Federal Court Ruling: AI Is Not Your Lawyer

March 18, 2026

Written by Tricia Dunlap

Tricia’s expertise centers on corporate law. She helps companies and individuals navigate: fiduciary duties, shareholder rights and corresponding corporate obligations, boards of director decision-making or conflict issues, and corporate officer responsibilities.

Executive Summary

A recent federal court decision delivers a clear warning for anyone using generative AI tools such as ChatGPT or Claude: a public AI platform is not part of your legal team. If you enter sensitive legal information into a consumer AI system, a court may treat that communication as if it were shared with a third party.

In United States v. Heppner, a federal judge ruled that documents created through a defendant’s conversations with an AI platform were not protected by attorney-client privilege or the work product doctrine. That allowed the government to review the materials and potentially use them in the prosecution.

The case highlights an emerging legal risk for businesses and individuals that rely on AI tools to analyze legal or strategic issues.

The Heppner Rule:

When a client independently shares legal information with a public generative AI platform, those communications may be treated as disclosures to a third party and are not protected by attorney-client privilege or the work product doctrine.

The Problem: Businesses Are Using AI to Think Through Legal Problems

Generative AI is rapidly becoming part of everyday life and business operations. People now routinely turn to AI tools to:

  • analyze problems
  • draft documents
  • summarize information
  • test arguments or ideas

In fact, Judge Jed Rakoff noted in the decision that ChatGPT alone is used by hundreds of millions of people each week.

But the legal system still operates on rules that were developed long before AI existed. Those rules depend heavily on confidentiality. When sensitive information is shared with a third party, important legal protections can disappear.

That is exactly what happened in the Heppner case.

What Happened in United States v. Heppner

Daniel Heppner was charged in federal court with securities fraud and related offenses. After learning he was under investigation and after receiving a grand jury subpoena, Heppner began using Anthropic’s generative AI platform, Claude. He entered detailed information about the facts of his situation and asked the AI system to analyze:

  • possible defenses
  • legal theories
  • potential strategies

The platform generated written reports discussing those issues. Heppner later shared the AI-generated reports with his attorney. However, an important fact shaped the outcome of the case:

His attorney had not instructed him to use the AI platform and did not supervise the process. Heppner chose to use the public AI tool on his own.

During the investigation, federal agents searched Heppner’s home and seized the AI-generated documents. His legal team argued the materials were protected by:

  • attorney-client privilege
  • the work product doctrine

The court disagreed.

The Court’s Legal Analysis

Judge Rakoff ruled that the documents were not protected by either doctrine.

Attorney–Client Privilege

Attorney-client privilege protects confidential communications between a lawyer and a client when the purpose of the communication is to obtain legal advice.

The protection depends on two key elements:

  1. The communication must be with an attorney (or the attorney’s agent).
  2. The communication must be confidential.

The court found that neither condition was satisfied.

Heppner’s communications were with a public AI platform operated by a third-party company, not with a lawyer.

Because of that, the court concluded it was unreasonable for Heppner to expect the communications to remain confidential.

As a result, attorney-client privilege did not apply.

Work Product Doctrine

The work product doctrine protects materials prepared by:

  • a lawyer, or
  • someone working at the direction of a lawyer

when the materials are created in anticipation of litigation.

This rule protects legal strategy and analysis from disclosure. However, the court found that Heppner created the AI-generated documents on his own initiative, not at the direction of his attorney. Because the work was not supervised by counsel, it did not qualify as protected work product.

An Important Distinction in the Opinion

Judge Rakoff made an important observation that lawyers and businesses should note. The analysis might have been different if:

  • the lawyer had directed the client to use the AI system, or
  • the lawyer had used the AI platform as part of preparing the case.

In that situation, the AI platform might arguably function as an assistant to the attorney, similar to:

  • a paralegal
  • an investigator
  • an expert consultant

If an AI system were used in that way, the privilege analysis could potentially change. But that was not the situation in Heppner’s case. He used the consumer AI tool independently, outside the supervision of counsel.

Why This Matters for Businesses

Generative AI is now embedded in everyday decision-making.

Only three years after its release, [ChatGPT] is being used by more than 800 million people worldwide every week.

~ Judge Rakoff, U.S. v. Heppner

Executives and employees increasingly use AI tools to think through complex issues, including legal questions. The Heppner decision underscores an important legal reality:

Consumer AI platforms are not part of the confidential attorney–client relationship.

If sensitive information about a dispute, investigation, or legal risk is entered into a public AI platform, a court may treat that information as having been shared with a third party. That can destroy the confidentiality that normally protects communications with your lawyer.

Why This Decision Matters Now

Generative AI is no longer an emerging technology. It is already embedded in daily work and decision making. Business owners, executives, and employees increasingly use AI tools to analyze problems, draft documents, and test ideas. The Heppner decision shows how quickly those everyday habits can collide with longstanding legal doctrines that depend on confidentiality. As AI becomes part of normal business workflow, courts will continue to define where the boundaries of privilege and confidentiality lie.

Key Practical Takeaways:

A public AI platform is not your lawyer and is not automatically part of your legal team. If sensitive legal information is entered into a consumer AI system, a court may treat that communication as having been shared with a third party.

Until courts provide clearer guidance, businesses should treat consumer AI platforms cautiously when legal issues are involved.

As a general rule:

  • Do not enter sensitive legal information into public AI platforms.
  • Do not use consumer AI tools to analyze disputes or investigations.
  • Do not upload confidential documents related to legal matters.
  • Speak with your attorney before using AI tools in connection with legal issues.

Generative AI will almost certainly become a powerful tool in legal work. But for now, courts are signaling that public AI platforms are not automatically part of your legal team.

This material is for informational purposes only. It is not intended as legal advice and does not create an attorney-client relationship between its readers and Dunlap Law. Consult an attorney before taking action on issues outlined here. This is attorney ADVERTISING MATERIAL.

FREQUENTLY ASKED QUESTIONS:

Can communications with AI ever be protected by attorney-client privilege?

Possibly. If the AI tool is used by an attorney, or at the direction of an attorney, the tool might function as an assistant to the lawyer. Courts have not fully resolved this issue yet.

Does this decision apply only to criminal cases?

No. The reasoning could apply in civil litigation, regulatory investigations, and other disputes where discovery rules allow access to relevant documents.

Does using ChatGPT automatically waive privilege?

Not automatically. But entering sensitive legal information into a public AI platform can create a serious risk that the communication will be treated as non-confidential.