Decades in Business,
Technology and Digital Law

  1. Home
  2. โ€”
  3. Blog
  4. โ€”
  5. ๐Ÿค–AI Chats May Not Be Privileged

๐Ÿค–AI Chats May Not Be Privileged

by | Feb 23, 2026 | Blog

AI and Attorney Client Privilege

On February 17, 2026, Judge Jed Rakoff of the Southern District of New York issued a significant ruling in United States v. Bradley Heppner. The opinion squarely addressed whether conversations with a publicly available generative AI system can be protected by attorney-client privilege or the work product doctrine.

The courtโ€™s answer: not under the circumstances presented.

This decision has immediate implications for executives, compliance teams, and individuals who use public AI platforms to think through legal strategy.


๐“๐ก๐ž ๐…๐š๐œ๐ญ๐ฌ ๐๐ž๐ก๐ข๐ง๐ ๐ญ๐ก๐ž ๐‘๐ฎ๐ฅ๐ข๐ง๐ 

The case arose in a federal securities fraud prosecution. After learning he was under investigation, the defendant used a widely available AI chatbot to evaluate potential defenses, analyze legal exposure, and explore anticipated arguments from the government.

When authorities executed a search warrant in late 2025, they recovered dozens of documents reflecting those AI exchanges.

The defendant argued the materials were protected because:

  • He had incorporated information obtained from counsel,

  • He prepared the materials to assist in discussions with his attorneys, and

  • He later shared the outputs with them.

However, defense counsel acknowledged they had not instructed him to use the AI tool.


๐“๐ก๐ž ๐‚๐จ๐ฎ๐ซ๐ญโ€™๐ฌ ๐€๐ง๐š๐ฅ๐ฒ๐ฌ๐ข๐ฌ

Judge Rakoff applied traditional privilege doctrine and found multiple deficiencies.

1๏ธโƒฃ No Attorney-Client Relationship

Attorney-client privilege protects communications between a client and a licensed attorney (or an agent acting on the lawyerโ€™s behalf). A public AI system is neither. The court emphasized that privilege depends on a professional human relationship grounded in fiduciary duties and regulatory oversight. An algorithm cannot satisfy that requirement.

2๏ธโƒฃ No Reasonable Expectation of Confidentiality

The AI providerโ€™s published terms disclosed that user inputs and outputs could be collected, used for system improvement, and disclosed under certain circumstances. By agreeing to those terms, the defendant undermined any assertion that the communications were confidential.

Even if privileged information had originally been involved, sharing it with a third-party platform constituted waiver.

3๏ธโƒฃ Not Communications for Legal Advice from Counsel

Although the defendant maintained that he intended to discuss the AI output with his lawyers, he independently chose to use the system. Because counsel did not direct or supervise the AI use, the chatbot was not treated as the lawyerโ€™s agent.

The relevant inquiry became whether he was seeking legal advice from the AI โ€” which does not trigger privilege protection.


๐–๐จ๐ซ๐ค ๐๐ซ๐จ๐๐ฎ๐œ๐ญ ๐ƒ๐จ๐œ๐ญ๐ซ๐ข๐ง๐ž

The court also rejected work product protection. That doctrine applies to materials prepared by or at the direction of counsel in anticipation of litigation. Since the defendant used the AI tool on his own initiative, and not under attorney instruction, the protection did not attach.


๐†๐จ๐ฏ๐ž๐ซ๐ง๐š๐ง๐œ๐ž ๐ˆ๐ฆ๐ฉ๐ฅ๐ข๐œ๐š๐ญ๐ข๐จ๐ง๐ฌ

The lesson from United States v. Heppner is practical and immediate:

  • Public AI tools are not confidential advisors.

  • Terms of service can defeat privilege arguments.

  • Independent AI use may waive otherwise protected information.

  • Counsel involvement is critical if AI is used in litigation strategy.

For companies developing AI governance programs, privilege risk must now be explicitly addressed in policies, training, and vendor contracting.

This is no longer a theoretical concern. It is judicial precedent.

How Can GalkinLaw Help?

Fields marked with an * are required

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Would you like to schedule an initial consultation?
How do you prefer to be contacted?
This field is hidden when viewing the form
Disclaimer