Has a court actually ruled that AI chatbot conversations are not privileged?
Yes. In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y.), Judge Rakoff ruled orally on 10 February 2026 and issued a written opinion on 17 February 2026 holding that 31 documents a defendant generated through exchanges with a consumer generative-AI chatbot were protected by neither the attorney-client privilege nor the work-product doctrine.
The reasoning had two distinct teeth, and they are worth separating because they do different work. The first is categorical and blunt: the AI system is not an attorney, which on its own disposed of the attorney-client privilege claim. The second is the one with wider consequences for firms, because it does not depend on who was doing the typing.
Why did the provider’s privacy policy matter to the privilege analysis?
Because a privilege claim requires a reasonable expectation of confidentiality, and the court in United States v. Heppner read the provider’s published terms as defeating one. The policy described collecting inputs and outputs, using them for training, and reserving the right to disclose to third parties including governmental regulatory authorities.
That is the part firms should sit with. The document that undermined the confidentiality expectation was not a leaked internal memo or an adversary’s discovery request. It was the vendor’s own public policy, available to anyone before the tool was ever used. A term a firm never read still described what the firm had agreed to.
It also means the analysis is portable. Any tool whose published terms describe training on inputs or disclosure to third parties invites the same argument, whatever the brand on it.
Does this mean any use of AI waives privilege?
No, and reading it that way would be a serious over-correction. In Warner v. Gilbarco, Inc. (E.D. Mich., 10 February 2026) a court denied a motion to compel into a party’s litigation-related generative-AI use, treating AI-assisted internal analysis and drafting as protected work product and holding that using a general-purpose AI tool did not waive protection absent disclosure to an adversary. In Tremblay v. OpenAI (N.D. Cal.), attorney-crafted prompts testing legal theories were treated as opinion work product.
By spring 2026 courts had declined to adopt a blanket Heppner rule in favour of fact-specific analysis. Two decisions eight days apart in February 2026 came out differently, which tells you the doctrine is being built case by case rather than announced.
What actually distinguishes the protected uses from the unprotected one?
Three variables recur across the decisions: who did the prompting, whether it was done at counsel’s direction, and what the retention and training terms of the tool were. United States v. Heppner involved a party using a consumer tool on his own initiative under consumer terms. Warner v. Gilbarco, Inc. and Tremblay v. OpenAI involved litigation-related work sitting inside an attorney’s direction.
The older authorities being marshalled around these questions are the familiar ones — Kovel, 296 F.2d 918 (2d Cir. 1961) on agents assisting counsel, and Monterey Bay Military Housing v. Ambac (S.D.N.Y., 19 January 2023). The novelty in 2026 is not the framework. It is that a vendor’s terms of service are now an evidentiary fact inside it.
What should a firm change about how it deploys AI in response?
Treat the deployment decision as a privilege decision rather than a procurement preference, which mostly means knowing which tier every attorney is actually on. The distinction the courts are drawing runs along consumer-versus-enterprise terms, and that boundary sits inside a firm’s own subscription choices.
Two practical consequences follow. A partner expensing a personal consumer subscription is making an architectural decision on the firm’s behalf, usually without knowing it. And a firm that blocks AI without provisioning a sanctioned alternative tends to move the usage onto personal devices, where the terms are consumer terms and the firm has no visibility at all.
The Institute’s Confidentiality & Security area covers the diligence side of this, and Tool Selection & Evaluation covers how the tiers differ in practice.
What is still unsettled about AI and privilege?
A great deal, and as of September 2026 the honest answer is that no stable rule has emerged. No court has squarely held that using an enterprise-tier tool under a no-training contract preserves privilege, and no court has squarely held that it waives it. That is a live argument, not a settled rule.
What can be said with confidence is narrower and still useful: a court has now treated a provider’s published retention and training terms as material to whether an expectation of confidentiality was reasonable. A firm that cannot say what its own terms provide cannot make the argument either way.