Skip to main content

What’s attorney-client privilege? Why would you care?

A founder’s reality check on typing your worst moment into a chatbot. Updated August 2026, because the courts finally showed up.

Story LLPUpdated August 202617 min read

It’s Friday, late. At your desk. Teammate you weren’t sure you wanted to keep on anyway just told you they have advancing cancer. Tragedies abound, and like any founder, you freak out trying to figure out what to do about it. You don’t want to be horrible, but you actually can’t afford this. You jump on ChatGPT and explain the situation, then ask “can I fire them for having cancer?”

No one saw you say it. Privacy settings at max. In the morning, you probably see things differently. But if you eventually fire this person and they lawyer up, you’re in trouble. If you asked your lawyer that question, no one could ever know. When you ask ChatGPT, you’ve essentially sent yourself a discoverable email to memorialize your intentions at the moment when you looked worst.

I wrote a version of this post several months ago, before there was a single court decision on the subject. There are now quite a few. They mostly say what I said they would, with one wrinkle worth knowing about. This is, of course, not legal advice. It’s a founder reality check and a TLDR.

What’s this legalese?

Attorney-client privilege

The protection of confidentiality for private communications between a lawyer and client. It protects your communications with your lawyer (a human admitted to at least one bar) from disclosure, including in litigation or regulatory investigations. This confidentiality guarantee is stronger than any NDA — a court order can override an NDA. A court order will generally not override attorney-client privilege unless YOU waive it.

Privilege exists because it makes lawyers more effective. If we know the ugliest real truth and all the bad facts, we’ll be better at helping you navigate them. The law WANTS you to be brutally honest with your lawyers in a way you could not be brutally honest publicly, so it provides strong protections — starting when you begin to seek legal advice.

Discovery

The portion of litigation or regulatory action in which the parties use the power of the court and strict penalties to gather information about the claims in a case. In our example above, this would include your sick employee’s lawyer requesting any and all communications you ever had about the employee or illness, including AI chats. This is where stuff comes out, because if you hide stuff in this process you can be strongly penalized — even, in the worst case, with jail.

When you email your lawyer “can I fire them for having cancer so I can hire someone else?” that (and the lawyer telling you no, you cannot) is privileged, and you don’t have to produce the question in response to the opposing lawyer’s request.

When you asked ChatGPT, you have to produce that chat. It’s discoverable.

The courts have now said this out loud

In February 2026, Judge Jed Rakoff in the Southern District of New York decided United States v. Heppner, No. 25 Cr. 503 (JSR). Bradley Heppner got a grand jury subpoena, learned he was a target, and — on his own, without telling his lawyers — used Claude to work through his defense strategy. He generated about 31 documents. He then shared them with his attorneys. The FBI seized them under a warrant. He claimed privilege and work product.

He lost on both, and the opinion is refreshingly blunt:

Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege.

United States v. Heppner (S.D.N.Y. 2026)

Then Rakoff went further, and this is the part founders should actually read. Even setting aside the not-a-lawyer problem, he found there was no reasonable expectation of confidentiality in the first place, because Anthropic’s privacy policy says Anthropic

collects data on both users’ ‘inputs’ and Claude’s ‘outputs,’ that it uses such data to ‘train’ Claude, and that Anthropic reserves the right to disclose such data to a host of ‘third parties,’ including governmental regulatory authorities.

And on the theory that you can fix it after the fact by forwarding the chat to your lawyer:

Non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel.

That is the whole post, in one sentence, from a federal judge. The court also noted the obvious: “AI’s novelty does not mean that its use is not subject to longstanding legal principles.”

Two footnotes on Heppner before anyone over-reads it. First, it’s a district court decision in a criminal case, it was interlocutory, and there is no appellate law on any of this anywhere in the country yet. Heppner was convicted on all counts in May 2026 and is set for sentencing in October, so a Second Circuit appeal is likely coming. Second, Rakoff left a door open, and it’s the door I’ve been pointing at all along:

Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.

That’s the Kovel doctrine — the rule that lets your lawyer bring in an accountant or an interpreter without blowing privilege. Nobody has actually held that it extends to an AI vendor. But it is the only known path, and it runs through a lawyer. Which is what I said.

Why would you care?

Ask yourself: have you ever asked AI something that you wouldn’t want the person on the other side of the contract, dispute, etc. to see? Things like:

  • How can I edit this language to seem like I’m SOC2 compliant even if I’m not?

    fraud in the inducement claims against you get stronger

  • Help me edit this contract so I can copy the vendor’s technology

    creates bad faith claims and strengthens breach claims against you

  • What’s the best way to avoid FDA labeling requirements?

    convinces a regulator you’re a bad egg

  • What marketing technologies can help me track users across the web without them knowing

    makes that tracking tech lawsuit a lot more powerful

This becomes relevant if and when things end up in court. You may never face that. But as you grow more successful, the chances that someone takes you to court increase.

And in case that still sounds theoretical, here is what it looks like when it actually happens to a CEO.

In Fortis Advisors, LLC v. Krafton, Inc., C.A. No. 2025-0805-LWW (Del. Ch. Mar. 16, 2026), Krafton bought the studio behind Subnautica for $500M plus up to $250M in earnout. When it turned out the earnout was going to be huge, Krafton’s CEO went looking for a way out. Vice Chancellor Lori Will opens the opinion like this:

Fearing he had agreed to a ‘pushover’ contract, Krafton’s CEO consulted an artificial intelligence chatbot to contrive a corporate ‘takeover’ strategy.

Fortis Advisors, LLC v. Krafton, Inc. (Del. Ch. 2026)

The chats came out in discovery. ChatGPT produced a document titled “Response Strategy to a ‘No-Deal’ Scenario,” containing a “pressure and leverage package” and an “implementation roadmap by scenario.” The CEO forwarded it to Krafton’s Head of Strategy. Then, per the court: “At ChatGPT’s suggestion, Kim formed an internal task force, dubbed ‘Project X.’” And: “Over the next month, Krafton followed most of ChatGPT’s recommendations.” Krafton locked the studio out of Steam, exactly as recommended. It posted a message to fans that the court found false — a message the CEO suggested ChatGPT draft, with the stated goal of securing “legal validation of our legitimacy.”

Krafton lost. The studio CEO it fired got reinstated, the earnout clock got equitably extended by 258 days, and the court found Krafton’s stated reasons for the firings pretextual. The chat logs are why. They proved the sequence: he knew the earnout was hard to escape, and then went looking for cause.

Nobody had to break into anything. It was produced in ordinary discovery, quoted in a published opinion, and is now on the internet forever.

Four things people asked me that the original post didn’t cover

1. Work product is a separate thing, and it is where the interesting fight is.

Privilege and work product are two different protections. Privilege covers lawyer-client communications and is waived by disclosure to basically anyone. Work product covers material prepared in anticipation of litigation and is only waived by disclosure to an adversary, or in a way likely to get it into an adversary’s hands.

That distinction is doing almost all the work in the cases that came out after Heppner. On the very same day Rakoff ruled from the bench, a magistrate judge in Michigan went the other way in Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026), refusing to make a pro se plaintiff hand over her ChatGPT usage:

ChatGPT (and other generative AI programs) are tools, not persons, even if they may have administrators somewhere in the background.

Warner v. Gilbarco, Inc. (E.D. Mich. 2026)

Because, the court said, “the work-product waiver has to be a waiver to an adversary or in a way likely to get in an adversary’s hand.” A chatbot is not your adversary.

A federal court in Colorado went the same direction in Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026):

It is true that AI systems like ChatGPT, Claude, Gemini, and others widely available to the public, collect user data for training and other purposes. But in this Court’s estimation, that does not eliminate all expectations of privacy or automatically waive protections.

Morgan v. V2X, Inc. (D. Colo. 2026)

Courts in Texas and New York have since protected AI prompts and outputs as litigation-preparation material too — the New York court quashed a subpoena served directly on OpenAI seeking a party’s prompts and outputs. There’s a real split forming, and Heppner is starting to look like the outlier on work product.

Here’s why that should not make you feel better

Work product only exists once litigation is reasonably anticipated. It protects your trial prep. It does nothing for you on a Friday night when nobody has sued you yet and you’re asking whether you can fire the person with cancer. Every case protecting AI chats so far involved someone preparing for a lawsuit that already existed. The moment I’m actually worried about — the moment where you create the bad document — is squarely outside all of it.

2. Privilege is not a magic shield for asking your lawyer to help you deceive someone.

Fair point from the comments, and I agree. My SOC2 example probably isn’t privileged even if you ask your lawyer, because of the crime-fraud exception, which strips privilege from communications made in furtherance of a crime or fraud. The Supreme Court set the bar for getting a judge to look in United States v. Zolin, 491 U.S. 554 (1989), and it is not a high one: a showing “adequate to support a good faith belief by a reasonable person” that review might reveal evidence the exception applies. “The threshold we set, in other words, need not be a stringent one.”

Whether the SOC2 question specifically crosses that line is a genuinely hard question — asking your lawyer whether conduct is lawful is protected, asking your lawyer to help you accomplish a fraud is not, and the line between them is where the litigating happens. Which is itself a good example of how this whole area is more complicated than any blog post.

3. CC’ing your lawyer does not make something privileged.

This is the single most common misconception I see in founder email. Courts ask whether the communication was actually for the purpose of getting legal advice, not whether a JD was on the thread. The Second Circuit’s formulation in In re County of Erie, 473 F.3d 413 (2d Cir. 2007): “whether the predominant purpose of the communication is to render or solicit legal advice.” The D.C. Circuit’s somewhat friendlier version in In re Kellogg Brown & Root, 756 F.3d 754 (D.C. Cir. 2014) (Kavanaugh, J.), asks whether legal advice was “one of the significant purposes.”

Either way: the burden is on you, courts construe privilege narrowly because it hides relevant evidence, and good trial lawyers will fight to the death in discovery over every one of these. Adding your GC to a business email accomplishes nothing except making that fight more expensive.

4. Yes, it’s the same for Google, Slack, and texts.

Someone asked whether this applies to search history. It does. Any LLM chat has this issue — Gemini, Grok, whatever. For that matter, an email you send to a non-lawyer has this issue. The prosecutors in Heppner made exactly this point in their brief: if the defendant “had instead conducted Google searches or checked out certain books from the library to assist with his legal case, the underlying searches or library records would not be protected from disclosure simply because the defendant later discussed what he learned with his attorney.”

So basically: the same problem as any digital footprint. If you wouldn’t be comfortable seeing it printed as a headline, don’t type it unless it’s to your lawyer. That’s a hard bar, and none of us clear it every time. But the more you can avoid sending your worst moment onto the interwebs, the better.

But what about zero data retention? Or just deleting it?

I get asked about ZDR a lot now, usually by someone who wants me to say it solves the problem. It doesn’t, but it’s not nothing.

ZDR might help, in the sense that a scheduled, periodic, litigation-agnostic process for clearing data wholesale is a legitimate thing to have. The D.C. Bar is the only ethics authority I know of that names it directly, noting that a zero-retention policy is “one option that some GAI products provide to resolve confidentiality concerns,” and that paying business customers “may be able to negotiate better terms” than free-tier users. Courts have started writing those terms into protective orders — the Morgan court, for example, barred parties from putting confidential material into any AI tool “unless the AI provider is contractually prohibited from: (1) storing or using inputs to train or improve its model; and (2) disclosing inputs to any third party,” and required documentation proving the contract says so.

Three problems.

  1. I’m not clear that having a ZDR agreement actually results in true ZDR. It depends on the provider and your specific contract whether anything discoverable remains.

  2. ZDR gets you out of the retention problem but not the duty to preserve. When litigation begins — at the demand phase — you generally have a duty to preserve, even for data that would otherwise be swept up in a retention policy. That duty overrides your vendor’s deletion schedule.

    Ask OpenAI, which spent most of 2025 under a court order in the New York Times MDL directing it to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis,” notwithstanding its own product promises. That order was eventually lifted, but the court was careful to specify that Rule 37(e) preservation duties continue anyway — and OpenAI was separately ordered to produce 20 million de-identified consumer conversation logs, an order affirmed by the district judge in January 2026.

  3. If you said something you regret, deleting it ASAP is also a double-edged sword. Incomplete deletion whose residue gets discovered makes you look far worse than the original document. Look at footnote 185 in Fortis: “Kim admitted at trial that he had deleted specific, relevant ChatGPT logs. . . . This particular chat was deleted.”

    Nobody moved for spoliation sanctions and the court didn’t impose any. It didn’t need to. It had enough of the surrounding record — Slack messages, the strategy doc that survived — to write, a few pages later, that “Krafton’s witnesses lacked credibility.” You do not want to be the guy who deleted the chat and lost anyway.

They say that removing something from the internet is about as easy as removing urine from a swimming pool, and that’s pretty much the story.

Judge Alex Kozinski, The Dead Past, 64 Stan. L. Rev. Online 117, 124 (2012)

No matter what you do to get it out, it’s always there.

This is, FWIW, why lawyers love to call you on the phone instead of emailing you.

What to do about it

We’re all obviously going to be using LLMs when we face difficult situations. The more of the right context and background you give your favorite LLM, the more help it can be in law or anything else — and also the more likely you are to say something that could hurt you in litigation.

Here’s my suggested rubric, assuming you have some money for lawyers and interest in avoiding unnecessary downside risk:

  1. BEFORE you submit the tokens, ask yourself: “If this chat — OR ANY PART of this chat lifted out of context — were visible to the other side or the government, could that hurt me?”

  2. If yes, ask whether you can extract the part that would hurt you and still get as good an answer. If you can, extract it, and consider using what you extracted as the focus of a targeted, specific question to a lawyer that you craft using the rest of the answer.

  3. If you can’t get a good answer without the thing that makes you look bad — or that could make you look bad in some unknown future circumstance where everything has gone horribly wrong — and you really need to answer the question, you might want to bite the bullet on a lawyer for that particular question.

  4. New, post-Heppner: if you’re already in or anticipating a dispute, have your lawyer direct the AI use. Have them do it, or have them tell you in writing to do it and tell you what tool to use. That’s the only theory anyone has for getting protection, it’s the one Rakoff himself floated, and it costs you an email.

  5. Also new: use tools whose terms don’t say what Anthropic’s consumer policy said. Enterprise agreements with no-training and no-third-party-disclosure terms don’t create privilege — nothing does, outside a lawyer — but they knock out the specific reasoning that sank Heppner’s confidentiality argument. Keep a copy of the terms.

Related reading: Discovery — what it costs and why it is the largest box on our map of American civil litigation — and tracking-technology demand letters, the other way founders end up in a fight they did not start.

Where I think this goes

I said a few months ago that I expected the interesting new law to come out of Delaware, around AI use in transactions. I was half right. It came out of Delaware, and it was AI use by a CEO in a deal — but Fortis was a contract case, not a fight about whether counsel waived privilege by using a third-party tool. That fight is still coming. ABA Formal Opinion 512 says that “a client’s informed consent is required prior to inputting information relating to the representation” into a self-learning GAI tool — and that boilerplate in your engagement letter doesn’t count. The state bars have already split on how hard that requirement is. Oregon says flatly that for an open model, “lawyers must obtain their clients’ informed consent.” Texas is softer: a lawyer “should consider informing clients about the associated risks and may need to secure client consent.”

Nobody has litigated what happens when a lawyer gets it wrong. Someone will.

I also said I didn’t expect new law on privilege to give AI chats any new protection, and I’ll stand on that. The work product cases are real and they matter, but they protect litigation prep, not confessions. There’s still no legal or policy reason I can see for privilege to expand to cover a founder talking to a chatbot, unless a lawyer is in the loop.

The core advice hasn’t moved

AI doing legal is neither privileged nor free. If you’re getting an offer to pay $0 for legal work, understand what you’re actually paying.

Thanks for reading this PSA. Questions welcome.

Nothing here is legal advice, and there are about 6 million pages of law that can be more precise about this topic than I have been. I wrote this so people would read it, not to comprehensively cover an area that is going to keep changing as more cases come down. Cases cited are current as of August 2026 and none of them have been reviewed on appeal.

Cases and authorities cited

  • United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.)

    no privilege, no work product for a defendant’s self-directed Claude chats

  • Fortis Advisors, LLC v. Krafton, Inc., C.A. No. 2025-0805-LWW (Del. Ch. Mar. 16, 2026) (Will, V.C.)

    CEO’s ChatGPT strategy chats as the evidentiary spine of a pretext finding

  • Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026) (Patti, M.J.)

    ChatGPT exchanges protected as work product; motion to compel denied

  • Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026) (Dominguez Braswell, M.J.)

    work product preserved; no-training/no-disclosure terms written into the protective order

  • Jeffries v. Harcros Chemicals Inc., No. 25-2352-KHV-ADM (D. Kan. Mar. 25, 2026) (Mitchell, M.J.)

    protective order limiting all discovery material to “closed” AI tools

  • Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, No. 25-BC11B-0020 (Tex. Bus. Ct., 11th Div. June 3, 2026) (Dorfman, J.)

    a non-lawyer’s ChatGPT conversations may be work product under Tex. R. Civ. P. 192.5, which protects material prepared “by or for a party”; expressly disagrees with Heppner. Note: this is a minute entry following in camera review, not a final order, and the court ordered some of the material produced anyway

  • Assini v. Hayward, 2026 NY Slip Op 26086 (N.Y. Sup. Ct., Nassau Cty. June 4, 2026) (Fischer, J.)

    subpoena to OpenAI for a pro se party’s prompts, uploads, and outputs quashed

  • In re OpenAI, Inc., Copyright Infringement Litigation, No. 25-md-3143 (S.D.N.Y.)

    preservation order (May 13, 2025), terminated (Oct. 9, 2025), 20M-log production affirmed (Jan. 5, 2026)

  • United States v. Zolin, 491 U.S. 554 (1989)

    crime-fraud exception threshold

  • In re County of Erie, 473 F.3d 413 (2d Cir. 2007)

    predominant purpose test

  • In re Kellogg Brown & Root, Inc., 756 F.3d 754 (D.C. Cir. 2014)

    “one of the significant purposes” test

  • United States v. Kovel; United States v. Adlman, 296 F.2d 918 (2d Cir. 1961); 68 F.3d 1495 (2d Cir. 1995)

    counsel’s non-lawyer agents

  • United States v. Maher, 120 F.4th 297 (2d Cir. 2024)

    Google’s terms of service did not extinguish a reasonable expectation of privacy (Fourth Amendment; the best counter-authority to Heppner’s privacy-policy reasoning)

  • ABA Formal Opinion 512, Generative Artificial Intelligence Tools, July 29, 2024; ABA Formal Opinion 477R (2017)

    informed consent before inputting information relating to the representation

  • Alex Kozinski, The Dead Past, 64 Stan. L. Rev. Online 117 (2012)

    the swimming-pool line

  • D.C. Bar Ethics Opinion 388; Oregon Formal Opinion 2025-205; Texas Opinion 705, 2024; 2025; 2025

    state ethics guidance on generative AI and client consent — Oregon and Texas split on how hard the consent requirement is

We're lawyers, remember? Please read this important note:

Story LLP is a law firm, and Story's lawyers built Aegis to deliver better, standard legal services at scale so founders can choose between top-tier specialized lawyers and standardized process automations that replicate those lawyers according to their needs and budget. By definition, a standardized process may not be perfect for you. Please review our Policies page to better understand the difference, as well as how we use AI and how we manage conflicts, privilege, etc.


As a law firm, we must screen clients for conflicts of interest, and we treat all correspondence with clients seeking legal advice as privileged and confidential to the maximum extent possible in consideration of any conflicts. However, Story's law firm or our Attorney Allies do not represent you or your company as your lawyer, do not have an attorney-client relationship with you or your company, and do not provide you with legal advice absent a formal Engagement Letter signed between you and the Story LLP law firm. Please don't confuse the free knowledge we offer on this site with legal advice for you.