I love legal tech. I build with it. I preach it. I use it. But I'm also a trial lawyer who loses sleep over one thing: avoidable risk. And right now, nothing is more avoidable—or more misunderstood—than the way generative AI can quietly wreck attorney-client privilege and work product when it's used the wrong way.
Let's talk about the jurisprudence of digital intermediaries—without turning this into a law review article you'll "bookmark for later" and never read again.
The Vibe Shift: AI Isn't a Typewriter—It's a Third Party with Terms of Service
A lot of lawyers (and even more clients) want the law to treat generative AI like a typewriter: a neutral tool that helps you get your thoughts on paper.
The problem is that many AI tools aren't "tools" in the way a typewriter is. They're services—often cloud-based—owned and operated by someone else, subject to someone else's policies, logs, retention rules, and (sometimes) human review. And privilege law has never been sentimental about "the spirit of confidentiality." It cares about whether the communication was actually confidential.
That's not me being dramatic. That's the core architecture of privilege law.
Privilege in 90 Seconds: The Rule, the Reason, and the Trap Door
The attorney-client privilege is the oldest recognized privilege for confidential communications in Anglo-American law, designed to encourage "full and frank" attorney-client communications. Upjohn says it best.1
But courts also remind us that privileges are exceptions to the truth-seeking process and are not treated like a casual "good vibes" doctrine.2
The Trap Door
Voluntary disclosure to an unnecessary third party usually waives privilege, because the communication wasn't kept confidential.3 So the real question with generative AI is not "Is it a machine?" The question is: "Did you just disclose protected information to a third-party service in a way that kills confidentiality?"
Necessary Intermediaries: Kovel, Translators, and Why AI Is Not Automatically "On the Team"
The law does allow privilege to survive when certain third parties are involved—if they're necessary to the legal representation. The classic case is United States v. Kovel, where the Second Circuit extended privilege to communications involving an accountant who functioned like a translator for the attorney.4
But courts also draw a hard line: Kovel doesn't cover a third party who is merely providing useful information or advice, as opposed to facilitating attorney-client communications.5
That matters for generative AI because most public-facing AI platforms are not your agent. They don't owe fiduciary duties. They're not supervised like staff. They may explicitly disclaim confidentiality. They may reserve rights to store or use data. And they may be capable of handing data over under legal process.
That's not "your paralegal." That's a vendor.
If you've ever said "We'll just run it through ChatGPT to tighten it up," ask yourself: did we hire and supervise this tool like we'd hire and supervise a human assistant? Or did we just pour client secrets into a commercial platform and hope for the best?
Confidentiality Is About Expectations—Not Your Intentions
Courts have been dealing with privilege problems in "modern" communications for years. Not AI—just email, employer systems, and third-party access.
A well-known framework comes from In re Asia Global Crossing, which focuses on whether the person had a reasonable expectation of privacy when using a corporate email system (looking at policies, monitoring, access, and notice).6
Privilege Preserved
Stengart v. Loving Care Agency — privilege held where the right circumstances existed.7
Privilege Lost
Holmes v. Petrovich Dev. Co. — employer policy/notice killed privacy expectations.8
The through-line is simple: if the environment screams "not private," courts are not impressed that you hoped it would stay private. Now apply that to a tool that openly says your inputs aren't confidential. That's not a gray area. That's a flashing neon sign.
The "Heppner" Wake-Up Call: The Court Says the Quiet Part Out Loud
If you want the headline version: a federal judge in SDNY ruled from the bench that documents generated through a commercial AI platform weren't protected by attorney-client privilege or work product—and the court grounded the reasoning in third-party disclosure and lack of confidentiality.
This wasn't theoretical. It was litigation.
United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y.)
The government moved for a ruling that roughly 31 documents the defendant generated using Anthropic's Claude were not privileged. The motion emphasized three core points: (1) the AI tool isn't a lawyer and no lawyer was involved when the documents were created; (2) the platform disclaimed legal advice / an attorney-client relationship; and (3) the platform's privacy policy permitted disclosure to governmental authorities—undercutting confidentiality.14
At the February 10, 2026 conference, Judge Rakoff stated he was "not saying, remotely, any basis for any claim of attorney-client privilege," pointing to the fatal fact: the defendant "disclosed it to a third-party, in effect, AI," which had an express provision that submissions were "not confidential." Then the court granted the government's motion.13
Let's pause and translate that into plain English: if your client (or you) dumps confidential case facts into a tool that says "your inputs aren't private," do not be surprised when a judge treats that like talking about your case in front of a stranger.
Work Product Is Not a Force Field, Either
Work product doctrine exists to protect the mental impressions and strategies of counsel.9 And it can extend to certain agents working under attorney direction.10
But Heppner highlights an uncomfortable reality: when AI content is created by the client independently (not at counsel's direction) and doesn't reflect counsel's strategy, courts may treat it as the client's self-help "research," not attorney work product.13
Also note the related "can't retroactively create privilege" principle: preexisting documents don't become privileged just because they get sent to a lawyer later.11 So if a client creates an "AI defense memo" on their own, you may be inheriting a discovery problem, not a privileged asset.
A Sneaky Extra Problem: "Congrats, Counsel—You Might Be a Witness Now"
If AI prompts include information counsel shared with the client, and the AI output becomes evidence, you can stumble into witness-advocate conflict territory. Even in Heppner, defense counsel raised concerns that using the AI-generated material at trial could turn the defense team into fact witnesses.
Translation: the AI tool isn't on your team, but it can drag your team into the case as witnesses. That's not a "tech issue." That's a litigation landmine.
Ethics Has Entered the Chat: ABA Formal Opinion 512
Even if your jurisdiction hasn't issued an AI-specific opinion yet, the ABA has: Formal Opinion 512 (July 29, 2024).15 In plain English, the ABA's message is:
You must understand the benefits and risks of GAI (competence).
You must protect confidentiality (and that includes understanding how tools handle data).
You must supervise the work and verify outputs (no hallucinated citations, no "the robot said so").
You may need informed client consent when using GAI in ways that create meaningful confidentiality risk.
And if you think courts don't care about hallucinations, go read the sanctions order in Mata v. Avianca, Inc.16
Ohio Spotlight: Courts Are Already Regulating Generative AI Use
I practice in Ohio, so I pay close attention to what's happening here. And Ohio courts (state and federal) are not waiting for a national "AI rulebook."
Standing orders requiring disclosure when generative AI is used to draft filings, plus certification that the filer reviewed source material and verified accuracy (Rule 11 energy, basically).17
Similarly requires an attached declaration captioned "Disclosure and Verification of Use of Generative AI."18
Flatly prohibits attorneys (and pro se parties) from using AI in the preparation of any filing submitted to the court (while clarifying the ban doesn't apply to traditional legal research tools like Westlaw/Lexis or search engines).19
Local Rule 12.08 requiring a "disclosure/certificate" with filings if generative AI was used, and a certification that the party reviewed for accuracy and legal validity.20
So if you're practicing in Ohio and you're not tracking AI standing orders and local rules, you're practicing with a blindfold on.
Privilege-Safe AI: The Practical Playbook (What I Tell My Team)
This is the part you can actually use on Monday morning.
Treat public AI like a public place
If the tool is consumer-grade, web-based, and governed by terms you didn't negotiate, assume the safest rule: don't input client confidential information. If you wouldn't put it on a postcard, don't put it in a prompt.
Stop letting clients "prep their case" with chatbots
Clients love to "organize their thoughts" and show up with an AI-generated timeline, strategy memo, or "questions for cross." After Heppner, that can be toxic—especially if it contains facts learned from counsel. Put it in writing. Put it in your welcome packet. Say it out loud: "Do not use generative AI tools to analyze your legal exposure or draft statements about your case."
If you use AI internally, architect it like you mean it
Privilege doesn't survive vibes. It survives process. That means: vendor vetting, non-training / non-retention commitments, access controls and audit trails, isolation by client/matter, and internal policies that limit what can be entered and by whom.
Don't let "AI note-taking" become a silent participant
Meeting transcription can be incredibly useful—until it converts a sensitive conversation into a searchable artifact stored somewhere outside your control. Treat that system like evidence handling: know where the data lives, who can access it, and how it's retained.
Human verification is not optional
If a court requires disclosure/certification, comply. If it doesn't, comply anyway in spirit—verify citations, verify quotes, verify the law. Mata is your cautionary tale.
A Legislative "Wish List"
If I had a magic wand, I'd love to see evidence and privilege rules modernize around the reality of "digital assistants"—especially when they're used as functional equivalents of transcription, translation, or summarization agents under attorney supervision. But until the rules catch up, we have to practice under today's standards: confidentiality depends on reasonable steps and real-world third-party access, not on our hopes about what a machine "should" be.
Bottom Line
Generative AI is not the enemy. Sloppy AI workflows are.
If your AI tool is effectively a third party, and it's telling you the inputs aren't confidential, the privilege analysis is brutally simple: you've got a problem. Heppner didn't invent that rule—it just applied it to modern tech with modern consequences.
So yes: use AI. Build with AI. Enjoy the speed. But don't gamble with the one thing your clients expect you to protect with your life: confidentiality.
Download the Full Article
Get the complete article as a Word document for offline reading, sharing with colleagues, or CLE reference.
Endnotes
1. Upjohn Co. v. United States, 449 U.S. 383, 389 (1981).
2. United States v. Nixon, 418 U.S. 683, 709 (1974).
3. In re Horowitz, 482 F.2d 72, 81 (2d Cir. 1973).
4. United States v. Kovel, 296 F.2d 918, 922 (2d Cir. 1961).
5. United States v. Ackert, 169 F.3d 136, 139 (2d Cir. 1999).
6. In re Asia Global Crossing, Ltd., 322 B.R. 247, 257 (Bankr. S.D.N.Y. 2005).
7. Stengart v. Loving Care Agency, Inc., 201 N.J. 300, 323–24, 990 A.2d 650, 664–65 (2010).
8. Holmes v. Petrovich Dev. Co., 191 Cal. App. 4th 1047, 1071, 119 Cal. Rptr. 3d 878, 896 (2011).
9. Hickman v. Taylor, 329 U.S. 495, 510–11 (1947).
10. United States v. Nobles, 422 U.S. 225, 238–39 (1975).
11. Fisher v. United States, 425 U.S. 391, 403–04 (1976).
12. In re Grand Jury Subpoenas Dated Mar. 19, 2002 & Aug. 2, 2002, 318 F.3d 379 (2d Cir. 2003).
13. Transcript of Conference at 3, 6, United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 10, 2026) (Rakoff, J.).
14. United States' Motion for a Ruling that Documents the Defendant Generated Through an Artificial Intelligence Tool Are Not Privileged, United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 6, 2026), ECF No. 22.
15. ABA Comm. on Ethics & Prof'l Resp., Formal Op. 512 (2024).
16. Mata v. Avianca, Inc., No. 22-cv-1461 (PKC), 2023 WL 4114965 (S.D.N.Y. June 22, 2023).
17. Standing Order on the Use of Generative Artificial Intelligence (S.D. Ohio Oct. 21, 2025) (Graham, J.).
18. Standing Order Governing the Use of Generative Artificial Intelligence (S.D. Ohio Aug. 20, 2025) (Hopkins, J.).
19. Court's Standing Order on the Use of Generative AI (N.D. Ohio) (Boyko, J.).
20. Montgomery Cnty. Ct. Com. Pl. Loc. R. 12.08.
Not legal advice; this is general education and risk-spotting. For specific issues, talk to counsel in your jurisdiction.
AI Disclosure: This article was human-reviewed but may contain AI-generated elements. Readers should conduct their own research and remain skeptical of potential factual errors.








