top of page

Your AI Chat Is Not Privileged: What Clients Need to Know Before Asking a Chatbot

dnelson58
Aug 26
5 min read

Clients increasingly arrive at a first meeting having already “researched” the matter with an AI chatbot. They typed in the facts, described the dispute, sometimes pasted an email from a prior lawyer, and asked what to do. It feels private. You are typing alone into a window, the way you might write in a journal.


It is not private. In February 2026 a NY federal court held for the first time that a defendant’s exchanges with a consumer AI chatbot were protected by neither the attorney-client privilege nor the work product doctrine, and were available to prosecutors. Every client should understand what that means before the next time they open a chat window.


United States v. Heppner

In United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. Feb. 17, 2026), Judge Jed Rakoff addressed what he called a question of first impression nationwide. Bradley Heppner, a former financial services executive facing securities and wire fraud charges, had generated a set of documents by prompting a consumer version of an AI chatbot about his own case. Federal agents seized the documents from his devices during a search. Heppner asserted privilege and work product protection. The government moved for a ruling that neither applied. The court ruled from the bench on February 10, 2026, and issued a written opinion on February 17.


The court held the materials failed at least two, and possibly all three, elements of the privilege, any one of which would be fatal.


First, the exchange was not between a client and an attorney. As the court put it, because the chatbot is not an attorney, that alone disposed of the privilege claim. An AI system holds no license, owes no duty of loyalty, and cannot form an attorney-client relationship.


Second, the communications were not made in confidence. The court examined the platform’s terms of service and privacy policy and found they defeated any reasonable expectation of confidentiality. This is the point clients find most surprising: where the provider may retain, review, or train on user inputs, there was never a protected communication to begin with. Nothing was waived, because nothing was privileged in the first place.


Third, the court questioned whether a user can be seeking legal advice from a tool that expressly disclaims being a lawyer.


Work product failed for a related reason. Heppner’s counsel confirmed the documents were prepared by the defendant on his own initiative, which meant he was not acting as his counsel’s agent when he communicated with the chatbot. The decisive fact throughout was that the client acted unilaterally, without direction from his lawyers.


Some Nuance Remains

One week before the Heppner written opinion, in Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629 (E.D. Mich. Feb. 10, 2026), a magistrate judge denied a motion to compel a self-represented litigant’s AI-assisted materials, holding that work product protection applied and reasoning that generative AI platforms are tools rather than persons, so feeding material to one is not disclosure to an adversary. Courts in Texas and New York reached protective results on work product in June 2026.


The distinction is doctrinal, not contradictory. Attorney-client privilege can be defeated by voluntary disclosure to almost any third party outside the circle of confidence. Work product protection is harder to waive; it generally falls only on disclosure to an adversary or in a manner that substantially increases the likelihood an adversary will obtain the material. The same keystrokes can therefore destroy privilege while leaving work product intact. However, the protection clients most need, privilege over their own candid account of the facts, is the one most easily lost.


What About New Jersey, Pennsylvania, and Illinois?

No published decision in New Jersey, Pennsylvania, or Illinois has yet addressed whether communications with a generative AI tool are privileged. The reported activity so far is federal and out-of-state. That absence is not reassurance. It means these questions will likely be resolved under each state’s ordinary privilege and waiver principles, and those principles point the same direction.


The Danger Clients Underestimate: Waiving the Privilege They do Have

Most clients worry that the chat itself becomes evidence. That is real, but the larger exposure runs the other way. When a client pastes an attorney’s email, a litigation strategy, or a summary of what counsel told them into a public AI tool, they are disclosing a privileged communication to a third party. That can waive privilege over the underlying communication, not merely over the chat. The chatbot session is recoverable; the privilege may not be.


Two practical points follow. Pasting AI output into an email to your lawyer does not cure the problem, because the disclosure already happened. And deleting the chat is not a fix: AI chat logs are ordinary electronically stored information, subject to preservation obligations and subpoena, and courts have ordered providers to produce conversation logs and to preserve data that would otherwise have been deleted on the ordinary cycle.


Other Risks, briefly

Privilege is not the only hazard. A chatbot is not licensed, carries no malpractice coverage, and owes no duty of loyalty, so a client who relies on it has no recourse when it is wrong. These tools have produced fabricated case citations that have drawn sanctions against lawyers who filed them. They cannot know facts the client did not supply, cannot spot the issue the client did not think to ask about, and do not track the filing deadline that quietly expires while the client is researching. A confident, fluent, wrong answer is more dangerous than no answer, because it forecloses the question.


Practical Guidance

For clients, the rule is simple: do not use public AI tools to discuss a matter where you have counsel or expect to need counsel. Do not paste your lawyer’s advice into any chatbot. If you have already done so, tell your lawyer immediately and without embarrassment; counsel cannot manage exposure they do not know about, and this is information they need in order to plan.


For counsel, the Heppner opinion contains its own roadmap. The court left open that counsel-directed use of an AI tool, on a platform bound by contractual confidentiality, may preserve protection on reasoning familiar from United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), which extends privilege to accountants, interpreters, and similar agents retained by counsel to assist in rendering legal advice.


Three features tend to matter: the tool is engaged by counsel, used under counsel’s supervision, and subject to enforceable confidentiality terms. Client-initiated use of a consumer tier satisfies none of them.


The technology is genuinely useful. The mistake is treating it as a confidant. A chat window feels like a private conversation with a knowledgeable friend, and it is neither private nor a lawyer. Anything you would not put in an email to a stranger who keeps a permanent copy does not belong in a chatbot.


Legal note: This article provides general information and is not legal advice.



 
 
 

Comments


bottom of page