AI Just Waived Attorney–Client Privilege in Court: What Every Lawyer Must Know

Published: August 9, 2026 — In February 2026, a federal judge ruled for the first time that a criminal defendant's conversations with an AI chatbot were not protected by attorney–client privilege or work product. Here's what the decision actually said, what it doesn't say, and how law firms can keep using AI without waiving client confidences.

⚖️ Quick Takeaways

The Ruling That Changed the Conversation

On February 10, 2026, Judge Jed S. Rakoff of the U.S. District Court for the Southern District of New York ruled in United States v. Heppner (25-cr-00503-JSR) that 31 documents a defendant produced with the AI platform Claude were protected by neither the attorney–client privilege nor the work product doctrine. As Paul, Weiss noted in its client memo, it appears to be the first ruling in which a court determined that interactions with a publicly accessible AI tool based on prompts containing privileged information are not themselves privileged.

The facts matter. Heppner was arrested on fraud charges in November 2025, and law enforcement seized his devices. Before his arrest — and without any direction from counsel — Heppner had used Claude to run queries about the investigation and to prepare reports outlining what he might argue about the facts and the law. His defense team claimed privilege; the government moved to force disclosure; Judge Rakoff sided with the government.

⚠️ Read that last point twice. The documents at issue were not created by a law firm's sanctioned AI review tool. They were created by a defendant, on his own initiative, in a public consumer chatbot, before he ever involved counsel. That is the worst-case configuration for privilege — and it is exactly how many people still use AI today.

Why the Court Said "No Privilege"

Judge Rakoff gave three independent reasons the attorney–client privilege did not attach:

  1. The chatbot is not an attorney. "Claude is not an attorney," he wrote, and no relationship with "a licensed professional who owes fiduciary duties and is subject to discipline" exists between an AI user and a platform. Recognized privileges require a "trusting human relationship" — a machine doesn't qualify.
  2. The communications were not confidential. Heppner communicated with a third-party AI platform and consented to its privacy policy, which collects data on user inputs and outputs, uses data for training, and reserves the right to disclose data to third parties, including regulatory authorities. That put users "on notice" there was no reasonable expectation of confidentiality.
  3. They weren't for legal advice. Heppner didn't use Claude at the suggestion or direction of counsel. Sharing the documents with his lawyer later couldn't retroactively create privilege — and Claude itself disclaims that it can give legal advice.

The work product doctrine failed for a related reason: the documents were not prepared "by or at the behest of counsel" and did not reflect defense counsel's strategy. The core purpose of work product — protecting the mental strategies of counsel in anticipation of litigation — wasn't served by a defendant's self-directed chatbot sessions.

The Nuance Most Headlines Miss

It would be wrong to read Heppner as "AI = automatic waiver." Three qualifications are already visible in the record:

In other words: the law is settling around the traditional privilege elements, applied to new facts. Confidentiality, purpose, and counsel involvement still decide the outcome. The AI is just the new medium.

What This Means for Law Firms and In-House Teams

If your firm uses consumer or general-purpose chatbots for anything involving client information, Heppner is a forcing function. Three questions should be on every matter budget:

🔎 Where does the data go?

Does the tool collect prompts and outputs? Are they used for training? Can the provider disclose them to third parties or regulators? If the answer to any is yes, you have a confidentiality problem.

🧭 Who directed the use?

Was the AI used at counsel's direction, as part of a defined workflow? Self-directed client experimentation is the configuration that produced the Heppner outcome.

📜 What does the policy say?

Does the firm have a written AI policy, with approved tools and prohibited ones, as ABA Formal Opinion 512 directs under Model Rule 5.1?

How to Use AI for Legal Work Without Waiving Privilege

  1. Never paste client documents into public chatbots. Anything you type can be collected, trained on, or disclosed. This is the single most important rule and the one Heppner illustrates most directly.
  2. Vet every provider's terms before use. Read the data, retention, training, and disclosure sections of the privacy policy — the exact provisions that sank the privilege claim in Heppner.
  3. Prefer local or on-premise AI. When the model runs on your own hardware, there is no third party receiving the data, no training pipeline, and no disclosure clause to trip over. The confidentiality element of privilege is preserved by architecture rather than by policy.
  4. Deploy AI at counsel's direction. Structure AI use inside the representation — a defined workflow where the tool is an extension of the lawyer's work — which is the configuration the courts have signaled can qualify for protection.
  5. Get client informed consent where required. Some jurisdictions require disclosure before using AI on client matters; when in doubt, ask.
  6. Verify everything anyway. Privilege protects confidentiality; it doesn't make the output correct. You remain responsible for the work product under the competence rules.

💡 The architectural answer. A local RAG pipeline — documents indexed and answered on your own machine, with citations back to the source passages — keeps client data off every third-party server while giving lawyers the speed of AI. That's exactly the design of Lawyer Assistant: 100% offline, no account, no telemetry, with inline citations on every answer. Read the full technical breakdown in Lawyer Assistant: A Privacy-First Legal AI Built on a Local RAG Pipeline.

Frequently Asked Questions (FAQ)

What is US v. Heppner?

US v. Heppner (25-cr-00503-JSR, S.D.N.Y.) is the February 10, 2026 ruling in which Judge Jed Rakoff held that 31 documents a defendant generated with Anthropic's Claude were not protected by attorney-client privilege or the work product doctrine — the first ruling of its kind nationwide.

Can using AI waive attorney-client privilege?

Yes, in the right circumstances. If you share privileged client information with a third-party AI platform that collects inputs and outputs for training or may disclose them, a court can find there was no reasonable expectation of confidentiality — as happened in US v. Heppner.

Why did the court in Heppner find no privilege?

The court gave three reasons: Claude is not an attorney and owes no fiduciary duties; the communications were not confidential because the platform's privacy policy allowed data collection for training and disclosure to third parties; and the defendant did not use the tool for the purpose of obtaining legal advice. Work product protection also failed because the documents were not prepared at counsel's direction.

Is using AI for legal work always a privilege waiver?

No. Heppner is fact-specific. Judge Rakoff noted that if counsel had directed the client to use the AI tool, the tool might have functioned like a lawyer's agent within the privilege. Local AI that never sends data to a third party avoids the confidentiality problem entirely, but lawyers must still verify output.

How can lawyers use AI without waiving privilege?

Use tools with no third-party data exposure (local or on-premise AI), vet every provider's data and training terms, never paste client documents into public tools, use AI at counsel's direction where possible, get client informed consent when required, and verify all output before relying on it.

⚖️ Need this built for your firm?

I design and deploy privacy-first local AI systems — private RAG, cited answers, on-premise LLMs for legal and regulated work. Contact me for a scoping conversation, no obligation. Or start with the free, open-source Lawyer Assistant — private legal AI on your own machine.