- Attorney-Client Privilege
- Work Product Doctrine
- AI in Litigation
I Read the Heppner Opinion Twice. Here's What Actually Changes for Trial Lawyers.

On this page
Within a week of Judge Jed Rakoff's February 2026 opinion in United States v. Heppner, three lawyers sent me some version of the same warning: AI destroys privilege.
I read the opinion twice. That is not the holding.
Rakoff held that a criminal defendant's chats with a consumer AI platform were protected by neither the attorney-client privilege nor the work-product doctrine. The facts were not unusual: the defendant acted on his own, outside counsel's direction, used a consumer AI platform, and later tried to bring the resulting material inside the attorney-client relationship. The court refused.
That makes Heppner important, but not because it makes AI radioactive. It is important because it shows how privilege and work product can fail when a client uses AI as an unsupervised litigation strategist. It also arrives as civil courts are taking a more protective approach to AI-assisted work product. For trial lawyers, the lesson is not "ban AI." It is: control the channel, direct the work, and do not assume a client's chatbot history is protected.
The facts, stripped down
Bradley Heppner was facing federal fraud charges. After he'd retained counsel, he sat down on his own and used a public, consumer version of an AI chatbot to ask questions about his case. Federal agents later seized those documents. When the government argued they weren't privileged, Rakoff agreed.
This is a very common fact pattern, and I'd bet well over 90% of criminal defendants are doing this exact same thing right now unless counsel advised them otherwise.
Why Rakoff ruled the way he did
Strip away the technology. This is old doctrine on a new medium. Rakoff ran two separate analyses. Trial lawyers should too.
Attorney-client privilege protects confidential communications with an attorney made to get legal advice. Rakoff found the documents failed at least two elements, maybe all three:
- No attorney. Claude is not a lawyer. Legal talk with a non-lawyer is not privileged. That alone defeated the claim.
- No confidentiality. The privacy policy let Anthropic collect his inputs, train on them, and share them with third parties, including regulators. You cannot expect confidentiality in material you agreed could go to the government.
- Not for legal advice. The closer call. But Claude disclaims giving legal advice. And forwarding the outputs to counsel later could not create privilege after the fact.
Work product is the separate doctrine. It is where "no direction from counsel" lives. It shelters material prepared by or at counsel's direction in anticipation of litigation, to protect the lawyer's strategy. Counsel conceded Heppner ran Claude on his own. The reports may have affected the defense later. They did not reflect counsel's strategy when made. No protection.
The actual lesson
Your litigation clients are using AI. Not some of them. All of them. They are pasting your emails into chatbots, asking for case assessments, war-gaming strategy at midnight. And after Heppner, you have to assume those conversations are discoverable.
Remember what actually sank Heppner: not that he used AI, but how. He used a consumer platform, alone, with no direction from counsel. Judge Rakoff even signaled that counsel-directed use might have come out differently. That is the entire lesson.
Criminal defense lawyers have dealt with a version of this for decades. You don't tell a client in custody to stop making calls. You tell them the line is recorded, so the case never gets discussed on it. AI is no different. The answer isn't "stop using AI." The answer is: never discuss your case in an environment that can't protect it. And if AI is going to touch the case at all, use AI built for privilege: attorney in the loop, confidential by design, direction running from counsel down, never from the client up.
Never discuss your case in an environment that can't protect it.
If your firm hasn't made this a standard part of client counseling, understand what that silence costs. Your clients are using AI either way. The only question is whether it happens under privilege or on the record.
One more thing worth saying
I've spent fifteen years watching clients try to help their own case in ways that end up hurting it. Long before AI, it was clients emailing their theory of the case to a friend, or writing it all down in a journal a prosecutor later subpoenaed. The instinct to prepare is a good one. Left unsupervised, it's also how privilege gets waived.
That instinct is exactly why, when we built the client portal inside OurFirm.ai, we didn't build a chat window and hope for the best. Clients work alongside counsel, inside the firm's environment, under the attorney's direction, the same three things Heppner turned on. Not because we were reacting to a headline, but because any litigator who has watched a client "help" has seen this exact fact pattern before. Heppner just gave it a name.
However you feel about the decision, the risk is now real and worth mitigating. Do not build a privilege strategy around drawing the friendlier judge. Control the channel. Define the purpose. Direct the work. Check the terms. Teach the client before the client creates the record. That is not a new rule for AI. It is competent litigation practice on a new medium, before your client's chatbot history lands in the government's exhibit binder.
- 01Control the channelNever discuss the case in an environment that cannot protect it.
- 02Define the purposeThe work exists to obtain legal advice, not to freelance a defense.
- 03Direct the workDirection runs from counsel down, never from the client up.
- 04Check the termsRead the platform's privacy policy before anything about the case touches it.
- 05Teach the clientCounsel the client before the client creates the record.
See how the OurFirm.ai client portal keeps client work under privilege, with the attorney in the loop.
Explore the Client PortalFrequently asked questions
Did the Heppner ruling hold that using AI waives attorney-client privilege?
How can litigators use AI without risking privilege?
What is the difference between the privilege and work-product problems in Heppner?
Keep reading
Verify or Get Sanctioned: What the Case Law Actually Requires
Courts aren't punishing attorneys for using AI. They're punishing attorneys for signing filings they never verified. Here's the doctrine emerging from three years of sanctions opinions.
Security Review5 min readI Helped Build a FedRAMP Program From Inside a Vendor. Here's What Law Firms Aren't Asking.
Law firms are buying AI tools with less security scrutiny than a mid-market SaaS deal gets from a federal procurement officer. Here are the six questions to ask before you sign, from someone who built the vendor side.
Litigation Reimagined4 min readKnow Your Judge Like No One Else: Inside Judge AI, OurFirm's Judicial Analytics Engine
Judge AI turns years of docket history into a ruling profile you can act on before you file: grant rates by motion type, argument preferences, oral argument patterns, and case-matched precedent for your specific judge.