Does Using AI Waive Attorney-Client Privilege? What the First Rulings Actually Say — and How to Protect It
10/10/20265 min read


Does Using AI Waive Attorney-Client Privilege? What the First Rulings Actually Say — and How to Protect It
The question is no longer hypothetical. In early 2026, federal courts began ruling on whether putting confidential information into an AI tool destroys attorney-client privilege and work-product protection — and the early answers should get every litigator's attention. The headline most coverage ran with ("AI waives privilege") is wrong, but the real rule is almost as important: it isn't the tool that creates the risk. It's the disclosure.
Here's what the first decisions actually hold, where courts are already dividing, and how to use AI without handing your opponent a discovery windfall.
The landmark: United States v. Heppner
In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York addressed what he called a question of first impression nationwide: were a criminal defendant's written exchanges with a publicly available consumer AI platform (Anthropic's Claude) protected by attorney-client privilege or the work-product doctrine? His answer was no on both counts.
The reasoning tracks settled privilege principles rather than inventing new anti-AI doctrine:
On privilege, the communications were not confidential. The defendant voluntarily entered information into a third-party platform whose terms permitted the provider to collect, retain, and in some circumstances disclose user inputs and outputs. Voluntary disclosure to a non-confidential third party generally waives the privilege — and here it meant the privilege never attached. The court also rejected the idea that privilege could be created after the fact by routing already-disclosed material through an attorney; the privilege must exist at the time of the communication.
On work product, the materials weren't prepared by or at the direction of counsel and didn't reflect counsel's strategy. The AI was not functioning as the lawyer's agent. Notably, the court observed that had the tool been used at counsel's direction as a kind of highly trained assistant, the Kovel doctrine — which extends privilege to agents who help a lawyer deliver legal advice — might have applied. It wasn't, so it didn't.
Crucially, Heppner does not hold that all AI use waives privilege, that any AI tool automatically forfeits protection, or that secure, attorney-supervised platforms can't preserve confidentiality. It reinforces the traditional requirements — confidentiality, attorney involvement, and purpose of obtaining legal advice — in a new setting.
The counterpoint: courts are already dividing on work product
Within months, a federal court in Michigan reached a different result on work product. In a decision involving a pro se plaintiff's use of generative AI, the Warner court rejected the argument that using AI tools — which it described as "tools, not persons" — waived work-product protection.
The divergence isn't random; it reflects a real doctrinal distinction. Attorney-client privilege is fragile: disclosure to almost any outside third party can waive it. The work-product doctrine is more robust: it is generally waived only by disclosure to an adversary, or in a manner that substantially increases the likelihood an adversary will obtain the material. Pasting litigation material into a public AI tool is a serious confidentiality problem, but it isn't necessarily "disclosure to an adversary" — which is why some courts will treat privilege and work product differently for the same AI interaction.
The emerging picture: expect privilege to be the more vulnerable of the two protections, and expect the law to stay unsettled while trial courts work through it.
The distinction every attorney should internalize
Put the two protections side by side. Attorney-client privilege is held by the client, protects confidential communications made to obtain legal advice, and is waived by voluntary disclosure to a non-confidential third party. Work product is held by the attorney or party, protects material prepared in anticipation of litigation, and is waived mainly by disclosure to an adversary. The same careless AI input can jeopardize both — but through different doors, and with different likelihoods.
The nuance the headlines miss: it's the channel, not the tool
The single most important takeaway from these cases is that using AI does not, by itself, waive anything. Disclosing confidential client information through an unsecured channel does. That distinction is what separates a reckless workflow from a defensible one:
A consumer-tier tool whose terms permit the vendor to use, retain, or disclose your inputs looks, to a court, like handing confidential material to a non-confidential outside party. An enterprise or attorney-directed platform — one contractually barred from training on your data or disclosing it, used under counsel's supervision as the lawyer's agent — sits much closer to the litigation-support vendors courts have long accepted under Kovel. The protections aren't guaranteed, but the waiver risk is substantially reduced.
The California layer
California attorneys operate under a statutory privilege, and the statute contains a useful hook. Under California Evidence Code section 952, a "confidential communication" between client and lawyer includes information disclosed to third persons to whom disclosure is reasonably necessary for transmitting the information or accomplishing the purpose for which the lawyer was consulted. Section 954 establishes the privilege; section 912 governs waiver by voluntary disclosure.
The practical question for AI is whether a given tool can be framed as that kind of reasonably necessary intermediary — an agent assisting the lawyer — rather than an outside party to whom the client simply volunteered confidential facts. Attorney direction, secure configuration, and contractual confidentiality are what move a tool toward the former. Unsupervised client self-help on a public chatbot is squarely the latter.
How to protect privilege and work product when using AI
Build these into your firm's standard before the next matter, not after a motion to compel:
Keep litigation-related AI use attorney-directed and documented, so an agency relationship is clear rather than assumed. Use enterprise or secure platforms whose contracts bar training on your data and third-party disclosure, and confirm data-retention and deletion terms. Never route confidential case facts through consumer-tier tools with permissive terms. Advise clients, in writing, not to discuss their case with public AI platforms — a client's own DIY AI session can be discoverable, as Heppner shows, and you can't protect what you don't control. Segregate any AI handling of privileged or work-product material to approved, secure systems. Treat understanding your tools' data terms as part of your competence obligation, not an IT afterthought.
FAQ
Does using AI automatically waive attorney-client privilege? No. Courts have been clear that the tool itself isn't the problem. The risk comes from disclosing confidential information through a channel that doesn't keep it confidential.
What did Heppner actually decide? That a criminal defendant's exchanges with a public consumer AI platform were protected by neither privilege nor work product — because voluntary disclosure to a non-confidential third party defeated confidentiality, and the tool wasn't used at counsel's direction.
Is work product treated the same as privilege here? No, and that difference matters. Work product is harder to waive — generally only by disclosure to an adversary — so some courts have declined to find work-product waiver from AI use even where privilege would fail.
Can enterprise AI tools preserve privilege? They can substantially reduce the risk. Attorney-directed use of a platform contractually barred from using or disclosing your data looks far more like a protected agent relationship than a public chatbot does. Nothing is guaranteed; the law is still developing.
What about my client using AI on their own? That's a real exposure. A client's independent exchanges with a public AI tool may be discoverable. Advise clients in writing to keep case matters off public platforms.
The protections your clients rely on were built for a world of human intermediaries, and courts are now deciding how they apply to machine ones. The firms that come out ahead will be the ones that structured their AI use to preserve privilege before a court forced the question. If you'd like help building an AI workflow that keeps confidentiality and work-product protection intact, that's exactly the kind of readiness we help attorneys put in place.