Skip to content
All guides
Photograph of four blank sheets of paper laid out in a row like steps, with small tabs at their edges

Contracts

Is Anything You Type Into an AI Confidential? (2026)

By FixMyContractLast updated Sep 9, 20269 min read

Short answer, for US courts: no. Typing a legal question into an AI assistant does not make the conversation privileged, and in February 2026 a federal judge said so directly. Your AI chats can be demanded in discovery like any other document you wrote. That does not make AI useless for contracts — it makes what you type a decision worth making on purpose. This guide explains the three 2026 cases that changed the picture, and the practical version of what to do about it.

The question people were actually asking

For about three years, "is it safe to ask an AI about my legal problem?" had no real answer. People assumed one of two things, and both were guesses:

  • "It's like talking to a search engine, so it doesn't matter."
  • "It's like talking to an advisor, so it's probably private."

In 2026, US courts started answering. Three separate matters — a criminal case, a civil suit, and a Supreme Court denial — each addressed a different edge of the same question. Taken together they draw a line that is genuinely useful to know before you paste anything sensitive into any tool, ours included.

Case 1: your AI chats are not privileged (February 2026)

The clearest of the three. In United States v. Heppner (S.D.N.Y., No. 25-CR-503), Judge Jed S. Rakoff ruled from the bench on 10 February 2026, with a written opinion following on 17 February 2026.

The facts. Bradley Heppner, a financial-services executive facing securities- and wire-fraud charges, had received a grand jury subpoena and had hired counsel. Separately — on his own initiative, not at his lawyers' direction — he used a consumer Claude account to research the charges he might face and the defences he might raise. That produced 31 documents of prompts and responses. Those documents were seized in a November 2025 arrest search; his counsel withheld them on a privilege log, and when the government moved in February 2026 to compel their production, he claimed attorney-client privilege and work-product protection.

The ruling. He lost on every element. As reported by multiple firms summarising the opinion, the court held: "Because Claude is not an attorney, that alone disposes of Heppner's claim of privilege." The court went further and found two additional problems:

  1. There was no confidentiality. Entering the text disclosed it to a third party whose own published policy reserves the right to disclose inputs and outputs to third parties including governmental regulatory authorities. Privilege requires an expectation of confidentiality; the terms he agreed to defeated it.
  2. There was no legal-advice purpose. He consulted the tool of his own volition rather than at counsel's direction, so the work-product doctrine — which protects material prepared in anticipation of litigation, by or for a party's representative — did not reach it either.

The limit worth knowing. The decision addressed a consumer account used without counsel's direction. Commentators reading the opinion note it leaves open whether counsel-directed use of an enterprise platform, under a contract with real confidentiality terms, would be analysed differently. That is an open question, not a loophole — and it does nothing for someone using a chatbot on their own.

What this means for a normal person. If you are in a dispute, or think you might be, assume anything you type into any AI assistant could later be read by the other side. That is the safe operating assumption in US practice as of September 2026.

On 4 March 2026, Nippon Life Insurance Company of America filed suit against the OpenAI entities in the Northern District of Illinois (Nippon Life Ins. Co. of Am. v. OpenAI Fdn., No. 1:26-cv-02448).

The alleged facts, per the complaint as reported: a litigant whose case had already settled and been dismissed with prejudice uploaded correspondence from her own attorney into ChatGPT and asked it to evaluate the advice she had been given. The complaint alleges the system questioned her lawyer's conduct and the settlement's legitimacy, encouraged her to dismiss counsel and pursue the matter further, then helped research, draft and file motions and subpoenas attempting to reopen the closed case. The complaint pleads tortious interference with contract, abuse of process, and unlicensed practice of law, and seeks a declaratory judgment, an injunction, and $10 million in punitive damages.

This is an allegation, not a finding — the case is pending, and nothing here should be read as a conclusion about what OpenAI did. Its importance is the question it forces into the open: at what point does an AI stop describing the law and start practising it?

Two things follow from that question, whatever the case's outcome:

  • A tool that tells you what a clause means is doing something different from a tool that tells you to sue. The first is explanation; the second is a strategic recommendation about your specific dispute. The distance between them matters legally, and it is the distance we deliberately keep.
  • "Confidently wrong" has a cost. The complaint's core grievance is not that the system was unhelpful — it is that it was persuasive. That is a good reason to check any AI reading of your contract against the clause it is describing, rather than against how certain it sounds.

Case 3: who is allowed to help you at all (March 2026)

The third piece is quieter but shapes everything above. Upsolve, Inc. v. James asked whether a nonprofit could train non-lawyer "Justice Advocates" to help low-income New Yorkers fill in a state-issued check-the-box answer form in debt-collection cases — activity all parties agreed would violate New York's unauthorized-practice-of-law rules.

The district court had enjoined enforcement on First Amendment grounds. The Second Circuit vacated the reasoning, holding the UPL rules content-neutral and therefore subject to intermediate rather than strict scrutiny. Upsolve petitioned the US Supreme Court on 6 February 2026 (No. 25-948). On 30 March 2026, the petition was denied.

A denial of certiorari is not a ruling on the merits — the Court gives no reasons and decides nothing. But the practical effect is real: who may give individualised legal advice remains a question each US state answers for itself, and the Second Circuit's framework stands in its circuit. There is no national rule coming soon that would let a piece of software — or a trained volunteer — step into a lawyer's role.

So what should you actually do?

The three cases point in one direction, and it is not "don't use AI." It is: decide what goes in.

1. Separate "explain this" from "what should I do about my dispute." Asking what an indemnification clause means, or which parts of a lease are unusual, is understanding a document. Asking whether to sue someone, or whether your lawyer is any good, is asking for legal strategy about a live matter — and that is the category the Heppner and Nippon matters both sit in.

2. Treat every AI chat as a document you wrote. Not a diary, not a private thought. If it exists, it can be requested. In a live or foreseeable dispute, that is the whole calculus.

3. Be careful with your lawyer's emails. This is the sharpest practical point in the Heppner commentary. Your correspondence with your lawyer is privileged — until you show it to a third party. Firms reading the decision flag the risk that feeding privileged material into a consumer AI could waive privilege over the original exchange. Whatever you gain from the summary is not worth that.

4. Check the tier you are on — the terms are not the same. Per Anthropic's own published policy for consumer accounts (Free, Pro, Max; page last updated 1 July 2026): a deleted conversation leaves your history immediately and back-end storage within 30 days — but if you leave the model-improvement setting on, your data may be retained in de-identified form for up to five years in model-training pipelines. Content flagged under the usage policy is kept up to two years, with safety classification scores up to seven. That same page states plainly that commercial products and the API are covered by a different policy. Most people have never opened that setting. It is worth two minutes.

5. For anything high-stakes, a lawyer is still the answer. Not a hedge — a boundary. See what a contract review actually costs if you are trying to work out whether your situation clears that bar.

And what about us? The honest version

We build an AI contract review tool. It would be convenient to skip this section. Here is where we actually stand, in the same plain terms:

  • Nothing you send us is privileged. We are not a law firm and we have no lawyers on the other end of your upload. Everything in the Heppner analysis above applies to us exactly as it applies to any other tool. If you are in a dispute, the same caution applies here.
  • We give you a reading, not a recommendation about your dispute. The output is a clause-by-clause explanation, a risk read from your side of the deal, and specific things to ask for before you sign. It is built for the moment before you sign, not for a matter already in front of a court.
  • On the data itself, we publish specifics rather than adjectives. Your documents are analysed by our AI provider (named in our Privacy Policy), which does not train its models on that data, and per its published retention policy deletes the text we send within 30 days at most. We delete the document you uploaded 30 days after upload, and your report whenever you delete it yourself. Data is encrypted in transit and at rest, and access is scoped to your own account. The exceptions, the edge cases, and the sources are all set out on our privacy page — including the two different "30 days" on that page, which are not the same thing.

That is a narrower promise than "your data is safe with us," and it is narrower on purpose. A promise you can check is worth more than one you cannot.

The one-line version

In US practice as of September 2026: an AI is not your lawyer, your chats with it are not privileged, and the rules about who may give legal advice are still set state by state. Use AI to understand the contract in front of you — and keep the strategy conversation where privilege actually exists.

Sources

All links checked 9 September 2026.

  1. United States v. Heppner, No. 25-CR-503 (S.D.N.Y.) — bench ruling 10 Feb 2026, written opinion 17 Feb 2026 (Rakoff, J.). Harris Beach Murtha, "In a First, Court Finds AI-Generated Documents Not Protected by Attorney-Client Privilege" — https://www.harrisbeachmurtha.com/insights/in-a-first-court-finds-ai-generated-documents-not-protected-by-attorney-client-privilege/
  2. United States v. Heppner, No. 25-CR-503 (S.D.N.Y. Feb. 17, 2026), Mem. Op. at 5, ECF No. 27 — primary source for the "Because Claude is not an attorney…" quote — https://www.courtlistener.com/docket/71872024/united-states-v-heppner/
  3. Epstein Becker Green, "'Claude Is Not an Attorney': Individuals Risk Abandoning the Attorney-Client Privilege and Attorney Work-Product Doctrine When Consulting AI" (published 12 Mar 2026) — https://www.ebglaw.com/commercial-litigation-update/claude-is-not-an-attorney-individuals-risk-abandoning-the-attorney-client-privilege-and-attorney-work-product-doctrine-when-consulting-ai
  4. Jones Walker LLP, "Your AI Conversations Are Not Privileged: What a New SDNY Ruling Means for Every Lawyer and Client" — https://www.joneswalker.com/en/insights/blogs/ai-law-blog/your-ai-conversations-are-not-privileged-what-a-new-sdny-ruling-means-for-every.html
  5. Nippon Life Ins. Co. of Am. v. OpenAI Fdn., No. 1:26-cv-02448 (N.D. Ill., filed 4 Mar 2026). Norton Rose Fulbright, "AI in litigation series: Complaint accuses OpenAI of practicing law without a license" (2 Apr 2026) — https://www.insidetechlaw.com/blog/2026/04/ai-in-litigation-series-complaint-accuses-openai-of-practicing-law-without-a-license
  6. Upsolve, Inc. v. James, No. 25-948 (U.S.) — docket, petition filed 6 Feb 2026, certiorari denied 30 Mar 2026 — https://www.supremecourt.gov/docket/docketfiles/html/public/25-948.html
  7. Upsolve, Inc. v. James, No. 22-1345 (2d Cir. 2025) — https://law.justia.com/cases/federal/appellate-courts/ca2/22-1345/22-1345-2025-09-09.html
  8. Anthropic, "How long do you store my data?" (consumer products; page last updated 1 July 2026) — https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data
  9. FixMyContract privacy policy, sections 8–9 — https://fixmycontract.com/privacy