Warning: Your AI Chat Is Not Privileged and It Probably Doesn’t Help That Much

We have all heard the old classic story – dumb criminal busted after googling “how to hide a body.”

AI chatbots create the same problem, but far worse. A chatbot does not just record the question. It often collects the whole story. It asks follow-up questions. It tests weaknesses. It asks the user to explain motives, documents, timelines, and bad facts. By the end, the person may have created a clean transcript of the very admissions the other side wants most.

That is why AI-generated “case briefs” from prospective clients create a serious problem. The memo itself may be marginally useful. Sometimes it gives counsel a decent starting point. But more often when I get these from a prospective client, they identify a long list of issues that do not matter much. But the memo is not the main danger. I can sort through that pretty easily. The danger is the conversation behind it.

In February 2026, the Southern District of New York gave that problem a sharp legal edge. In United States v. Heppner,[1] Judge Jed S. Rakoff held that written exchanges between a criminal defendant and Anthropic’s Claude platform were not protected by the attorney-client privilege or the work product doctrine. Commentators described the decision as addressing a “question of first impression nationwide.”

The ruling arose in a criminal case. Federal agents seized materials that memorialized the defendant’s communications with Claude. Those materials concerned proposed legal strategy. The defendant argued that the materials should remain protected. The court disagreed. The central point was straightforward: Claude was not the defendant’s lawyer, the communications were not confidential legal communications with counsel, and the documents were not created at counsel’s direction.

That does not mean every AI-related document is automatically discoverable or admissible. It means courts will apply ordinary privilege rules to this new technology. Those rules are not friendly to a person who voluntarily gives sensitive facts to a public third-party platform before speaking with a lawyer.

The civil litigation risk is somewhat different, since civil discovery is a different animal than criminal admissibility. While the work product privilege may protect an AI conversation if a judge looks at the question extremely generously, it’s best to assume your opponent’s lawyer will eventually get access to the whole AI chat.

Work product protection can shield certain materials prepared in anticipation of litigation. Federal Rule of Civil Procedure 26(b)(3)(A) protects “documents and tangible things” prepared in anticipation of litigation or trial by or for a party or its representative. But the party asserting that protection carries the burden. Courts ask who created the material, why it was created, and whether it was prepared by or for a party or representative in the legally relevant sense. In Shih v. Petal Card (S.D.N.Y. 2021) 565 F.Supp.3d 557, another Southern District of New York case, the court applied that familiar three-part framework for work product protection. But in that case, there was an additional element where the conversations included a husband and wife, one of whom was an attorney. It is very unclear whether such privilege would hold up for an AI chat.

The law is unsettled in the civil litigation area. A prospective client’s public AI chat may fail that test. The user may have created the conversation alone, before counsel was retained, through a platform that is not counsel, not a consultant retained by counsel, and not an agent of the lawyer. Later sending the AI output to a law firm does not necessarily repair the problem.

That fight will involve evidence rules, authentication, hearsay, relevance, unfair prejudice, and constitutional issues. But privilege is still the first gate. If the communications are not privileged, the defendant may have to fight on narrower evidentiary grounds to keep their admissions out of the opponent’s hands. That is a worse position than never creating the transcript in the first place.

The practical lesson is simple. Do not explain your case to a chatbot before you explain it to your lawyer.

This matters for business disputes, securities litigation, employment claims, internal investigations, financial services disputes, and any legal matter where a party may later face discovery. A person who asks an AI tool to “analyze my case” may also be creating a roadmap for the other side. The transcript may identify the weakest facts, the missing documents, the inconsistent explanations, and the admissions that would otherwise have been harder to find.

Law firms should adjust intake accordingly. When a prospective client sends an AI-generated memo, counsel should ask whether the client used a public AI platform, what facts were entered, whether documents were uploaded, and whether a transcript or saved output exists. That question should come early. It may affect preservation duties, discovery strategy, privilege review, and the client’s exposure in traditional litigation.

AI can help organize public information. It can summarize documents when used under proper controls. It can support legal work when counsel supervises its use and protects confidentiality. But a public chatbot is not a lawyer, and it is not a confidential legal consultation.

The safest rule for prospective clients is also the clearest: tell the lawyer first.

Shustak Reynolds & Partners, P.C. focuses its practice on securities and financial services law and complex business disputes.
We represent many investment advisors, financial professionals, broker-dealers, registered representatives, investors and businesses.
Attorney William M. Moore can be reached in the firm’s San Diego office at (619) 696-9500.

[1] United States v. Heppner, No. 25 Cr. 503 (JSR), Memorandum, United States District Court for the Southern District of New York, Feb. 17, 2026, (download link https://websitedc.s3.amazonaws.com/documents/US_v._Heppner_USA_17_February_2026.pdf.) See, e.g., pp. 1, 4–10 (holding that written exchanges with a public AI platform were not protected by attorney-client privilege or work product doctrine and describing the reasons for that ruling).