Client Alerts

Claude Is Not An Attorney: The Heppner Ruling and the Risks of Using AI for Legal Matters

Client Alerts | June 4, 2026 | Commercial and Corporate Litigation | Risk Management

Federal judge Jed S. Rakoff of the United States District Court for the Southern District of New York recently ruled that thirty-one documents a criminal defendant generated using the consumer-tier version of Anthropic’s AI platform Claude were not protected by attorney-client privilege or the attorney work product doctrine, although the defendant had prepared them for use in his legal case and intended to transmit them to his attorneys.1 The decision has generated extensive commentary and criticism from practitioners and academics since its issuance in February 2026.

Bradley Heppner, who was charged with multiple felonies, was subsequently tried and found guilty on all counts on May 7, 2026. He is now awaiting sentencing. Although the decision has been criticized on doctrinal grounds and currently applies only in Manhattan and seven other counties of New York, the guilty verdict in Heppner strongly emphasizes the potentially dire consequences of the February 2026 decision: anything you input into a consumer AI platform in connection with a legal matter, unless done at the direction and under the supervision of your counsel, is potentially subject to discovery or seizure in civil or criminal litigation.

Kleinberg Kaplan’s practical recommendations in light of the Heppner decision and verdict are: (1) refrain from using consumer AI tools such as ChatGPT, Claude, or Gemini to research, analyze, or strategize about potentially sensitive legal matters; (2) consult your attorney before using any AI tool in connection with a legal matter, and if directed to use AI by an attorney, document that direction in writing; (3) update any internal AI use policies to prohibit the ingestion of privileged or confidential information into consumer AI tools, and (4) require use of enterprise-grade platforms with robust confidentiality and data security protections.

The Heppner Case

Heppner, a Dallas-based financial services executive, was indicted in October 2025 on charges of securities fraud, wire fraud, conspiracy, and related offenses arising from his alleged role in defrauding investors of more than $150 million. After receiving a grand jury subpoena and retaining defense counsel, Heppner, on his own initiative and without his lawyers’ direction, used the consumer-grade version of Claude to generate a set of documents outlining potential defense strategies, legal arguments, and factual analyses. He later shared those documents with his attorneys, and when FBI agents executed a search warrant at his home upon his arrest, they seized electronic devices containing the materials.

As Heppner’s trial approached, Heppner sought to exclude the documents from evidence on the grounds that they were protected by privilege. Judge Rakoff ruled that the documents failed to satisfy the required elements of attorney-client privilege on multiple independent grounds: the crux of the Court’s decision was that the communications could not be privileged because (1) “Claude is not an attorney;” (2) the communications were not confidential since Anthropic’s consumer privacy policy permits data collection, model training, and disclosure to third parties; and (3) Heppner did not communicate with Claude for the purpose of obtaining legal advice, since he communicated with Claude “of his own volition” and Claude itself disclaims the ability to give legal advice. The court also held that sharing already-unprivileged materials with counsel after the fact (as Heppner did by sharing the materials with his lawyers) cannot retroactively cloak the documents in privilege, and that the work product doctrine did not apply because the documents were not prepared “by or at the behest of counsel.” Critically, Judge Rakoff left open the possibility that had Heppner’s counsel directed him to use AI, the platform “might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.”2

The Decision Has Been Widely Criticized

Judge Rakoff’s ruling has been widely criticized since its issuance in February. The most substantial academic criticism came from the Harvard Law Review, which argued that Judge Rakoff’s opinion “:veers toward categorically excluding a client’s use of generative AI from attorney-client privilege” when “[a] more fact-dependent analysis, and careful consideration of the role of AI within the attorney-client relationship, would suggest that such use should at least sometimes qualify for privilege[.]” The piece challenged each prong of the Court’s reasoning: it argued that treating Claude’s non-attorney status as dispositive oversimplifies how courts treat communications with non-attorney third parties within the attorney-client relationship; challenged the finding that Heppner had no reasonable expectation of confidentiality in prompts transmitted to Claude, and argued that the court should have asked not whether Heppner intended to obtain legal advice from Claude, but rather whether he intended to use Claude to facilitate obtaining legal advice from his attorney. The article concluded that the court’s approach “would seem to categorically preclude clients’ use of today’s frontier AI models” from privilege, which would “asymmetrically disempower clients” while inviting “performative adherence to formalities.”

Notably, a decision issued the same day by the Eastern District of Michigan held that a pro se plaintiff’s use of ChatGPT to prepare litigation materials was protected by privilege.3 That Court reached the opposite conclusion from Heppner based on the premise that AI programs are “tools, not persons,” rejecting the argument that uploading information to an AI platform is a third-party disclosure that waives privilege, and warning that if such use constituted waiver it “would nullify attorney work-product protection in nearly every modern drafting environment, a result no court has endorsed.” While the two decisions are reconcilable on their facts, they reflect a genuine tension in how courts are likely to characterize AI platforms for purposes of privilege analysis going forward.

AI Prompts and Outputs as Discoverable ESI

Every commentary agrees on one foundational point: AI prompts and outputs constitute electronically stored information (ESI) and are subject to the same preservation, discovery, and production obligations as any other form of electronic data. This means that in any litigation, regulatory investigation, or government enforcement action, opposing parties or the government may seek production of communications with AI platforms, and a court may order those communications (including any documents provided to the platforms) to be produced.

What the Court Left Open

The Heppner opinion is notable not only for what it decided but for what it deliberately left undecided. Judge Rakoff expressly acknowledged that the analysis might differ if counsel had directed the AI use, invoking the Kovel doctrine under which privilege can extend to non-lawyer agents retained by counsel (most usually, accountants or other expert consultants) to assist in providing legal advice.

Perhaps more significantly, the court’s confidentiality analysis was specifically tethered to the features of Anthropic’s consumer privacy policy, not to any inherent characteristic of AI technology. The Court did not address the use of other enterprise-grade or legal-specific AI platforms with contractual confidentiality protections, zero data retention, and prohibitions on model training with the user’s data. Enterprise and legal-specific AI platforms, such as Harvey, Lexis+ AI and Thomson Reuters CoCounsel operate under fundamentally different contractual and technical frameworks than the consumer version of Claude at issue in Heppner.

When an attorney uses an enterprise-grade secure platform to research, draft, or analyze legal issues on behalf of a client, the circumstances are distinguishable from Heppner on every prong of Judge Rakoff’s analysis. The platform is deployed by counsel, not by the client, creating a direct nexus to the provision of legal advice. The contractual framework with the service reinforces the expectation of confidentiality in the information provided to the AI tool. And the tool functions not as an independent third party but as an instrumentality within the attorney-client relationship, akin to a paralegal, a legal research database, or an expert consultant retained by counsel, exactly like the accountant in the Kovel case decided over 60 years ago.

However, it is important to emphasize that no court has affirmatively ruled that enterprise AI use preserves attorney-client privilege. Enterprise tools provide a materially stronger factual foundation for a privilege claim, but the question remains open.

Practical Takeaways

The single most important takeaway from Heppner is that the consumer-grade versions of AI platforms should not be used to research, analyze, or strategize about legal matters, particularly matters involving litigation, government investigations, or regulatory exposure. The privacy policies of these tools expressly permit data collection, training, and disclosure, and the Heppner court treated those terms as dispositive of the inquiry into whether Heppner had a reasonable expectation of confidentiality in his communications with Claude. Using such a tool to discuss your legal situation is, as one commentator observed, “the rough equivalent of discussing their case with a barber.”

If you want to use AI to help process legal issues, whether to organize facts, research legal questions, or prepare for discussions with counsel, discuss that need with your attorney first. The Heppner decision makes clear that whether AI use was “at the direction of counsel” may be a decisive factor in any future privilege analysis. Your attorney can advise you on which tools are appropriate, what information may be input, and how to document the attorney-directed nature of the work. If your attorney directs you to use a specific AI tool, that direction should be memorialized in writing so that it can be demonstrated to a court if necessary.

Companies should also review and update their AI usage policies to address the privilege and discovery risks highlighted by Heppner. At minimum, policies should specify which AI platforms are approved for use in connection with legal matters, prohibit the input of privileged or confidential information into consumer AI tools, route any AI use related to legal work through counsel, and require the use of enterprise tools with robust confidentiality protections. Employee training should emphasize that communications with public AI platforms are not confidential and should never be treated as substitutes for privileged communications with attorneys.

Conclusion

United States v. Heppner is a significant but narrow decision. It applies traditional privilege principles to a specific, and particularly unfavorable, set of facts involving a represented criminal defendant who independently used a consumer-level AI tool with no confidentiality protections to develop legal strategy, and then attempted to cloak those materials in privilege after the fact. The decision has been widely criticized for reasoning that verges on categorical exclusion of non-attorney AI use from privilege, but it does not announce a blanket rule against AI in legal practice; and it leaves meaningful room for the argument that use of enterprise-grade legal AI tools, perhaps by clients, but certainly by the lawyers themselves, preserves privilege.

Nevertheless, the practical effects are clear. Clients in the Southern District of New York, which encompasses Manhattan, the Bronx, Westchester and five other counties, should assume that any interaction with a consumer AI platform is potentially discoverable and not protected by privilege. The safest course is to refrain from using AI for legal analysis or strategy without your attorney’s direction, and to rely on enterprise tools selected by your counsel and perform those inquiries under your counsel’s supervision when AI-assisted work is appropriate. We are monitoring developments in this area closely and are available to assist with the review and updating of AI governance policies and your use of AI to ensure that any applicable privilege is preserved.

———————————————————-

1 United States v. Heppner, No. 25 Cr. 503 (S.D.N.Y. Feb. 17, 2026).
2 U.S. v. Adlman, 68 F.3d 1495, 1498-99 (2d Cir. 1995); U.S. v. Kovel, 296 F.2d 918 (2d Cir. 1961).
3 Warner v. Gilbarco, Inc., No. 2:24-CV-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026).