Attorney-Client Privilege and AI
Has Anyone Actually Waived It Yet?

Published July 26, 2026

This article is general information, not legal advice. Privilege law is jurisdiction-specific and, on this question, actively splitting. For your own situation, consult a qualified lawyer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers.

For two years this was a hypothetical that ethics committees and CLE panels chewed on without an answer. As of February 2026, it has case law — and the answer is messier than anyone predicted. In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York held that a criminal defendant's strategy documents generated with Anthropic's consumer Claude chatbot were protected by neither attorney-client privilege nor the work-product doctrine — the first ruling to strip protection from AI chats. The very same week, a federal court in Michigan reached the opposite framework in Warner v. Gilbarco, holding that a pro se litigant's ChatGPT queries and answers were protected work product, and that "telling" ChatGPT was not a waiver. So: has anyone actually lost privilege through a chatbot yet? One defendant has effectively lost protection over 31 documents; another litigant kept hers; and the scenario lawyers fear most — a client pasting their attorney's actual advice into a consumer chatbot — still has no square ruling. Here is where the law stands, decision by decision.

Why This Question Took Until 2026

Attorney-client privilege has an element people forget until it bites: confidentiality. The privilege protects communications between lawyer and client made in confidence for the purpose of legal advice — and it is waived when the communication is disclosed to a third party outside the circle. The work-product doctrine separately shields material prepared in anticipation of litigation, with its own, more forgiving waiver rules. Every fight about AI and privilege is really a fight about two questions: is a chatbot a "third party," and does typing into one destroy the expectation of confidence?

The warning lights were on well before any ruling. In July 2024, the American Bar Association's Formal Opinion 512 — its first ethics opinion on generative AI — told lawyers that client confidentiality applies fully to what they feed these tools, flagging self-learning consumer tools as a disclosure risk that may require informed client consent. A year later, OpenAI's own CEO Sam Altman said the quiet part aloud on a podcast: there is "legal privilege" when you talk to a lawyer, doctor or therapist, but for ChatGPT conversations "we haven't figured that out yet" — and those chats can be produced in a lawsuit. People kept typing anyway. Litigation did the rest.

Heppner: The First Court to Say No

Bradley Heppner, an executive indicted in October 2025 on securities and wire fraud charges connected to Beneficient and GWG Holdings, did something thousands of defendants have quietly done since 2023: he opened a chatbot. After his indictment — and after retaining counsel, but on his own initiative — he used the consumer version of Claude to generate 31 documents: reports outlining potential defense strategies, legal arguments, and analyses of the charges. He shared them with his lawyers. Prosecutors moved for the documents; Heppner claimed privilege and work product.

In February 2026, Judge Rakoff rejected both claims. The reasoning, compressed:

  • Claude is not a lawyer. Communications with a chatbot are not attorney-client communications, full stop.
  • The chats were not confidential. Anthropic's consumer privacy policy permits collecting and using inputs and outputs — so typing into the tool defeated any reasonable expectation of confidentiality. This is the sentence every privacy lawyer underlined: the provider's data terms decided the confidentiality element.
  • No counsel direction. Heppner ran the queries himself, not at his lawyers' direction — so the documents were not a lawyer's agent's work, and the outputs did not reflect counsel's strategy.

The court left one door open, and it matters: had counsel directed the AI use, the tool might function like a lawyer's agent under a Kovel-type arrangement (the doctrine that extends privilege to accountants and experts assisting counsel). The problem wasn't AI as such; it was a defendant freelancing his defense into a consumer product whose terms said his words weren't private.

Warner: The Same Week, the Opposite Framework

On February 10, 2026 — as the Heppner motion was being argued in Manhattan — Magistrate Judge Anthony Patti in the Eastern District of Michigan decided Warner v. Gilbarco, an employment case where the plaintiff, representing herself, had used ChatGPT to research legal questions and draft filings. The employer demanded her queries and the AI's responses in discovery.

The court said no. The ChatGPT exchanges reflected the plaintiff's mental impressions prepared in anticipation of litigation — classic work product. And on waiver, the court applied the Sixth Circuit's rule: work-product protection is waived by disclosure to an adversary or in a manner likely to reach one. Telling ChatGPT, the court held, is neither. Where Heppner treated the AI as a third party that receives your secrets, Warner treated it as a tool you think with — closer to a very talkative legal pad than to a person.

Three Courts, No Consensus

By late April 2026, commentators were already describing a genuine split. A third line of decisions has rejected Heppner's confidentiality logic as a blanket rule, reasoning that a service provider's technical access to data does not automatically destroy protection — while pointedly noting that enterprise AI deployments (contractual commitments not to train on inputs, data segregation, confidentiality terms) can support a reasonable expectation of confidentiality that consumer chatbots do not. The practical map, as of this writing:

  • Consumer chatbot, used on your own initiative: after Heppner, assume no privilege and — outside the Sixth Circuit's approach — fragile work-product protection at best.
  • AI use directed by counsel, on terms that keep data confidential: the Kovel door Heppner left open; likeliest to be protected, though not yet squarely blessed.
  • Work product from AI-assisted preparation: depends on where you are sued — protected in Warner's framework, denied in Heppner's circumstances.

No appellate court has ruled. The doctrine is being built one magistrate opinion at a time, and the frameworks are incompatible.

The Scenario Still Untested

Note what none of these cases decided. Heppner's documents were his own AI-generated strategizing, created before being shared with counsel. The nightmare scenario — a client takes their lawyer's actual privileged memo or email and pastes it into a consumer chatbot ("explain this to me", "is my lawyer right?") — has not yet produced a published waiver ruling. But the logic is not hard to extend: if typing into a consumer tool defeats confidentiality under Heppner, then pasting an existing privileged communication into one looks like a textbook disclosure to a third party, with the loss falling not on 31 AI reports but on the underlying attorney-client communication itself. Every serious commentator reads the case law as pointing that way; nobody should volunteer to be the test case.

Also unresolved: whether anything like an "AI privilege" should exist for everyone else — the therapist-style confidentiality Altman mused about. No legislature has created one. Until one does, AI conversations sit exactly where we described them in Your AI Chats Can Be Subpoenaed: discoverable business records with no privilege attached.

What This Means in Practice

  • If you are (or might become) a party to anything — criminal, civil, divorce, employment — do not run your case through a consumer chatbot. Your queries can be demanded in discovery, and Heppner says the products' own data terms may have already stripped their protection. If you want AI in your defense, ask your lawyer to direct and structure that use.
  • If you are a lawyer, ABA Opinion 512 already frames the duty: confidentiality applies to every prompt. The emerging case law adds the litigation angle — route AI work through counsel-directed, enterprise-grade arrangements whose terms support confidentiality, and paper the direction. Our confidentiality and privilege guide for lawyers covers the wider ethics landscape.
  • For everyone: the deeper lesson of Heppner is that a provider's privacy policy can decide a legal question about you. What a chatbot's terms say about collecting, retaining and training on your words — the fine print we audit in our 13-provider retention audit — turned out to be the load-bearing fact in a federal fraud prosecution.

How Secret Chat AI Fits — and Its Honest Limits

Let's apply the same candor we ask of everyone else. No AI service — Secret Chat included — creates attorney-client privilege. Privilege comes from a lawyer, and no court anywhere has held a chatbot conversation privileged. If your situation is legal, the protected place to discuss it is with counsel, and nothing here changes that.

What Secret Chat AI honestly changes is the discovery surface that made these cases possible. Secret Chat keeps no server-side archive of your conversations — chats live only in your own browser — so there is no stored transcript on our side for an opposing party to demand from us. And it is an anonymizer: it builds no profile of you, associates no chat with your identity, and your queries reach the top models anonymously — your email is used only for account access and payment, never linked to your prompts, and your queries are never used for training. The Heppner problem — a provider's logs, tied to a named user, describing his defense — is structurally the thing Secret Chat is built not to create.

And the limits, stated plainly: Secret Chat AI removes you from your queries — it does not remove the data from your messages. What you type still reaches the model provider verbatim (anonymously, but verbatim) and is processed under that provider's terms; copies you keep or share can still be discovered from you; and anonymity is not privilege, not a legal shield, and not a licence to hide anything a court is entitled to. Redacting names and sensitive details before sending remains your responsibility — here as anywhere.

Frequently Asked Questions

  1. Has a court actually ruled that AI chats aren't privileged?

    Yes. In United States v. Heppner (S.D.N.Y., February 2026), Judge Rakoff held that a criminal defendant's 31 defense-strategy documents generated with consumer Claude were protected by neither attorney-client privilege nor the work-product doctrine — partly because the provider's privacy policy defeated any expectation of confidentiality.

  2. So does using ChatGPT or Claude always destroy protection?

    No. The same week, Warner v. Gilbarco (E.D. Mich.) held a pro se litigant's ChatGPT queries and responses were protected work product, and that disclosure to the chatbot waived nothing under Sixth Circuit law. Courts are split, no appellate court has ruled, and outcomes currently depend on the facts and the jurisdiction.

  3. What happens if I paste my lawyer's advice into a chatbot?

    No published ruling has decided exactly that yet — but under Heppner's logic it looks like disclosure of a privileged communication to a third party, risking waiver of the underlying advice itself. Ethics guidance (ABA Formal Opinion 512) already treats client confidences in prompts as a serious risk. Don't be the test case.

  4. Can lawyers use AI without endangering privilege?

    The emerging safe pattern is counsel-directed use on enterprise terms: the Heppner court itself suggested AI used at a lawyer's direction might qualify as a lawyer's agent under a Kovel-type arrangement, and later decisions note that enterprise contracts (no training on inputs, confidentiality terms) support an expectation of confidentiality that consumer tools lack.

  5. Does Secret Chat give my chats legal privilege?

    No — no AI service can. Privilege requires a lawyer. What Secret Chat does is architectural: it stores no conversations on its servers and sends your queries to the models with no identity attached, so there is no provider-side, name-linked transcript of the kind produced in these cases. The content you type still reaches the model provider verbatim, and legal matters belong with counsel.

Conclusion

The hypothetical era is over. A federal court has now compelled a defendant's chatbot-drafted defense strategy on the reasoning that a consumer AI's own terms of service destroyed confidentiality; another has protected a litigant's ChatGPT research as work product days apart; and the question everyone actually asks — what if I paste my lawyer's advice? — is still waiting for its unlucky pioneer. Until appellate courts sort the frameworks out, the practical rule is the one that was always true: privilege lives in the conversation with your lawyer, and it survives by staying there. For everything else you ask an AI, assume it is discoverable — and prefer tools built so that the transcript courts would fight over never exists, and is never linked to you, in the first place.

Sources