跳到正文 / Skip to main content
LAWMAY路迈

Insights

Going to Market in the U.S. (II): The First Federal Ruling That AI Chats Are Not Protected by Attorney-Client Privilege

Author

Hongchang Deng · 邓宏昌

美国(加州)执业律师(Bar #354529)· USPTO · 中国专利代理师

 

Yi Yi · 易伊

美国(加州)执业律师

Published

2026-05-15 · 25 min read

TL;DR

Thirty-one AI conversation logs became evidence. Judge Rakoff held they were protected by neither attorney-client privilege nor the work product doctrine — and explained why.

AI platform conversations do not receive attorney-client privilege protection

Overview: Thirty-One AI Chat Logs Ruled Admissible

In November 2025, Bradley Heppner, former CEO of the U.S. company GWG Holdings, was arrested in connection with a securities fraud case involving more than $150 million. Before that, under the weight of a grand jury proceeding, Heppner took a step that proved to be a compliance disaster.

Without instruction from counsel, he opened the AI assistant Claude, entered core case information his lawyers had conveyed to him, and directed the AI to help him organize his defense strategy and analyze doctrinal weaknesses. He then sent the AI-generated reports to his legal team.

When federal investigators executed a search warrant, they extracted 31 detailed AI conversation documents from his devices.

Defense counsel argued the documents were protected by attorney-client privilege and the work product doctrine and should not be produced to the government.

On February 10, 2026, Judge Jed S. Rakoff of the Southern District of New York ruled: the documents were protected by no privilege and had to be produced.

What Are Attorney-Client Privilege and the Work Product Doctrine?

In common law systems and most jurisdictions, these two doctrines are foundational protections:

Attorney-client privilege protects confidential communications between client and counsel for the purpose of seeking or providing legal advice. Its purpose is to encourage candor, so that the client discloses the facts fully and truthfully and legal advice — and the representation that follows — is accurate and effective. It has three core elements: the communication must be between client and attorney; it must be intended to be confidential and treated as such; and it must concern legal advice.

The work product doctrine protects materials prepared by counsel or counsel's agents in anticipation of litigation — memoranda, analyses, strategy outlines. It protects counsel's independent work and thinking, preventing an opponent from obtaining litigation preparation and core strategy through discovery, and thereby preserving procedural and substantive parity between the parties.

In practice these principles are not abstractions but operational standards. At LawMay, we build privilege protection into our standard process from the outset of an engagement: engagement letters, legal analyses, strategy memoranda, and client communications all carry privilege designations, so that confidentiality obligations and litigation defense are implemented at every step.

The Exception: Waiver by Third-Party Disclosure

Privilege is not absolute. Once a party voluntarily discloses confidential information to an unrelated third party, the law will generally find the privilege waived.

The central question in Heppner was whether an AI assistant is a communication tool or a third party whose involvement destroys privilege.

The Court's Three Lines of Reasoning

Judge Rakoff explained the ruling along three dimensions.

AI has no legal professional status. Privilege rests on professional trust between people. An AI holds no law license and bears no fiduciary duty. The court was explicit: privilege cannot be created unilaterally by a client; it must exist between the client and a regulated legal professional. Claude is not a lawyer, so the communication departed from the privilege track at the first step.

Consumer AI users lack a reasonable expectation of confidentiality. The privacy policies of mainstream consumer AI platforms — including Anthropic's Claude, at issue here — generally provide that the company collects user prompts for model training and reserves the right to disclose information to regulators. A user who accepts that policy and uses a consumer AI tool is treated in law as having voluntarily disclosed information to a third party.

Independent conduct is not work product. The work product doctrine generally requires that materials be prepared by counsel or at counsel's express direction. Heppner's own use of a consumer AI for research was personal initiative, not action under counsel's direction, and therefore did not qualify.

A Related Ruling: Losing Trade Secret Status

Heppner is not isolated. In the contemporaneous Trinidad v. OpenAI, the court took a similar position.

The plaintiff claimed an AI framework it had developed using ChatGPT was a trade secret and alleged infringement by OpenAI. The court rejected the claim, reasoning that by entering the information into ChatGPT, the plaintiff had affirmatively disclosed it to a third party owing no duty of confidentiality.

The implication: information entered into a public AI platform without redaction may lose its legal status as a trade secret.

How Privilege Can Be Preserved

If disclosure to a public consumer AI platform can destroy privilege, must one avoid AI entirely? No.

While rejecting Heppner's arguments, Judge Rakoff left an important compliance note in the opinion. He suggested the law does not resist technological progress but requires that technology be brought within the existing framework of legal ethics.

Specifically, the opinion indicated that where an attorney directs a client to use an AI tool, that tool may be regarded as an extension of counsel's discharge of the representation and fall within privilege protection. So where a client, under counsel's careful direction, uses an enterprise AI system subject to confidentiality obligations, the legal characterization of those communications in a privilege analysis differs materially — providing a persuasive basis for maintaining privilege or work product protection.

Risk Management Recommendations

Heppner marks the beginning of judicial line-drawing on artificial intelligence and privilege. The efficiency AI brings does not automatically offset legal confidentiality obligations. At the intersection of law and technology, the security of information depends not only on the algorithm but on the user's understanding of, and adherence to, legal rules.

For individual users. It is easy to fall into the trap of conversational psychological safety — assuming an exchange with an AI is private. Under third-party disclosure principles, once information flows to a commercial entity owing no fiduciary duty, the reasonable expectation of confidentiality is at risk of failing. Users must develop strict data redaction discipline and must not enter litigation strategy, unpublished sensitive agreements, or highly personal information into consumer AI tools. Any organization of information touching legal proceedings should be conducted under counsel's substantive direction.

For companies. AI is double-edged: while it raises output substantially, it can become an invisible channel for trade secret loss. Management must recognize that a single copy-paste or file upload may cost the company years of R&D or trade secret protection. As Trinidad v. OpenAI shows, secrecy is irreversibly lost once disclosed outside a legally protected confidential environment. Companies should therefore establish routine controls from the top down and, where AI is deeply integrated into operations, prioritize enterprise services with data isolation, no-training, and contractual confidentiality terms.

For legal professionals. Efficiency gains from AI must be reconciled with professional ethics and the rules of evidence. Counsel must raise their own technical literacy and discharge a duty of careful risk disclosure, advising clients at engagement that AI interactions not reviewed by counsel may collapse privilege entirely. Within a firm, the technical architecture of any tool should be assessed rigorously against what judicial practice requires of protected work product. Following the reasoning in Heppner, counsel should position AI tools as confidential auxiliary channels under counsel's substantive control, ensuring that data flow, purpose, and output review remain attorney-directed — so that the arrangement satisfies the legal elements of privilege in function as well as form.

Conclusion: The AI Trap in Outbound Compliance

For companies going to market in the United States, the combined effect of Heppner and Trinidad is more serious still. In cross-border practice, companies increasingly rely on generative AI to draft submissions, prepare compliance responses, or model strategy when handling overseas IP disputes, responding to regulatory inquiries (from the FTC, for example), or planning cross-border structures.

But if a company enters unpublished patent details, sensitive supply chain agreements, or internal accounts bearing on a tax dispute directly into a public AI platform for polishing or analysis, then under the principles these decisions confirm, that critical evidence automatically loses privilege protection through third-party disclosure.

Once cross-border litigation or an overseas regulatory investigation begins, a competitor or a regulator can obtain those AI logs through legal process and turn them into evidence against the company. More seriously still, where the brand patents and exclusive product frameworks on which cross-border e-commerce depends lose secrecy through AI interactions unprotected by confidentiality obligations, the company will find it extremely difficult to assert trade secret misappropriation in a foreign court.

Outbound companies handling legal matters across jurisdictions should therefore weigh these risks carefully and establish mitigations — an AI usage firewall, for example — in advance, ensuring that all conduct touching submission strategy and core assets proceeds within a closed loop guided by professional counsel.

Cases referenced: United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 10 & 17, 2026); Trinidad v. OpenAI, Inc., No. 25-cv-06328-JST (N.D. Cal. Jan. 5, 2026).

This article addresses general legal questions only and does not constitute legal advice on any specific matter.

关于作者 / About the Authors

Richard Deng

Partner · LawMay P.C.

邓律师主要从事中国及美国商品及服务争议解决,以及专利、商标、版权、商业秘密等涉外知识产权诉讼与无效确权业务,并办理中美商标申请及中国专利申请。常年服务跨境工贸企业、跨境电商、电子烟行业、科技制造业等领域,为财富 500 强、国际连锁品牌、出海科技品牌等多家中外知名企业提供常年及专项法律服务。

在跨境电商争议领域,邓律师专注 Schedule A 批量诉讼的被告应对,包括临时限制令(TRO)项下的店铺账户与资金解冻、通过确认不侵权之诉(Declaratory Judgment,DJ)与「反向 TRO」动议争取恢复被下架的商品链接与店铺经营,以及亚马逊账户冻结申诉、品牌备案(Brand Registry)争议等平台纠纷的代理。在华盛顿州西区联邦法院,邓律师代理多起确认不侵权之诉(DJ),取得了恢复商品上架、并禁止对方继续投诉的「反向 TRO」与「反向初步禁令(反向 PI)」。他熟悉 Schedule A 案件高发的伊利诺伊州北区、佛州南区等联邦法院的程序节奏,能在中美时差下迅速响应、把握应诉与和解的时间窗口。

在涉外电子烟与 FDA 监管领域,邓律师为电子烟及新型烟草企业提供覆盖确权、合规到维权的全流程代理,涵盖行业知识产权维权与 337 调查、PMTA 上市前申请与 STN 状态争议、FDA 执法防御(警告信、营销拒绝令 MDO、进口扣留 Import Alert),以及美国海关(CBP)清关合规与扣押货物申诉。

他代理的知识产权相关案件多次荣获「广东省知识产权行政保护典型案例」「广东省商业秘密保护大事件」、「深圳律师承办知识产权十大典型案例」、「深圳市侵害商业秘密典型案例」、「深圳律师国际贸易、投资领域典型案例」、「广东知识产权保护协会年度知识产权推荐学习案例」等专业荣誉。

他代理的商品及服务贸易纠纷、知识产权等争议解决案件涉案标的额总计达数十亿元人民币。

美国联邦知识产权诉讼 · 跨境工贸与电商争议 · 电子烟与 FDA 监管 · 商业秘密与不正当竞争

Rdeng@lawmayus.com

+1 (213) 682-7241 · 美国 / US

+86 186 8156 7690 · 中国 / China,微信同号

Yi Yi

Non-Equity Partner · LawMay P.C.

易伊是美国加利福尼亚州执业律师,执业领域主要包括美国联邦法院知识产权诉讼、跨境电商争议、产品责任纠纷及联邦上诉案件。易伊代理中国及其他国际客户处理专利侵权、商标及著作权争议、产品责任纠纷、临时限制令与初步禁令、网络平台知识产权执法及其他跨境商事纠纷。

易伊经常协助客户应对临时限制令及初步禁令申请,挑战不当的管辖权主张,制定专利不侵权及无效抗辩,并协调中美两地的诉讼策略。易伊亦为跨境电商企业就知识产权执法、平台账户及商品链接争议、产品责任索赔及相关诉讼风险提供法律服务。

易伊具备在美国联邦巡回上诉法院、美国第十一巡回上诉法院、加州中区、北区联邦地区法院及德克萨斯东区、南区、伊利诺伊州北区联邦地区法院的出庭经验(涵盖正式执业资格与临时出庭许可 Pro Hac Vice / PHV 两种形式)。易伊亦办理美国专利商标局商标申请事务,并为美国知识产权法律协会会员。

美国联邦知识产权诉讼 · 跨境电商争议解决 · 联邦巡回上诉法院实务

Yiyi@lawmayus.com

+1 (747) 241-3130 · 美国 / US

+86 152 2005 1240 · 中国 / China,微信同号

About LawMay P.C.

美国路迈律师事务所(LawMay P.C.)

深耕中美跨境争议解决的美国精品律所。专注于美国联邦知识产权诉讼、337 调查、产品责任纠纷及重大商事争议。

Law May, We May.