In July 2025 Sam Altman said the quiet part out loud: “If you talk to a therapist or a lawyer or a doctor about those problems, there’s legal privilege for it … We haven’t figured that out yet for when you talk to ChatGPT” (TechCrunch). Seven months later a Manhattan federal judge figured it out for him. The answer was no.

So does using ChatGPT waive attorney-client privilege? The question bundles three problems, and 2026 produced a ruling on each. A client who talks to a chatbot on his own has no privilege to lose. A lawyer who uses one at the client’s direction may keep work-product protection, and might keep privilege, on the right terms. And the prompts themselves are discoverable by whoever can reach the server. The tier-by-tier picture lives in the confidentiality cluster; this page is about the cases.

Three separate questions hiding in one

The question The 2026 case What it decided Practical rule
Is the client’s own chatbot session privileged? United States v. Heppner (S.D.N.Y., 10 and 17 Feb 2026) No privilege, no work product Warn clients at intake; consumer chats are evidence
Does a litigant’s own AI use waive work product? Warner v. Gilbarco (E.D. Mich., 10 Feb 2026); Morgan v. V2X (D. Colo., 30 Mar 2026) No waiver; but Morgan required disclosure of the tool Work product survives if nothing reaches an adversary
Can lawyer-directed AI use sit inside the privilege? Heppner dicta “Might arguably” be a lawyer’s agent Direct the use in writing on a confidential tier
Can discovery material go into public AI at all? Jeffries v. Harcros (D. Kan., 25 Mar 2026); Morgan v. V2X Banned by protective order Read the order before pasting anything

Michelle R. Six of Gunster calls this “the early formation of a framework” in which “the specific terms of service of the AI platform” help decide outcomes.

Heppner: the search, the thirty-one documents, the ruling

Indicted for an alleged securities fraud of more than $150 million, the defendant had started asking Claude about his situation after receiving a grand jury subpoena. When he was arrested on 4 November 2025, FBI agents searched his home and took approximately thirty-one documents memorialising those conversations. Judge Jed Rakoff granted the Government’s motion to use them from the bench on 10 February 2026 and explained why in a memorandum filed on 17 February (United States v. Heppner, ECF 27).

“Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege.” — Judge Jed S. Rakoff, United States v. Heppner (S.D.N.Y. 2026), via Orrick

Two further findings mattered more. The communications were not confidential, because the platform’s privacy policy allowed third parties to see them. And they were not work product, because they were not prepared by or at the behest of counsel; defence counsel conceded they had not directed the use.

Why Anthropic’s privacy policy mattered more than the technology

Judges ask whether the speaker reasonably expected confidentiality, not how a transformer works. Rakoff answered by reading the consumer Privacy Policy as it stood on 19 February 2025: Anthropic collects “inputs” and “outputs”, uses them to “train” Claude, and may disclose them to “third parties”, including “governmental regulatory authorities”. A person who accepts those terms cannot then claim the conversation was confidential.

Whichever Claude tier a client is on, the court reads the contract, not the model card. A policy reserving training and third-party disclosure is fatal; use a tier whose terms do not.

English courts reached the same place. The Upper Tribunal held that to put client letters “into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege” (UK v SSHD [2026] UKUT 81 (IAC), para 21).

The Kovel opening: counsel-directed use on a confidential tool

The memorandum’s most useful passage is dicta:

“Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.” — Judge Jed S. Rakoff, United States v. Heppner, via ABA Litigation News

That is Kovel logic: an accountant retained by counsel to help render advice sits inside the privilege because the lawyer directs the work. The argument has two conditions, and you control both. Direction: at counsel’s instruction, for the purpose of the advice, and on the record. Confidential terms: direction is worthless if the contract reserves training and third-party disclosure, because the first Heppner ground still bites. Only business and enterprise tiers with a written no-training clause, a DPA and defined retention qualify, and even then the argument is untested. The cheapest insurance is a file note.

Document counsel's direction before the work starts
Draft a one-paragraph internal file memorandum, headed "Privileged and confidential - prepared at the direction of counsel", recording that [name, role] has directed the use of [tool and tier, e.g. ChatGPT Enterprise / Claude Team] on matter [reference] for the purpose of [rendering legal advice on X]; that the tool operates under [no-training clause; DPA; retention period]; that inputs will be [anonymised / limited to these categories]; who reviews the outputs; and that every output is a draft for counsel's review. Under 120 words, plain English, no conclusion on whether privilege attaches. Add date and initials.

Warner, Morgan and Jeffries: what the civil courts added

Three civil decisions in one quarter, summarised by Akin Gump, complete the framework.

Warner v. Gilbarco: “tools, not persons”

In Warner v. Gilbarco, Inc. (E.D. Mich., 10 February 2026) the defendant argued that a pro se plaintiff drafting with ChatGPT had waived work product. The court disagreed: “the work-product waiver has to be a waiver to an adversary”, generative AI programs are “tools, not persons”, and compelling production would “nullify work-product protection in nearly every modern drafting environment”.

Morgan v. V2X: protected, but name the tool

In Morgan v. V2X, Inc. (D. Colo., 30 March 2026) work product was again upheld for a pro se plaintiff, but he had to disclose which AI tool he had used. The court then amended the protective order so that confidential information may not go into an AI platform unless the provider is contractually prohibited from “(1) storing or using inputs to train or improve its model; and (2) disclosing inputs to third parties except where essential”, conceding that this “practically bars the use of most ‘low-to-no-cost’ AI tools”. A court has written your vendor test.

Jeffries v. Harcros: no public AI for discovery material at all

Jeffries v. Harcros Chemicals Inc. (D. Kan., 25 March 2026) banned public, “open” AI tools for all discovery materials, confidential or not, because it is “practically impossible” to claw back data once processed.

Read together: work product survives when nothing reaches an adversary; privilege only when the tool is confidential and counsel directs the use; neither matters if the protective order forbids the tool. Check the order, then the tier, then the direction.

The client-side leak: divorce, custody and will contests

The larger exposure is what clients do with advice after it leaves your office. Ward and Smith’s family-law team lists what divorce clients do with ChatGPT, from summarising attorney communications to preparing for depositions, and warns that “sharing information with them can waive privilege just as easily as forwarding a confidential email to a stranger”; clients should expect subpoenas for “all communications with AI-based tools, including prompts, inputs, and outputs” (Ward and Smith).

Estate practice is sharper still. Ridley Law describes the will contest in which “They can read your own words, typed to a chatbot, laying out exactly what you were thinking and why”, and warns that pasting the lawyer’s advice into a chatbot for a “second opinion” risks waiver under California Evidence Code section 912 (Ridley Law). Corporate clients are not immune: a CEO’s ChatGPT conversations about a $250 million earn-out surfaced in Fortis Advisors v. Krafton (Del. Ch. 2026).

What to write in the engagement letter and the client handout

Three bar sources shape it. ABA Formal Opinion 512 requires informed consent before client information goes into a self-learning tool, says “Merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient”, and calls the engagement agreement “a logical place” for the disclosure (ABA 512). DC Ethics Opinion 388 applies Rules 1.1, 1.6, 5.1 and 5.3, among others, to a tool it calls, borrowing NPR, “an omniscient, eager-to-please intern who sometimes lies to you”. Pennsylvania’s Joint Formal Opinion 2024-200 says lawyers “must communicate with clients about using AI technologies in their practices”. Ward and Smith’s client directive is the model: “Do not input, paste, upload, or otherwise transmit any legal advice, attorney communications, case documents, financial information, or strategy discussions into any public AI tool.” This prompt produces both documents.

Engagement-letter clause and day-one client warning
Act as a [jurisdiction] professional-responsibility partner. Draft two documents in plain English. (1) An engagement-letter clause on our use of AI that meets an informed-consent standard, not boilerplate: the tools we use (enterprise tiers with no-training and retention terms; never consumer tools for client information); what client information may be processed and how it is anonymised; the specific risks (error, confidentiality, retention, disclosure to the provider); our human-review commitment; the client's right to instruct otherwise; billing for actual time only. (2) A client handout headed "Please do not paste our advice into a chatbot", under 250 words, explaining why doing so can waive privilege, noting that a US court in 2026 held a client's own AI conversations unprotected, and offering the alternative: ask us. Tag rule citations [VERIFY].

A privilege-preserving workflow

Orrick’s post-Heppner advice (no privileged material in public tools; assume AI analysis is discoverable; AI warnings in Upjohn scripts; enterprise terms) and GC AI’s “counsel visibly directing the work” reduce to five steps.

  1. Read the protective order first. A Jeffries- or Morgan-style clause answers the tool question.
  2. Choose a tier that passes the Morgan test: written no-training clause, no third-party disclosure except as essential, defined retention, a DPA. The Business versus Enterprise comparison shows which plans qualify.
  3. Direct the use in writing, with the file memo above, so the Kovel argument exists if you ever need it.
  4. Anonymise, label and file. Placeholders in, key table offline; outputs marked “prepared at the direction of counsel” and kept in the matter file, not a chat history; feedback buttons off, since a thumbs-up sends the document to the vendor for years.
  5. Warn the client at intake, in writing, and again whenever you send advice that would hurt read aloud in a deposition. “Deleted” is conditional: the NYT preservation order kept every deleted Free, Plus, Pro and Team chat for four and a half months in 2025.

When a client sends you chatbot output that contradicts your advice, this reply prompt from the prompt library corrects it without lecturing.

Reply to "the chatbot told me otherwise" without lecturing
A client has sent me the following AI-generated analysis <client_ai_text>[paste]</client_ai_text>, which conflicts with my advice <my_advice>[paste]</my_advice> under [jurisdiction] law. Draft a reply that: thanks them; identifies where the AI text goes wrong (wrong jurisdiction, outdated law, invented authority, missing fact) in one sentence each; explains plainly why our advice stands; and warns, in one sentence without lecturing, that pasting our communications into public AI tools can jeopardise confidentiality and privilege. Warm, brief, no defensiveness. Under 200 words. Cite nothing that is not already in my advice.

Criminal, family and estate clients are least likely to know the rule; the criminal defence, family law and estate planning guides each carry a practice-specific intake script, and the client communication guide covers tone.

Where to go next: the tier-by-tier confidentiality answer explains which plans of ChatGPT, Claude, Gemini and Copilot train on your prompts, and the ABA 512 explainer sets out the consent rules the engagement clause must satisfy. Turning the file memo, the client warning and the tier check into a Monday-morning routine is the confidentiality session of AI Lab for Lawyers, done live on anonymised material rather than on slides.

Frequently asked questions

Are ChatGPT conversations privileged?

Not on their own. Privilege protects confidential communications between a client and a lawyer for the purpose of legal advice; a chatbot is neither a lawyer nor, on a consumer plan, confidential. In United States v. Heppner (S.D.N.Y. 2026) Judge Rakoff held a defendant's Claude exchanges unprotected because Claude is not an attorney and the consumer privacy policy allowed third-party access. Counsel-directed use on a contractually confidential tool may be different, but no court has yet so held.

What did the court decide in United States v. Heppner?

That roughly thirty-one documents recording a securities-fraud defendant's conversations with Claude, seized by the FBI from his home, were covered by neither attorney-client privilege nor the work-product doctrine. Claude is not an attorney, the consumer privacy policy allowed disclosure to third parties, and the material was not prepared at the behest of counsel. The ruling came from the bench on 10 February 2026 with a written memorandum on 17 February 2026.

Can my prompts be subpoenaed?

Yes, if they exist somewhere a subpoena can reach. Family lawyers now tell clients to expect subpoenas for all communications with AI tools, including prompts, inputs and outputs, and Morgan v. V2X required a litigant to disclose which AI tool he used. The NYT preservation order showed a vendor can be forced to keep deleted chats. A lawyer's own unused prompts and test results were opinion work product in Tremblay v. OpenAI, but that protection is not automatic.

Does a client pasting my advice into ChatGPT waive privilege?

On a consumer tool, it very likely can. The UK Upper Tribunal treated pasting client letters into ChatGPT as placing them in the public domain and waiving privilege, and Ward and Smith warn that sharing advice with a chatbot can waive privilege as easily as forwarding an email to a stranger. Ridley Law warns that a California client who does this for a second opinion risks waiver under Evidence Code section 912. Warn clients in writing on day one.

Is work product protection available for AI drafts?

Often, yes. Warner v. Gilbarco (E.D. Mich., February 2026) held that a pro se litigant's ChatGPT use did not waive work product, because waiver requires disclosure to an adversary and AI programs are tools, not persons. Morgan v. V2X (D. Colo., March 2026) agreed but ordered disclosure of the tool used. Heppner denied work product only because the material was not prepared at counsel's direction. Document counsel's direction and use a no-training tier.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.