Site icon Edplatza Blogs

When Thinking Becomes Evidence

Legal and AI Literacy

When Thinking Becomes Evidence

The AI Prompt That Entered the Courtroom

Shakti Anand

Founder, EdPlatza  ·  MBA – Chicago Booth  ·  FCS – ICSI


A February 2026 US federal ruling is forcing organisations to rethink how sensitive reasoning happens inside AI systems. What many employees experience as private thinking through a conversational tool may increasingly be treated, in at least some contexts, as part of the institutional record.


What This Case Is, and Is Not, About.

The question in Heppner was not whether Anthropic improperly disclosed anything, or whether AI companies are reading user conversations. The question was narrower: when a person shares sensitive information with a consumer AI platform, does that act of sharing affect the confidentiality analysis that privilege doctrine requires? Privilege protects confidential communications from being forced into court.

The Case

United States v. Heppner

In February 2026, Judge Jed Rakoff of the Southern District of New York issued what Harvard Law Review described as addressing “a question of first impression nationwide.” ¹. The case is United States v. Heppner. ²

Bradley Heppner, founder and former Chairman of Beneficient and former Chairman of GWG Holdings, was indicted in October 2025 on charges including securities fraud, wire fraud, conspiracy, and falsification of records arising from an alleged scheme to defraud investors. After retaining legal counsel and receiving a formal legal demand from investigators, he used Anthropic’s consumer version of Claude, on his own initiative and without direction from his lawyers, to draft 31 documents covering potential defence strategies, anticipated legal arguments, and factual analyses connected to the prosecution’s case. Some of what he typed had been received directly from counsel. He later shared the outputs with his legal team.

During a search warrant execution at his home, the FBI seized his devices. His defence team asserted legal professional privilege and work-product protection over the AI documents. Judge Rakoff ruled that all 31 documents were not privileged and ordered their production to the prosecution. ³

Heppner suggests courts may increasingly focus less on what users believe an AI tool is, and more on how the platform is actually designed and governed.

Three Grounds, One Ruling

How the Court Reached Its Decision

Sr. Ground Court’s Reasoning
I No Lawyer–Client Relationship Claude is not a lawyer and cannot provide legal advice. No lawyer–client relationship existed. That foundational condition for privilege was absent.
II No Confidentiality Heppner entered sensitive information into Anthropic’s consumer platform, whose terms at the time permitted collection of user inputs, model training and disclosure in certain circumstances. The court concluded that, by voluntarily sharing information under those terms, he had disclosed it to a third party outside any protected relationship. That was sufficient to undermine confidentiality.
III Intent Assessed at the Moment of Input Intent is assessed at the moment of input, not on later transmission. Sharing outputs with counsel after the fact cannot retroactively create privilege.

Early Judicial Opinion: Not Settled Law.

This article examines one US district court decision based on its specific facts. Another court has already reached a different conclusion, and no appellate court has established a general rule. The law in this area remains unsettled.

Beyond the Courtroom

Why the System You Use Matters, Not Just What You Type

This is where the ruling becomes relevant beyond courtrooms. The question is no longer only what you type into an AI tool. It is what system receives it, under what contractual terms, what data arrangements, and what professional governance. Three contexts appear materially different from the Heppner facts.

Enterprise AI Under Contract

Enterprise agreements can include no-training provisions, confidentiality obligations, and zero data-retention terms. Whether those safeguards change the confidentiality analysis has not yet been tested in court. The Heppner reasoning was tied directly to Anthropic’s consumer-tier terms, suggesting a contractually isolated deployment presents a different factual picture. ⁴

Internally Deployed AI

Some organisations run AI within their own infrastructure, without data flowing to a third-party vendor. Where this is properly configured, the core concern in Heppner is materially reduced. Internal systems can still raise issues around logging, internal discoverability, employee access, and backup exposure, but the specific third-party disclosure concern at the centre of Heppner may not arise in the same way.

AI Used Under Professional Direction

Judge Rakoff left one notable opening. In certain circumstances, a third party brought in to support a lawyer’s work, such as an accountant or a technical expert, can be treated as part of a protected professional relationship when acting under that lawyer’s direction. ⁵ The court indicated the outcome might have been different had Heppner’s counsel directed him to use Claude as part of their strategy. This distinction, individual improvisation versus a supervised professional workflow, carries the most doctrinal weight across both decisions issued that week.

Divergent Outcomes

The Case That Went the Other Way

Interestingly, a federal magistrate judge in the Eastern District of Michigan reached a different conclusion. In Warner v. Gilbarco, a self-represented litigant’s ChatGPT-related materials were treated as protected work product. The court characterised AI as “tools, not persons.” Critically, the court held that work-product protection is waived only by disclosure to an adversary, not merely by using a public AI platform.

Two Courts. Divergent Outcomes. The Law Remains Unsettled.

White & Case observed that Heppner and Warner together show how materially different privilege outcomes can follow from how, not merely which, AI tool a party uses, and critically, under what context and doctrine. ⁴

The Harvard Law Review criticised the Heppner opinion for adopting an approach that risks categorically excluding clients’ use of generative AI from attorney-client privilege, and argued that future courts should instead adopt a more fact-specific, case-by-case analysis. Future courts may draw narrower lines. No appellate court has yet established a general rule governing consumer AI and privilege.

A Fair Picture

Counterarguments Worth Acknowledging

Some legal scholars argue that a privacy policy most users have never read should not alone determine whether a confidentiality expectation was reasonable. Others contend that enterprise AI environments with strict contractual controls should be treated categorically differently, not merely as a factual variation.

Curl and Kshrisagar, writing in Lawfare, argued that the ruling placed unusually significant weight on contractual privacy terms, a reliance that, if sustained, would give corporate terms of service a level of doctrinal authority they have not historically held. ⁶ These remain live objections.

What This Does Not Mean

Five Common Misconceptions

All AI use destroys privilege. The ruling is fact specific. Consumer AI, self-directed, on a platform with permissive data terms: that combination drove the outcome.
Enterprise AI faces the same analysis. Contractually isolated deployments with no-training terms present a different factual picture. No court has yet ruled on this directly.
AI vendors are reading your conversations. Heppner was not based on evidence that Anthropic read the conversations. It focused on the fact that the platform’s terms permitted access to and use of user data.
Courts have reached consensus. Heppner and Warner reached different conclusions, reflecting early judicial thinking rather than established law.
AI is inappropriate for sensitive professional work. Heppner does not suggest that AI is always inappropriate for sensitive professional work. It suggests that legal risk depends on how AI is used.

What It Does Suggest:

Heppner suggests courts may evaluate AI use by examining platform design, contractual structure, and professional supervision, not merely by the category of information involved. That shifts the question from “What did I type?” to “What system received it, and under whose governance?”

Practical Guidance

Four Changes Worth Considering Now

1 Audit Tool Design by Sensitivity Tier Consumer AI terms typically permit data collection, training use, and third-party disclosure. Enterprise tools, when properly contracted, can restrict all of this. Legal and IT need to be in the same room on this decision.
2 Classify Information Before Prompting Different information types carry different risk profiles. Decide what category something falls into before you type it, not after you have the output.
3 Establish Direction and Documentation for High-Stakes Use Whether AI use was directed or improvised is legally material. Who approved the tool, for what purpose, under what data terms: if you cannot answer these, that is the governance gap.
4 Check Your Profession’s AI Guidance Regulators and industry associations aren’t waiting. A recent New York State Bar Association publication urged attorneys/lawyers to alert clients to the risks of using consumer AI tools in legal matters. Similar guidance is emerging in finance, healthcare, and education. Waiting for an incident to prompt review is itself a risk posture.

Framework

A Five-Question Framework for Using AI in Sensitive Contexts

Derived from the Heppner and Warner reasoning.

Sr. Layer Question What This Reveals
1 Content Sensitivity What am I putting in? Legally sensitive or regulated information entered into a consumer platform without governance replicates exactly the conditions in Heppner.
2 Platform Design Where does the prompt go? Platform design and contractual terms are now part of the legal analysis, not just the content of what you type.
3 Direction & Authority Who authorised this? Individual improvisation, without professional direction or a documented workflow, is what created Heppner’s exposure.
4 Retention & Access Who can retrieve this? Retention policy is confidentiality policy. If you do not know your vendor’s data retention terms, you do not fully know your exposure.
5 Consequence Could this matter in a dispute? Ask whether you would be comfortable if the prompt were later seen by a regulator or opposing party. Confidentiality is assessed at the moment of input.

The Operative Question Has Changed.

“Can this tool help me with this task?” has become: “Which system receives it, under what contractual terms, under what data arrangements, and under what governance?”

Looking Ahead

Where This Is Heading

Heppner is one ruling. It will not be the last. The direction of reasoning, applying existing confidentiality doctrine to AI platform design without creating new law, is beginning to take shape even at this early stage.

Early judicial treatment suggests courts may place substantial responsibility on users and institutions to understand how AI systems are contractually and technically structured. That is a different kind of literacy than most organisations have yet built. It is not one that vendor marketing will supply.

No appellate court has yet established a general rule. The case most likely to shape doctrine next is the one Judge Rakoff explicitly left open: a represented party using AI under attorney direction and with proper enterprise-grade contractual controls. Until that question is resolved, the prudent posture is to treat platform design and professional oversight not as compliance details, but as legally material facts.

The question is not whether to use AI for sensitive work. It is under what platform setup, under what contract, and under whose professional oversight.


References & Sources

Cited Works

[1]  Harvard Law Review, “United States v. Heppner,” March 23, 2026

[2]  United States v. Heppner, 25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026 written opinion; Feb. 10, 2026 oral ruling)

[3]  Reuters, “AI Ruling Prompts Warnings from US Lawyers: Your Chats Could Be Used Against You,” April 15, 2026

[4]  White & Case, “Attorney-Client Privilege and Work Product in the Age of Generative AI,” April 23, 2026

[5]  United States v. Kovel, 296 F.2d 918 (2d Cir. 1961)

[6]  J. Curl, M. Kshrisagar, Lawfare, “AI and Privilege After United States v. Heppner,” March 30, 2026


Editorial Intelligence · edplatza.com

Not legal advice. For educational purposes only.

Shakti Anand

Founder, EdPlatza · Chicago Booth MBA · FCS-ICSI

Written in a personal capacity.

The views expressed are solely those of the author and do not necessarily reflect the views of any current or former employer, client, or affiliated organisation.

Exit mobile version