SDNY Court Rules AI-Generated Legal Documents Not Protected by Privilege

Court Decision on AI-Generated Legal Documents
On February 10, 2026, Judge Jed S. Rakoff of the U.S. District Court for the Southern District of New York ruled in U.S. v. Heppner that 31 documents generated using a third-party AI tool were not protected by either attorney-client privilege or the work product doctrine. This appears to be the first court decision addressing whether interactions with publicly accessible AI tools containing privileged information are themselves privileged.
Key Findings from the Ruling
Judge Rakoff rejected attorney-client privilege claims based on several specific findings:
- The defendant communicated with a third-party AI platform (Anthropic's Claude)
- The AI tool's privacy policy states the company collects data on both user inputs and tool outputs
- Collected data is used to train the tool
- The company reserves the right to disclose such data to third parties including government regulatory authorities
The court found there was a diminished expectation of confidentiality when using public AI tools. The ruling also declined work product protection because the defendant prepared the material without direction from counsel.
Case Background
Defendant Bradley Heppner was arrested on fraud charges on November 4, 2025. Before his arrest, he used Claude to:
- Run queries related to the government's investigation
- Prepare reports outlining defense strategy
- Outline arguments regarding facts and law he anticipated the government might charge
Defense counsel argued privilege because Heppner's inputs included information learned from counsel, the documents were created to obtain legal advice, and he shared them with counsel.
Legal Standards Applied
The court applied traditional privilege standards:
- Attorney-client privilege requires communications between client and attorney that are kept confidential for obtaining/providing legal advice
- Work product doctrine protects materials prepared by counsel or at counsel's direction in anticipation of litigation
- The party invoking privilege bears the burden of demonstrating it applies
This ruling suggests companies and litigants should carefully review AI tool terms, particularly regarding data use for training and disclosure permissions. While fact-specific, it establishes precedent for how courts may treat AI-generated legal materials.
📖 Read the full source: HN AI Agents
👀 See Also

A 50-Dev Low-Code Shop Vaporized in 12 Months: The Dependency Trap of AI Coding Agents
A 50-person low-code shop lost all clients in 12 months because "low-code + AI" beats pure low-code and full-stack. Meanwhile, a solo developer dependent on Claude Max faces session caps and rising costs. Both illustrate the same dilemma: adapt or depend.

Claude Opus 4.7 Suffers Elevated Errors — Status Update
An automatic status update reports elevated errors on Claude Opus 4.7. Check the incident page and community megathread for progress.

Claude Code v2.1.187: Structured Output Fixes, Sandbox Security, and Org Model Restrictions
Claude Code v2.1.187 adds sandbox.credentials setting, org model restrictions, and fixes for structured output loops, remote MCP hangs, and subagent depth tracking.

AI Is Making Me Dumb: A Developer's Confession of Skill Atrophy
James Pain confesses that after a year or two of using AI exclusively for coding (no hand-written code), he has mostly forgotten how to code. He's now teaching himself to code by hand again, and warns that heavy AI use can erode writing and coding skills.