[HN Gopher] US v. Heppner (S.D.N.Y. 2026) no attorney-client pri...
       ___________________________________________________________________
        
       US v. Heppner (S.D.N.Y. 2026) no attorney-client privilege for AI
       chats [pdf]
        
       Author : 1vuio0pswjnm7
       Score  : 178 points
       Date   : 2026-04-15 13:47 UTC (1 days ago)
        
 (HTM) web link (fingfx.thomsonreuters.com)
 (TXT) w3m dump (fingfx.thomsonreuters.com)
        
       | rogerallen wrote:
       | Previously: https://news.ycombinator.com/item?id=47555642
        
       | jeffbee wrote:
       | Heppner's argument was dumb but it opens a field of interesting
       | questions. If I use a document processor (like Google Docs) to
       | compose a message to my attorney, which message itself would be
       | privileged, but I use some sidebar feature of Google Docs/Gemini
       | to clean up a sentence that I thought was clunky, and elsewhere I
       | have, for whatever reason, enabled features that permit Google to
       | use inputs and outputs to train or refine their models, has that
       | destroyed the privilege?
        
         | mrhottakes wrote:
         | Yes, you lose the privilege if your attorney-client
         | communications are not intended to be confidential. If you
         | agree to share those communications with a third party, you
         | don't intend them to be confidential.
        
           | jeffbee wrote:
           | I don't think that hot take will survive much contact with
           | the near future, at least not without a good deal of
           | controversy.
        
           | margalabargala wrote:
           | What constitutes "Sharing with a third party" though? Using a
           | 3rd party email service like outlook or gmail? Using a third
           | party docs service like google docs?
           | 
           | It doesn't seem right that google docs would be privileged,
           | but if you use the fancy spellcheck button, it no longer is.
        
             | jeffbee wrote:
             | Right, exactly. It is also too much to expect that if a
             | user enabled the "personalization" button in the Gemini
             | app, for unrelated reasons, they now can't expect to
             | compose a privileged email to their counsel. It's a
             | minefield.
        
               | lokar wrote:
               | Well, at Google people get legal advice from in house
               | lawyers via Gmail. Are they not sharing that with at
               | least some of the Gmail team (who could read the email)?
        
               | jeffbee wrote:
               | Gmail users (correctly and reasonably) do not expect the
               | "gmail team" to read their emails, except using glass-
               | breaking incident response privileges that leave audit
               | trails and trigger review. Users expect that email is
               | private. Anyway, both Google's privacy policy and
               | American jurisprudence segregate things like emails,
               | voice calls, and video calls into a separate
               | "communications" category, while Google's privacy policy
               | treats Google Docs as "other content you create", even
               | though the difference seems immaterial if you know how
               | these systems work.
        
               | kevin_thibedeau wrote:
               | Google originally declared that they read all emails.
               | That was semi-changed with the Workspace rollout but
               | there is nothing preventing them from reverting to the
               | old policy. They already do it anyway for reminders
               | extracted from email.
        
               | jeffbee wrote:
               | No normal person believes that systems delivering and
               | classifying messages amounts to "gmail team reads my
               | emails".
        
               | lokar wrote:
               | To me, "read" means by a human. Humans read, computers
               | process.
        
             | shimman wrote:
             | The onus is on the companies to make this clear, if they
             | aren't willing to tell users the dangers of using their own
             | tools that kinda tells you everything you need to know
             | (they don't care about their customers, only $$$).
             | 
             | Be upset at Google for not taking privacy seriously, they
             | never have and never will.
        
           | hrimfaxi wrote:
           | Right so calling my attorney is the same since I'm sharing
           | the call with the phone company.
        
             | altairprime wrote:
             | Nope. The wiretapping laws precedent is known as
             | 'minimization'; when a legal tap is obtained of your phone
             | lines, the expectation is that every effort will be taken
             | not to tap attorney-client calls, lest your entire evidence
             | packet get thrown out for failure to do so. That precedent
             | is not _automatically_ transitive to AI just because one
             | thinks it ought to be; telephone lines between human beings
             | are protected both by extensive case law and also _actual
             | law_ ; neither yet applies between one human and a third-
             | party corporation offering an AI, _especially_ when at
             | least one major AI is contractually declared in shrinkwrap
             | to be 'for entertainment use only'.
        
             | pvtmert wrote:
             | maybe not the call itself but the voicemail for example.
             | can it be "extracted"?
             | 
             | another point to make it safer would be sharing the "chat"
             | with the lawyer, this way it becomes media of communication
        
           | robterrell wrote:
           | But that communication is clearly intended to be
           | confidential. Also isn't having one attorney on a multi-party
           | communication marked confidential sufficient to create
           | privilege?
        
             | mtlynch wrote:
             | When I worked at two different FAANG companies, both legal
             | orientation sessions taught this specific scenario as an
             | example of something that's _not_ attorney-client
             | privileged.
             | 
             | If you email your lawyer to ask legal questions, that's
             | privileged communication.
             | 
             | If you just cc a lawyer on a thread while you talk to other
             | people, adding the lawyer doesn't make the conversation
             | privileged or protected.
        
           | hedora wrote:
           | That is an erosion of the social contract from the early days
           | of SaaS.
           | 
           | The law in the US is based on the expectation of privacy. If
           | companies and the US government repeatedly egregiously share
           | private data in violation of terms of service and the law,
           | then what expectation is there?
           | 
           | 25 years ago, I'd say "Checking the 'do not train on my data'
           | button in an Anthropic account would pretty clearly create an
           | expectation of privacy." These days? OpenAI had to send all
           | such data to the New York Times, the government has been
           | illegally wiretapping the whole planet for decades, the US
           | CLOUD Act exists, and companies retroactively change terms of
           | service all the time.
           | 
           | Heck, Meta has been secretly capturing lewd bedroom videos
           | and paying people to watch them, and _it barely made the
           | news_ , just like the allegations the WhatsApp content
           | moderation team made where they claimed they have access to
           | WhatsApp E2EE content (what other content could they be
           | moderating?!?)
        
         | leni536 wrote:
         | What about email?
        
         | erikerikson wrote:
         | The brief linked above[0] was easy to read. IANAL but in it the
         | author seems to say that online tools fail to meet the
         | confidentiality "test" and explains the ruling in clear
         | language.
         | 
         | [0] https://news.ycombinator.com/item?id=47779377
        
           | jeffbee wrote:
           | I don't know why you think I did not read it. My remark is an
           | application of the 3-point test in the decision to another
           | system.
        
             | erikerikson wrote:
             | Well, hrrm. I thought that because it seemed to start
             | clearly in the document I linked that something like Google
             | docs wasn't safe, regardless of spell checking feature use.
             | However, following my link again, it seems that the
             | referenced post has been edited or something because going
             | to grab a quote, I found myself in a different document
             | than I remember.
             | 
             | I think in hindsight I was remarking, effectively, these
             | two claims (yours and the courts) don't seem to live in the
             | same world. Not your responsibility to resolve my confusion
             | and different parts of the court system can issue edicts
             | that contradict to be later resolved at higher levels of
             | the system so... Sorry I didn't respond within the full
             | context you wrote.
        
       | mmastrac wrote:
       | There is no way that this state of things survives long-term.
       | Rationally, it's really no different than any other tool involved
       | in production of your work product.
       | 
       | FWIW not all cases have gone the same way, so there is likely to
       | be a higher reckoning on this in multiple countries:
       | https://fingfx.thomsonreuters.com/gfx/legaldocs/mypmyjwdzpr/...
        
         | altairprime wrote:
         | They'd have to pass a Senate bill modifying copyright and
         | granting corporate-nonperson status with legal rights to
         | hosted, certified by the bar, registered and renewed AIs
         | _only_. Otherwise the work that's markov'd as 'legal advice'
         | has no origination of record from a legally-recognized entity
         | and therefore can't be affirmed to be legal advice (legal
         | advice is not public domain, or else protections would be
         | drastically weakened; and, provided by A to B test fails: no
         | such entity A), and anyone could claim the entirety of their
         | email as protected from discovery by 'cc'ing AI' for legal
         | advice on every email for a vacation responder reply emitted by
         | a self-hosted trepanned agent (a corrupted lawyer can still
         | give protected legal advice).
         | 
         | Or, they'd have to assert that content generated by AI on
         | behalf of a user is protected -- there's no way to tell whether
         | it's legal advice so it all must be treated as such (can't
         | trust the AI to judge this, given how hallucinatory they are in
         | legal filings!) -- at which point AI companies would be refused
         | the right to harvest your AI conversations for further training
         | and profit-extraction (which would subject them to prosecution
         | for, of all things, illegal wiretap under SS2511(1)(e)(i) if
         | not others). Google would never allow that to happen, seeing as
         | how that's literally _their entire business_.
         | 
         | I fully expect someone to set up the equivalent of HIPAA for
         | legal advice AIs and for _that_ to be found acceptable for
         | instances hosted in protected enclaves, but the big four's main
         | products aren't likely to qualify for that until they solve
         | hallucinations and earn back judges' trust.
         | 
         | (I am not your lawyer, this is not legal advice. Ironically, I
         | wouldn't have to say this if it was AI writing. Heh.)
        
         | fny wrote:
         | > "Plaintiff, as a pro se litigant, has a right to assert work
         | product protection over such material."
         | 
         | This just argues _attorneys_ have this protection--which is
         | true. Typical plaintiff 's do not have the same level of
         | protection.
        
       | siliconc0w wrote:
       | This is a pretty terrible decision and inconsistent with all
       | sorts of all other standards. If I did legal research in Google
       | docs, it'd be covered. If I went to a legal library and took
       | notes, it'd be covered, etc
        
         | bobro wrote:
         | Chatting with Claude strikes me as fundamentally different from
         | writing your own notes.
        
       | pvtmert wrote:
       | people point out in sibling comments that is phone call then be
       | out of client-attorney privileges? since it goes through a "3rd
       | party"? maybe not the call itself but the voicemail for example.
       | can it be "extracted" for the same purpose?
       | 
       | another point to make it safer would be sharing the "chat" with
       | the lawyer, this way it becomes media of communication.
        
         | asdfasgasdgasdg wrote:
         | Well, what type of phone call? You mean a phone call between a
         | lawyer and a client? If so, then, of course it is protected,
         | because it is communication between the lawyer and the client.
         | It is not a good analogy for Claude chats because those chats
         | are not communication between a laywer and a client.
         | 
         | The concept of sharing the chat with the lawyer will not work,
         | since as the ruling points out, you cannot turn a non-
         | privileged document into a privileged one by sharing it with
         | your lawyer after the fact.
        
           | avaer wrote:
           | > It is not a good analogy for Claude chats because those
           | chats are not communication between a laywer and a client.
           | 
           | How is it not? I get that a chatbot is not a person with
           | rights. And NAL.
           | 
           | But for all intents and purposes, it _is_ a communication
           | about legal advice. The way a lot of people use it _is_ legal
           | advice. They will continue to use it that way.
           | 
           | So for the law to then turn around and say that it's evidence
           | that will be used against them is kind of messed up. It means
           | confidentiality of your case is bought by paying a lawyer for
           | legal protection, not because you actually need their advice
           | over a chatbot's.
        
             | compass_copium wrote:
             | It's not a communication with a lawyer, though. Asking a
             | guy on the street if it's illegal to sell the meth you have
             | in your pocket is not privileged communication, and he
             | could definitely testify about that after you got arrested!
        
               | submerge wrote:
               | That would be hearsay, yes?
        
               | compass_copium wrote:
               | -\\(o O)/- maybe, IANAL
        
               | jmalicki wrote:
               | Why? He heard you say it and can testify to it.
        
               | TheCoelacanth wrote:
               | Repeating something that you heard someone say is the
               | literal definition of hearsay. Typically courts want to
               | hear about facts from people who actually know those
               | facts, not someone who heard someone talking about those
               | facts.
               | 
               | This would fall under the "statement against interest"
               | exception to hearsay, though, because obviously the
               | person who originally said the thing isn't going to want
               | to admit in court that they were committing a crime.
        
               | jmalicki wrote:
               | The fact is that he said it.
               | 
               | You aren't repeating a fact you heard him say, you are
               | reporting what you heard him say.
        
               | TheCoelacanth wrote:
               | Reporting what you heard someone say is the literal
               | definition of hearsay.
               | 
               | If you want to use someone saying something as evidence
               | in court, they need to say it to the court as directly as
               | is practical. If the person saying it isn't going to say
               | it directly to the court, then it needs to be justified
               | with one of the exceptions to the hearsay rule.
               | 
               | In this example, it would be allowed because the person
               | saying it wouldn't be willing to admit to a crime in
               | court.
        
               | jmalicki wrote:
               | It's a statement not offered to prove the truth of the
               | asserted statement - non-hearsay.
               | 
               | It would be hearsay if offered as evidence that you had
               | meth in your pocket. It would not if offered in evidence
               | you were enquiring about the legality, to show intent.
        
             | salawat wrote:
             | Government decides not to make it's own ability to make a
             | case and use what you do against any more difficult. More
             | at 11.
        
             | asdfasgasdgasdg wrote:
             | Because as you correctly point out the chatbot is not an
             | attorney. Thus no attorney client privilege.
        
             | simonreiff wrote:
             | It's not a communication if only one human person
             | participates in the conversation. That's just enhanced
             | note-taking and generating. I don't agree with the notion
             | that talking to an LLM is disclosure to a third party
             | because an LLM is neither a natural person nor even an
             | artifical person recognized at law like a corporation,
             | trust, LLC, etc.
        
           | impossiblefork wrote:
           | I don't think it's communication at all. Instead, I think
           | it's a kind of _lookup_. Dealing with an LLM is searching a
           | database. You are looking up legal texts in order to prepare
           | legal arguments.
           | 
           | I think the principled way of treating this is that it's
           | privileged for the purpose of preparing legal arguments, but
           | not privileged in general. I think this can be supported
           | using the existing law.
           | 
           | Presumably a lawyer's Google searches with terms like "what
           | article is X" etc. are privileged too, since they are used
           | for preparing legal arguments. That it uses AI doesn't
           | suddenly make it communication.
        
           | jmalicki wrote:
           | So I can't turn an unprivileged draft email into a privileged
           | email by hitting send?
           | 
           | At what point does my typing become communications with my
           | lawyer?
        
             | jmalicki wrote:
             | Reading the decision, they seem to say that online word
             | processing software would be viewed similarly, since the
             | TOS may allow Google to see your data, it is not
             | confidential, so use of Google Docs or Gmail would not be
             | considered privileged?
             | 
             | WTF
        
           | mcintyre1994 wrote:
           | > you cannot turn a non-privileged document into a privileged
           | one by sharing it with your lawyer after the fact.
           | 
           | Surely this is how all async communication with a lawyer
           | works though? Or are gmail drafts privileged if you can make
           | a case that it was going to be sent to your lawyer? Is a
           | letter at your house privileged if you can make a case that
           | it was going to be sent to your lawyer?
        
             | DannyBee wrote:
             | Lawyer here: So first, while this entire comments section
             | seems to treat privilege as if their is a single universal
             | corpus of law around it, their isn't. Federal and and state
             | courts do different things here. Each state does different
             | things than other states.
             | 
             | It's therefore practically hard to give a useful answer to
             | your questions. There are states and courts that don't
             | recognize drafts as privileged. There are states that do as
             | long as they are created for the purpose of seeking legal
             | advice. There are states in between.
             | 
             | Also keep in mind the main goal of _this_ kind of privilege
             | is to ensure people seek legal advice, and feel comfortable
             | doing so, _before_ they do something that's going to get
             | them into trouble. it does protect your ability to prepare
             | a defense, and that sort of thing,but if you do a thing
             | after you email your lawyer and the lawyer says  "that is a
             | horribly illegal idea", privilege isnt really there to help
             | you, even if that particular email often happens to be
             | privileged. It's there to help society, not keep you from
             | having to pay damages. For example, Companies overuse
             | lawyers in things like clean up after security incidents -
             | very little of that will be actually privileged from
             | discovery no matter how many lawyers got involved.
             | 
             | All that said general advice is to ensure drafts are
             | deleted after being sent.
             | 
             | The only real common thing in this area of law is that the
             | party trying to withhold the document bears the burden of
             | showing it is privileged.
        
         | jerf wrote:
         | The law has a concept of a "carrier" [1], and has the ability
         | to judge whether or not the carrier in question is responsible
         | for what it is carrying.
         | 
         | I'm not making a blanket statement that that means everything
         | is a carrier, because a good chunk of the page I linked is
         | devoted to endless legal nuances and I defer the _details_ of
         | the concept to those who know better. I 'm just saying that the
         | law has a well-established concept for this sort of situation,
         | such that it is not the case that just because a third party is
         | involved instantly all protections dissolve. If you really want
         | to dig into the details, that's something an AI that hits the
         | web and digests things would be pretty good at, as long as
         | you're not planning on legal action based on that. Sometimes
         | the hardest part of learning about something is just finding
         | the term for it that lets you dig in.
         | 
         | [1]: https://en.wikipedia.org/wiki/Common_carrier
        
         | SpicyLemonZest wrote:
         | > another point to make it safer would be sharing the "chat"
         | with the lawyer, this way it becomes media of communication.
         | 
         | This guy made the same argument, but as the court detailed,
         | this is a misunderstanding of attorney-client privilege.
         | Sharing an unprivileged conversation with your lawyer doesn't
         | make it privileged. A phone call _to your lawyer_ is
         | privileged, but a phone call to your cousin Jimbo about what
         | you should tell your lawyer is not.
        
       | MengerSponge wrote:
       | I'm guessing a self-hosted chat remains privileged?
        
         | asdfasgasdgasdg wrote:
         | Definitely not, unless you are acting as your own advocate.
         | Self-hosting does not offer any form of protection. Just like
         | notes you write yourself on your PC, a self-hosted chat could
         | be used as evidence against you.
        
           | nullc wrote:
           | Private notes you make for the purpose of working with your
           | lawyers are privileged.
        
             | baq wrote:
             | Takeaway is write stuff down and securely delete the local
             | chat archive
        
         | baq wrote:
         | Yes if you thoroughly shred the archives.
        
       | fny wrote:
       | I highly recommend everyone actually read the opinion. It's such
       | a thorough legal takedown of Heppner, you'll learn how the law
       | works and why it doesn't apply to a lot of the made up cases in
       | this thread:
       | 
       | TLDR:
       | 
       | - Claude told him IANAL
       | 
       | - Claude privacy policies say they "may disclose personal data to
       | third parties in connection with claims, disputes, or litigation"
       | 
       | - Work product doctrine, _does not apply_ in the same way to
       | plaintiffs
       | 
       | - Lawyers did not direct him to use Claude (i.e. the laywers did
       | not direct him to do research for the case using a specific tool)
       | 
       | My takeaway is that, as is, I should not do any work without a
       | VPN or in plaintext. Everything else was up for grabs even before
       | this case.
        
         | asdfasgasdgasdg wrote:
         | Is a VPN really going to help here? I guess if you can figure
         | out a way to pay Claude anonymously. But if you are charged
         | with a crime and your computer is siezed, and there is some way
         | to discover your Claude account from the contents of your
         | computer, then you will be up a creek either way.
         | 
         | My takeaway is: don't do crime, and if you must do crime, don't
         | use AI in the commission of a crime, in a similar way as it is
         | unwise for criminals to keep recordings of their own phone
         | conversations or what have you (a surprisingly common habit for
         | criminals!).
        
           | randallsquared wrote:
           | That's a great takeaway, but may not be practically
           | achievable in the world where
           | 
           | > _The average professional in this country wakes up in the
           | morning, goes to work, comes home, eats dinner, and then goes
           | to sleep, unaware that he or she has likely committed several
           | federal crimes that day._
           | 
           | -- https://www.amazon.com/Three-Felonies-Day-Target-
           | Innocent/dp...
        
             | gruez wrote:
             | That claim by the way, is totally unsubstantiated, and the
             | cases have very questionable applicability to the "average
             | professional".
        
               | metalliqaz wrote:
               | I once saw a talk given by a lawyer on exactly this
               | topic. It was a long time ago, unfortunately I won't be
               | able to find it. Anyway, the takeaway is that there are
               | plenty of Federal laws that are written in such a way
               | that there is incredible room for interpretation by
               | prosecutors. Vagueness and overbroad language to the
               | point that indeed they can come up with some kind of
               | crime pretty much any time they want to.
               | 
               | On the other hand, that kind of thing would not _only_ be
               | enough to bring a case. They use that kind of power to
               | enhance their case against people they know are real
               | criminals. Of course, the more the Justice Department
               | becomes captured by bad actors, the less this applies.
        
               | yonaguska wrote:
               | In a state that I lived in, one day the laws changed and
               | I became a felon overnight for not registering certain
               | inanimate objects with my state govt.
        
             | asdfasgasdgasdg wrote:
             | I don't think very many people charged with federal crimes
             | are actually just innocent bystanders. So even if we grant
             | that people are technically committing three felonies a day
             | (which I don't) I think the admonition can simply be read
             | "don't do crimes that a federal prosecutor might actually
             | charge you with."
        
         | impossiblefork wrote:
         | Yes, but he's still using it to prepare his legal arguments and
         | to understand the law.
         | 
         | The reason attorney-client communication is privileged is so
         | that people won't interfere in people's preparation of their
         | case, not because the lawyer is magic. The principled thing is
         | for the courts to apply principles like this based on the
         | principle.
        
           | asdfasgasdgasdg wrote:
           | According to the ruling's citations, the purpose of the
           | privilege is to provide protection for the mind of the
           | advocate. If you're not the advocate and you're not talking
           | to the advocate the privilege doesn't apply. Should-bes in
           | this case are imponderable to me but that appears to be what-
           | is.
        
             | impossiblefork wrote:
             | Yes, I think that's completely wrong. It focuses on the
             | advocate as some kind of special role, but I think the core
             | problem is preparing for a court case, and I don't think it
             | makes sense to focus on him.
             | 
             | I think an accused should be able to make strategy notes
             | for a court case and be able to have those be secret from
             | the prosecution, and to look up things for these purposes,
             | and, to use Google docs etc. if he so wants.
             | 
             | I also see that some other comments describe that work
             | product has previously been treated as a broader notion
             | with less focus on the advocate and more on preparing for
             | the court case, so I'm far from convinced this has been
             | decided correctly.
        
               | asdfasgasdgasdg wrote:
               | I understand why you feel that way, but the current
               | policy is not in the direction you are hoping for. The
               | important thing to understand is that all evidence is
               | available by default, that privilege covers the
               | _exceptions_ to that availability. Privilege is construed
               | narrowly, and for now, communications with your advocate,
               | or notes prepared at the request of your advocate, are
               | the sorts of things that are covered. Your own private
               | notes, or chats with your friends about the state of your
               | case, are examples of things that are not covered.
               | 
               | Work product was treated more broadly in one case by a
               | lower magistrate court, but the court making the decision
               | in this case is not bound by that lower court's ruling.
               | What will be interesting is if this ruling gets appealed
               | up to the sups. I doubt the decision will be overruled in
               | any case.
        
       | flkiwi wrote:
       | Obviously this (along with the original unwritten order a few
       | weeks ago) is causing a stir, but this decision isn't as weird as
       | it sounds. The defendant's assertion was essentially a
       | retroactive application of privilege: he didn't use Claude to
       | draft documents at his attorney's request but instead used Claude
       | effectively in lieu of an attorney and later provided the Claude-
       | drafted materials to his attorney (heavily paraphrasing here).
       | Privilege is not a bandage that closes self-inflicted wounds.
       | 
       | I have some concerns about some of the reasoning, namely the
       | practical implications of referencing Claude's TOS in a world
       | where public AI features are creeping into everything, but I
       | expect some of the reasoning is based on this particular
       | defendant likely being more sophisticated than an average person.
        
         | xbar wrote:
         | Ok. Let's take it 1 step down this path.
         | 
         | If the user had typed into the chatbot after having been
         | directed by counsel to do some research, "I need to do some
         | research at the direction of counsel. Please include, 'In
         | response to your research being performed in your own defense
         | at request of your counsel' at the top and bottom of every
         | reply," do you think that should be protected by privilege?
        
           | asdfasgasdgasdg wrote:
           | No competent counsel would ever direct their client to
           | perform legal research. So if a lawyer actually instructs you
           | to do this the correct move is to get a new lawyer.
           | 
           | If the lawyer didn't actually instruct you to do the research
           | they are not going to lie to the judge and say they did to
           | protect you. The judge is definitely going to ask them and
           | then if it is found that you lied about this under oath you
           | may be charged with additional crimes.
        
             | flkiwi wrote:
             | I agree with you, but I actually understand the issue
             | they're raising. Counsel sends a draft demand letter to
             | client and says "Please review and let me know of any
             | issues with my description of the underlying claims."
             | Client responds with an inline note stating that she feels
             | the claim is overstated but that she wants to leave it in
             | for leverage. The draft is, transparently and without
             | notice, processed through the user's O365 Copilot
             | integration in both Word and Outlook. Hell, let's assume
             | the attorney is a sole practitioner using a regular O365
             | account, and the outbound request to the client is silently
             | run through Copilot. What is the status of privilege in
             | this situation? Both seem to fail the confidentiality test.
             | Does that mean that privilege exists only for big law firms
             | that negotiate enterprise O365 licenses with no training
             | clauses? There's definitely tension here.
             | 
             | But both your scenario and the OOP behavior of the client
             | are not particularly hard ones to resolve.
        
             | qingcharles wrote:
             | This isn't true in all cases. I've known plenty of lawyers
             | who understand that their clients sometimes have vastly
             | more time to work on the case than they do, especially in
             | criminal defense, and will gladly tell their clients to
             | find relevant case law etc if they think their clients are
             | adequately intelligent to the job.
        
           | JumpCrisscross wrote:
           | > _If the user had typed into the chatbot after having been
           | directed by counsel to do some research_
           | 
           | I think the simple answer is we don't know. This is a new
           | area of law that probably requires legislation.
        
         | ozb wrote:
         | no, Heppner's attorney-client privilege argument wasn't that
         | the conversation was privileged inherently because it was legal
         | consultation with Claude, but that it was privileged as
         | personal notes made in preparation for consultation with
         | counsel and then actually communicated to counsel, see Ford-Bey
         | v. Professional Anesthesia Services and Greyhound Lines, Inc.
         | v. Viad Corp.
         | 
         | Rakoff makes two arguments against this:
         | 
         | - privilege was broken because Claude/Anthropic is a third
         | party; but I don't think he successfully distinguishes Claude
         | from say Google Docs/Translate/Gmail in this regard (he just
         | notes that Google Docs isn't usually claimed to confer
         | privilege on its own; but this is not the claim being made
         | about Claude either); and see NYSBA ethics rules 820 and 842)
         | 
         | - he quotes Gould v Mitsui: documents do not "acquire
         | protection merely because they were transferred" to counsel;
         | but that same case says they do acquire protection if
         | communicated "for the purpose of obtaining or rendering legal
         | advice"
        
           | flkiwi wrote:
           | I didn't say he said it was privileged because he consulted
           | with Claude for legal purposes so I'm not sure where that
           | came from.
           | 
           | Re: Mitsui, it's not the same case. It's the same paragraph.
           | And it's pretty clear from the context that, if I send my
           | lawyer an email requesting legal advice, the contents of that
           | email are privileged, but if I attach pre-existing documents
           | those documents are not, because they had no privilege to
           | begin with. That's not controversial. The challenge comes
           | from the interplay between the court's description of the
           | privilege test, the reasonable expectations of a technology
           | user, and the underlying, possibly obfuscated, reality of
           | that technology's function. Read literally, this case
           | undermines privilege for a wide range of laypeople and
           | attorneys doing a wide range of normal activities that have
           | nothing to do with asking Claude for trial strategy.
        
             | ozb wrote:
             | You're right, I either misread your comment or got confused
             | with a different comment or something.
             | 
             | But I do think the Mitsui point is relevant; in particular,
             | the claim that the citation is supposed to back up is:
             | 
             | "Moreover, even assuming that Heppner intended to share
             | these communications with his counsel and eventually did
             | so, it is black-letter law that non-privileged
             | communications are not somehow alchemically changed into
             | privileged ones upon being shared with counsel."
             | 
             | But the distinction Mitsui is actually making is rather
             | different: between communications "for the purpose of
             | obtaining or rendering legal advice" and not; that's at
             | best orthogonal to Rakoff's claim; and the other two cases
             | I mentioned pretty explicitly make the opposite case:
             | documents written with intent to share with counsel, and
             | then actually shared with counsel seeking legal advice, are
             | in fact covered under privilege. The assumption being that
             | the documents are not "pre-existing", they're created as
             | part of the process of communicating with counsel.
             | 
             | But yes, I agree that the "third-party" point separately
             | undermines privilege in many contexts.
        
       | Sevii wrote:
       | How is this not effectively a ban on representing yourself in
       | court? The lawyers and judge are going to be using AI. But the
       | layman isn't allowed to use it?
        
         | AnimalMuppet wrote:
         | I _think_ this means that if lawyers use it, they have also
         | lost confidentiality. That could be a significant issue in a
         | big case.
         | 
         | [Edit: Or maybe not, legally. But they have definitely lost
         | confidentiality in the "corporate secrets" sense, and that may
         | still matter.]
        
           | xbar wrote:
           | This is really the question. Conversely, why would an
           | attorney get to have privilege over chatbot interactions in a
           | manner that an individual using a chatbot for self-defense
           | not have such privilege?
        
           | jcranmer wrote:
           | If lawyers use it, they may have the ability to claim work
           | product exemption, although this itself is going to be
           | dependent on a lot more factors I can't analyze.
        
         | bawolff wrote:
         | Its no different then if you ask a friend (who is not your
         | lawyer) for advice. You can ask anything you want, it just only
         | gets the special protection if it is actually your lawyer.
        
           | GJim wrote:
           | The AI is a glorified search engine, not a human!
        
             | adampunk wrote:
             | And?
        
         | SkyBelow wrote:
         | So, how would it apply to web searches? If a lawyer searches
         | something for a person's case, is it protected? If a person
         | searches something for their own case, does it have a similar
         | level of protection? Seems AI chats would need to follow the
         | same rules.
        
         | yonaguska wrote:
         | This is exactly what it is. I know someone that's essentially
         | representing themselves in family court. They had attorneys but
         | the attorneys are basically useless for you if the opposition
         | has more money and can spam you with motions that they are
         | using AI to generate. which you then need to pay a lawyer to
         | respond to. They since began representing themselves due to
         | lack of money, and lawyer incompetence, and actually started to
         | shut down the opposition... then the judge threatened contempt
         | of court and jail time during one hearing if they chose to
         | continue to make a statement and not accept a court appointed
         | attorney to speak for them. Family court in the US is an
         | absolute farce. The same judge recently started asking about
         | "chatGPT" and mentioning that anything there would need to be
         | disclosed to the courts. The person I know was primarily using
         | their own local machine and models, however.
        
           | qingcharles wrote:
           | It's just not family courts. Judges absolutely loathe anyone
           | who appears without counsel, mostly because they've been
           | burned with too many sovcits and other nonsense that jams up
           | the systems. So, even if you are competent they will try
           | everything they can to shut you down and won't give you much
           | time of day versus the party with the lawyers.
        
             | watwut wrote:
             | There is also the possibility that the person in question
             | aggravated the judge by acting in a bonkers way. I have
             | totally seen that - someone not understanding rules and
             | procedures making all the wrong moves and then framing
             | themselves as unfair victim.
        
       | mystraline wrote:
       | I'm not surprised at all. Corporate LLM chats are saved, used as
       | training corpus, and are definite target for discovery.
       | 
       | Running your own LLM on your own hardware is how you can do this
       | without getting hit with discovery.
       | 
       | And also, you want to run a LLM thats abliterated and larger. And
       | if you connect to the internet, USE A VPN.
        
       | dathinab wrote:
       | The headline is a bit misleading.
       | 
       | It's not "no attorney-client privilege for AI chats" in general.
       | 
       | But a situation where the same would also apply if, instead of
       | going to an chat bot, the person had gone to a random 3rd party
       | non-attorney related person.
       | 
       | As in:
       | 
       | - the documents where not communication between the defendant and
       | their attorney, but the defendant and the AI
       | 
       | - the AI is no attorney
       | 
       | - the attorney didn't instruct the defendant to use the AI / the
       | court found the defendant did not communicate with the AI with
       | the purpose of finding legal consule
       | 
       | - the communications with the AI (provider) where not
       | confidential as a) it's a arbitrary 3rd party and b) they
       | explicitly exclude usage for legal cases in their TOS
       | 
       | Still this isn't a nothing burger as some of the things the court
       | pointed out can become highly problematic in other context. Like
       | the insistence that attorney privilege is fundamentally build on
       | a trusting human relationship, instead of a trusting
       | relationship. Or that AI isn't just part of facilitating
       | communication, like a spell checker, word program or voice mail
       | box, legal book you look things up. All potentially 3rd parties
       | all not by themself communication with a human but all part of
       | facilitating the communication.
        
       | neogodless wrote:
       | Related:
       | 
       | https://news.ycombinator.com/item?id=47778308 _AI ruling prompts
       | warnings from US lawyers: Your chats could be used against you_
       | (reuters.com)
       | 
       | ~3 hours ago, 43+ comments
       | 
       | https://news.ycombinator.com/item?id=47555642 _Be careful:
       | chatting with AI about your case is discoverable_
       | (harvardlawreview.org)
       | 
       | ~18 days ago, 13 comments
        
       | dumah wrote:
       | Use Kovel.
       | 
       | https://law.resource.org/pub/us/case/reporter/F2/296/296.F2d...
        
       | malcolmgreaves wrote:
       | tl;dr Don't be arrogant, get an attorney so you can enjoy
       | attorney-client privileges. An LLM isn't an attorney.
        
         | nullc wrote:
         | Yeah, silly less than stupendously rich people-- who do they
         | think they are? trying to have confidentiality. ha.
        
           | watwut wrote:
           | LLM is not attourney whether you are rich or not.
        
       | int32_64 wrote:
       | Are there any model providers that don't log chats? It seems like
       | a good market opening.
       | 
       | I wonder if anybody has gone all the way and made a darknet LLM
       | service with no logs served only over TOR with XMR payments.
        
         | poplarsol wrote:
         | strongwall.ai is logless and supports anonymous payments
         | including physical cash.
        
           | bredren wrote:
           | This sounded pretty good, a ~mullvad for LLM. Then:
           | 
           | > Strongwall.ai is led by Andrew Northwall, CEO and Bryce
           | Nyeggen, CTO. Andrew has 20+ years in tech, former COO of
           | Trump Media & Technology Group, architect behind the relaunch
           | of Parler, and senior technologist for large-scale
           | infrastructure and AI systems.
        
         | ZoneZealot wrote:
         | None that operate legally will be able to avoid logging chats
         | when ordered to do so.
         | 
         | For example OpenAI were required by a US federal judge to log
         | all chats, and make them discoverable to lawyers representing
         | The New York Times last year.
         | https://www.businessinsider.com/openai-new-york-times-copyri...
         | 
         | Additionally the company can be gagged by a court from
         | disclosing that the chats are being logged, at least in the USA
         | and the UK.
        
           | poplarsol wrote:
           | There is a legal distinction between document retention,
           | which is what OpenAI was ordered to do, versus re
           | architecting to generate documents for logless providers.
        
             | ZoneZealot wrote:
             | OpenAI were already logging all the chats, it's just that
             | if the end-user decided to delete their chat history - they
             | would respect that at the time and also delete it server
             | side (apparently). The court order mandated them keep the
             | chat content even if the end-user wanted it deleted.
             | 
             | They were required to change the way their systems worked,
             | to no longer respect a user's chat deletion request. That
             | means a non-chat-logging company can of course be forced to
             | change the way their system works, to instead log chats.
             | 
             | In the same way Apple can not only be forced to hand over
             | back-doored access to UK users iCloud data (when Apple also
             | hold a copy of the keys), they can also be forced to change
             | the way their OS works to prevent the scenario where Apple
             | don't hold the keys (preventing Advanced Data Protection
             | from being enabled). The USA could force the same thing via
             | the CLOUD Act.
        
               | poplarsol wrote:
               | "You have to make a change either way" is not the
               | standard. Of course legislation can be passed or a
               | settlement signed that mandates whatever, but there is
               | well established civil procedure around document
               | retention in the context of discovery for ongoing
               | litigation that does not extend to demands to start
               | _generating_ business records that are not currently
               | created.
        
           | bluGill wrote:
           | Although a good lawyer can appeal a board order. What the
           | courts will say is unknown, but there are real constitutional
           | questions about ordering everything.
        
           | int32_64 wrote:
           | The Lavabit case years ago was quite scandalous, things have
           | only gotten worse. There should have been much harsher limits
           | on what companies can be compelled to do.
        
       | 1vuio0pswjnm7 wrote:
       | "Judge Rakoff issued an oral ruling that neither the attorney-
       | client privilege nor the work product doctrine protected the AI-
       | generated documents.12 The decision rests on traditional
       | principles of privilege.
       | 
       | The attorney-client privilege protects (1) communications, (2)
       | among only privileged parties, (3) made for the purpose of
       | providing or obtaining legal advice.13 Importantly, the
       | protection of the attorney-client privilege is lost if the
       | communication is shared outside of the privileged parties.14 The
       | party claiming privilege has the burden of showing that
       | confidentiality was maintained.15 Judge Rakoff stated that the
       | attorneyclient privilege did not apply because the communications
       | were shared with a thirdparty tool that did not maintain
       | confidentiality.16
       | 
       | Second, Judge Rakoff held that the work product doctrine did not
       | protect the documents.17 The work product doctrine protects (1)
       | legal work product, (2) discussing legal strategy, (3) prepared
       | by or at the direction of legal counsel, (4) in anticipation of
       | litigation.18 Judge Rakoff rejected Heppners arguments that the
       | work product doctrine could apply because the AI-generated
       | reports did not reflect the legal strategy of Heppners legal
       | counsel, although they contained theories generated by the client
       | and Claude.19 Since neither Heppner nor the AI tool are legal
       | counsel, and Heppner was not working at the direction of Heppners
       | legal counsel, the materials were not protected by the work
       | product doctrine. Judge Rakoff noted that the AI tools disclaimer
       | that users have no expectation of confidentiality also undermined
       | the work product doctrine claim.20
       | 
       | 12 Transcript of Pretrial Conference at 6, _United States v.
       | Heppner_ , No. 25-cr-00503-JSR (S.D.N.Y. Feb 10, 2026).
       | 
       | 13 See _United States v. Mejia_ , 655 F.3d 126, 132 (2d Cir.
       | 2011).
       | 
       | 14 See _In re Six Grand Jury Witnesses_ , 979 F.2d 939, 943 (2d
       | Cir. 1992).
       | 
       | 15 See _In re Grand Jury Subpoenas_ Dated Mar. 19, 2002 and Aug.
       | 2, 2002, 318 F.3d 379, 384 (2d Cir. 2003).
       | 
       | 16 Tr. at 3, _Heppner_ , No. 25-cr-00503-JSR.
       | 
       | 17 _Id._ at 6.
       | 
       | 18 See _In re Grand Jury Subpoenas_ , 318 F.3d at 383.
       | 
       | 19 Tr. at 5, _Heppner_ , No. 25-cr-00503-JSR.
       | 
       | 20 _Id._ at 6. "
       | 
       | https://www.debevoise.com/-/media/files/insights/publication...
       | 
       | "Reasons Privilege Failed
       | 
       | 1
       | 
       | No attorney was involved. An AI tool is not a lawyer. It has no
       | law license, owes no duty of loyalty, cannot form an attorney-
       | client relationship, and is not bound by confidentiality
       | obligations or professional responsibility rules. Discussing
       | legal matters with an AI platform is legally no different from
       | talking through your case with a friend.
       | 
       | 2
       | 
       | Not for the purpose of obtaining legal advice. Anthropic's own
       | public materials state that Claude follows the principle of
       | choosing the "response that least gives the impression of giving
       | specific legal advice." The tool explicitly disclaims providing
       | legal services. You cannot claim you used a tool for legal advice
       | when the tool itself says it does not provide it. Claude's terms
       | were specifically highlighted by the government, which directly
       | undermined the claim that Heppner was seeking legal advice from
       | the tool.
       | 
       | 3
       | 
       | Not confidential. This is the finding with the broadest
       | implications. Anthropic's policy expressly states that user
       | prompts and outputs may be disclosed to "governmental regulatory
       | authorities" and used to train the AI model. Judge Rakoff found
       | there was simply no reasonable expectation of confidentiality. As
       | he put it, the tool "contains a provision that any information
       | inputted is not confidential." This is not unique to Claude.
       | OpenAI's privacy policy contains comparable provisions permitting
       | data use for model training and disclosure in response to legal
       | process.
       | 
       | And the distinction between free and paid plans matters less than
       | many assume. Both Anthropic and OpenAI use conversations from
       | free and individual paid plans (Claude Free, Pro, and Max;
       | ChatGPT Free, Plus, and Pro) for model training by default. Users
       | can opt out, but opting out of training does not eliminate the
       | platforms' rights to disclose data to government authorities or
       | in response to legal process. Only enterprise-tier agreements
       | (ChatGPT Enterprise and Business; Claude's commercial and
       | government plans) exclude user data from training by default and
       | offer contractual confidentiality protections. A $20-per-month
       | subscription does not buy you privilege.
       | 
       | 4
       | 
       | Pre-existing documents cannot be retroactively cloaked in
       | privilege. The AI-generated documents were created by Heppner
       | before he transmitted them to counsel. Sending these unprivileged
       | materials to his lawyers after the fact did not retroactively
       | make them privileged.
       | 
       | Implications for waiver of privilege
       | 
       | Heppner fed information he had received from his attorneys into
       | Claude. The government argued, and Judge Rakoff agreed, that
       | sharing privileged communications with a third-party AI platform
       | may constitute a waiver of the privilege over the original
       | attorney-client communications themselves. The privilege belongs
       | to the client, but so does the responsibility to maintain it."
       | 
       | https://natlawreview.com/article/your-ai-conversations-are-n...
       | 
       | "Privacy policies, including the one on Claude's website, openly
       | inform users how their data is used. However, very few users
       | actually read the fine print on these privacy policies, or even
       | know these policies exist in the first place. It would probably
       | surprise most people to learn that Claude's privacy policy
       | explicitly gives its parent company, Anthropic, the right to
       | disclose a user's data to third parties in connection with legal
       | disputes and litigation."
       | 
       | https://nysba.org/loose-ai-prompts-sink-ships-how-heppner-sh...
        
       | drivebyhooting wrote:
       | So use local or Chinese models instead? Got it.
        
       | anonymousiam wrote:
       | Here's my question: If the attorney-client privilege, and more
       | importantly, the work product doctrine don't apply here, would
       | they also not apply to direct conversations between an attorney
       | and an AI?
       | 
       | It seems to me that the court would need to apply some twisted
       | logic to claim that those protections apply to an attorney, but
       | not to a petitioner or respondent.
        
         | ozb wrote:
         | The ruling explicitly overrules Shih, thus making exactly that
         | argument:
         | 
         | > Shih, of course, is not binding on this Court, and this Court
         | respectfully disagrees with its holding. As relevant here, the
         | court in Shih principally concluded that the work product
         | doctrine is not limited to materials prepared by or at the
         | direction of an attorney. Id. But that conclusion undermines
         | the policy animating the work product doctrine, which, as one
         | of the cases cited in Shih explains, is "to preserve a zone of
         | privacy in which a lawyer can prepare and develop legal
         | theories and strategy 'with an eye toward litigation.'"
        
           | BobaFloutist wrote:
           | Does that imply that materials produced by the client in
           | conversation with the attorney (e.g. attorney says to client
           | "Ok write here in your own words what happened so I can
           | understand your perspective") are _not_ privileged?
           | 
           | Or would those presumably exist under the umbrella of privacy
           | because they're relevant to the lawyer preparing and
           | developing their legal strategy?
        
         | Digory wrote:
         | 1. "Conversation" is purely anthropomorphism. It's software
         | input and output. If the client makes an excel spreadsheet
         | about the cost benefit of ripping off people, it's not work-
         | product.
         | 
         | But the lawyer's draft damages analysis in excel has always
         | been protected.
         | 
         | 2. If we're going to buy the "conversation" conceit, lawyers
         | talking to consulting experts have always had a lot more work
         | product protection than testifying experts.
         | 
         | The lawyer talking to Claude feels like talking to a consulting
         | expert, especially since Claude can't have independent
         | knowledge of facts that would allow it to testify.
        
           | pclmulqdq wrote:
           | A spreadsheet I produce for myself probably isn't attorney-
           | client privileged. A spreadsheet or word document I produce
           | for my lawyer can be attorney-client privileged (especially
           | if it's literally only for the lawyer). If a ChatGPT or
           | Claude chat is legally like a spreadsheet, it sounds like
           | it's probably not privileged, but a ChatGPT chat you create
           | "for your lawyer" would be.
        
         | GJim wrote:
         | > direct conversations between an attorney and an AI
         | 
         | For the love of God! I hope an attorney isn't stupid enough to
         | share a client confidential and personal data with an
         | effectively unregulated AI.
        
           | anonymousiam wrote:
           | With so many attorneys using AI to write their court filings
           | (and many being fined for the AI-generated hallucinations), I
           | suspect there are many stupid attorneys that are already
           | doing this.
        
             | qingcharles wrote:
             | I can tell you, just as a lot of developers are using AI
             | and maybe not saying it, a _lot_ of lawyers are using AI
             | right now. The ones I know are all on the Pro $250 /mo
             | plans too, since they can afford it.
        
         | freejazz wrote:
         | No, because in the circumstance of an attorney doing it, it is
         | an attorney doing it.
        
       | midtake wrote:
       | What if you pay a lawyer whose entire function is to type your
       | questions into Claude?
        
       | ozb wrote:
       | The overruling of both Shih and the standards laid out in NYSBA
       | ethics opinions 820/842 (and various other state bar
       | associations, and the fact that apparently no one tried to
       | challenge those in court until AI) without real discussion of
       | implications seems rather unusual; and that's a rather charitable
       | reading to avoid the crazier "Claude is a person" framing
       | 
       | also, he quotes Gould v Mitsui: documents do not "acquire
       | protection merely because they were transferred" to counsel; but
       | that same case says they do acquire protection if communicated
       | "for the purpose of obtaining or rendering legal advice"
        
       | simonreiff wrote:
       | Attorney admitted in NY here. It's fascinating that Judge Rakoff
       | likely would have come to the opposite conclusion if the Claude
       | chat was at the attorney's request or suggestion. I am surprised
       | the court placed so much reliance on the Terms of Service, which
       | are probably not so different than those of Outlook, Gmail, etc.,
       | say, yet nobody disputes that attorney-client emails remain
       | privileged notwithstanding the Terms of Service of those
       | providers. At least I have never seen anyone argue in NY that
       | privilege is waived by emailing. And unlike sending an email to
       | another person, chatting with Claude is a solo conversation more
       | like organizing one's notes, which if in contemplation of
       | obtaining legal advice seems privileged to me. I think this is a
       | very close question and am not sure it would come out the same
       | way in other courts or on even slightly different facts. Very
       | interesting legal question.
        
         | joshribakoff wrote:
         | Not an attorney, but its a chat between a non attorney... and
         | well, themselves. It seems no different than a client writing
         | hand written notes. But if they hand wrote a note to... give to
         | their attorney, that seems different (which is how you seem to
         | frame it). I trust that the court articulated clearly, why the
         | defendants "certain notes" were not privileged, however its not
         | surprising that there is nuance. In fact, its no different than
         | how only "certain emails" could be privileged. This also seems
         | like a win for society, if there is some sort of pattern with
         | ai helping with crimes.
        
           | Gregaros wrote:
           | > This also seems like a win for society, if there is some
           | sort of pattern with ai helping with crimes.
           | 
           | That fails to recognize the tradeoff between freedom and
           | security. Society suffers if we, for instance, lock everyone
           | up, despite the reduction that would have in crimes. The
           | balance between the two cannot be ignored to justify
           | outcomes, though it is American tradition to value liberty
           | over security when the two come in conflict.
        
             | watwut wrote:
             | > it is American tradition to value liberty over security
             | when the two come in conflict.
             | 
             | It is american tradition to yell slogans about freedom
             | while not favoring it at all.
        
           | salawat wrote:
           | No. No it isn't a win. We need to grow beyond this stupid
           | anachronistic concept that "just because you speak to a Third
           | Party" there is no expectation of privacy. Humanity _works_
           | as a result of third-party communication, and I extremely
           | infrequently see Governments cracking open their operational
           | notes to the Public except at great cost, delay, and the
           | ultimate possibility of refusal. In point of fact, the
           | Government _taxes us_ to build out it 's capability to _not_
           | have to do so, but doesn 't do a damn thing to ensure anyone
           | else has the same capability.
           | 
           | Until "Good of the goose, good of the gander" is honored in
           | good faith, this is a strict, hypocritical loss.
        
             | tyzoid wrote:
             | It doesn't even need to be a third party. Documents you
             | make for yourself but never send to a third party could
             | still be seized in a criminal context or subject to
             | discovery in a civil one.
             | 
             | Attorney-client privilege is a special carve out because
             | the courts have recognized that clients need to be open and
             | honest with their attorneys to get proper counsel and
             | representation.
             | 
             | This ruling is the court declining to extend that special
             | carve out to non-lawyer AI tooling, and keeping the status
             | quo of contemporaneous documents made by someone
             | discoverable, whether or not shared with a third party. The
             | judge draws from the TOS as an admonishment, effectively
             | saying (my words, not the judge) _the TOS should have put
             | you on notice that you have no expectation this data is
             | confidential_.
        
         | rkagerer wrote:
         | _chatting with Claude is a solo conversation_
         | 
         | I only wish it were.
         | 
         | While your analogy may reflect the mental model held by most
         | users, I'd argue it sidesteps the reality that the company
         | providing the service can by definition listen in on every word
         | you exchange. Even if they were trustworthy enough to abide by
         | their promises (which life experience has taught me trends
         | inversely proportional to the size of the organization*), data
         | breaches have become routine across even the best resourced
         | institutions.
         | 
         | Email carries a similar exposure (unless you run your own in-
         | house server / both parties are encrypting). I once had a
         | lawyer who couldn't handle decrypting a zip file, and I
         | insisted on hand-delivery from the other party as an
         | alternative. It boggles my mind to see legal firms increasingly
         | rely on consumer-oriented cloud services while acting like they
         | are retaining custody of the data entrusted to them. Might as
         | well send your manilla folders to a third party warehouse where
         | they're handled by staff you didn't vet who aren't strongly
         | bound by attorney-client privilege.
         | 
         | Don't get me wrong, I like your analogy and found your
         | viewpoint insightful. I do feel as we fork over more of our
         | lives to a handful of digital cloud providers, society will
         | inevitably craft stronger protections to bring the legal regime
         | into alignment with most users' inherent expectations. I just
         | feel there is a huge gap today between how people expect the
         | systems they rely on are architected vs. how they really work.
         | 
         | I wonder how plausible it would be for a frontier provider to
         | offer something like enclaved AI instances where the user held
         | sole custody of the key (marketed somewhat like Kagi Privacy
         | Pass). While I doubt it could be bulletproof from a technical
         | perspective, it might act as a strong signal about their
         | privacy commitment. Do you think such a configuration might
         | have had an impact on this Justice's deliberations?
         | 
         | ---
         | 
         | *Life experience has taught me the bigger a corporation is the
         | more likely this is a stretch - not because employees are
         | willfully nefarious, but because the corporate culture doesn't
         | prioritize it anywhere near as much as they do pace of growth
         | and revenue, and because the consequences they face in practice
         | from harming your privacy are bascially non-existent - like a
         | year or two of credit monitoring could somehow mitigate the
         | consequences of all your PII being forever leaked (my general
         | advice to companies collecting PII is not to treat it as an
         | asset, but rather as toxic hazardous material that you
         | minimize, contain and shed at the earliest opportunity).
        
         | mnky9800n wrote:
         | Would a self hosted model also not be protected? Like because
         | it's classified as "ai" can those logs be read without a
         | warrant?
        
         | nashashmi wrote:
         | IANAL. Emailing with an attorney would encapsulate the emailer,
         | email service, any software, and the recipient under attorney
         | client privilege.
         | 
         | If the claude chat log / agent was shared with the attorney,
         | then even the use of the claude chat would be encapsulated
         | under attorney client privilege
        
         | turtlesdown11 wrote:
         | > which are probably not so different than those of Outlook,
         | Gmail, etc., say, yet nobody disputes that attorney-client
         | emails remain privileged notwithstanding the Terms of Service
         | of those providers.
         | 
         | Those are tools used to communicate with others, Claude is not
         | a tool to communicate with others, its akin to basic internet
         | searching.
        
         | bfa1fdbc46 wrote:
         | https://iapps.courts.state.ny.us/attorneyservices/wicket/pag...
         | 
         | "DELINQUENT Attorney has failed to file one or more biennial
         | registrations, and is subject for referral for disciplinary
         | action by the Appellate Division, as required by Part 118 of
         | the Rules of the Chief Administrator."
         | 
         | https://iappscontent.courts.state.ny.us/aronline/Attorney-Re...
        
           | digitaltrees wrote:
           | What is the point of this? Are you seeking to undermine the
           | credibility of the poster? Admitted attorney means they
           | passed the bar and were eligible to practice law at one
           | point, which is what they said, not currently practicing
           | attorney.
        
         | freejazz wrote:
         | >At least I have never seen anyone argue in NY that privilege
         | is waived by emailing.
         | 
         | It was a frequent issue when email first was a thing
        
         | JumpCrisscross wrote:
         | > _like organizing one 's notes, which if in contemplation of
         | obtaining legal advice seems privileged to me_
         | 
         | Is it? Aren't notes, _et cetera_ , not privileged by default?
        
       | koliber wrote:
       | Communicating with an attorney is protected by privilege. In this
       | case it seems they ruled that researching your case is not
       | protected by privilege.
       | 
       | What about drafting communications with an attorney? Is a draft
       | email that has not yet been sent protected? What about a Word doc
       | containing a draft of an email? What about a Google search for
       | "how do I spell amfeetamine?" that is part of your process of
       | drafting your communication with your lawyer?
        
       | general1465 wrote:
       | Letting this being decided by courts is like letting tobacco
       | companies decide if smoking is addictive or not. It is obvious
       | that they will always rule in their own interest.
        
       | Kim_Bruning wrote:
       | Questions this raises for me (making a note here to maybe
       | research a bit later):
       | 
       | Does this analysis change if using on-site AI? What if the ToS is
       | different? Is it possible to stand up a service that _does_ get
       | the protections required? This might also be interesting when
       | dealing with trans-atlantic work.
        
       ___________________________________________________________________
       (page generated 2026-04-16 23:02 UTC)