Skip to main content
Now accepting Founding Firms: 25% off any plan, for life — ends August 31. Become a founding firm
AI in Legal Practice|August 31, 2026|12 min read

Does AI Waive Attorney-Client Privilege? What Courts Have Actually Said

Using AI does not automatically waive attorney-client privilege, but disclosure to a tool that defeats any reasonable expectation of confidentiality can. Here is the doctrine: the cloud-computing analogy the bars settled years ago, the five 2026 decisions from Heppner forward, what remains genuinely unsettled, and the protocol that keeps your precautions defensible.

Legal EthicsAI in Legal PracticeProfessional ResponsibilitySmall Firm Practice

Using AI does not automatically waive attorney-client privilege. But feeding privileged information into a tool whose terms defeat any reasonable expectation of confidentiality can, and in February 2026 a federal judge held exactly that about documents a criminal defendant generated with consumer Claude. The analysis turns on two things you control: the tool's terms and your precautions.

One fact from that case belongs at the top, because it should change your engagement letter: the lawyers did nothing wrong. The client created the exposure himself, alone with a chatbot. Most writing on this question is either a scare piece or a vendor pitch. What follows is the doctrine, the five decisions that exist, and an honest map of what remains unsettled.

Why privilege depends on confidentiality

Attorney-client privilege protects confidential communications between lawyer and client made for the purpose of obtaining or providing legal advice. The load-bearing word is confidential. A communication made in front of a third party, or later disclosed to one, generally loses protection. That waiver doctrine is old, settled, and indifferent to technology.

It has a carve-out. Under the Second Circuit's Kovel line of cases, privilege survives sharing with agents whose participation is necessary to the legal work: the accountant translating financial facts for the lawyer, the interpreter, the copy vendor. Firms have run privileged material through outside vendors for decades without waiving anything, because the vendor processes it under confidentiality obligations in service of the representation.

So the AI question is not new in kind. The profession answered it for email and cloud storage: is this vendor a confidential conduit, or a third party you just told your client's secrets to?

Is an AI vendor a "third party" that breaks privilege?

The closest settled analogy is cloud computing, and the bars resolved it years ago. Thirty states have issued ethics opinions on lawyers' use of cloud storage, and they converge on one rule: a lawyer may store client confidences with an outside provider under a reasonable-care standard. New York State Bar Opinion 842 (2010) approved online storage and told lawyers to keep watching for "instances when using technology may waive an otherwise applicable privilege." Pennsylvania's Formal Opinion 2011-200 and Florida Opinion 12-3 say the same. Nobody seriously argues today that a properly vetted cloud account waives privilege: the provider's confidentiality terms and the lawyer's precautions preserve a reasonable expectation of confidentiality.

The ethics standard matches. Model Rule 1.6(c) requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." ABA Formal Opinion 477R (2017) applied that fact-specific framework to transmitting client information electronically, and ABA Formal Opinion 512 (2024) extended it to generative AI: know the tool's data practices before client information touches it, and obtain informed consent where the tool may expose it.

The analogy has an honest limit. A cloud provider stores your data inertly. Some AI vendors read yours: they retain prompts, review them, train on them. Whether courts will treat an AI vendor like a Kovel agent, a cloud host, or a stranger is the open question.

What have courts actually said about AI and privilege?

Five trial-court decisions, all in 2026, none from an appellate court, and every one involving a litigant alone with a chatbot. Start with the pair decided the same day.

United States v. Heppner (S.D.N.Y.; bench ruling Feb. 10, 2026, written opinion Feb. 17). After retaining counsel in a criminal investigation, the defendant used the consumer version of Claude to analyze his own case, feeding in what he had learned from his lawyers and generating dozens of strategy documents, which he shared with counsel. Agents seized them from his devices. Judge Jed Rakoff held the documents unprotected on three grounds: a chatbot is not a lawyer; the consumer terms and privacy policy, which permitted training on inputs and disclosure to third parties, defeated any reasonable expectation of confidentiality; and counsel never directed the work, so the work-product doctrine did not apply either. Rakoff left one door ajar: had counsel directed the AI use, Claude "might arguably" have functioned as a lawyer's agent under Kovel. "Might arguably" is the entire comfort on offer.

Warner v. Gilbarco, Inc. (E.D. Mich., Feb. 10, 2026). The same day, Magistrate Judge Anthony Patti protected a pro se plaintiff's ChatGPT queries and outputs as work product: they reflected her mental impressions, prepared in anticipation of litigation, and work-product waiver requires disclosure to an adversary or in a way likely to reach one. Generative AI programs, the court wrote, "are tools, not persons." Typing into ChatGPT is not disclosure to your adversary.

Read precisely, the two decisions are consistent: Heppner is about attorney-client privilege failing for lack of confidentiality; Warner is about work product surviving because its waiver standard is narrower. Neither holds that using AI waives anything categorically.

The decisions since have run Warner's way. Morgan v. V2X, Inc. (D. Colo., Mar. 30, 2026) protected a pro se plaintiff's AI materials as work product while making the identity of the tool he used discoverable, and it amended the protective order to bar consumer AI tools from confidential discovery material unless the provider gives contractual guarantees against retention, training, and third-party disclosure. In June, a Texas business court adopted the Warner and Morgan reasoning, and a New York trial court quashed subpoenas served on the AI provider itself for a pro se litigant's prompts and outputs.

Now the unsettled markers. No appellate court has addressed AI and privilege. Every decision so far involves a litigant using AI on his or her own case; none involves a lawyer. No court has decided whether a lawyer's use of an enterprise-grade tool with contractual confidentiality preserves privilege: nobody has held that it waives, and nobody has blessed it. Whether AI vendors get Kovel treatment is open. Anyone who tells you this is settled, in either direction, is selling something.

Does the type of AI tool change the waiver analysis?

It does, and the courts are already drawing the line. Both the reasonable-efforts analysis and the expectation-of-confidentiality inquiry turn on the tool's actual terms, and the Morgan protective order names the price of running confidential material through AI: contractual guarantees against retention, training, and disclosure.

TierTypical termsPrivilege posture
Consumer chatbot (free/standard)Inputs may be retained, reviewed by vendor personnel, and used for trainingThe Heppner fact pattern: no reasonable expectation of confidentiality
Business/enterprise tier of a general toolContractual no-training commitment, limited retentionDefensible under the cloud-computing analogy, if you verify the terms actually say it
Purpose-built legal tool with contractual confidentiality and isolationNo training on firm data, tenant isolation, deletion including derived dataThe strongest reasonable-efforts record a firm can build

The consumer tier's exposure is not hypothetical. In the New York Times copyright litigation, a federal court ordered OpenAI to preserve ChatGPT conversations, including chats users had deleted, and later required production of twenty million de-identified chat logs. A "deleted" consumer chat can outlive your matter. The full consumer-tier confidentiality analysis (Rule 1.6, Opinion 512, the four vendor questions) is in can I upload client documents to ChatGPT; this article owns what happens to privilege once the paste occurs.

The third tier is the standard we built CaseRead against. It is an AI associate that knows your matter: it searches the firm's own files and the public law together, answers with citations it verified, and flags anything it could not — the same check the free Hallucination Shield runs on any pasted brief. Each firm's documents live in their own database schema, not commingled with other customers'. Documents can stay in storage the firm controls (Google Drive, OneDrive, or the built-in vault), and firm data is never used to train models, as a matter of contract rather than a settings toggle. None of that guarantees privilege. No tool can, because the reasonable-efforts analysis judges the lawyer's precautions on the whole record. What a tool built this way gives you is a record worth defending. There is a free tier, with Solo at $89 and Team at $149.

Is AI-assisted work product protected in discovery?

The work-product doctrine runs on a different track. Rule 26(b)(3) protects documents "prepared in anticipation of litigation or for trial by or for another party or its representative," a broader circle than privilege with a narrower waiver rule. Privilege can be lost by disclosure to almost any outsider; work product is generally waived only by disclosure to an adversary or in a way that makes adversary access likely.

That asymmetry explains the results so far. Warner, Morgan, and the state cases protected litigants' AI research as work product without any lawyer in the picture. Heppner denied it because the defendant acted on his own initiative rather than at counsel's direction. The practical lesson: AI research and drafting done at counsel's direction, in anticipation of litigation, on a tool with confidentiality terms stacks every protective factor available. AI use a client freelances on a consumer app stacks none of them. Treat prompts and outputs as discoverable-until-protected and write them accordingly.

How do I use AI without risking privilege?

The protocol is short, and every line of it doubles as evidence of reasonable efforts:

  1. Read the terms before the tool sees a client fact. Four answers must be in writing: no training on your data, defined retention you can shorten to zero, access limited and logged, and an express confidentiality commitment. A vendor that answers any of the four vaguely has answered all of them.
  2. Draw the consumer-tool line at zero. No client names, no facts traceable to a matter, no privileged communications, no work product, ever, in a free or standard chatbot tier. Generic legal questions with no client information are the only safe cargo, a line explained in can lawyers use AI for legal research.
  3. Route AI work through counsel. After Heppner, direction by counsel is the single most protective fact available. Document that the tool is being used at the lawyer's direction, for the representation.
  4. Put it in the engagement letter. Per Opinion 512, disclose the firm's use of AI tools and obtain informed consent where a tool could expose representation information. Then add the clause almost nobody has yet: advise the client, in writing, not to run the case through a chatbot. The client in Heppner generated dozens of strategy documents alone with a consumer app; the government seized every one, and no privilege covered any of them.
  5. Write it down as policy. One page: approved tools, the consumer-tool prohibition, the verification rule. The template is in law firm AI policy.

The honest summary: the doctrine is old, the applications are six months of trial-court rulings, and the gap between them is where your precautions live. A lawyer who can show the court a no-training contract, an isolation architecture, counsel-directed use, and an engagement letter that addressed AI has a confidentiality record like every vendor arrangement courts have protected for decades. A lawyer who pasted the client's facts into a free chatbot has Heppner.

Frequently asked questions

Does using ChatGPT waive attorney-client privilege? Not by itself, but the disclosure can. Privilege requires confidentiality, and pasting privileged communications into a consumer tier whose terms permit retention, human review, and model training undercuts the reasonable expectation of confidentiality the privilege depends on. In United States v. Heppner (S.D.N.Y. 2026), a federal court held a defendant's consumer-AI documents unprotected on essentially that ground. Enterprise tiers with contractual confidentiality present different facts. No court has resolved every scenario; the tool's terms and your precautions decide.

Is AI-assisted work product protected? The early rulings say yes, on the right facts. In Warner v. Gilbarco (E.D. Mich. 2026), a pro se litigant's ChatGPT queries and outputs were held protected work product: prepared in anticipation of litigation, and not waived, because work-product waiver requires disclosure to an adversary, not just any third party. Morgan v. V2X (D. Colo. 2026) and two state courts followed. But Heppner denied work-product protection where a client generated AI documents without counsel's direction. The safest posture is AI research directed by counsel on a secured tool.

What did United States v. Heppner actually decide? In February 2026, Judge Jed Rakoff of the Southern District of New York held that documents a criminal defendant generated with consumer Claude, on his own initiative, feeding in information learned from his lawyers, were neither privileged nor work product. The chatbot is not a lawyer, the consumer terms and privacy policy defeated any expectation of confidentiality, and counsel had not directed the work. The court did not hold that lawyer use of AI waives privilege; it said only that counsel-directed use "might arguably" have qualified the tool as a lawyer's agent.

Do I need client consent before using AI on a matter? Under ABA Formal Opinion 512, informed client consent is required before inputting information relating to the representation into a tool that may expose it, which is the consumer-chatbot scenario. Using a tool with genuine contractual confidentiality protections for internal work generally does not require consent, though engagement-letter disclosure is an emerging best practice. Add the mirror-image warning: tell clients not to run the case through their own chatbots. In Heppner, the exposure came from the client, not the lawyers.

Are my AI chats discoverable? Treat them as documents, because courts do. Every 2026 decision on the question was a fight over an adversary's access to a litigant's prompts and outputs. Work product protected them in Warner, Morgan, and the state cases; nothing protected them in Heppner. Morgan also held the identity of the AI tool discoverable even where its content was protected. Consumer chat logs also live on the vendor's servers: in the New York Times litigation, OpenAI was ordered to preserve ChatGPT conversations, including deleted ones, and later to produce twenty million de-identified logs. Write every prompt as if opposing counsel may read it.

CaseRead

CaseRead Team

AI-powered legal research built for practicing attorneys.

Ready to try AI-powered legal research?

Free to start. No credit card required.

Start Free