Skip to main content

Generative AI has slipped into everyday life so quickly that many people now treat a chatbot conversation as a kind of private thinking space: a place to test theories, organize facts, and rehearse arguments before speaking to another human being. That instinct can be especially strong when the stakes are high. If you are facing an investigation, a lawsuit, or a prosecution, it can feel natural to open a blank prompt and ask the model what the law says, what arguments might work, and how a prosecutor might see the facts. In United States v. Heppner, however, a federal judge in the Southern District of New York delivered a blunt reminder that the law does not treat consumer AI tools as an extension of your lawyer’s office. The court ruled that AI-generated documents created by the defendant and later sent to his attorneys did not become privileged simply because they were shared with counsel, and that the underlying communications with the AI platform were not protected by attorney-client privilege or the work-product doctrine. ¹

Please note this blog post should be used for learning and illustrative purposes. It is not a substitute for consultation with an attorney with expertise in this area. If you have questions about a specific legal issue, we always recommend that you consult an attorney to discuss the particulars of your case.

The decision matters not because it invents a brand-new rule of privilege, but because it applies very old rules to a very new habit. Privilege doctrines are built around relationships, confidentiality, and professional accountability. Generative AI systems, especially publicly available consumer tools, are typically operated by third parties that collect and process user inputs under terms users rarely read closely. Heppner turns that mismatch into a practical warning: if you use a public AI platform as your legal sounding board, you may be creating discoverable evidence rather than protected preparation. The case is also notable because Judge Jed S. Rakoff treated the dispute as a “first impression” question in the sense that courts had not previously confronted this exact fact pattern, even though privilege law has long addressed analogous problems involving third-party disclosure and client-created materials. ¹

The procedural posture of the dispute is almost as important as the privilege doctrine. The defendant, Bradley Heppner, was charged in an indictment returned in late October 2025 and unsealed in early November 2025. The indictment alleged serious white-collar offenses, including securities fraud and wire fraud, along with related allegations such as false statements to auditors and falsifying corporate records. ¹ The case moved into pretrial litigation with a trial date set for April 2026, but long before a jury was seated the parties found themselves fighting about documents created outside the usual attorney-client workflow. ¹

When federal agents executed a search warrant connected to Heppner’s arrest, they seized devices and materials from his home. Among the seized items were roughly thirty-one documents memorializing his written exchanges with a generative AI platform called Claude, which is operated by Anthropic. ¹ The documents were created during 2025, after Heppner had received a grand jury subpoena and after it had become clear he was the target of an investigation. According to the defense, he used the AI tool to produce reports outlining defense strategy and potential arguments about facts and law that he anticipated the government might pursue. ¹

Because the seized material included items the defense claimed were privileged, the parties entered a protocol under which the government segregated the AI documents and refrained from reviewing them until the court could resolve the privilege claims. The government then moved for a ruling that the AI documents were protected by neither attorney-client privilege nor work product. After hearing argument at February 10, 2026, pretrial conference, Judge Rakoff granted the motion from the bench and later issued a written memorandum explaining the reasons for the decision. ¹

From a lay perspective, the defense theory is easy to understand. A client, worried about imminent prosecution, uses an AI tool to research law and organize facts. The client then sends the resulting output to his lawyers so they can discuss strategy. That sounds like preparation for legal advice, and privilege law is supposed to encourage candid attorney-client communication. The defendant therefore argued, in substance, that the AI documents were created to support communications with counsel and were ultimately shared with counsel, so they should be treated as privileged. ¹

The problem is that privilege law does not protect “legal preparation” in the abstract. It protects specific kinds of communications under specific conditions, and it often turns on what happened at the moment the communication was made, not on what the client intended to do with it later. Courts also place the burden on the party asserting privilege to show that its elements are satisfied, and they construe privileges narrowly because privilege blocks access to potentially relevant evidence. Judge Rakoff emphasized those traditional principles as the foundation for analyzing a modern tool. ¹

In the Second Circuit, a frequently cited formulation is that attorney-client privilege protects communication between a client and an attorney that are intended to be, and in fact are, kept confidential, for the purpose of obtaining or providing legal advice. ² That formulation is not unique to AI cases; it reflects long-settled doctrine. The key is that communication must be between a client and counsel (or counsel’s agent in limited circumstances), must be confidential, and must be aimed at legal advice rather than general discussion or business planning. ²

The court’s analysis in Heppner treated the AI exchanges as failing multiple elements at once. Even if the defendant was trying to use the AI output as preparation for conversations with counsel, the question was whether communications with the AI platform themselves were privileged, and whether the resulting documents were protected when the government seized them. Judge Rakoff concluded that the AI documents lacked at least two, and possibly all three of the core privilege elements. ¹

The simplest point in the decision is also the most rhetorically powerful: Claude is not an attorney. Privilege, at its core, is anchored to an attorney-client relationship. The court reasoned that communications “between two non-attorneys” about legal issues are not protected by the attorney-client privilege in the absence of the attorney-client relationship that gives the privilege its purpose and legitimacy. ¹   The opinion also noted that “recognized privileges” are tied to trust relationships with licensed professionals who owe duties and are subject to discipline, a structure that does not exist between a user and a consumer AI platform. ¹

This part of the opinion is not merely semantic. Privilege is a policy choice: society tolerates the loss of evidence because confidential lawyer-client communication serves the administration of justice. That policy justification becomes harder to defend when the “advisor” is a third-party product, and the “conversation” is governed by the provider’s terms. In other words, the law is not just asking whether the AI gave something that looked like legal advice; it is asking whether the legal system should treat the AI interaction as part of the legally protected channel between client and counsel. In Heppner, the answer was no. ¹

Even if one tried to conceptualize AI as a tool rather than a conversational partner, the confidentiality requirement was a second, independent barrier. Judge Rakoff concluded that the communications memorialized in the AI documents were not confidential, both because they were made to a third-party AI platform and because the platform’s written privacy policy put users on notice that the provider collected data from user inputs and outputs, used it for model-related purposes, and reserved rights to disclose data to third parties, including governmental or regulatory authorities. ¹ This combination meant the defendant could have had no reasonable expectation of confidentiality in his communications with Claude. ¹

This portion of the ruling is where many readers feel the decision most sharply. People often treat a chat window as private because it feels ephemeral and personal, like thinking out loud. But privilege law asks whether confidentiality was maintained. If the user is told by the governing policy that the provider may retain, use, or disclose the content, then the communication starts to resemble telling your story to a third party rather than confiding in counsel. The court also stressed that the AI documents were unlike confidential notes a client might prepare for a lawyer, because the defendant “first shared the equivalent of his notes” with the AI platform. ¹

Privilege also requires that communication be made for the purpose of obtaining legal advice from the lawyer. In Heppner, the defense argued that the communications with Claude were undertaken for the express purpose of talking to counsel later. The court treated that as a closer question than the “not a lawyer” and “not confidential” problems, but it still concluded that the defendant did not act at the suggestion or direction of counsel when he used the AI tool. ¹ The opinion suggested that if counsel had directed the use of Claude, the platform might arguably have functioned in a manner akin to a professional agent assisting counsel, a concept that appears in privilege law when lawyers use translators, accountants, or other specialists as necessary intermediaries. ¹ But the defendant used the platform on his own initiative, and in that posture the crucial question became whether he intended to obtain legal advice from Claude itself, not whether he later planned to share Claude’s outputs with a lawyer. ¹

This framing is a subtle but important doctrinal move. It separates two ideas people commonly conflate: “I created this to help my lawyer” and “this was a privileged communication.” The first can be true while the second is false. Many documents are created with the hope they will be helpful to counsel timelines, summaries, personal notes, research printouts but privilege does not automatically attach just because a client intends to use them in a legal discussion.

Perhaps the most broadly applicable takeaway in Heppner is the rejection of what might be called the “retroactive privilege” theory. Judge Rakoff wrote that it is black-letter law that non-privileged communications are not somehow transformed into privileged ones merely by being shared with counsel. Because the AI documents would not have been privileged if they stayed in the defendant’s own hands, they did not acquire protection simply because they were transferred to counsel. ¹ The memorandum supported that point by citing Second Circuit authority stating, in essence, that materials do not become privileged merely because they pass through a lawyer’s inbox. ³
This principle reaches far beyond AI. If you email a friend about your legal exposure, that email does not become privileged when you forward it to your attorney. If you write a memo to yourself that contains damaging admissions, the memo does not become privileged because you later send it to counsel. The privilege attaches to specific communications within the attorney-client relationship, not to everything that might be useful in a defense strategy session. AI output, in the court’s view, was no different.

The work-product doctrine is related to privilege but distinct in purpose and scope. Its classic articulation comes from the idea that lawyers must be able to prepare cases with a degree of privacy, without fear that their mental impressions, interviews, and strategic assessments will be freely available to an adversary.  ⁴
Unlike attorney-client privilege, work product can sometimes protect materials prepared by non-lawyers, but it remains anchored to the idea of protecting the lawyer’s thought processes and trial preparation, not shielding everything a party generates while anxious about litigation. ¹

In Heppner, the court assumed for argument’s sake that the AI documents were prepared in anticipation of litigation but still denied work-product protection because they were not prepared by or at the behest of counsel and did not reflect counsel’s strategy at the time they were created. ¹ The defense conceded that counsel did not direct the defendant to run the AI searches. That concession mattered because it meant the defendant was not acting as counsel’s agent when communicating with the AI platform and generating the documents. ¹

The opinion also addressed the idea that the documents might influence counsel’s strategy going forward. Influence, the court reasoned, is not enough. If a client independently generates materials and later sends them to counsel, those materials might shape the lawyer’s thinking, but they still do not necessarily reveal the lawyer’s mental impressions at the time the materials were created. Work products are designed to protect what the lawyer is doing in preparing the case, not to create a safe harbor for any self-directed analysis a defendant performs with a third-party tool. ¹

It would be a mistake to read Heppner as a declaration that “AI and privilege can never mix.” Judge Rakoff’s memorandum did not announce a categorical ban on using AI in a privileged legal workflow. It instead applied familiar privilege elements and concluded they were not satisfied on the record presented, emphasizing the consumer nature of the tool, the disclosures in the governing privacy policy, and the fact that defense counsel had not directed the AI use. ¹ In fact, the opinion’s discussion of agency suggests a path at least conceptually by which some AI-assisted work might fit within privilege doctrine if it is performed at counsel’s direction and under conditions that preserve confidentiality. ¹

Yet the ruling still delivers a wide practical warning because many real-world users follow the defendant’s pattern rather than an enterprise-grade, lawyer-controlled approach. People use public AI tools on their own initiative, with personal accounts, in moments of stress, and they paste in facts they would never share with anyone else. They then forward the output to counsel, believing they have helped. Heppner makes clear that this sequence can produce evidence that the government may be entitled to inspect, and that the later involvement of counsel does not necessarily cleanse the initial disclosure.  ¹

To understand why the result is doctrinally unsurprising, it helps to step back from AI and consider what privilege law is trying to prevent. Attorney-client privilege protects confidentiality so clients can tell lawyers the truth. The moment a client shares the substance of a legal problem with an unnecessary third party, the law assumes confidentiality has been compromised. That is why privilege is routinely lost when communications occur in the presence of outsiders or are transmitted through channels that are not reasonably confidential. ²

Generative AI tools complicate this intuition because they blur the line between “tool” and “person.” If a client types into a chatbot the same way they type into a note’s app, it feels like private drafting. But the legal system often treats third-party platforms as third parties even when they provide a useful service, and the key inquiry becomes what expectations of confidentiality were reasonable and what the user consented to. The Heppner court’s focus on the AI platform’s privacy policy is, in this light, an updated version of a much older question: did the client take reasonable steps to keep the communication confidential, or did the client knowingly send it into a system controlled by someone else? ¹ ²

Similarly, work product is not a generic “litigation is coming” shield. It is about protecting the attorney’s preparation, which is why courts frequently ask whether a document was prepared by or for counsel, whether it reflects counsel’s mental impressions, and whether it was created under counsel’s direction. If the doctrine could be triggered by any self-generated document created while anticipating legal trouble, it would swallow discovery rules and impede fact-finding. That policy concern becomes even sharper when the “preparation” is performed through a third-party AI platform that may store and disclose the content. ¹ ⁴

A central risk exposed by Heppner is that using a chatbot to “think through” a defense can generate a written record of the user’s story, priorities, fears, and strategic calculations. Even if the AI output is wrong on the law, the prompt-and-response history can still be informative to an adversary because it may reveal what facts the user chose to disclose, what explanations the user offered, and what themes the user found persuasive. In a criminal context, those materials can become especially sensitive, because prosecutors may treat them as admissions, inconsistencies, or evidence of intent depending on the surrounding facts.  ¹

The case also highlights a psychological trap. People often use AI when they feel they do not yet have the full picture or do not want to bother counsel with “half-baked” questions. But privilege law is most protective when the client speaks directly to counsel early, before the client creates unnecessary third-party records. Heppner demonstrates that trying to pre-package your defense strategy through a public AI platform can backfire it may not only fail to protect the material, it may also create new material the government did not previously have. ¹

For lawyers, Heppner is a reminder that privilege is not just something counsel “has.” Privilege is something counsel and clients must preserve through behavior, and modern clients now use a wide range of technology outside the lawyer’s point of view. A client might consult a chatbot, a cloud transcription tool, or a shared workspace and then send the results to counsel assuming it is all part of the legal consultation. Heppner indicates that courts may scrutinize those upstream actions, especially when the tools are publicly available and governed by policies that undermine confidentiality. ¹

The opinion also hints at an emerging best practice: if AI use is to be integrated into privileged legal work, it should be structured as something counsel directs and controls, with confidentiality safeguards that mirror the way law firms manage investigators, e-discovery vendors, and other agents. Judge Rakoff’s discussion of agency is not a guarantee that privilege will attach in every counsel-directed AI workflow, but it signals that courts may be more receptive when the AI tool is used as part of counsel’s supervised preparation rather than as an independent advisor the client consults alone. ¹

Many organizations already distinguish between consumer-grade AI accounts and enterprise or commercial deployments for security reasons. Heppner adds a litigation-facing reason to take that distinction seriously. The court’s analysis leaned heavily on the fact that the tool was publicly available and governed by a privacy policy that contemplated collection, model-related use, and disclosure of user data under certain circumstances. ¹ ⁵ In privilege terms, those features are not merely technical; they are markers that a third party has interests and rights in the content of the conversation, which is often incompatible with the confidentiality privilege requires. ¹

That does not mean that every enterprise AI deployment automatically protects privilege. Privilege is a legal doctrine, not a marketing feature. But it does mean that organizations and counsel should stop treating “I used AI” as a single fact. The legal question becomes what tool was used, under what contractual terms, with what retention and training settings, and with what documented direction from counsel. In other words, Heppner pushes AI use into the same category as any other third-party service that can compromise confidentiality if mishandled.

The most enduring line in Judge Rakoff’s memorandum is the closing reminder that generative AI may be new, but its novelty does not exempt it from long-standing legal principles governing privilege and work product. ¹ That framing suggests how courts may approach similar disputes in the near future. Rather than inventing “AI privilege” doctrines, judges are likely to apply traditional elements relationship, confidentiality, and purpose while paying closer attention to the realities of how AI platforms operate and what users agreed to when they clicked “accept.”  ¹

If that is right, the next wave of cases may turn less on abstract fear of AI and more on evidentiary detail. Courts may ask whether counsel truly directed the AI work, whether the tool functioned as an agent of counsel in a meaningful sense, whether the client took reasonable steps to preserve confidentiality, and whether the platform’s contractual terms and technical settings supported a reasonable expectation of privacy. Heppner does not resolve all those questions, but it makes clear that “I planned to share this with my lawyer” is not, by itself, a winning privilege argument. ¹

United States v. Heppner is a cautionary tale for anyone tempted to treat a chatbot as a private rehearsal room for legal strategy. The defendant’s AI-generated documents did not become privileged simply because they were later sent to his attorneys, and the court found the underlying AI communications unprotected because they lacked the core features privilege law demands: a protected attorney-client relationship channel, maintained confidentiality, and the right kind of purpose within a lawyer-directed legal advice framework. ¹

For clients, the practical message is to resist the urge to outsource early legal thinking to a publicly available AI platform, especially when the facts are sensitive and the stakes are high. For lawyers, the message is to proactively address client AI use, because privilege can be lost before counsel ever sees the materials. The deeper lesson is that technology changes fast, but privilege doctrine changes slowly, and courts will continue to ask the same fundamental questions they always have who the communication with was, was it truly confidential, and was it made in a way that the law recognizes as part of the protected legal advisory relationship. ¹ ²

Contact Tishkoff

Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources)

Footnoted Sources

  1. United States v. Heppner, No. 25 Cr. 503 (JSR), Memorandum, U.S. District Court for the Southern District of New York (Feb. 17, 2026) (Rakoff, J.). https://www.akingump.com/a/web/ssTGsd5NHbtZ1onzXQMTye/1_25-cr-503-27-memorandum.pdf
  2. United States v. Mejia, 655 F.3d 126 (2d Cir. 2011). https://www.chapman.com/publication-federal-court-rules-that-ai-generated-documents-are-not-protected-by-privilege
  3. Gould, Inc. v. Mitsui Mining & Smelting Co., Ltd., 825 F.2d 676 (2d Cir. 1987). https://law.justia.com/cases/federal/appellate-courts/F2/825/676/449932/
  4. Hickman v. Taylor, 329 U.S. 495 (1947). https://supreme.justia.com/cases/federal/us/329/495/
  5. Anthropic, Privacy Policy (version referenced by the Heppner court as in effect Feb. 19, 2025), as discussed in United States v. Heppner, No. 25 Cr. 503 (JSR), Memorandum (S.D.N.Y. Feb. 17, 2026). https://www.venable.com/insights/publications/2026/02/ai-privilege-and-the-heppner-ruling-what-the-court

This publication is for general informational purposes and does not constitute legal advice. Reading it does not create an attorney-client relationship. You should consult counsel for advice on your specific circumstances.