australia?
A practice can use an AI scribe with Australian-only audio processing, but must verify the vendor, plan and underlying model. Check the clinical guidance.