top of page

Your AI Is Not Your Lawyer — And Your Conversion is Discoverable

  • Richard Liu
  • Jun 9
  • 7 min read
We speak business — so let's talk about the risk that's hiding in plain sight on your screen.

As generative AI and AI tools become a routine part of business operations, legal professionals and executives must understand a simple but critical point: an AI assistant is not an AI lawyer, and it does not create attorney-client privilege.


Imagine you're being sued. And imagine you're carrying a hard secret — something you know happened, something the other side hasn't discovered yet. One night you open up an AI platform, type the whole thing in, and ask it to help you think through where you stand.


Now the lawsuit heats up and discovery begins. Is the other side allowed to read what you typed? Are AI conversations confidential? Does privilege apply to AI?


The answer is not what you think. In early 2026, U.S. federal courts started answering — for the first time — exactly that question: when you talk to an AI about a legal problem, is it discoverable in lawsuits later?



The case that should make you put down the keyboard

In United States v. Heppner, a company chairman under federal investigation did almost exactly what we just described. Knowing he was a target, he used the consumer version of a popular AI platform to organize his thoughts, synthesize facts, and draft analyses for his defense — including information he'd learned from his own lawyers. When the FBI raided his home, they seized the devices. His defense team flagged 31 of those AI-generated documents as privileged. The government said: hand them over.


Federal Judge Jed Rakoff agreed with the government — on every point.

The attorney-client privilege didn't apply, the court reasoned, for a simple reason that lands like a slap: an AI is not a lawyer. Privilege exists to protect a trusting relationship with a licensed professional — not a conversation with software. (The tool itself, when asked, even said it couldn't give legal advice.) And there was no expectation of confidentiality, because the platform's own privacy policy disclosed that it collects user inputs and outputs, may use them to train its models, and may share them with third parties — including the government. In the court's framing, confiding case strategy to that tool was a lot like confiding it to a stranger who reserves the right to repeat it.


Then came the line that should rearrange how every executive thinks about this. The court held that material which isn't privileged when you create it doesn't "acquire protection merely because they were transferred" to your lawyer afterward. You can't, the judge wrote, "alchemically" turn an unprotected document into a privileged one just by emailing it to counsel. The protection has to exist at the moment of creation — and at midnight, alone with an AI, it didn't.

The work-product doctrine — the separate shield for materials prepared for litigation — failed too, because the chairman created the documents on his own, not at his attorney's direction.



The waiver trap

Here's the detail that turns a bad day into a catastrophe. Because the chairman fed in things his lawyers had told him, the court treated that as disclosure to a third party — which can waive the privilege over the original attorney-client communications themselves.


Read that again. The risk isn't just that your AI conversation becomes discoverable. It's that pasting your lawyer's advice into a public AI can strip the protection off the advice your lawyer already gave you. You don't just fail to create a new shield — you can dissolve one you already had.


So back to your secret. You typed it in to think it through. Now it sits in a tool whose terms let the provider keep it, learn from it, and hand it over. The thing the other side didn't know? You may have just created a written record of it — and handed away the very protection that would have kept it out of their hands.



The case that points to the way out

Now the plot twist. The same week, another federal court in Michigan went the other direction. In Warner v. Gilbarco, a plaintiff representing herself admitted she'd used an AI tool to help draft her court filings. The defense demanded every prompt and every output. Magistrate Judge Anthony Patti said no — those materials were protected work product.


Why the opposite result? Two reasons worth internalizing:

  • An AI is "a tool, not a person." Using one to draft is more like using a very advanced word processor than confiding in a third party.

  • Work-product protection is only waived by disclosure to an adversary — or in a way likely to reach one. Typing into an AI isn't handing your file to the other side.


The difference between losing everything and keeping protection wasn't the technology. It was who was driving, why, and what doctrine applied.


The legal issues are not limited to one AI product or one platform. They apply across a wide range of AI technologies, including language models, AI-driven research tools, and consumer-facing AI assistant platforms.



So what's the actual rule? (Not what you've heard)

This area of law is developing as we speak. Below are a few points we can discern from the cases so far (not legal advice):

  1. Is a real, licensed lawyer directing the work? AI used at counsel's direction has a fighting chance at protection. AI used solo, on your own initiative, usually doesn't.

  2. What tool — and what terms? A consumer-facing AI product may create very different risks than a closed enterprise tool used by a law firm or legal team under strict contractual terms.

  3. Privilege or work product? They're different shields with different breaking points. Work product survived in Warner; privilege shattered in Heppner.

  4. Was there a genuine expectation of confidentiality? The terms of service you clicked through can decide this for you — before any dispute even exists.


And one sober footnote: no court has yet ruled that even a top-tier enterprise AI tool preserves privilege. Heppner left the door open; nobody has walked through it. Until they do, treat the question as live.



The ILS playbook: turning the doctrine into operating rules

We speak business, so here's the doctrine translated into things you can actually run a company on. Think of it as data hygiene for your most sensitive thinking.


1. Adopt one default rule: nothing legally sensitive goes into a public AI. 

Assume anything you type into a consumer AI tool could end up in front of a regulator or an opposing party. If you wouldn't post it to a vendor's servers with a "feel free to reuse this" note attached — don't paste it.


2. Route legal-matter AI through counsel. 

When AI will touch a legal question, the safest posture is to use it at the written direction of your lawyers, the way you'd use any other litigation consultant. That's the difference Heppner and Warner both turned on.


3. Use enterprise, "closed" deployments — and check the contract, not the marketing. 

For anything touching legal or regulatory matters, insist on terms that include: no training on your inputs, no third-party disclosure, zero or limited data retention, and deletion or claw-back rights. The default consumer settings are usually the opposite of what you want; opt out of training at minimum, but get it in the contract.


4. Wall off your workstreams. 

Drafting a marketing email with AI is fine. Pressure-testing your litigation strategy is not the same activity. Keep legal-sensitive use in a separate, counsel-supervised channel — don't let the two blur in the same casual tool. This distinction matters across multiple practice areas, including litigation, employment, immigration, investigations, corporate transactions, and regulatory compliance.


5. Write an AI governance policy before you need one. 

Who can use which tools, for what kinds of data, and when legal has to be in the loop. Most companies have raced ahead on adoption while skipping governance — and courts are starting to treat that gap as the company's problem, not an excuse.


6. Remember that AI conversations are documents. 

Saved chats, exports, and logs are discoverable — and seizable. They live inside your litigation-hold obligations like any other file. Plan for that before a dispute, not during one.


7. Mind the new protective orders. 

Some courts are now issuing orders that flatly bar uploading confidential case materials into any AI tool that can train on or share them. That's no longer a best practice — in those courtrooms, it's a rule.



The bottom line

AI is one of the most powerful tools your business has ever had. None of this is a reason to unplug it. But the convenience of thinking out loud with an AI can quietly cost you the single thing that lets you speak freely with your own lawyer — and you won't feel the loss until someone else is reading the transcript.


The fix isn't fear. It's structure: the right tools, the right terms, and your lawyers in the loop before the prompt, not after. That's a problem we solve for a living.

If you'd like us to pressure-test how your team is using AI on sensitive matters — or to stand up an AI-use policy that holds up in discovery — let's talk. We speak business. We also speak privilege.


Disclaimer: The materials provided on this website are for general informational purposes only and do not, and are not intended to, constitute legal advice. You should not act or refrain from acting based on any information provided here. Please consult with your own legal counsel regarding your specific situation and legal questions.

As Managing Partner at ILS, Richard Liu ranks among the leading U.S. attorneys in corporate, employment, and regulatory law. He is known for crafting legal strategies aligned with clients’ business objectives and advising Fortune 500 companies, startups, and executives on corporate transactions, financing, privacy, and employment matters across the technology, healthcare, and financial sectors.


Before founding ILS, Richard practiced at top defense firms, where he developed a reputation for anticipating risks and designing strategies that balance protection with growth. He has secured favorable outcomes in contract and intellectual property disputes, represented clients in state and federal courts, and is recognized for combining large-firm expertise with boutique-firm agility. Richard is also a frequent speaker at industry and legal conferences.


Email: contact@consultils.com | Phone: 626-344-8949

Comments


bottom of page