For law firms

Attorney-client privilege and AI chats: does using ChatGPT waive it?

Published 17 July 2026 · Updated 17 July 2026 · Occlira team

Putting privileged material into a public AI tool can waive attorney-client privilege — because it’s a voluntary disclosure to a third party. But the law is new and genuinely split: two US courts reached opposite results in the same month. The safe move isn’t to bet on how your court will rule — it’s to keep privileged material out of public AI and minimize what you send. This is general information, not legal advice.

Short answer. Privilege can be waived by voluntary disclosure to a third party, and a consumer AI provider that logs and may disclose your inputs can be that third party. US district courts have split (Heppner vs. Warner), so the question is unsettled. Don’t rely on privilege attaching — strip identifiers locally first, and keep privileged material off public AI.

Three protections people mix up

Before the AI question, it helps to separate three things that get lumped together:

ProtectionWhat it is
Attorney-client privilegeAn evidentiary rule: it can stop a court compelling testimony about confidential communications between a lawyer and client made to obtain legal advice. It’s about what you can be forced to disclose in litigation.
Work-product doctrineProtects materials a lawyer (or party) prepares in anticipation of litigation from discovery by the other side.
Duty of confidentiality (Rule 1.6)The broadest of the three — an ethics duty covering all information relating to the representation, “whatever its source.” It applies outside litigation and survives even after privilege is waived.

The waiver rule: disclosure to a third party

Privilege exists to protect confidential communications, so it usually falls away the moment you voluntarily share the communication with an outside third party. That’s the doctrine that makes AI risky: if a public, consumer AI provider counts as a third party, typing privileged content into it can be the disclosure that waives the privilege.

Is a public AI provider a “third party”?

This is the unresolved core of the debate. Consumer AI tools generally log prompts, may train on them, and can disclose them to others under their terms — none of which looks like a confidential relationship. A court could reasonably conclude there was no expectation of confidentiality, and therefore no privilege. But the law here is developing and fact-specific, with very little settled authority — so treat the following cases as early signposts, not rules.

What the courts have said so far — an early split

CaseWhat the court held
United States v. Heppner (S.D.N.Y., Feb 2026)Documents a criminal defendant created with the consumer version of Claude were protected by neither privilege nor work product. The court’s reasons: the AI “is not an attorney,” the consumer terms let the provider log, train on and disclose the data (so no reasonable expectation of confidentiality), and he used it on his own initiative, not at counsel’s direction. Reportedly a question of first impression — and expressly confined to its facts.
Warner v. Gilbarco (E.D. Mich., Feb 2026)The same month, the opposite result: a self-represented litigant did not waive work-product protection by putting information into ChatGPT, because the disclosure was “to an AI software,” not to a litigation adversary — “tools, not persons.”

Two non-binding district-court rulings, opposite outcomes, weeks apart — the question is one of first impression and unsettled. (Sources: Paul, Weiss on Heppner; International Bar Association on the split.) Notably, Heppner reserved the situation where a lawyer directs the use — where the tool might arguably act as the lawyer’s agent within the privilege. (Source: Covington.)

Confidentiality still applies — even if privilege never did

Privilege is only part of the picture. The ethical duty of confidentiality under Model Rule 1.6 is broader and applies regardless: inputting client information into a self-learning tool implicates it, and ABA Formal Opinion 512 says a client’s informed consent may be required first. So you can breach confidentiality by using AI even in a matter where privilege was never in play. We cover the ethics rules in ABA Formal Opinion 512, explained.

Won’t Rule 502 save an accidental disclosure?

Federal Rule of Evidence 502(b) can undo an inadvertent disclosure of privileged material in a federal proceeding — if the disclosure was inadvertent, you took reasonable steps to prevent it, and you promptly moved to fix it. (Source: FRE 502.) Deliberately typing privileged content into a public AI tool isn’t inadvertent — it’s a voluntary, intentional act — so the sound reading is that it falls outside that safety net. No court has squarely decided it, but don’t count on 502 to rescue you.

Your AI chats are discoverable — and can be preserved by order

Even setting privilege aside, prompts and outputs can end up in evidence. In the New York Times litigation, a court ordered OpenAI to preserve chat logs — including chats users had deleted — and later affirmed it must produce a 20-million-conversation sample. (Source: Bloomberg Law.) Once your data is on a provider’s servers, its retention and disclosure are outside your control. The one reliable fix is to keep client identifiers off those servers in the first place — minimize locally before anything reaches the tool. For how retention works, see does ChatGPT store your data?

How to protect privilege and confidentiality when using AI

  1. Don’t put privileged material or attorney work product into public, consumer AI tools.
  2. Minimize and anonymize/de-identify client information before any AI use.
  3. Check the tool’s retention, training and disclosure terms — prefer enterprise/no-training tiers or on-device tools.
  4. Get informed client consent where it’s required (see ABA Formal Opinion 512).
  5. Use AI at the lawyer’s direction and under supervision, with a written AI policy.
  6. Verify every output — and assume prompts and outputs could later be discoverable.
  7. Document the steps you took to protect confidentiality.
  8. Check your own jurisdiction’s rules — this area is genuinely unsettled.

How Occlira helps — keep privileged material off public AI

The through-line of every case above is disclosure: privilege and confidentiality erode when client material reaches an outside tool. Occlira attacks that at the source. It detects and removes client identifiers from Word, PDF, Excel, email, audio and images on your own computer — no cloud, no account — so the public AI never sees them. You anonymize a document locally, run any AI tool on consistent placeholders like <PERSON_1>, then restore the real values on your machine.

Occlira flagging client identifiers — names, an organization, dates, an address and a phone number — in a document for local review before a lawyer uses an AI tool.
Occlira strips the client identifiers from a document locally, so nothing privileged reaches a public AI tool.

Be clear on what this is: Occlira is a data-minimization tool that supports the Rule 1.6 step — not legal advice, and not a guarantee that privilege is preserved. Minimizing reduces the disclosure risk, but it doesn’t by itself decide privilege or remove your confidentiality and consent duties. The mechanics are in anonymize before ChatGPT.

Frequently asked questions

It can. Privilege protects confidential communications, so voluntarily disclosing them to an outside third party generally waives it — and a consumer AI provider that logs, trains on and may disclose your inputs looks a lot like that third party. But the law is genuinely unsettled: US district courts have split, so treat entering privileged material into public AI as a real waiver risk and avoid it.

There’s no settled answer yet. In United States v. Heppner (S.D.N.Y., 2026) a court held a defendant’s consumer-Claude documents were not privileged or work product; weeks earlier in Warner v. Gilbarco a different court protected a litigant’s ChatGPT work product. Two non-binding district-court rulings, opposite results — so don’t rely on privilege attaching.

Judge Rakoff (S.D.N.Y.) held that documents a criminal defendant made using consumer Claude were protected by neither attorney-client privilege nor the work-product doctrine — because the AI is not an attorney, the consumer terms defeated any reasonable expectation of confidentiality, and he used it on his own initiative rather than at counsel’s direction. The court expressly limited the ruling to those facts.

That’s the crux, and it’s unresolved. Because consumer providers can access, retain, train on and (per their terms) disclose your inputs, a court may treat the disclosure as breaking confidentiality — as Heppner did. A different court (Warner) saw the AI as a tool, not a person. Until it settles, the safe assumption is that public AI is a third party.

Privilege is a narrow evidentiary rule about compelled disclosure of lawyer-client communications. The duty of confidentiality (Model Rule 1.6) is much broader: it covers all information relating to the representation, applies outside litigation, and survives even after privilege is waived. So putting client data into AI can breach confidentiality even where privilege was never in play.

Probably not for deliberate use. FRE 502(b) can undo an inadvertent disclosure in a federal case if you took reasonable steps to prevent and to fix it. Typing privileged content into a public AI is a voluntary, intentional act — the sound reading is that it falls outside 502(b)’s inadvertence safety net, though no court has squarely decided it.

Yes — and they can be preserved by court order. In the New York Times litigation, OpenAI was ordered to preserve chat logs (including deleted ones) and later to produce a 20-million-conversation sample. Once your data is on a provider’s servers, its retention and disclosure are outside your control. See does ChatGPT store your data?

It might change the analysis — Heppner reserved that question, suggesting a tool used at counsel’s direction could arguably act as the lawyer’s agent within the privilege (a Kovel-style argument). Enterprise tools with no training and a confidentiality agreement present different facts too. But this is untested, so don’t treat it as a safe harbor.

It’s a strong safeguard. If the personal data never reaches the tool, there’s nothing for a third party to store or disclose. Just remember it’s not a complete answer to privilege or confidentiality — non-identifying facts can still be information relating to the representation — so anonymize and use your own judgment about consent.

Keep privileged material out of public AI

Strip client identifiers locally, then use any AI tool on the anonymized copy. Free for 14 days on Windows and macOS. This article is general information, not legal advice, and the law in this area is unsettled.

More: does ChatGPT store your data? · is ChatGPT safe for confidential data? · redact Word, PDF & Excel · how your data is handled