In February 2026 the Southern District of New York decided whether documents a defendant had produced with the help of a consumer AI assistant were protected by attorney-client privilege or the work-product doctrine. The court held they were not.[1] The reporting that followed compressed this into a rule that AI use waives privilege. That is not what the court held, and a firm that acts on the compressed version will spend money in the wrong place.
The opinion is worth reading closely, because it is unusually explicit about what would have produced a different answer.
What happened
The defendant, facing securities and wire fraud charges, used a public conversational AI product on his own initiative to organise material for his anticipated defence. Some of what he typed came out of conversations with his retained counsel. He produced thirty-one documents this way, intending to use them in future communications with his lawyers. The FBI seized them on arrest.[1]
He then asserted privilege and work product over the thirty-one documents. Both claims failed.
Three separate failures, not one
The privilege claim failed on three independent grounds, and the distinction matters because a firm can cure some of them and not others.[1]
- The exchange was not with a lawyer. Privilege attaches to communications with a licensed professional, and software is not one. No architecture fixes this — it is an argument for keeping a named practitioner in the loop, not for choosing a different vendor.
- There was no reasonable expectation of confidentiality. The product's own terms permitted the provider to retain inputs and outputs, use them for training, and disclose them to third parties including government. The court treated submitting confidential material to a system whose published terms contemplate exactly that as inconsistent with maintaining confidentiality over it.
- The communication was not for the purpose of obtaining legal advice. The tool's terms disclaimed giving any.
The work-product claim failed for a different reason again: the documents were prepared by the defendant on his own volition rather than at counsel's direction, so he was not acting as counsel's agent. The court added that material which is not protected when created does not acquire protection merely by being handed to a lawyer afterwards.[1]
What the court said would have mattered
This is the part that gets lost. The court indicated the analysis could run differently where counsel had directed the use of the tool, and commentary has focused on the same three variables: whether a lawyer initiated and supervised the use, whether the deployment carried contractual confidentiality with training disabled, and whether access sat inside the firm's own boundary rather than on a public product.[2]
None of that is exotic. Courts have long extended privilege to translators, forensic accountants and consultants engaged to help counsel give advice. The question the doctrine asks is whether the third party was brought in to facilitate legal advice under the lawyer's direction — and a tool can satisfy that test in one deployment and fail it in another.
The variable is the deployment, not the technology
Read that way, Heppner is not a case about artificial intelligence. It is a case about terms of service, about who directed the work, and about whether anyone can show it afterwards. All three are properties of how a tool is deployed and governed.
The practical consequence for a firm is that two questions have changed places. "Is the output any good" has become the easier one. The harder one is now evidentiary: can you show, in a form that survives an adversary's scrutiny, which lawyer directed the work, what the system was permitted to do with the material, and where it went.
A processing agreement answers part of that. It allocates liability between a firm and a vendor, which is useful. What it does not do is bind the party on the other side of a discovery dispute, or establish for a court that a disclosure did not occur. That has to come from the record.
What this changes in practice
- Read the terms of the tools already in use, including the ones nobody procured. Retention, training and third-party disclosure are the three clauses the court weighed, and a consumer tier usually answers all three the wrong way.
- Make the direction visible. Work-product protection turned on whether counsel initiated the use. If a matter's AI work is supervised by a named practitioner, the supervision should be recorded at the time, not reconstructed later.
- Decide the confidentiality question per matter rather than per firm. The sensitivity of the material, not the convenience of the tool, is what the balancing test asks about.
- Keep a record you could produce. The point of an audit trail here is not operational reporting — it is the ability to answer, with evidence, where privileged material was processed and under whose instruction.
Bernio exists because those answers are easier to give when they are properties of the system rather than assertions about it. But the honest summary of Heppner is narrower than any product claim: the court did not say AI breaks privilege. It said that this use, on those terms, without a lawyer directing it, never had privilege to break.
