A United States federal court decision handed down earlier this year could be a warning sign for Australian commercial practitioners and their clients. The case is a practical illustration of something that can easily be overlooked in the rush to adopt AI tools: uploading legal advice or confidential documents into a public AI platform. The stance in the US indicates that this may permanently destroy legal professional privilege.
What Happened in Heppner
The defendant in United States v Heppner, No. 23-CR-251 (S.D.N.Y., 17 February 2026) was the former CEO of a Dallas-based financial services company facing criminal fraud charges. When he learned he was under investigation, he turned to a public generative AI platform to work through his legal position and prepare documents. The defendant did this of his own accord, without being directed to do so by his lawyers. He later handed those documents to his defence counsel.
The government sought access to the documents at trial. Judge Jed S. Rakoff refused to shield them as the AI platform was not a lawyer. Its privacy policy made clear that it retained user inputs and outputs, used them to train its models, and could disclose them to third parties including government regulators. The court’s view was that there was no reasonable expectation of confidentiality or legal privilege.
Judge Rakoff put it plainly: it is “black-letter law that non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel.” The fact that the tool happened to be AI, rather than any other non-confidential medium, was inconsequential.
It is worth noting that the court left open the possibility that the outcome might have differed had the defendant’s lawyer specifically directed him to use the AI tool as part of the legal representation. The distinction of instructed as opposed to self-directed use may be material in future cases.
Why This Matters for Commercial Transactions
Most commercial clients understand that legal advice should be kept confidential in principle. What they may not appreciate is that uploading that advice or related documents into a public AI tool can constitute a waiver of privilege, regardless of their intentions.
The scenarios are not far-fetched. A CFO pastes a due diligence summary into ChatGPT to get a quick overview. A commercial manager uploads a draft share sale agreement to check a clause. An in-house lawyer feeds a privileged memorandum into an AI tool to generate a board summary. In each case, the information has been shared with a third party whose terms of service almost certainly permit retention, model training, and third-party disclosure.
If the transaction later falls into dispute or regulatory scrutiny, the counterparty or regulator can argue that privilege has been waived and those documents are discoverable. Once privilege is lost, there is no mechanism to restore it.
The Australian Regulatory Position
Australian legal regulators have addressed this directly. The Victorian Legal Services Board and Commissioner, together with the Law Societies of New South Wales and Western Australia, state in their joint guidance on Maintaining client confidentiality (ASCR r 9.1; BR r 114).
“Lawyers cannot safely enter confidential, sensitive or privileged client information into public AI chatbots/co-pilots (like ChatGPT), or any other public tools. If lawyers use commercial AI tools with any client information, they need to carefully review contractual terms to ensure the information will be kept secure.”
The Federal Court of Australia’s Practice Note on Generative AI (GPN-AI) similarly cautions against inputting confidential or privileged information into public AI tools.
What To Do
While the use of AI shortcuts for commercial expediency is attractive for many reasons, the practical steps to avoid loss of privilege are not complicated:
- Do not upload privileged advice, due diligence materials, or confidential transaction documents into any public AI platform, especially tools whose terms allow data retention, model training, or third-party disclosure.
- Where AI tools are used in connection with a matter, use only internal platforms that contractually prohibit use of client data for training and maintain appropriate data segregation. ²
- Any use of AI in connection with a legal matter should be directed by the lawyer handling it, not initiated independently by the client or their staff.
- Brief commercial teams: CFOs, in-house counsel, transaction managers, before a deal commences, not after something has gone wrong.
Judge Rakoff closed his judgment with a line worth remembering: “AI’s novelty does not mean that its use is not subject to longstanding legal principles.” The rules around privilege and confidentiality were not written with AI in mind, but they apply to it fully.
References
DLA Piper, ‘Are AI-Generated Documents Protected from Discovery if You Send Them to Your Lawyer? Key Takeaways from the Heppner Decision’, 18 February 2026, reporting on United States v Heppner, No. 23-CR-251 (S.D.N.Y., 17 February 2026, Rakoff J).
DLA Piper, ‘Are AI-Generated Documents Protected from Discovery if You Send Them to Your Lawyer? Key Takeaways from the Heppner Decision’, 18 February 2026, reporting on United States v Heppner, No. 23-CR-251 (S.D.N.Y., 17 February 2026, Rakoff J).
Federal Court of Australia, Practice Note: Use of Generative Artificial Intelligence (GPN-AI).











