All articles
Compliance & Risk 4 min read

Can AI Put Attorney-Client Privilege at Risk?

A federal judge held that a defendant's AI chat logs were protected by neither privilege nor work product. What that ruling means for firms whose staff already use public AI tools.

A laptop screen showing an AI chatbot prompt that reads "What can I help with?"

AI can help law firms move faster, reduce repetitive work, and catch details people miss. But speed is not the only consideration. When an attorney or staff member pastes client information into a public AI tool, the firm may create a confidentiality and discovery risk it cannot undo.

Across practice areas, the tempting use cases are obvious: summarize discovery, review medical or financial records, extract key dates from transcripts, organize a case chronology, analyze contracts, or draft client communications. These are also the tasks most likely to contain real client data.

That does not mean every use of AI automatically waives attorney-client privilege. It means firms cannot assume legal work stays protected simply because it was performed for a client.

What the Heppner Ruling Actually Said

In February 2026, U.S. District Judge Jed Rakoff ruled in United States v. Heppner that 31 documents a criminal defendant generated through the consumer version of Claude were protected by neither attorney-client privilege nor the work-product doctrine. The defendant created them independently, not at the direction of counsel, to help develop potential defense strategies.

The court found that the exchanges were not communications with an attorney, were not confidential under the platform's terms, and did not qualify as attorney work product under the facts of the case. Other courts have reached different work-product conclusions under different facts, so the law is still developing. That makes governance more important, not less.

Why This Matters for Law Firms Right Now

Heppner involved a criminal defendant, not a law firm employee uploading a client file. Still, the court's reasoning matters to attorneys, paralegals, and legal operations leaders. Courts are looking at who used the tool, why it was used, whether counsel directed the work, what confidentiality protections applied, and where the data went.

A chatbot can feel like a private workspace, but the firm may have little visibility into how the platform stores, retains, or discloses what was entered.

Clio's 2025 Legal Trends Report found that nearly half of legal professionals use generic AI tools such as ChatGPT, Gemini, Claude, or Perplexity. It also found that 53% of legal professionals said their firm had no AI policy or they were unaware of one. There is a good chance AI is already part of your firm's workflow, whether leadership approved it or not.

The risk is not usually reckless behavior. It is a lawyer or staff member trying to work efficiently by summarizing discovery, reviewing a contract, drafting a motion or client letter, translating records, or pulling dates from a transcript. Those useful tasks also carry the client data your firm is obligated to protect.

It's Not a Hard "No AI" Line

The answer is not a blanket AI ban. Bans often push usage into personal accounts and unapproved tools, leaving the firm with even less visibility.

A safer approach is to let the AI work with the document's context without receiving the client's real identity. Sidian's AI Vault creates a synthetic twin of the document by replacing names, emails, account numbers, and other identifiers with consistent stand-ins before the file reaches ChatGPT, Claude, Copilot, or another outside model. The structure and meaning stay intact, while the real values remain sealed inside the firm.

The same real value always maps to the same stand-in across a matter, so the model can still connect the dots. Only the firm can reverse the mapping, and AI Vault logs what was de-identified and what each tool saw. This does not turn AI use into an automatic privilege guarantee, but it gives the firm stronger confidentiality controls, human review, and an auditable record instead of an untracked disclosure.

The Practical Risk for Every Law Firm

Law firms across every practice area handle information clients cannot afford to have exposed: medical records, Social Security numbers, tax returns, financial statements, business plans, contracts, employment records, immigration files, criminal case details, family disputes, and information about minors. Sending that data to a public AI tool can put it outside the firm's direct control.

For firm leaders, the issue is not only whether a vendor promises security. It is whether the firm can show where client information went, what the model actually received, who approved the use, and whether the original data remained inside the firm's controlled environment. Without a clear AI policy and technical guardrails, the firm can be exposed on two fronts: the client data itself and the legal protections surrounding it.

What Does a Safer AI Process Look Like?

A safer process keeps original documents where they already live, prevents real identifiers from reaching outside models, applies consistent replacements across an entire matter, records what each tool saw, and requires a person to review the output before real values are restored.

Sidian DataGuard protects sensitive information as it moves through the tools your firm already uses, including Microsoft 365, Google Workspace, and Clio. The AI Vault adds a controlled path for using outside AI tools on confidential documents without handing those models the real client names and identifiers.

The question is not whether your firm will use AI. It is whether your firm can use it without losing control of the information clients trusted you to protect.

Use AI without handing over the client file

Book a 20-minute demo and watch AI Vault build a synthetic twin of a document from your own workflow, so you can see exactly what the model receives and what stays inside your firm.

Use AI without handing over the client file

Book a 20-minute demo and watch AI Vault build a synthetic twin of a document from your own workflow, so you can see exactly what the model receives and what stays inside your firm.

Loading the calendarOr open the booking page