LawCurate
Law as Thought, Law as Structure
Documents generated through a public AI chatbot are not protected by attorney-client privilege: United States v. Heppner

The decision in United States v. Heppner, No. 25 Cr. 503 (S.D.N.Y.), delivered by Judge Jed S. Rakoff on February 10, 2026, and supplemented by a written memorandum on February 17, 2026, addresses a question that no court in any jurisdiction had previously been called upon to decide.

The ruling is of particular interest because the defendant did not use AI casually. He used it deliberately, after hiring lawyers, to prepare his legal defence.

He fed information he had received from his lawyers into the chatbot, generated strategy documents, and shared those documents with his legal team. The court held that none of this attracted privilege. Judge Rakoff noted in his opinion that, “the implications of AI for the law are only beginning to be explored.”

The prosecution against Bradley Heppner

The underlying case involves serious financial crime allegations. Bradley Heppner served as the chairman and chief executive officer of GWG Holdings, Inc., a publicly traded financial services company based in the United States. On October 28, 2025, a federal grand jury returned a five-count indictment against him.

The charges include securities fraud, wire fraud, conspiracy to commit securities and wire fraud, making false statements to auditors, and falsification of corporate records.

The prosecution’s case, as set out in the indictment, is that Heppner and others orchestrated a scheme to fraudulently extract funds from GWG Holdings through a shell entity he controlled, the Highland Consolidated Limited Partnership.

Heppner was arrested on November 4, 2025 in Texas. The case is assigned to Judge Jed S. Rakoff and is scheduled for trial in April 2026. The privilege dispute that produced this ruling arose not from the fraud charges themselves, but from what was found on Heppner’s electronic devices at the time of his arrest.

How the AI documents came into existence

The sequence of events is important. Heppner first became aware that he was the target of a federal investigation when he received a grand jury subpoena. He engaged defence counsel. It was after this point, while represented by lawyers but before his arrest, that he began using Claude, a generative AI chatbot developed by Anthropic.

The version of Claude that Heppner used was the consumer version, which is the standard publicly available product. It was not an enterprise version with enhanced confidentiality protections. Heppner used the chatbot on his own initiative. His lawyers did not instruct him to do so. Defence counsel later conceded in court that they “did not direct Heppner to run Claude searches.”

Over the course of his interactions with Claude, Heppner input information that he had received from his lawyers. He used the chatbot to prepare reports that, in the words of defence counsel at the pre-trial conference, “outlined defence strategy, outlined what he might argue with respect to the facts and the law.” He generated approximately 31 such documents and subsequently shared them with his legal team.

When FBI agents executed a search warrant at Heppner’s residence upon his arrest, they seized several electronic devices. These devices contained the 31 AI-generated documents. Heppner’s lawyers claimed that the documents were protected by attorney-client privilege and the work product doctrine, and asked that they be segregated from the prosecution team’s review.

The Government initially agreed to the segregation but then filed a motion on February 6, 2026, seeking a ruling that neither privilege nor work product protection applied to the documents.

The attorney-client privilege analysis

Attorney-client privilege is the legal doctrine that protects confidential communications between a lawyer and their client from compelled disclosure.

The doctrine exists to enable clients to communicate with their lawyers without reservation, on the understanding that what they say will not be revealed to adverse parties or to the court. It is recognised in virtually every common law jurisdiction, including India.

In the United States, three conditions must be met for the privilege to attach.

The communication must be between a client and an attorney.

It must be intended to be, and must in fact have been kept, confidential.

And it must be made for the purpose of obtaining or providing legal advice. If any one of these conditions is absent, the privilege does not apply.

Judge Rakoff held that the 31 AI-generated documents failed on at least two of these three conditions, and possibly all three.

On the first condition, the court held that the communications were not between Heppner and his attorney. Claude is not an attorney. It holds no law licence, it owes no fiduciary duties to users, and it is not subject to professional discipline.

Judge Rakoff observed that every recognised form of privilege depends upon what he described as “a trusting human relationship” with “a licensed professional who owes fiduciary duties and is subject to discipline.” No such relationship is capable of existing between a person and an AI platform.

The Government drew a comparison that the court found persuasive: a person who discusses legal matters with a friend may find the conversation useful, but the conversation is not privileged. The same applies to a conversation with a chatbot.

On the second condition, the court held that the communications were not confidential. This aspect of the ruling rests on the specific terms under which Claude operates. Anthropic’s privacy policy, which users must accept in order to use the platform, states that the company collects data on user inputs and the chatbot’s outputs.

The policy further provides that the collected data may be used to train the AI model and that Anthropic reserves the right to disclose user data to third parties, including governmental regulatory authorities. Judge Rakoff held that, given these terms, Heppner could have had “no reasonable expectation of confidentiality” in his communications with Claude.

The court also drew a distinction between these AI documents and the confidential notes a client might make in preparation for a meeting with their lawyer. Such notes, if kept private, may be protected.

In Heppner’s case, however, the client did not keep the information private. He shared it first with a commercial AI platform operated by a third-party company, and only afterwards with his lawyers.

Sending documents that are not privileged to a lawyer after the fact does not, under well-settled law, retroactively make them privileged.

On the third condition, the court examined whether Heppner used Claude for the purpose of obtaining legal advice. The Government submitted evidence on this point by asking Claude directly whether it could provide legal advice.

The chatbot responded that it is not a lawyer and cannot provide formal legal advice, and recommended that users consult a qualified attorney.

Judge Rakoff held that what matters is whether the user sought legal advice from the entity to which the communication was directed. Heppner communicated with Claude, not with his lawyer. Claude disclaims any capacity to give legal advice.

The fact that Heppner later shared the output with counsel did not convert the original communication into one made for the purpose of obtaining legal advice.

The work product doctrine and its limits

The work product doctrine is a separate protection from attorney-client privilege. It shields materials that have been prepared by a lawyer, or at a lawyer’s direction, in anticipation of litigation.

The purpose of the doctrine is to protect the lawyer’s thought process, strategy, and mental impressions from being accessed by the opposing side.

Heppner’s lawyers argued that the 31 documents fell within this doctrine because they were prepared in anticipation of a potential indictment and reflected legal strategy. The court rejected this argument.

Defence counsel had conceded that Heppner prepared the documents on his own initiative, not at the direction of his lawyers. The court held that because neither Heppner nor the chatbot is legal counsel, and because Heppner was not acting at his lawyer’s behest, the doctrine did not apply.

The documents did not reflect the legal strategy or mental impressions of Heppner’s defence counsel at the time they were created. Even if counsel later used these materials to shape strategy, that did not retroactively bring the original documents within the scope of the protection.

The question Judge Rakoff left open

One observation in the ruling has attracted particular attention. Judge Rakoff stated that, “had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.”

This observation draws on a doctrine known as the Kovel doctrine, which takes its name from the 1961 decision of the US Court of Appeals for the Second Circuit in United States v. Kovel.

Under the Kovel doctrine, attorney-client privilege can extend beyond the lawyer to include third parties whose assistance is necessary for the lawyer to provide effective legal representation.

The classic examples are accountants, translators, and forensic experts retained by the lawyer to help understand a client’s affairs.

For the Kovel doctrine to apply, the third party must be acting at the direction of counsel and must be bound by obligations of confidentiality.

The court did not decide whether an AI platform could ever qualify as such an agent. It left that question for another day and another set of facts. The implication, however, is that if a lawyer were to direct a client to use an enterprise-grade AI tool with contractual confidentiality protections, the analysis could be different.

The waiver problem

There is a further dimension to the ruling that has caused concern among practitioners. Heppner did not simply ask Claude general questions about the law. He input information that his lawyers had shared with him, information that was itself privileged.

The Government argued, and the court agreed, that by sharing privileged communications with a third-party AI platform, Heppner may have waived the privilege over the original attorney-client communications as well.

This is a well-established principle. Privilege belongs to the client, but so does the responsibility to maintain it. If a client voluntarily discloses privileged information to a third party without any obligation of confidentiality, the privilege may be lost, not only over the disclosure itself but over the underlying communication.

Judge Rakoff also flagged a practical complication that may arise at trial. Because the AI documents incorporate information that counsel conveyed to Heppner, the Government’s use of those documents could require Heppner’s lawyers to testify about what they told their client.

This creates a potential witness-advocate conflict, a situation where the lawyer is simultaneously acting as both advocate and witness, which is prohibited under professional conduct rules. The court observed that the Government’s victory on the privilege question does not make the evidentiary picture simple.

How the ruling has been received

The decision has generated extensive analysis across the US legal profession. The Harvard Law Review, in a blog post published days after the written opinion, offered a detailed critique. The Review argues that the court’s reasoning “veers toward categorically excluding a client’s use of generative AI from attorney-client privilege.”

A more appropriate approach, the Review contends, would have been a fact-dependent inquiry into whether the client had a reasonable expectation of confidentiality, rather than the court’s reliance on what is technically possible under the AI platform’s terms of service.

The Harvard analysis also identifies two practical problems with the court’s approach. First, the ruling disempowers clients relative to their lawyers by effectively requiring that all use of AI in legal matters be initiated by counsel. Second, the ruling invites what the Review calls “performative adherence to formalities,” where lawyers could simply have clients sign pre-drafted declarations stating that any future AI use is at counsel’s direction, creating a fictional basis for privilege.

Several prominent US law firms have published analyses noting that the ruling is confined to its specific facts. The defendant used a consumer-grade tool. He acted without attorney direction. The platform’s privacy policy disclaimed confidentiality.

Whether the same result would follow where an enterprise-grade AI tool with contractual confidentiality protections is used at the direction of counsel is a question the ruling expressly leaves open.

The Indian position: a gap in the law

Indian law recognises attorney-client privilege, but the framework differs in structure and scope from the US position. The relevant provisions are now contained in the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which replaced the Indian Evidence Act, 1872. The BSA came into effect on 1 July 2024.

Section 132 of the BSA is the primary provision governing privileged communications between advocates and their clients. It provides that no advocate shall, at any time, be permitted to disclose any communication made to him in the course and for the purpose of his service as such advocate, by or on behalf of his client, unless the client gives express consent.

The protection extends to the contents of documents that come to the advocate’s knowledge during professional service and to any advice given by the advocate. The obligation of confidentiality continues even after the professional relationship has ended and extends to interpreters, clerks, and employees of the advocate.

Section 134 supplements this by providing that no person shall be compelled to disclose to the court any confidential communication made between that person and their legal adviser, unless the person offers himself as a witness.

There are two exceptions under section 132. Communications made in furtherance of an illegal purpose are not protected. And any fact observed by an advocate during the course of service showing that a crime or fraud has been committed since the commencement of the engagement is also not protected.

The Indian framework differs from the US framework in one important respect that is relevant to the Heppner analysis.

Under Indian law, the privilege in section 132 operates as a restriction on the advocate. It is the advocate who is barred from disclosing client communications.

Under section 134, the client is protected from disclosing any confidential information discussed between him and this legal adviser, to the Court. The Indian provisions do not contain an explicit doctrine equivalent to the US concept of privilege waiver through voluntary disclosure to a third party, though Indian courts have applied similar principles in practice.

The question that Heppner poses for Indian law is this: if a client in India were to input privileged information into a consumer-grade AI chatbot, would that constitute a waiver of the protection under section 132 and section 134 of the BSA?

The BSA does not address AI platforms at all. No Indian court has ruled on the question, yet.

But the underlying principles point in a direction that is broadly consistent with Judge Rakoff’s reasoning.

Privilege under section 132 protects communications made “in the course and for the purpose of” the advocate’s service. A communication made by a client to an AI chatbot is not a communication made to an advocate or in the course of the advocate’s service.

An AI chatbot does not fall within the categories of persons covered by section 132, which extends only to advocates, their interpreters, clerks, and employees.

The position under the Digital Personal Data Protection Act, 2023 (DPDPA) adds a further layer.

AI platforms operating in India, or targeting Indian users, are data fiduciaries under the DPDPA. They are required to process personal data only for lawful purposes and with explicit consent.

However, the DPDPA does not create a privilege. It governs data processing obligations, not the evidentiary status of communications.

A client who consents to an AI platform’s terms of service, which typically permit data retention and model training, would find it difficult to argue that the communication was made in confidence within the meaning of section 134 of the BSA.

The Bar Council of India Rules, framed under the Advocates Act, 1961, impose duties of confidentiality on advocates.

Rule 17 of the BCI Rules of Professional Standards provides that an advocate shall not, directly or indirectly, disclose communications made by a client.

However, these rules bind the advocate, not the client. They do not prevent the client from disclosing privileged information to third parties on their own initiative.

If a client in India were to share privileged information with a public AI platform, the advocate’s obligations under the BCI Rules would remain intact, but the privilege itself may no longer subsist if the underlying information has already been disclosed to a third party outside the scope of the professional relationship.

Indian courts have not yet been confronted with this question. But as AI tools become routine in legal practice and in the daily lives of clients, a Heppner-type dispute in India is not a matter of if, but when.

The BSA, the DPDPA, and the BCI Rules will need to be read together when that question arrives, and the absence of any express provision dealing with AI-mediated communications will require courts to apply existing principles of confidentiality and waiver to a technological context that the legislature did not foresee.

Leave a Reply