By Dilini Galanga, Founder, AI Nativ. Dilini passed the bar examination in Sri Lanka and served on Google’s Law Enforcement Response Team handling compelled legal process and government data demands. This article is operational commentary, not legal advice; firms should consult their own counsel on privilege questions.
On February 10, 2026, Judge Jed Rakoff of the Southern District of New York ruled from the bench on what he called a question of first impression nationwide: whether documents a client generates with a consumer AI chatbot are protected by attorney-client privilege. In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y.), 2026 WL 436479, the answer was no, and the written opinion followed on February 17. The FBI had seized roughly 31 documents that a securities fraud defendant created using the consumer version of Anthropic’s Claude after receiving a grand jury subpoena. He acted without direction from his lawyers, and he shared the outputs with his defense team afterward. The court held that neither attorney-client privilege nor the work-product doctrine applied, and the government got the documents.
Within weeks, two other federal courts reached materially different conclusions on related questions. The result is a doctrinal landscape that is unsettled, jurisdiction-dependent, and moving quickly. Lawyers who wait for appellate clarity before building controls are making a bet with their clients’ privilege. The sounder approach treats privilege preservation as an operational discipline: a set of documented decisions about tools, contracts, and workflows made before any dispute arises. This article maps the doctrine, the ethics guidance, and the vendor mechanics, and it closes with a five-control framework a firm of any size can implement.
Executive briefing. Three 2026 federal rulings (Heppner, Warner, and Morgan) split on whether AI use waives privilege, and the splits turned on tool tier, attorney direction, and the litigant’s role. Courts are treating consumer AI tools as unprivileged third parties while signaling that enterprise setups with contractual no-training terms and zero data retention (ZDR) may support a different analysis. Malpractice carriers now ask about AI controls at renewal. Privilege has become an operational architecture question, and this article sets out the five controls that answer it.
The doctrine you already know still controls
Nothing about AI changes the baseline rule. The attorney-client privilege protects confidential communications between lawyer and client made for the purpose of seeking or providing legal advice, and voluntary disclosure to a third party generally waives it. Three doctrines preserve privilege despite a third party’s involvement, and all three predate generative AI by decades.
The Kovel doctrine, from United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), extends privilege to a third party whose involvement is necessary, or at least highly useful, to the lawyer’s provision of legal advice. Judge Friendly’s original analogy was a foreign-language interpreter; the doctrine has since covered accountants, investigators, and technical experts. Two structural requirements recur across the case law: the attorney, and not the client, should engage the consultant for the purpose of rendering legal advice, and the attorney should direct the consultant’s work. Where the legal advice is incidental to the consultant’s business advice, courts scrutinize the claim closely and frequently reject it. One boundary deserves emphasis at the outset: Kovel and its progeny cover human third parties who owe duties and can be supervised. Software has traditionally been analyzed as a medium or processor of communication, and its confidentiality question runs through the reasonable-expectation analysis that governs cloud vendors. Keeping those two tracks separate matters throughout this article, because the strongest privilege arguments assign the human consultant to the Kovel track and the AI tool to the vendor-confidentiality track.
The functional-equivalent doctrine, rooted in In re Bieter Co. (8th Cir. 1994) and applied in cases such as Export-Import Bank of the U.S. v. Asia Pulp & Paper Co., 232 F.R.D. 103 (S.D.N.Y. 2005), extends privilege to a non-employee so thoroughly integrated into an organization as to be a de facto employee. Courts apply it narrowly, disagree about its criteria, and some jurisdictions reject it outright; Washington did so in Hermanson v. MultiCare Health System (Wash. Ct. App. 2019).
The common-interest doctrine covers aligned parties pursuing a shared legal strategy. It matters less for AI questions directly, although it becomes relevant when co-parties share AI-assisted work product.
These doctrines are the analytical frame courts are now applying to AI. Understanding them is a prerequisite to understanding why the 2026 decisions diverge.
We run this review for law firms. Book a diagnostic →
The 2026 trilogy: three courts, three answers
United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026), 2026 WL 436479: consumer tools plus no attorney direction equals no protection. Rakoff’s reasoning rested on three grounds. First, Claude is not an attorney; the court invoked the requirement that recognized privileges rest on a trusting relationship with a licensed professional who owes fiduciary duties and is subject to discipline. Second, the defendant had no reasonable expectation of confidentiality. The court reviewed the consumer privacy policy in effect at the time, which disclosed that inputs and outputs could be collected, used to train the model, and disclosed to third parties including government authorities. Third, privilege cannot be created retroactively; what mattered was whether the defendant intended to obtain legal advice from Claude at the moment of the communication, and later sharing the outputs with counsel could not cloak them.
The opinion left two doors open, and both matter enormously for practice. As reported consistently across the firm analyses of the ruling, Rakoff suggested that if counsel had directed the client to use Claude, the tool might arguably have functioned in a manner akin to a Kovel agent. He also expressly limited the decision to the consumer version, which trains on user data, and firm commentary from Proskauer and Debevoise concluded that the ruling leaves open whether enterprise products with contractual confidentiality protections would support a different confidentiality analysis. Both points are dicta. Proskauer’s caution deserves emphasis: contractual confidentiality protections alone do not automatically establish privilege.
Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026), 2026 WL 373043: AI is a tool, not a person. Decided the same day as the Heppner bench ruling, Magistrate Judge Anthony Patti held that a pro se plaintiff’s ChatGPT queries and outputs were protected work product prepared in anticipation of litigation. His reasoning drew a distinction Heppner collapsed: generative AI programs are tools, even if administrators exist somewhere in the background, and under established precedent, disclosure to a third person waives attorney-client privilege while work-product protection is waived only by disclosure to an adversary or in a manner likely to reach one.
Morgan v. V2X, Inc., No. 1:25-cv-01991-SKC-MDB (D. Colo. Mar. 30, 2026): a middle path with a template. Magistrate Judge Maritza Dominguez Braswell followed Warner on work product, rejected the argument that routing information through a consumer AI tool automatically forfeits privacy expectations, and distinguished Heppner on the ground that a pro se litigant is simultaneously the party and the advocate. The court then did something practically useful: it added protective-order language permitting AI use only where the provider is contractually prohibited from training on inputs, is restricted from third-party disclosure, and permits deletion. That language is a preview of the conditions courts will likely impose, and it maps directly onto the controls described below.
One earlier data point completes the picture. In Tremblay v. OpenAI, 2024 WL 3748003 (N.D. Cal. Aug. 8, 2024), the court held that counsel’s unused testing prompts constituted opinion work product because they reflected counsel’s mental impressions. Prompts written by lawyers, in a litigation context, at counsel’s direction, sit on far firmer ground than prompts written by clients acting alone.
The discovery layer: your prompts are records
The New York Times v. OpenAI litigation demonstrated that AI logs are discoverable and that tool tier governs exposure. In May 2025, Magistrate Judge Ona Wang ordered OpenAI to preserve and segregate all output log data that would otherwise be deleted, including chats users had deleted. OpenAI’s own disclosure specified who was affected: ChatGPT Free, Plus, Pro, and Team subscribers, and API users without a Zero Data Retention agreement. ChatGPT Enterprise was excluded, and ZDR customers were unaffected. The going-forward obligation ended in late 2025, and data captured during the window remains held.
The lesson generalizes. Every prompt containing client information is a record that exists on someone’s infrastructure, subject to that vendor’s retention terms, that vendor’s litigation obligations, and compelled legal process directed at that vendor. On Google’s Law Enforcement Response Team, I reviewed legal demands for user data at volume, and the operative truth of cloud discovery is simple: companies produce what their systems retain. If a vendor logs prompts for 30 days, those logs are targetable during that window by grand jury subpoenas, civil discovery, and third-party process, regardless of what the marketing page says about privacy. Zero data retention is the only arrangement under which a vendor has nothing to produce, because the technical guarantee and the legal exposure are the same fact viewed from two directions. Enterprise contracts with short retention windows may narrow that exposure without eliminating it, which is why the strictest matters belong on ZDR terms. And ZDR removes the vendor as a production source; it does not remove the data from discovery, because the firm’s own copies of prompts and outputs remain discoverable from the firm through ordinary process.
What the ethics rules require
ABA Formal Opinion 512 (July 29, 2024) applies the existing Model Rules to generative AI; it creates no new rules. The confidentiality analysis under Rule 1.6 covers all information relating to the representation, regardless of source, and requires a fact-based risk assessment before inputting client information into any tool. The opinion is blunt on consent: because many self-learning tools could lead directly or indirectly to disclosure of client information, informed consent is required before inputting such information, and general boilerplate in engagement letters is insufficient. Genuine informed consent explains why the tool is used, the specific risks, the categories of client information involved, and how later users might access it. Supervisory duties under Rules 5.1 and 5.3 extend to AI vendors, building on the bar’s prior outsourcing and cloud-computing opinions.
State guidance converges on the same core duties with local variation. California’s Practical Guidance states that a lawyer must not input confidential client information into any generative AI solution lacking adequate security, and the state is moving toward binding Rule 1.6 amendments. Florida Ethics Opinion 24-1 requires researching a tool’s data retention, data sharing, and self-learning policies before use. Texas Opinion 705 requires human oversight of AI-generated work. New York, New Jersey, Pennsylvania, and North Carolina have issued guidance reinforcing competence, confidentiality, and vendor vetting. A lawyer practicing across jurisdictions should engineer to the strictest applicable standard.
The vendor layer: tier is the decisive variable
The consumer-versus-enterprise distinction did the dispositive work in Heppner, and it deserves the same weight in your procurement decisions.
Consumer tiers frequently retain conversation data and may use it for training. Enterprise and API tiers generally exclude customer data from training and can offer contractual zero data retention. OpenAI’s enterprise privacy terms provide that API inputs and outputs may be retained for up to 30 days for abuse monitoring, with ZDR available for eligible endpoints and qualifying use cases. Anthropic offers zero-data-retention arrangements, subject to approval, for eligible commercial API products and enterprise offerings; these arrangements are distinct from consumer defaults. Microsoft 365 Copilot operates under Enterprise Data Protection, keeps data within the Microsoft 365 compliance boundary, and does not train foundation models on tenant data; its defining risk is oversharing, because Copilot honors existing file permissions and will surface anything a user can technically access. Legal-specific tools such as Harvey require ZDR from their model providers and contractually prohibit training on customer data, while CoCounsel and Lexis+ AI ground outputs in proprietary databases and market SOC 2 Type II compliance.
The doctrinal support for treating a contractually bound enterprise vendor as confidential processing comes from the cloud-storage line of authority. Bar opinions in New York, Florida, and Massachusetts permit cloud storage of confidential information where the lawyer takes reasonable care. The flip side appears in Harleysville Insurance Co. v. Holding Funeral Home (W.D. Va. 2017), where an unprotected upload to a cloud site with no precautions waived privilege. The analogy protects careful, contractually secured processing, and it protects nothing else.
The five-control framework
The cases, the ethics opinions, and the vendor terms converge on five controls. Each one is documentable, and the documentation is the point; if privilege is ever challenged, the file you built in advance is your evidence.
Control 1: Tool tier. Prohibit consumer-tier AI for any matter touching client information, and enforce the prohibition technically as well as on paper: block consumer AI endpoints at the network level, route approved tools through single sign-on, and monitor for shadow AI on managed devices. A policy without enforcement fails at the first associate with a personal ChatGPT account. Standardize on enterprise or API tiers with written no-training commitments, and secure ZDR agreements for the most sensitive work. This single control addresses the fact that decided Heppner.
Control 2: Attorney direction. Ensure that AI use in a matter occurs at counsel’s direction and within counsel’s workflow, and record that direction. For third-party consultants, structure the engagement as a Kovel arrangement: the attorney retains the consultant, the letter states that the work is performed to assist the lawyer in rendering legal advice, confidentiality obligations are express, scope is defined, and the attorney’s control over the work is documented. Two honest caveats belong here. Documented direction preserves the Kovel argument; it does not guarantee the argument wins, because Rakoff’s language was dicta. A deeper objection also exists: Heppner’s first ground held that privilege rests on a relationship with a licensed professional who owes fiduciary duties and is subject to discipline, and if that reasoning controls, no amount of attorney direction converts a model into a Kovel agent. The stronger version of the argument therefore treats the AI as the lawyer’s instrument, with the human consultant as the Kovel agent who operates it, and documented direction is what makes that characterization available.
Control 3: Tailored client consent. Replace boilerplate with tool-specific informed consent that explains the tool, the categories of client data involved, the risks, and the safeguards, as Opinion 512 requires. Be precise about what consent accomplishes: it discharges the ethics duties under Rules 1.6 and 5.3 and defends against malpractice claims. It does not by itself preserve evidentiary privilege, because a client cannot consent a third-party disclosure into confidentiality; the privilege analysis runs through the vendor terms and the confidentiality expectation addressed in Controls 1 and 4. Consent and privilege are separate protections, and a complete file contains both.
Control 4: Vendor diligence files. Maintain one dated, signed diligence file per approved tool covering data retention, training on inputs, subprocessor lists, breach notification timing, SOC 2 Type II status, encryption, deletion rights, and available legal recourse. Refresh quarterly, because vendor terms change, and suspend use if terms weaken. The maintenance burden is real for a firm running fifteen or twenty tools, which is an argument for keeping the approved list short and for assigning the diligence function to a named owner in operations rather than leaving it to individual lawyers. Recognized frameworks including NIST AI RMF, SOC 2, and ISO/IEC 42001 give the file structure.
Control 5: Data-flow hygiene. Apply minimum-necessary access; sanitize, anonymize, or use synthetic data where the task permits; keep consultants working inside the firm’s tenant; obtain deletion certification at engagement close; and maintain prompt-hygiene and citation-verification logs. The Morgan protective-order conditions (no training, restricted disclosure, deletion rights) should be verified for every tool touching an active matter.
One warning applies across all five controls: the documentation you create is itself discoverable. Diligence files, consent letters, and verification logs can be requested by opposing counsel, and an incomplete log is worse than no log because it evidences a standard the firm set and then missed. Build the records with an adversary as the assumed reader, keep them accurate and current, and involve counsel in structuring them so that work-product protection attaches where it can.
This is the review AI Nativ runs for firms, fixed scope, one report. Book a diagnostic →
Your carrier is already asking
Malpractice insurers moved from observation to underwriting. CNA, the largest U.S. legal malpractice carrier, published a March 2025 risk-control bulletin on ethical AI use and flags AI as an evolving exposure in its public filings. Underwriters across the lawyers professional liability market increasingly ask whether the firm uses AI, polices it, and has written protocols. On coverage terms, specialty carriers including Hamilton Select have filed broad generative AI exclusions on professional liability and E&O forms, although market tracking as of this writing shows no major carrier attaching an AI-specific exclusion to a named lawyers professional liability form. AXA XL offers an affirmative generative AI endorsement on its cyber line for companies building their own models, which signals where carriers see the exposure even though it does not reach legal malpractice coverage. Standard E&O generally covers AI-related negligence arising from professional services unless excluded, and court sanctions from hallucinated citations are typically not covered. A firm with the five controls documented answers those underwriting questions well; a firm without them answers under oath later.
AI Nativ maps these five controls against your firm's tools. Book a diagnostic →
What remains unresolved
Honesty about the open questions strengthens rather than weakens the case for controls. No court has held that attorney-directed use of an enterprise AI tool qualifies the tool as a Kovel agent; Heppner’s favorable language is dicta. No court has held that ZDR terms alone preserve a confidentiality expectation sufficient for privilege. The Heppner and Warner courts disagree about whether an AI system is a third party for waiver purposes, and no appellate court has resolved the split. Every decision discussed here is a trial-court ruling, and two came from magistrate judges. The controls above are designed for exactly this uncertainty: they position a firm to prevail under the strictest reading currently in circulation, and they lose nothing if courts later adopt the more permissive one.
The operational conclusion
Privilege has always depended on facts established before the fight: who was in the room, who engaged whom, what the parties reasonably expected. Generative AI adds a vendor, a contract, and a data pipeline to that factual record. The firms that will keep their privilege intact are the ones treating those elements as things to be designed, documented, and audited. That work is unglamorous, and it belongs to operations as much as to the general counsel. It is also unevenly priced: ZDR agreements are approval-gated, enterprise tiers carry seat minimums, and Morgan itself acknowledged that its conditions burden small parties more heavily than large ones. A boutique can still get most of the way there, because the highest-leverage controls (banning consumer tools, papering attorney direction, and writing tailored consent) cost discipline before they cost money. Start with the tool tier, paper the direction, and build the file before anyone asks for it.
Dilini Galanga is the founder of AI Nativ (ainativ.co). She holds a law degree and passed the bar examination in Sri Lanka, served on Google’s Law Enforcement Response Team handling compelled legal process and government data demands, and does not practice law in the United States. Through AI Nativ, she designs and audits the operational controls discussed in this article, including zero-data-retention pipelines, vendor diligence programs, and data-flow architecture for firms and legal departments. Firms evaluating their privilege posture can reach her at ainativ.co.
Book an AI operations diagnostic
One review, one report: your exposure points, what's safe to automate, and where the legal judgment stays with you.