Attorney-Client Privilege and AI
Has Anyone Actually Waived It Yet?

Published July 26, 2026 · Updated August 18, 2026

This article is general information, not legal advice. Privilege law is jurisdiction-specific and, on this question, actively splitting. For your own situation, consult a qualified lawyer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers.

For two years this was a hypothetical that ethics committees and CLE panels chewed on without an answer. As of February 2026, it has case law — and the answer is messier than anyone predicted. In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York held that a criminal defendant's strategy documents generated with Anthropic's consumer Claude chatbot were protected by neither attorney-client privilege nor the work-product doctrine. Note precisely what that means: the court did not find that protection existed and was then waived — it found that protection never attached in the first place. The very same day, a federal court in Michigan reached the opposite framework in Warner v. Gilbarco, holding that a pro se litigant's ChatGPT queries and answers were protected work product, and that "telling" ChatGPT was not a waiver. Three more civil decisions have since sided with Warner. So: has anyone actually lost privilege through a chatbot yet? Not squarely — one defendant's 31 documents turned out never to have been protected, four civil litigants kept theirs as work product, and the scenario lawyers fear most, a client pasting their attorney's actual advice into a consumer chatbot, still has no published ruling of its own. Here is where the law stands, decision by decision.

Why This Question Took Until 2026

Attorney-client privilege has an element people forget until it bites: confidentiality. The privilege protects communications between lawyer and client made in confidence for the purpose of legal advice — and it is waived when the communication is disclosed to a third party outside the circle. The work-product doctrine separately shields material prepared in anticipation of litigation, with its own, more forgiving waiver rules. Every fight about AI and privilege is really a fight about two questions: is a chatbot a "third party," and does typing into one destroy the expectation of confidence?

The warning lights were on well before any ruling. In July 2024, the American Bar Association's Formal Opinion 512 — its first ethics opinion on generative AI — told lawyers that client confidentiality applies fully to what they feed these tools, flagging self-learning consumer tools as a disclosure risk that may require informed client consent. A year later, OpenAI's own CEO Sam Altman said the quiet part aloud on a podcast: there is "legal privilege" when you talk to a lawyer, doctor or therapist, but for ChatGPT conversations "we haven't figured that out yet" — and those chats can be produced in a lawsuit. People kept typing anyway. Litigation did the rest.

Heppner: The First Court to Say No

Bradley Heppner, an executive indicted in October 2025 on securities and wire fraud charges connected to Beneficient and GWG Holdings, did something thousands of people under investigation have quietly done since 2023: he opened a chatbot. The timing matters, and it is easy to get wrong. He had received a grand-jury subpoena, knew he was a target, and had retained counsel — but had not yet been indicted. In that window, on his own initiative, he used the consumer version of Claude to generate 31 documents: reports outlining potential defense strategies, legal arguments, and analyses of the charges he expected. He fed in information he had learned from his attorneys, and shared the results with them.

Nor did prosecutors have to ask for the documents. Heppner was indicted on October 28, 2025; a week later, on November 4, FBI agents arrested him and executed a search warrant at his home, seizing his devices. It was his own defense counsel who then told prosecutors that roughly 31 of the seized files were conversations with Claude — and claimed privilege and work product over them. The government moved for a ruling that they were unprotected.

On February 10, 2026, Judge Rakoff rejected both claims. The reasoning, compressed:

  • Claude is not a lawyer. Communications with a chatbot are not attorney-client communications, full stop.
  • The chats were not confidential. Anthropic's consumer privacy policy permits collecting and using inputs and outputs — so typing into the tool defeated any reasonable expectation of confidentiality. This is the sentence every privacy lawyer underlined: the provider's data terms decided the confidentiality element.
  • No counsel direction. Heppner ran the queries himself, not at his lawyers' direction — so the documents were not a lawyer's agent's work, and the outputs did not reflect counsel's strategy.

Read the holding narrowly, because that is how later courts have read it: Rakoff found the documents failed at least two of the elements privilege requires, so the privilege never attached. This was not a ruling that a client had held protection and thrown it away.

The court left one door ajar, and it matters — though less than it is often reported to. Had counsel directed the AI use, Rakoff allowed, the tool might arguably function like a lawyer's agent under a Kovel-type arrangement (the doctrine that extends privilege to accountants and experts assisting counsel). He entertained the possibility; he did not bless it, and no court has since. The problem wasn't AI as such; it was a target freelancing his defense into a consumer product whose terms said his words weren't private.

Warner: The Same Week, the Opposite Framework

On February 10, 2026 — the very day Heppner came down in Manhattan — Magistrate Judge Anthony Patti in the Eastern District of Michigan decided Warner v. Gilbarco, an employment case where the plaintiff, representing herself, had used ChatGPT to research legal questions and draft filings. The employer demanded her queries and the AI's responses in discovery.

The court said no. The ChatGPT exchanges reflected the plaintiff's mental impressions prepared in anticipation of litigation — classic work product under Rule 26(b)(3). And on waiver, the court reasoned that generative AI programs are tools, not persons, so handing material to one is not the disclosure that forfeits protection. Where Heppner treated the AI as a third party that receives your secrets, Warner treated it as a tool you think with — closer to a very talkative legal pad than to a person. Worth knowing before you lean on it: the ruling did not rest on work product alone. The court also found the demand irrelevant and disproportionate under Rule 26(b)(1), and noted there was no evidence the plaintiff had uploaded confidential material — so a better-targeted request might not have fared the same way.

Eight Decisions — and the Dividing Line Is Not Criminal vs Civil

By late April 2026 commentators were describing a three-way split. The count has moved since, and it has moved in one direction. Four further civil courts have now sided with Warner:

  • Morgan v. V2X, Inc. (D. Colo., March 30, 2026) protected a pro se litigant's AI-assisted analysis, while conditioning it — ordering disclosure of which AI platforms were used and a protective order keeping confidential material out of consumer tools that are not contractually barred from training on it.
  • Tym v. Cerno (D.N.M., April 22, 2026) is the quietest of them and worth reading for what it does not do. Magistrate Judge Jennifer Rozzoni, ruling from the bench on a motion to compel, adopted Morgan's reasoning and held that if the plaintiff used generative AI to prepare his filings or for hearings, those interactions are shielded by work product. But she noted there is limited case law, that the parties had not briefed the question, and adopted the reasoning "at this time and for this case only" — a two-page order, not a considered opinion.
  • Tate Group Automotive v. Legacy Automotive Capital (Business Court of Texas, June 3, 2026) is the important one, because the party was represented by counsel — the fact Heppner turned on. Judge Grant Dorfman protected most of a businessman's ChatGPT conversations as work product under Texas Rule of Civil Procedure 192.5(a)(1) and expressly rejected Heppner's reasoning as governed by a federal rule that was not the one before him. Not everything survived: some pages were ordered produced, and the underlying materials fed to the tool had to be disclosed.
  • Assini v. Hayward (Sup. Ct. Nassau County, June 4, 2026) went further procedurally — quashing a subpoena served on OpenAI itself for a pro se defendant's prompts, uploads and outputs relating to the case. Adopting Morgan's framework under CPLR 3101(d), the court found it reasonable for a user to expect privacy and confidentiality in that exchange.

Two later decisions break the tidy version of that story, and they are the two a practitioner should actually read.

  • Tremblay v. OpenAI (N.D. Cal., the consolidated author copyright class action) protected prompts crafted by counsel to test ChatGPT as opinion work product — the near-absolute tier — because they embodied counsel's mental impressions about how to interrogate the model. Negative test results stayed protected; the positive ones the complaint relied on had to be produced. This is the closest thing yet to the counsel-directed pattern Heppner left open.
  • Shealy v. Seaside Investments (Suffolk County Superior Court, Business Litigation Session, Massachusetts, June 16, 2026) went the other way in a civil case with a represented party. The plaintiff's romantic partner had put litigation documents into ChatGPT without counsel's involvement, and the court held a non-attorney third party is not a "representative" under Massachusetts Rule 26(b)(3): "Neither the queries of AI programs for legal assistance by a party's romantic partner nor the AI output are protected from disclosure under the work product doctrine unless performed at the direction of counsel." It distinguished Warner and Morgan as pro se cases.

So the useful axis is not criminal versus civil — Shealy is civil and refused, Tremblay is civil and protected. It is counsel direction. Ranked by how strong the argument is: prompts written by your lawyer to test something (Tremblay); a self-represented litigant preparing their own case (Warner, Morgan, Tym, Assini, and Tate for a represented party under Texas's broader rule); material a represented party had generated by someone who is not counsel (Shealy, refused); and independent use with no litigation purpose (Heppner, refused).

Counting them: five civil decisions recognizing work-product protection for AI-assisted preparation, one criminal decision finding none, and one civil decision finding none. But resist calling it a clean jurisdictional split, and resist the criminal-versus-civil story too, because the cases are not asking the same question under the same rule. Heppner was a criminal prosecution, a represented defendant working independently, decided under Second Circuit doctrine that emphasizes material prepared by or at counsel's behest. Warner and Morgan were pro se civil litigants under Federal Rule 26(b)(3). Tate applied Texas's broader wording; Assini, New York's. Every one of the civil courts distinguished Heppner on its facts rather than defying it. The practical map:

  • Consumer chatbot, used on your own initiative: after Heppner, assume no attorney-client privilege. Work product is a live argument — increasingly a good one in civil litigation — but it is an argument, not a guarantee.
  • AI use directed by counsel, on terms that keep data confidential: the Kovel door Heppner left ajar. It strengthens the argument considerably; it has never been held to create privilege, and a court would still ask whether the tool genuinely facilitated the lawyer's advice and whether confidentiality was actually preserved.
  • Work product from AI-assisted preparation: not simply "depends on where you are sued." It turns on the governing civil or criminal rule, whether litigation was genuinely anticipated, who created the material, whether counsel directed or adopted it, what the prompts themselves reveal, and whether the disclosure made adversarial access substantially more likely.

No appellate court has ruled. The doctrine is being built one trial-court opinion at a time.

The Scenario Still Untested

Note what none of these cases squarely decided. The nightmare scenario — a client takes their lawyer's actual privileged memo or email and pastes it into a consumer chatbot ("explain this to me", "is my lawyer right?") — has not yet produced a published US ruling on whether the underlying advice loses its privilege. That qualifier now has to be there, because England has said something close to it out loud. In R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC), promulgated 17 November 2025, the Upper Tribunal stated in its headnote that "uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege". Read it for what it is: a proposition in a regulatory judgment about a solicitor's conduct and AI-generated fake citations, not an adversarial privilege fight between parties, and concerning a lawyer uploading client documents rather than a client uploading their lawyer's memo. But it is published judicial language using the word waive, and anyone relying on the silence should know it is no longer complete silence. It is closer to the line than it looks in the US too: Heppner told the court he had put information learned from his attorneys into Claude, and it bought him nothing. The logic is not hard to extend either — if typing into a consumer tool defeats the confidentiality element, then pasting an existing privileged communication into one looks like a textbook disclosure to a third party, with the loss falling not on 31 AI reports but on the attorney-client communication itself. That said, disclosure to a third party is not an automatic forfeiture in every setting: agents assisting counsel, translators, common-interest arrangements and promptly-remedied inadvertent disclosures all have their own doctrines. None of them was built with chatbots in mind, and nobody should volunteer to be the test case.

Also unresolved: whether anything like an "AI privilege" should exist for everyone else — the therapist-style confidentiality Altman mused about. No legislature has created one. Until one does, AI conversations sit roughly where we described them in Your AI Chats Can Be Subpoenaed: ordinary records carrying no privilege of their own. What Assini adds is that "no privilege" is not the same as "hand it over" — a subpoena still has to clear relevance and proportionality, and that one was quashed outright.

What This Means in Practice

  • If you are (or might become) a party to anything — criminal, civil, divorce, employment — do not run your case through a consumer chatbot. Your queries can be demanded in discovery, and Heppner says the products' own data terms may have already stripped their protection. If you want AI in your defense, ask your lawyer to direct and structure that use.
  • If you are a lawyer, ABA Opinion 512 already frames the duty: the confidentiality obligation follows any prompt containing information relating to a client's representation. It is ethics guidance under the Model Rules, not privilege law — it tells you what you must not do, while Heppner tells you what a court may later refuse to protect. The emerging case law adds the litigation angle — route AI work through counsel-directed, enterprise-grade arrangements whose terms support confidentiality, and paper the direction. Our confidentiality and privilege guide for lawyers covers the wider ethics landscape.
  • For everyone: the deeper lesson of Heppner is that a provider's privacy policy can decide a legal question about you. What a chatbot's terms say about collecting, retaining and training on your words — the fine print we audit in our 13-provider retention audit — turned out to be the load-bearing fact in a federal fraud prosecution.

How Secret Chat AI Fits — and Its Honest Limits

Let's apply the same candor we ask of everyone else. No AI service — Secret Chat included — creates attorney-client privilege. Privilege comes from a lawyer, and no court has held that a standalone exchange between a user and a chatbot is covered by attorney-client privilege merely because it concerns legal problems. Read the four civil wins above for what they are: work-product rulings, a separate and more losable protection that depends on litigation being anticipated and on who prepared the material. If your situation is legal, the protected place to discuss it is with counsel, and nothing here changes that.

What Secret Chat AI honestly changes is the discovery surface that made these cases possible. Secret Chat keeps no server-side archive of your conversations — chats live only in your own browser, and a prompt exists on our side only for as long as it takes to fetch your answer — so there is no stored transcript on our side for an opposing party to demand from us. (What does persist is ordinary infrastructure telemetry: IP addresses, request timestamps and error codes, kept for security for at most 30 days, as our privacy policy says. That is not a record of what you asked.) And it is an anonymizer: it builds no profile of you, associates no chat with your identity, and your queries reach the top models anonymously — your email is used only for account access and payment, never linked to your prompts, and your queries are never used for training. The Heppner problem — a provider's logs, tied to a named user, describing his defense — is structurally the thing Secret Chat is built not to create.

And the limits, stated plainly: Secret Chat AI removes you from your queries — it does not remove the data from your messages. "Anonymously" describes the link, not the words: no account identifier travels with your prompt. It is not a claim that the text stops being identifying — write your own name, your case number or your employer into a message and it is all still sitting there in the message. What you type still reaches the model provider verbatim (anonymously, but verbatim) and is processed under that provider's terms; the copies in your own browser, and anything you forward, remain fully discoverable from you, which is exactly how Heppner's documents surfaced — from his devices, not from Anthropic; and anonymity is not privilege, not a legal shield, and not a licence to hide anything a court is entitled to. Redacting names and sensitive details before sending remains your responsibility — here as anywhere.

Frequently Asked Questions

  1. Has a court actually ruled that AI chats aren't privileged?

    Yes. In United States v. Heppner (S.D.N.Y., February 10, 2026), Judge Rakoff held that a criminal defendant's 31 defense-strategy documents generated with consumer Claude were protected by neither attorney-client privilege nor the work-product doctrine — partly because the provider's privacy policy defeated any expectation of confidentiality. Precisely, the court found protection never attached; it did not find that the defendant had waived a protection he once held.

  2. So does using ChatGPT or Claude always destroy protection?

    No. On the same day, Warner v. Gilbarco (E.D. Mich.) held a pro se litigant's ChatGPT queries and responses were protected work product, and that handing material to a tool is not the disclosure that forfeits protection. Four more civil courts have since agreed — Morgan v. V2X (D. Colo., March 2026), Tym v. Cerno (D.N.M., April 2026, adopting Morgan from the bench), Tate Group Automotive v. Legacy Automotive Capital (Business Court of Texas, June 2026, a represented party) and Assini v. Hayward (Sup. Ct. Nassau County, June 2026, quashing a subpoena to OpenAI). All five protected work product, not attorney-client privilege, and each distinguished Heppner on its facts. No appellate court has ruled.

  3. What happens if I paste my lawyer's advice into a chatbot?

    No published US ruling has decided exactly that yet, though England's Upper Tribunal has stated in a regulatory judgment (R (Munir) v SSHD [2026] UKUT 81 (IAC)) that uploading confidential documents into an open AI tool breaches client confidentiality and waives legal privilege. Under Heppner's logic it looks like disclosure of a privileged communication to a third party, risking waiver of the underlying advice itself. Heppner did tell the court he had entered information learned from his attorneys into Claude, and it did not save the documents. Ethics guidance (ABA Formal Opinion 512) already treats client confidences in prompts as a serious risk. Don't be the test case.

  4. Can lawyers use AI without endangering privilege?

    The strongest available position is counsel-directed use on enterprise terms — but call it a stronger argument, not a safe harbour. The Heppner court entertained the possibility that AI used at a lawyer's direction might qualify as a lawyer's agent under a Kovel-type arrangement without deciding it, and no court has since held that counsel direction plus an enterprise contract creates privilege. Other decisions note that enterprise terms (no training on inputs, confidentiality commitments) support an expectation of confidentiality that consumer tools lack.

  5. Does Secret Chat give my chats legal privilege?

    No — no AI service can. Privilege requires a lawyer. What Secret Chat does is architectural: it stores no conversations on its servers and sends your queries to the models with no identity attached, so there is no provider-side, name-linked transcript of the kind produced in these cases. The content you type still reaches the model provider verbatim, and legal matters belong with counsel.

Conclusion

The hypothetical era is over. A federal court has now held a defendant's chatbot-drafted defense strategy unprotected, partly on the reasoning that a consumer AI's own terms of service defeated any expectation of confidentiality; on the same day another court protected a litigant's ChatGPT research as work product, and three more have since followed it; and the question everyone actually asks — what if I paste my lawyer's advice? — is still waiting for its unlucky pioneer. Until appellate courts sort the frameworks out, the practical rule is the one that was always true: privilege lives in the conversation with your lawyer, and it survives by staying there. Everything else you type is, at best, arguable work product. For everything else you ask an AI, the prudent working assumption is that it is discoverable — and the sound instinct is to prefer tools that keep no retained, name-linked server-side transcript for anyone to fight over in the first place.

Sources