THE CONSEQUENCE OF UNCONTROLLED AI

Can AI Become Your Liability?

United States v. Heppner began as a dispute about attorney-client privilege. Its larger lesson reaches every enterprise: information can lose legal, regulatory, or commercial protection when employees give it to an AI system without understanding where it goes.

The warning from United States v. Heppner

After receiving a grand jury subpoena, Bradley Heppner used the consumer version of Anthropic’s Claude to analyze his circumstances and develop reports about possible defense strategies. He did so independently, not at the direction of his attorney. He entered information he had learned from counsel and later shared some of the resulting material with his legal team.

When the government sought the conversations, Heppner argued that they were protected by attorney-client privilege and the work-product doctrine. The federal district court disagreed. Claude was not his lawyer, the exchanges had been made through a third-party consumer platform under terms that did not support a reasonable expectation of confidentiality, and the materials had not been prepared by or at the direction of counsel. Giving the reports to his lawyer afterward did not retroactively protect them.

The consequence was concrete: material Heppner created while developing his defense was not shielded from the government by the protections he asserted. The decision did not hold that every use of AI by a lawyer or client destroys privilege. It showed that legal protection depends on purpose, direction, access, contractual terms, and reasonable measures to preserve confidentiality.

Law firms are the canary in the coal mine

The protected interest changes by industry, but the pattern does not: an employee gives sensitive information to an external AI system before the organization has determined whether that disclosure is permitted. The organization discovers the consequence only after control of the information has been lost.

A hospital can turn convenience into a HIPAA event

A clinician copies a patient history into a public AI assistant to summarize a chart. An administrator uploads a spreadsheet containing names, diagnoses, or treatment details to generate a report. If the service receives or maintains protected health information without a permitted basis, appropriate safeguards, and a required business associate agreement, the hospital may have made an impermissible disclosure or violated the HIPAA Rules.

The consequence can include breach analysis and notification, an Office for Civil Rights investigation, corrective-action obligations, civil monetary penalties, and loss of patient trust. The problem is not that AI is inherently incompatible with healthcare. It is that shadow AI can bypass the agreements, access controls, risk analysis, and auditability that lawful processing of health information requires.

Employee data can become a GDPR violation

A manager asks an AI model to compare performance reviews. Human resources uploads employee records to draft a restructuring plan. A recruiting team sends applicant profiles, compensation history, health information, or demographic data to an API. For employees and applicants covered by GDPR, those actions are processing of personal data, even when the purpose is internal.

If the organization lacks a lawful basis, adequate transparency, data minimization, processor terms, security controls, or a valid mechanism for an international transfer, the processing may violate GDPR. The consequence can include orders to stop processing or erase data, employee claims, reputational harm, and—depending on the infringement—administrative fines reaching the greater statutory tier of up to €20 million or 4 percent of worldwide annual turnover. The fact that an employee found the tool useful does not create legal authority to disclose the data.

AI-assisted invention can put patent rights and trade secrets at risk

An engineer uploads an unreleased design, research notes, experimental results, or a technical problem to an AI service while developing an invention. AI assistance does not automatically make an invention unpatentable, but only natural persons can be named as inventors under current United States patent law. The company must be able to identify and document the human contribution to conception.

If the inventive contribution is poorly documented, the organization may face disputes over correct inventorship and the validity or enforceability of a resulting patent. If confidential technical information is disclosed under terms that allow retention, review, or reuse, the company may also weaken its claim that it took reasonable measures to protect a trade secret. Depending on where and how disclosure occurs, patent rights—particularly outside the United States—may also be jeopardized. The precise issue is not whether AI makes the work “unoriginal.” It is whether inventorship, novelty, confidentiality, and ownership can still be established.

Source code can stop being only the company’s problem

A developer pastes proprietary source code, security architecture, customer configurations, or an unreleased vulnerability into an unapproved coding assistant. Even if no public disclosure follows, the submission may breach a customer contract, software license, nondisclosure agreement, or internal security policy. It may expose credentials or give an external provider access to information the company was obligated to keep confidential.

The consequence can be contractual liability, an incident-response obligation, weakened trade-secret protection, remediation expense, or a customer relationship placed at risk. A productivity shortcut can become evidence that the organization did not control its most valuable technical assets.

Corporate strategy can compromise a transaction

An executive uploads acquisition materials, board presentations, earnings forecasts, pricing strategy, or an unreleased restructuring plan to obtain a summary. That information may be subject to an NDA, fiduciary controls, securities restrictions, or carefully timed disclosure obligations.

The consequence may be a breached confidentiality obligation, a damaged transaction, premature disclosure of market-sensitive information, regulatory scrutiny, or loss of negotiating leverage. The AI output may be useful; the undisclosed transfer of the underlying information may be far more consequential.

The remedy is an enterprise control model

A policy telling employees not to paste sensitive information into public AI is necessary, but it is not sufficient. People will use AI when it helps them work. Governance must therefore provide approved ways to obtain that value while preserving the protections attached to enterprise information.

A practical control model
  • Classify before submission. Define which legal, health, employee, financial, security, and intellectual-property data may enter each class of AI system.
  • Approve tools by use case. Evaluate contracts, retention, model training, human review, subprocessors, data location, deletion, security, and audit rights—not merely the vendor’s name.
  • Provide a governed alternative. Give employees private, enterprise-approved AI capabilities with access controls and data boundaries that reflect how the organization already protects information.
  • Preserve context and authority. Record who authorized the use, why the information was processed, which system received it, and what human review occurred.
  • Control APIs as well as chat tools. An API is not automatically private or compliant. Its configuration, contract, logging, downstream processing, and data flows must be governed.
  • Monitor for shadow AI. Combine education with technical discovery, procurement controls, incident reporting, and proportionate enforcement.
  • Assign enterprise ownership. Legal, privacy, security, technology, data, and business leaders need one operating model with accountable executive authority.

Govern the disclosure, not only the output

Most AI governance discussions focus on whether a model’s answer is accurate, biased, or explainable. Those questions matter, but the risk often begins earlier—when the prompt, document, code, or record leaves the control environment in which it was protected.

Heppner gives enterprises a useful warning. For a legal client, uncontrolled AI use may cost an asserted privilege. For a hospital, it may create HIPAA exposure. For an employer, it may become unlawful personal-data processing. For an innovator, it may place patent rights or trade secrets at risk. For an executive, it may compromise a transaction.

The governance question is therefore not simply, “May our employees use AI?” It is: What information may they give it, under whose authority, within which controlled environment, and with what evidence that the organization preserved the protection the information requires?

References: United States v. Heppner opinion; Harvard Law Review analysis; ABA Formal Opinion 512; HHS cloud-computing guidance; General Data Protection Regulation; and USPTO AI-assisted inventorship guidance.