{"id":145195,"date":"2026-03-02T16:11:29","date_gmt":"2026-03-03T00:11:29","guid":{"rendered":"https:\/\/xira.com\/p\/2026\/03\/02\/hate-to-say-i-told-you-so-again-your-chats-aint-private\/"},"modified":"2026-03-02T16:11:29","modified_gmt":"2026-03-03T00:11:29","slug":"hate-to-say-i-told-you-so-again-your-chats-aint-private","status":"publish","type":"post","link":"https:\/\/xira.com\/p\/2026\/03\/02\/hate-to-say-i-told-you-so-again-your-chats-aint-private\/","title":{"rendered":"Hate To Say I Told You So Again: Your Chats Ain\u2019t Private"},"content":{"rendered":"<p>On February 20<sup>th<\/sup>, <a href=\"https:\/\/abovethelaw.com\/2026\/02\/clients-and-genai-lawyers-better-be-ready-to-deal-with-it\/\" rel=\"nofollow noopener\" target=\"_blank\">my article<\/a> warning about the dangers of clients using GenAI tools and creating discoverable information was published. Unbeknownst to me, the day before the article was published, a <a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.nysd.652138\/gov.uscourts.nysd.652138.27.0.pdf\" rel=\"nofollow noopener\" target=\"_blank\">ruling<\/a> from the Southern District of New York affirmed my very fears. So once again, I get to say, \u201cI told you so.\u201d Unlike what many think, just because someone puts something in a GenAI tool doesn\u2019t mean it\u2019s private.<\/p>\n<p>In <em>United States of America v. Bradley Heppner<\/em>, Judge Rakoff ruled that certain written exchanges Heppner had with the GenAI platform, Claude, were not protected from disclosure to the government by either the work product or attorney client privilege.<\/p>\n<p><strong>Without Suggestion from Counsel<\/strong><\/p>\n<p>The key concept cited by Judge Rakoff was that Heppner consulted Claude without any suggestion or direction of counsel when he: a) outlined for Claude his defense strategy and sought comments, b) outlined the law and facts he might argue, and c) asked what the other side might argue. He then gave what he had learned from Claude to his counsel.<\/p>\n<p>Heppner argued that he did all this in anticipation of speaking with his lawyer to get legal advice.<\/p>\n<p><strong>The Attorney-Client Privilege<\/strong><\/p>\n<p>According to the court, application of the attorney-client privilege requires a communication between a client and their lawyer, that was intended to be and was kept confidential, and was for purpose of obtaining legal advice.<\/p>\n<p>Judge Rakoff made short work of Heppner\u2019s attorney-client privilege argument. First of all, the communications between Heppner and Claude were not between lawyer and client but between a client and a GenAI platform. Second, the communications were not confidential. Under the terms of use, it was clear that Claude collects data from those who use it and then uses those communications for training purposes. Heppner was thus clearly on notice of the lack of confidentiality and that any input data could be disclosed to others. As a result, said the court, Heppner had no reasonable expectation of privacy.<\/p>\n<p>The court noted Heppner\u2019s argument that he consulted with Claude with the intent to give it to counsel to get later advice. But that argument rang hollow since <em>Heppner didn\u2019t tell counsel in advance that he was going to do it, and his lawyer didn\u2019t know he did it<\/em>.<\/p>\n<p><strong>The Work Product Privilege<\/strong><\/p>\n<p>The work product privilege is designed to protect and shelter the mental processes and thinking of an attorney in representing their client and in anticipation of litigation. But the key, said the court, was that the material needs to be prepared by the attorney. Certainly, said the court, the privilege may apply if done by an agent and at the direction of the attorney. On first blush, that sounds like it may save the Heppner communications from disclosure. But once again, Heppner didn\u2019t communicate with Claude under the direction of his lawyer or, again, even with his knowledge. So, there was no way either Heppner or Claude was acting as an agent of the lawyer. Even if the material was prepared in anticipation of litigation, \u00a0the privilege doesn\u2019t apply, nor did it reflect the lawyer\u2019s strategy or mental processes.<\/p>\n<p><strong>Lessons Learned<\/strong><\/p>\n<p>I have been <a href=\"https:\/\/www.techlawcrossroads.com\/2025\/07\/sam-altmans-warning-everything-you-tell-chatgpt-could-end-up-being-used-against-you\/\" rel=\"nofollow noopener\" target=\"_blank\">warning<\/a> about the impact of throwing caution to the wind when inputting sensitive material into GenAI tools.<\/p>\n<p>First, it\u2019s clear that what a client puts into a GenAI and what they get out before they see a lawyer is fair game for discovery. Nor, under the court\u2019s analysis in Heppner, will it be protected from once litigation is commenced unless directed by the lawyer. That doesn\u2019t change by afterwards saying, well, I was going to give to my lawyer. Right. How convenient.<\/p>\n<p>Granted, some systems provide the option to direct the tool not to disclose the information to others or use it for training. But it still pays to read the terms of use very carefully before placing confidential material into the platform. Oh, and by the way, ignoring the privilege issue for the moment, under the ethical confidentiality rules (<a href=\"https:\/\/www.americanbar.org\/groups\/professional_responsibility\/publications\/model_rules_of_professional_conduct\/rule_1_6_confidentiality_of_information\/?login\" rel=\"nofollow noopener\" target=\"_blank\">Model Rule 1.6<\/a>), it\u2019s not just confidential material we need to protect. It\u2019s information \u201crelating to the representation of a client.\u201d That\u2019s a little broader.<\/p>\n<p>Nor will ignorance of the terms of use be an excuse. Terms of use matter and it\u2019s clear \u2014 lawyer or not \u2014 they better be read.<\/p>\n<p>So, as I have <a href=\"https:\/\/abovethelaw.com\/2026\/02\/clients-and-genai-lawyers-better-be-ready-to-deal-with-it\/\" rel=\"nofollow noopener\" target=\"_blank\">discussed before<\/a>, we as lawyers need to educate our clients as to these basic principles if we want to protect them down the road.<\/p>\n<p><strong>But What About the Lawyers?<\/strong><\/p>\n<p>But what about us lawyers? It\u2019s been said over and over that we shouldn\u2019t put client confidential material into an open or public system. And that we need to be careful in directing our clients to use the tools as well. Merely telling a client to look something on ChatGPT doesn\u2019t make what they input or get back privileged if the other criteria are not met.<\/p>\n<p>But more and more, I see lawyers themselves going to public GenAI tools to do many of the things Heppner was doing: brainstorming their cases and strategies. Will the work product privilege apply to that material?<\/p>\n<p>Certainly, if the lawyer inputs the material, the platform might be considered an agent. Assuming that the material is being prepared or obtained in anticipation of litigation and contains or references the lawyer\u2019s mental processes and strategies, there should be no problem, right?<\/p>\n<p>Maybe. As I have <a href=\"https:\/\/www.techlawcrossroads.com\/2024\/12\/privilege-in-the-age-of-gen-ai-lots-of-questions\/\" rel=\"nofollow noopener\" target=\"_blank\">discussed<\/a>, the issue is whether the privilege is waived by placing it in a public platform where, like Claude, the material is retained by the platform and used for training.<\/p>\n<p>In thinking how this issue might come up, assume that you use Claude and ask it for help with evaluating your strategy. Assuming that what you say is relevant to the case itself\u00a0 (which granted could be a tall order for the other side to show), your opponent moves to compel production of the material. You make your arguments, and your adversary says with a sly smile, \u201cI actually asked ChatGPT what it thought about this. Here is what it said\u201d:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Placing thoughts and ideas into a large language model (LLM) like ChatGPT\u00a0<strong>could potentially waive work product protection.\u00a0<\/strong>If a lawyer uses a\u00a0<strong>public, consumer-facing LLM<\/strong>\u00a0(like ChatGPT or Copilot) without a\u00a0<strong>confidentiality agreement or enterprise-level protections<\/strong>, inputting sensitive legal analysis or impressions\u00a0<strong>might be considered disclosure to a third party.\u00a0<\/strong>If the provider reserves the right to\u00a0<strong>retain, review, or use<\/strong>\u00a0the input data, a court might find that confidentiality was not preserved.<\/p>\n<\/blockquote>\n<p>Nothing like having your own tool stuck up your you know what. As the judge says, you got 10 days to produce your prompts and the outputs.<\/p>\n<p><strong>What\u2019s the Point?<\/strong><\/p>\n<p>The point is not to use GenAI tools but to use them knowledgeably, understanding the risks to you and to your client. You can\u2019t do that by sticking your head in the sand about GenAI. You need to carefully read the terms of use. You need to train yourself. Beyond what you do for yourself, you also need to educate your clients. You need to think about what you\u2019re putting in and getting out and weigh the risks.<\/p>\n<p>As a profession, we don\u2019t want our clients or ourselves ending up like Mr. Heppner.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\">\n<p><em><strong>Stephen Embry is a lawyer, speaker, blogger, and writer. He publishes\u00a0<a href=\"https:\/\/www.techlawcrossroads.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechLaw Crossroads<\/a>, a blog devoted to the examination of the tension between technology, the law, and the practice of law<\/strong><\/em>.<\/p>\n<p>The post <a href=\"https:\/\/abovethelaw.com\/2026\/03\/hate-to-say-i-told-you-so-again-your-chats-aint-private\/\" rel=\"nofollow noopener\" target=\"_blank\">Hate To Say I Told You So Again: Your Chats Ain\u2019t Private<\/a> appeared first on <a href=\"https:\/\/abovethelaw.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Above the Law<\/a>.<\/p>\n<p>On February 20<sup>th<\/sup>, <a href=\"https:\/\/abovethelaw.com\/2026\/02\/clients-and-genai-lawyers-better-be-ready-to-deal-with-it\/\" rel=\"nofollow noopener\" target=\"_blank\">my article<\/a> warning about the dangers of clients using GenAI tools and creating discoverable information was published. Unbeknownst to me, the day before the article was published, a <a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.nysd.652138\/gov.uscourts.nysd.652138.27.0.pdf\" rel=\"nofollow noopener\" target=\"_blank\">ruling<\/a> from the Southern District of New York affirmed my very fears. So once again, I get to say, \u201cI told you so.\u201d Unlike what many think, just because someone puts something in a GenAI tool doesn\u2019t mean it\u2019s private.<\/p>\n<p>In <em>United States of America v. Bradley Heppner<\/em>, Judge Rakoff ruled that certain written exchanges Heppner had with the GenAI platform, Claude, were not protected from disclosure to the government by either the work product or attorney client privilege.<\/p>\n<p><strong>Without Suggestion from Counsel<\/strong><\/p>\n<p>The key concept cited by Judge Rakoff was that Heppner consulted Claude without any suggestion or direction of counsel when he: a) outlined for Claude his defense strategy and sought comments, b) outlined the law and facts he might argue, and c) asked what the other side might argue. He then gave what he had learned from Claude to his counsel.<\/p>\n<p>Heppner argued that he did all this in anticipation of speaking with his lawyer to get legal advice.<\/p>\n<p><strong>The Attorney-Client Privilege<\/strong><\/p>\n<p>According to the court, application of the attorney-client privilege requires a communication between a client and their lawyer, that was intended to be and was kept confidential, and was for purpose of obtaining legal advice.<\/p>\n<p>Judge Rakoff made short work of Heppner\u2019s attorney-client privilege argument. First of all, the communications between Heppner and Claude were not between lawyer and client but between a client and a GenAI platform. Second, the communications were not confidential. Under the terms of use, it was clear that Claude collects data from those who use it and then uses those communications for training purposes. Heppner was thus clearly on notice of the lack of confidentiality and that any input data could be disclosed to others. As a result, said the court, Heppner had no reasonable expectation of privacy.<\/p>\n<p>The court noted Heppner\u2019s argument that he consulted with Claude with the intent to give it to counsel to get later advice. But that argument rang hollow since <em>Heppner didn\u2019t tell counsel in advance that he was going to do it, and his lawyer didn\u2019t know he did it<\/em>.<\/p>\n<p><strong>The Work Product Privilege<\/strong><\/p>\n<p>The work product privilege is designed to protect and shelter the mental processes and thinking of an attorney in representing their client and in anticipation of litigation. But the key, said the court, was that the material needs to be prepared by the attorney. Certainly, said the court, the privilege may apply if done by an agent and at the direction of the attorney. On first blush, that sounds like it may save the Heppner communications from disclosure. But once again, Heppner didn\u2019t communicate with Claude under the direction of his lawyer or, again, even with his knowledge. So, there was no way either Heppner or Claude was acting as an agent of the lawyer. Even if the material was prepared in anticipation of litigation, \u00a0the privilege doesn\u2019t apply, nor did it reflect the lawyer\u2019s strategy or mental processes.<\/p>\n<p><strong>Lessons Learned<\/strong><\/p>\n<p>I have been <a href=\"https:\/\/www.techlawcrossroads.com\/2025\/07\/sam-altmans-warning-everything-you-tell-chatgpt-could-end-up-being-used-against-you\/\" rel=\"nofollow noopener\" target=\"_blank\">warning<\/a> about the impact of throwing caution to the wind when inputting sensitive material into GenAI tools.<\/p>\n<p>First, it\u2019s clear that what a client puts into a GenAI and what they get out before they see a lawyer is fair game for discovery. Nor, under the court\u2019s analysis in Heppner, will it be protected from once litigation is commenced unless directed by the lawyer. That doesn\u2019t change by afterwards saying, well, I was going to give to my lawyer. Right. How convenient.<\/p>\n<p>Granted, some systems provide the option to direct the tool not to disclose the information to others or use it for training. But it still pays to read the terms of use very carefully before placing confidential material into the platform. Oh, and by the way, ignoring the privilege issue for the moment, under the ethical confidentiality rules (<a href=\"https:\/\/www.americanbar.org\/groups\/professional_responsibility\/publications\/model_rules_of_professional_conduct\/rule_1_6_confidentiality_of_information\/?login\" rel=\"nofollow noopener\" target=\"_blank\">Model Rule 1.6<\/a>), it\u2019s not just confidential material we need to protect. It\u2019s information \u201crelating to the representation of a client.\u201d That\u2019s a little broader.<\/p>\n<p>Nor will ignorance of the terms of use be an excuse. Terms of use matter and it\u2019s clear \u2014 lawyer or not \u2014 they better be read.<\/p>\n<p>So, as I have <a href=\"https:\/\/abovethelaw.com\/2026\/02\/clients-and-genai-lawyers-better-be-ready-to-deal-with-it\/\" rel=\"nofollow noopener\" target=\"_blank\">discussed before<\/a>, we as lawyers need to educate our clients as to these basic principles if we want to protect them down the road.<\/p>\n<p><strong>But What About the Lawyers?<\/strong><\/p>\n<p>But what about us lawyers? It\u2019s been said over and over that we shouldn\u2019t put client confidential material into an open or public system. And that we need to be careful in directing our clients to use the tools as well. Merely telling a client to look something on ChatGPT doesn\u2019t make what they input or get back privileged if the other criteria are not met.<\/p>\n<p>But more and more, I see lawyers themselves going to public GenAI tools to do many of the things Heppner was doing: brainstorming their cases and strategies. Will the work product privilege apply to that material?<\/p>\n<p>Certainly, if the lawyer inputs the material, the platform might be considered an agent. Assuming that the material is being prepared or obtained in anticipation of litigation and contains or references the lawyer\u2019s mental processes and strategies, there should be no problem, right?<\/p>\n<p>Maybe. As I have <a href=\"https:\/\/www.techlawcrossroads.com\/2024\/12\/privilege-in-the-age-of-gen-ai-lots-of-questions\/\" rel=\"nofollow noopener\" target=\"_blank\">discussed<\/a>, the issue is whether the privilege is waived by placing it in a public platform where, like Claude, the material is retained by the platform and used for training.<\/p>\n<p>In thinking how this issue might come up, assume that you use Claude and ask it for help with evaluating your strategy. Assuming that what you say is relevant to the case itself\u00a0 (which granted could be a tall order for the other side to show), your opponent moves to compel production of the material. You make your arguments, and your adversary says with a sly smile, \u201cI actually asked ChatGPT what it thought about this. Here is what it said\u201d:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Placing thoughts and ideas into a large language model (LLM) like ChatGPT\u00a0<strong>could potentially waive work product protection.\u00a0<\/strong>If a lawyer uses a\u00a0<strong>public, consumer-facing LLM<\/strong>\u00a0(like ChatGPT or Copilot) without a\u00a0<strong>confidentiality agreement or enterprise-level protections<\/strong>, inputting sensitive legal analysis or impressions\u00a0<strong>might be considered disclosure to a third party.\u00a0<\/strong>If the provider reserves the right to\u00a0<strong>retain, review, or use<\/strong>\u00a0the input data, a court might find that confidentiality was not preserved.<\/p>\n<\/blockquote>\n<p>Nothing like having your own tool stuck up your you know what. As the judge says, you got 10 days to produce your prompts and the outputs.<\/p>\n<p><strong>What\u2019s the Point?<\/strong><\/p>\n<p>The point is not to use GenAI tools but to use them knowledgeably, understanding the risks to you and to your client. You can\u2019t do that by sticking your head in the sand about GenAI. You need to carefully read the terms of use. You need to train yourself. Beyond what you do for yourself, you also need to educate your clients. You need to think about what you\u2019re putting in and getting out and weigh the risks.<\/p>\n<p>As a profession, we don\u2019t want our clients or ourselves ending up like Mr. Heppner.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\">\n<p><em><strong>Stephen Embry is a lawyer, speaker, blogger, and writer. He publishes\u00a0<a href=\"https:\/\/www.techlawcrossroads.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechLaw Crossroads<\/a>, a blog devoted to the examination of the tension between technology, the law, and the practice of law<\/strong><\/em>.<\/p>\n<p>The post <a href=\"https:\/\/abovethelaw.com\/2026\/03\/hate-to-say-i-told-you-so-again-your-chats-aint-private\/\" rel=\"nofollow noopener\" target=\"_blank\">Hate To Say I Told You So Again: Your Chats Ain\u2019t Private<\/a> appeared first on <a href=\"https:\/\/abovethelaw.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Above the Law<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On February 20th, my article warning about the dangers of clients using GenAI tools and creating discoverable information was published. Unbeknownst to me, the day before the article was published, a ruling from the Southern District of New York affirmed my very fears. So once again, I get to say, \u201cI told you so.\u201d Unlike [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-145195","post","type-post","status-publish","format-standard","hentry","category-above_the_law"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/145195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/comments?post=145195"}],"version-history":[{"count":0,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/145195\/revisions"}],"wp:attachment":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media?parent=145195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/categories?post=145195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/tags?post=145195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}