Judge Jed Rakoff has spent three decades making lawyers uncomfortable. In February 2026, he did it again. In United States v. Heppner out of the Southern District of New York, Rakoff ruled that documents prepared using a public AI tool — specifically, a workflow routed through Anthropic's Claude on standard commercial terms — were not protected by attorney-client privilege or the work product doctrine. The reason was surgical and, in hindsight, obvious: the platform's privacy policy explicitly permitted data retention and potential disclosure to third parties. That language, Rakoff concluded, eliminated any reasonable expectation of confidentiality. Privilege evaporated at the moment of upload.
The decision landed like a fire alarm in AmLaw managing partner meetings. But the more consequential development may be what followed: a Q1 2026 Akin Gump analysis documented an emerging circuit split across federal courts, with SDNY now holding that public AI can destroy work product protection in criminal matters, while courts in the Eastern District of Michigan and the District of Colorado reached different conclusions in civil cases. Simultaneously, the D. Colorado court issued an order doing something almost without precedent — affirmatively mandating that parties use only 'closed' AI tools in eDiscovery, explicitly banning public platforms and citing both U.S. privacy law and GDPR exposure.
We are past the point where AI data governance is a preference. Federal judges are writing it into orders.
The Heppner Logic: Why Public Privacy Policies Are Now a Liability
To understand the stakes, it helps to follow Rakoff's reasoning precisely — because it applies far beyond one criminal case in Manhattan.
The traditional attorney-client privilege analysis requires, among other things, that the communication be made in confidence and that the confidentiality be reasonably maintained. Work product doctrine similarly requires that materials be prepared in anticipation of litigation and not disclosed to adversaries or their agents. The moment you voluntarily route a document through a system whose governing terms permit the service provider to read, retain, analyze, or share that content, you have introduced a third party into what was supposed to be a protected relationship.
This is not new doctrine. It is the same logic courts have applied to unsecured email, shared Dropbox folders, and inadvertent disclosures for decades. What Rakoff did was apply that existing framework to AI workflows — and the result was a finding that the act of using the wrong AI tool was itself the privileged waiver.
The implications for law firm operations are immediate:
- Any attorney who drafted strategy memos, litigation analyses, or client advisories using a public AI tool may have created discoverable documents
- Any work product that touched a public LLM's servers — even if the output looked like an internal memo — may be subject to production
- The risk is not prospective only; historical use of public AI tools in active matters is now a disclosure and privilege review problem
Akin Gump's analysis flags that the Heppner ruling is specifically tied to criminal proceedings, where privilege protections are scrutinized more aggressively. The civil cases in E.D. Michigan and D. Colorado did not find waiver. But that divergence is precisely the problem: no firm can currently advise its clients with confidence about which standard applies to a given matter until that matter reaches a specific court.
The Circuit Split in Plain Terms
Here is where the Q1 2026 landscape actually stands, stripped of hedging:
| Court | Case Type | Public AI Used | Privilege/Work Product Outcome |
|---|---|---|---|
| S.D.N.Y. (Heppner, Feb. 2026) | Criminal | Yes (Claude, public tier) | Waived — no reasonable expectation of confidentiality |
| E.D. Michigan (Q1 2026) | Civil | Yes | Preserved — no waiver found on facts presented |
| D. Colorado (Q1 2026) | Civil/eDiscovery | N/A — prospective order | Public AI banned — closed tools mandated by court order |
The split matters because it creates a jurisdiction-by-jurisdiction compliance map that is effectively unworkable at scale. A firm handling a multi-district litigation with touchpoints in SDNY, Colorado, and Michigan is operating under three different standards simultaneously. Associate training programs cannot reasonably instruct attorneys to check the circuit before choosing which AI tool to draft with.
The only architectural response that resolves the split across all three jurisdictions is one that eliminates the vulnerability Heppner identified: third-party data access through vendor privacy policies.
What the Colorado Order Actually Says — and Why It Matters More Than Heppner
The Heppner ruling is the headline, but the District of Colorado order may be the more durable precedent. Rakoff's decision is, at its core, a finding of fact about a specific platform's privacy policy and a specific workflow. A different AI vendor with tighter contractual terms might survive the same analysis.
The Colorado court went further. It did not analyze a specific tool's terms of service. It issued a standing order: public and open AI platforms are prohibited from eDiscovery workflows in matters before that court, full stop. Closed AI tools are required.
That is a compliance mandate, not a judicial opinion subject to factual distinction. And it cited not just domestic privilege doctrine but GDPR and U.S. data privacy laws — meaning the court is already thinking about cross-border data flows, processor agreements, and the legal geography of where client data lands when it hits a commercial LLM's inference servers.
For AmLaw 200 firms with European client relationships, matters touching EU data subjects, or clients in regulated industries like financial services and healthcare, this framing should trigger an immediate review. The question is no longer whether your AI vendor has a good privacy policy. The question is whether your firm can demonstrate, to a court's satisfaction, that client data never left infrastructure under your control — or that any data that did leave was minimized, governed, and transmitted under terms you negotiated.
The Architectural Answer: What 'Closed' AI Actually Means
The legal industry has spent two years debating AI tools primarily on the basis of output quality — accuracy, hallucination rates, citation reliability. The Heppner-Colorado development reframes the evaluation entirely. Architecture is now a legal compliance variable.
It is worth being precise about what distinguishes a defensible AI architecture from a vulnerable one, because the market has become noisy with vendors claiming "private" or "secure" deployment without specifying what that actually means.
The core architectural question is: what leaves the firm's infrastructure, and under whose terms?
For most commercial AI tools — including enterprise tiers of consumer platforms — the answer involves the firm's documents, queries, retrieved content, and interaction history flowing through vendor infrastructure governed by vendor terms. Even products marketed to law firms under BAAs or enterprise agreements may route substantial data through shared model infrastructure.
A genuinely sovereign architecture looks different:
What stays on firm infrastructure:
- The full client document corpus and matter files
- The retrieval and indexing layer (vector stores, embeddings, document chunking)
- The agentic scaffolding — the workflows, connectors, permissions models, and audit logs
- The full context of who accessed what, when, and in connection with which matter
- All intermediate reasoning steps and retrieved document sets
What may leave firm infrastructure:
- Only the minimal retrieved text chunks necessary to answer a specific query, sent to a chosen LLM provider API under the firm's directly negotiated terms
That distinction — full corpus plus agent layer under client control, versus minimized chunks to the model — is what separates an architecture that can survive a Heppner challenge from one that cannot. When a court asks whether you maintained a reasonable expectation of confidentiality, the answer depends not on your vendor's marketing copy but on what your data flow diagrams actually show.
This is the design principle behind private AI deployment for legal workforces: the intelligence layer — the retrieval, the permissions, the matter-level access controls, the logs that would satisfy a court-ordered audit — lives on your infrastructure. The LLM is used as a commodity inference engine, and even that usage is scoped to the minimal data needed, under API terms the firm controls.
To be clear: this architecture does not require running a local LLM. Firms using frontier models via API — GPT-4o, Claude 3.7 Sonnet, Gemini 1.5 Pro — can still operate in a sovereignty-preserving posture if the retrieval and agentic layers are on-premise and only minimized chunks reach the API endpoint. The question is not whether you use a commercial LLM. The question is how much of your client universe reaches that LLM, and under what governance.
The Tools in the Market and Where They Stand
This is where the market gets complicated, and where the Heppner analysis forces some honest evaluation of tools that managing partners may have already deployed.
Harvey, CoCounsel, Lexis+ Protege, and Legora are all purpose-built for legal workflows, and all represent a substantial step up from routing client documents through consumer ChatGPT. Most operate under enterprise agreements with data processing terms, and several offer configurations with meaningful data isolation. But the core architectural question — where does the retrieval layer live, who controls the vector store, what does the audit trail look like to a court — varies by product and deployment configuration, and in most cases the answer involves material vendor-side data processing.
That is not a disqualifying fact for every matter. For general legal research, public-record analysis, or drafting assistance on non-privileged work, the risk profile of SaaS legal AI tools is manageable. Firms should be using these tools for appropriate workloads. The AI for law firms guide covers the workflow segmentation logic in detail.
The problem is that most firms have not done the segmentation work. The same tool used to summarize public SEC filings is being used to draft strategy memos in active SDNY litigation. That is the workflow pattern Heppner makes dangerous.
The Compliance Imperative: What Firms Need to Do in the Next 90 Days
The circuit split will likely resolve at the appellate level over the next 12 to 24 months — either through circuit court opinions or, eventually, a Supreme Court cert grant. But the resolution could go either way, and the D. Colorado standing order demonstrates that individual courts are not waiting for appellate guidance. They are issuing mandates now.
Firms that wait for doctrinal clarity are making a bet. Here is the triage framework we would apply:
Immediate (0-30 days):
- Audit all active matters in SDNY and D. Colorado for AI tool usage in privileged work product; flag for privilege review
- Map which AI tools are being used for which workflow types across practice groups
- Review vendor agreements for any tool used with client-confidential material; identify what data flows to vendor infrastructure and under what terms
Near-term (30-90 days):
- Segment AI usage by risk tier: public-record/research tasks (SaaS tools acceptable), privileged work product (requires sovereign architecture), eDiscovery in D. Colorado (closed tools required by order)
- For sovereignty-critical workloads, evaluate private AI deployment architectures where the retrieval layer, permissions, and audit logs remain on firm infrastructure
- Brief the PSC and litigation management committee on the Heppner ruling and circuit split; this is a professional responsibility issue, not just an IT governance question
Strategic (90+ days):
- Update AI use policies to specify permissible tool tiers by matter type and jurisdiction
- Establish a repeatable architecture review for new AI tool onboarding that evaluates data flow diagrams, not just vendor privacy policies
- Build the audit trail capability that courts will eventually require: logs showing what AI tools were used, on what documents, in connection with which matters
The case search infrastructure question is directly implicated here — firms using AI-enhanced research workflows need to be able to demonstrate that client matter context used to guide retrieval stayed within firm-controlled infrastructure.
The Longer View: Judges Are Learning the Technology
There is a broader signal in the Heppner decision and the Colorado order that deserves attention beyond the immediate privilege analysis. Judge Rakoff understood, with sufficient technical precision, that routing a document through a commercial AI platform with a data-retention privacy policy was legally equivalent to sharing it with a third party. The District of Colorado understood enough about AI infrastructure to distinguish between open and closed deployment architectures and write that distinction into a court order.
This is a step change. Two years ago, most judicial AI-related rulings concerned hallucinated citations — courts sanctioning attorneys for submitting fake cases. That was a quality and candor problem. What we are seeing now is courts reasoning about AI data architecture as a substantive legal matter. The sophistication will increase.
By the time circuit courts are ruling on Heppner's progeny — likely 2027 at the earliest — the judiciary will be evaluating AI deployment architectures with considerably more precision. Firms that have built defensible, documented, sovereign architectures for privileged work will be able to satisfy that scrutiny. Firms that have been routing client matter context through commercial SaaS platforms on vendor-controlled terms will face a much harder set of questions.
The firms most exposed are not the ones that avoided AI — they are the ones that deployed it enthusiastically without resolving the architectural question of where client data actually goes.
The combination of the Heppner ruling, the Colorado standing order, and the Q1 2026 circuit split has done something rare in legal technology: it has made an architectural decision into a compliance obligation. If your firm is assessing which AI deployments require a sovereignty-first architecture — where the retrieval layer, agent scaffolding, and client document corpus stay on firm infrastructure — that evaluation should account for not just today's circuit split but the trajectory courts are on. The judges are getting technically literate faster than most firms are getting architecturally disciplined.
Frequently Asked Questions
Does using ChatGPT or Claude destroy attorney-client privilege?
What is the difference between public AI tools and private/on-premise AI for law firms?
Are courts ordering law firms to use closed AI tools?
Related Articles
Heppner v. United States: Why Your Firm's AI Infrastructure Now Determines Privilege
The SDNY ruling that changes how every law firm should think about AI — Judge Rakoff held that documents generated using consumer AI chatbots are not protected by attorney-client privilege.
Your AI Vendor's Moat Is Your Data. Here's How to Take It Back.
How SaaS AI vendors build competitive moats from your firm's usage data — the shared learning paradox, the dilution problem, and why proprietary AI keeps the compounding advantage with you.
AI for Law Firms in 2026: The Complete Guide to Choosing, Deploying, and Owning Legal AI
Comprehensive guide to AI adoption for law firms in 2026 — agentic AI, proprietary vs SaaS, privilege implications, pricing, and the ownership model.
The Hidden Cost of Legal AI: Why 300-Lawyer Firms Are Spending $4.3M on Tools That Can't Find Their Own Case Files
Legal AI subscriptions cost up to $4.3M/year for large firms, yet can't search internal case files. Compare SaaS costs vs proprietary AI ownership economics.
RAGbase builds private AI systems for law firms: deployed on the firm's own infrastructure, zero data retention, full ownership.
See How RAGbase Works on Your Data
30-minute call. We scope your use case and show the system live.