Correction and update — September 11, 2026: The original article misstated the Heppner ruling date as February 6, 2024. The court ruled from the bench on February 10, 2026, and filed its written memorandum on February 17, 2026. This revision draws on that later memorandum and clarifies the decision’s scope. The article’s original February 14, 2026 publication date is preserved.

Large language models (LLMs) like ChatGPT have rapidly become confidants for legal questions, medical advice, mental health support, and other sensitive matters. Users often treat these AI tools as advisors, sharing intimate details and seeking guidance. This raises a novel question: should communications with an AI be protected by a legal privilege, akin to attorney-client privilege or doctor-patient confidentiality? In United States v. Heppner, a federal district court rejected attorney-client privilege and work-product protection for a defendant’s unsupervised Claude exchanges. That ruling, delivered on February 10, 2026 and explained in a February 17 memorandum, addresses a specific use of AI. The broader doctrinal, ethical, policy, and practical debate remains open.

The Heppner Case: A Defendant’s Unsupervised Claude Chats

In United States v. Heppner, the defendant used the publicly available Claude platform to prepare reports about possible defenses while under federal investigation. According to the memorandum, approximately 31 documents memorialized these exchanges. He later shared the material with his lawyers, who had not directed the searches. The documents were seized in an FBI search, and the court allowed government inspection after rejecting the asserted privilege and work-product protections.

Judge Jed S. Rakoff’s written memorandum found that the documents lacked at least two, if not all three, elements of attorney-client privilege. Its analysis addressed the relationship, confidentiality, and purpose of these communications.

First, the exchanges were between Heppner and Claude, rather than between Heppner and his lawyer. The court reasoned that Claude was not an attorney and that these exchanges did not themselves create an attorney-client relationship.

Second, the court questioned whether these unsupervised exchanges were for obtaining legal advice. It considered Heppner’s stated intent to consult his lawyers afterward, the absence of counsel’s direction, and Claude’s disclaimer. The memorandum expressly contemplated that counsel-directed use might be analyzed differently, as use of an agent assisting a lawyer. It did not decide that such a setup would necessarily be privileged.

Third, the court found no reasonable expectation of confidentiality under the circumstances. It relied on the Anthropic privacy policy before it, dated February 19, 2025, which described collecting inputs and outputs, using data for training, and possible disclosure to third parties. This was a finding about the platform and policy involved in Heppner, not a determination that every AI product or contractual arrangement has identical privacy terms.

Fourth, the defendant could not retroactively cloak the AI output in privilege by sending it to his attorney after the fact. Longstanding doctrine holds that pre-existing, non-privileged documents do not become privileged merely by sharing them with counsel.

The court also rejected work-product protection because Heppner acted on his own initiative and the documents did not reflect counsel’s strategy when created. The memorandum separately explained that sharing previously privileged information with Claude and Anthropic would waive protection under the circumstances it examined. These findings make the manner of using AI central: a later decision to send self-generated material to counsel did not supply the missing protections.

Heppner is a district court decision on the record before it. It should not be read as resolving every use of AI within a lawyer-client relationship. In particular, the opinion’s discussion of counsel-directed use leaves questions about attorney agents and different confidentiality arrangements for another case. The policy question below is broader than this holding: whether the law should create protection for some AI interactions even when traditional privilege requirements are not met.

Against this backdrop, we turn to whether the law should evolve to protect at least some AI interactions.

Should an “AI-Client” Privilege Exist?

The notion of an “AI-client privilege” (or extending existing privileges to AI communications) is deeply controversial. On one hand, AI tools increasingly perform functions similar to lawyers, doctors, or therapists, and users may expect privacy or even depend on these tools in lieu of professionals. On the other hand, privileges in law are exceptional rules, historically limited to certain fiduciary relationships and governed by strict conditions that AI simply does not meet. We explore both sides below, in contexts ranging from legal advice to medical and mental health counseling.

The Case for Protecting AI Interactions

Functional Equivalence and User Expectations

Proponents of an AI privilege focus on what users seek from a conversation: help with legal questions, emotional distress, or other sensitive matters. They argue that people who cannot afford professional services should not be ignored when designing privacy protections. That concern does not make an AI service equivalent to a licensed professional, and a chatbot conversation does not necessarily have no privacy protection at all. Contractual confidentiality, privacy law, and evidentiary privilege are different forms of protection. The policy debate is whether existing protections are adequate and, if not, which additional safeguards would help.

Encouraging Candor for Social Benefit

The core rationale of privileges is to promote candor in socially valuable relationships. Attorney-client privilege exists so clients will freely divulge the whole truth to their lawyers, enabling effective representation; doctor-patient and psychotherapist-patient privileges exist so people feel safe disclosing symptoms and traumas to get proper treatment. If AI platforms are the chosen confidant for millions of users, denying any protection could chill frank communication and deter individuals from seeking help on sensitive matters. Advocates note that many users naturally expect a degree of privacy with AI. They type personal questions into ChatGPT in the solitude of their home, often under the false impression it’s a private conversation. Recognizing some legal protection could align the law with reasonable user expectations and prevent a “dangerous illusion of privacy” from leading users to self-incriminate or expose themselves to legal risk. In this view, a narrowly crafted privilege for AI communications (for instance, limited to those seeking legal, medical, or therapeutic advice from an AI) might safeguard personal autonomy and encourage responsible use of technology, without waiting for users to learn confidentiality lessons the hard way.

Doctrinal Evolution - Privilege by Analogy.

Legally, supporters argue that courts have the tools to extend privilege to new scenarios. Federal Rule of Evidence 501 allows the privilege law to develop “in the light of reason and experience” on a case-by-case basis. History shows privilege doctrines can evolve when societal needs demand it. For example, the Supreme Court in Jaffee v. Redmond recognized a psychotherapist-patient privilege, noting it was widely adopted in the states and essential for effective therapy (confidentiality being “indispensable to treatment”). If interactions with AI come to mirror traditionally privileged communications, courts (or legislatures) could conclude that protecting them serves the same public good. Notably, attorney-client privilege already covers more than just direct lawyer-client talks; it can extend to some communications involving agents who facilitate legal advice, subject to the governing law and facts. Merely involving a third party or an insurer does not establish that protection. The “privilege follows the function, not the form.” If an LLM effectively functions as a legal research aide or translator for a client, one might argue it is analogous to a consultant assisting in the rendition of legal advice. In a scenario where an attorney directs a client to use a secure AI tool or where an AI is integrated into a law firm’s services, a court might view the AI as within the privileged circle (akin to the Kovel doctrine protecting communications through third-party experts). Likewise, in medicine, if a hospital uses an AI triage system as part of patient intake, communications through that system could be seen as part of the confidential medical consultation. The “functionalist” argument is that privilege law should focus on the purpose of the interaction, i.e., seeking advice or therapy, rather than the status of the listener as a human or machine.

Constitutional and Policy Considerations

Some commentators even ground the case for AI privilege in constitutional principles of privacy and fairness. They note that the Fourth Amendment protects the privacy of our digital data (e.g., the Supreme Court in Riley v. California recognized the vast privacy interests in cellphone contents), and argue that highly personal AI conversations deserve no less protection. The First Amendment could be implicated as well. The freedom to seek information or counsel (including from an AI) may require a degree of confidentiality to be meaningful. Additionally, the Fifth Amendment’s privilege against self-incrimination might be eroded if people’s confidential queries about their legal troubles to an AI can be subpoenaed and used against them. Practically speaking, it’s noted that technology can facilitate confidentiality: AI platforms could implement end-to-end encryption, data silos, or on-device processing such that communications truly remain secret unless the user consents. Technical protections can reduce disclosure risks, but they do not themselves create an evidentiary privilege or eliminate legal and operational risks.

Venice illustrates why product-specific terms matter. In its privacy documentation checked for this September 11, 2026 correction, Venice distinguishes several modes: an anonymous proxy can obscure identity while a model provider still retains content; other modes rely on zero-retention commitments or protected hardware. Those are the provider’s descriptions, not an independent security assessment. Users need to check the selected model and mode. A privacy feature, by itself, does not establish attorney-client privilege. Venice privacy modes

Proponents of LLM-privilege assert that clear legal protection for AI communications would also remove a barrier to innovation. Users and enterprises are currently wary of using AI for sensitive tasks due to legal uncertainty. Establishing a privilege (even a limited one) could foster beneficial uses of AI by assuring users that their private disclosures won’t boomerang against them in court. The pro-privilege camp contends that as AI systems increasingly act “in loco advisoris,” the law should catch up to protect those seeking guidance in this new way.

The Case Against an AI Privilege

Despite these arguments, many experts and authorities caution against extending privilege to AI communications under current conditions. The recent scholarly commentary is aptly titled “Against an AI Privilege,” contending that any new privilege here would be premature, unworkable, and doctrinally inconsistent. Several reasons underpin the skepticism:

Lack of a True Fiduciary Relationship

Attorney-client and psychotherapist-patient privileges center on protected professional relationships and their requirements of confidentiality. The attorney-client privilege protects a client’s communications with a licensed lawyer bound by ethical obligations and the law’s oversight; the psychotherapist-patient privilege protects dialogue with a trained therapist who has duties of care and confidentiality (and even legal obligations like Tarasoff warnings). In contrast, an AI system is not a person and not a fiduciary. The software is not a licensed professional subject to that professional’s disciplinary regime. Providers and deploying professionals may still have contractual, statutory, or professional obligations. The Heppner court emphasized the absence of an attorney-client relationship in the defendant’s direct exchanges with Claude. There is no decades-old bond of trust or ethical code between user and algorithm. Extending privilege to what is essentially a user and a commercial software tool would invert the rationale of privilege, shielding the tool (and its corporate owner) without the checks and accountability that justify withholding evidence. Critics argue that privileging AI communications would primarily “insulate providers and their systems from scrutiny” (entrenching corporate secrecy) rather than protecting a human relationship. This flips the usual equation at the public’s expense, given privileges impede truth-finding in court.

Absence of Confidentiality and Control

Confidentiality is a central obstacle to the proposed privilege. In Heppner, the court considered the provider’s collection, training, and disclosure provisions when finding that the defendant’s exchanges were not confidential. A service’s actual terms and technical arrangements therefore matter; a conversational interface alone does not establish confidentiality. From the opposing policy perspective, creating a privilege without reliable limits on retention and access could give users false comfort. That argument should be evaluated separately from whether a particular lawyer-directed use meets existing privilege requirements.

Historical Reluctance and “Human” Limits

Doctrinally, courts have been very hesitant to recognize new privileges. The Supreme Court repeatedly emphasizes that evidentiary privileges are not to be casually created or expansively interpreted, because they hide relevant facts from the justice system. Privileges emerge only when necessary to foster a socially beneficial relationship of trust, and even then usually after a consensus has developed (often via legislation or uniform practice in the states). For instance, the high court declined to create an “academic peer review” privilege in University of Pennsylvania v. EEOC, finding no sufficient basis in experience or policy. By contrast, the psychotherapist privilege in Jaffee was recognized only after nearly every state had adopted it and a clear public interest in confidential counseling was shown. In the case of AI, there is no comparably established tradition or consensus in law that AI deserves privileged status. If anything, Heppner and related decisions show the opposite. The argument that “many people treat AI as a confidant” is not enough. Courts do not grant privileges simply because communications feel intimate or commonplace; “ubiquity and intimacy are not the touchstones.” The key question is whether confidentiality is essential to a human relationship that society deems worth protecting. Without the relational “human anchor,” efforts to expand privilege have failed historically. An AI, no matter how conversational, cannot hold your hand, look you in the eye, or bear human accountability. The law’s bias (so far) is that privilege stops where the human professional connection ends. Critics maintain that any change to this principle is better left to legislatures to debate and define, rather than courts stretching old doctrines to fit AI.

Ethical and Policy Concerns

Opponents of AI privilege also raise broader policy concerns. Granting privileged status to AI interactions might inadvertently legitimize AI as a substitute for licensed experts, encouraging laypeople to rely on unregulated algorithms for life-affecting advice. This could be dangerous: unlike a lawyer or doctor, a public LLM has no duty of care and can produce errors or hallucinations with impunity. From an access-to-justice perspective, while AI can help fill gaps, it is not a panacea. Some scholars suggest energy would be better spent expanding access to human counsel or bolstering privacy protections, rather than inventing a privilege for AI. Additionally, a new privilege could be ripe for abuse. How would courts determine what counts as a privileged AI communication? A savvy litigant could try to shield inculpatory information by “chatting” about it with an AI and then claiming privilege. Policing the boundaries (e.g., only apply it when AI acts “like” a lawyer or therapist) would be complex and could bog down courts in line-drawing and technical inquiries. Heppner illustrates the risk of assuming that unsupervised legal research becomes privileged simply because a user later shares it with counsel. Expanding privilege to AI might open a floodgate of people attempting to classify casual computer interactions or research as off-limits in litigation, undermining the truth-seeking mission for marginal benefit. Finally, any such privilege could conflict with existing law on unauthorized practice: many jurisdictions forbid non-lawyers from dispensing legal advice. Anointing AI advice with privilege might contradict the principle that only licensed attorneys enjoy that legal protection.

Professional oversight and data protection also appear in regulation. Illinois’ August 2025 announcement describes a law restricting AI therapeutic decision-making while permitting specified administrative and supplementary support for licensed professionals. The ABA’s July 2024 Formal Opinion 512 directs lawyers to evaluate the confidentiality risks of particular generative-AI tools, along with competence, communication, and supervision duties. These sources address professional conduct and permitted uses; neither creates a general AI-user evidentiary privilege. Illinois announcement ABA Formal Opinion 512

Scholarly and Policy Perspectives

In his November 2025 essay Against an AI Privilege, Ira P. Robbins argues that the law should protect sensitive AI interactions through confidentiality requirements and enforceable data practices rather than a new category of evidentiary privilege. His objection centers on the professional relationships that justify existing privileges and on the risk of shielding providers from scrutiny. That is a policy argument about the appropriate form of protection, not a judicial holding about every AI workflow. Robbins’ essay

Robert Nogacki takes the opposing position in a July 2025 commentary. He argues that the function of sensitive AI conversations and unequal access to professional advice support developing a new privilege. He proposes incremental recognition under Rule 501 or legislation with narrow boundaries and exceptions. These are proposals for legal change, rather than statements that courts have already adopted an AI-user privilege. Their policy appeal must be weighed against the concerns about accountability, evidence, and actual confidentiality discussed above. Nogacki’s commentary

Heppner did not recognize a standalone AI-user privilege. Its reasoning emphasizes the relationship with counsel, the purpose of the communications, and confidentiality under the facts before the court. It does not establish a nationwide rule for every AI-assisted legal workflow. The practical question is whether a particular use meets existing legal requirements, rather than whether a tool is simply labeled an AI assistant.

Should interactions with AI models receive an evidentiary privilege of their own? That remains a policy question. Heppner demonstrates why users cannot assume that independent conversations with a public chatbot receive the protections associated with professional advice. It also leaves room to examine materially different arrangements involving counsel. A useful debate must distinguish a proposed new AI-user privilege from the application of existing protections to a particular workflow.

Learn more about the issues presented by ground breaking AI tools and their impact on the practice of law.

Infinite Counsel book cover, by Jonathan Nessler

Infinite Counsel helps lawyers understand how AI is impacting the practice of law.