Are Your ChatGPT Or Claude Legal Chats Attorney-Client Privileged?

August 23, 2026

Your ChatGPT or Claude legal chat is not automatically privileged. See what Heppner held, what later work-product rulings protected, and what remains uncertain.

No. A private conversation with ChatGPT or Claude is not automatically protected by attorney-client privilege just because you asked a legal question. The chatbot is not your lawyer, and a federal court has ordered production of documents a represented defendant created independently with consumer Claude.

That does not mean every AI-assisted legal document is discoverable. Later 2026 decisions protected some ChatGPT prompts and outputs as litigation work product. The result can change with the jurisdiction, why the material was created, whether a lawyer directed the work, who could access it, the product terms and configuration, and whether disclosure made it likely an adversary would receive it.

The practical rule for consumers is simple: do not treat a consumer AI chat as a privileged substitute for speaking with a lawyer. If you already have counsel, ask which AI tools and configurations are approved before entering facts, documents, strategy, settlement positions, or communications from your lawyer.

This article explains the emerging U.S. cases and is general information, not legal advice.

What Is Confirmed

In United States v. Heppner, the U.S. District Court for the Southern District of New York considered 31 documents that a criminal defendant created using a consumer Claude account. He had lawyers, used information they supplied, intended to send the results to them, and later did so. But his lawyers had not directed him to use Claude.

The court held that the documents were neither attorney-client privileged nor attorney work product. Its reasoning included several separate points:

The ruling is important, but it is not a nationwide declaration that every AI prompt is discoverable. It is one federal trial-court decision based on specific facts. The court expressly left room for a different analysis if a lawyer directed a client to use an AI tool as part of legal representation.

Later courts have reached different work-product results. In a June 2026 Texas Business Court order, the court agreed with Warner v. Gilbarco and Morgan v. V2X that some ChatGPT conversations prepared in anticipation of litigation could be protected work product. It rejected the idea that using ChatGPT automatically waived that protection merely because information passed through a third party.

That same Texas order did not hide everything. It ordered some pages produced because they were not work product, required identification of discovery materials shared with ChatGPT, and recommended that the parties clarify AI use in their protective order. Protection was document-specific, not a blanket chatbot privilege.

Anthropic's June 2026 legal-work guidance identifies four post-Heppner trial-court decisions that protected some AI-assisted litigation preparation as work product: Warner, Morgan, Tate Group Automotive, and Assini. Anthropic also cautions that none is an appellate decision and that courts in other jurisdictions may disagree.

The confirmed answer is therefore narrower than the viral claim:

Question Defensible answer today
Is a consumer chatbot your lawyer? No. Asking an AI a legal question does not create a lawyer-client relationship.
Is every ChatGPT or Claude legal chat privileged? No. There is no automatic chatbot privilege.
Is every AI-assisted legal chat discoverable? Also no. Some courts have protected litigation-related material as work product.
Does using an AI vendor always waive work product? No. Several courts have rejected automatic waiver, especially when disclosure does not make adversary access substantially more likely.
Can a provider receive civil legal process for user data? Yes, subject to applicable law, service requirements, objections, scope, and what records actually exist.

What Is Still Unclear

The law is developing quickly, and several important questions do not have one national answer:

There is also an important distinction between legal protection and ethical permission. The American Bar Association's Formal Opinion 512 says lawyers using generative AI must consider duties including competence, confidentiality, communication, supervision, candor, and reasonable fees. It does not declare every lawyer's AI use privileged, and it does not mean a consumer should upload case materials without counsel's approval.

Attorney-Client Privilege, Work Product, Privacy, And Discovery Are Different

Online discussion often compresses four separate concepts into the word "private." They are not interchangeable.

Attorney-client privilege

Attorney-client privilege generally protects qualifying confidential communications between a client and a lawyer for the purpose of obtaining or providing legal advice. A chatbot alone is neither party to that relationship.

A draft, note, or AI transcript can sometimes reflect or transmit a privileged lawyer-client communication. But the label "legal chat" does not itself create the privilege. Courts examine the people involved, the purpose of the communication, confidentiality, and the governing law.

Work-product protection

Work product generally protects qualifying materials prepared in anticipation of litigation or for trial. Depending on the applicable rule, it can cover a party's own mental impressions even when no attorney authored the material.

That helps explain the different results in Heppner and the later cases. The later courts focused on litigation preparation and whether using an AI service disclosed the work to an adversary or made adversary access substantially more likely. The Texas court also emphasized that its state rule expressly covered material prepared by or for a party.

Work product is not identical to attorney-client privilege. A document can fail one doctrine and satisfy the other, or satisfy neither.

Product privacy and retention

A provider's privacy controls answer operational questions: whether chats appear in account history, are used for model improvement, are retained for abuse monitoring, are available to workspace administrators, or can be exported or deleted.

Those controls can matter to confidentiality, but they do not create a lawyer-client relationship. A "temporary" chat is not automatically privileged. A no-training setting is not a discovery shield. A business contract is not a court ruling.

The inverse is also true: a vendor processing confidential material does not necessarily destroy legal protection. Lawyers routinely use non-adversary vendors such as e-discovery platforms and translators. The contract, configuration, purpose, supervision, and disclosure risk all matter.

Discovery and legal process

Discovery is the process through which parties obtain relevant information in a lawsuit. A party may be asked to produce records in its possession, custody, or control. A provider can also receive a subpoena or court order.

OpenAI's civil user-data request policy says it responds to civil requests validly served under applicable law and produces information only as legally permitted. It says requests should identify the account, categories of records, time period, court, caption, and case number. OpenAI may reject or seek clarification of incomplete or overbroad requests and may object when a party has not first tried to obtain counterparty data through ordinary party discovery. It ordinarily notifies the user before disclosure when legally possible and appropriate.

That policy proves there is a process. It does not prove that any opponent can ask casually and receive every chat, that OpenAI retains every requested record, or that privilege and other objections disappear.

What Heppner Actually Means For Consumer AI Users

Heppner is a warning against a common mental shortcut: "I was researching my case, so the conversation must be privileged."

The defendant's later decision to send the Claude-generated documents to his lawyers did not retroactively turn his earlier exchange with the chatbot into a confidential lawyer-client communication. The court also refused to treat Claude as the functional equivalent of a lawyer's agent on those facts because the lawyers did not direct the use.

The ruling does not say that using Claude is illegal, that AI-generated legal research can never assist a lawyer, or that every provider record is available in every case. It says that the traditional legal tests still apply. The AI interface does not supply the missing lawyer, purpose, direction, confidentiality, or litigation nexus by itself.

Why The Later Work-Product Cases Matter

The post-Heppner decisions prevent an equally misleading conclusion: "Anything sent to an AI company loses all protection."

The June Texas order reasoned that work-product waiver normally turns on disclosure to an adversary or a disclosure that substantially increases the chance an adversary will obtain the material. It protected many ChatGPT conversations created in anticipation of litigation while ordering other material produced. It also required the party to identify discovery materials it had uploaded.

That combination is useful. A court can protect the user's litigation thinking without treating the AI workflow as invisible. Tool identity, input sources, privilege logs, protective-order compliance, and non-protected pages may remain discoverable.

Anthropic argues that lawyer-directed use under confidentiality-bound commercial terms can resemble other legal-service vendors. That is Anthropic's position, not a universal legal rule. Its own guidance tells legal teams to consider jurisdiction, client consent, retention, deployment, and whether a lawyer remains visibly in the loop.

Use The COUNSEL Check Before Discussing A Legal Matter With AI

Before entering legal facts or strategy into any AI product, use this seven-part check:

C - Counsel

Do you already have a lawyer? If yes, ask that lawyer before using AI on the matter. Do not assume that sending the output later is enough.

O - Objective

Why are you creating the material? General curiosity, business planning, and preparation for anticipated litigation can receive different treatment.

U - User account and terms

Identify the exact product, plan, workspace, settings, and terms in effect. Do not transfer an enterprise privacy claim to a consumer account.

N - Network of recipients

List everyone who can access the prompt, output, export, shared link, device, workspace, or destination document. Sharing with an adversary is especially consequential.

S - Sources supplied

Know what you are pasting: lawyer emails, discovery, medical records, employment files, financial statements, settlement positions, or third-party personal data. Authorization to possess a document is not automatically authorization to upload it.

E - Evidence and preservation

If litigation is pending or reasonably anticipated, do not delete chats or files to make them unavailable. Preservation duties can apply even when the material is embarrassing or damaging. Ask counsel before changing or deleting relevant records.

L - Local and provider copies

Map account history, browser-local storage, temporary-chat records, exports, screenshots, backups, provider retention, and downstream documents separately. One deletion control rarely reaches every copy.

Does Temporary Chat Create Attorney-Client Privilege?

No. Temporary-chat or history-off settings can change visibility, retention, or training behavior, depending on the provider. They do not turn the provider into a lawyer or automatically satisfy a jurisdiction's privilege or work-product test.

Temporary chat can still leave other records: a device screenshot, copied text, a downloaded file, browser artifacts, a provider safety record, or a document that received the output. The relevant question is not just whether the chat appears in a sidebar. It is which copies existed, what legal doctrine applies, and who controlled them.

Can Opposing Counsel Get Your ChatGPT History?

They can ask for relevant AI records through discovery, and a court may order production if the request is valid and no privilege, work-product protection, proportionality objection, or other rule blocks it. They may first seek records from you because account exports or device copies can be within your control. They can also attempt valid legal process directed to a provider.

Whether they actually receive content depends on the case, jurisdiction, scope, objections, protective orders, provider records, and the facts behind any privilege or work-product claim. OpenAI's policy specifically notes that it may object if a litigant seeks counterparty data from OpenAI without exhausting party discovery first.

The large ChatGPT-log production orders in the New York Times copyright litigation do not prove that every individual's legal chats are freely available. Those orders addressed specific copyright claims, specific log reservoirs, de-identification, and a court-supervised production protocol. They show that provider-held AI records can become discovery evidence in major litigation, not that privacy interests or legal objections never matter.

A Safer Practical Workflow

If your question could affect a real legal right, deadline, claim, defense, contract, settlement, or criminal matter:

  1. Use a licensed lawyer in the relevant jurisdiction for advice.
  2. Ask whether AI use is appropriate for the matter and which tool is approved.
  3. Minimize personal, privileged, confidential, and third-party information.
  4. Confirm the exact account type, settings, contract, retention, access, and training rules.
  5. Keep the lawyer directing and reviewing any approved AI-assisted work.
  6. Verify AI output against primary legal authorities; models can invent cases and misstate current law.
  7. Follow preservation instructions and litigation holds. Do not delete relevant material to avoid discovery.

For low-stakes brainstorming that does not require case facts, redact names, addresses, account numbers, medical details, exact dates, unique events, and document text. Redaction reduces exposure but does not create privilege.

Where OpenVeil Fits - And Where It Does Not

OpenVeil is a privacy-focused hosted AI workspace for adults. It keeps normal chat history in the browser and does not create a normal server-side chat-history record. That can be useful for people who want a narrower history boundary than a conventional account-side archive.

It does not make a legal chat attorney-client privileged, create work-product protection, prevent discovery, defeat subpoenas or court orders, block access to the device, or authorize uploading confidential case material. Browser-local history can still exist on the device, in browser sync or backups, in exports or screenshots, and in documents where text was copied.

OpenVeil is also not fully offline or anonymous. Active prompts, uploads, selected history, and outputs still require processing by OpenVeil and necessary providers. Operational records may exist outside normal chat history. Read what browser-local chat history means and why no chat history does not mean no logs before deciding whether that boundary fits your use case.

If you need a privacy-focused workspace for ordinary, non-privileged AI tasks, you can try OpenVeil with ten preview actions. Plans begin at $10 and differ by included credits, not by a separate feature tier. Do not use OpenVeil as a substitute for a lawyer or as a promise of legal confidentiality.

Frequently Asked Questions

Are ChatGPT conversations attorney-client privileged?

Not automatically. ChatGPT is not your attorney, and a private chat with it alone does not create a lawyer-client relationship. A specific document may still qualify for another protection, such as work product, depending on the facts and governing law.

Are Claude conversations attorney-client privileged?

Not automatically. Heppner rejected privilege and work-product claims for documents a represented defendant independently made with consumer Claude. Anthropic says lawyer-directed use under appropriate commercial configurations can present different facts, but courts and jurisdictions can differ.

Can AI prompts be protected as work product?

Yes, in some circumstances. Several 2026 trial courts protected AI-assisted litigation materials prepared in anticipation of litigation. Other materials were ordered produced. The purpose, jurisdiction, disclosure risk, lawyer involvement, and specific document matter.

Does deleting an AI chat keep it out of discovery?

Not necessarily. Copies may exist in exports, screenshots, browser data, backups, downstream documents, or provider records. Deleting relevant material after a preservation duty arises can create additional legal problems. Ask counsel before deletion.

Does a no-training setting make a legal chat privileged?

No. Training use, retention, confidentiality, privilege, and work product are different questions. A no-training promise can support a confidentiality analysis but does not create an attorney-client relationship or guarantee protection.

Can I use AI to prepare questions for my lawyer?

You can use AI for general organization, but avoid entering confidential facts or lawyer communications without approval. Sending the result to a lawyer later does not necessarily protect the earlier AI exchange. The safer choice is to ask your lawyer how to prepare and which tools are acceptable.

Bottom Line

Your ChatGPT or Claude legal chat is not automatically attorney-client privileged. Heppner shows the risk when a client independently uses a consumer chatbot and later sends the result to counsel. Later cases show the opposite overstatement is also wrong: some AI-assisted litigation material can be protected work product, and using a confidentiality-bound vendor does not always waive that protection.

Treat product privacy, attorney-client privilege, work product, and discovery as four separate questions. When a real matter is involved, put the lawyer - not the chatbot - in charge of the workflow.

Sources

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.