home  /  insights  /  is-a-chatgpt-conversation-privileged
Confidentiality & Security

Is what you type into a consumer AI chatbot privileged?

In February 2026 a federal judge in the Southern District of New York said no, and the reasoning turned partly on the provider’s own privacy policy. A different court had reached the opposite result a week earlier on different facts. The distinction between them is the thing to understand.

September 4, 2026 · 5 min read

The short answer

Not reliably, and on consumer-grade tools a court has now said not at all. In United States v. Heppner (S.D.N.Y., Judge Rakoff, written opinion 17 February 2026), 31 documents a defendant generated through exchanges with a consumer AI chatbot were held protected by neither attorney-client privilege nor work product, partly because the provider’s own privacy policy defeated any reasonable expectation of confidentiality. But a blanket rule has not emerged: in Warner v. Gilbarco, Inc. (E.D. Mich., 10 February 2026) AI-assisted internal analysis and drafting was held protected work product. The operative variables are who prompted, at whose direction, and on what retention terms — which means the deployment decision is now a privilege decision.

What this article establishes

  • A court has held that consumer-grade AI exchanges were neither privileged nor work product, and one of its two stated reasons was the provider’s published privacy policy.
  • That ruling is not a blanket rule. A separate February 2026 decision protected AI-assisted work product, and by spring 2026 courts were doing fact-specific analysis rather than applying a categorical bar.
  • The variables that appear to matter are who did the prompting, whether it was at counsel’s direction, and what the retention and training terms were.
  • The practical consequence is architectural: the tier and terms a firm deploys on are now part of the privilege analysis rather than a procurement preference.

Has a court actually ruled that AI chatbot conversations are not privileged?

Yes. In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y.), Judge Rakoff ruled orally on 10 February 2026 and issued a written opinion on 17 February 2026 holding that 31 documents a defendant generated through exchanges with a consumer generative-AI chatbot were protected by neither the attorney-client privilege nor the work-product doctrine.

The reasoning had two distinct teeth, and they are worth separating because they do different work. The first is categorical and blunt: the AI system is not an attorney, which on its own disposed of the attorney-client privilege claim. The second is the one with wider consequences for firms, because it does not depend on who was doing the typing.

Why did the provider’s privacy policy matter to the privilege analysis?

Because a privilege claim requires a reasonable expectation of confidentiality, and the court in United States v. Heppner read the provider’s published terms as defeating one. The policy described collecting inputs and outputs, using them for training, and reserving the right to disclose to third parties including governmental regulatory authorities.

That is the part firms should sit with. The document that undermined the confidentiality expectation was not a leaked internal memo or an adversary’s discovery request. It was the vendor’s own public policy, available to anyone before the tool was ever used. A term a firm never read still described what the firm had agreed to.

It also means the analysis is portable. Any tool whose published terms describe training on inputs or disclosure to third parties invites the same argument, whatever the brand on it.

Does this mean any use of AI waives privilege?

No, and reading it that way would be a serious over-correction. In Warner v. Gilbarco, Inc. (E.D. Mich., 10 February 2026) a court denied a motion to compel into a party’s litigation-related generative-AI use, treating AI-assisted internal analysis and drafting as protected work product and holding that using a general-purpose AI tool did not waive protection absent disclosure to an adversary. In Tremblay v. OpenAI (N.D. Cal.), attorney-crafted prompts testing legal theories were treated as opinion work product.

By spring 2026 courts had declined to adopt a blanket Heppner rule in favour of fact-specific analysis. Two decisions eight days apart in February 2026 came out differently, which tells you the doctrine is being built case by case rather than announced.

What actually distinguishes the protected uses from the unprotected one?

Three variables recur across the decisions: who did the prompting, whether it was done at counsel’s direction, and what the retention and training terms of the tool were. United States v. Heppner involved a party using a consumer tool on his own initiative under consumer terms. Warner v. Gilbarco, Inc. and Tremblay v. OpenAI involved litigation-related work sitting inside an attorney’s direction.

The older authorities being marshalled around these questions are the familiar ones — Kovel, 296 F.2d 918 (2d Cir. 1961) on agents assisting counsel, and Monterey Bay Military Housing v. Ambac (S.D.N.Y., 19 January 2023). The novelty in 2026 is not the framework. It is that a vendor’s terms of service are now an evidentiary fact inside it.

What should a firm change about how it deploys AI in response?

Treat the deployment decision as a privilege decision rather than a procurement preference, which mostly means knowing which tier every attorney is actually on. The distinction the courts are drawing runs along consumer-versus-enterprise terms, and that boundary sits inside a firm’s own subscription choices.

Two practical consequences follow. A partner expensing a personal consumer subscription is making an architectural decision on the firm’s behalf, usually without knowing it. And a firm that blocks AI without provisioning a sanctioned alternative tends to move the usage onto personal devices, where the terms are consumer terms and the firm has no visibility at all.

The Institute’s Confidentiality & Security area covers the diligence side of this, and Tool Selection & Evaluation covers how the tiers differ in practice.

What is still unsettled about AI and privilege?

A great deal, and as of September 2026 the honest answer is that no stable rule has emerged. No court has squarely held that using an enterprise-tier tool under a no-training contract preserves privilege, and no court has squarely held that it waives it. That is a live argument, not a settled rule.

What can be said with confidence is narrower and still useful: a court has now treated a provider’s published retention and training terms as material to whether an expectation of confidentiality was reasonable. A firm that cannot say what its own terms provide cannot make the argument either way.

For informational purposes only. Not legal advice and not ethics advice. Professional conduct rules are adopted state by state and diverge, and this record changes monthly. Anything here that reads as a holding should be checked against your own jurisdiction before it is relied on.

Related

The practice area

AI adoption conciergeorientation · not legal or ethics advice
Happy to. Tell me roughly how big the firm is and what it already pays for — Microsoft 365, Google Workspace, a practice-management system — because the honest answer to most AI questions at a firm your size starts with what you have already bought rather than what you should go and buy.