Blog Post

AI Review of Privileged Material and the Waiver Question

September 27, 2026

Table of Contents

Sending privileged material through an external AI service is a disclosure to a third party, and voluntary disclosure to a third party waives privilege. The reasoning is straightforward and a federal court has now applied it.

‍

A second federal court reached the opposite conclusion on the same question within days, on a distinction the first did not draw. The position is genuinely unsettled, and the parts that are settled point at configuration choices rather than at a prohibition.

‍

What Did the Court Decide?

‍

In United States v. Heppner, the Southern District of New York held in February 2026 that documents a criminal defendant produced through exchanges with a publicly available consumer AI platform were protected by neither attorney-client privilege nor the work product doctrine. The court described the question as one of first impression nationwide.

‍

The reasoning rested on three points. The platform is not a lawyer and had not been engaged by counsel as an agent. The terms authorized collection, retention and disclosure, so no reasonable expectation of confidentiality attached. Privilege also cannot be applied retroactively, since sharing the material with attorneys afterwards could not cure a waiver that had already occurred.

‍

Which Fact Did the Most Work?

‍

The absence of an attorney. The opinion states that because the platform is not an attorney, that alone disposes of the privilege claim, and commentary including a law review analysis has criticized the reasoning for foreclosing any case where a client uses AI on their own initiative.

‍

Why Did Another Court Disagree?

‍

Because privilege waiver and work product waiver are not the same test, which is the distinction that makes this unsettled rather than decided.

‍

Detection view listing personal-tier and consumer accounts of AI services flagged as unsanctioned alongside sanctioned tools, with severity and upload volume per finding
Which tier and which account handled the material is the fact the analysis turns on, and it is observable before anybody needs to argue about it.

In Warner v. Gilbarco, the Eastern District of Michigan denied a motion to compel documents a self-represented litigant had prepared using a public chatbot, holding that work product protection applied. The court reasoned that while voluntary disclosure to a third person generally suffices to waive attorney-client privilege, it does not suffice on its own for work product, where waiver requires disclosure to an adversary or in a way likely to reach an adversary.

‍

One Act, Two Answers

‍

The same submission can waive privilege while leaving work product intact. Two protections with different tests attach to overlapping material, and a control adequate to preserve one may not preserve the other. An organization treating them as a single category will get the analysis wrong.

‍

What Is Confidentiality Versus Privilege?

‍

A distinction worth stating because the two get used interchangeably and behave differently.

‍

Confidentiality is a broad duty, ethical and contractual, not to share information without authority. Privilege is a narrow rule of evidence permitting specific communications to be withheld from discovery. All privileged material is confidential and most confidential material is not privileged, and the relationship runs one way, since maintaining confidentiality does not create privilege while destroying confidentiality can end it.

‍

Which Explains the Asymmetry of Controls

‍

A control that keeps material inside the organization protects confidentiality. Preserving privilege additionally requires that the disclosure be to a lawyer or a lawyer's agent for the purpose of legal advice, which is a property of the relationship rather than of the storage, and privilege as a loss category covers what happens when it fails.

‍

What Did the Ruling Leave Open?

‍

Four questions, and each maps to a decision an organization controls.

‍

Privacy control panel showing detection running locally with a list of fields transmitted and a separate list of content types never transmitted
What a tool retains and transmits is the confidentiality half of the analysis, and it is a configuration fact rather than a legal one.

The court left four questions open. Whether an attorney's own use of generative AI to prepare work product would be protected. Whether the analysis changes where the tool is non-public rather than publicly available. How a different provider's privacy policy would affect the confidentiality assessment. Then whether a client using AI at counsel's direction could assert either protection.

‍

Which Are All Governable

‍

Each open question is a variable rather than a mystery. Who used the tool, at whose direction, on which tier, under which terms. None requires a court to resolve before an organization can choose the more defensible side of it.

‍

Which Facts Distinguished the Case?

‍

Four, and reading them as a checklist is more useful than reading the holding as a prohibition.

‍

  • A consumer tier: A publicly available platform whose terms authorized collection, training use and disclosure to third parties.
  • No direction from counsel: The defendant acted on his own initiative rather than at a lawyer's instruction.
  • No engagement of the tool as an agent: Counsel had not retained the platform in the way a firm retains an expert or a translator.

‍

The fourth is procedural. The government already held the documents under a search warrant before the privilege question arose, so the court was deciding admissibility rather than preventing disclosure.

‍

Is There Any Remediation?

‍

No, and this is the finding with the most operational weight.

‍

The court held that privilege must exist at the time of the communication and cannot be manufactured afterwards by routing previously disclosed material through an attorney. So unlike almost every other data incident, there is no response that reduces the consequence. The protection either attached when the material was submitted or it did not.

‍

Which Argues for Prevention Over Detection

‍

Where a response cannot reduce the loss, monitoring that finds the submission afterwards is evidence rather than mitigation. Enforcement at the point of submission is the only control that changes the outcome, and losses no response can undo share the same structure.

‍

Does This Reach Outside Law Firms?

‍

Considerably, and reading it as a legal sector story is the most likely way to miss it.

‍

Privilege attaches to communications with counsel wherever they occur, so any organization with in-house legal holds privileged material. A compliance investigation conducted under legal direction, an internal report prepared for counsel, a memorandum assessing exposure ahead of litigation. Each is the kind of document somebody might reasonably paste into a tool to summarize.

‍

Which Function Is Most Exposed?

‍

Not legal, which is aware of the issue. The exposure sits with the functions that produce material for legal without thinking of it as privileged, including compliance, internal audit, human resources during an investigation, and security during an incident. A forensic summary prepared for counsel carries the protection and reads like an operational document.

‍

What Does That Change About the Control?

‍

The population it has to cover. A restriction applied to the legal department addresses the group least likely to need it, and the material moving through an incident response channel or an investigation workstream is where the same protection is at stake with none of the awareness, and the mechanism by which it arrives does not distinguish by department.

‍

What Should Be in Place?

‍

Four things, and none requires resolving the open legal questions.

‍

A record of which tier and which account handled material in any matter, since that fact is where the analysis starts and it is observable at the time. Terms review on any tool that touches legal material, specifically for training use and third-party disclosure. A stated position on whether counsel may direct AI use and how that direction is recorded. Then enforcement at submission for the categories that carry a protection, since detection afterwards cannot restore one. An AI Interaction Data Fabric supplies the first from observed activity rather than from a survey nobody completes accurately.

‍

Two Protections, Two Tests, One Submission

‍

A federal court held in February 2026 that a defendant's exchanges with a consumer AI platform carried neither privilege nor work product protection, on the reasoning that the platform is not a lawyer, its terms defeated any expectation of confidentiality, and privilege cannot attach retroactively. Another federal court reached the opposite result on work product within days, holding that work product waiver requires disclosure to an adversary rather than merely to a third party. So one submission can waive one protection and not the other, and a control adequate for confidentiality may not preserve privilege, which is a property of the relationship rather than of the storage. The first ruling left four questions open and each is a configuration choice. There is also no remediation, since the protection attached at submission or never. Kovrr's AI Security and Governance Platform records which tier and which account handled the material.

‍

To see which accounts and tiers your AI activity runs through, book a demo mapped to your own estate.

Or Amir

Product & Customer Growth Manager

AI and Privilege FAQs

Speak to an Expert

Does using a consumer AI tool waive attorney-client privilege?

What did United States v. Heppner decide?

Is work product waiver the same as attorney-client privilege waiver?

What is the difference between confidentiality and privilege?

Does an enterprise AI tier preserve privilege?

Can privilege be restored after material is sent to an AI tool?