What You Tell Your AI Could End Up In Court

Update: 2026-07-27 14:30 GMT
Click the Play button to listen to article

In February 2026, a New York federal court ordered Bradley Heppner, facing securities fraud charges, to hand over legal defence notes he drafted using Anthropic's Claude chatbot. Heppner had prepared these notes in anticipation of his arrest, and shared them with his lawyer beforehand. Since the notes drew on information received from counsel and informed Heppner's defence strategy, his lawyer argued the notes were protected by attorney-client privilege. This privilege bars disclosure of communications between a client and their attorney, and ensuring clients can speak freely with counsel, without fear of self-incrimination. However, the court held that the notes were not confidential, because Anthropic's privacy policy allows user inputs to be collected, used to train Claude, and disclosed to third-parties.

In contrast, a Michigan federal court reached the opposite conclusion for a litigant who used ChatGPT to prepare her case. The court held that AI programmes are “tools, not persons” that merely process a litigant's own thinking. The court also addressed the work product doctrine, which protects materials prepared by a litigant in anticipation of litigation. It held that this protection covers mental impressions and strategy, and is waived only by disclosure to an adversary. A tool, the court reasoned, does not count as an adversary, so the protection survives.

The contrasting decisions raise a fundamental question – is an AI platform an adversarial third-party, or a mere software tool? The answer decides whether feeding legal strategy into AI waives privilege or keeps it intact.

1. A privacy policy cannot be the test for confidentiality

The New York court used Anthropic's privacy policy to deny Heppner's notes confidentiality. However, privacy policies are dynamic, making them a poor legal standard. Companies update them multiple times a year, and most users never read or understand them. A conversation protected in January could become discoverable in June simply because a company revised its terms.

A better standard, therefore, is whether the user had a reasonable expectation of privacy. In Katz v. United States, the Supreme Court held that a person using a public phone booth retained a reasonable expectation of privacy, even though the FBI could intercept the call. Katz established that the mere possibility of access does not defeat a reasonable expectation of privacy.

The New York court ignored this principle. Instead, it relied on Anthropic's technical ability to access user data to negate an expectation of privacy. The court also assumed Heppner had opted into data collection without establishing which account settings he had selected. This is a critical omission since Anthropic allows users to restrict data collection and opt out of model training entirely. A user who opts out has a materially stronger claim to privacy than the court's blanket ruling allows.

2. Service providers do not jeopardise confidentiality

The Heppner ruling treats an AI platform as a third-party whose involvement waives privilege. But clients already rely on third-party digital services for confidential work – in drafting documents on Google Docs, storing case files on cloud servers, and exchanging legal strategy on Slack. While these platforms can be compelled to produce user data under lawful process, the underlying communications remain protected. This is because a digital service provider is a mere conduit between parties and not a party to the communication itself.

United States v. Kovel extended this logic to human consultants, holding that a third-party does not waive privilege if they facilitate legal advice. For instance, an accountant translating raw numbers into financial analysis for a lawyer remains covered by privilege because they support the lawyer's workflow.

Claude performs a similar function when organising a client's thoughts for counsel. The relevant question is not whether Claude has the ability to transform a user's input, but whether that transformation helps the user communicate with their lawyer. When a user feeds their thoughts into Claude to organise them for counsel, the output remains an articulation of their own case, and does not amount to disclosure to an outsider.

3. Preparing for a lawyer is not the same as replacing one

The court erred in asking whether Heppner intended to obtain legal advice from Claude, because that question assumes he was looking to the AI as a replacement for an attorney. The pertinent question is whether he used Claude to prepare for advice from his attorney.

A client's notes remain privileged when prepared for counsel, provided they relay information the lawyer needs and are ultimately shared with counsel. Heppner's notes met both requirements. He fed into Claude information he received from his attorneys, used it to work through possible defence arguments, and shared the resulting output with his defence team.

Yet the court dismissed this on two grounds. It held that confidentiality was lost the moment Heppner shared his inputs with Claude, and that subsequent sharing with counsel could not restore it. Further, it ruled that work-product protection requires materials to be prepared at counsel's direction, which Heppner had not done.

The court pointed to Claude's disclaimer which states it cannot give legal advice, and concluded that Heppner could not have intended to obtain legal advice from Claude. However, this disclaimer simply shields Anthropic from liability for the unauthorised practice of law. It has nothing to do with whether a user can think through their case before speaking to their attorney.

The court further suggested that counsel-directed AI use might have survived under the Kovel doctrine, where Claude would be treated as a third-party that facilitates legal advice, without revoking confidentiality. However, this test invites workarounds - likely a boilerplate declaration signed at the outset, claiming all AI use was directed by counsel. This reduces the legal standard to a mere formality with no means to ascertain if the use was in fact at the counsel's direction.

4. Privilege does not always require secrecy

India

Under Indian law, privilege strictly protects communications between a client and their advocate, extending narrowly to direct staff such as clerks. There is no recognised carve-out for third-parties who facilitate legal advice. Nor does it recognise litigation privilege, an English law doctrine which protects materials prepared by a client independently, in anticipation of litigation. If Indian courts characterise an AI platform as a third-party, the protection could collapse entirely.

This warrants attention because it exposes clients to a critical vulnerability when using AI tools to synthesise facts or structure their thoughts before consulting a lawyer. The recent draft Regulations for Use of Artificial Intelligence in Courts fail to address this vulnerability. The absence of safeguards for clients leaves a dangerous gap that opposing counsel can easily exploit.

Canada

Conversely, Canadian litigation privilege protects materials a client prepares independently, provided their dominant purpose is anticipated litigation. Like the UK, this is a more liberal standard than the New York court's counsel-direction requirement. Confidentiality plays no role in this test. Protection is determined by the purpose behind the creation of material, and not whether a third-party had access to it. Therefore, Anthropic's ability to access user data would not, by itself, nullify litigation privilege in Canada or the UK.

The way forward

The contrasting American rulings prove that existing laws offer no settled answer on whether AI platforms are independent third-parties or mere software tools. Yet, when a person uses AI to organise their thoughts, they are doing so to facilitate their legal defence. This underlying purpose should dictate whether a document remains confidential, just as it does under the litigation privilege rules in Canada and the UK. Even in more conservative legal systems like the United States or India, privilege should remain intact once these materials are shared with counsel.

The right to speak candidly with a lawyer, or even prepare to do so should not depend on the dynamic terms of a privacy policy. Until courts explicitly classify AI platforms as digital conduits, identical facts will keep producing opposite outcomes.

Author is a Research Assistant at Esya Centre, New Delhi. Views are personal.

Tags:    

Similar News

Who Speaks For The Indian Bar?