If you use ChatGPT, Claude, or any AI tool for work, whether it’s drafting documents, researching legal questions, or organizing your thoughts, a recent federal court ruling just made one thing very clear.
Your AI conversations are not private. And they can be used against you in court.
What Happened in United States v. Heppner
In February 2026, a defendant facing a federal investigation in New York used Claude Anthropic’s AI assistant to do what a lot of people do with AI:
- Analyze his legal situation
- Research potential defense strategies
- Draft arguments and organize his thinking
He later shared those AI-generated outputs with his attorney.
When the government demanded access to his entire Claude conversation history, he pushed back. He argued it was protected by attorney-client privilege, the same rule that keeps your conversations with your lawyer confidential.
The court disagreed. On every count.
Judge Jed Rakoff of the U.S. District Court for the Southern District of New York ruled that the defendant’s AI chat history was fully discoverable by the government.

Why the Court Ruled AI Chats Aren’t Privileged
The ruling came down to three principles. None of them are new law; they’re established rules applied to new technology.
1. AI Is Not Your Attorney
The attorney-client privilege protects only communications between you and a licensed attorney. Claude is not an attorney. ChatGPT is not an attorney. It doesn’t matter how legal the question was or how good the answer sounded.
If the other party in the conversation isn’t a lawyer, the privilege doesn’t apply.
2. There’s No Expectation of Privacy
This is the part that should concern every business owner.
Claude’s privacy policy, like most consumer AI tools, reserves the right to use your inputs for model training and to share data with third parties, including government authorities.
The moment you type something into a public AI tool, you’re handing your information to a third party. Legally, that breaks confidentiality. It’s no different from cc’ing a stranger on a privileged email.
3. The Defendant Acted Independently
Work product protection covers materials prepared by or at the direction of counsel. The defendant used Claude on his own, not because his lawyer asked him to. Sharing the outputs with his attorney afterward didn’t retroactively make them privileged.
The court was clear: you can’t undo the disclosure after the fact.
This Isn’t Just a Legal Problem It’s a Business Data Problem
Most coverage of this ruling focuses on lawyers and courtrooms. But think about what businesses type into AI tools every single day:
- 💼 Client names, contract details, deal terms
- 📊 Financial projections and revenue data
- 👥 Employee performance notes and HR conversations
- 🔒 Internal strategy documents and competitive analysis
- 📋 Compliance-related questions and audit prep
All of that data now sits on someone else’s servers. And if any of it becomes relevant to a lawsuit, an investigation, or a regulatory audit, a court has now confirmed it’s fair game.
Consumer AI vs. Enterprise AI: The Distinction That Matters
The Heppner ruling specifically cited Claude’s consumer privacy policy as a reason the data wasn’t protected. An enterprise agreement with different data-handling terms could change the legal analysis.
Here’s the difference:
Consumer AI (Free / Personal) | Enterprise AI (Business License) | |
Data used for training? | ✅ Yes, your inputs may train the model | ❌ No, data isolation guaranteed |
Shared with third parties? | ✅ Yes, per the privacy policy | ❌ No, contractual data protections |
Expectation of privacy? | ❌ None; court confirmed this | ✅ Possible, depends on agreement |
Discoverable in court? | ✅ Yes, Heppner ruling confirms | ⚠️ Potentially defensible, not tested yet |
Suitable for sensitive data? | ❌ No | ✅ With proper configuration |

What You Should Do Right Now
1. Find out what your team is putting into AI
Most businesses have zero visibility into this. People use ChatGPT on personal phones. Teams paste client data into Claude to “speed things up.” Start by understanding which tools are in use and what data is going in.
2. Create a simple AI use policy
It doesn’t need to be a 40-page document. Three rules cover most of it:
- Don’t put confidential, privileged, or client-identifiable information into consumer AI tools
- Do use enterprise-grade AI platforms with proper data controls for sensitive work
- When in doubt, ask before you paste
3. Use enterprise AI tools, not consumer ones
The ruling cited Claude’s consumer privacy policy as the reason confidentiality was broken. Enterprise agreements with vendors like Microsoft (Copilot for Business), OpenAI (ChatGPT Enterprise), and Anthropic (Claude for Business) offer contractual data isolation, meaning your inputs aren’t stored, trained on, or shared.
That distinction matters legally. It mattered in this case.
4. Talk to your attorney now, not later
If your business handles sensitive data client records, financials, health information, legal strategy have a conversation with your legal counsel about AI use before it becomes an issue in discovery.
FAQ Section
Q: Does attorney-client privilege apply to AI conversations?
A: No. A U.S. federal court ruled in United States v. Heppner (February 2026) that conversations with AI tools like Claude and ChatGPT are not protected by attorney-client privilege because AI is not a licensed attorney, and public AI platforms don’t provide a reasonable expectation of privacy.
Q: Can AI chat history be subpoenaed in court?
A: Yes. The Heppner ruling confirmed that a defendant’s entire AI conversation history was discoverable by the government. Courts treat AI chat logs as electronic records subject to standard discovery rules.
Q: Is enterprise AI safer than consumer AI for legal purposes?
A: Potentially, yes. The Heppner ruling specifically cited the consumer privacy policy of Claude as a reason for the lack of confidentiality. Enterprise AI agreements often include data isolation and contractual privacy protections that could change the legal analysis, though this hasn’t been directly tested in court yet.
Level 5 Management provides IT services for law firms across South Florida and helps businesses implement secure, enterprise-grade technology including AI governance, data protection, and compliance-aligned infrastructure. If your team is using AI and you’re not sure where your data is going, let’s talk.


