The risk can begin outside the organization
An internal AI policy governs employees and approved systems. It does not control what a client enters into a public chatbot, what an AI notetaker captures, or what an always-on device records before counsel becomes involved. That means responsible AI practice may require more than internal guidance. Legal organizations also need to decide when and how to discuss AI use with clients, especially when a matter involves sensitive facts or communications.
Courts have begun to answer parts of this.
In United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. Feb. 17, 2026), a defendant used a public chatbot on his own initiative to prepare defense strategy documents after he had retained counsel. The court found no privilege, reasoning that "Claude is not an attorney" and that "that alone disposes of Heppner's claim of privilege," and adding that because the provider's privacy policy disclosed collection of user inputs and outputs and reserved the right to share them with third parties, the defendant "could have had no reasonable expectation of confidentiality in his communications" with the tool. The court also declined to protect the documents as work product, because they "were not prepared at the behest of counsel and did not disclose counsel's strategy."
A different result is possible on the work product side. In Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629 (E.D. Mich. Feb. 10, 2026), the court held that a party's use of ChatGPT did not waive work product protection, observing that "ChatGPT (and other generative AI programs) are tools, not persons, even if they may have administrators somewhere in the background," and that work product waiver "has to be a waiver to an adversary or in a way likely to get in an adversary's hand."
The variable running through both is counsel's involvement. The Heppner court said as much: "Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent within the protection of the attorney-client privilege." It did not so hold, because counsel there had not directed the use. That is the practical point for an organization deciding when to raise AI with a client. Whether the client was on their own is doing much of the work.
Client guidance is an operating decision
A blanket warning is easy to write and difficult to apply. Useful guidance has to account for when the conversation occurs, which system is used, what information is shared, how the provider handles that information, and whether counsel directed or supervised the activity.
Those facts can change the analysis. The organization therefore needs a repeatable way to identify higher-risk situations and decide when a client conversation is warranted.
Questions worth resolving now
The first useful output may be a conversation guide rather than a universal rule. It can help attorneys surface the right facts and involve the right internal leaders before a matter becomes a test case for an improvised practice.
- When should an engagement or matter-opening process address client AI use?
- Which public AI, transcription, and recording scenarios deserve explicit discussion?
- How should attorneys document guidance, exceptions, and client decisions?
- Who reviews the guidance as technology, provider terms, and legal authority change?
Why the Council is following this question
This issue sits at the intersection of professional duty, client behavior, vendor systems, and everyday practice. It is exactly the kind of question that benefits from legal review, field research, and comparison across organizations.
AI Legal Council is developing this topic as a research and working-session theme. Any future legal briefing will identify its sources, uncertainties, and review process before publication.
This article is general research and educational material. It is not legal advice and does not create an attorney-client relationship.