Business Law
Federal Judge: No Attorney-Client Privilege Between Defendant and the AI Agent He Discussed Legal Strategy With
The ruling seems to indicate that people don’t have a reasonable expectation of privacy in their AI chat logs.
Author: Jonathan Simmons
At a pretrial conference held on Feb. 10, 2026, a New York federal judge orally granted the federal government’s motion for a ruling that certain written exchanges that defendant Bradley Heppner had with Claude were not protected from government inspection. In a subsequent written memorandum, U.S. District Judge Jed S. Rakoff set forth the reasons for the court’s ruling, finding that the exchanges were not protected by attorney-client privilege or the work product doctrine.
In 2025, after Heppner had received a grand jury subpoena related to his alleged misconduct as a corporate executive, and before reaching out to his attorney, he discussed a legal defense strategy with Claude. When the FBI executed a search warrant at Heppner’s home, it seized about 31 documents that memorialized Heppner’s Claude chat logs, referred to in court documents as the “AI Documents.” In court, Heppner’s lawyer asserted that the government could not review the AI Documents as Heppner “was preparing these reports in anticipation of a potential indictment.” Heppner’s lawyer conceded, however, that they “did not direct [Heppner] to run Claude searches.”
The Court’s Holdings
Ultimately, the court held the AI Documents could be reviewed by the government, as they were not protected by either the attorney-client privilege or the work product doctrine.
Attorney-client privilege protects “communications” (1) between a client and their attorney, (2) that are intended to be kept confidential, (3) for the purpose of obtaining or providing legal advice. The court held:
- First, the AI Documents are not communication between Heppner and his counsel because Heppner does not have an attorney-client relationship with Claude.
- Second, Heppner had no reasonable expectation that the AI Documents were intended to be kept confidential. Heppner agreed to Claude’s written privacy policy, which provides that Anthropic collects data on both users’ inputs and Claude’s outputs, that it uses such data to train Claude and that Anthropic reserves the right to disclose such data to third parties, including governmental regulatory authorities.
- Third, related to the first point, Heppner did not and could not communicate with Claude for the purpose of obtaining “legal advice” because Claude is not a lawyer. Whenever you ask Claude a legal question, it reminds you that it can’t provide formal legal advice and to consult a licensed attorney.
Related to but distinct from the attorney-client privilege, the work product doctrine protects materials prepared by or at the direction of counsel in anticipation of litigation or trial. As Heppner’s lawyer conceded, however, they “did not direct [Heppner] to run Claude searches.” Since the documents were not prepared by or at the direction of Heppner’s lawyer, they were not protected by the work product doctrine. The fact that Heppner later submitted the AI Documents to his lawyer did not change their status from unprotected to protected.
Next, the court rejected Heppner’s arguments that the work product doctrine is not limited to materials prepared by or at the direction of an attorney. In the court’s view, those arguments were unpersuasive and relied on non-binding precedent.
Finally, the court rejected Heppner’s arguments relying on Federal Rule of Criminal Procedure, rule 16(b)(2)(A) as inapplicable on its face. That rule provides certain protection in pretrial discovery. However, the AI Documents were seized from Heppner’s home pursuant to a valid search warrant. The government did not request them, and Heppner did not produce them, in pretrial discovery.
Implications for People and Businesses
In addition to ruling that Heppner’s AI Documents were unprotected, the court noted that even if certain information that Heppner input into Claude was privileged, he waived that privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party.
While this Second Circuit case is non-binding in California, one can see how this line of reasoning leads to the undoing of confidential information when it is processed by an AI.
For individuals, this case should chill the kinds of questions people ask their AI chatbots. For example, we now know that the alleged Palisades Fire arsonist, during a 911 call, typed a question into the ChatGPT app on his iPhone, asking, “Are you at fault if a fire is lift [sic] because of your cigarettes.”
For organizations, this case should motivate them to ask themselves questions about their AI solutions. For example, does your organization use an enterprise AI?
If not, it is safe to assume that your operative privacy policy comes close to the Claude and Anthropic policy discussed in U.S. v. Heppner. Like the defendant in Heppner, you would not have a reasonable expectation of privacy for the information you input into the system.
Consider the kinds of information you’re willing to give the AI and communicate that to your organization. The best way to start is with an AI policy. Here are a few off-the-shelf AI policies and frameworks to start: NTEN (last accessed Feb. 26, 2026); NIST AI RMF; ISO/IEC 42001.
If your organization does have an enterprise AI solution, consider outsourcing privacy policy reviews to an attorney with experience in data privacy. Additionally, begin your own diligence by asking your vendor about the AI’s data lifecycles.
The following are a few common terms to ground the discussion:
- Inference: The phase where you use the AI. When you give a prompt and the model generates an answer, that is “inference.”
- Tokens: The small chunks of text (words or parts of words) that the AI reads and writes.
- Processing: Where tokens go, who sees them and whether they are kept after the chat ends.
The following are a few common sales claims about enterprise AI and questions to help you understand how inference tokens are processed:
- Claim (Data Retention): “Your data is safe with us.”
- Question (Auto-Deletion Policy): Does the vendor store your prompt and the AI’s response on their servers? If so, how long?
- Claim (The Training Loop): “We don’t use your data for training.”
- Question 1 (Defining “Data”): Does this apply to metadata and “synthetic data” generated from our tokens?
- Question 2 (Defining “Training”): Does the vendor use your inputs to “fine-tune” or improve their model later?
- Claim (Third Parties): “It’s our proprietary model.”
- Question 1 (On-Premises v. Off-Premises): Are tokens processed on-premises, or are they sent to a third-party cloud provider (Azure, AWS, Google)?
- Question 2 (Third-Party Routing): Is the vendor using their own model, or are they just a “wrapper” for someone else? If they are a wrapper, your tokens are sent to a third party. You need to know if that party’s privacy policy matches what the vendor promised you.
- Question 3 (Human-in-the-Loop): Some companies have human reviewers to check for accuracy or safety. You need to know if a human contractor is reading your sensitive inputs.
Disclaimer: These questions do not consider whether the AI solution complies with your industry’s standards (e.g., HIPPA) or how the AI was trained (data validation).
Looking ahead to Agentic AI, we may lose any sense of privacy or security when agents are installed (see Meredith Whittaker, president of Signal Foundation, discuss this question at this year’s Davos World Economic Forum, from about the 7- to 12-minute mark). For now, the courts are crystallizing the idea that people do not have a reasonable expectation of privacy in their AI chat logs.
Jonathan is a content attorney at CEB where he works with experts in their fields to update CEB’s California law practice guides for business and intellectual property.
A version of this article previously appeared on the Continuing Education of the Bar website. © The Regents of the University of California, 2026. Reprinted with permission. Click here to learn more about CEB’s legal research and CLE products and our commitment to service the California legal community.
