
All rights reserved, Habeas 2026
See our Privacy Policy
See our Privacy Policy

A solicitor acting for a defendant in a commercial dispute has 200 pages of correspondence on her desk. The opposing party's account shifts across the chronology, and she wants to use an AI tool to map the inconsistencies, fast. The demonstrations were convincing, the tool works, and the file is open. The cursor hovers over upload.
This moment stops more practitioners from using legal AI than any technical limitation. The tool can analyse the correspondence. What matters is what happens to the file after it leaves the firm's control, and whether the solicitor is creating an exposure that surfaces months later when a regulator or a client asks how their information ended up somewhere it should not have been.
The file contains more than the legal question. Scattered through the correspondence are employee records, customer data, contact lists, commercially sensitive information about the client's operations. The solicitor's firm may sit below the $3 million turnover threshold and rely on the small business exemption in section 6D of the Privacy Act 1988 (Cth). The exemption is narrower than it looks. The corporate client is itself an APP entity, and the personal information in the file was collected by that client in the course of its business. Uploading that material to a third-party platform is a use or disclosure of information an APP entity collected, and the handling rules in Australian Privacy Principle 6 attach to it. The client collected customer data to fulfil orders and manage accounts. Legal research is unlikely to appear among those purposes, and the practitioner who uploads a customer database to research a consumer law claim may be causing a use the client's own privacy policy does not authorise.
Most general-purpose AI platforms process data on infrastructure outside Australia, which triggers obligations under APP 8.1. Before an APP entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient handles the information consistently with the APPs. The cross-border accountability provisions go further: the entity that uploads remains answerable for the overseas recipient's handling. A practitioner who sends personal information to a platform whose servers sit overseas carries the compliance obligation with the data. The regulator's question, if something goes wrong, lands on the firm that uploaded it.
The solicitor turns to the retainer. It authorises the use of external service providers for document review. The retainer was drafted before AI tools of this kind existed, and the question is whether that authorisation extends to feeding material into a general-purpose AI platform whose terms of service allow the provider to retain and reuse inputs. The authorisation a client gives for a managed document review platform, where a human consultant is bound by confidentiality and a defined purpose, is a different thing from the authorisation needed for a tool that may train on the material or store it indefinitely.
Legal professional privilege sits alongside confidentiality as a separate exposure. The matter file contains legal advice, communications with the client for the dominant purpose of obtaining or providing that advice, and drafts that may attract privilege. Uploading that file to a platform whose terms permit the provider to access, store, or reuse the material is a disclosure to a third party. If the platform does not share a common interest with the client, the disclosure may waive the privilege. Once waived, privilege cannot be reasserted. The waiver may surface years later in litigation when a discovery request or subpoena exposes how the material was handled.
The generic advice to check the privacy policy fails here. The privacy policy covers data handling. What the solicitor needs to know is specific to the provider's terms of service: does the platform retain inputs, for how long, does it use them for model training, and does it permit third-party access? Most general-purpose AI tools do not give clean answers to all of these. Some reserve broad rights over user inputs. A practitioner who uploads without resolving these terms is accepting them on the client's behalf.
The legal profession has long relied on third-party service providers. Litigation support companies, managed document review platforms, and expert witnesses all receive confidential client material under contractual arrangements that define the purpose and bind the recipient to confidentiality. A general-purpose AI platform whose terms reserve the right to use inputs for model training sits outside that framework. Treating an AI platform as another litigation support vendor applies a contractual model the platform's own terms may not support.
We have been building Habeas with this problem in mind. The distinction that matters is between tools that require you to upload matter materials and tools that do not. Habeas is built on a closed corpus of over 300,000 Australian cases and pieces of legislation. When the solicitor researches the governing principles for the claim against her client, the Search Engine returns results grounded in that dataset, with citations that resolve to primary sources and can be verified. She does not need to upload a client file to get an answer grounded in Australian authority. No client material leaves the firm, so the privacy and confidentiality questions that governed the upload decision do not arise.
For practitioners who need to work with their own documents, Habeas's Document Stores let you upload matter materials and query them. A Document Store accepts the materials a practitioner selects: contracts, correspondence, pleadings, transcripts. The materials remain within the controlled environment rather than feeding a general training pipeline, and the citations the platform returns are traceable to the source documents and to the Australian authorities in the corpus. The choice sits with the practitioner: Australian primary-law research does not require uploading anything, and when document analysis is needed, the materials stay in a controlled environment with verifiable citations.
We see this in how the platform is already used. Solo GCs and small in-house teams advise across a wide surface area, covering privacy, consumer protections, contractual obligations, employment matters, and regulatory compliance, and use Habeas as a powerful first-line intelligence layer that gives depth and speed before escalating the specialist or strategic work to external counsel. Foundational research processes that used to take a full morning can now be completed in minutes. The upload question narrows to the documents a practitioner chooses to upload, not the research workflow itself.
The cursor still hovers, and it should. The risk lies in uploading client personal information and confidential material to third-party platforms whose data handling is opaque. The answer is to separate the research task from the upload task: use a tool that answers Australian-law questions from a closed, verifiable corpus without requiring matter materials, and reserve document uploads for a controlled environment where the terms are clear and the citations trace back to source.
If you want to see how Australian legal research works when the upload question is not the price of entry, you can sign up at habeas.ai.
If you want to try for yourself or get in contact, book a demo with us here. We also offer the capacity for self-serve individuals to sign up, and subscribe or register a free trial at app.habeas.ai.
The legal research in this article was conducted and every citation verified using Habeas, the Australian legal AI research platform.
Hero image: Tima Miroshnichenko on Pexels
