The question isn't whether you used AI, it's how you used it
Article for the Tasmanian Law Letter
Key Takeaways
A 2026 Supreme Court of NSW case shows generative AI failures are no longer confined to litigation. The same risks now arise in corporate advisory, governance and client-facing work.
Whether AI was used matters less than whether that use can be explained, verified and defended when someone looks closely, including under three different Australian court practice notes.
Five straightforward questions, encompassing the tool used, the information put into it, independent verification, records kept and supervision will give practitioners in any practice area a defensible starting point, including for maintaining privilege claims.
In July 2026, the New South Wales Supreme Court handed down a judgment in a case where the strategy that caused all the trouble was developed without a lawyer anywhere in sight, and with ChatGPT firmly in the room instead. In the matter of Lanmar Pty Ltd (No 2) [2026] NSWSC 800 concerned two majority directors of a Canberra defence engineering consultancy who used ChatGPT to develop and carry out a strategy to force their co-director and co-shareholder out of the business.
No lawyer was involved at any stage of their strategy to oust the other director, and that absence is exactly why the case matters to every lawyer reading this article.
How it happened
When the two non-lawyer directors asked generative AI (gen AI) tool ChatGPT to develop a strategy to deal with a director who they thought “needed to go”, the tool framed what was, in substance, a corporate governance issue as an employment law problem. The two directors then approached removing the director in accordance with ChatGPT’s suggested HR strategy, leading Black J to make a finding that their conduct amounted to oppression. His Honour ordered the appointment of a receiver for the purpose of winding up the company and selling its shares with “its value as an ongoing concern destroyed”.
Black J’s oppression finding rested on the directors’ own conduct, not on their use of generative AI as such. But the tool had a hand in that conduct: it suggested the approach, the directors followed it, and the chat log then became the evidence that proved what had happened. Practitioners need to recognise that pattern - AI informing a decision and then documenting it, in their own work, in their clients’ conduct, and on the other side of the bar table.
Plausible, but untrue
Gen AI tools are large language models. They predict the next plausible word based on patterns learned from huge volumes of training text; they do not retrieve verified facts and they do not apply legal reasoning. A hallucinated citation can therefore be formatted correctly, read confidently, and still be completely fictitious.
Lanmar illustrates a more subtle failure than fabrication only. The tool answered the question it was asked, but neither it, nor the directors, asked whether that was the right question, or had the legal judgment to make a meaningful assessment of the output. A failure of this kind is often the harder risk to catch, because the output reads as coherent, responsive and useful right up until someone with legal expertise and judgment takes a closer look.
What the courts now require
Australian courts have moved quickly from guidance to enforceable expectation, and while the three main regimes are generally consistent in underlying philosophy, they are not identical.
The Federal Court’s General Practice Note on the Use of Generative AI (GPN-AI), effective 16 April 2026, applies to lawyers, litigants, witnesses and third parties. It imposes a personal verification obligation - the responsible practitioner must confirm that cited authorities exist and support the proposition advanced, that evidence referred to is in the materials and reasonably admissible, and that factual claims can be proved. Disclosure is required wherever AI use might reasonably affect the admissibility of evidence or how the court treats it.
The NSW Supreme Court’s Practice Note SC Gen 23, in force since 3 February 2025 (as amended), goes further. Generative AI must not be used to generate the content of affidavits, witness statements or character references, although preparatory use for the purpose of work such as chronologies and witness lists is permitted. Citations in submissions must be independently verified, and that verification cannot itself be carried out solely by a generative AI tool. Suppressed, privileged and subpoenaed material must not be entered into any AI tool unless strict conditions are met, and expert reports require the court’s leave before AI-assisted content can be relied on at all.
Victoria’s position changed materially and more recently. Practice Note SC Gen 25, effective 14 May 2026, replaced the Supreme Court of Victoria’s 2024 litigant guidelines. What was previously non-binding guidance is now a binding practice note, and applies to all court users. It draws an explicit line between public AI and closed AI tools, and states plainly that one AI tool cannot be used to verify another’s output; there must be “meaningful human control”. Asking ChatGPT to check a citation ChatGPT itself supplied is not verification. Firms with otherwise mature AI policies may not yet have caught up with this change.
The message across all three jurisdictions is consistent - AI use is permitted, but professional responsibility obligations remain exactly the same regardless. Practitioners appearing across jurisdictions need to know which regime applies in which registry, because the specific obligations differ.
Hallucinations
In Dayal [2024] FedCFamC2F 1166, a Victorian solicitor filed AI-generated content containing inaccurate citations. The Victorian Legal Services Board’s response, in August 2025, was significant - loss of the right to practise as a principal, loss of authorisation to handle trust money, and two years of supervised practice with quarterly reporting. In Handa & Mallick [2024] FedCFamC2F 957, a list of prior cases submitted to the court simply did not exist; the practitioner said he had relied on his practice management software’s AI feature and had not used its verification process. In Valu v Minister for Immigration and Multicultural Affairs, a lawyer’s use of ChatGPT produced fabricated cases and led to a referral to the Legal Services Commissioner.
Damien Charlotin’s public tracker of AI hallucination incidents in courts records approximately 96 reported Australian incidents involving hallucinations, misrepresentations, false quotes or incorrect legal “norms” as at July 2026, across every level of the court system. Lawyers, not only self-represented litigants, appear as the source in a material number of entries. The figure should be read with care - it captures only what was detected, raised and published, so it is likely a floor rather than a ceiling on what is actually occurring.
The pattern is not confined to Australia, or to smaller practices. In April 2026, one of America’s most prominent law firms, Sullivan & Cromwell, apologised to a US federal bankruptcy judge after filing documents containing AI-generated hallucinations, despite having comprehensive AI policies and mandatory training in place. Even more awkwardly, the errors were detected by opposing counsel, not the firm. This was not a case of no policy existing. It shows that having a policy and applying it under the pressure of a looming deadline are two different disciplines.
Beyond the courtroom: privilege and confidentiality
The risk is broader than litigation practice, and it reaches privilege directly. In Munir v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the UK Upper Tribunal found that the actions of a lawyer in uploading confidential documents to a publicly available AI tool placed that information in the public domain, breaching confidentiality, and permanently waiving legal professional privilege. While the decision is not binding in Australia, its reasoning is consistent with concerns already reflected in GPN-AI at paragraphs 4.13 to 4.15 - information given to a generally accessible generative AI tool may become available to others, and users often do not know where it is stored or who can access it. Entering material into a supposedly ringfenced or confidential tool is not necessarily a complete answer either. GPN-AI notes that outputs later used for a different purpose than originally intended can still create disclosure problems, even where none was ever intended.
For Australian practitioners, the practical implication is clear - if your firm does not know whether an AI tool is open or closed source, and what its provider does with inputs, you do not have the information you need to be sure of protecting a client’s privilege.
Privilege is not automatically lost the moment a lawyer uses gen AI. Client legal privilege, whether under the uniform Evidence Act framework or the common law dominant purpose test confirmed in Esso Australia Resources Ltd v Federal Commissioner of Taxation (1999) 201 CLR 49, turns on whether a communication was made, or a document prepared, for the dominant purpose of giving or obtaining legal advice, or for use in litigation. Prompts and outputs generated by a lawyer, at the lawyer’s direction, for that dominant purpose, are capable of being privileged in the same way any other file note or draft can be. What is much harder to protect is material generated independently by a client, without a lawyer’s involvement, particularly where it has already been typed into a public platform. This is the gap Lanmar’s directors fell into - there was no lawyer, so there was no privilege to lose, only a complete evidentiary record of how the strategy was developed.
The practical lesson is to control the process, not just the outcome. Where AI is used to help form legal advice, that use should be directed by the lawyer, recorded as part of the file, and treated with the same discipline as any other privileged working document. Where a client has already used AI before instructions are taken, the task becomes triage - what has already been disclosed to a third-party platform cannot be un-disclosed.
Discoverability
A related and newer question is what happens to AI prompts and outputs once litigation is on foot, or reasonably anticipated. There is no Australian decision squarely on point at the time of writing, but a body of United States case law is developing quickly and is instructive, at least as an indication of the potential future direction that Australian courts will take. It is foreign authority, not Australian law, and readers should treat it accordingly.
US courts have so far applied existing e-discovery and privilege frameworks to generative AI materials rather than creating an AI-specific standard - relevance and reasonableness govern discoverability, and existing privilege and work product principles govern protection. Where a lawyer’s own prompts reflect legal strategy, US courts have treated prompts crafted by counsel to test legal theories as akin to opinion work product and protected them from production. Where a client’s own AI use was not directed by counsel and contained no legal advice, the position has been different - a spreadsheet of employee prompts was found not to be privileged (see “Discoverability of Generative AI Prompts and Outputs: Best Practices for Litigation Holds”, by Joel D. Bush, for further detail).
Australia has no direct equivalent yet, but the underlying logic is already visible in Lanmar, where chat logs could become the subject of evidence because privilege was never attached to them. The practical guidance transfers even without a binding Australian authority - lawyers should know where AI interaction logs are stored, know each platform’s default retention period, and treat them as part of the total body of documents the moment litigation is reasonably anticipated, in the same way any other electronic record would be treated. Preservation of evidence procedures that do not expressly capture AI prompts, outputs and related logs will be incomplete, and US commentary already flags that generative AI logs often sit on short default retention windows that are inconsistent with the preservation requirement unless someone actively intervenes.
The client-facing dimension
There is another dimension that has nothing to do with what a lawyer types into a tool. Lanmar’s directors executed an ill-advised strategy precisely because no lawyer was in the loop at any stage. Clients now arrive at first consultations with views of their legal position already shaped by AI, which are sometimes accurate, and sometimes not. Recognising when a client’s “research” is really a chatbot transcript, and correcting a mistaken impression before it hardens into conduct, is now part of giving competent advice. It helps to point clients to the tool’s own terms of use, which typically state plainly that it is not providing legal advice, even in cases where that is exactly what has occurred, only without anyone holding a practising certificate.
Five questions to ask
None of this is an argument for avoiding AI. Used well, it saves time and money and can improve the quality of work. What it requires is a habit of recording that use and being ready to explain it. Large corporate clients already ask law firms to list the tools they use as part of due diligence, and opposing lawyers are starting to demand production of prompt records where no valid privilege claim exists. Whatever the practice area, litigation, transactional, advisory or in-house, the following five questions give a defensible starting point for any AI-assisted piece of work:
What tool was used, and is it open source, on a public platform such as ChatGPT or Claude, or closed source, such as Harvey, a tool where no information leaves the firm?
What information went into it, and was any of that confidential?
Who verified the output, and how, given that under court practice rules an AI tool cannot verify its own output or another AI tool’s output?
What records exist of the prompts and outputs?
Who supervised the work, and did they know AI was involved?
A practitioner who can answer all of the above questions, and who can show that the applicable court rules and professional obligations were complied with, is in a defensible position. A practitioner who cannot is exposed, regardless of whether anything has actually gone wrong yet, to potential findings of breach of confidentiality, breach of duties to the court, or a failure of supervision.
Not a technology problem
None of the matters discussed above suggest the technology is not useful. Each one came down to unexamined trust in a plausible-sounding answer, misplaced confidence that uploading information wasn’t really a breach of confidentiality, a supervisor accepting work presented by a junior colleague without asking whether AI was used, or simply no one pausing to ask whether the question being answered was the right one.
That’s a judgment problem, not a tech failure, and it’s one that a policy document sitting unread in a shared drive won’t fix. It makes sense to build the habit now of asking those five questions, before a regulator, a judge, an opponent or a client asks them instead.
This article was researched and directed by the author, drafted with the assistance of AI tools using the author's prior writing and other source materials, and reviewed, verified and finalised by the author before submission.