In February of this year, a federal judge in the Southern District of New York ruled on a question no court had ever squarely answered: is a conversation with an AI chatbot protected by attorney-client privilege?

The answer, on the facts presented, was no. And in a passage that got less press than the headline holding but matters more for small business owners, Judge Jed Rakoff went a step further: the defendant's practice of feeding his lawyers' advice into the chatbot to think about it risked waiving privilege over the underlying legal advice itself.

The case is United States v. Heppner. The defendant was a former chief executive under federal indictment for fraud. What he did was what a great many people now do when they are frightened and have a laptop: he opened a chatbot and started typing. Over a period of months he produced thirty-one documents with a consumer version of Anthropic's Claude, working through the charges he expected, the arguments he might make, and — critically — things his lawyers had told him. When the FBI executed a search warrant, it seized the documents. His lawyers moved to claw them back as privileged.

The court held that none of it was. The chats were not communications with a lawyer. They were not prepared at counsel's direction. And the platform he used was a consumer service whose published privacy terms disclosed that inputs and outputs could be collected, used to improve the model, and disclosed to third parties including the government. On those facts, there was no reasonable expectation of confidentiality — the threshold condition for privilege to attach.

I open with a criminal defendant because the stakes make the point unmissable. But the person I'm writing this article for is not a defendant. It's the HR manager who pastes a personnel file into a chatbot to draft a termination letter. The founder who uploads a term sheet to ask whether the liquidation preference is normal. The bookkeeper who drops the client's general ledger in to find the error. The paralegal who summarizes the deposition transcript. None of them believes what they're uploading is private, exactly. What they believe is that it doesn't matter, because nobody will ever look.

That belief is wrong, and Heppner is the case that makes the point in a way that will now be cited in every future dispute over AI-tool disclosures.

What Privilege Actually Requires

Attorney-client privilege is a specific legal doctrine with specific elements. It protects confidential communications between a lawyer and a client made for the purpose of seeking or providing legal advice. To be privileged, a communication must be:

The work product doctrine is a related but distinct protection covering materials prepared by or at the direction of an attorney in anticipation of litigation.

A conversation with an AI chatbot fails the threshold elements of the privilege on its face. The chatbot is not your attorney. It cannot provide legal advice. Your interaction with it is not a communication with a lawyer for the purpose of legal advice — it's a use of a commercial service. Unless something specific in the arrangement changes those facts, the privilege was never available to protect the conversation.

The Waiver Problem

The subtler holding in Heppner is the one that matters most for legitimately privileged material.

Privilege can be waived, and one of the most common ways it's waived is disclosure to a third party. A conversation between you and your lawyer is privileged. The same conversation, forwarded to a friend, is no longer privileged as to that conversation. The friend can be subpoenaed to testify about it. So, in the AI context, can the vendor's records.

Judge Rakoff observed that when the defendant took his lawyers' advice and typed it into a consumer chatbot to think about it, he had disclosed that advice to the chatbot's operator — a third party. The privilege that would have attached to the underlying communication with his lawyer had potentially been waived by the AI upload itself.

This is not an academic point. It means that a business owner who receives a legal opinion from counsel and then pastes it into a chatbot to summarize it, translate it, or think about it has potentially waived the privilege on the underlying opinion. In future litigation, opposing counsel may be entitled to see the opinion. Not just the AI conversation — the opinion the AI conversation was about.

What Actually Is and Isn't Privileged When AI Is Involved

Under current law and the Heppner framework:

Not privileged (privilege never attached):

At risk of waiver (privilege originally existed, may have been forfeited):

Still privileged (privilege likely preserved):

The last category is the escape hatch, but it requires specific arrangement — enterprise or zero-retention contract terms, use directed by counsel as part of the legal work, and documentation of the use pattern.

The Four Practical Rules

For small business owners using AI tools, four rules that follow from Heppner and stand up under current law:

Rule 1: Use business or enterprise tiers, not consumer tools, for anything business-related.

The privacy terms of consumer chatbots are the primary reason a court finds no reasonable expectation of confidentiality. Business and enterprise tiers typically include stronger data protection terms — data not used for training, retention limits, and contract remedies. Even ordinary business information (not legal) is safer on business tiers.

Rule 2: Do not paste your lawyer's advice into any AI tool without counsel's specific direction.

This is the Heppner waiver problem. If you receive a legal opinion, contract review, or advice from counsel, do not upload it to a chatbot to summarize, translate, or think about — even a business-tier one. The privilege you had is potentially forfeit the moment the third party sees it. If you want AI help understanding your lawyer's advice, call your lawyer and ask them to explain it — that's what the fee covers.

Rule 3: Set up a privilege protocol before you need it.

For businesses using AI substantively, work with counsel to establish which AI tools may receive which categories of data, whether privileged material may ever be uploaded and under what specific terms, and how the use will be documented. This is not exotic corporate governance — it's the equivalent of the document retention policy every business has for other purposes.

Rule 4: Train the belief, not just the rule.

Employees who believe uploads don't matter will not follow a policy that says they do. The training that works explains why — the Heppner case, the waiver mechanic, the fact that vendor records are subpoenaed all the time in litigation people never heard about. Twenty minutes, once, for everyone who touches sensitive business data. Policy without belief change doesn't survive contact with a busy Tuesday.

What Happened to Heppner After the Ruling

The court's holding was that the AI conversations weren't privileged. The prosecution was permitted to use them. The defendant's underlying case continues.

More consequentially for everyone else, the ruling is now the reference point for every future dispute over AI-tool disclosure. Every litigator handling document collection now asks whether the client used AI tools during the relevant period. Every state bar considering AI ethics rules now cites Heppner. Every enterprise AI vendor now sells against the case. The privilege landscape for AI use is materially different than it was 12 months ago, and the trajectory is toward more scrutiny, not less.

For small business owners, the practical implication is simpler than the doctrine: the AI tool is a third party that keeps records of what you tell it. Treat it like one. Consumer tools for things you'd say in public. Business or enterprise tools for actual business information. Nothing sensitive-legal without counsel involved. And never, ever your lawyer's advice pasted in for the AI to think about.

Frequently Asked Questions

Is my conversation with ChatGPT or Claude legally privileged?

Under current law, no. Attorney-client privilege protects confidential communications with a lawyer for the purpose of legal advice. A conversation with an AI chatbot is not a communication with a lawyer, and consumer chatbot privacy terms typically defeat any argument that the conversation was made in confidence. United States v. Heppner (S.D.N.Y. 2026) is the leading case on this question and answered no on those facts.

If I paste my lawyer's advice into an AI tool to summarize it, do I lose privilege?

Potentially yes. Disclosure to a third party generally waives attorney-client privilege on the disclosed material, and the AI vendor is a third party. In Heppner, the court observed that feeding lawyers' advice into the chatbot risked waiving privilege on the underlying advice. Don't paste attorney communications into AI tools without your lawyer's specific direction and appropriate contract terms.

What about using AI at my lawyer's direction — is that different?

The Heppner court noted this as an open question. AI tool use conducted at counsel's direction, as part of the legal work, on a platform with contract terms that preserve confidentiality, may qualify as work of a lawyer's agent inside the privilege. This is the scenario most likely to preserve protection — but it requires the specific arrangement, not just after-the-fact rationalization.

Are business or enterprise AI tools safer than consumer versions?

Yes, meaningfully. Business and enterprise tiers typically offer stronger data protection — data not used for training, defined retention limits, and contract remedies for breach. This shifts the analysis from consumer privacy terms (which defeated privilege in Heppner) to a contracted processing relationship. It doesn't automatically create privilege, but it addresses several of the Heppner court's specific concerns.

What should I do if I've already uploaded sensitive material to a consumer AI tool?

Triage rather than panic. Identify what was uploaded and to which service. Delete the conversations from the account and, where available, submit the vendor's deletion request. Assess by data category — a routine business upload may be a policy issue with limited legal consequence; a legal document may require notice to affected parties; privileged material may require a waiver analysis with counsel. Document what happened and what was done. Most single uploads are recoverable in practice if handled promptly and candidly.

This article draws from the forthcoming Silverton Publishing book AI in Business and Law: A Practical Guide to Using Artificial Intelligence Without Getting Sued. The doctrine on AI and privilege is developing quickly; for ongoing updates on court rulings, vendor terms changes, and regulatory developments after this article's publication, see the AI Legal Tracker.

This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.