United States v. Heppner: what the first AI-privilege ruling actually held
In February 2026 a federal court in New York became the first to rule on whether a person's chats with a public AI tool are privileged. The answer, on the facts, was no. The case is worth understanding in full, because the reasoning is simpler and more portable than the headlines suggest.
A defendant used the consumer version of a well-known chatbot, on his own initiative and without his lawyers' direction, to prepare analyses of his own defense. He later shared them with counsel. When investigators recovered the files, he claimed attorney-client privilege and work product. The court rejected both.
The privilege claim failed on the threshold: an AI tool is not an attorney, and a privileged communication runs between a client and a lawyer. It failed again on confidentiality, because the consumer-tier terms let the provider retain the data, train on it, and disclose it to third parties, so submitting it was treated as disclosure. The work product claim failed because the defendant, not counsel, prepared the material.
Two things keep the ruling narrow, and an honest reading has to say so. It turned on consumer-tier terms, and the analysis shifts when a platform's terms forbid training on and disclosure of customer data. And the privacy-policy characterization was contested, since current terms include opt-out language. Read it as fact-specific, not as a rule that AI and privilege cannot coexist.
The court also left a door open. Had counsel directed the use, the tool might have acted as a professional agent under the Kovel line, and the analysis could have differed. And it did not decide the scope of any waiver, which is the part that should worry practitioners most, because a single upload of counsel-derived information might reach the underlying conversations with the lawyers themselves.
The same day, a court in Michigan went the other way for a self-represented litigant, holding that AI programs are tools, not persons, so documented use tied to litigation prep kept work product protection. Together the two cases describe a spectrum: unsupervised consumer use at one end, counsel-directed and documented use in the middle, and, at the strongest end, use where the document never reaches a third party at all.
That last position is an architectural one, and it is the reason we built RedactLocal. It finds the identifying details in a document, the names, the parties, the numbers, and replaces them on your own machine before anything is sent to a model. The model works on placeholders, the real values are restored locally, and the document never leaves your computer. There is no third-party disclosure to argue about, because nothing was transmitted.