• Attorney-Client Privilege
  • Work Product Doctrine
  • AI in Litigation

I Read the Heppner Opinion Twice. Here's What Actually Changes for Trial Lawyers.

Andrew Mancilla5 min read
A litigator alone in a still courtroom, reading closely
On this page

Within a week of Judge Jed Rakoff's February 2026 opinion in United States v. Heppner, three lawyers sent me some version of the same warning: AI destroys privilege.

I read the opinion twice. That is not the holding.

Rakoff held that a criminal defendant's chats with a consumer AI platform were protected by neither the attorney-client privilege nor the work-product doctrine. The facts were not unusual: the defendant acted on his own, outside counsel's direction, used a consumer AI platform, and later tried to bring the resulting material inside the attorney-client relationship. The court refused.

That makes Heppner important, but not because it makes AI radioactive. It is important because it shows how privilege and work product can fail when a client uses AI as an unsupervised litigation strategist. It also arrives as civil courts are taking a more protective approach to AI-assisted work product. For trial lawyers, the lesson is not "ban AI." It is: control the channel, direct the work, and do not assume a client's chatbot history is protected.

The facts, stripped down

Bradley Heppner was facing federal fraud charges. After he'd retained counsel, he sat down on his own and used a public, consumer version of an AI chatbot to ask questions about his case. Federal agents later seized those documents. When the government argued they weren't privileged, Rakoff agreed.

This is a very common fact pattern, and I'd bet well over 90% of criminal defendants are doing this exact same thing right now unless counsel advised them otherwise.

Why Rakoff ruled the way he did

Strip away the technology. This is old doctrine on a new medium. Rakoff ran two separate analyses. Trial lawyers should too.

Attorney-client privilege protects confidential communications with an attorney made to get legal advice. Rakoff found the documents failed at least two elements, maybe all three:

  • No attorney. Claude is not a lawyer. Legal talk with a non-lawyer is not privileged. That alone defeated the claim.
  • No confidentiality. The privacy policy let Anthropic collect his inputs, train on them, and share them with third parties, including regulators. You cannot expect confidentiality in material you agreed could go to the government.
  • Not for legal advice. The closer call. But Claude disclaims giving legal advice. And forwarding the outputs to counsel later could not create privilege after the fact.

Work product is the separate doctrine. It is where "no direction from counsel" lives. It shelters material prepared by or at counsel's direction in anticipation of litigation, to protect the lawyer's strategy. Counsel conceded Heppner ran Claude on his own. The reports may have affected the defense later. They did not reflect counsel's strategy when made. No protection.

The actual lesson

Your litigation clients are using AI. Not some of them. All of them. They are pasting your emails into chatbots, asking for case assessments, war-gaming strategy at midnight. And after Heppner, you have to assume those conversations are discoverable.

Remember what actually sank Heppner: not that he used AI, but how. He used a consumer platform, alone, with no direction from counsel. Judge Rakoff even signaled that counsel-directed use might have come out differently. That is the entire lesson.

Criminal defense lawyers have dealt with a version of this for decades. You don't tell a client in custody to stop making calls. You tell them the line is recorded, so the case never gets discussed on it. AI is no different. The answer isn't "stop using AI." The answer is: never discuss your case in an environment that can't protect it. And if AI is going to touch the case at all, use AI built for privilege: attorney in the loop, confidential by design, direction running from counsel down, never from the client up.

Never discuss your case in an environment that can't protect it.

Andrew Mancilla, Founder

If your firm hasn't made this a standard part of client counseling, understand what that silence costs. Your clients are using AI either way. The only question is whether it happens under privilege or on the record.

One more thing worth saying

I've spent fifteen years watching clients try to help their own case in ways that end up hurting it. Long before AI, it was clients emailing their theory of the case to a friend, or writing it all down in a journal a prosecutor later subpoenaed. The instinct to prepare is a good one. Left unsupervised, it's also how privilege gets waived.

That instinct is exactly why, when we built the client portal inside OurFirm.ai, we didn't build a chat window and hope for the best. Clients work alongside counsel, inside the firm's environment, under the attorney's direction, the same three things Heppner turned on. Not because we were reacting to a headline, but because any litigator who has watched a client "help" has seen this exact fact pattern before. Heppner just gave it a name.

However you feel about the decision, the risk is now real and worth mitigating. Do not build a privilege strategy around drawing the friendlier judge. Control the channel. Define the purpose. Direct the work. Check the terms. Teach the client before the client creates the record. That is not a new rule for AI. It is competent litigation practice on a new medium, before your client's chatbot history lands in the government's exhibit binder.

The routine after Heppner
  1. 01
    Control the channelNever discuss the case in an environment that cannot protect it.
  2. 02
    Define the purposeThe work exists to obtain legal advice, not to freelance a defense.
  3. 03
    Direct the workDirection runs from counsel down, never from the client up.
  4. 04
    Check the termsRead the platform's privacy policy before anything about the case touches it.
  5. 05
    Teach the clientCounsel the client before the client creates the record.

See how the OurFirm.ai client portal keeps client work under privilege, with the attorney in the loop.

Explore the Client Portal

Frequently asked questions

Did the Heppner ruling hold that using AI waives attorney-client privilege?
No. Judge Rakoff held that a specific defendant's chats with a consumer AI platform, used on his own without counsel's direction, were protected by neither the attorney-client privilege nor the work-product doctrine. The ruling turns on how the tool was used, not on AI itself.
How can litigators use AI without risking privilege?
Keep the attorney in the loop, use a confidential environment rather than a consumer platform, and make sure the work runs from counsel's direction down. Counsel clients early that case discussions do not belong in any tool that cannot protect them.
What is the difference between the privilege and work-product problems in Heppner?
Attorney-client privilege failed because the communications were not with a lawyer, were not confidential under the platform's terms, and were not made to obtain legal advice. Work product is a separate doctrine that shelters material prepared at counsel's direction in anticipation of litigation, and it failed because the client ran the tool on his own.

Keep reading

Put it to work on your next matter.

Book a DemoMore from the blog