Your Client Talked to an AI Before They Called You. Is That Conversation Privileged?

A federal court held that a client’s own exchanges with a consumer AI platform were protected by neither the attorney-client privilege nor the work product…

Attorney-client privilege and AI chatbot conversations, Georgia law firm risk

A federal court held that a client’s own exchanges with a consumer AI platform were protected by neither the attorney-client privilege nor the work product doctrine. The ruling did not rest on a hack, a leak, or a vendor failure. It rested in part on the platform’s own published terms, which told every user that inputs and outputs are collected, used to train the tool, and subject to disclosure to third parties.

I have spent 20+ years at closing tables in Georgia real estate finance. In that room I control the record. I know who is present, what was said, and what was written down. Privilege there is not an assumption. It is a structure I build and hold.

Your client builds nothing. In United States v. Heppner (S.D.N.Y. 2026), a person who was the target of a federal investigation used a consumer AI platform to work through his own legal exposure. A federal court held that a client’s own exchanges with a consumer AI platform were protected by neither the attorney-client privilege nor the work product doctrine.

That is all you need from him. The doctrine is what follows you home.

Because somewhere in your active matter list is a client who did the same thing on a Tuesday night. A developer facing a loan modification. A seller staring at a title objection she does not understand. She opened a free AI tab, typed the facts of her deal, and asked what she should do. Then she called you Wednesday morning and told you nothing about it.

You have been representing her for six weeks. You have never asked.

What did the court actually rest its ruling on?

The court applied settled privilege law to a new fact pattern. Attorney-client privilege requires a communication between client and attorney, kept confidential, made for the purpose of obtaining or giving legal advice. The court held that at least two of those three elements failed, and possibly all three.

The confidentiality element is the one that reaches your practice. The court noted that the platform’s privacy policy stated it collects data on user inputs and outputs, uses that data to train the tool, and reserves the right to disclose it to third parties, including government regulatory authorities.

No breach occurred. No file escaped. The terms said so from the beginning, and the user accepted them by using the service.

The State Bar of Georgia Generative AI Toolkit warns about exactly this. It cautions practitioners about shrinkwrap and clickwrap licenses, the standard-form agreements accepted by the simple act of using a service. The Toolkit notes those agreements frequently carry broad disclaimers and may expressly exclude any obligation of confidentiality. Information shared under them may not be protected by any enforceable duty of non-disclosure.

Read that alongside the ruling. Published Bar guidance identified the risk. A federal court then applied that same reasoning to destroy a real privilege claim over real documents in a real proceeding.

The work product doctrine failed for a separate reason. That doctrine protects materials prepared by counsel or at the behest of counsel. The materials here were prepared by neither.

Is your client already exposed in a matter you are handling right now?

Probably. And there is no cure step available to you after the fact.

The court addressed the waiver point directly. Even assuming the information the client typed into the platform was privileged when it lived in his head, sharing it with the platform waived that protection. Handing the output to counsel afterward does not restore what disclosure already destroyed.

This is the fuse. It is already lit in matters you are billing this week, and you cannot see it because you have never asked the question that would reveal it.

There is no motion you can file. No clawback provision reaches it. No protective order un-discloses a disclosure your client made voluntarily to a third party before you were involved. The reality is that your first notice of the problem will be a document request that produces something you did not know existed.

There is a second fuse, and it points at you.

The same reasoning that stripped protection from a client’s exchanges reaches a lawyer’s own use of the same category of tool. The court did observe that if counsel had directed the use, the tool might arguably be said to have functioned as a lawyer’s agent. It did not decide that question. Nothing in the ruling promises that an enterprise tier, a paid plan, or attorney direction preserves privilege. Treating any of those as settled protection is an assumption, not a holding.

Your obligations under GRPC 1.6 do not soften because a vendor’s marketing page uses the word secure.

Shadow AI Check: is your firm carrying client-side exposure it cannot see?

Answer these six questions. Answer them honestly, and answer yes only where you could produce a dated document rather than a recollection.

  1. Does the engagement letter say anything at all about the client’s own use of AI tools on their matter?
  2. At intake, does anyone tell the client that what they type into a chatbot about their case may not be protected?
  3. If a client asked today whether they can use AI to think through their own position, does the firm have an answer, or would three attorneys give three different ones?
  4. Has the firm ever asked a client, in an active matter, whether they have already done this?
  5. If the firm directs a client to use a tool, is that direction documented, and did anyone read that tool’s terms before giving the direction?
  6. Does the firm’s AI policy cover anyone other than firm personnel?

Six documented yes answers. You are a Digital Fortress. Your Forensic Audit Trail exists on paper and would survive scrutiny.

A policy that lives internally but never reaches the engagement letter or the intake conversation. You are a Fragile Hybrid. You built the structure and left the client-facing side open.

Neither. You are a Statutory Time Bomb. The exposure is present, it is undocumented, and the timing of discovery belongs to your adversary.

Shadow AI is not only the tool your associate opened on a personal browser tab. It is the tool your client opened before your first phone call, in a matter you now own.

What three steps close the gap this week?

Start with the client-facing side, because that is where the exposure is oldest and least visible.

Step One. Put it in the engagement letter and say it out loud. Add a provision addressing client use of AI tools in the matter. Then raise it verbally at intake. GRPC 1.4 requires you to explain a matter to the extent reasonably necessary for the client to make informed decisions. A client who does not know that typing case facts into a consumer tool can forfeit protection cannot make that decision.

Step Two. Ask every active client, now. Do not wait for the next intake cycle. Work your open matter list. The question is short. Have you discussed this matter with any AI tool. Document the answer and the date in the file.

Step Three. Decide the direction question and write the decision down. Determine whether the firm will ever direct a client to a specific tool, under what conditions, and who approves it. Write it so that it does not promise privilege protection, because no court has granted that protection. Audit-Ready Compliance means the decision exists in writing before anyone needs it, not after.

What separates the Wild West from the Governance Way?

QuestionThe Wild West WayThe Governance Way
Who does the AI policy cover?Firm personnelFirm personnel and clients
What does the client know?Whatever they assumeThat consumer tools are third parties, told at intake
When is the privilege lost?Assumed to be safe until proven otherwiseUnderstood to be gone at the moment of input
Terms of serviceNobody has read themRead, summarized, and on file before any client data goes near the tool
Client’s own AI useNever discussedAsked about in every active matter, answer recorded
Directing a client to a toolCasual, verbal, unrecordedDeliberate, documented, tool vetted first
Discovery of a problemIn discovery, from opposing counselIn the file, from the client, early
Engagement letterSilentContains a plain-language AI paragraph

The Bottom Line

A federal court has now held that a client’s own exchanges with a consumer AI platform were protected by neither the attorney-client privilege nor the work product doctrine, and that later sharing the material with counsel does not restore protection. The exposure sits inside matters Georgia firms are billing today, and the only defense available is documentation created before the request arrives.

Frequently Asked Questions

Does my client using ChatGPT or a similar tool waive attorney-client privilege in Georgia?
A federal court in New York held that a client’s own exchanges with a consumer AI platform were protected by neither the attorney-client privilege nor the work product doctrine. That decision applies federal common law and is not binding on Georgia state courts. Georgia privilege law requires the same core elements, so a Georgia court confronting the same facts would be reasoning from a similar framework.

If my client shows me the AI output afterward, does that make it privileged?
No. The court addressed this directly and held that sharing the information with the platform waived the protection, and that handing the material to counsel afterward does not restore it. There is no retroactive cure once voluntary disclosure to a third party has occurred.

Does using a paid or enterprise version of an AI tool preserve privilege?
No court has held that it does. The ruling addressed a public consumer version and expressly declined to decide what would happen if counsel had directed the use. Any firm treating an enterprise tier as privilege protection is relying on an assumption rather than an authority.

What does the State Bar of Georgia Generative AI Toolkit say about AI tool terms of service?
The Toolkit warns practitioners about shrinkwrap and clickwrap licenses, which are accepted simply by using a service. It notes those agreements often contain broad disclaimers and may expressly exclude any duty of confidentiality, meaning information shared with such tools may not be protected by any enforceable non-disclosure obligation.

Which Georgia Rules of Professional Conduct apply to client-side AI use?
GRPC 1.4 governs communication and supports raising the issue with the client directly. GRPC 1.6 governs confidentiality of client information. GRPC 5.3 governs supervision of nonlawyer assistants and reaches staff use of AI tools on client matters.

Should I tell clients not to use AI tools for their legal matters?
That is a firm policy decision, not a rule requirement. What GRPC 1.4 supports is making sure the client understands the consequence before they choose. A client who is never told that a consumer tool may strip protection from their own words cannot make an informed decision about using one.

Find out where your firm stands. Take the AI Liability Quiz and find out whether your firm is a Statutory Time Bomb, a Fragile Hybrid, or a Digital Fortress.

This article is provided for general informational purposes and does not constitute legal advice or create an attorney-client relationship. Georgia attorneys should evaluate their own practices against the current Georgia Rules of Professional Conduct and current State Bar guidance.