AI Translation and Attorney-Client Privilege (2026)

    #AI#document#translation#enterprise#comparison#security#compliance#authenticity#localization#format#preservation#Bluente#BluTranslate#MCP


    Sending a privileged document out for translation does not, by itself, waive attorney-client privilege. Translators are the textbook example of the Kovel agent doctrine, which extends the privilege to third parties a lawyer engages to help render legal advice. What puts the privilege at risk is not the act of translating — it is whether you had a reasonable expectation of confidentiality in the tool you used, and that expectation is established by the vendor's contract, not by its marketing page.

    Bluente builds BluTranslate, a document translation platform that law firms and in-house legal teams use to move contracts, exhibits and filings across 120+ languages with the original layout intact. This guide explains the doctrine as of September 2026 and the questions it makes worth asking. It is not legal advice, and privilege analysis is jurisdiction-specific.

    The Kovel doctrine covers translators by name

    United States v. Kovel established that privilege can extend to a non-lawyer the attorney engages to help interpret information — the canonical illustration being an accountant, and, in the case law that followed, an interpreter or translator. The reasoning is mechanical rather than generous: a lawyer who cannot read the client's documents cannot advise on them, so the person who renders them readable is functioning as the lawyer's agent, not as an outside recipient.

    The American Bar Association's own survey of recent Kovel case law sets out the conditions courts actually test. The third party must be assisting the lawyer in giving legal advice. The communication must be made in confidence and for that purpose. And the engagement should run through counsel. Where the third party is retained for an ordinary business purpose that happens to touch the same documents, courts have found waiver.

    Heppner narrowed where that protection ends

    On 10 February 2026, Judge Rakoff of the Southern District of New York decided what the Harvard Law Review described as a question of first impression: whether a defendant's written exchanges with a consumer generative-AI platform were privileged. They were not. The opinion's most quoted line is the shortest one — the platform is not an attorney, and that alone disposed of the claim.

    Two facts did the real work, and both are portable to any AI tool a legal team touches. First, counsel had not directed the defendant to use it; there was no attorney in the chain for the agency theory to attach to. Second, the provider's consumer-facing privacy policy expressly disclosed that inputs and outputs could be used to train models — so there was no reasonable expectation that the material would stay confidential.

    The holding is narrow. It is about a criminal defendant using a consumer product on his own initiative. But the second finding is the one that reaches ordinary translation workflows, because it turns a routine procurement detail into a privilege question.

    Reasonable expectation of confidentiality is a contract question

    After Heppner, "we use an AI translator" is not a sufficient answer and neither is "it's enterprise-grade." What a court looked at was the document that governed the relationship, and what that document said happened to the inputs.

    That reframes the diligence. A tool with a consumer free tier and a paid enterprise tier may handle data very differently across the two, and the tier your associate signed up for at 11pm is the one that governs. Terms that permit training "to improve our services," or that reserve a right to human review of submitted content, are the terms a privilege challenge will quote back at you. Our post on AI translation and legal risk covers the adjacent exposure; this one is narrower and more binary. Either the contract creates the expectation or it does not.

    The three clauses that carry the privilege argument

    Three provisions do nearly all of the load-bearing work, and all three should be in the agreement rather than on the website.

    No training on submitted content. Not "we do not sell your data" and not "we may use aggregated data" — an unambiguous statement that customer documents are never used to train or fine-tune models. This is the exact clause Heppner turned on.

    Retention and deletion, with a stated interval. Zero data retention with automatic deletion inside a defined window is a testable claim. "Deleted when no longer necessary" is not.

    A named sub-processor list. Most translation pipelines call something downstream — an OCR service, a model provider, storage. Privilege attaches to the whole chain, not just the vendor whose logo is on the invoice. Our guide to document translation security and compliance goes through how to read one.

    Counsel has to be in the chain

    The agency theory only works if there is an attorney for the agent to be an agent of. Heppner suggested the exchanges could have been privileged had counsel directed their creation, and the practical implication for legal teams is procedural rather than technical.

    ABA Formal Opinion 512 points the same way from the ethics side: a lawyer must consider the tool's data-handling before putting client information into it, and in some circumstances must obtain the client's informed consent first. Engage the translation provider through counsel, in writing, for the specific matter. Say in the engagement that the purpose is to enable the provision of legal advice. Where a business unit — not the legal department — holds the vendor relationship, route privileged files through a separate instance or a separate account, because a vendor retained for ordinary business purposes is the fact pattern where courts have found the protection does not attach.

    This costs one paragraph in an engagement letter and it is the cheapest part of the entire analysis.

    Inadvertent disclosure has a backstop, and it is thin

    Federal Rule of Evidence 502(b) preserves privilege over an inadvertent disclosure where the holder took reasonable steps to prevent it and promptly took reasonable steps to rectify it. It is a genuine protection and it is not a substitute for the controls above.

    The rule asks what steps you took before the disclosure. A firm that ran privileged material through a consumer tool with published training terms is arguing about reasonableness from a poor starting position, and the same rule's court-order mechanism under 502(d) does nothing for material that left the building through a browser tab. Treat 502 as the thing that saves you from a mis-click during a production, not as cover for a tooling decision.

    Reformatting is a privilege problem, not just an annoyance

    This is the part that is specific to document translation and it is routinely missed. When a translation comes back with the tables collapsed, the numbering restarted and the exhibit references broken, somebody rebuilds it by hand. That work is usually done outside the controlled pipeline — pasted into a local template, emailed to a floating assistant, sometimes sent to an outside typesetter with no confidentiality terms at all.

    Every one of those hops is an unlogged disclosure of privileged material to a person who is not in the engagement. The formatting defect creates the human workaround, and the human workaround creates the exposure.

    There is a sharper version involving redactions. A redaction that is a black rectangle drawn over a live text layer, rather than one where the underlying characters have been removed, will still hand that text to any processor that reads the file. Redact first, confirm the characters are actually gone, then translate — the order matters, and it is covered in our note on translating discovery files securely.

    What to ask before the first privileged file

    Five questions, in the order that resolves them fastest.

    1. Is the no-training commitment in the contract, and does it cover fine-tuning as well as training?

    2. What is the stated retention interval, and what triggers deletion?

    3. Who are the named sub-processors, and where does processing physically occur?

    4. Does the provider hold SOC 2 Type II and ISO/IEC 27001, and will they complete a security questionnaire before, not after, the first upload?

    5. Does the output come back in the source format, so that no one has to rebuild it by hand?

    The fifth looks like a productivity question. It is the one that quietly determines how many people end up touching a privileged document.

    BluTranslate is built for this pattern: files in and out in the original format across PDF, DOCX, XLSX, PPTX and scanned images, zero data retention with automatic deletion, no training on customer content, and SOC 2, ISO 27001 and GDPR compliance behind it. The vendor security checklist is the longer form of the list above.

    Related Reading

    Sources and Further Reading


    Put privileged documents through a pipeline you can describe in an engagement letter. BluTranslate returns your file in its original format across 120+ languages, with zero data retention and no training on your content. Start with BluTranslate, or talk to our team about a security review first.

    Last reviewed 16 September 2026. Written by the Bluente document engineering team, who build and test the format-preservation pipeline described above. We update these guides when the underlying standards, regulations or case law change.

    Published by
    #AI#document#translation#enterprise#comparison#security#compliance#authenticity#localization#format#preservation#Bluente#BluTranslate#MCP
    Back to Blog
    Share this post: TwitterLinkedIn