IntegrationsBlogBook a free AI assessment
Industry

A Federal Judge Ruled That AI Chats Are Not Privileged. The Footnotes Matter More.

A federal judge held that chats with a public AI platform are not privileged. What the ruling binds, what it leaves open, and the footnote on counsel direction.

By Mustafa Najoom»Oct 1, 2026»8 min read»ai attorney client privilege

A judge in the Southern District of New York held that a defendant's written exchanges with a publicly available AI platform were protected by neither attorney-client privilege nor the work product doctrine. It is one district court memorandum and it binds no other court. The reasoning, though, tells you exactly which facts would change the answer.

What did the court actually decide?

That a defendant's written exchanges with a generative AI platform were protected by neither attorney-client privilege nor the work product doctrine. The Government moved for that ruling and won.

The motion was granted from the bench on 10 February 2026, with the memorandum filed 17 February 2026 by Judge Jed S. Rakoff in United States v. Bradley Heppner, No. 25 Cr. 503 (JSR), in the Southern District of New York.

Note the precise question the court framed, because the scope matters more than the headline. At page 2 the memorandum says the ruling "appears to answer a question of first impression nationwide: whether, when a user communicates with a publicly available AI platform in connection with a pending criminal investigation, are the AI user's communications protected by attorney-client privilege or the work product doctrine?" And then: "For the reasons that follow, the answer is no."

Two qualifiers are doing real work there. "Publicly available" and "in connection with a pending criminal investigation." Neither is decorative.

Is this really the first ruling of its kind?

On the court's own account, yes. Footnote 1 states: "The Court is unaware of, and the parties have not identified, any case to date that has presented this issue." That is a court telling you there is no body of law here yet, which is a more useful signal than the holding itself.

It also means the usual comfort of pointing to a line of authority is unavailable to you in either direction. There is no case saying your AI logs are protected, and until February there was none saying they were not.

Why did the court say the chats were not privileged?

The court gave three grounds, holding that the documents lack "at least two, if not all three, elements of the attorney-client privilege". The first is the short one, at page 5: "Because Claude is not an attorney, see ECF No. 23-6, that alone disposes of Heppner's claim of privilege."

Read "that alone". The court is flagging this ground as independently sufficient, which matters when you start evaluating fixes, because a fix that does not address this sentence does not reach the privilege question at all. The second ground is confidentiality and the third is whether the exchange was for the purpose of obtaining legal advice.

The second ground: you agreed it would not stay confidential

The alternative ground is confidentiality, and it comes from the terms the user accepted. At page 6 the court points to the privacy policy users consent to, which provides that Anthropic collects data on "inputs" and "outputs", uses it to "train" Claude, and reserves the right to disclose it to "third parties", including "governmental regulatory authorities".

Privilege requires an expectation of confidentiality. The court's point is that the user had agreed, in advance and in writing, to a document describing the opposite. This is the ground that should worry a firm most, because it does not depend on anything exotic. It depends on the terms of service nobody read.

Waiver is the reasoning that reaches past this case

Footnote 3 is the part with the longest reach, though note what it is: a footnote answering a point the defendant's counsel raised in passing at oral argument, not one of the court's three numbered grounds. It reads: "even if certain information that Heppner input into Claude was privileged, he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party."

That framing is the one to carry into your own risk assessment. The court is not treating the platform as a novel category. It is treating it as a third party, and third party disclosure is a waiver analysis lawyers already know how to run. If you can reason about forwarding a memo to an outside consultant, you can reason about this.

The sentence most of the coverage dropped

Page 7 contains the counterfactual, and it is the most practically useful line in the document: "Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent within the protection of the attorney-client privilege." The court cites Adlman, 68 F.3d 1495, 1498-99 (2d Cir. 1995), itself citing Kovel, 296 F.2d 918 (2d Cir. 1961).

This did not happen here because, at page 4, counsel conceded they "did not direct [Heppner] to run Claude searches." The client went and used a tool on his own.

So the opinion contains both the loss and the shape of the argument that was not available. Kovel is the familiar doctrine that a lawyer's non-lawyer agents, the classic example being an accountant retained by counsel, can sit inside the privilege. The court is saying a model used at counsel's direction might fit that frame.

Do not overread it. The word is "might", followed by "arguably". That is a judge declining to decide a question not in front of him, not a safe harbor.

How much does this ruling bind?

Very little, formally. It is one memorandum from one district judge. It binds no other court, it is not appellate authority, and another district could reach the opposite conclusion next month on the same facts without creating a conflict anyone has to resolve.

Treat it as the best available reasoning on an open question rather than as settled law. For most firms that distinction changes the tone of the client conversation but not the actions, because the cheap precautions are worth taking whether or not the next court agrees.

Does an enterprise agreement change the analysis?

Nobody knows, and the structure of the opinion suggests it would only get you halfway at best.

Terms that bar training on your data and bar third party disclosure would speak directly to the confidentiality ground at page 6. They would say nothing about page 5, where the court held that the tool not being an attorney "alone disposes" of the privilege claim.

On the logic of the opinion, the only route that touches the first ground is the Kovel path: counsel directing the use, so the tool is arguably counsel's agent. That argument has not been tested anywhere. Anyone selling you an enterprise tier as a privilege solution is selling you something the opinion does not support.

What should a firm change this week?

Four decisions, none of which needs a policy project, a committee or a vendor: tell people in writing that public AI chats are discoverable, separate research from drafting with client facts, have counsel direct any use that touches privileged work, and read your actual terms of service.

  • Tell people, in writing, that chats with public AI tools are discoverable and are being treated as third party disclosure. One paragraph, circulated, dated.
  • Separate the two use cases. Research with no client facts is a different risk than drafting with client facts in the prompt, and only the second one needs a gate.
  • Where a model genuinely is part of privileged work, have counsel direct the engagement explicitly and in writing, with a human review step on anything that leaves the firm. On page 7 that is the only fact pattern with an argument attached, and it costs nothing to create the record now.
  • Read your actual terms of service for training and disclosure, including the consumer tiers people signed up for personally, because that is the document the court read.

Where Gaper fits

Gaper builds and deploys custom AI agents for law firms inside your own cloud, so the inputs and outputs stay in infrastructure you control and the data path is something you can describe to a court rather than infer from a vendor's policy. We are an implementation partner, so the agents and their configuration belong to you, not to a platform whose terms can change. General enquiries go to hello@gaper.io.

What this means for your firm

Assume for now that anything typed into a public AI tool is discoverable, and say so to your people this week rather than after a preservation notice arrives. The deployment shape is what moves the risk: a tool your firm controls, used at counsel's direction, is the only fact pattern in this opinion with an argument behind it. Read the paragraph on page 7 yourself before you let anyone tell you the question is closed in either direction.

Book a free AI assessment

Thirty minutes, no commitment. We map one workflow, make the build or buy call, and scope the smallest thing worth shipping.

Frequently asked questions

What did the court actually decide?
That a defendant's written exchanges with a generative AI platform were protected by neither attorney-client privilege nor the work product doctrine. The Government moved for that ruling and won.
Is this really the first ruling of its kind?
On the court's own account, yes. Footnote 1 states: "The Court is unaware of, and the parties have not identified, any case to date that has presented this issue." That is a court telling you there is no body of law here yet, which is a more useful signal than the holding itself.
Why did the court say the chats were not privileged?
The court gave three grounds, holding that the documents lack "at least two, if not all three, elements of the attorney-client privilege". The first is the short one, at page 5: "Because Claude is not an attorney, see ECF No. 23-6, that alone disposes of Heppner's claim of privilege."
How much does this ruling bind?
Very little, formally. It is one memorandum from one district judge. It binds no other court, it is not appellate authority, and another district could reach the opposite conclusion next month on the same facts without creating a conflict anyone has to resolve.
Does an enterprise agreement change the analysis?
Nobody knows, and the structure of the opinion suggests it would only get you halfway at best.
What should a firm change this week?
Four decisions, none of which needs a policy project, a committee or a vendor: tell people in writing that public AI chats are discoverable, separate research from drafting with client facts, have counsel direct any use that touches privileged work, and read your actual terms of service.
MN
Written by

Mustafa Najoom

Marketing & GTM, Gaper

Mustafa is a CPA turned B2B marketer focused on go-to-market strategy, working on growth at Gaper, the AI-native partner that builds and deploys production AI agents.

Ready to turn AI into execution?

Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.