Your client wanted an early start. What he handed over was an early Exhibit A.
Picture this: he knows he’s under investigation, but he’s anxious, he can’t sleep, and he wants to get ahead of the thing. So, he opens a chatbot at 1 AM and does what people do now: he talks, he types, he lays out his whole preferred theory of defense. He talks to his AI adviser about arguments that worry him and the facts he’d rather nobody saw. Thirty-one documents worth of them, as it turns out.
And then the FBI executes a search warrant, and those thirty-one documents come off his devices. Oh, no.
He says they’re privileged. The court says they’re not. Oh, double no.
That’s the short version of United States v. Heppner, decided in the Southern District of New York in February 2026. Judge Jed Rakoff held that a securities-fraud defendant’s conversations with a public AI tool (Anthropic’s Claude, as it happens) were protected by neither attorney-client privilege nor the work-product doctrine, and were fair game for the government to keep and cherish. Even if it was privileged when Heppner told it to attorneys, he waived the privilege when he disclosed it to Claude.
I’m a computer geek, not a lawyer, so I’ll stay out of the deep end on privilege doctrine. That’s your department, counselor. But the data side of this is my lane, and there’s a moral to the story.
“Come on. It’s just a fancy word processor.”
That was the argument, more or less, and the court didn’t buy it. See, a word processor doesn’t answer back. When your client types into a public chatbot, he isn’t just taking notes; he’s having a conversation with a third party. And sharing it with a third party can waive the confidentiality on which privilege depends.
It’s easy to forget that it’s not only that a human somewhere might read it. If you read the privacy policy on many consumer AI tools you’ll likely find that the provider reserves the right to log what you type, use it to train the model, and to hand it over to regulators or law enforcement when asked. And don’t even start with what happens to the data if and when another company buys the AI company.
He thought he was talking to a machine that forgets. Nope. Depending on the service, he was talking to one that remembers, transcribes, and keeps all the receipts.
“But he showed it to his lawyer afterward. Doesn’t that make it privileged?”
Privilege isn’t a stamp you get to press onto a document after the fact. The court was clear that sharing a preexisting document with counsel later doesn’t reach back in time and wrap it in protection. The horse is already out of the barn and Elvis has left the room. Walking it past your attorney on the way out doesn’t reverse history and put them back.
Rakoff found work product didn’t save it either. Under the Second Circuit authority he applied, the documents weren’t prepared by or at the behest of counsel and didn’t reflect counsel’s strategy, but rather that he made these on his own initiative, before anyone told him to. No lawyer’s fingerprints on it and no protection.
“So AI is radioactive now. Great.”
Well, not quite. Judge third left a door open. He suggested that if counsel had directed the client to use the tool, the AI might function more like a lawyer’s agent, the way a translator, an e-discovery vendor, or a forensic examiner does when brought in under the attorney’s umbrella. Different setup, potentially different result.
So the line that matters isn’t “AI, yes or no.” It’s who’s driving, under what terms, with what confidentiality. A consumer chatbot your client opened alone, long before dawn, is one thing. An enterprise tool, deployed under counsel’s direction, with a contract that forbids training on your data and locks down disclosure, is a very different animal. Same technology. Different lock, different key.
What does a forensics guy care about any of this?
Well, because I’m the one who finds it.
When a device comes in for examination, at least a portion of chatbot histories could be just another artifact now, sitting right alongside texts, browser history, and deleted photos. They’re potentially recoverable, they’re timestamped, and they read like a diary. People unwittingly treat these tools as a confidant that won’t repeat what it heard. Whether the exam is for the defense or the prosecution, the evidence is the evidence. If it’s there, it’s there.
That cuts both ways, by the way. It isn’t only defendants who overshare with a chatbot. Witnesses do it. Executives do it. The person on the other side of your case may have a transcript on a laptop that’s every bit as revealing, and under Heppner, likely to be discoverable.
Human nature doesn’t change but tools do. People have always talked too much when they’re frightened or overconfident. What’s new is that the confidant now writes it all down and reserves the right to share it.
So, what to do?
A few practical points from the data side of the fence. The privilege calls stay with you.
Ask early. When you map a client’s devices and accounts, ask which AI tools they’ve used and what they typed into them. It belongs on the same checklist as their email, their texts, and their cloud backups.
Limit the AI. ChatGPT and Gemini have Temporary Chat, Claude and Perplexity have Incognito Chat. As of September, 2026 some of the limitations include:
- ChatGPT Temporary Chat: not in ordinary history or memory and not used for training; OpenAI says a copy may remain for up to 30 days.
- Claude Incognito: not saved to chat history or memory and not used for training, but Anthropic normally retains it for 30 days.
- Gemini Temporary Chat: not in recent chats/activity and not used for training or personalization, but Google retains it for up to 72 hours.
- Perplexity Incognito: memory and search history are disabled; current Perplexity documentation says incognito sessions can persist for 24 hours.
These limit what is saved to tool memory, reflection, model training bit are not any guarantee that there won’t be artifacts saved to the local device.
Assume it’s recoverable. “I deleted the chat” is not the same as “the chat is gone.” Treat a chatbot transcript like any other piece of ESI, because, by and large, that’s what it is.
Get people off the consumer tools. The cheapest fix is behavioral. A client who understands that typing his case into a public chatbot is like telling it to a stranger on a train tends not to do it in the first place.
Bring the tool inside the tent. If AI is going to be part of the work, the setup, including direction, terms, and confidentiality, is what may keep it protected. Structure it on purpose, not by accident.
I’ll leave the doctrine to the lawyers. But I’ll say this much. Heppner isn’t really a story about artificial intelligence. It’s the oldest story there is with a new gadget in it. Typing to a chatbot may be no more secure than telling your neighbor, “Don’t tell anyone, but…” Confidentiality has always been something you can give away without meaning to. The chatbot just made it easier than ever.
Have you started asking clients about their AI use when you map their devices? I’d be curious what you’re finding, and whether you’ve seen one of these transcripts turn up where nobody expected it.
Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.
Burgess Forensics: (866) 345-3345 | steve@burgessforensics.com
