The memo your firm's ethics partner has been dreading arrived in February 2026, when Judge Heppner's ruling landed with the quiet force of a governing precedent nobody had quite prepared for. By July 2026, it was being cited in four federal jurisdictions. The holding was precise and unsparing: a lawyer who inputs confidential client communications into an AI tool whose Terms of Service permit data retention and third-party disclosure has made a voluntary disclosure to a third party — and privilege is gone.
This is not a hypothetical risk buried in a bar association ethics opinion. It is now case law, and the circuit courts are actively building on it.
What Heppner Actually Held — and Why It's Broader Than You Think
The Heppner ruling's logic tracks directly from established privilege doctrine. Attorney-client privilege protects confidential communications between attorney and client. Work-product protection shields materials prepared in anticipation of litigation. Both protections are destroyed when the protected information is voluntarily disclosed to a third party without a common-interest agreement or other recognized exception.
The court's analytical move was straightforward but consequential: an AI platform that contractually reserves the right to retain, review, or use submitted data is a third party. Submitting client documents to such a platform is a voluntary disclosure. The fact that the disclosure is to a machine rather than a human attorney is legally irrelevant — the ToS creates the relationship, and the ToS was unambiguous.
What makes the ruling broader than its immediate facts is the court's treatment of constructive knowledge. The attorneys in Heppner claimed they did not read the platform's Terms of Service. The court declined to treat ignorance of publicly available contractual terms as a defense. If the ToS permitted retention, and attorneys used the tool, disclosure occurred.
The implication for the 69% of legal professionals now using general-purpose AI tools for work: most of them have not read a single ToS, and most of those ToS documents permit exactly the kind of retention Heppner held fatal to privilege.
The Q1 2026 Ruling Cluster: An Emerging Circuit Split You Cannot Ignore
Heppner did not emerge in isolation. Federal courts issued four significant privilege-related AI rulings in Q1 2026 alone, and the doctrinal picture is actively contested.
The fault line is clearest on work-product protection. Two circuits have followed Heppner's logic strictly: if the AI platform's ToS permits any data retention or model-training use, work-product protection is waived as to materials submitted to that platform. Two other circuits have applied a more nuanced "reasonable precautions" framework, asking whether the attorney took affirmative steps to limit disclosure — including whether they selected enterprise-tier agreements with explicit no-retention terms, whether they reviewed the applicable ToS, and whether they maintained documentation of those steps.
The practical effect of the "reasonable precautions" standard is not that public AI tools are safe. It is that firms must now be prepared to produce evidence of their AI governance posture in discovery — the specific tool used, the specific ToS version operative at the time, any enterprise agreement provisions, and audit logs demonstrating what data left the firm's control and when.
| Circuit Framework | What Courts Ask | What You Must Produce |
|---|---|---|
| Strict Heppner | Did the ToS permit retention? | The ToS. Privilege is gone if yes. |
| Reasonable Precautions | Did counsel take affirmative steps to limit disclosure? | Enterprise agreement, ToS review memo, audit logs, zero-retention confirmation |
| Emerging hybrid | Was the disclosure reasonably necessary to the legal representation? | Necessity justification + governance documentation |
Under any of these frameworks, firms with no AI policy — 43% of AmLaw 200 firms and a larger share of mid-market firms — are exposed. They cannot produce governance documentation they never created.
The Architecture Question Courts Are Really Asking
Lawyers and technologists discussing these rulings often conflate two distinct questions: which AI tool did you use and what data left your control, and under what terms. Courts are beginning to ask the second question, and the answer depends entirely on how your AI system is architected.
Consider the difference between two approaches to AI-assisted due diligence on a sensitive M&A matter:
Approach A — Direct consumer or SMB-tier cloud AI tool: The attorney pastes excerpts from target company contracts into ChatGPT's standard interface, or uploads documents to a general-purpose AI assistant operating under standard Terms of Service. The full text of those documents — potentially including trade secrets, representations and warranties, and privileged deal communications — is submitted to the platform. The platform's ToS permits retention for service improvement. Under Heppner, privilege and work-product protection for those materials is waived.
Approach B — Private deployment with sovereign data layer: The firm's AI system ingests the full contract corpus into a vector store and retrieval index running on firm-controlled infrastructure. When an attorney queries the system, the retrieval layer identifies the relevant contract clauses — perhaps a few hundred tokens of text — and sends only those minimal chunks to an external LLM API under the firm's enterprise agreement, which explicitly prohibits data retention and training use. The full documents never leave the firm's infrastructure. The LLM sees fragments, not files. The firm's audit log records exactly what was retrieved and sent.
The architectural distinction that matters legally: it is not simply "our data never leaves." Sophisticated private deployments may still use external LLM providers for inference. The defensible claim is more precise: the full corpus, the agent layer, the retrieval index, the vector stores, the workflow logic, and the complete client documents remain on firm-controlled infrastructure. Only the minimal retrieved text necessary to answer the specific query is sent to an external model provider, under enterprise API terms the firm has reviewed and controls.
That distinction — sovereign data layer versus minimized model call — is what survives scrutiny under both the strict Heppner framework and the emerging "reasonable precautions" standard. You can produce the audit log. You can produce the API agreement. You can demonstrate that no complete client document was ever transmitted to a third party.
This is the architecture underlying private AI deployment models designed specifically for privilege-sensitive legal work — and it is meaningfully different from simply paying for an enterprise tier of a consumer AI product.
What "Enterprise Tier" Actually Gets You — and What It Doesn't
The standard industry response to privilege concerns has been: use the enterprise version, which doesn't train on your data. This answer is partially correct and dangerously incomplete.
Enterprise agreements for tools like ChatGPT Enterprise, Microsoft 365 Copilot, or enterprise Harvey typically do include no-training-use provisions. That addresses one of the two Heppner concerns: model training as a disclosure mechanism. But it does not address all of them:
- Retention for operational purposes: Many enterprise agreements permit temporary retention of prompts and outputs for purposes like abuse prevention, safety monitoring, or service delivery. Whether that retention constitutes a "disclosure" sufficient to waive privilege under Heppner is an open question courts have not uniformly resolved.
- Subprocessor chains: Enterprise agreements delegate data handling to subprocessors whose own terms may not be reviewed by the contracting firm. Full corpus documents submitted to a cloud AI tool may touch infrastructure governed by terms the firm never read.
- Audit log accessibility: Enterprise agreements vary significantly in what logging they provide to the customer versus what they retain internally. Under the "reasonable precautions" standard, you need your log, not a vendor's promise.
- Incident notification obligations: If a cloud AI platform experiences a data incident involving your client documents, your notification obligations under professional conduct rules are triggered — but your ability to detect and respond depends on whether the platform tells you, and when.
None of this means enterprise cloud AI tools are categorically unusable for legal work. It means the calculus is more complex than the enterprise-tier checkbox suggests, and it means the governance burden falls on the firm, not the vendor.
For a deeper look at how to evaluate AI tools across the privilege and governance dimensions, our AI for law firms guide walks through the specific contractual and architectural questions your evaluation process should address.
The 43% Problem: No Policy, No Defense
The statistic that should concentrate minds in every managing partner meeting: 43% of law firms have no AI policy, even as 69% of legal professionals report using general-purpose AI tools for work. That gap — widespread unsupervised use with no governance framework — is precisely the fact pattern Heppner was decided on.
An AI policy is not, by itself, a privilege shield. Courts will not accept "we had a policy" as a defense if the policy permitted use of tools with data-retention terms. But the absence of any policy eliminates the possibility of the "reasonable precautions" defense entirely. You cannot argue you took reasonable steps to prevent disclosure if you took no steps at all.
What a privilege-defensible AI policy needs to address in a post-Heppner environment:
- Tool inventory and ToS review: A documented, date-stamped review of the operative Terms of Service and data processing terms for every AI tool approved for use on client matters
- Matter classification: A framework for identifying privilege-sensitive matters and specifying which AI tools may and may not be used on those matters
- Data minimization requirements: Explicit restrictions on submitting complete client documents to any AI tool whose full data handling cannot be verified — as opposed to working with retrieved excerpts under a controlled architecture
- Audit log requirements: A requirement that any AI tool used on client matters generates a log the firm can access and produce in discovery
- Periodic recertification: A process for re-reviewing tool terms when vendors update their ToS — which the major providers do regularly
Building this policy is not optional. It is the table stakes for defending against a Heppner-style privilege challenge.
Toward a Privilege-Safe AI Architecture: What the Leading Firms Are Building
The firms moving fastest in response to Heppner are not retreating from AI. They are investing in architectural control — the ability to use powerful AI capabilities while maintaining demonstrable sovereignty over client data.
The practical pattern emerging at leading AmLaw 100 firms involves separating the AI stack into two distinct layers with different governance requirements:
Layer 1 — The sovereign data layer (stays on firm infrastructure):
- Full client document corpus
- Vector stores and retrieval indices built from those documents
- Agentic scaffolding and workflow logic
- Permission controls (who can query which documents)
- Audit logs (what was retrieved, when, by whom, what was sent externally)
- Matter metadata and client identifiers
Layer 2 — The inference layer (external LLM call, minimized data):
- Retrieved text chunks (not full documents) necessary to answer the specific query
- System prompts and query context
- Governed by firm-reviewed enterprise API terms with explicit no-retention provisions
This separation does two things simultaneously. It enables access to the most capable frontier models — GPT-4o, Claude 3.5 Sonnet, Gemini 1.5 Pro, and their successors — without surrendering the firm's corpus to those providers' data environments. And it creates a defensible audit trail: if challenged in discovery, the firm can demonstrate exactly what data left its control, in what form, under what contractual terms.
Tools built on this architectural pattern — including case search and document analysis capabilities that keep retrieval on firm infrastructure while allowing flexible model selection — represent a different category of solution than either consumer AI tools or simple enterprise-tier subscriptions to general-purpose platforms.
The key question to ask of any AI vendor in your evaluation process is not "do you have an enterprise tier?" It is: "Where does my full document corpus live, who controls the retrieval layer, what exactly gets sent to the LLM, and can you show me the audit log?"
What the Next 18 Months Look Like
The Heppner ruling will not be the last word. The circuit split on work-product waiver will likely produce appellate decisions in 2026 and 2027 that refine the doctrine. Bar associations in several jurisdictions have accelerated formal ethics opinion processes on AI tool use, and the ABA's Standing Committee on Ethics and Professional Responsibility is expected to issue updated guidance before year-end 2026.
Three developments to watch:
1. Discovery requests targeting AI tool use. Opposing counsel in high-stakes litigation will increasingly include AI tool interrogatories — which tools did you use, when, on what documents, under what ToS. The firms that cannot answer these questions precisely are exposed.
2. Malpractice claims predicated on privilege waiver. The causal chain from Heppner to a malpractice claim is short: attorney uses public AI tool, privilege is waived, adverse party obtains protected communications in discovery, client suffers harm. Malpractice insurers are already beginning to ask about AI tool governance in renewal conversations.
3. Competitive differentiation on governance. Within 18 months, sophisticated clients — particularly financial institutions, pharmaceutical companies, and any client that has experienced litigation involving AI-related privilege disputes — will begin asking firms directly about their AI governance architecture before engagement. The firms with documented, auditable answers will have a material advantage.
The conversation your firm needs to have is not whether to use AI — that decision has been made by your associates and partners, with or without your policy. The conversation is whether you have the architectural control to use AI on the matters that matter most, with a governance posture you can defend in front of a federal judge. If you are evaluating what that architecture looks like in practice, the private AI deployment frameworks being adopted by leading firms in the post-Heppner environment are a useful starting point — not as a retreat from capability, but as the infrastructure that makes capability sustainable.
Frequently Asked Questions
Does the Heppner ruling mean law firms can't use AI tools like ChatGPT or Harvey?
What is the difference between a public AI tool and a private or on-premise AI deployment for privilege purposes?
What should a managing partner or CIO do right now in response to the Heppner ruling?
Related Articles
Heppner v. United States: Why Your Firm's AI Infrastructure Now Determines Privilege
The SDNY ruling that changes how every law firm should think about AI — Judge Rakoff held that documents generated using consumer AI chatbots are not protected by attorney-client privilege.
Your AI Vendor's Moat Is Your Data. Here's How to Take It Back.
How SaaS AI vendors build competitive moats from your firm's usage data — the shared learning paradox, the dilution problem, and why proprietary AI keeps the compounding advantage with you.
AI for Law Firms in 2026: The Complete Guide to Choosing, Deploying, and Owning Legal AI
Comprehensive guide to AI adoption for law firms in 2026 — agentic AI, proprietary vs SaaS, privilege implications, pricing, and the ownership model.
Agentic AI for Law Firms: What It Actually Means in 2026
What agentic AI actually means for law firms — plain-English definition, what the big players are doing, real deployment examples, and how custom agents differ from SaaS workflows.
RAGbase Legal builds proprietary AI systems for law firms — deployed on the firm's own infrastructure, zero data retention, full code ownership. 80+ enterprise deployments.
See How RAGbase Legal Works on Your Data
Free 3-5 day proof of concept. Your data, your infrastructure, working results.