Is an AI chat privileged? Legal professional privilege and generative AI after the 2026 rulings
Within seven days in February 2026, two United States federal courts reached opposite results on whether what a litigant typed into a chatbot could be demanded by the other side. A week later the Upper Tribunal in London published a warning that uploading client letters into a public AI tool waives privilege. In June an examining magistrate in Rotterdam wrote the first Dutch reasoning on the point and handed ChatGPT conversations to the prosecution. None of these decisions changes the law of privilege. All of them show what happens when a rule written for people is applied to software that stores what it is told.
The short answer: a chatbot's answer is never privileged, because privilege protects a relationship with a lawyer rather than legal content. Whether material that was already privileged survives being pasted into an AI tool depends on one fact: was the tool inside the circle of confidentiality or outside it? A consumer app whose terms allow retention, training and disclosure is outside it. A tool the firm controls, under a contract that binds the provider to secrecy, limits it to what it needs and forbids training, can be inside it. Most of what a firm must do follows from that distinction, and most of the damage so far has been done by clients, not lawyers.
Three questions that are being asked as one
"Is my AI chat privileged?" is the search query. It hides three legally distinct questions, and a firm that answers them together will get at least one of them wrong.
- Is the chatbot's output privileged advice? No, in every jurisdiction discussed here. Privilege exists because the law protects consultation with a member of a regulated profession who owes a duty of secrecy and can be disciplined for breaching it. Software satisfies none of those conditions, however good the answer.
- Does putting privileged material into an AI tool destroy the protection it already had? This is the question the 2026 decisions actually decided, and the answer turns on confidentiality. If the disclosure was to a party outside the protected circle, the protection is at risk. If the tool sits inside the circle, it is not.
- Does a lawyer breach professional secrecy by using an AI provider? This is a question about the lawyer's own conduct under the rules of the profession and, in some countries, the criminal law. It is governed by provisions on service providers that existed long before generative AI, and they are more precise than most firms assume.
The first answer is easy. The second and third are where the work is, and they are governed by different rules in the Netherlands, Germany, France and the common-law world. What follows takes the decisions first, then the European framework, then the controls.
What the courts decided in 2026
United States v. Heppner: a consumer chatbot is a third party
Bradley Heppner, the former chairman of a listed company, was indicted in the Southern District of New York on 28 October 2025. After becoming aware of the investigation and before the indictment, he used the consumer version of a well-known assistant to work through the facts and legal issues of his case, incorporating information he had received from his lawyers and producing documents he then shared with them. The FBI obtained those documents when it executed a search warrant. Judge Rakoff ruled orally on 10 February 2026 and issued a written opinion on 17 February that the material was protected neither by attorney-client privilege nor by the work-product doctrine (1).
The court gave three reasons. The assistant is not an attorney, and privilege requires a trusting relationship with a professional who owes fiduciary duties and is subject to discipline. The communications were not confidential, because the provider's privacy policy told users that inputs could be retained, used for training and disclosed to third parties including governmental authorities. And the documents were not made to obtain legal advice from counsel; they were made by the defendant of his own volition and shared with counsel afterwards. Work product failed for the same last reason: the documents were not prepared by or at the behest of counsel (1).
Two things the court did not say matter as much as what it did. It did not hold that using generative AI waives privilege as such. And it left open, through the long-standing Kovel line of authority on agents who assist a lawyer, that a tool used at counsel's direction, under terms that preserve confidentiality, could be treated differently. Commentators on both sides of the Atlantic have read the opinion as turning on the consumer terms, not on the technology (2).
Warner v. Gilbarco: a tool, not a person
A week earlier, on 10 February 2026, the Eastern District of Michigan had reached what looks like the opposite conclusion. A self-represented employment claimant admitted using ChatGPT to answer legal questions and draft filings. The defendants asked for her prompts and the responses. The court refused. Work-product protection, it reasoned, is waived only by disclosure to an adversary or in a manner that makes such disclosure likely, and an AI platform is a tool rather than a person to whom something can be disclosed (3).
The two decisions are reconcilable, and the reconciliation is the most useful thing a European lawyer can take from them. Attorney-client privilege is destroyed by disclosure outside the confidential relationship. Work product is destroyed only by disclosure to the opponent. The same chat can therefore lose one protection and keep the other. A client's own case preparation in a chatbot may remain protected as litigation work; the lawyer's advice that the client pasted into the same chat may not.
The Upper Tribunal: client letters in a public tool are in the public domain
In joined immigration cases heard in October and November 2025 and published on 19 February 2026, the Upper Tribunal dealt mainly with fictitious authorities generated by AI. It added a passage on confidentiality that has been quoted ever since. Putting client letters and Home Office decision letters into an open AI tool such as ChatGPT, the tribunal said, is to place that information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege; a regulated professional who does so should inform their regulator and consult the Information Commissioner's Office. The tribunal contrasted closed tools that do not place information in the public domain, which it said are available for tasks such as summarising without those risks (4).
Practitioners have rightly questioned whether "public domain" is the precise legal description of a submission to a provider's servers. The point survives the criticism. Under English law both legal advice privilege and litigation privilege require confidentiality, and the tribunal's warning is a statement by a senior court that a public consumer tool does not supply it.
Rotterdam: entering privileged information into ChatGPT is a disclosure
The Dutch decision is procedurally modest and substantively the most direct. During a filtering exercise under article 98 of the Code of Criminal Procedure, an examining magistrate in Rotterdam had to decide which data seized from a suspect's phones and laptop had to be withheld from the investigation team as privileged. Among the data were ChatGPT conversations in which the suspect had used a prompt to draft a message evidently intended for a person entitled to privilege, and the generated text named that person (5).
The magistrate's reasoning began from the rationale of the privilege: the public interest in finding the truth must yield to the public interest that everyone can turn freely to certain professionals for help and advice without fear of what they confide being disclosed. An external AI system stores both the entered and the generated information and can use it, for example, to train the model. Entering potentially privileged information into ChatGPT, and having it generate a text intended for a privilege-holder, can therefore be regarded as making that information public. That breaks its confidentiality, so it loses its confidential character and can no longer be treated as privileged. The ChatGPT conversations that search terms had flagged were re-marked as not privileged and released to the investigation team and the prosecution, subject to the access controls of the forensic platform through which the data are viewed (5).
A record of findings by an examining magistrate binds nobody but the parties to that investigation. It is nonetheless the first published Dutch reasoning on the question, it was reached under the framework the Supreme Court laid down in March 2024 for handling privileged data in seized digital material (6), and it was reached about a suspect's own conduct, not a lawyer's. That last point is the pattern across all four decisions.
Why the European question is different from the American one
American commentary speaks of waiver: privilege is a right that its holder can lose by careless disclosure. The continental systems in which LexVera's readers mostly practise are built differently. The protection belongs primarily to the professional, takes the form of a duty of secrecy backed by a right to refuse evidence and a bar on seizure, and extends to a defined circle of people who assist the professional. Three consequences follow for AI.
First, the question whether a client's own chatbot drafts are protected is narrower than in the United States. Protection attaches to communications with the professional and to what the professional holds in that capacity. A client's preparatory notes may fall within the protected sphere when they are made for the purpose of the consultation, and the Rotterdam decision shows that a draft of a message to a lawyer was at least a candidate. But the client has no free-standing privilege over their own legal reasoning of the kind the Michigan court recognised as work product.
Second, the decisive issue for a firm is whether the AI provider is inside or outside the circle of persons the law allows the professional to involve. That is a question of statute and contract, and each system has answered it.
- Netherlands. Article 11a of the Advocates Act imposes the duty of secrecy on the advocate and, in the same sentence, on employees and staff and on other persons involved in the practice of the profession (7). Rule 3 of the Rules of Conduct restates it. The right to refuse evidence in article 218 of the Code of Criminal Procedure and article 165(2)(b) of the Code of Civil Procedure, and the seizure restrictions in article 98 of the Code of Criminal Procedure, protect what is held in that capacity, and Supreme Court case law recognises a derived privilege for persons whose assistance the advocate needs. Whether an AI provider is one of the "other persons involved" is exactly the question a firm's contract and configuration must answer (8), and the Dutch bar's AI recommendations ask every firm to settle it in a firm-wide AI policy that clients are told about (22).
- Germany. The duty of secrecy in section 43a(2) of the Federal Lawyers' Act is backed by section 203 of the Criminal Code, which criminalises unauthorised disclosure by lawyers and, since 2017, also by the persons who assist them. Section 203(3) allows disclosure to such assisting persons so far as necessary for their contribution, and section 43e of the Federal Lawyers' Act sets out what that requires: careful selection of the provider, a contract in text form containing a secrecy undertaking with a warning of the criminal consequences, purpose limitation, rules on further subcontractors, and, for providers abroad, protection comparable to domestic protection (9) (10). The Federal Bar's guidance on AI, current at December 2024, applies that scheme to language models expressly: only abstract prompts where possible, full anonymisation before any upload, and the observation that removing names is not enough when the matter can be inferred from context. It adds that the offence of disclosure does not require the provider actually to read anything; the possibility of access suffices (11).
- France. Article 66-5 of the Law of 31 December 1971 provides that in all matters, whether advice or defence, consultations sent by a lawyer to the client, correspondence between them, meeting notes and, more generally, all the pieces of the file are covered by professional secrecy (12). The National Bar Council's rules describe that secrecy as a matter of public order, general, absolute and unlimited in time, and breach is an offence under article 226-13 of the Criminal Code. On 17 March 2026 the Council adopted a guide on professional ethics and artificial intelligence which asks lawyers to keep intellectual control and responsibility over their work, not to transmit client or file data to a generative AI tool, to anonymise before any use, to check where data are hosted and to inform clients (13).
Third, the constitutional floor is higher than the American one. The Court of Justice has held, in the DAC6 case in December 2022 and again in the Luxembourg tax-advice case in September 2024, that Article 7 of the Charter guarantees the confidentiality of a lawyer's advice as to both its existence and its content, and that a person who consults a lawyer may reasonably expect that confidentiality to be respected save in exceptional situations (14) (15). The European Court of Human Rights has treated the professional secrecy of lawyers as a component of the right to respect for private life and correspondence since Michaud v. France (16). The Akzo Nobel limitation of privilege in EU competition proceedings to independent lawyers is a reminder that the protection follows the professional status of the human, which is precisely why it cannot follow software (17).
What the terms of the tool actually say
Every decision above turned on a factual premise: the tool stores what it is told and may use or disclose it. That premise should be checked against the terms in force rather than assumed, because the terms differ sharply between consumer and business tiers and they change.
The largest consumer assistant uses content from its free and individual paid plans to improve its models unless the user turns that off in settings, and states that its business, enterprise and API products are not used for training by default (18). Another major provider announced on 28 August 2025 that users of its consumer plans would be asked to choose whether their chats may be used for training, with retention extended to five years for those who agree and thirty days for those who do not, while its work, enterprise, API and government offerings were excluded (19). Deleted consumer conversations are generally removed within thirty days, but litigation can intervene: in the copyright proceedings against the largest provider, a New York federal judge affirmed on 5 January 2026 an order requiring production of a sample of twenty million de-identified consumer conversations to the plaintiffs, and an earlier preservation order had suspended routine deletion for several months in 2025 (20).
The lesson is not that one provider is safe and another is not. It is that the confidentiality analysis depends on the tier, the settings, the contract and the litigation posture of the provider at the time of use, and that a firm which cannot state those facts for each tool its people use cannot state whether the circle of confidentiality has been kept.
The client-side problem, and a new intake duty
Read the four decisions again and one fact stands out. In New York, Michigan and Rotterdam, the person who put material into a chatbot was the client or suspect, not the lawyer. In London it was a representative, but the risk described was generic. The largest exposure for a firm in 2026 is therefore not its own tools. It is a client who, between receiving advice and the next meeting, pastes the advice into a free assistant to understand it, to draft a reply, or to check whether the lawyer is right.
That conduct is natural, it is common, and nothing in the engagement letter of most firms addresses it. Three responses are proportionate.
- Tell clients at intake, in writing. A short paragraph in the engagement letter or first-advice email explaining that advice and correspondence must not be entered into public AI tools, and why, costs nothing and changes behaviour. In criminal and regulatory matters, where seizure is a realistic prospect, say it orally as well.
- Offer an alternative. Clients use chatbots because they want to understand. A lawyer who explains advice in plain terms, or who offers to answer questions by message, removes the incentive. Where the firm has a controlled AI environment it may, in appropriate matters, be able to let the client work within it.
- Where the client will use AI anyway, direct it. In common-law matters the difference between Heppner's documents and protected ones was counsel's direction. A written instruction from the lawyer to prepare a chronology or a list of questions, using a tool the firm has approved, for the purpose of the lawyer's advice, is the structure that keeps the material inside the relationship. It is also the structure that keeps it within the protected sphere in continental systems, because it makes the client's work part of the consultation.
Seven controls for the firm's own use
The controls below are drawn from the German statutory scheme, which is the most detailed, and they satisfy the Dutch and French requirements as well. They are ordered from the decision a firm makes once to the habits it must maintain every day.
1. Classify tools into three tiers, and say which is which
Public consumer tools, whose terms permit retention, training or disclosure. Business tiers of general tools, where training is off by default but where the contract, data location and retention still need to be verified. Firm-controlled tools, procured for legal work under a contract that meets the statutory standard. Client-identifiable material is confined to the third tier. Anonymised or abstract work may use the second. The first is for nothing that concerns a client, including the fact of an instruction.
2. Contract to the section 43e standard everywhere
Whether or not German law applies, its list is a good one: a secrecy undertaking by the provider, purpose limitation, a prohibition on training with the firm's data, disclosure of subcontractors and the same obligations imposed on them, deletion on request and at the end of the contract, EU data location or an equivalent level of protection, and notification of any request from an authority. A provider that will not sign those terms has told the firm which tier it belongs to. Our vendor due diligence checklist covers the commercial side of the same exercise.
3. Minimise what goes in
The Federal Bar's point bears repeating because it is the one firms most often get wrong: removing names and addresses is not anonymisation when the matter can be reconstructed from the facts. An abstract question about a legal issue is safe in most tools. A description of the client's transaction with the parties renamed is usually not. Treat the whole prompt as a document that may one day be produced, because in Heppner it was.
4. Keep a record of use
A matter-level record of which tool was used, under which account, for what purpose and with what category of input is what allows a firm to answer a court or a regulator in a sentence. It is also what allows the firm to demonstrate, in the common-law world, that the use took place at counsel's direction. The audit-trail discipline in our AI audit trail checklist applies directly.
5. Keep listening tools out of privileged channels
The quiet route into the circle of confidentiality is not the chatbot window. It is the meeting assistant that joins every call, the transcription bot in the client's video platform, the browser extension that reads every page, and the tenant-wide assistant that indexes every mailbox it is given access to. Each of these is a third party present in a privileged conversation or a privileged file store, and each needs the same tiering and the same contract. A recording of a client meeting made by an assistant the client's employer runs may be discoverable in that employer's hands.
6. Be ready for seizure and disclosure
The Rotterdam exercise took a year and depended on the defence being able to say, precisely, which privilege-holders might appear in the data and on which search terms would find them. A firm should be able to identify its privileged material in its own systems in the same way: by matter, by correspondent and by tool. Where an AI environment holds matter material, the firm should know how to export it, how to prove what it contains and how to show that it was never accessible to the provider for any other purpose.
7. Train, and revisit the terms twice a year
Article 4 of the AI Act already requires the firm to ensure a sufficient level of AI literacy among the people who use these tools, and confidentiality is the item most directly tied to professional discipline. The training should include the terms of the tools in tier two, because they change without notice, and the dates they were last checked should be recorded; the CCBE's technical guide of March 2026 treats understanding a tool's data handling as part of the competence the profession now expects (21). Our guide to AI literacy under Article 4 sets out a role-based programme.
When it has already happened
Sooner or later a firm will learn that a trainee, a client or a co-counsel has put something privileged into a public tool. The response has four steps, and their order matters.
- Establish the facts. What exactly was entered, from which account, on which tier, with which settings, and when. Export the conversation before anything is deleted, because the firm's own record of the incident may later be needed.
- Contain. Delete the conversation, turn off any training or memory setting, and where the tier allows it, send a deletion request to the provider and keep the acknowledgement. Deletion does not undo a disclosure, but it limits how long the material exists outside the circle.
- Assess the legal position honestly. Was the material a lawyer-client communication, the client's own preparation, or the lawyer's work? Which system's rules apply? Is a claim to privilege still arguable, for example because the disclosure was to a tool rather than an adversary, or because the provider is contractually bound? Is there a personal data breach requiring notification under the GDPR within seventy-two hours?
- Inform the client, and where required the regulator. The client's confidentiality has been affected and the client is entitled to know. In England and Wales the Upper Tribunal has said the conduct should be brought to the regulator's attention and referred to the Information Commissioner's Office. In the Netherlands, Germany and France the disciplinary rules on confidentiality govern, and a prompt, documented response is the best mitigation available.
How this fits the way LexVera supports legal work
Every decision described above is, in the end, about the same thing: who was inside the circle of confidentiality when the material was handled, and whether the lawyer could prove it. That is a question of professional structure before it is a question of technology, and it is the question LexVera was built to make answerable.
The platform is provided to the firm, for the firm's own use, under terms that place it among the persons a firm is permitted to involve in its practice: bound to confidentiality, limited to the purpose of the firm's legal work, not permitted to use matter material to train models, and able to delete on instruction. Matter material stays within the context the firm has approved for it, so the question a regulator or an examining magistrate would ask has an answer in a contract and a configuration rather than in a privacy policy written for consumers. Analysis remains attached to the material it came from, so a lawyer can move from a statement in a memorandum back to the passage or authority that supports it instead of accepting fluent text on trust. And a qualified lawyer decides what becomes advice, correspondence or a filing, which is where every professional rule discussed here places the responsibility. The same distinction between sourced fact, professional interpretation and product context underpins our editorial policy.
Frequently asked questions
Is a conversation with a chatbot covered by legal privilege?
No. Privilege protects consultation with a member of a regulated profession who owes a duty of secrecy and can be disciplined. A chatbot meets none of those conditions, so its answers are not privileged advice in any of the systems discussed here, however accurate they are.
If a client pastes my advice into a public AI tool, is the advice still privileged?
It is at real risk. The New York court in Heppner found no confidentiality because the consumer terms allowed retention, training and disclosure; the Rotterdam magistrate treated entry into ChatGPT as a disclosure that breaks confidentiality; the Upper Tribunal described uploading client letters into a public tool as a breach of confidentiality that waives privilege. Warn clients at intake and give them a better route to understanding.
Do I breach professional secrecy simply by using an AI tool?
Not if the tool is inside the circle the law recognises. Dutch law extends the duty to other persons involved in the practice, German law regulates service providers in section 43e of the Federal Lawyers' Act, and French law covers every piece of the file. The test is whether the provider is bound, limited to what it needs, prevented from training and able to delete, not whether software was involved.
What is the difference between Heppner and Gilbarco?
Different protections with different waiver rules. Attorney-client privilege is lost by disclosure outside the confidential relationship; work product is lost only by disclosure to an adversary or in a way that makes it likely. The Michigan court treated the chatbot as a tool, so a litigant's own preparation kept work-product protection. The New York court treated the consumer provider as a third party, so advice-related documents lost privilege.
Are enterprise tools safer in law, not only in practice?
The reasoning so far suggests so, although no court has decided the point. Heppner turned on consumer terms permitting training and disclosure, and the Upper Tribunal contrasted public tools with closed tools that keep information out of the public domain. German bar guidance and section 43e describe what the contract must contain for a provider to count as a permitted service provider.
Does the answer differ in criminal matters?
The rules are the same but the stakes are higher, because seizure is realistic and the filtering of seized data is where the Rotterdam decision arose. In criminal and regulatory matters, warn the client orally as well as in writing, and make sure the defence can identify its privileged material precisely if a device is taken.
What should we do if it has already happened?
Establish exactly what was entered and where, delete and request deletion, record the incident, assess whether the material was a communication with the lawyer or the client's own work and whether any protection survives, check whether a data protection notification is due, and inform the client. In England and Wales, the Upper Tribunal expects a referral to the regulator and the Information Commissioner's Office.
Sources and methodology
This guide reflects court decisions, legislation, bar guidance and provider terms available on 10 September 2026. It distinguishes binding decisions from guidance and from provider documentation, and it summarises national law at the level of principle. It is general professional information rather than advice on a specific matter; the applicable code, case law and disciplinary rules must be checked in context, and provider terms should be read in the version in force at the time of use.
- United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. 17 February 2026), discussed in the Harvard Law Review Blog, March 2026
- Venable LLP, AI, privilege and the Heppner ruling: what the court actually held, February 2026
- Warner v. Gilbarco, Inc. (E.D. Mich. 10 February 2026), discussed by Proskauer Rose LLP
- UK and Munir v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC), paragraphs 21 and 60
- Rechtbank Rotterdam (rechter-commissaris), 12 June 2026, ECLI:NL:RBROT:2026:9319
- Hoge Raad, 12 March 2024, ECLI:NL:HR:2024:375, on the handling of privileged data in seized digital material
- Advocatenwet, article 11a
- Wetboek van Strafvordering, articles 98 and 218
- Bundesrechtsanwaltsordnung, section 43e, with section 43a(2)
- Strafgesetzbuch, section 203
- Bundesrechtsanwaltskammer, Hinweise zum Einsatz von künstlicher Intelligenz, December 2024
- Loi n° 71-1130 du 31 décembre 1971, article 66-5
- Conseil national des barreaux, Guide déontologie et intelligence artificielle, adopted 17 March 2026
- CJEU, 8 December 2022, C-694/20, Orde van Vlaamse Balies and Others
- CJEU, 26 September 2024, C-432/23, Ordre des avocats du barreau de Luxembourg
- ECtHR, Michaud v. France, no. 12323/11, 6 December 2012
- CJEU, 14 September 2010, C-550/07 P, Akzo Nobel Chemicals and Akcros Chemicals v Commission
- OpenAI, How your data is used to improve model performance
- Anthropic, Updates to consumer terms and privacy policy, 28 August 2025
- In re OpenAI copyright litigation (S.D.N.Y.), order of 5 January 2026 affirming production of twenty million de-identified logs, discussed in The National Law Review
- CCBE, Technical guide on the use of AI tools and models by lawyers, 27 March 2026
- Nederlandse orde van advocaten, Aanbevelingen AI in de advocatuur