Federal Court Rules Prompts to Public AI Platforms Are Not Protected by Attorney-Client Privilege
A landmark federal ruling has established that using consumer-grade artificial intelligence tools to process legal information waives attorney-client privilege. The decision warns that public chatbots are legally considered third parties, leaving sensitive prompts and outputs vulnerable to discovery in litigation.
The modern executive faces a dilemma: they have a powerful artificial intelligence assistant on their laptop, but a looming legal crisis on their desk. When they feed legal strategies into the chatbot to organize their thoughts, are they talking to a confidant, or broadcasting to the prosecution?[1]
A landmark federal ruling has just answered that question. In United States v. Heppner, a New York federal judge ruled that prompts and outputs generated by public AI platforms are not protected by attorney-client privilege or the work-product doctrine.[3]
The decision by Judge Jed S. Rakoff of the Southern District of New York serves as a nationwide warning. It clarifies that feeding sensitive legal information into consumer-grade AI tools effectively waives confidentiality, treating the AI not as a legal assistant, but as a third-party stranger.[5]
The case centered on Bradley Heppner, a financial services executive facing federal fraud charges. After receiving a grand jury subpoena, Heppner consulted his attorneys and then turned to Anthropic's Claude to synthesize his defense strategy.[8]
Heppner inputted details he had learned from his legal counsel into the chatbot. In response, Claude generated 31 documents outlining potential defense strategies, which Heppner subsequently shared with his lawyers.[1][7]
When federal agents executed a search warrant at Heppner's residence in November 2025, they seized his electronic devices. The government discovered the AI-generated documents and moved to review them, prompting Heppner's legal team to claim they were shielded by attorney-client privilege.[8]
To understand the court's rejection of this claim, one must examine the mechanics of legal privilege. The attorney-client privilege requires a communication between a client and a licensed attorney, made in strict confidence, for the express purpose of obtaining legal advice.[6]
Judge Rakoff systematically dismantled the defense's argument, starting with the most basic requirement. The court noted that an AI platform is plainly not an attorney. Because the software lacks a law license, fiduciary duties, and professional discipline, interacting with it cannot constitute a lawyer-client communication.[3][8]
The most technically significant part of the ruling focused on the expectation of privacy. The court examined the terms of service for public AI platforms, noting that consumer agreements routinely allow the provider to retain user inputs, use them for model training, and disclose them to government authorities.[1][5]
By agreeing to these terms, the court reasoned, a user forfeits any reasonable expectation of confidentiality. In the eyes of the law, typing privileged information into a public chatbot is functionally identical to discussing a legal strategy loudly in a crowded coffee shop.[2][4]
The defense also attempted to shield the documents under the work-product doctrine, which protects materials prepared in anticipation of litigation. However, this protection typically requires the materials to be prepared by or at the specific direction of legal counsel.[2][6]
Because Heppner initiated the AI queries independently, without his lawyers instructing him to do so, the court ruled the resulting documents were not attorney work product. The fact that he later handed the AI outputs to his lawyers did not retroactively grant them protection.[8]
Legal experts note that the ruling specifically targeted publicly available AI platforms. This leaves an open question regarding enterprise-tier AI systems, which often feature strict data isolation contracts guaranteeing that user inputs are never retained or reviewed by the provider.[1][4]
A separate ruling in Michigan, Warner v. Gilbarco, highlighted this nuance. In that case, a self-represented litigant maintained work-product protection over AI-generated documents because, as a pro se plaintiff, they were acting as their own attorney and the AI was deemed a mere tool rather than a third party.[6]
For businesses and individuals navigating litigation, the mechanical takeaway is clear. Public generative AI tools cannot be used as sounding boards for sensitive legal matters without risking exposure during discovery.[1][7]
The ruling bridges the gap between centuries-old legal doctrines and cutting-edge technology. It establishes that while AI can simulate the reasoning of a lawyer, it cannot provide the legal shield of one, forcing a fundamental rethink of how professionals integrate chatbots into their legal workflows.[5]
Viewpoints in depth
Corporate Legal Departments
In-house counsel are rapidly updating policies to restrict the use of public AI tools.
Following the Heppner ruling, corporate legal departments are treating public AI platforms as a severe liability. Many are issuing immediate directives prohibiting employees from entering any information related to investigations, pending litigation, or communications with counsel into consumer-grade chatbots. Instead, they are accelerating the adoption of closed, enterprise-tier AI systems that contractually guarantee data isolation and confidentiality, hoping these platforms will survive future privilege challenges.
Litigators and Prosecutors
Opposing counsel are emboldened to request AI prompts in discovery to uncover opposing strategies.
The government's success in piercing the privilege veil has provided a new playbook for litigators. Adversaries are now expected to routinely request 'AI prompts and outputs' during discovery, scouring privilege logs for any indication that a client used a chatbot to brainstorm legal problems. This creates a potential backdoor into a party's thought processes and vulnerabilities that would have been entirely shielded had the client simply spoken to a human attorney.
Pro Se Litigants
Self-represented individuals maintain different protections when using AI as a drafting tool.
While the Heppner ruling serves as a warning for represented clients, a parallel decision in Michigan (Warner v. Gilbarco) suggests a different standard for those representing themselves. Because a pro se litigant acts as both party and advocate, courts have shown a willingness to treat their use of generative AI as protected work product, viewing the chatbot as a mechanical drafting tool rather than a third-party confidant. This distinction preserves access to AI assistance for those who cannot afford traditional legal counsel.
Key points
- A federal judge ruled that prompts to public AI platforms are not protected by attorney-client privilege.
- The court found that AI chatbots are not attorneys and cannot form a lawyer-client relationship.
- Public AI privacy policies that allow data retention eliminate any reasonable expectation of confidentiality.
- Documents generated independently by a client using AI do not qualify for work-product protection.
What we don’t know
- Whether enterprise-grade AI platforms with strict data isolation contracts will survive similar privilege challenges.
- How state courts will interpret AI privilege issues under their specific statutory frameworks.
- Whether an attorney explicitly directing a client to use a public AI tool would be enough to trigger work-product protection.
How we got here
October 2025
Bradley Heppner is indicted on federal securities and wire fraud charges.
November 2025
Federal agents execute a search warrant at Heppner's residence, seizing electronic devices containing 31 AI-generated documents.
February 6, 2026
The government files a motion seeking a ruling that the AI-generated documents are not privileged.
February 10, 2026
Judge Jed S. Rakoff issues an oral bench ruling granting the government's motion.
February 17, 2026
Judge Rakoff publishes the written memorandum opinion, establishing a nationwide precedent on AI and legal privilege.
- Corporate Defense Counsel
- Argues that AI is merely a modern tool, akin to a legal research database, and its use should not automatically waive privilege.
- Federal Prosecutors
- Maintains that public AI platforms are third parties with no duty of confidentiality, making any disclosure to them a waiver of privilege.
- Legal Technology Advocates
- Emphasizes the distinction between public and enterprise AI, arguing that properly secured platforms can maintain confidentiality.
Perspectives this story doesn't cover
- AI Platform Providers
- Civil Liberties Organizations
Sources
[1]Dorsey & WhitneyFederal ProsecutorsIn the fast-paced intersection of artificial intelligence and law, a big decision by a New York federal judge
Read on Dorsey & Whitney →
[2]Husch BlackwellLegal Technology AdvocatesKey Point: In a question of first impression, a federal judge's ruling that documents a client's prompts
Read on Husch Blackwell →
[3]Lowenstein SandlerCorporate Defense CounselFederal Court Rules Client's AI-Generated Materials Are Not Protected by Attorney-Client Privilege or Work Product Doctrine
Read on Lowenstein Sandler →
[4]Business Valuation ResourcesLegal Technology AdvocatesA federal court has issued what appears to be the first ruling directly addressing whether attorney-client privilege
Read on Business Valuation Resources →
[5]Gibson DunnCorporate Defense CounselClient Alert | February 20, 2026
Read on Gibson Dunn →
[6]White & CaseCorporate Defense CounselAs clients and lawyers increasingly turn to generative AI tools to enhance legal work
Read on White & Case →
[7]Saiber LLCCorporate Defense CounselIn a case that has significant implications for those using AI tools for legal matters
Read on Saiber LLC →
[8]BakerHostetlerFederal ProsecutorsAI Is Not Your Lawyer: Federal Court Rules AI-Generated Documents Are Not Privileged
Read on BakerHostetler →
More in Artificial Intelligence
See all →Positional Bias
The Positional Advantage of the System Prompt: How Pre-pending Instructions to the Context Window Constrains LLM Output
5 sources
AI Architecture
The Mechanics of Tokenization: How Text Becomes Numbers and Defines the LLM Context Window
5 sources
Agentic AI
How OpenAI's ChatGPT Work Agent Shifts AI from Prompting to Multi-Hour Delegation
7 sources
Context Engineering
'Context Engineering' Replaces Prompting as Core LLM Skill, Shifting Focus to Context Window Management
8 sources
Comments
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns, free every day.




