October 4, 2026 · 11 min read
Heppner vs Warner: The AI Privilege Split and What It Means for Choosing an AI Notetaker in 2026
Published October 04, 2026
- Two federal courts split on the same day (Feb 10, 2026): Heppner stripped privilege from consumer-AI materials; Warner protected AI-assisted work product.
- Heppner's logic — that voluntary disclosure to an AI platform destroys confidentiality — directly threatens cloud AI notetakers that log and train on audio.
- Warner's narrow protection depended on no adversarial disclosure and on treating AI as a 'tool, not a person' — a framing most cloud notetakers can't claim.
- ABA Formal Opinion 512 and NYC Bar Formal Opinion 2025-6 now require lawyers to vet AI vendor retention, training, and access before use.
- On-device transcription (Apple's iOS 26 SpeechAnalyzer) eliminates the third-party vendor from the chain — the architecture Heppner's reasoning punishes isn't present.
Quick answer: It depends on how your AI tool is architected. In February 2026, two federal courts split: United States v. Heppner (S.D.N.Y.) held consumer AI use destroyed attorney-client privilege, while Warner v. Gilbarco (E.D. Mich.) held AI-assisted work product stayed protected. Cloud notetakers that log inputs, train on content, or disclose to subprocessors sit squarely on Heppner's side of the line. On-device transcription avoids the third-party disclosure that Heppner punished.
Two federal courts answered the same question on the same day in February 2026 — and reached opposite conclusions. For lawyers now choosing an AI notetaker for client calls, depositions prep, and internal strategy, the split is less academic than it looks. Here's how to read it, and why vendor architecture — not vendor marketing — decides which side of the line you land on.
On February 10, 2026, two federal courts answered the same question — does using a public AI tool waive privilege? — and gave opposite answers within hours of each other. In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York ruled that documents a defendant generated with Anthropic's Claude were not protected by attorney-client privilege or the work-product doctrine. Hours later, in Warner v. Gilbarco, Magistrate Judge Anthony Patti of the Eastern District of Michigan held that a pro se plaintiff's ChatGPT-assisted drafts were protected work product. Both rulings now sit on every white-collar partner's reading list — and both have direct implications for the AI notetaker running in the background of your next client call.
What Heppner actually held
The facts of Heppner are narrow but the reasoning is wide. Bradley Heppner, a financial-services CEO facing securities-fraud charges, used the free consumer version of Claude to research his legal exposure, generating 31 documents he later shared with his defense team at Quinn Emanuel. The government moved to compel production. Judge Rakoff agreed with the government. As Gibson Dunn summarizes the February 17 written opinion, the court concluded that attorney-client privilege was unavailable because the AI tool was not a lawyer, there was no expectation of confidentiality under the platform's privacy policy, and the defendant was not communicating with the AI for the purpose of obtaining legal advice.
The deepest cut comes in a footnote flagged by King & Spalding: even if some of Heppner's inputs had been privileged, the court said he waived privilege "by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party." That is the sentence that should make every firm pause before approving a cloud notetaker. The analysis does not turn on whether the AI tool is "public" or "private" — it turns on whether the vendor is a third party receiving the content.
What Warner actually held
On the same day, in a civil employment case, Magistrate Judge Patti denied defendants' motion to compel a pro se plaintiff to produce her ChatGPT queries, outputs, and activity logs. His reasoning drew the line Judge Rakoff did not: attorney-client privilege waiver and work-product waiver are not the same thing. Citing D.C. Circuit precedent, Judge Patti held that work-product waiver requires disclosure to an adversary or in a manner likely to reach an adversary — which the plaintiff's private AI session was not. He went further, writing that generative AI programs "are tools, not persons," so disclosure to them is not disclosure to a third party at all.
In other words, Warner is narrower than its headline. It is a work-product case, not a privilege case; it is a pro se case where no third-party vendor was arguing with the court about data retention; and it rests on a view of AI as drafting software, not as an outsider receiving confidences. As Jones Walker notes, the real tension between the two cases is not the outcomes — both may be correct on their facts — but the incompatible frameworks the judges adopted for how AI relates to privilege doctrine.
Why the split matters for AI notetakers specifically
Neither Heppner nor Warner was an AI-notetaker case. Heppner used Claude for legal research; Warner used ChatGPT for drafting. But the Heppner analysis maps cleanly onto cloud AI notetakers that record meetings, upload audio to vendor servers, and reserve rights to use content for product improvement. Three Heppner findings translate directly:
- No reasonable expectation of confidentiality. As the Maryland Daily Record reports, Judge Rakoff grounded his ruling partly in Claude's privacy policy terms. Cloud notetakers like Otter, Fireflies, and Zoom AI Companion all operate under terms of service that permit vendor access, subprocessor involvement, and in some cases training use.
- No alchemy on sharing with counsel. Materials created with a third-party AI do not become privileged just because a lawyer later sees them. If an associate pastes an Otter transcript into a privileged memo, Heppner's logic suggests the underlying transcript still sits outside privilege.
- Privilege is not retroactive. As the transcription privilege analysis of Heppner emphasizes, the platform conditions at the moment of creation matter. Switching to a privacy-respecting tool later does not retroactively protect audio already uploaded elsewhere.
Warner, by contrast, offers less comfort to notetaker buyers than it first appears. Judge Patti's "tools, not persons" framing works when the AI really is a drafting aid running on your own machine with no outside data flow. It gets harder when the "tool" is a vendor-hosted service whose terms of service, as White & Case notes, retain user data "in the ordinary course of its operations."
The bar guidance running in parallel
While the courts were splitting, state bars were tightening the vendor-due-diligence screws. The 2Civility analysis of NYC Bar Formal Opinion 2025-6 is blunt: when a cloud notetaker records a privileged attorney-client call, "the record is transmitted, processed, and stored by a cloud-based vendor and may be accessible to the vendor for training and analytics under their terms of service," which "risks the loss of attorney-client privilege and the further opening of confidential information to discovery." If you want more on how that opinion stacks against its 2026-2 companion for non-client calls, we broke it down in our NYC Bar Formal Opinions walkthrough.
ABA Formal Opinion 512 is more general but equally binding on lawyers nationally: lawyers must obtain informed client consent before inputting confidential information into self-learning AI tools and must understand each tool's terms of use. CMS's England & Wales guidance on legal professional privilege reaches a similar conclusion for UK practitioners: "if you would not forward a law firm's advice to a stranger, do not paste it into a consumer grade AI/LLM tool or allow an external AI notetaker to record it."
The architecture question your GC should be asking
Read Heppner and Warner together and a decision framework emerges. The question is not "does our vendor say it's compliant?" The question is: where does the audio go, and who else can see it? That is an architecture question, and it has one of two answers.
Architecture A: Cloud notetaker (Otter, Fireflies, Zoom AI Companion, Fathom)
Audio travels from the meeting to the vendor's servers. The vendor processes, stores, and in some cases trains on the content. Subprocessors (speech-to-text providers, LLM providers, cloud infrastructure) each receive copies. The vendor's Otter.ai privacy policy and Fireflies privacy policy both describe uses that extend well beyond pure transcription. The vendor can be subpoenaed. On Heppner's reasoning, that is "disclosure to a third party."
Architecture B: On-device transcription (Apple SpeechAnalyzer, Basil AI)
Audio is captured by the microphone, transcribed by a model running on the Apple Neural Engine, and stored locally. No vendor server receives the audio. No subprocessor processes it. The Apple Developer documentation confirms the iOS 26 SpeechAnalyzer framework is on-device-only, with no server-side path. Independent benchmarking by Silicon Report finds the API operates "entirely locally" at a 2.12% word error rate competitive with cloud models. On Warner's framing, this really is "a tool, not a person."
Side-by-side: how each architecture reads against Heppner and Warner
| Dimension | Cloud notetaker (Otter, Fireflies, Zoom) | On-device (Basil AI, iOS 26 SpeechAnalyzer) |
|---|---|---|
| Where audio is processed | Vendor cloud + subprocessors | On the lawyer's device, Neural Engine |
| Third-party receives content? | Yes — vendor + subprocessors | No vendor server receives audio |
| Heppner "third-party disclosure" trigger | Fires | Does not fire |
| Warner "tool, not person" framing | Hard to argue — vendor is a company | Directly applicable — software on your device |
| Training on content | Depends on policy; often opt-out | No model trains on your audio |
| Subpoena surface | Vendor can be served | No third-party custodian to subpoena |
| Fits ABA 512 vendor diligence | Requires contract review + DPA | Diligence scope is the OS vendor, not a notetaker vendor |
Where the bar opinions and the case law converge
Reading Heppner, Warner, ABA 512, NYC Bar 2025-6, and the Ogletree cautionary analysis together, the convergent rule is simple: privilege survives in the AI era where confidentiality is architecturally preserved, lawyer involvement is real, and vendor exposure is minimized. The International Bar Association's analysis of the split echoes this: it is not the fact of AI use that moves the needle, but the conditions under which the AI tool receives the content.
That is good news for lawyers who want AI help without betting the matter. It is bad news for firms that assumed a vendor's SOC 2 report and a DPA were enough to let an Otter bot sit in a privileged call. For the discovery-side angle, see our deeper treatment of whether AI meeting notes are discoverable in litigation.
A 10-question vendor diligence checklist you can bring to procurement
Treat these as the minimum any lawyer should ask before approving an AI notetaker for use in matters where privilege or confidentiality attaches. Pair the answers with the one Heppner question that matters: is there a reasonable expectation of confidentiality under this tool's terms?
- Where exactly is the audio processed — on-device, in a vendor VPC, or on multi-tenant cloud infrastructure?
- What is the default retention for the audio file, the transcript, and the summary?
- Is content used — in any form — for model training, benchmarking, or product improvement, with or without opt-out?
- Which subprocessors receive content? (Speech-to-text vendors? LLM vendors? Cloud providers?) Where are they located?
- Can the lawyer self-delete, or does deletion require vendor action?
- Does the tool support bot-free capture, or does a visible participant join every meeting?
- Does the vendor require all-party consent in two-party states, and how is that captured?
- Is there a signed DPA (and BAA where PHI may be present)?
- What is the vendor's subpoena-response policy, and will it notify the firm?
- Can the tool operate fully offline, so no audio leaves the device at all?
If answers 1 and 10 both point to "on-device, offline," most of the other answers become moot — not because the ethics duties disappear, but because the vendor largely leaves the chain. For a parallel buyer's playbook, see our bot-free vs bot-based AI notetakers guide.
How Basil AI solves this
Basil AI is a privacy-first iOS and Mac AI meeting notetaker that runs entirely on-device. It uses Apple's iOS 26 SpeechAnalyzer framework — which Apple's privacy posture and the framework's architecture guarantee operates with no server-side path — plus the Apple Neural Engine for real-time transcription. Audio and transcripts never leave the device. There is no vendor cloud. There is no subprocessor chain. There is no training on your audio.
Why that matters for the Heppner/Warner analysis:
- No third-party disclosure. Because the audio does not reach any Basil-controlled server, the Heppner trigger — "shared that information with [the vendor], just as if he had shared it with any other third party" — does not fire. There is no vendor copy of the audio.
- "Tool, not person" is literal. Warner's framing — AI as drafting software — fits an on-device transcription engine far more naturally than a vendor-hosted SaaS. There is no company processing your client's words.
- No subpoena target. A vendor you have no contract with has no audio to produce. The transcripts live on your device and are governed by your firm's own retention policy.
- Bot-free capture. Nothing visible joins the call. The NYC Bar's concern about "an uninvited participant in the room" is architecturally resolved.
None of this makes Basil "HIPAA compliant" or "privilege-proof" — compliance is your determination to make, and your bar duties around consent, competence, and client communication under GDPR Article 5 or your state's equivalent apply regardless of architecture. But the architecture removes the vendor from the chain, which is where Heppner found waiver and where the bar opinions want you to focus diligence. For the parallel analysis on how the architecture handles corporate confidentiality more broadly, see our deep dive on AI notetakers and discovery.
What this split does not resolve
Three important caveats before any lawyer treats Heppner/Warner as decided law:
- Heppner is a S.D.N.Y. ruling. It is not binding outside the Second Circuit, though Texas practitioners and firms nationwide are already updating their guidance in anticipation of similar rulings elsewhere.
- Warner is a work-product ruling, not a privilege ruling. As Perkins Coie emphasizes, the two cases apply traditional doctrine to new facts — they do not create AI-specific privilege rules.
- Enterprise AI with proper agreements may be different. Both the Harvard Law Review's analysis and Mayer Brown's AI notetaker analysis emphasize that enterprise AI with contractual confidentiality may fare better. The question is whether your particular vendor's enterprise contract actually locks down training, subprocessors, and retention — a lot of them don't.
Bottom line
The Heppner/Warner split is a gift to lawyers who are willing to make an architectural choice. If your AI notetaker lives on a vendor's cloud, Heppner's reasoning says you have a waiver problem to manage with contracts, policies, and consent flows — and your CCO or GC owns that risk. If your AI notetaker lives on your device, Warner's "tool, not person" framing fits natively and the Heppner third-party-disclosure trigger simply does not fire. Your bar duties still apply, but the vendor is no longer a liability vector. That is the clearest practical lesson of the February 2026 split.
Get Weekly Privacy Insights
On-device AI tips, privacy news, and Basil AI updates. No spam.
Unsubscribe anytime. Privacy Policy
Keep privileged conversations off the cloud.
Basil AI records and transcribes meetings entirely on your iPhone or Mac. No vendor cloud. No subprocessors. No audio ever leaves your device.
Frequently Asked Questions
Does using an AI notetaker waive attorney-client privilege?
It can. In United States v. Heppner, Judge Rakoff ruled that documents a defendant generated using Anthropic's Claude were not protected by attorney-client privilege, because the AI was not a lawyer, there was no expectation of confidentiality under the platform's privacy policy, and no legal advice was being sought. Cloud AI notetakers that upload audio to a vendor and reserve training rights raise the same waiver concerns.
What is the Heppner v. Warner split on AI and privilege?
On February 10, 2026, two federal courts reached opposite conclusions. In Heppner, the S.D.N.Y. held that AI-generated materials lost both attorney-client privilege and work-product protection. In Warner v. Gilbarco, the E.D. Michigan held that a pro se litigant's ChatGPT work product stayed protected, because AI tools are 'tools, not persons' and waiver requires disclosure to an adversary.
Are cloud AI notetakers like Otter and Fireflies safe for privileged client calls?
They introduce a third-party vendor into otherwise confidential communications, and state bars have made clear that lawyers must vet retention, training use, and vendor access before using such tools. ABA Formal Opinion 512 and NYC Bar Formal Opinion 2025-6 both require informed client consent and vendor due diligence. Many firms conclude the cleanest option for privileged conversations is on-device capture that never leaves the lawyer's device.
Does the Heppner ruling apply outside New York?
Heppner is a S.D.N.Y. decision and not binding outside the Second Circuit, but Judge Rakoff described the issue as a nationwide matter of first impression, and law firms including Gibson Dunn, King & Spalding, and Paul Weiss have warned that the reasoning will travel. Any court applying traditional privilege principles — confidentiality, lawyer involvement, legal-advice purpose — can reach a similar result on comparable facts.
How does on-device AI transcription change the privilege analysis?
On-device transcription keeps audio and transcripts on the lawyer's own device — no vendor server receives the recording, and no subprocessor processes it. That removes the 'disclosure to a third party' step that drove Heppner. Your bar duties under Rule 1.6, Rule 1.1, and your state's consent statute still apply, but you eliminate the vendor as a potential waiver vector and discovery custodian.
What should a buyer's checklist for a legal AI notetaker include?
At minimum: where is the audio processed (device vs. vendor cloud), what is the retention default, is content used for model training, who are the subprocessors, can the lawyer self-delete, is there a signed BAA or DPA, is capture bot-free, and does the tool support all-party consent in the relevant states. If any answer involves a vendor server holding privileged audio, your CCO or GC needs to decide whether that risk is acceptable for the matter.