Your Client Told a Chatbot His Defense Strategy. Is It Still Privileged?

by | Sep 21, 2026 | Attorneys, Cell phones | 0 comments

Your client wanted an early start. What he handed over was an early Exhibit A.

Picture this: he knows he’s under investigation, but he’s anxious, he can’t sleep, and he wants to get ahead of the thing. So, he opens a chatbot at 1 AM and does what people do now: he talks, he types, he lays out his whole preferred theory of defense. He talks to his AI adviser about arguments that worry him and the facts he’d rather nobody saw. Thirty-one documents worth of them, as it turns out.

And then the FBI executes a search warrant, and those thirty-one documents come off his devices. Oh, no.

He says they’re privileged. The court says they’re not. Oh, double no.

That’s the short version of United States v. Heppner, decided in the Southern District of New York in February 2026. Judge Jed Rakoff held that a securities-fraud defendant’s conversations with a public AI tool (Anthropic’s Claude, as it happens) were protected by neither attorney-client privilege nor the work-product doctrine, and were fair game for the government to keep and cherish. Even if it was privileged when Heppner told it to attorneys, he waived the privilege when he disclosed it to Claude.

I’m a computer geek, not a lawyer, so I’ll stay out of the deep end on privilege doctrine. That’s your department, counselor. But the data side of this is my lane, and there’s a moral to the story.

“Come on. It’s just a fancy word processor.”blank

That was the argument, more or less, and the court didn’t buy it. See, a word processor doesn’t answer back. When your client types into a public chatbot, he isn’t just taking notes; he’s having a conversation with a third party. And sharing it with a third party can waive the confidentiality on which privilege depends.

It’s easy to forget that it’s not only that a human somewhere might read it. If you read the privacy policy on many consumer AI tools you’ll likely find that the provider reserves the right to log what you type, use it to train the model, and to hand it over to regulators or law enforcement when asked. And don’t even start with what happens to the data if and when another company buys the AI company.

He thought he was talking to a machine that forgets. Nope. Depending on the service, he was talking to one that remembers, transcribes, and keeps all the receipts.

“But he showed it to his lawyer afterward. Doesn’t that make it privileged?”

blankPrivilege isn’t a stamp you get to press onto a document after the fact. The court was clear that sharing a preexisting document with counsel later doesn’t reach back in time and wrap it in protection. The horse is already out of the barn and Elvis has left the room. Walking it past your attorney on the way out doesn’t reverse history and put them back.

 

Rakoff found work product didn’t save it either. Under the Second Circuit authority he applied, the documents weren’t prepared by or at the behest of counsel and didn’t reflect counsel’s strategy, but rather that he made these on his own initiative, before anyone told him to. No lawyer’s fingerprints on it and no protection.

“So AI is radioactive now. Great.”

blankWell, not quite. Judge third left a door open. He suggested that if counsel had directed the client to use the tool, the AI might function more like a lawyer’s agent, the way a translator, an e-discovery vendor, or a forensic examiner does when brought in under the attorney’s umbrella. Different setup, potentially different result.

So the line that matters isn’t “AI, yes or no.” It’s who’s driving, under what terms, with what confidentiality. A consumer chatbot your client opened alone, long before dawn, is one thing. An enterprise tool, deployed under counsel’s direction, with a contract that forbids training on your data and locks down disclosure, is a very different animal. Same technology. Different lock, different key.

What does a forensics guy care about any of this?

Well, because I’m the one who finds it.

When a device comes in for examination, at least a portion of chatbot histories could be just another artifact now, sitting right alongside texts, browser history, and deleted photos. They’re potentially recoverable, they’re timestamped, and they read like a diary. People unwittingly treat these tools as a confidant that won’t repeat what it heard. Whether the exam is for the defense or the prosecution, the evidence is the evidence. If it’s there, it’s there.

That cuts both ways, by the way. It isn’t only defendants who overshare with a chatbot. Witnesses do it. Executives do it. The person on the other side of your case may have a transcript on a laptop that’s every bit as revealing, and under Heppner, likely to be discoverable.

Human nature doesn’t change but tools do. People have always talked too much when they’re frightened or overconfident. What’s new is that the confidant now writes it all down and reserves the right to share it.

So, what to do?

A few practical points from the data side of the fence. The privilege calls stay with you.

Ask early. When you map a client’s devices and accounts, ask which AI tools they’ve used and what they typed into them. It belongs on the same checklist as their email, their texts, and their cloud backups.

blankLimit the AI. ChatGPT and Gemini have Temporary Chat, Claude and Perplexity have Incognito Chat. As of September, 2026 some of the limitations include:

  • ChatGPT Temporary Chat: not in ordinary history or memory and not used for training; OpenAI says a copy may remain for up to 30 days.
  • Claude Incognito: not saved to chat history or memory and not used for training, but Anthropic normally retains it for 30 days.
  • Gemini Temporary Chat: not in recent chats/activity and not used for training or personalization, but Google retains it for up to 72 hours.
  • Perplexity Incognito: memory and search history are disabled; current Perplexity documentation says incognito sessions can persist for 24 hours.

These limit what is saved to tool memory, reflection, model training bit are not any guarantee that there won’t be artifacts saved to the local device.

Assume it’s recoverable. “I deleted the chat” is not the same as “the chat is gone.” Treat a chatbot transcript like any other piece of ESI, because, by and large, that’s what it is.

Get people off the consumer tools. The cheapest fix is behavioral. A client who understands that typing his case into a public chatbot is like telling it to a stranger on a train tends not to do it in the first place.

Bring the tool inside the tent. If AI is going to be part of the work, the setup, including direction, terms, and confidentiality, is what may keep it protected. Structure it on purpose, not by accident.

I’ll leave the doctrine to the lawyers. But I’ll say this much. Heppner isn’t really a story about artificial intelligence. It’s the oldest story there is with a new gadget in it. Typing to a chatbot may be no more secure than telling your neighbor, “Don’t tell anyone, but…” Confidentiality has always been something you can give away without meaning to. The chatbot just made it easier than ever.

Have you started asking clients about their AI use when you map their devices? I’d be curious what you’re finding, and whether you’ve seen one of these transcripts turn up where nobody expected it.

Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.

Burgess Forensics: (866) 345-3345 | steve@burgessforensics.com

 

Related Posts

Auto-Delete, Take Two: Regulatory Fines Can Dwarf Sanctions

Deleting the messages was the cheap part. I recently wrote about sanctions: the adverse-inference instruction, the spoliation finding, the judge with disapproval written all over his face telling the jury it may assume the worst about whatever got erased. That's a...

The Fourth Amendment Meets the Fourth Dimension

The Fourth Amendment walks into the fourth dimension. The bartender says, “Why are you here?” The Fourth Amendment replies, “You’re going to need probable cause to ask me that.” In some of my earlier articles and videos, I referred to a “Fourth Amendment search”...

Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed

Your phone has been keeping a travel diary. For years, Google kept a copy too. That made possible one of the more controversial investigative tools of the smartphone era: the geofence warrant, sometimes called a reverse-location warrant. Instead of starting with a...

What Happens to Your Digital Life When You Die (And Who Can Access It)

By Steve Burgess, Burgess Forensics, 2026 “He passed last month, and his whole life is locked inside his phone. Can’t you just get in?” I hear some version of that rather often —more than you might think, in fact. The request comes from grieving families, from...

Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access

“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete....

The Metadata You Didn’t Know You Were Sending

You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren't looking. That paperwork is metadata — data about data. And it travels with your files whether or not...

Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having

The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: "produce as PDF, that's fine." Maybe not so fine when that same attorney later pays me to...

Why “He Deleted Everything” Is Usually Good News for Your Case

When a client or opposing party says "he deleted everything," attorneys often hear a dead end. I hear the opposite and you probably should as well. In digital forensics, deletion is rarely the end of the story. In fact, it may be the beginning of a better one. What...

Your Smart Home Is Testifying Against You

A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn't built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and...

The Future of Expert Testimony in a Digital World

Twenty years ago, a forensic report about a hard drive was mostly an argument about whether a file existed and when it was last touched. And of course, trying to recover deleted material. Today the same report might need to address whether a video is real, whether a...

Pin It on Pinterest

Share This