AI Legal Risk: Summary and Board Takeaways

Eran Goldman-Malka · July 28, 2026

AI can accelerate legal work, but it can also accelerate legal mistakes.

AI is powerful, but it does not change privilege rules, discovery risk, or professional responsibility. Courts are already testing these boundaries in privilege disputes, fraud cases, and hallucination sanctions.

Over the past seven posts, we have covered:

  1. What AI can and cannot do (Post 1): AI can help explain law, summarize documents, and draft first-pass text, but it cannot replace licensed legal advice or create privilege by itself.

  2. The privilege problem (Post 2): In U.S. v. Heppner, a Manhattan federal judge ruled that materials created with an AI tool and later shared with counsel were not protected by attorney-client privilege or work-product doctrine.

  3. AI in fraud cases (Post 3): Courts are allowing search warrants targeting executives’ ChatGPT records in securities fraud cases, showing that AI outputs and prompts may become discoverable in white-collar investigations.

  4. Hallucinated legal citations (Post 4): In Mata v. Avianca, lawyers were sanctioned for filing a brief containing fabricated citations generated by ChatGPT, showing that the harm is not just embarrassment—it can lead to sanctions, cost orders, and credibility loss.

  5. Pattern of sanctions (Post 5): Current trackers document 1,598 AI hallucination or sanction incidents across jurisdictions, showing that courts are seeing repeated failures in verification and supervision. The issue is no longer whether AI hallucinates; it is whether legal teams have controls.

  6. Lawyer-client vs AI-client privacy (Post 6): Lawyer-client privilege is a legal doctrine; AI privacy is mostly a contract and security question. In the Heppner ruling, the judge noted that the AI platform’s terms said user inputs were not confidential, which weakened the privacy argument. Privacy in an app is not the same thing as privilege in court.

  7. Practical rules for safe use (Post 7): AI can still be useful if used with guardrails. The safest uses are brainstorming, issue spotting, summarizing public material, and drafting internal outlines. Risky uses include sharing sensitive facts, legal strategy, or privileged communications into consumer tools. A simple policy: no privileged facts, no client names, no litigation strategy, no confidential data unless the tool is approved and contractually protected.

One Practical Message for Executives, Lawyers, and Founders

Use AI, but govern it like any other sensitive third-party system.

That means:

  • Know what tools your teams are using. Consumer tools (free ChatGPT, Claude, Gemini) have different terms than enterprise tools (ChatGPT Enterprise, Claude for Enterprise, Microsoft Copilot for Business).

  • Check the platform terms. Do they guarantee confidentiality? Do they say user inputs are not used for training and not shared with third parties? If not, assume your inputs are not confidential.

  • Define safe and risky uses. Safe: brainstorming, summarizing public material, drafting internal outlines. Risky: sharing privileged facts, legal strategy, client names, or confidential data.

  • Require verification. If you use AI to assist with research, drafting, or analysis, verify the output before you rely on it or submit it. Verification is non-delegable.

  • Treat AI prompts like sensitive business records. If an AI prompt contains strategy, risk assessments, or legal analysis, it may be discoverable in litigation or investigations.

Five Board-Level Questions

  1. Inventory: What AI platforms are our executives, legal teams, and compliance officers using? Are they consumer tools or enterprise tools?

  2. Policy: Do we have a formal AI use policy for legal and compliance work? Does it define safe uses, prohibited uses, and verification requirements?

  3. Training: Do our teams understand that AI can hallucinate, that AI chats may be discoverable, and that privilege is not automatic?

  4. Verification: What is our verification workflow? Who is responsible for checking AI outputs before they are submitted or relied upon?

  5. Audit: Do we log AI use in high-risk areas (legal, compliance, finance) so we know what was created, by whom, and whether it was verified?

The Direct Question

Should law firms treat consumer AI tools as non-confidential by default?

Based on the Heppner ruling and the sanctions tracker, the answer is yes. Unless the tool is an enterprise tool with contractual confidentiality protections, and unless the use is directed by counsel for the purpose of obtaining legal advice, assume the tool is not confidential and privilege does not apply.

That does not mean you cannot use AI. It means you need to govern it.


Want a structured approach to AI governance, legal risk, and verification controls? I deliver board-level courses and consult on AI strategy, governance, and legal compliance. Contact me.


Relevant Sources

  1. United States v. Heppner, No. 1:25-cr-00503-JSR, Order (S.D.N.Y. Feb. 17, 2026) — U.S. District Court, Southern District of New York — https://jlellis.net/wp-content/uploads/2026/02/USA-v-Heppner-Order-2026-02-17-AI-Not-Privileged.pdf
  2. Mata v. Avianca, Inc., Opinion and Order on Sanctions (S.D.N.Y. June 22, 2023) — U.S. District Court — https://www.nhd.uscourts.gov/sites/default/files/pdf/Mata-v-Avianca-sanctions-order.PDF
  3. AI Hallucination Cases: The 1,598-Case Sanctions Tracker — HAQQ — https://haqq.ai/blog/ai-legal-hallucination-audit
  4. US Judge Allows Search Warrant Seeking Crypto Exec’s ChatGPT Records — Law.com — https://www.law.com/newyorklawjournal/2026/06/23/us-judge-allows-search-warrant-seeking-crypto-execs-chatgpt-records/
  5. AI, Privilege, and the Heppner Ruling: What the Court Actually Held—And How to Structure AI Use Safely — Venable LLP — https://www.venable.com/insights/publications/2026/02/ai-privilege-and-the-heppner-ruling-what-the-court
  6. Practical Lessons from the Attorney AI Missteps in Mata v. Avianca — Association of Corporate Counsel — https://www.acc.com/resource-library/practical-lessons-attorney-ai-missteps-mata-v-avianca
  7. Use of Generative AI in the Law: Lessons from Two Federal Cases — American Bar Association — https://www.americanbar.org/groups/litigation/resources/newsletters/privacy-data-security/generative-ai-in-the-law/

Twitter, Facebook