A federal judge just answered the question no one in legal technology wanted to face. The answer changes how every law firm needs to think about AI deployment.

The question was never whether AI would enter legal practice. It was whether the legal profession would govern its entry before a court did it for them.

On February 17, 2026, a court did it for them.

In United States v. Heppner, No. 25 Cr. 503 (S.D.N.Y.), Judge Jed S. Rakoff of the Southern District of New York held that 31 documents a criminal defendant generated using the consumer version of Anthropic's Claude were protected by neither attorney-client privilege nor the work product doctrine. The documents, containing defense strategy built from confidential attorney communications, became fully discoverable by federal prosecutors.

The defendant did not get hacked. There was no data breach. He typed his legal strategy into a consumer AI tool. That was sufficient to destroy the privilege.

For law firm leaders responsible for high-throughput practices, this ruling is not a cautionary tale about someone else's client. It is a structural warning about every AI-assisted workflow currently operating inside your firm.

The Facts Of The Case

Bradley Heppner was a Texas-based finance executive and the founder and former CEO of Beneficient, a financial services company. A federal grand jury in the Southern District of New York indicted him in October 2025 on charges of securities fraud, wire fraud, conspiracy, making false statements to auditors, and falsification of corporate records. The government alleged a $150 million scheme involving GWG Holdings and its retail L-bond investors, many of them retirees.

After receiving a grand jury subpoena and retaining defense counsel, Heppner used the consumer version of Anthropic's Claude to analyze his legal exposure, outline potential defense strategies, and formulate arguments about the anticipated charges. He fed the tool information received directly from his attorneys during confidential consultations. He generated 31 documents recording those interactions, intending to share them with his legal team.

FBI agents executed a search warrant at his residence following his November 2025 arrest, seized his electronic devices, and recovered the full cache of AI-generated documents. The government moved to compel production and introduce them as evidence.

Defense counsel asserted attorney-client privilege and work product protection, arguing the materials were functionally equivalent to notes a client drafts before an attorney meeting.

Judge Rakoff denied both claims from the bench on February 10, 2026, and published a 12-page written memorandum one week later.

Why The Privilege Failed: Three Findings That Apply Universally

Rakoff characterized the ruling as "a question of first impression nationwide." His analysis rested on three independent grounds, each sufficient on its own to defeat the privilege claim.

Finding One: The AI Platform Is Not An Attorney

Attorney-client privilege requires the communication be between a client and a licensed attorney. The court stated without ambiguity that "Claude is plainly not an attorney." An AI platform is a mathematical model executing probabilistic text generation on corporate servers. It owes no duty of loyalty and cannot be sanctioned by a state bar.

When Heppner typed his strategy into Claude, he was communicating with a third party, not with his lawyer. Third-party disclosures destroy privilege. The first element failed.

Finding Two: No Reasonable Expectation Of Confidentiality

The court examined Anthropic's terms of service, which state that user inputs and outputs may be retained, used to train the model, and disclosed to third parties, including regulatory authorities. By logging in, Heppner accepted those terms. The court held he possessed no reasonable expectation of confidentiality.

Rakoff's framing: disclosing privileged information to a commercial platform with those data practices is functionally equivalent to handing a written document to a stranger and assuming they will keep it private.

Finding Three: The Platform Disclaimed Legal Advice

The privilege requires the communication be made for the predominant purpose of obtaining legal advice. Claude's own terms and design explicitly disclaim the ability to provide legal advice. The government tested this during proceedings and received a response stating Claude is not a lawyer and cannot provide formal legal recommendations. That element failed before the first document was reviewed.

On Work Product: The Volition Problem

The work product doctrine requires materials prepared by or at the direction of counsel in anticipation of litigation. Defense counsel conceded Heppner generated the documents "on his own volition" without attorney instruction.

The court also established that transmitting non-privileged documents to your attorney after the fact does not create privilege retroactively. As Rakoff wrote, non-privileged communications are not "alchemically changed into privileged ones upon being shared with counsel."

The Subscription Tier Does Not Change The Analysis

This is the most common misconception in current legal AI discourse. A paid individual subscription, whether Pro, Max, or any personal tier, does not alter the underlying data exposure. Both major platforms use conversations from free and individual paid accounts for model training by default.

As one legal analysis of Heppner put it: "A $20-per-month subscription does not buy you privilege." Only enterprise-tier agreements, with contractual zero-retention commitments and no-training guarantees, change the operative legal posture.

The Ruling That Went The Other Way

The same day Rakoff issued his bench ruling, a federal court in Michigan reached the opposite conclusion. In Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 10, 2026), Magistrate Judge Anthony P. Patti denied a motion to compel a pro se plaintiff's ChatGPT prompts, holding that ChatGPT is a "tool, not a person," and that disclosing information to a tool does not waive work product protection under Sixth Circuit precedent.

Two courts. One week. Same technology. Opposite outcomes. No circuit court has resolved the split.

The Door Rakoff Left Open

Judge Rakoff did not prohibit AI in legal practice. His written opinion contains explicit dictum: had defense counsel directed Heppner to use the AI tool, the platform "might arguably" have functioned like a professional acting as a lawyer's agent, protected under the established Kovel doctrine.

Two structural requirements emerge from the opinion. Attorney direction: the AI system must be deployed at the documented, specific direction of licensed counsel. Confidentiality architecture: the platform must operate under an enterprise agreement that expressly prohibits data retention and training on client inputs, and restricts disclosure to government authorities without formal legal process.

The Hallucination Crisis Has Reached The Appellate Level

The privilege exposure is the structural risk. The hallucination risk is already generating sanctions at scale. As of early 2026, the most comprehensive tracker of AI-generated fabricated content in legal proceedings documents over 1,178 verified incidents globally, with the United States accounting for 788. In 2025 alone, U.S. courts recorded 487 instances of errors or hallucinations in court filings, a tenfold increase over the prior year.

The Sixth Circuit sanctioned two attorneys $15,000 each in one case for submitting briefs containing over two dozen fabricated citations. In another, an attorney faced a total penalty of $109,700 for submitting fabricated case law and false judicial quotes. Courts have now extended the verification duty beyond a firm's own filings, sanctioning attorneys for failing to detect opposing counsel's fabricated citations.

What The Ethics Opinions Require Right Now

As of early 2026, seventeen jurisdictions have issued formal ethics opinions specifically addressing attorney use of generative AI. None prohibit it. All require the same substantive obligations under the core Model Rules: competence, confidentiality, communication, supervision, and fees.

Several jurisdictions have drawn explicit lines. North Carolina's ethics opinion states lawyers should avoid inputting client-specific information into publicly available AI resources. Florida's opinion requires informed consent when AI use involves disclosure of confidential information to a third-party vendor. The through-line across every opinion is consistent with Heppner's framework: consumer AI tools with permissive data practices are not a reasonable confidentiality measure. Enterprise tools with contractual protections are.

The Adoption Reality And The Governance Gap

Enterprise legal AI has crossed the threshold from early adoption to competitive infrastructure. Industry reporting puts CoCounsel Legal adoption at 85% of AmLaw 100 firms, with Harvey AI reporting it partners with the majority of the AmLaw 100. Legal tech spending grew 9.7% in 2025, the most rapid real growth in those expense categories ever recorded.

A Forrester study modeled enterprise AI deployment at a large law firm and found 344% ROI over three years, with payback in under six months.

The productivity case is documented. The governance gap is equally documented. One 2025 legal trends report found that 53% of firms have no AI policy or are unaware of whether one exists. Firms moving fast on AI without enterprise infrastructure and governance frameworks are accumulating a liability they cannot see until it surfaces in discovery, a sanctions order, or a bar complaint.

The Governance Framework: What Needs To Happen Now

This is not a technology project to schedule for next quarter. The case law is decided. The bar opinions are published. The sanctions are monthly.

  • Audit actual AI usage, not approved AI usage. Identify every tool being used on client matters, including consumer accounts and personal subscriptions.
  • Establish a hard boundary on client-confidential data. Any prompt containing client names, case facts, legal strategy, or personal identifiers belongs only in enterprise infrastructure with a signed data processing agreement.
  • Evaluate enterprise platforms against your workflow requirements, not marketing claims.
  • Document attorney direction for all AI use on client matters, with the deployment documented and the output reviewed.
  • Build citation verification into every filing workflow. Not spot-checking. Verification, every time.

Conclusion

The legal profession has adopted AI faster than it has governed AI. That gap is now closing, and not on the profession's terms.

United States v. Heppner established that consumer AI tools are third-party commercial platforms whose data practices destroy attorney-client privilege. It also established that attorney-directed, enterprise-grade AI operating under contractual confidentiality protections is a materially different situation courts may treat differently. The Kovel door is open. The path through it requires structure, documentation, and the right infrastructure.

The clients who retain your firm trust that the facts they share will be used to help them, not handed to the other side. Every AI deployment decision your firm makes is a decision about whether that trust is warranted. Make it deliberately.