As we cautioned in our article discussing the risks of using generative artificial intelligence (AI), a federal court has now confirmed those concerns in one of the first decisions of its kind. In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026), Dkt. No. 27, the United States District Court for the Southern District of New York held that a defendant’s communications with the consumer version of AI tool Claude were discoverable because they were not protected by attorney-client privilege or the attorney work product doctrine, even though the defendant had included and discussed communications with his own counsel in those AI exchanges.
The key lesson is simple but serious: If you paste your lawyer’s advice or legal strategy into a public AI system, you may be giving up privilege.
Why Privilege Did Not Apply
For attorney-client privilege to exist:
The communication must be with a lawyer.
It must be intended to stay confidential.
It must be for the purpose of getting legal advice.
The AI conversations failed that test. First, an AI platform is not a licensed attorney. No matter how advanced it is, it does not owe you professional duties. Second, the platform’s privacy policy allowed it to store and potentially disclose user information. Because of that, the court said the user could not reasonably expect the conversation to remain private. And without confidentiality, there is no privilege. Third, the defendant used the AI tool on his own, not at his lawyer’s direction. The court noted that simply sharing the AI output later with counsel does not “fix” the problem. Once you share sensitive information with a third party, privilege may already be lost.
Why Work Product Protection Also Failed
The defendant also argued that the materials were protected as legal “work product.” The court disagreed. Work product generally protects materials prepared by a lawyer, or at a lawyer’s direction, as part of preparing a case.
Here, the documents were created by the client alone, without instruction from counsel, and did not reflect the lawyer’s thinking at the time. That was not enough for protection.
What Information Is at Risk?
This ruling should be taken seriously by businesses and individuals. The following types of information may not be protected if entered into public AI systems (including publicly available AI chats, platforms or similar tools):
Emails or summaries of legal advice from your attorney
Draft defense strategies
Internal investigation findings
Regulatory exposure assessments
Confidential facts you discussed with counsel
Notes summarizing meetings with your lawyer
Even if your intention is simply to better understand your lawyer’s advice or to prepare questions, entering that advice into a public AI system may be treated as sharing it with a third party.
An Evolving Area of Law
This appears to be one of the first federal decisions directly addressing privilege in the context of generative AI. Other federal or state courts may analyze similar facts differently, particularly where secure enterprise systems are used or where AI tools are deployed at counsel’s direction.
We will continue to monitor developments and provide updates as courts further address these issues.
Bottom Line
Public AI tools are powerful, but they are not part of your legal team. Before entering attorney advice, litigation strategy, or sensitive legal information into any open AI system, consult with counsel. Once privilege is waived, it may be difficult, if not impossible, to restore it.


