Your lawyer sends a complicated email. You want to understand it, so you paste it into a chatbot and ask for a plain-English explanation. It feels like using a private notebook. But you may have just shared legal advice with a company outside your relationship with your lawyer.
Using ChatGPT, Claude or another AI service does not automatically waive attorney–client privilege in every situation. It can, however, put protected communications at risk. And a conversation you create with a chatbot may never have been privileged in the first place. Those are different problems, with potentially serious consequences.
What privilege actually protects
Attorney–client privilege generally protects confidential communications between a client and a lawyer made to obtain or provide legal advice. It helps people speak candidly with their lawyers. It is not a blanket shield over everything connected with a case. Sharing a protected communication outside the relationship can undermine its confidentiality, although exceptions and the applicable jurisdiction matter. Cornell Legal Information Institute: attorney–client privilege.
The underlying facts are a separate issue. In Upjohn Co. v. United States, the Supreme Court distinguished protected communications from the facts they discuss. Sending an existing document to a lawyer does not make its underlying facts disappear from discovery. Upjohn, 449 U.S. 383, 395–396 (1981).
Two other protections are easy to confuse with privilege. A lawyer’s ethical duty of confidentiality covers a broader range of information about the representation. Work-product protection concerns certain materials prepared for anticipated litigation. Neither is interchangeable with attorney–client privilege. ABA Model Rule 1.6, comment 3; Federal Rule of Civil Procedure 26(b)(3). State rules may differ from the ABA model.
A real warning from the courts
In United States v. Heppner, a defendant independently used consumer Claude to prepare defense-related material and later shared it with his lawyers. On February 17, 2026, a federal judge explained why the AI documents were protected by neither attorney–client privilege nor work product on those facts. The court considered the absence of counsel’s direction and the provider’s then-applicable privacy policy. It also said that any privileged information entered into Claude had been waived by that disclosure. Giving the resulting documents to counsel afterward did not make them privileged. Heppner, No. 25 Cr. 503 (S.D.N.Y.), opinion, sections II–III and footnote 3.
That is a concrete warning, not a universal rule about every AI product. In Morgan v. V2X, a Colorado federal court recognized work-product protection for a self-represented litigant’s AI-assisted preparation. It nevertheless required disclosure of the tool’s identity and added contractual safeguards for processing confidential discovery. This concerned work product and a protective order; it did not turn a chatbot into a lawyer. Morgan, No. 25-cv-01991, March 30, 2026 order.
The practical lesson from these decisions is to examine the actual material, the tool’s terms, counsel’s role, and the rules governing the case. “AI always destroys privilege” and “my chat is private, so privilege is safe” are both unreliable shortcuts.
What losing protection could mean
In a civil case, relevant, proportional, nonprivileged material may be subject to discovery. Whether a particular record must be produced, and whether it can be used as evidence, are separate questions. Loss of privilege is not automatic publication of your entire case file. But it may remove an important basis for resisting disclosure. Federal Rule of Civil Procedure 26(b)(1).
Consider these fictional examples. They illustrate possible consequences, not predictions about how a judge would rule:
- A settlement discussion. You upload your lawyer’s assessment of a weak point and your willingness to compromise. If that communication becomes obtainable, the other side could learn something you expected to discuss only with counsel.
- A chronology you are still checking. You ask a model to turn uncertain memories into a confident narrative. The draft gets a date wrong. If produced, it could prompt questions about inconsistency even though the model’s wording was never a verified account.
- A bundle of discovery documents. You upload records marked confidential to get a summary. A protective order may restrict that upload separately from any privilege question. A convenient summary does not change the order’s terms.
Even a successful fight to preserve protection can consume time and legal fees. The concern is not that asking for an explanation is wrong. It is that an unnoticed disclosure can create a second dispute alongside the one you were trying to understand.
A privacy setting is not a privilege ruling
Before using any hosted tool, ask who can access the content, how long it is retained, whether it can be used for training, what contractual confidentiality obligations apply, and whether other services receive it. A no-training commitment answers one question; it does not answer all of them. Encryption during storage is also different from keeping content unreadable to a provider while it processes a request.
The ABA’s guidance tells lawyers to understand a generative AI tool’s risks, evaluate confidentiality safeguards, and obtain informed consent where required. A product label or a generic consent clause does not replace that assessment. ABA Formal Opinion 512, confidentiality discussion.
A better way to ask for help
Start by asking your lawyer to explain the email, or ask which tools and workflow they approve for the specific material. For general learning, use a question that does not disclose your case: “What is a deposition?” is different from uploading your lawyer’s advice about your own testimony. Removing names alone may still leave identifying facts or confidential strategy.
If you already uploaded sensitive material, tell your lawyer what you shared, when, and through which service and settings. Do not try to solve the problem by quietly deleting potential evidence. Preservation duties may apply, and a lawyer can advise on mitigation and any necessary notice. Federal Rule of Civil Procedure 37(e), electronically stored information.
Where CoClient fits
CoClient helps you understand your records and prepare better questions. The web workspace stores case content encrypted in your browser by default; optional cloud storage receives encrypted copies under your key. Optional hosted AI requires you to review and approve the context for each request, and that approved context is readable during processing. Account and billing information are separate operational records.
CoClient does not create attorney–client privilege or guarantee that it will be preserved. Local storage and deliberate disclosure controls help you manage information; they are not a legal determination. You can explore the workflow with fictional records before deciding what belongs in your own workspace.
This article provides general US legal information, not advice about your case. The cited decisions are examples, not a comprehensive survey. Privilege depends on the applicable law and facts; speak with a qualified lawyer before sharing protected material.