Sovereign AI · confidentiality

Every prompt your team types into a public AI is a future exhibit.

In March 2026 a federal court ruled that a CEO's conversations with a public AI assistant were not privileged — and the government kept the files. The fix isn't to stop using AI. It's to run it where nothing leaves your walls.

The case

United States v. Heppner

S.D.N.Y. · Hon. Jed S. Rakoff · ruling March 2026

31 documents. Zero protection.

Bradley Heppner, a former financial-services CEO indicted for securities and wire fraud, used a publicly available AI assistant — on his own initiative, without his attorneys — to analyse his situation and draft defense arguments. During a search of his home, the FBI seized roughly 31 documents memorialising those AI conversations.

The court held the exchanges were protected by neither the attorney-client privilege nor the work-product doctrine. They became evidence.

  • Why #1An AI assistant is not an attorney. No attorney-client relationship can form, so the privilege never attaches.
  • Why #2He voluntarily shared the information with a third party — the AI vendor — waiving any confidentiality.
  • Why #3The vendor's own privacy policy lets it collect inputs and outputs, train on them, and disclose them to third parties, including the government.

The vendor in this case was the maker of a well-known assistant. That is the point, not a loophole: any public AI runs on someone else's servers under someone else's terms. This page is served by an estate built on AI that runs on its owner's machines — which is the whole reason it can say this plainly.

The difference, prong by prong

Same three questions. Opposite answers.

The court's reasoning is a checklist. Run your setup through it. Toggle where the AI actually lives:

Said honestly

Necessary, not magic.

Running AI inside your perimeter removes the third-party-disclosure problem — the vendor never holds your data, no terms grant anyone rights to it, and there is nothing on an outside server to subpoena. That is the one prong that is yours to fix, and it is decisive.

It does not, by itself, make an AI chat privileged — an AI still isn't a lawyer. Confidential AI is the necessary foundation for any privilege or work-product claim (do the work under counsel, as work product), not a substitute for one. We build the foundation and say exactly where it ends. Anyone promising more is selling the thing this page is about.

What "inside your perimeter" actually means

Your AI. Your machines. Your walls.

Questions

Straight answers.

Are AI chatbot conversations protected by attorney-client privilege?

No. In United States v. Heppner (Southern District of New York, 2026) a federal court held that a chief executive's conversations with a public AI assistant were protected by neither the attorney-client privilege nor the work-product doctrine, because an AI assistant is not an attorney and no attorney-client relationship can form. This is information, not legal advice.

Can prompts to an AI be used as evidence in court?

Yes. In United States v. Heppner the FBI seized around 31 documents recording the defendant's conversations with a public AI assistant, and the court held they were not privileged — so they could be used as evidence. Anything typed into a public AI sits on the vendor's servers under terms that permit collection, training, and disclosure, including to the government.

Does running AI on-premise make my conversations privileged?

No — and it is important not to overclaim this. Running AI inside your own perimeter removes the third-party-disclosure problem: no vendor holds your data and there is nothing on an outside server to subpoena. But it does not make an AI your lawyer. Confidential, on-premise AI is a necessary foundation for any privilege or work-product claim, not a substitute for one.

Is it safe to put confidential or client data into a public AI chatbot?

Treat it as not safe. Public AI assistants run on the vendor's servers under terms that typically permit retaining, training on, and disclosing your inputs, and courts have found such conversations discoverable and not privileged. For confidential or regulated data, use AI that runs inside your own perimeter so the data never leaves your control.