Can Lawyers Use ChatGPT with Client Files? What US v. Heppner Changed

legalprivilegeUS v. Heppnerconfidentialityon-premise AI

Lawyers cannot defensibly put client files into consumer ChatGPT, and US v. Heppner is the reason the question is now settled. In February 2026, Judge Jed Rakoff of the Southern District of New York held that a defendant's conversations with a consumer AI assistant were not privileged — the AI provider is a third party, so the communications were discoverable like any other disclosure to an outsider. For lawyers, the implication is direct: privileged material typed into a third-party AI tool passes through — and may persist on — infrastructure the firm does not control, in front of a provider that can be compelled to produce it. ABA Model Rule 1.6, ABA Formal Opinion 512, and rule 3.3-1 of the Federation of Law Societies of Canada Model Code all point the same way. The defensible alternative is architectural: an open-weight model running on infrastructure the firm owns, where client files never leave the building.

What did US v. Heppner actually decide?

US v. Heppner (SDNY, February 2026) addressed whether a litigant's consumer-AI conversations could be shielded from discovery. Judge Rakoff's answer was no. Privilege protects confidential communications between lawyer and client; a consumer AI service is neither. Telling an AI assistant about your legal problem is, in privilege terms, telling a third-party company about your legal problem — the communication is not privileged, and the provider's records of it are discoverable.

For law firms, the decision matters in two directions:

  1. Your clients' AI chats are discoverable. Opposing counsel can now seek a party's consumer-AI conversation history in discovery, and Heppner is the authority that it is fair game.
  2. Your own AI use is a disclosure event. When a lawyer pastes privileged material into a consumer tool, the firm has transmitted client confidences to a third party that logs, retains, and — under many consumer terms of service — trains on them. That is a confidentiality problem under professional conduct rules whether or not a court ever calls it waiver.

What professional rules govern lawyers using AI with client files?

The duties are older than the technology, and they are strict:

  • United States: ABA Model Rule 1.6 requires lawyers to make "reasonable efforts" to prevent unauthorized disclosure of client information. ABA Formal Opinion 512 (2024) applied it squarely to generative AI: before inputting client information, a lawyer must evaluate the tool's terms, data retention, and whether inputs are used for training — and self-learning consumer tools generally require informed client consent.
  • Canada: Rule 3.3-1 of the FLSC Model Code imposes a near-absolute duty of confidentiality, broader than privilege itself. Law societies including Ontario, British Columbia, and Alberta have issued generative-AI guidance requiring lawyers to understand where data goes before using a tool on client matters.
  • Quebec: Law 25 adds statutory teeth — cross-border communication of personal information requires an assessment that the destination offers "adequate protection," with penal fines up to C$25 million or 4% of worldwide turnover.
  • Cross-border reality: the US CLOUD Act (18 USC 2713) lets US authorities compel US providers to disclose data in their possession, custody, or control — including data stored in Canadian data-centre regions. A Canadian firm's "Canada region" cloud AI still has a US company in the chain.

How do the deployment options actually compare?

Consumer ChatGPT Enterprise cloud API On-premise open-weight model
Who holds the prompt Provider, indefinitely per consumer terms Provider, per contract/retention policy The firm only
Trained on your inputs Yes, by default on consumer tiers Contractually excluded Never — no vendor in the loop
Privilege posture after Heppner Third-party disclosure; chats discoverable Third party still holds material No third party; no disclosure
CLOUD Act (18 USC 2713) exposure Yes Yes — provider can be compelled None — no US provider in the chain
Law 25 cross-border analysis Fails or requires consent machinery Requires assessment, contracts, monitoring Not triggered; data never leaves
Audit trail Provider's, not yours Provider's, partially shared Fully yours — SSO, logs, access control

Does an enterprise agreement solve the problem?

It helps, and it is not enough. Enterprise tiers typically exclude training on your data and offer shorter retention — genuine improvements. But three exposures survive every contract:

  • The provider still holds the material. Logs, abuse-monitoring copies, and transient storage exist on vendor systems, under vendor control, subject to vendor legal process.
  • Jurisdiction doesn't move. A US provider is CLOUD Act-reachable wherever the server sits. A contract cannot override 18 USC 2713.
  • The privilege argument weakens with every hop. Post-Heppner, a firm's cleanest position is that privileged material was never communicated to any third party at all. "It went to a vendor, but the contract was good" is a defense; "it never left our building" is a fact.

What does the defensible architecture look like?

As of September 2026, open-weight models make the sovereign option practical, not aspirational. GLM-5.3-Flash — Zhipu AI's 320-billion-parameter mixture-of-experts model with 18B active parameters, native document understanding and a 1-million-token context window, released under the fully permissive MIT license in August 2026 — runs from a single node inside a firm's own network, and its predecessor GLM-5.2 already ran on a single rack. A million-token context means entire document productions, deposition transcripts, and precedent sets fit in one pass, and overnight discovery triage runs at zero marginal cost on hardware the firm already owns.

The pattern we deploy for firms is consistent: an on-premise LLM deployment with SSO, role-based access mapped to matters, and full audit logging — fine-tuned on the firm's own precedent corpus so the model drafts in house style. The economics work at surprisingly modest scale: self-hosting typically breaks even around 2 million tokens per day of usage, a threshold a busy litigation group crosses quickly. See our law firm practice page for the full architecture.

The jurisdictional analysis matters as much as the privilege analysis — our guide to why the CLOUD Act reaches "hosted in Canada" data covers the statute in detail, and Quebec firms should read our Law 25 AI compliance guide.

The bottom line for firms

Heppner did not ban lawyers from using AI. It clarified what was always true: disclosure to a third party is disclosure, and AI providers are third parties. Firms that want frontier-class AI on privileged matters have exactly one architecture that removes the question rather than papering over it — open weights, on the firm's own hardware, with zero data egress. Everything else is a risk memo waiting to be written.

Questions we get

Frequently asked questions

Is it illegal for a lawyer to put client information into ChatGPT?

It is not categorically illegal, but it can breach professional conduct rules. ABA Model Rule 1.6 and rule 3.3-1 of the Federation of Law Societies of Canada Model Code require lawyers to protect confidential client information, and ABA Formal Opinion 512 (2024) requires lawyers to evaluate a generative-AI tool's data handling before inputting client information. Consumer tools that retain and train on inputs make that evaluation fail.

Did US v. Heppner say AI chats are discoverable?

Yes. In February 2026, Judge Rakoff in the Southern District of New York held that a litigant's conversations with a consumer AI assistant were not protected by attorney-client privilege because the AI provider is a third party outside the privileged relationship, and the chats were subject to discovery.

Does an enterprise ChatGPT or API agreement make client files safe?

It reduces training-data risk but not jurisdictional risk. A US provider remains subject to the CLOUD Act (18 USC 2713), which reaches data the provider holds regardless of where it is stored, and the provider's logs and retention practices remain outside the firm's control. Contractual scaffolding narrows the exposure; it does not eliminate the third party.

What is the defensible way for a law firm to use AI on privileged material?

Run an open-weight model — such as GLM-5.2 under the MIT license — on hardware the firm owns, inside the firm's network, with role-based access and audit logging. No third party ever holds the privileged material, so there is no provider to compel, no vendor retention policy, and no waiver argument built on disclosure to an outsider.

Take the 40 Claude skills and the briefing with you

The Vault 2026 skills pack (calendar audits, hiring scorecards, calibration, continuity plans) plus the sovereignty briefing: model releases, deployment economics and regulatory shifts for regulated firms. One click to unsubscribe.

Free. You get the Vault 2026 skills pack now and the sovereignty briefing roughly monthly. One-click unsubscribe.

Ready to move from reading to running?

We design, build, fine-tune, host, and maintain sovereign AI deployments end to end.

Book a sovereignty assessment How deployment works