Frontrow Technology
← All insights & guides
Guide

Applied AI · Legal

Copilot and legal privilege: a firm-readiness checklist

Does Microsoft 365 Copilot put legal professional privilege at risk? The confidentiality analysis, the controls that protect it, and a readiness checklist for AU firms.

Daniel Brown · 28 August 2026 · 11 min read

When Frontrow first wrote about Copilot for Australian law firms, the questions were about workflows: what it drafts well, what it should never be trusted with, how a pilot runs. That ground is covered at /insights/copilot-for-lawyers-australia. The question partners ask now is sharper, and it is the one that stalls otherwise-ready rollouts: does putting client matter files within reach of an AI assistant put legal professional privilege at risk?

It deserves a straight treatment rather than a reassurance. This guide works through where the privilege risk actually sits, what the January 2026 Copilot confidentiality bug taught firms about relying on vendor assurances, the conduct obligations that apply regardless of tooling, and the technical controls, matter-centric permissions, ethical walls and labels, that a firm should have in place before the first Copilot seat touches a matter file. Frontrow's lane here is deliberate: this is practical IT guidance on confidentiality controls. The privilege questions themselves belong to the firm's own professional judgment and, where it matters, its own advisers.

Where the privilege question actually sits

Legal professional privilege protects confidential communications made for the dominant purpose of legal advice or litigation, and it survives only while the communication stays confidential. Conduct inconsistent with maintaining that confidentiality is how privilege gets waived. That is why generative AI raises the question at all: the tools are typically operated by someone other than the client or the firm.

Baker McKenzie's Australian chapter of its global privilege guide frames the open issues as two questions: are communications with an AI tool themselves privileged, and does inputting privileged material into a tool waive the privilege that already exists? Its analysis lands on confidentiality as the hinge in both directions, with care needed to ensure confidentiality is maintained from the public and from the tool's vendor alike. The Law Council of Australia has similarly cautioned that improper use of generative AI carries professional and legal risk where client confidentiality is not assured. The questions are live and Australian courts have not settled them, which is precisely why the controllable part, the confidentiality of the systems involved, deserves the firm's attention.

On that hinge, Microsoft 365 Copilot sits in a materially different position from a consumer chatbot. It operates inside the firm's own tenant, prompts and responses stay within the Microsoft 365 service boundary under enterprise data protection commitments covered by the same contractual terms as the rest of the tenant, tenant data is not used to train foundation models, and it can only surface content the signed-in user already has permission to access. Pasting privileged advice into a free public chatbot hands it to a third-party service on consumer terms. Asking Copilot to summarise a matter file the lawyer already holds does not involve that kind of disclosure. Different posture, different risk.

What the January 2026 bug taught firms

The reason vendor assurances cannot be the whole answer arrived in January 2026. A code error in Microsoft 365 Copilot caused Copilot Chat to read and summarise emails in users' Sent Items and Drafts folders even where those emails carried confidentiality sensitivity labels and data loss prevention policies were configured to keep labelled content away from AI processing. Microsoft acknowledged the bug and rolled the fix out through February. Affected content across organisations reportedly included legal communications, and legal-industry coverage, LawFuel among it, made the obvious point: for a profession whose confidentiality obligations are not aspirational, an AI layer that briefly ignored the controls is a governance lesson, not a footnote.

The lesson is not that Copilot is unsafe for firms; the content stayed inside each tenant, and the labels and DLP model is the right one. The lesson is defence in depth. A firm that relies on a single control, whether a label, a policy or a vendor promise, has a single point of failure. A firm whose permissions are matter-centric to begin with limits what any single failure can reach. That is the design principle behind everything in the next two sections.

The conduct obligations that apply regardless

Rule 9 of the Australian Solicitors' Conduct Rules requires solicitors to keep client information confidential, with narrow exceptions, and that duty applies to systems as much as to conversations. Practical guidance has followed the technology. The Law Society of NSW's guide to responsible AI use, updated in January 2026, asks solicitors to understand where an AI tool sends data before using it on client information, to keep AI to lower-risk tasks such as first drafts, and to be transparent with clients and courts where the use is material. The Victorian Legal Services Board and other state regulators have published in similar terms.

For a firm's IT decision-makers, the translation is concrete: the firm must be able to answer, in writing, where Copilot processing happens, what the vendor may do with the data, and which staff can reach which matters through it. Those answers exist for Microsoft 365 Copilot, but only a firm that has actually configured its tenant properly can give them honestly.

The technical controls that carry the weight

Copilot inherits the firm's existing permission model, which means the permission model is the privilege control. Four pieces matter most:

  • Matter-centric permissions in SharePoint. Each matter is a site or membership-controlled workspace accessible only to the lawyers working it. Copilot can then only ever draw on matters the user is actually on. A firm-wide open document store, by contrast, turns Copilot into a very efficient way to discover oversharing.
  • Ethical walls as enforced controls. Microsoft Purview information barriers turn a conflict wall from a memo into a technical restriction on who can communicate with whom and reach which sites, which Copilot then respects because the underlying access is blocked.
  • Sensitivity labels on the highest-confidentiality tiers: partnership matters, regulator correspondence, matters under strict confidentiality undertakings. Labels enforce encryption and shape what AI processing may touch, and after January's bug, firms should verify label behaviour against Copilot rather than assume it.
  • Audit and testing. Purview auditing records Copilot interactions; a quarterly test that a staff member outside a walled matter genuinely cannot surface its content through Copilot is cheap insurance and good evidence of diligence.

Some clients have views, and some have contracts. Government panels, banks and insurers increasingly include confidentiality or outsourcing clauses that touch AI processing, and some engagement terms predate the technology entirely. A firm rolling out Copilot should review its standard engagement terms, identify clients whose agreements restrict data processing arrangements, and decide its disclosure position before a client asks rather than after. The Law Society's transparency guidance points the same direction. Whether any given engagement requires consent is a question for the firm's own reading of its own terms; the IT contribution is being able to describe, precisely, what the tool does and does not do with client data.

The firm-readiness checklist

  1. 1Confirm matter-centric permissions: every active matter access-controlled to its team, verified by sampling, not assumed from policy.
  2. 2Run an oversharing audit across SharePoint and OneDrive before enabling Copilot, and fix what it finds first.
  3. 3Configure information barriers for standing conflict walls and confirm they block search and Copilot retrieval as well as chat.
  4. 4Deploy sensitivity labels to the top confidentiality tiers and test how labelled content behaves with Copilot enabled.
  5. 5Write the data-flow answer: where processing occurs, what the enterprise data protection terms commit to, who can access what. One page, kept current.
  6. 6Review engagement terms and client contracts for AI-relevant clauses; settle the firm's disclosure position.
  7. 7Update the firm's AI acceptable-use policy so Copilot is the sanctioned path and public chatbots are explicitly off-limits for client material.
  8. 8Enable Purview auditing for Copilot interactions and put the quarterly wall-test in someone's calendar.

Try it

Check the oversharing risk before Copilot does

The permission model is the privilege control. Score the firm's SharePoint oversharing exposure in a few minutes.

Score each dimension · 4 options

Is your tenant ready for Microsoft 365 Copilot?

Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.

  • 01

    Anonymous "anyone with the link" shares

    External access

    How does your tenant handle anonymous sharing links?

  • 02

    Tenant-wide / "Everyone except external" site sharing

    Permissions hygiene

    Do you have sites shared with "Everyone" or "Everyone except external users"?

  • 03

    External guest access hygiene

    External access

    How do you manage external guest users in Entra ID?

  • 04

    Site collection admin sprawl

    Identity & privileged access

    How tightly is SharePoint site collection admin access controlled?

  • 05

    Broken permission inheritance

    Permissions hygiene

    How much unique (non-inherited) permissioning exists across your sites?

  • 06

    Orphaned sites with no active owner

    Permissions hygiene

    How do you handle sites whose owner has left or gone inactive?

  • 07

    OneDrive personal sharing patterns

    External access

    Do staff share sensitive documents (HR, finance, contracts) from OneDrive?

  • 08

    Sensitivity label coverage

    Content classification

    How much of your content is classified with Microsoft Purview sensitivity labels?

  • 09

    Restricted SharePoint Search / content discovery controls

    Content classification

    Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?

  • 10

    Microsoft Teams / Groups public vs private hygiene

    Permissions hygiene

    How strict is the hygiene on Team / Microsoft 365 Group privacy settings?

  • 11

    Legacy classic SharePoint sites

    Permissions hygiene

    Do you still have classic (pre-modern) SharePoint sites in the tenant?

  • 12

    Access review cadence for sensitive sites + external access

    Identity & privileged access

    How often do you review access to sensitive sites and external user lists?

Common questions

Frequently asked

Does using Microsoft 365 Copilot waive legal professional privilege?
There is no Australian authority saying so, and commentators including Baker McKenzie frame it as an open question that turns on confidentiality: privilege is put at risk by conduct inconsistent with keeping the communication confidential. Copilot operating inside the firm's own tenant, under enterprise data protection terms, is a materially different posture from disclosing material to a public consumer chatbot. Whether privilege is maintained in any specific setting is a legal question for the firm, not an IT provider.
Is Copilot different from ChatGPT for client confidentiality?
Structurally, yes. Microsoft 365 Copilot runs against the firm's own tenant, keeps prompts and responses within the Microsoft 365 service boundary, does not use tenant data to train foundation models, and can only retrieve what the signed-in user already has permission to see. A consumer chatbot involves sending client material to an external service on consumer terms. That difference is exactly why professional guidance asks solicitors to understand where a tool sends data before using it.
What was the Copilot confidential email bug?
In January 2026 Microsoft acknowledged a code error that caused Copilot Chat to read and summarise emails in Sent Items and Drafts folders even where confidentiality sensitivity labels and DLP policies should have kept them out of AI processing. A fix rolled out through February. Content stayed within each organisation's tenant, but for law firms the episode is the case for defence in depth: matter-centric permissions limit what any single control failure can reach.
Do law firms need client consent before using Copilot?
There is no blanket rule. Some engagement terms, government panel arrangements and insurer or bank contracts contain confidentiality or outsourcing clauses that bear on AI processing, and Law Society guidance encourages transparency with clients where AI use is material. The practical step is reviewing standard terms and key client agreements before rollout and settling the firm's disclosure position, with the firm's own advisers making the call on specific engagements.
How do ethical walls work with Copilot?
Through the underlying access model. Microsoft Purview information barriers restrict which users can communicate with each other and reach which SharePoint sites, and Copilot only retrieves content the user can already access, so a properly configured wall holds for Copilot because the access itself is blocked. The discipline that matters is testing: verify that someone outside a walled matter cannot surface its content through Copilot, rather than assuming it.
What should a firm fix before enabling Copilot on matter files?
Permissions first. Confirm every matter workspace is restricted to its team, run an oversharing audit across SharePoint and OneDrive, configure information barriers for conflict walls, and label the top confidentiality tiers. Then document the data flow, settle the client disclosure position, make Copilot the sanctioned tool in the firm's AI policy, and enable auditing. Firms with legacy wide-open document stores should treat that cleanup as the project's first phase, not an afterthought.

The matched next step

Working out where Copilot actually pays for itself?

Frontrow's Copilot readiness review looks at your data hygiene, licensing position and the three or four roles where the numbers stack up first — before you commit to seats for everyone.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.