data sovereignty

The Heppner Ruling Drew a Bright Line Between Consumer and Enterprise AI

A federal court ruled consumer AI tools forfeit privilege protections. Here's what the Heppner decision means for law firm AI strategy in 2026.

RAGbase Legal Research TeamJuly 7, 2026 11 min read

On February 10 and 17, 2026, a federal judge issued a ruling that every managing partner, CIO, and general counsel in private practice should have read by now. In United States v. Heppner, the court held that documents generated using a publicly available AI tool were not protected by attorney-client privilege or the work product doctrine — because the choice of platform itself destroyed the reasonable expectation of confidentiality required to sustain either protection.

This is not a hypothetical risk from a law review article. It is a published federal ruling with a clean, actionable logic: the architecture of the AI tool you use is now a legal element of your privilege analysis. And in a single paragraph, the court drew a line that functions as a product specification — describing the features an AI platform must have to preserve the protections lawyers have relied on for over a century.

For law firms still treating AI vendor selection as a procurement decision rather than a risk management decision, Heppner is the wake-up call that arrives with a citation.

What the Court Actually Said — and What It Didn't

The Heppner ruling turned on the doctrine of reasonable expectation of confidentiality. Attorney-client privilege protects communications made in confidence between attorney and client. Work product protection shields materials prepared in anticipation of litigation. Both doctrines require that the party asserting them maintained a reasonable expectation that the materials would remain confidential.

The court found that using a publicly available, consumer-grade AI platform — one without contractual confidentiality protections, without defined data segregation, and with terms of service that permit the provider to use inputs for model training — destroyed that expectation. The documents weren't privileged not because they lacked legal substance, but because the channel used to create them was architecturally incompatible with confidentiality.

Critically, the court did not say AI tools categorically destroy privilege. It said this kind of AI tool does. The opinion expressly noted that enterprise AI platforms may give rise to a reasonable expectation of confidentiality that consumer tools do not — identifying three distinguishing features:

  1. Contractual commitments not to train on user data
  2. Defined data segregation between users or clients
  3. Explicit confidentiality terms in the service agreement

This is unusually specific guidance from a federal court. It reads less like dicta and more like a checklist — which is precisely how practitioners and their clients should treat it.

The Consumer-Enterprise Divide Is Now a Legal Divide

Before Heppner, the consumer-versus-enterprise AI distinction was primarily a sales and procurement concern: enterprise tools cost more, offer SLAs, provide admin controls. After Heppner, that distinction carries legal consequences that go directly to a firm's ability to protect its clients.

Here is how the major categories of AI tools in active law firm use map against the Heppner criteria as of mid-2026:

Platform CategoryNo-Training CommitmentData SegregationExplicit Confidentiality TermsHeppner Risk Profile
ChatGPT Free / Consumer tier✗ (default on)High
ChatGPT Enterprise✓ (contractual)PartialModerate
Harvey (SaaS)✓ (contractual)Lower
CoCounsel / Thomson Reuters✓ (contractual)Lower
Lexis+ AI Protege✓ (contractual)Lower
Legora✓ (contractual)Lower
Private / self-hosted deployment✓ (architectural)✓ (architectural)✓ (firm-defined)Lowest

The SaaS enterprise platforms — Harvey, CoCounsel, Legora, Lexis+ Protege — have invested in contractual frameworks that satisfy the Heppner criteria on paper. But there is a meaningful difference between contractual assurance and architectural assurance, and that difference will matter in the next wave of privilege disputes.

Contractual vs. Architectural Confidentiality: A Critical Distinction

A contract is a promise. Architecture is a constraint. When a SaaS vendor signs a data processing agreement committing not to train on your data, you are trusting their operational compliance with a written promise. When your AI infrastructure runs on your own servers or within your firm's private cloud environment, the data physically cannot leave without your explicit action.

This distinction will not be lost on sophisticated opposing counsel or federal judges who are increasingly technically literate about how these systems work.

Consider what actually happens when an attorney uses a cloud-based AI platform to draft a legal strategy memo or analyze deposition transcripts. The full document — including client name, matter details, strategic thinking — moves from the firm's systems to the vendor's infrastructure for processing. What comes back is an output. The vendor's contractual commitment not to train on that data is real and enforceable, but it is a downstream constraint on what they do with data that has already left your control.

A private AI deployment inverts this model. The agentic scaffolding, the document retrieval layer, the vector stores, the workflow orchestration, the permission architecture, and the full client document corpus all remain on infrastructure the firm controls. What may leave that perimeter is only the minimal retrieved context needed to answer a specific query — small chunks sent to a selected LLM provider under the firm's chosen API terms. The difference is between moving your entire filing cabinet to a vendor's warehouse versus occasionally mailing a relevant page to a consultant.

That architectural reality provides a substantively stronger basis for claiming a reasonable expectation of confidentiality than any contract can.

The Agentic Layer Is Where Privilege Risk Compounds

Most privilege analysis in the AI context has focused on the prompt: what did the attorney type, and did it reveal client confidences? That framing is already obsolete.

In 2026, the meaningful legal work is happening in agentic workflows — systems that autonomously retrieve documents, synthesize across matters, draft and revise, and iterate across multiple reasoning steps. An agentic system processing a due diligence workstream may touch hundreds of confidential documents across dozens of retrieval cycles before producing an output. Each retrieval cycle, each tool call, each intermediate reasoning step represents a potential data exposure vector if the underlying infrastructure is not under the firm's control.

For agentic AI deployments at law firms, the question is not just "where does the final prompt go?" It is: where does the agent run, where do the retrieved chunks go, where are the intermediate outputs logged, and who has access to the reasoning trace? If the answer to any of those questions is "a third-party SaaS vendor's cloud," the Heppner analysis applies with greater force than it does to a single-turn chatbot interaction.

What the Bar Is Now Likely to Require

Heppner was decided in a specific factual context, and no single district court ruling creates binding national precedent. But the opinion's reasoning is sound, its logic is portable, and malpractice insurers, bar ethics committees, and sophisticated clients are going to start asking questions that cite it.

Several predictable downstream developments are already taking shape:

Ethics opinions are coming. State bar ethics committees that have issued AI guidance to date — including those in California, New York, Florida, and Texas — have generally addressed competence and disclosure. Heppner gives them a concrete framework to address confidentiality specifically. Expect updated guidance that tracks the court's three-factor test.

Client due diligence requests are escalating. General counsel at Fortune 500 companies were already asking outside counsel firms to disclose AI tool usage in 2024-2025. Post-Heppner, those requests will include specific questions about whether the tools in use meet enterprise-grade confidentiality standards. Firms that cannot answer with specificity are at a competitive disadvantage in panel reviews.

Malpractice exposure is newly concrete. Before Heppner, a plaintiff arguing that an attorney's use of a consumer AI tool constituted a breach of the duty of confidentiality was making a novel argument. After Heppner, they are citing a federal court that already made it.

Litigation holds and discovery protocols will expand. If AI-generated work product can be challenged on privilege grounds based on the tool used, discovery requests will increasingly seek to identify which AI platforms were used in document preparation. Firms need to be able to answer that question with precision — which requires the kind of logging and audit trails that enterprise deployments, especially private ones, are better positioned to maintain.

The Audit Every Firm Should Conduct Now

The practical immediate response to Heppner is a structured audit. Based on the court's framework, here is the minimum inventory every firm should complete:

Step 1: Catalog all AI tools in active attorney use. This includes officially sanctioned platforms and the shadow IT reality of consumer tools attorneys are using on personal devices. A 2025 survey by the American Bar Foundation found that 41% of attorneys at firms with formal AI policies reported using at least one AI tool not covered by those policies. Heppner makes that statistic legally dangerous.

Step 2: Classify each tool against the three Heppner criteria. Does the vendor's agreement include a no-training commitment? Is there defined data segregation between your firm's data and other customers? Are confidentiality terms explicit and contractually enforceable? Document the answers.

Step 3: Map tool usage to matter sensitivity. Not every AI use case carries the same privilege risk. Using a consumer tool to generate a first draft of a generic form carries different risk than using it to analyze deposition strategy on an active securities litigation. Segment your risk accordingly.

Step 4: Establish written AI usage policies by matter category. The firms best positioned after Heppner will be those that can demonstrate — in response to a motion to compel or a malpractice claim — that they had explicit, documented policies governing which tools could be used on which types of matters.

For case search and document retrieval workflows, where the retrieval corpus includes the most sensitive client communications and litigation strategy documents, the architectural question is most acute. These are precisely the workflows where the difference between a private deployment and a SaaS platform is most legally consequential.

The Architecture the Court Implicitly Endorsed

It is worth being precise about what Heppner does and does not endorse. The court did not rule that on-premise AI is required, or that SaaS platforms are categorically problematic. It articulated a functional standard — contractual no-training commitments, data segregation, explicit confidentiality terms — and noted that enterprise platforms are more likely to satisfy it.

A private AI deployment that keeps the full agentic infrastructure, document corpus, retrieval layer, and workflow logic on firm-controlled infrastructure satisfies the Heppner standard architecturally rather than contractually. That is a stronger position — but it is not the only defensible position. Well-structured SaaS enterprise agreements can also satisfy the standard. The question is which type of assurance is sufficient for a given workstream and a given client.

For sovereignty-critical matters — government investigations, M&A transactions subject to regulatory scrutiny, litigation involving sensitive trade secrets, or matters where the client has explicitly required data residency commitments — the architectural answer is the more defensible one. For less sensitive, higher-volume workflows, a well-contracted SaaS platform may be entirely appropriate.

The firms that navigate this well will not be those that pick a single answer. They will be those that have the infrastructure flexibility to deploy the right architecture for each workload, with the governance framework to document the rationale.

This is not a niche concern for the most paranoid data security partners. It is now a core element of competent representation — and courts are beginning to say so explicitly.


Heppner will not be the last ruling in this area. As AI systems become more capable, more autonomous, and more deeply embedded in legal work product, courts will continue developing the doctrine. The firms that treat this ruling as a one-time compliance event rather than a signal about the direction of travel will find themselves responding reactively to each successive ruling. The more durable approach is to build an AI governance framework anchored to the architectural principles the court articulated — and to select infrastructure that makes those principles structurally enforceable rather than merely contractually promised. If you are evaluating your firm's AI stack against the Heppner criteria, the AI for law firms guide provides a structured framework for that assessment.

Frequently Asked Questions

Does using ChatGPT or consumer AI tools waive attorney-client privilege?
Under the Heppner ruling (February 2026), a federal court found that documents generated using a publicly available consumer AI tool were not protected by attorney-client privilege or the work product doctrine, because use of a consumer platform eliminated any reasonable expectation of confidentiality. The court explicitly distinguished enterprise AI platforms — which carry contractual data protections — as potentially preserving privilege.
What makes an AI platform 'enterprise-grade' for privilege purposes after Heppner?
The Heppner court identified three key factors: contractual commitments that prohibit training on user data, defined data segregation between clients, and explicit confidentiality terms in the service agreement. Private or self-hosted AI deployments that keep the agentic layer, document corpus, and retrieval infrastructure on the firm's own infrastructure provide the strongest architectural basis for meeting these criteria.
How should law firms update their AI governance policies in light of Heppner?
Firms should immediately audit which AI tools attorneys are using, classifying each by whether it meets the Heppner enterprise criteria: no-training commitments, data segregation, and explicit confidentiality terms. Any consumer or prosumer tool used to process client communications or case strategy documents should be flagged as a privilege risk. Firms should also establish written AI usage policies that specify approved platforms by matter type and sensitivity level.

Related Articles

R
RAGbase Legal Research Team
Research

RAGbase builds private AI systems for law firms: deployed on the firm's own infrastructure, zero data retention, full ownership.

See How RAGbase Works on Your Data

30-minute call. We scope your use case and show the system live.

We use audience and marketing cookies (Google Analytics, LinkedIn). No tracker loads without your consent. Learn more