Skip to content
Menu ▾
Patent pending

Privilege, work product, and the tool's terms of service

AI and attorney-client privilege:
the split every litigator should know.

Two federal decisions on the same day in February 2026 read opposite ways, until you look at what each was actually deciding. The difference is not AI versus no AI. It is whose tool, whose terms, and whose direction.

Quotations are from the opinions as quoted in the linked primary and law-firm sources.

The answer first. In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y., bench ruling 10 February 2026; written opinion 17 February 2026, Rakoff, J.), 31 documents a criminal defendant created with a consumer AI tool were protected by neither attorney-client privilege nor work product. The mechanism was the platform's own privacy terms, it collects inputs and outputs, trains on them, and reserves the right to disclose them to third parties, including the government, which defeated any reasonable expectation of confidentiality.

Heppner did not hold that using AI waives privilege. It held that this tool's terms destroyed confidentiality for these documents. The same day, in Warner v. Gilbarco (E.D. Mich.), a magistrate judge protected a litigant's AI-assisted materials under the work-product doctrine. That is the split, and it is narrower, and more manageable, than the headlines.

What Heppner held, the three grounds

Bradley Heppner, a defendant in a securities-fraud prosecution, used the consumer version of Anthropic's Claude to prepare documents about his case, and later shared them with his lawyers. Judge Rakoff ruled from the bench on 10 February 2026 and issued a written opinion on 17 February 2026 (2026 WL 436479). As summarized in the Paul Weiss client memorandum (PDF) and Quinn Emanuel's analysis, Quinn Emanuel was defense counsel in the case, all three traditional elements of privilege failed:

  • Not a communication with counsel. “Because Claude is not an attorney, that alone disposes of Heppner's claim of privilege”, the communications were with a tool, not a lawyer.
  • Not confidential. Anthropic's privacy policy, as the court read it, collects data on users' inputs and Claude's outputs, uses them to train the model, and reserves the right to disclose them to third parties, including governmental authorities. Sharing case material with a platform on those terms was not a confidential communication.
  • Not for the purpose of obtaining legal advice. Heppner used the tool on his own initiative, not at counsel's direction. And sending the output to a lawyer afterward does not cure it: non-privileged communications are not, in the court's phrase, “alchemically changed into privileged ones upon being shared with counsel.”

Work product failed for a parallel reason: the documents were not prepared by counsel or at counsel's direction, so they were not litigation materials of the party's representative under Rule 26(b)(3). Judge Rakoff pointedly left the door open to a different result where counsel directs the AI use, the Kovel analogy, where an accountant or translator working at a lawyer's behest shares the lawyer's privilege.

What Warner held, and how it differs

Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. 10 February 2026, Patti, M.J.) went the other way on nearly everything that matters here: a pro se plaintiff's use of ChatGPT in her own case was protected work product; the defendants' motion to compel “all documents and information concerning her use of third-party AI tools” was denied; and the court wrote that work-product waiver “has to be a waiver to an adversary or in a way likely to get in an adversary's hand,” and that AI programs “are tools, not persons.”

The reconciliation, decision by decision: Heppner is a criminal case about attorney-client privilege, where confidentiality is the whole doctrine and the tool's terms destroyed it. Warner is a civil discovery dispute about work product, where the waiver question is narrower, disclosure to an adversary, and using a drafting tool is not disclosing to anyone's opponent. Neither court said “AI use waives privilege,” and neither said “AI use is always safe.” Both asked the ordinary questions and reached answers driven by the tool's terms and the doctrine's elements. (The Seyfarth Shaw comparison makes the same point.)

The practical rules for a law firm

  • Read the tool's privacy terms before client work touches it. Heppner turned on the consumer platform's terms, collection, training, and a disclosure reservation that reaches government. The confidentiality analysis is a terms-of-service analysis.
  • Different products and account tiers may be governed by different terms. The relevant question is the terms that applied to the specific use at issue.
  • Terms change; re-read them. We considered a per-vendor table here and omitted it deliberately: these policies are revised often, and a cached table would mislead. Read the current versions: Anthropic's privacy policy, OpenAI's terms and policies, Google's terms.
  • Counsel-directed use may matter. The Kovel door Judge Rakoff left open is the one a firm can walk through deliberately: use directed by counsel, documented as such, on terms that preserve confidentiality.
  • Document what you did, when you did it. If privilege or work product is ever challenged, the question will be exactly what Heppner asked: which tool, which terms, whose direction, what confidentiality. A sealed, dated record of AI use and human verification answers it from evidence rather than recollection.

The structural question: where does the work go?

Heppner makes confidentiality analysis fact-specific. For a locally executed workflow, fewer third parties may receive the underlying work, but architecture does not itself establish privilege. The Regulayer Receipt is designed so receipt creation and verification do not require the underlying document to be sent to Regulayer. See what data the product does and does not transmit → Privilege and work-product protection remain legal questions for counsel and, ultimately, the court.

What we are watching

  • Ireland, High Court Practice Direction HC 142, in operation 1 September 2026, read at source. Paragraph 10 lists legal privilege among the known risks of generative AI tools: information entered into such tools, including search results, may be required to be disclosed in legal proceedings, and privileged information entered into non-private tools may lose its privileged status. Paragraph 32 says that where documents, including documents obtained on discovery, are subject to a court order or an undertaking restricting their use, generative AI tools should not be employed on them if that would involve or risk disclosure contrary to it. Our page on HC 142.
  • Morgan v. V2X, Inc., 2026 WL 864223 (D. Colo. 30 March 2026), as reported, another federal court working through AI-drafted materials and protection questions.
  • The Heppner prosecution itself, as reported, the defendant was convicted on 7 May 2026; any appeal could put the privilege ruling before the Second Circuit.
  • Vendor terms, both major consumer platforms revised their data-use policies in late 2025 and early 2026; the confidentiality calculus in Heppner moves with those documents.
  • Bar guidance, state and city bar AI opinions continue to multiply; confidentiality duties under Rule 1.6 are the common thread.

The lesson for the next filing

After Heppner, technical facts can matter to the privilege analysis: where the work ran, under what terms, at whose direction, and what record exists. Our deeper treatment for practitioners is on the attorneys page; the receipts that document those facts are what we build.

AI and the practice of law →  ·  The security design →

Sources

Related

Checked 4 August 2026. The Heppner opinion text is paywalled (2026 WL 436479); the holdings and quotations above are drawn from the linked law-firm analyses and corroborate one another. Information, not legal advice, privilege questions in a live matter belong to your own counsel.

Information, not legal advice. Sources are identified above; some points rely on contemporaneous reporting where underlying court material is not publicly accessible.