Your Client Talked to ChatGPT First: AI Chats and Attorney-Client Privilege
People facing legal trouble increasingly run their case through a public AI chatbot before they ever call a lawyer. A federal court has now ruled on what those conversations are worth when litigation arrives: they're neither privileged nor work product, and hiring counsel afterward doesn't change that. Here's what United States v. Heppner held, where courts disagree, and what clients and their lawyers should do about it.
It's now common behavior. Someone is under investigation, anticipating a lawsuit, or deciding whether to hire a lawyer, and before making that call they open ChatGPT, Claude, or Gemini and type out the facts: what they did, what they're worried about, what the other side might be able to prove. The chatbot is free, available at midnight, and doesn't bill in six-minute increments. It feels private. The question a federal court has now answered is whether the law treats it that way, and the answer should change how both clients and lawyers behave.
What the Court Held
Judge Rakoff's reasoning ran on three tracks, and each one matters for how the ruling generalizes beyond its facts.
First, an AI chatbot isn't an attorney. Attorney-client privilege protects confidential communications between a client and a lawyer for the purpose of obtaining legal advice, and a conversation with software involves no lawyer at all. The court emphasized that the privilege presupposes communication within a professional relationship, which a consumer chat product cannot supply, however lawyerly its answers sound.
Second, the communications weren't confidential in the way privilege requires. The consumer product's privacy terms at the relevant time permitted user inputs to be collected, used, and potentially disclosed to third parties. By typing his situation into the chatbot, the defendant had effectively shared his defense thinking with a party outside any protected relationship. The terms of service everyone clicks through turned out to be the document that decided the question.
Third, the work-product doctrine failed because the defendant was acting on his own. Work product protects materials prepared in anticipation of litigation by counsel or at counsel's direction, and his lawyers hadn't directed him to use the chatbot. Self-help research, even research plainly motivated by looming litigation, didn't qualify.
Courts Aren't Finished With This Question
Heppner is a district court ruling, not a nationwide rule, and the early case law is genuinely split at the edges. In Warner v. Gilbarco, a court suggested that ChatGPT chat history could potentially fall within the work-product doctrine, a more protective reading than Heppner's. And in the OpenAI copyright litigation, a judge in the same Southern District found that users have a diminished privacy interest in their AI conversations in ordering that a vast set of ChatGPT logs was likely subject to compelled production. The direction of travel is visible: courts are treating AI conversations as records held by a third party, reachable through ordinary legal process, with the protective arguments losing more often than they win. But the law is developing, the decisions are fact specific, and other courts may reach different conclusions, particularly where counsel directed the AI use or where an enterprise environment with contractual confidentiality was involved.
What This Means for the Client Who Already Did It
For the person who ran their case through a public chatbot before hiring counsel, the consequences are concrete. The conversations exist as records in two places: on the provider's servers, under whatever retention applies to the account, and often in the account holder's own history, where a search warrant or discovery request can reach them, which is exactly how the Heppner exchanges surfaced. The client's own prompts can be the most damaging part, because a question like whether the other side can prove knowledge of a defect is a written statement about the client's state of mind, potentially usable as an admission. And the instinct to clean up makes things worse: once litigation is reasonably anticipated, deleting the chats invites a spoliation problem on top of the original exposure, and the OpenAI litigation has already demonstrated that deleted conversations may be preserved on the provider's side regardless.
Transferring the matter into a lawyer's hands protects what happens next, not what already happened. Communications with counsel about the AI conversations are privileged; the AI conversations themselves aren't, and forwarding a chatbot transcript to your new lawyer doesn't convert it into protected material any more than forwarding an email to opposing counsel's benefit could be undone.
What Lawyers Should Do at Intake
The practice implication is that AI use now belongs in the standard intake conversation, the way social media has for a decade. The questions are specific: has the client discussed this matter with ChatGPT, Claude, Gemini, or any other AI tool, on what account, and what was shared. The instructions are equally specific: stop discussing the matter with AI tools immediately, don't delete anything, and preserve what exists. From there the exposure gets assessed like any other adverse document set: what the prompts say, whether they contradict the intended theory of the case, and whether the other side is likely to know to ask for them. Opposing counsel increasingly will ask, because discovery requests are already being drafted to cover AI conversation histories.
For the firm's own use of AI, the lessons converge with what this publication's implementation guide for small and midsize firms recommends: work happens in a firm-managed business environment with contractual confidentiality terms, not consumer accounts, and genuinely privileged strategy stays out of systems whose retention the firm doesn't control. Commentators reading Heppner have drawn the same line the court did: the consumer product's terms sank the confidentiality argument, and enterprise agreements with training exclusions and confidentiality protections present a materially different question, one the courts haven't resolved yet.
The Business Reality Behind the Law
It's worth being honest about why this keeps happening. Public AI tools answer legal questions well enough to be genuinely useful, at midnight, for free, and the profession's response can't be pretending otherwise. People will keep consulting chatbots before lawyers for the same reason they consult search engines before doctors. The realistic goal isn't prevention; it's making sure clients learn early, ideally from the first consultation or the firm's website, that those conversations create records, that the records aren't protected, and that the safest time to stop is before there's anything worth demanding. A firm that explains this clearly isn't just managing risk. It's demonstrating that it understands the world its clients actually live in.
The law here will keep moving, and this publication will follow it. For now the operating rule is simple enough to tell every client on day one: nothing you type into a public chatbot about your legal problem is protected, no matter who you hire afterward.
Sources and Notes
- United States v. Heppner, U.S. District Court for the Southern District of New York (Judge Jed Rakoff, February 2026): consumer AI chatbot conversations held neither attorney-client privileged nor protected work product; reasoning based on the absence of an attorney, the absence of confidentiality under the product's privacy terms, and the absence of counsel's direction. Facts and holdings as reported in firm analyses including Jones Walker, Williams Mullen, and CDF Labor Law reviews of the decision, retrieved August 2026. Reported dates for the ruling vary slightly across accounts; verify against the docket before citing in a filing.
- Warner v. Gilbarco: reported decision suggesting ChatGPT chat history could potentially fall within the work-product doctrine, illustrating the early split; as discussed in the CDF Labor Law analysis.
- In re OpenAI copyright litigation (S.D.N.Y.): preservation of ChatGPT conversation logs including deleted chats, and a subsequent ruling finding users have a diminished privacy interest in AI conversations in connection with compelled production; as widely reported.
- This article describes developing law for general informational purposes and is not legal advice. The decisions discussed are fact specific district court rulings, not binding nationwide precedent, and other courts may reach different conclusions.
- Related analysis: Implementing AI in the Small and Midsize Law Firm, the LinkedIn AI eDiscovery decision, and AI Tools for Law Firms.