Privilege, work product, and the tool's terms of service
AI and attorney-client privilege:
the split every litigator should know.
Two federal decisions on the same day in February 2026 read opposite ways, until you look at what each was actually deciding. The difference is not AI versus no AI. It is whose tool, whose terms, and whose direction.
Quotations are from the opinions as quoted in the linked primary and law-firm sources.
The answer first. In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y., bench ruling 10 February 2026; written opinion 17 February 2026, Rakoff, J.), 31 documents a criminal defendant created with a consumer AI tool were protected by neither attorney-client privilege nor work product. The mechanism was the platform's own privacy terms, it collects inputs and outputs, trains on them, and reserves the right to disclose them to third parties, including the government, which defeated any reasonable expectation of confidentiality.
Heppner did not hold that using AI waives privilege. It held that this tool's terms destroyed confidentiality for these documents. The same day, in Warner v. Gilbarco (E.D. Mich.), a magistrate judge protected a litigant's AI-assisted materials under the work-product doctrine. That is the split, and it is narrower, and more manageable, than the headlines.
What Heppner held, the three grounds
Bradley Heppner, a defendant in a securities-fraud prosecution, used the consumer version of Anthropic's Claude to prepare documents about his case, and later shared them with his lawyers. Judge Rakoff ruled from the bench on 10 February 2026 and issued a written opinion on 17 February 2026 (2026 WL 436479). As summarized in the Paul Weiss client memorandum (PDF) and Quinn Emanuel's analysis, Quinn Emanuel was defense counsel in the case, all three traditional elements of privilege failed:
- Not a communication with counsel. “Because Claude is not an attorney, that alone disposes of Heppner's claim of privilege”, the communications were with a tool, not a lawyer.
- Not confidential. Anthropic's privacy policy, as the court read it, collects data on users' inputs and Claude's outputs, uses them to train the model, and reserves the right to disclose them to third parties, including governmental authorities. Sharing case material with a platform on those terms was not a confidential communication.
- Not for the purpose of obtaining legal advice. Heppner used the tool on his own initiative, not at counsel's direction. And sending the output to a lawyer afterward does not cure it: non-privileged communications are not, in the court's phrase, “alchemically changed into privileged ones upon being shared with counsel.”
Work product failed for a parallel reason: the documents were not prepared by counsel or at counsel's direction, so they were not litigation materials of the party's representative under Rule 26(b)(3). Judge Rakoff pointedly left the door open to a different result where counsel directs the AI use, the Kovel analogy, where an accountant or translator working at a lawyer's behest shares the lawyer's privilege.
What Warner held, and how it differs
Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. 10 February 2026, Patti, M.J.) went the other way on nearly everything that matters here: a pro se plaintiff's use of ChatGPT in her own case was protected work product; the defendants' motion to compel “all documents and information concerning her use of third-party AI tools” was denied; and the court wrote that work-product waiver “has to be a waiver to an adversary or in a way likely to get in an adversary's hand,” and that AI programs “are tools, not persons.”
The reconciliation, decision by decision: Heppner is a criminal case about attorney-client privilege, where confidentiality is the whole doctrine and the tool's terms destroyed it. Warner is a civil discovery dispute about work product, where the waiver question is narrower, disclosure to an adversary, and using a drafting tool is not disclosing to anyone's opponent. Neither court said “AI use waives privilege,” and neither said “AI use is always safe.” Both asked the ordinary questions and reached answers driven by the tool's terms and the doctrine's elements. (The Seyfarth Shaw comparison makes the same point.)
The practical rules for a law firm
- Read the tool's privacy terms before client work touches it. Heppner turned on the consumer platform's terms, collection, training, and a disclosure reservation that reaches government. The confidentiality analysis is a terms-of-service analysis.
- Consumer and enterprise tiers are different documents. Paid and enterprise tiers commonly contract out of training use and narrow disclosure rights; consumer tiers commonly do not. Which tier the work ran on is a fact you should be able to prove, not remember.
- Terms change; re-read them. We considered a per-vendor table here and omitted it deliberately: these policies are revised often, and a cached table would mislead. Read the current versions: Anthropic's privacy policy, OpenAI's terms and policies, Google's terms.
- Counsel-directed use may matter. The Kovel door Judge Rakoff left open is the one a firm can walk through deliberately: use directed by counsel, documented as such, on terms that preserve confidentiality.
- Document what you did, when you did it. If privilege or work product is ever challenged, the question will be exactly what Heppner asked: which tool, which terms, whose direction, what confidentiality. A sealed, dated record of AI use and human verification answers it from evidence rather than recollection.
The structural answer: don't send it anywhere
Every ground in Heppner shares one premise: the work product went to someone else's servers. A tool that runs on your own machine, under your own control, has no third party to disclose to, there is nothing to collect, nothing to train on, no disclosure reservation to invoke. That is the design premise of our own product: the Regulayer Receipt runs on your desktop, and nothing leaves your machine, the verifier confirms the seal without your documents ever transiting our servers. How the zero-egress design works → We would still say what we say everywhere on this site: architecture reduces a risk; it does not waive the duty to read the cases you cite.
What we are watching
- Morgan v. V2X, Inc., 2026 WL 864223 (D. Colo. 30 March 2026), as reported, another federal court working through AI-drafted materials and protection questions.
- The Heppner prosecution itself, as reported, the defendant was convicted on 7 May 2026; any appeal could put the privilege ruling before the Second Circuit.
- Vendor terms, both major consumer platforms revised their data-use policies in late 2025 and early 2026; the confidentiality calculus in Heppner moves with those documents.
- Bar guidance, state and city bar AI opinions continue to multiply; confidentiality duties under Rule 1.6 are the common thread.
The lesson for the next filing
Privilege after Heppner is an engineering question as much as a legal one: where the work ran, under what terms, at whose direction, and what record you can produce. Our deeper treatment for practitioners is on the attorneys page; the receipts that document the answers are what we build.
Sources
- Paul, Weiss client memorandum (PDF): “Federal Courts Reach Different Outcomes on Whether AI-Generated Materials Warrant Work Product Protection” (dates, document count, the three grounds)
- Quinn Emanuel: “A Tool-Based Framework: How AI Platforms Fit Into Centuries of Privilege Doctrine” (defense counsel in the case)
- Harvard Law Review note on United States v. Heppner (verbatim quotations from the opinion)
- United States v. Heppner, No. 1:25-cr-00503 (S.D.N.Y.), CourtListener docket; written opinion at 2026 WL 436479
- Warner v. Gilbarco, No. 2:24-cv-12333, ECF 94 (E.D. Mich. 10 Feb 2026), order text (CourtListener PDF)
- Seyfarth Shaw: “AI Privilege and Waiver: What Courts Are Actually Saying”
- Morgan v. V2X, Inc., 2026 WL 864223 (D. Colo. 30 Mar 2026), as reported in the analyses above.
Related
- Warner v. Gilbarco, the case page
- AI and the practice of law, including our Heppner analysis
- Zero-egress: how nothing leaves your machine
- The sanctions record, the other half of AI-in-court risk
- Every verified AI standing order
Checked 4 August 2026. The Heppner opinion text is paywalled (2026 WL 436479); the holdings and quotations above are drawn from the linked law-firm analyses and corroborate one another. Information, not legal advice, privilege questions in a live matter belong to your own counsel.
Information, not legal advice. Every entry is verified against the court's own document or contemporaneous reporting; where a source is reporting rather than the document, we say so.
