PRIVILEGE IN THE AI ERA
Public AI and Attorney-Client Privilege
The first major ruling is a warning about consumer AI, not a declaration that every use of AI destroys privilege.
In United States v. Heppner, a federal district court held that a defendant’s independently created exchanges with the consumer version of Claude were protected by neither attorney-client privilege nor the work-product doctrine. The decision matters, but its boundaries matter just as much.
What the court actually decided
The defendant used the tool on his own initiative, not at counsel’s direction. The court reasoned that Claude was not an attorney, the exchanges were disclosed to a third-party platform under consumer terms that did not support confidentiality, and the documents were not prepared by or at the direction of counsel. Sharing the reports with counsel later did not retroactively make the exchange privileged.
Why public tools create avoidable risk
Privilege and a lawyer’s broader duty of confidentiality are related but distinct. Before client information enters any AI system, the firm should understand retention, training, human review, subprocessors, disclosure rights, access controls, deletion, and contractual responsibility.
- Prohibit confidential matter data in unapproved consumer AI services.
- Approve tools by use case, contract, configuration, and data classification.
- Align retrieval permissions with ethical walls and matter access.
- Document counsel direction, purpose, review, and human accountability.
- Obtain informed consent when applicable rules and risks require it.
Private does not automatically mean privileged
An enterprise contract, zero-retention configuration, or private deployment can strengthen confidentiality, but none is a privilege switch. The analysis remains fact-specific: who directed the work, why it was created, who could access it, and whether confidentiality was reasonably maintained.
References: Harvard Law Review analysis of United States v. Heppner and ABA Formal Opinion 512.
