US v. Heppner Explained: The First AI Privilege Ruling
In February 2026, Judge Jed S. Rakoff of the Southern District of New York issued what appears to be the first federal decision squarely addressing whether a litigant's conversations with a public AI platform can be shielded from discovery. In United States v. Heppner, the court held that they cannot — at least on the facts presented — reasoning by analogy to the third-party doctrine that long governs bank records, phone metadata, and other information voluntarily conveyed to a service provider.
The ruling is narrow. It is not the last word. But for attorneys who have quietly integrated ChatGPT, Claude, Gemini, or cloud-hosted AI notetakers into their workflow, Heppner is the clearest signal yet that the architecture of the tools you choose has direct consequences for the confidentiality of what your clients tell you.
This article walks through what the court actually decided, what it did not decide, how it fits alongside ABA Formal Opinion 512 and the more recent NYC Bar Formal Opinion 2025-6, and what practical adjustments a careful practitioner should consider.
The Facts, in Brief
The defendant in Heppner had used a widely available consumer AI chatbot to draft, refine, and discuss aspects of conduct that later became the subject of a federal investigation. During discovery, the government obtained transcripts of those chats from the platform provider pursuant to legal process. The defense moved to suppress and, alternatively, argued that the communications were protected by the attorney-client privilege or the work-product doctrine because counsel had, at various points, been consulted about related matters.
Judge Rakoff rejected the privilege argument. The chats were between the defendant and a commercial software service — not between the defendant and his lawyer, and not made at counsel's direction for the purpose of obtaining legal advice. The court analogized the situation to the long-standing rule that information voluntarily disclosed to a third party generally loses any expectation of confidentiality sufficient to sustain a Fourth Amendment or evidentiary privilege claim. The platform's terms of service, which permitted the provider to store, review, and in some cases use the content for model training, reinforced the conclusion that the defendant had no reasonable expectation the conversations would remain private.
What the Court Did Not Decide
It is worth being precise about what Heppner does and does not stand for. The opinion does not hold that all AI-assisted work is discoverable. It does not address:
- Communications with an AI tool operated by counsel or under counsel's direct supervision as part of rendering legal advice.
- Fully on-device or client-side AI processing where no third party ever receives the content.
- Enterprise deployments with contractual restrictions on training use, retention, or human review — although the opinion signals skepticism about how much weight such contracts carry when the underlying architecture still routes content through a vendor's servers.
- Work-product doctrine as applied to attorney-directed AI research, which the court flagged but did not resolve.
Rakoff's reasoning is grounded in a familiar principle: privilege attaches to the confidential communication between lawyer and client, not to every artifact generated in the vicinity of a legal problem. When a client independently pours the substance of a matter into a consumer product whose provider retains and reviews the content, the client has stepped outside the protected channel.
How Heppner Fits With Existing Guidance
The decision does not arrive in a vacuum. Two ethics opinions frame the professional-responsibility landscape it now joins.
ABA Formal Opinion 512 (July 2024) addressed generative AI tools and reminded lawyers of their obligations under Model Rule 1.6 to safeguard client information, including when using third-party technology. The opinion emphasized understanding how a tool handles inputs — whether they are retained, used for training, reviewed by humans, or shared — before entrusting client confidences to it.
NYC Bar Formal Opinion 2025-6 (December 2025) went further, specifically flagging the risks of AI notetakers and transcription tools that route audio through cloud infrastructure. It advised counsel to obtain informed client consent, to prefer tools with strong contractual and architectural protections, and to consider whether the same result can be achieved with a less invasive tool.
Heppner gives these opinions teeth. It is one thing for a state bar to warn that cloud AI use may implicate confidentiality; it is another for a federal judge to conclude that a specific set of AI-mediated communications is fair game in discovery. The two work together: the ethics opinions tell you what to do prospectively, and Heppner illustrates the cost of getting it wrong.
The Third-Party Doctrine Analogy, and Its Limits
The court's reliance on the third-party doctrine is analytically tidy but not uncontroversial. That doctrine, most closely associated with Smith v. Maryland and United States v. Miller, has been narrowed in recent years — most notably by Carpenter v. United States, which recognized that some digital records (there, cell-site location information) are so revealing that voluntary disclosure to a provider does not extinguish a reasonable expectation of privacy.
A future defendant may well argue that extended, substantive conversations with an AI chatbot are more like the Carpenter location data than like the numeric bank records in Miller. They can be intimate, prolonged, and revealing of thought processes in ways bank ledgers are not. Whether courts accept that argument remains to be seen. Heppner is one district court opinion; it is persuasive, not binding, outside SDNY, and the doctrinal ground beneath it is still shifting.
For a thoughtful outside view, Lawfare has been tracking the intersection of AI, privilege, and evidence law, and its analysis is worth reading alongside the opinion itself.
Where Heppner Sits Alongside Other AI Discovery Cases
Two other recent decisions round out the picture. In West Technology Group v. Sundstrom (D. Conn. 2024), the court addressed the discoverability of AI-generated content in a commercial dispute and reinforced that outputs are treated like any other business record when they exist on a vendor's systems. And Brewer v. Otter.ai (2025) — a putative class action against a widely used cloud transcription service — has kept the wiretap and consent questions surrounding AI notetakers in active litigation.
The through-line is straightforward: when your AI vendor holds the data, your AI vendor's obligations, terms, and legal exposure become part of your risk surface.
A Comparison of Common AI Architectures
The following table summarizes how different AI deployment models tend to fare against the concerns Heppner and the ethics opinions raise. It is a generalization; specific products vary.
| Architecture | Who receives client content | Third-party doctrine exposure | Subpoena target exists |
|---|---|---|---|
| Consumer chatbot (default settings) | Vendor servers; may be used for training | High — the Heppner scenario | Yes (the vendor) |
| Enterprise cloud AI with no-training contract | Vendor servers under contractual restrictions | Moderate — contract mitigates but does not eliminate | Yes (the vendor) |
| Cloud AI notetaker (bot joins call) | Vendor servers; audio and transcript stored | Moderate to high depending on terms | Yes (the vendor) |
| On-device AI (processing on the lawyer's machine) | No third party | Low — no third-party disclosure occurred | No external vendor holds the content |
Practical Adjustments for Practicing Attorneys
The point of reading a case like Heppner is not to panic; it is to update your workflow. A few adjustments worth considering:
- Map your AI surface. List every AI tool touching client matters — drafting assistants, summarizers, notetakers, research tools, translation. For each, know where the data goes and how long it lives there.
- Read the terms, not the marketing. Training-use carve-outs, retention windows, and human-review clauses matter more than a landing page claim of "enterprise-grade security."
- Prefer architecture to promises. A tool that cannot transmit content reduces risk more than a tool that promises not to. There is no server to subpoena and no vendor to breach a contract.
- Get client consent where the tool has any cloud component. NYC Bar Opinion 2025-6 essentially requires this for AI notetakers, and it is good practice regardless.
- Advise clients about their own AI use. Heppner is, at bottom, a case about a client's independent chatbot use. Part of competent representation now includes counseling clients that their AI chats are not a diary and not a privileged consultation.
- Log the basis for privilege. Where AI is used at counsel's direction as part of rendering advice, contemporaneous documentation of that purpose will matter if the work-product question is ever litigated.
What Heppner Does Not Change
It is equally important to note what remains the same. The attorney-client privilege still protects genuine lawyer-client communications made in confidence for the purpose of legal advice. Work product still shields materials prepared in anticipation of litigation. Rule 1.6 still requires reasonable safeguards. The doctrinal furniture is unchanged; Heppner simply clarifies that dropping the substance of a matter into a consumer AI product is not one of the safeguards.
For a deeper walk-through of how bar authorities have been framing these questions, our earlier piece on Basil for Law and the compliance landscape covers the ethics opinions in more detail.
How Basil Approaches This
Basil was built by a practicing lawyer with cases like Heppner in mind. Audio capture, transcription, and summarization run entirely on the Apple Neural Engine on your Mac. Nothing is uploaded. There is no Basil server that receives your meetings, no subprocessor chain to audit, and no vendor mailbox for a subpoena to land in — because Basil never receives your data in the first place.
For in-person meetings and for virtual calls on Zoom, Teams, or Google Meet, Basil captures on-device without sending a bot into the call. The general Basil app is available today with a free 60-minute monthly tier. The Basil for Law edition — with privilege attestation, a consent log, matter organization, and Privileged & Confidential labeling — launches in August 2026 at $19/month for solos, with a 7-day trial. Basil signs DPAs and NDAs on request.
The architectural point is the one Heppner underscores: the safest client content is the client content that never leaves the device. That is privilege-safe by architecture, not by promise.
This article is for information only and is not legal advice.
Frequently asked questions
Is US v. Heppner binding on courts outside the Southern District of New York?
No. As a district court opinion, Heppner is persuasive authority only. It is not binding on other district courts, other circuits, or state courts. That said, it is the first federal ruling squarely on AI-privilege questions, so other courts confronting similar issues are likely to engage with its reasoning.
Does Heppner mean all AI-assisted legal work is discoverable?
No. The ruling addressed a defendant's own conversations with a consumer chatbot, not attorney-directed AI use for rendering advice or preparing for litigation. Work-product and privilege protections can still apply where AI is used within the traditional lawyer-client channel, though the boundaries are being tested.
What should I tell clients about their personal use of AI chatbots?
Advise them that conversations with consumer AI platforms are generally not privileged, may be stored by the provider, and can be obtained in discovery or by subpoena. If they need to discuss something sensitive, that conversation belongs with counsel, not with a chatbot.
Do enterprise AI contracts with no-training clauses solve the Heppner problem?
They help, but they do not eliminate the underlying architectural fact that a third party still receives and stores the content. Contracts can be breached, terms can change, and legal process can still reach vendor-held data. Architecture that never transmits content is a stronger posture than contract terms that restrict misuse.
How does Heppner interact with ABA Formal Opinion 512 and NYC Bar Opinion 2025-6?
The ethics opinions set forward-looking duties: understand your tools, safeguard client information, obtain informed consent for AI notetakers. Heppner shows the back-end consequence when those duties are not met — communications that a lawyer or client assumed were private turn out to be discoverable. Read together, they push toward tools with minimal third-party exposure.
Where can I read the opinion and further analysis?
The opinion is available through PACER and standard legal research databases. For commentary, Lawfare and the ABA's Journal have been covering the case, and the ABA and NYC Bar ethics opinions cited above provide the professional-responsibility backdrop.
Keep client conversations on your device
Basil transcribes and summarizes entirely on-device — no cloud, no bot, no server to subpoena. See Basil for Law → · Legal-tool reviews →
This article is for information only and is not legal advice.