Privacy in an app is not the same thing as privilege in court.
The Difference Between Privacy and Privilege
Many people assume that if an AI platform has a “privacy policy,” their conversations with the AI are confidential. That is not how legal privilege works.
Attorney-client privilege is a legal doctrine that protects confidential communications between a client and a lawyer, made for the purpose of obtaining or providing legal advice. It can prevent those communications from being disclosed in court or to third parties.
AI privacy is mostly a contract and security question. The platform’s terms of service and privacy policy tell you how the company will use your data, but they do not create a legal privilege.
The Heppner Ruling: Platform Terms Matter
In United States v. Heppner (S.D.N.Y., February 2026), the court emphasized that the defendant’s use of the AI platform Claude failed the privilege test in part because the platform’s privacy policy said user inputs were not confidential.
From the court’s written opinion:
“The communications memorialized in the AI Documents were not confidential… Anthropic’s privacy policy as of [the relevant date] stated: ‘We do not guarantee the confidentiality of information you submit to Claude.’… Heppner’s communications with Claude were not confidential.”
The court held that using an AI platform with terms that disclaim confidentiality is functionally the same as sharing information with any other third party—privilege is lost.
Four Overlapping Concepts: Privilege, Work Product, Privacy, and Internal Confidentiality
It helps to keep these concepts separate:
-
Attorney-client privilege: A legal doctrine that protects confidential communications with your lawyer. Requires (a) a communication with a lawyer, (b) made in confidence, (c) for the purpose of obtaining legal advice.
-
Work-product doctrine: A related protection for materials prepared in anticipation of litigation. Requires that the material be prepared by or for a lawyer, at the lawyer’s direction, and for litigation strategy.
-
Platform privacy policy: A contract term that tells you how the platform uses your data. It is not the same as privilege. A strong privacy policy (e.g., “your data is not used for training, not shared with third parties, and encrypted at rest”) is useful for data security, but it does not create privilege unless the platform is acting as an agent of your attorney.
-
Internal confidentiality policy: Your organization’s rules about what information can be shared outside the company. This is important for trade secrets, business strategy, and reputation, but it is also not the same as legal privilege.
The Key Distinction: Consumer vs Enterprise Tools
Consumer AI tools (e.g., free ChatGPT, Claude, Gemini) typically have terms that say:
- User inputs may be used to train the model.
- User inputs may be reviewed by human moderators.
- The platform does not guarantee confidentiality.
Enterprise AI tools (e.g., ChatGPT Enterprise, Claude for Enterprise, Microsoft Copilot for Business) typically have terms that say:
- User inputs are not used for training.
- User inputs are not shared with third parties.
- Data is encrypted and access is logged.
But even with enterprise tools, you still need a lawyer-client relationship for privilege to apply. The tool being “private” is not enough.
What Boards Should Ask
- What AI platforms do we use? Are they consumer tools or enterprise tools?
- What do the platform terms say? Do they guarantee confidentiality? Do they disclaim it?
- Do our teams assume consumer AI tools are confidential by default? If so, that assumption is wrong and needs to be corrected.
- Do we have a policy on AI and privilege? Does it say: no privileged facts, no client names, no litigation strategy into consumer tools unless approved and directed by counsel?
Do your teams assume consumer AI tools are confidential by default? I deliver board-level courses and consult on AI governance, legal risk, and privilege. Contact me.
Relevant Sources
- United States v. Heppner, No. 1:25-cr-00503-JSR, Order (S.D.N.Y. Feb. 17, 2026) — U.S. District Court, Southern District of New York — https://jlellis.net/wp-content/uploads/2026/02/USA-v-Heppner-Order-2026-02-17-AI-Not-Privileged.pdf
- AI, Privilege, and the Heppner Ruling: What the Court Actually Held—And How to Structure AI Use Safely — Venable LLP — https://www.venable.com/insights/publications/2026/02/ai-privilege-and-the-heppner-ruling-what-the-court
- The Intersection of AI and Attorney-Client Privilege—A Cautionary Tale — Ogletree Deakins — https://ogletree.com/insights-resources/blog-posts/the-intersection-of-ai-and-attorney-client-privilege-a-cautionary-tale/
- Your AI Conversations Are Not Privileged: What a New SDNY Ruling Means for Every Lawyer and Client — Jones Walker LLP — https://www.joneswalker.com/en/insights/blogs/ai-law-blog/your-ai-conversations-are-not-privileged-what-a-new-sdny-ruling-means-for-every.html
- Use of Generative AI in the Law: Lessons from Two Federal Cases — American Bar Association — https://www.americanbar.org/groups/litigation/resources/newsletters/privacy-data-security/generative-ai-in-the-law/
