When Frontrow first wrote about Copilot for Australian law firms, the questions were about workflows: what it drafts well, what it should never be trusted with, how a pilot runs. That ground is covered at /insights/copilot-for-lawyers-australia. The question partners ask now is sharper, and it is the one that stalls otherwise-ready rollouts: does putting client matter files within reach of an AI assistant put legal professional privilege at risk?
It deserves a straight treatment rather than a reassurance. This guide works through where the privilege risk actually sits, what the January 2026 Copilot confidentiality bug taught firms about relying on vendor assurances, the conduct obligations that apply regardless of tooling, and the technical controls, matter-centric permissions, ethical walls and labels, that a firm should have in place before the first Copilot seat touches a matter file. Frontrow's lane here is deliberate: this is practical IT guidance on confidentiality controls. The privilege questions themselves belong to the firm's own professional judgment and, where it matters, its own advisers.
Where the privilege question actually sits
Legal professional privilege protects confidential communications made for the dominant purpose of legal advice or litigation, and it survives only while the communication stays confidential. Conduct inconsistent with maintaining that confidentiality is how privilege gets waived. That is why generative AI raises the question at all: the tools are typically operated by someone other than the client or the firm.
Baker McKenzie's Australian chapter of its global privilege guide frames the open issues as two questions: are communications with an AI tool themselves privileged, and does inputting privileged material into a tool waive the privilege that already exists? Its analysis lands on confidentiality as the hinge in both directions, with care needed to ensure confidentiality is maintained from the public and from the tool's vendor alike. The Law Council of Australia has similarly cautioned that improper use of generative AI carries professional and legal risk where client confidentiality is not assured. The questions are live and Australian courts have not settled them, which is precisely why the controllable part, the confidentiality of the systems involved, deserves the firm's attention.
On that hinge, Microsoft 365 Copilot sits in a materially different position from a consumer chatbot. It operates inside the firm's own tenant, prompts and responses stay within the Microsoft 365 service boundary under enterprise data protection commitments covered by the same contractual terms as the rest of the tenant, tenant data is not used to train foundation models, and it can only surface content the signed-in user already has permission to access. Pasting privileged advice into a free public chatbot hands it to a third-party service on consumer terms. Asking Copilot to summarise a matter file the lawyer already holds does not involve that kind of disclosure. Different posture, different risk.
What the January 2026 bug taught firms
The reason vendor assurances cannot be the whole answer arrived in January 2026. A code error in Microsoft 365 Copilot caused Copilot Chat to read and summarise emails in users' Sent Items and Drafts folders even where those emails carried confidentiality sensitivity labels and data loss prevention policies were configured to keep labelled content away from AI processing. Microsoft acknowledged the bug and rolled the fix out through February. Affected content across organisations reportedly included legal communications, and legal-industry coverage, LawFuel among it, made the obvious point: for a profession whose confidentiality obligations are not aspirational, an AI layer that briefly ignored the controls is a governance lesson, not a footnote.
The lesson is not that Copilot is unsafe for firms; the content stayed inside each tenant, and the labels and DLP model is the right one. The lesson is defence in depth. A firm that relies on a single control, whether a label, a policy or a vendor promise, has a single point of failure. A firm whose permissions are matter-centric to begin with limits what any single failure can reach. That is the design principle behind everything in the next two sections.
The conduct obligations that apply regardless
Rule 9 of the Australian Solicitors' Conduct Rules requires solicitors to keep client information confidential, with narrow exceptions, and that duty applies to systems as much as to conversations. Practical guidance has followed the technology. The Law Society of NSW's guide to responsible AI use, updated in January 2026, asks solicitors to understand where an AI tool sends data before using it on client information, to keep AI to lower-risk tasks such as first drafts, and to be transparent with clients and courts where the use is material. The Victorian Legal Services Board and other state regulators have published in similar terms.
For a firm's IT decision-makers, the translation is concrete: the firm must be able to answer, in writing, where Copilot processing happens, what the vendor may do with the data, and which staff can reach which matters through it. Those answers exist for Microsoft 365 Copilot, but only a firm that has actually configured its tenant properly can give them honestly.
The technical controls that carry the weight
Copilot inherits the firm's existing permission model, which means the permission model is the privilege control. Four pieces matter most:
- Matter-centric permissions in SharePoint. Each matter is a site or membership-controlled workspace accessible only to the lawyers working it. Copilot can then only ever draw on matters the user is actually on. A firm-wide open document store, by contrast, turns Copilot into a very efficient way to discover oversharing.
- Ethical walls as enforced controls. Microsoft Purview information barriers turn a conflict wall from a memo into a technical restriction on who can communicate with whom and reach which sites, which Copilot then respects because the underlying access is blocked.
- Sensitivity labels on the highest-confidentiality tiers: partnership matters, regulator correspondence, matters under strict confidentiality undertakings. Labels enforce encryption and shape what AI processing may touch, and after January's bug, firms should verify label behaviour against Copilot rather than assume it.
- Audit and testing. Purview auditing records Copilot interactions; a quarterly test that a staff member outside a walled matter genuinely cannot surface its content through Copilot is cheap insurance and good evidence of diligence.
The client consent conversation
Some clients have views, and some have contracts. Government panels, banks and insurers increasingly include confidentiality or outsourcing clauses that touch AI processing, and some engagement terms predate the technology entirely. A firm rolling out Copilot should review its standard engagement terms, identify clients whose agreements restrict data processing arrangements, and decide its disclosure position before a client asks rather than after. The Law Society's transparency guidance points the same direction. Whether any given engagement requires consent is a question for the firm's own reading of its own terms; the IT contribution is being able to describe, precisely, what the tool does and does not do with client data.
The firm-readiness checklist
- 1Confirm matter-centric permissions: every active matter access-controlled to its team, verified by sampling, not assumed from policy.
- 2Run an oversharing audit across SharePoint and OneDrive before enabling Copilot, and fix what it finds first.
- 3Configure information barriers for standing conflict walls and confirm they block search and Copilot retrieval as well as chat.
- 4Deploy sensitivity labels to the top confidentiality tiers and test how labelled content behaves with Copilot enabled.
- 5Write the data-flow answer: where processing occurs, what the enterprise data protection terms commit to, who can access what. One page, kept current.
- 6Review engagement terms and client contracts for AI-relevant clauses; settle the firm's disclosure position.
- 7Update the firm's AI acceptable-use policy so Copilot is the sanctioned path and public chatbots are explicitly off-limits for client material.
- 8Enable Purview auditing for Copilot interactions and put the quarterly wall-test in someone's calendar.
Try it
Check the oversharing risk before Copilot does
The permission model is the privilege control. Score the firm's SharePoint oversharing exposure in a few minutes.
Score each dimension · 4 options
Is your tenant ready for Microsoft 365 Copilot?
Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.
- 01
Anonymous "anyone with the link" shares
External access
How does your tenant handle anonymous sharing links?
- 02
Tenant-wide / "Everyone except external" site sharing
Permissions hygiene
Do you have sites shared with "Everyone" or "Everyone except external users"?
- 03
External guest access hygiene
External access
How do you manage external guest users in Entra ID?
- 04
Site collection admin sprawl
Identity & privileged access
How tightly is SharePoint site collection admin access controlled?
- 05
Broken permission inheritance
Permissions hygiene
How much unique (non-inherited) permissioning exists across your sites?
- 06
Orphaned sites with no active owner
Permissions hygiene
How do you handle sites whose owner has left or gone inactive?
- 07
OneDrive personal sharing patterns
External access
Do staff share sensitive documents (HR, finance, contracts) from OneDrive?
- 08
Sensitivity label coverage
Content classification
How much of your content is classified with Microsoft Purview sensitivity labels?
- 09
Restricted SharePoint Search / content discovery controls
Content classification
Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?
- 10
Microsoft Teams / Groups public vs private hygiene
Permissions hygiene
How strict is the hygiene on Team / Microsoft 365 Group privacy settings?
- 11
Legacy classic SharePoint sites
Permissions hygiene
Do you still have classic (pre-modern) SharePoint sites in the tenant?
- 12
Access review cadence for sensitive sites + external access
Identity & privileged access
How often do you review access to sensitive sites and external user lists?