Privilege Lost in the Prompt: A Cautionary Tale About the Use of Generative AI
By Nicole Docherty | 06.15.2026 | Firm Post
A recent decision from the Southern District of New York, United States v. Heppner, serves as an important warning for clients, attorneys, and law firms navigating the growing use of generative artificial intelligence tools in legal matters. On October 28, 2025, Bradley Heppner was indicted for securities fraud, wire fraud, conspiracy, false statements to auditors, and falsifying corporate records, and pleaded not guilty on November 10, 2025. Upon Heppner’s November 2025 arrest, the FBI seized materials including about thirty-one documents memorializing his 2025 communications with Anthropic’s generative AI platform, Claude, created after a grand jury subpoena and while Heppner was under investigation. Heppner’s counsel asserted attorney-client privilege and work product protection over Heppner’s exchanges with Claude on the grounds that Heppner input information he learned from counsel and utilized Claude to facilitate obtaining legal advice and strategy, even though he was not instructed to do so by his counsel. The Court ruled that Heppner’s written exchanges with Claude are not protected by attorney-client privilege or the work product doctrine because the “communications” with Claude were not between client and attorney, nor were the prompts and communications prepared by Heppner’s attorney. Judge Jed Rakoff reasoned that Heppner voluntarily disclosed the information obtained from his attorney to a third party and, as a result, he lacked a reasonable expectation of privacy because, per Anthropic’s privacy policy, Claude may utilize those inputs for training and further disclosure to third parties.
This decision underscores the importance of discretion when using generative AI tools like CoPilot, ChatGPT, and Claude (to name a few). Information received from an attorney, including litigation strategy, privileged communications, or confidential business information, should not be uploaded into public, free versions of generative AI tools, or even some enterprise versions of these AI tools (if the enterprise versions allow for training or other uses of inputs), without first consulting counsel. Even well-intentioned attempts to develop strategy, summarize complex legal arguments, and test legal theories from an AI platform can create significant privilege and confidentiality risks. To put it in perspective, inputting sensitive legal information into Claude may be no different than discussing such matters on a busy elevator.
Heppner is not merely a cautionary tale for clients; this case also highlights an equally important reminder for attorneys and law firms. As clients increasingly use AI tools in their day-to-day lives, lawyers should consider discussing these risks with clients and/or adopting AI-usage policies. Law firms may wish to add provisions to their engagement letters expressly warning clients that the use of generative AI may waive confidentiality protections and privileges.
Let this serve as a stark reminder that privilege survives only so long as confidentiality does. The safest place for privileged legal communications remains where it has always been, between attorney and client.



