US v. Heppner: What It Means for Law Firms Using ChatGPT or Claude
Short answer: On February 10, 2026, Judge Jed S. Rakoff of the U.S. District Court for the Southern District of New York ruled that documents defendant Bradley Heppner created by prompting Anthropic's Claude, then shared with his lawyers, were not protected by attorney-client privilege or the work-product doctrine. It is the first ruling to hold that prompts to a public, consumer-facing AI tool are not privileged simply because the user later hands the output to counsel. The court left open that a private, self-hosted AI system — one where inputs never reach a third party — could reach a different result.
> What actually happened
Bradley Heppner, an executive charged in the Southern District of New York with securities and wire fraud, generated 31 documents by querying Claude and later shared them with his defense lawyers. Prosecutors sought the documents; Heppner's team argued they were privileged. Judge Rakoff disagreed, on three separate grounds:
-
No attorney-client relationship exists with the AI tool itself. The court noted that Claude "is not an attorney," and that no attorney-client relationship "exists, or could exist, between an AI user and a platform such as Claude." Talking to a chatbot is not the same as talking to counsel, however the output is later used.
-
The communications were not confidential. Anthropic's own privacy policy — like that of every major consumer AI product — discloses that user inputs may be used to improve the service and may be disclosed to third parties, including regulators. Privilege requires a reasonable expectation of confidentiality; a policy that discloses third-party access defeats that expectation before the conversation even starts.
-
The work-product doctrine did not apply either, because Heppner's prompts to Claude were not made at the direction of counsel — he was talking to a general-purpose consumer product on his own initiative, not using a tool his lawyers had deployed as part of preparing his defense.
> Why this is bigger than one case
The reasoning is not specific to Claude, and it is not specific to Heppner's facts. It applies to any lawyer or client who runs case-relevant material — draft pleadings, client communications, litigation strategy, deposition prep — through a consumer AI product whose terms of service disclose data to a vendor. That covers the default consumer tier of essentially every major AI assistant. Multiple law firms (McDermott, Akin, O'Melveny, Brooks Pierce) issued client alerts within weeks of the ruling flagging the same exposure for their own clients.
Two things the ruling does not say are worth being precise about, because they get flattened in hallway summaries:
- It does not say AI tools can never be used in privileged work. It says a public, consumer-facing tool with a data-disclosing privacy policy, used without counsel's direction, breaks two of the three legs privilege normally stands on.
- It does not resolve what happens with an enterprise AI tier that has a signed data processing agreement. Judge Rakoff's opinion focused on the consumer product Heppner actually used — but the underlying test (confidentiality, attorney direction, and whether a genuine attorney-client relationship exists) applies just as directly to any architecture where a third party retains technical or legal access to the inputs.
> What actually changes the analysis
The opinion's own logic points to the variable that matters: who can access the input, under what legal authority, and at whose direction. A privately hosted AI system — one running on hardware the firm controls, with no vendor able to access, retain, or be compelled to disclose the underlying prompts — does not have the third-party-disclosure problem that broke privilege in Heppner. That is an architectural question, not a marketing claim, and it is worth firms asking their AI vendor directly: can you, technically and contractually, access or be compelled to produce what my lawyers typed into this tool? If the answer is yes, Heppner is now a documented risk on the table, not a hypothetical.
> Sources
- United States v. Heppner — Harvard Law Review Blog
- Using AI Without Waiving Privilege: Lessons from Heppner — McDermott Will & Emery
- SDNY Rules Communications With a Public Generative AI Platform Are Not Protected by Privilege — Akin
- S.D.N.Y. First-of-its-Kind Ruling: AI-Generated Documents Are Not Privileged — O'Melveny
AI IBIZA builds private AI systems that run on hardware law firms own, with no third-party vendor able to access, retain, or be compelled to disclose client prompts. See Private AI for Law Firms.