To Claude or Not to Claude: Why Courts Aren’t Ready
By Julian Ramirez '27
Artificial intelligence (AI) has rapidly expanded into the legal industry, yet courts have not developed a clear framework to regulate its use. Attorneys and clients alike have utilized AI to assist with legal research, writing, and general queries. Although on the surface, AI may seem clear and quick to use, the use of AI creates tensions between two major legal doctrines: attorney-client privilege and the work-product doctrine. Furthermore, recent court decisions have reached inconsistent rulings, highlighting the ambiguity within the judicial branch surrounding AI.
United States v. Heppner (2026) ruled that the individual use of AI is not protected under attorney-client privilege. Warner v. Gilbarco Inc. (2026), by contrast, ruled in favor of the plaintiff’s work-product protection despite their use of generative AI, only due to the plaintiff being a pro se litigant. (1) The swift rise of AI within the legal industry has sparked tension over how the courts apply attorney-client privilege and the work-product doctrine to its use, reflecting a need for a strong governing standard from the American Bar Association, along with clear legal precedent to support it.
Attorney-client privilege protects confidential communications, but only if three conditions are met. Communication must be made for the primary purpose of seeking, obtaining, or providing legal advice, the discussion must be intended to be private, and the exchange must strictly be between the attorney and the client. (2) The use of generative AI undermines these conditions directly. First, data storage by AI companies now makes information public and obtainable. Second, AI can be considered a third party to protected communications. Third, AI disclaimers explicitly state that legal advice cannot be provided, dismissing the purpose of seeking legal advice.
The work-product doctrine has been challenged by AI because of similar flaws. The work-product doctrine protects documents and tangible things prepared by an attorney or their agents in anticipation of a trial from discovery by opposing counsel. (3) Work-product can only be waived by disclosure to an adversary or if information is conveyed in a manner that makes it likely the materials will reach an adversary. (4) Therefore, work-product is narrower in scope and more difficult to waive than attorney-client privilege. Without a clear governing standard, attorneys remain uncertain whether the use of AI preserves or waives privilege.
AI tools potentially fall under the third-party waiver exception, which refers to the waiver of attorney-client privilege when sharing legally privileged communications with a third party. (5) Public-facing AI tools specifically fall under this rule due to the nature of their data sharing and insufficient data privacy protections. When a query is submitted, the information is stored by the company and is accessible. Attorneys utilizing public-facing AI operate at their own risk, opening themselves up to professional liability and ethical conduct sanctions.
A privileged agent is a third party whose communications and work product are protected from discovery and disclosure. If a client commissions the use of AI under the discretion and direction of the attorney as part of legal strategy, does that invoke attorney-client privilege? Does AI become a privileged agent, similar to a paralegal? Without a clear standard, clients’ communications may be vulnerable to discovery by opposing counsel, and attorneys may put their careers at risk.
United States v. Heppner
In United States v. Heppner, Bradley Heppner was indicted on securities and wire fraud, conspiracy to commit securities and wire fraud, making false statements to auditors, and falsifying corporate records. (6) Following his arrest, the FBI produced a search warrant wherein they seized multiple documents and electronics from his home. (7) Among the seized documents were 31 documents containing queries Heppner submitted to a publicly available AI tool, Claude. (8)
Heppner independently used AI without the direction of his counsel. Some of the queries submitted to Claude included potential defense and argument strategies and privileged communications between Heppner and his attorney. (9) On February 6, 2026, the prosecution filed a motion to produce the 31 documents containing potentially privileged information. The prosecution argued that the AI documents did not meet attorney-client privilege because the AI tool was not an attorney, and Heppner did not act under his attorney's discretion. (10)
In his ruling, Judge Rakoff echoed the same argument as the prosecution, citing that the use of AI is not protected under attorney-client privilege when the information is not prepared under the attorney’s discretion. (11) The court's reasoning was based on the idea that generative AI stores any and all data. Claude’s privacy policy specifically allows data collection and disclosure to third parties, including the federal government.
Since the privacy policy explicitly states these facts, Heppner had no reasonable expectation of privacy and confidentiality when using Claude to produce defense strategies. Additionally, for attorney-client privilege to apply, one must inquire with their attorney for the primary purpose of obtaining legal advice. (12) Claude provides a disclaimer explaining that any information provided cannot be used as legal advice, as Claude is not a licensed attorney. Rakoff further explained that AI documents lacked the first two, “if not all three,” of the privilege requirements, stating that communications were not between an attorney and a client, dispelling claims of privilege. (13)
Had Bradley Heppner utilized Claude under the discretion of his attorney, Rakoff acknowledges that Claude may have been characterized as a legal agent, allowing for attorney-client privilege to apply. (14) With reference to the work-product doctrine, Rakoff said that documents made with AI were not protected, as the work was not prepared at counsel’s direction. The case leaves the industry questioning whether existing doctrines address the evolving use of generative AI in legal practice.
Warner v. Gilbarco, Inc.
Warner v. Gilbarco Inc. presented an opposing conclusion to the decision made in United States v. Heppner. In Warner v. Gilbarco Inc., the plaintiff Sohyon Warner, a pro se litigant, utilized AI tools when preparing for trial. (15) The defense moved to compel production of Warner’s interactions with AI, citing that her use of public-facing AI waived any rights to attorney-client privilege and the work-product doctrine. (16) However, the court ruled in favor of Warner, citing that work-product protection is only waived when information is disclosed to an adversary. (17) As a pro se litigant, Warner acted as her own counsel, allowing her to assert work-product protections over materials prepared. Warner utilized AI as a tool in preparation for trial and did not disclose any materials to opposing counsel, which protected her work under the rule; classifying AI as a tool rather than a third party is the sole reason why the plaintiff’s work was protected.
Had the plaintiff not been a pro se litigant, it is likely the ruling would have reached a different conclusion. The judge presiding over the case explained that accepting the defendant’s motion would “nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed”. (18)
The Sporck Doctrine
While courts still remain split on the exact terms of protection, this decision reflects a broader alignment with the Sporck doctrine protecting work-product, citing that an attorney's selection and compilation of documents in preparation for a deposition reflects an attorney’s mental impressions and trial strategies. (19) The Sporck doctrine is analogous to the Warner v. Gilbarco, Inc., decision, where the doctrine could potentially extend to protections of legal research, searches, and queries conducted through search engines and legal research platforms by attorneys. The doctrine potentially lays the groundwork for a new doctrine to be established that protects AI inquiries and documents in preparation for a deposition. Both United States v. Heppner and Warner v. Gilbarco, Inc. involved publicly available AI tools, yet reached opposite conclusions due to the nature of each issue. Together, Heppner and Warner leave the legal industry without a predictable standard to adhere to, pushing for the industry to search for its own solutions.
Reconciling the Split
On its face, both cases look contradictory, but each case tackles a different doctrinal question. Both cases anchor the ruling under attorney oversight and disclosure standards as core requirements to satisfy either of the two doctrines at hand. United States v. Heppner focuses on attorney-client privilege and confidentiality agreements with the use of AI. Warner v. Gilbarco, Inc. anchors its decision on the work-product doctrine and adversarial disclosure standards. The divergence between the two rulings lies not in the use of AI, but in how it was used throughout the cases. Although courts seem confident that certain data privacy protections and ample attorney oversight satisfy both doctrinal questions, neither ruling addresses what sufficient data privacy protections and attorney oversight look like in practice.
A Case for ABA Action
The two landmark cases of United States v. Heppner and Warner v. Gilbarco, Inc. represent the current lack of clarity surrounding AI in law. A standard enforced by the American Bar Association (ABA) or at the federal level is crucial when considering the future of AI tools within law. The ABA specifically acts as a professional organization that oversees professional conduct and ethical standards through the Model Rules of Professional Conduct. The ABA is able to produce a legal recommendation over attorney-client usage of AI tools and move more efficiently to create a standard that attorneys can operate under, until the courts set a true legal precedent. Ultimately, clear ABA guidelines are sufficient in clearing a path to responsible AI usage until the courts establish binding legal precedent governing its use.
The standard set by the ABA should answer whether attorney-directed use of AI preserves privilege, what level of attorney oversight is required, and what level of confidentiality is required to sufficiently protect privilege when considering the use of generative AI. A strong governing standard should create a distinct separation between public and enterprise-level AI. Once that distinction is clear, AI should be labeled as a privileged agent, similar to a paralegal or legal assistant, only if used under the discretion of an attorney. As a privileged agent, AI would be able to protect confidential information as a result of privileged communications between an attorney and their client and has the ability to act as an extension of the legal team. AI labeled as a privileged agent would allow for the legal team to utilize AI efficiently without worry of potential discovery due to information protection. Finally, there should be necessary documentation produced by the supervising attorney to ensure all criteria are met.
Further, an attorney aiming to use AI must provide documentation outlining data privacy protection guidelines that the AI in use must abide by. The attorney must provide documentation explicitly stating that they are guiding AI and take responsibility for any actions that follow as a result of using AI. Implementing a clear standard as outlined would look to serve the entirety of the legal industry while simultaneously protecting attorneys and the ABA alike from any liability as a result of using AI. A strong governing standard allows AI to serve the legal industry responsibly, rather than continuing to create tension within the practice of law.
Endnotes
United States v. Heppner, 25 Cr. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026).; Warner v. Gilbarco, Inc., No. 2:24-CV-12333, 2026 WL 373043, at *4 (E.D. Mich. Feb. 10, 2026).
Legal Information Institute, Cornell Law School. "Attorney-Client Privilege." Last updated August 2023. https://www.law.cornell.edu/wex/attorney-client_privilege.
Legal Information Institute, Cornell Law School. "Attorney Work Product Privilege." Last updated August 2023. https://www.law.cornell.edu/wex/attorney_work_product_privilege.
Federal Rules of Evidence, Rule 502. "Attorney-Client Privilege and Work Product; Limitations on Waiver." Legal Information Institute, Cornell Law School. https://www.law.cornell.edu/rules/fre/rule_502.
Heppner, 2026 WL 436479
Heppner, 2026 WL 436479
Heppner, 2026 WL 436479
Heppner, 2026 WL 436479
Heppner, 2026 WL 436479
Heppner, 2026 WL 436479
Sven Volkmer, Aalok Sharma, and Hope Anderson, “Attorney-client privilege and work product in the age of generative ai,” White & Case, 23 April 2026. https://www.whitecase.com/insight-alert/attorney-client-privilege-and-work-product-age-generative-ai
Heppner, 2026 WL 436479
Volkmer, Sharma, and Anderson, "Attorney-Client Privilege and Work Product."
Warner, 2026 WL 373043
Volkmer, Sharma, and Anderson, "Attorney-Client Privilege and Work Product."
Volkmer, Sharma, and Anderson, "Attorney-Client Privilege and Work Product."
Dale, Margaret A., Laura Gavioli, Nolan M. Goldberg, Robert Pommer, Peter J. Cramer, and Edward Wang. "Michigan Federal Court Protects AI-Assisted Litigation Work Product." Proskauer Rose LLP. March 2, 2026. https://www.proskauer.com/alert/michigan-federal-court-protects-ai-assisted-litigation-work-product.
Kallam AI. "Legal AI Tools Compared: A Decision Framework for Disputes Practices." Kallam AI Blog. April 15, 2026. https://www.kallam.ai/blog/legal-ai-tools-compared-a-decision-framework-for-disputes-practices.
Sporck v. Peil, 759 F.2d 312, 316 (3rd Cir. 1985).



Comments