Federal Courts Split on Whether Using AI Waives Attorney-Client Privilege
Two federal courts have reached opposite conclusions on whether typing legal strategies into generative AI tools destroys confidentiality protections, creating a high-stakes circuit split for the legal industry.
- Strict Confidentiality Advocates
- Argues that public AI tools function as third parties that destroy the expectation of privacy.
- Pragmatic Technologists
- Contends that AI programs are passive tools, not persons, and should not automatically waive protections.
- Enterprise AI Proponents
- Believes the solution lies in closed-loop, enterprise-grade AI systems with strict data privacy contracts.
Why this matters
If using a popular AI chatbot to analyze legal documents waives attorney-client privilege, millions of individuals and corporations could unknowingly be exposing their most sensitive legal strategies to their adversaries. This judicial split means that until the Supreme Court weighs in, the simple act of prompting an AI could cost a litigant their case.
Key points
- Two federal courts issued conflicting rulings in February 2026 on whether using AI waives legal privilege.
- A New York court ruled that using public AI tools destroys confidentiality because the platforms can train on user data.
- A Michigan court ruled that AI programs are 'tools, not persons,' preserving work-product protections.
- The split highlights the difference between attorney-client privilege and the more resilient work-product doctrine.
- Legal experts are urging firms to abandon public chatbots in favor of closed-loop enterprise AI systems.
The legal profession is built on a foundation of absolute secrecy. For centuries, the attorney-client privilege has guaranteed that what a client tells their lawyer cannot be used against them in court, fostering an environment of total candor. But the rapid, ubiquitous adoption of generative artificial intelligence has violently collided with this ancient doctrine, sparking a high-stakes existential question for the justice system: Does typing your legal strategy into a chatbot waive your right to confidentiality? As lawyers and clients alike integrate large language models into their daily workflows to summarize documents and draft arguments, they may unknowingly be handing their most sensitive secrets to their adversaries.[1][7]
In early 2026, this theoretical debate erupted into a formal judicial conflict. On the exact same day in February, two federal courts handed down diametrically opposed rulings on whether using AI tools destroys legal protections. This emerging circuit split has sent shockwaves through law firms and corporate legal departments across the country. It leaves litigators to navigate a doctrinal minefield where a single prompt could expose their entire case strategy. The conflicting decisions highlight how the law is struggling to keep pace with technological innovation, forcing judges to apply centuries-old evidentiary rules to cloud-based neural networks.[3][6]
The threat to legal confidentiality was starkly illustrated in the Southern District of New York in the case of United States v. Heppner. The defendant, a financial services executive facing severe federal fraud charges, utilized Anthropic's public AI tool, Claude, to analyze his legal exposure and draft comprehensive defense strategies. When federal agents executed a search warrant and seized his electronic devices, they discovered thirty-one documents generated through his interactions with the AI platform. The government immediately moved to compel the production of these documents, arguing that the AI-generated files were not privileged and could be used as direct evidence against him in court.[3][5]
Judge Jed S. Rakoff agreed with the government, delivering a decisive bench ruling that stripped the documents of both attorney-client privilege and work-product protection. The court's reasoning was blunt and structural: an AI platform is a machine, not a lawyer, and therefore cannot form a legally binding attorney-client relationship. More importantly, because the defendant used a public-facing AI tool whose privacy policy explicitly allowed user inputs to be retained and potentially used for future model training, the court ruled he had forfeited any 'reasonable expectation of confidentiality.' By sharing his secrets with the platform, he had effectively broadcast them to a third party.[3][5]

Yet, hundreds of miles away in the Eastern District of Michigan, a different federal judge reached the exact opposite conclusion in the civil case Warner v. Gilbarco, Inc. In this instance, a litigant representing himself used a public AI chatbot to prepare his litigation materials and organize his arguments. When the opposing side discovered this and attempted to compel the production of those AI-generated documents during discovery, the court firmly blocked the request. The judge ruled that the materials remained fully protected, setting up a direct ideological clash with the New York court's interpretation of digital privacy.[4][6]
The Michigan court anchored its decision in the fundamental nature of the technology itself, declaring that generative AI programs are 'tools, not persons.' The judge reasoned that inputting data into an AI platform's interface is not legally equivalent to disclosing secrets to a human third-party eavesdropper. Because the work-product doctrine is generally only waived when materials are shared directly with an adversary—or in a manner highly likely to reach an adversary—the court concluded that the AI's internal data processing and server storage did not constitute a waiver of legal protections.[4][6]
To fully understand this judicial collision, one must parse the mechanical differences between the two legal doctrines at play. The attorney-client privilege is notoriously fragile; it strictly protects communications between a lawyer and a client, but it is instantly destroyed if a third party is allowed to listen in. If a court views an AI company—or its server architecture—as a third-party eavesdropper, the privilege evaporates the moment the user hits the 'send' button. This strict standard makes attorney-client privilege highly vulnerable to modern cloud computing environments.[2][5]
To fully understand this judicial collision, one must parse the mechanical differences between the two legal doctrines at play.
The work-product doctrine, however, is significantly more resilient. It is designed to protect materials prepared specifically in anticipation of litigation, shielding a lawyer's mental impressions, conclusions, and trial strategies from the opposing side. Unlike attorney-client privilege, work-product protection survives incidental disclosure to third parties, provided that the disclosure does not substantially increase the risk that the adversary will obtain the information. This crucial distinction explains why the Michigan court was able to save the AI documents under the work-product doctrine, while the New York court struck them down under the stricter privilege standard.[2][4]

The circuit split has forced the legal community to confront the underlying architecture of generative AI. Historically, lawyers used software like Microsoft Word, Excel, or Westlaw without any fear of waiving privilege, because those tools were passive local applications or highly secure, closed databases. But public generative AI models are fundamentally different entities. They actively ingest user inputs, process them on external servers, and often retain that data to train future iterations of the model, creating a permanent digital footprint of the user's thought process.[2][7]
This active data-retention mechanism is the absolute crux of the confidentiality crisis. If an AI platform's terms of service allow it to review user prompts, share them with human reviewers for quality control, or use them for algorithmic training, courts are increasingly likely to rule that the user has voluntarily disclosed their secrets. The New York City Bar Association recently issued a comprehensive report warning that market participants must understand these underlying data flows, noting that the specific terms of service of the AI platform will be the deciding factor in any future privilege dispute.[2][6]
In response to this paralyzing uncertainty, a clear dividing line is emerging between consumer-grade and enterprise-grade artificial intelligence. Legal experts and professional associations are urgently advising law firms to abandon public chatbots entirely in favor of closed-loop, enterprise AI systems. These enterprise platforms operate under strict data processing agreements that contractually guarantee user inputs will not be used for model training or accessed by the AI provider. By eliminating the third-party data risk, these systems attempt to preserve the expectation of confidentiality required by the courts.[4][7]
The procedural landscape of litigation is already shifting rapidly to accommodate this new technological reality. Federal judges across the country are proactively updating standard protective orders to address the unique privacy risks of artificial intelligence. Some courts have even begun issuing blanket prohibitions on the use of public AI tools for any discovery materials, mandating that litigants either use closed enterprise systems or risk severe judicial sanctions for unauthorized data exposure. The era of unregulated AI use in legal discovery is effectively over.[4][7]
This technological shift also deeply implicates the ethical obligations of practicing attorneys. The American Bar Association explicitly requires lawyers to maintain technological competence, meaning they cannot simply ignore artificial intelligence or refuse to understand how it works. However, this duty to innovate is now directly at odds with their ironclad duty of client confidentiality. Litigators must now act as amateur technologists, rigorously auditing the data architecture, server locations, and privacy policies of any software they deploy in their daily practice.[1][2]
The factual nuances of the early 2026 cases leave several critical questions unanswered for the broader legal industry. In the Michigan case, the litigant was acting pro se—representing himself—which legally merges the roles of client and attorney and complicates the standard privilege analysis. In the New York criminal case, the defendant used the AI independently, without the explicit direction or supervision of his counsel. It remains entirely to be seen how appellate courts will rule when a fully retained, licensed attorney uses a public AI tool on behalf of a corporate client.[2][6]
As these foundational cases inevitably march toward the federal appellate courts, the legal industry remains in a precarious state of suspended animation. The eventual resolution of this circuit split will dictate the future of legal technology for decades to come. It will ultimately determine whether artificial intelligence becomes an indispensable, protected partner in the pursuit of justice, or a fatal liability that strips litigants of their most fundamental constitutional protections. Until the Supreme Court weighs in, every AI prompt carries a hidden legal risk.[6][7]
How we got here
November 2025
Federal agents arrest Bradley Heppner and seize 31 AI-generated defense documents.
February 10, 2026
A federal judge in New York rules Heppner's AI-generated documents are not protected by privilege.
February 10, 2026
On the same day, a federal judge in Michigan rules a pro se litigant's AI-generated materials are protected as work product.
March 30, 2026
A federal court in Colorado aligns with the Michigan ruling, holding that AI interactions do not automatically compromise work product.
Viewpoints in depth
Strict Confidentiality Advocates
Argues that public AI tools function as third parties that destroy the expectation of privacy.
This camp, heavily represented by white-collar defense attorneys and privacy purists, argues that the mechanical reality of public generative AI is incompatible with legal privilege. Because platforms like ChatGPT and Claude ingest prompts, process them on external servers, and reserve the right to train future models on that data, they function as third-party eavesdroppers. In their view, inputting a client's secret into a public prompt box is legally indistinguishable from discussing a case loudly in a crowded coffee shop.
Pragmatic Technologists
Contends that AI programs are passive tools, not persons, and should not automatically waive protections.
Proponents of this view argue that the legal system must adapt to modern workflows rather than applying analog rules to digital tools. They point out that lawyers have used third-party cloud servers, email providers, and legal research databases for decades without waiving privilege. By classifying AI as a 'tool' rather than a 'person,' this camp believes that standard work-product protections should survive AI assistance, provided the litigant takes reasonable steps to ensure the outputs do not fall directly into the hands of an adversary.
Enterprise AI Proponents
Believes the solution lies in closed-loop, enterprise-grade AI systems with strict data privacy contracts.
This perspective seeks a middle ground, arguing that the confidentiality crisis is a licensing problem, not an inherent flaw in artificial intelligence. They advocate for the exclusive use of enterprise-grade AI systems that operate under strict Data Processing Agreements (DPAs). Because these closed-loop systems contractually guarantee that user inputs will not be reviewed by humans or used to train underlying models, this camp argues they successfully preserve the 'reasonable expectation of confidentiality' required by courts.
What we don't know
- How federal appellate courts will ultimately resolve the conflicting district court rulings.
- Whether courts will treat a fully retained attorney's use of AI differently than a pro se litigant's use.
- If the Supreme Court will eventually have to decide whether an AI model constitutes a 'person' for the purposes of legal disclosure.
Key terms
- Circuit Split
- When different federal appellate or district courts reach opposing conclusions on the same legal issue, often requiring Supreme Court intervention.
- Attorney-Client Privilege
- A legal doctrine that protects confidential communications between a lawyer and their client from being disclosed to outside parties.
- Work-Product Doctrine
- A rule that protects materials prepared by an attorney or client in anticipation of litigation, shielding their mental impressions and strategies from adversaries.
- Pro Se
- A legal term for a litigant who represents themselves in court without the assistance of an attorney.
- Generative AI
- Artificial intelligence systems capable of generating text, analysis, or other content based on user prompts, often relying on large language models.
Frequently asked
Does using ChatGPT waive my attorney-client privilege?
It depends on the tool and the jurisdiction. Courts have ruled that using public AI tools with open privacy policies can destroy privilege, as it constitutes sharing secrets with a third party.
What is the difference between attorney-client privilege and work-product protection?
Attorney-client privilege protects communications and is waived if any third party is present. Work-product protects litigation strategy and is generally only waived if the information is shared with an adversary.
Are all AI tools a risk to legal confidentiality?
No. Legal experts distinguish between public consumer chatbots, which may train on user data, and closed-loop enterprise AI systems, which contractually guarantee that data remains private and untrained.
Sources
[1]American Bar AssociationStrict Confidentiality Advocates
Legal and Ethical Considerations for Generative AI Use in Litigation
Read on American Bar Association →[2]New York City Bar AssociationEnterprise AI Proponents
Report on Generative AI and the Attorney-Client Privilege
Read on New York City Bar Association →[3]BakerHostetlerStrict Confidentiality Advocates
AI Is Not Your Lawyer: Federal Court Rules AI-Generated Documents Are Not Privileged
Read on BakerHostetler →[4]Akin GumpEnterprise AI Proponents
Federal Courts Address AI and Privilege in Q1 2026
Read on Akin Gump →[5]White & CaseEnterprise AI Proponents
Public AI Chatbot Use Undermines Privilege and Work Product Protections
Read on White & Case →[6]Sidley AustinPragmatic Technologists
Federal Courts Address Generative AI in the Privilege Context
Read on Sidley Austin →[7]Factlen Editorial TeamEnterprise AI Proponents
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get law justice stories with full source coverage and perspective breakdowns delivered to your inbox.









