Two federal courts in the Southern District of New York have made something plain, and it's worth reading twice. Your clients' most sensitive communications, their defense strategy, their privileged disclosures, their legal thinking, may already be sitting in OpenAI's servers, subject to compelled production in litigation your firm has no part in, under a preservation order your firm didn't know existed and couldn't have stopped.
There's a particular silence that lands on a managing partner when a risk they didn't know about turns out to have been accumulating for months in their own attorneys' daily workflow. It's quieter than panic, and worse.
The Preservation Order That Changed Everything
Here's what happened. On May 13, 2025, U.S. Magistrate Judge Ona T. Wang issued a preservation order in In re: OpenAI, Inc. compelling OpenAI to preserve all output log data that would otherwise be deleted, whether at the request of users or under international privacy laws. (Hodder Law)
Let that land. User deletion requests, the thing your associates and partners think protects them when they clear a chat history, went legally meaningless overnight.
OpenAI's standard policy schedules deleted ChatGPT chat logs for permanent deletion within 30 days. Under the court order, even chats that are manually deleted by users are being maintained on OpenAI's servers rather than being automatically deleted. (Harris Beach Murtha) That covers ChatGPT Free, Plus, Pro and Team. ChatGPT Enterprise users got a narrow carve-out, which doesn't do a thing for you if your people aren't on it, and the attorneys and staff at most firms aren't on Enterprise. They're on whatever's convenient, whatever's fast, whatever gets the draft done before the deadline.
From Preservation to Production: 20 Million Logs
It didn't stop at preservation. It escalated straight into production.
News plaintiffs initially requested 120 million ChatGPT logs from the tens of billions of OpenAI logs that it has preserved. OpenAI countered with 20 million, arguing that was "surely more than enough." The plaintiffs agreed. Then OpenAI changed course in October 2025, proposing to run keyword searches and produce only conversations that implicated plaintiffs' specific works. Judge Wang sided with the news outlets, and denied reconsideration in December. (NatLawReview)
Courts treat AI chats as discoverable business records, not privileged communications like attorney-client conversations. There is no special AI privilege. (Terms) And there isn't one coming, because nobody's drafting it.
So: twenty million anonymized chat logs, pulled from tens of billions preserved under that May order, headed toward plaintiffs' experts for forensic analysis. The word carrying all the weight there is "anonymized." Courts considered it adequate protection, and I wouldn't bet a client relationship on it. Your clients may disagree rather vigorously once they understand what it means for their most sensitive disclosures to run through a de-identification process controlled by the company that holds the data, get reviewed by experts working for adverse parties, under a protective order that's already been tested, challenged, and still didn't stop production.
United States v. Heppner: AI Conversations Aren't Privileged
Then came United States v. Heppner, and the ground shifted again.
On February 10, 2026, Judge Jed S. Rakoff of the Southern District of New York addressed what he called "a question of first impression nationwide" and ruled that written exchanges between a criminal defendant and the generative AI platform Claude were not protected by attorney-client privilege or the work product doctrine. (Harvard Law Review)
The facts are worth getting precisely, because there's nothing exotic about them. They mirror what happens every day inside law firm walls. Bradley Heppner, charged with securities fraud, wire fraud, and falsification of records, had received a grand jury subpoena and retained counsel. Of his own volition and without attorney involvement, Heppner used Claude to prepare reports outlining his defense strategy and potential legal arguments, then shared those materials with his lawyers. (Chapman and Cutler LLP) His attorneys logged the documents as privileged. The government moved to compel. Judge Rakoff granted the motion from the bench. That's a man's own defense strategy, handed to the prosecution by the tool he'd used to write it down.
The government argued, and Judge Rakoff agreed, that sharing privileged communications with a third-party AI platform may constitute a waiver of the privilege over the original attorney-client communications themselves. (Jones Walker LLP)
The FBI seized the documents during a search of Heppner's home. A defense strategy, prepared in anticipation of indictment, prepared with the intent of handing it to counsel, became an exhibit for the prosecution. The structural version of that problem is the one I keep writing about. Heppner is what it looks like when it lands on an actual person.
The Shadow AI Problem Inside Your Firm
Heppner isn't just a story about a defendant making a bad technological choice, and I'd sit with the full shape of the risk before filing it that way.
Inputting confidential client information into public GenAI platforms may constitute disclosure to a third party, which can result in waiver of the attorney-client privilege, particularly if the information isn't adequately protected or the terms of service allow the provider to retain or use the data. Many GenAI tools store user inputs for model training or quality improvement, and without disabling those default settings or using paid and enterprise versions with stronger privacy protections, attorneys risk involuntarily exposing privileged content. (Frantz Ward LLP)
The ABA made it explicit in Formal Opinion 512, issued July 2024, its first formal guidance on generative AI in legal practice, which requires attorneys to protect client information as a foundational ethical obligation regardless of what tool they're using to do the work. The broader regulatory picture, from privilege waiver to discovery to data residency, runs through my compliance briefs.
According to the 2024 ABA Legal Technology Survey, AI adoption among lawyers has nearly tripled from 11% in 2023 to 30% in 2024, and many firms still lack the infrastructure to manage the associated risks. Shadow AI usage is rampant. Associates use ChatGPT on personal devices, partners experiment with AI writing tools, and paralegals might use online AI for quick spell-checks of confidential memos. (LeanLaw) An associate on a personal laptop. A partner trying out a writing tool. A paralegal running a spell-check. None of it's on anybody's risk register, and none of it's misconduct.
That last one deserves a beat. A paralegal spell-checking a confidential memo. The privileged text travels to OpenAI's servers. The memo lands in the preservation hold. A court orders production of twenty million logs. Nobody at the firm knew it was happening, least of all the paralegal, who was being careful.
The Terms of Service You Already Accepted
Anthropic's policy expressly states that user prompts and outputs may be disclosed to "governmental regulatory authorities" and used to train the AI model. OpenAI's privacy policy contains comparable provisions permitting data use for model training and disclosure in response to legal process. Both Anthropic and OpenAI use conversations from free and individual paid plans for model training by default. Users can opt out, and opting out of training doesn't eliminate the platforms' rights to disclose data to government authorities or in response to legal process. (Jones Walker LLP)
That's the contract your attorneys accepted when they made an account, clicked through the terms, and got to work. Nobody read it. Nobody ever does, and the platforms have priced that in.
OpenAI CEO Sam Altman warned that ChatGPT conversations are not legally protected and can be used as evidence in court, acknowledging that OpenAI is legally required to retain user chats, including deleted ones, due to the court order. (Kang Haggerty LLC)
Good on him for saying it out loud, and plenty of executives in his seat wouldn't have. He's called it a problem that needs addressing and described it as urgent, and the urgency is warranted. But an acknowledgment isn't a control. The architectural fix he's waiting on doesn't exist in cloud AI and it isn't going to, because the preservation obligation attaches to whoever's holding the data. It exists where the prompts never leave the building, the logs are yours alone to control, and no federal preservation order reaches data that was never transmitted to a third party in the first place.
What I Won't Tell You Until I've Watched You Work
Here's the part where a vendor hands you a rollout plan. I haven't got one, because I haven't met your firm.
I don't know what your new business intake and conflicts analyst does to resolve a corporate family tree of subsidiaries and DBAs against the conflicts database before a matter can even open. I don't know how your e-discovery PM handled the production that came back with redactions applied but never burned into the TIFFs. I don't know what your records and information governance manager is holding together across iManage and a decade of chron files, or how many times somebody's refiled because CM/ECF kicked a brief back over a PDF that wasn't text-searchable. Those people have run that work for fifteen or twenty years and it barely lives in the documentation.
So the sequence runs backwards from how this normally gets sold. I show up, sit down next to them, and shut up until I understand the work the way they run it instead of the way the SOP describes it. Discovery turns up the use cases already sitting in the building. Only then do I recommend a stack, and what I recommend is whatever the work turned out to need. Then we deploy and configure it together on site, and I onboard the firm on the workflows and the agentic orchestration a practice runs on.
You can't govern what you can't see, so the question for every managing partner reading this is simple and serious. Do you know what your attorneys typed into ChatGPT last week, and do you know where that text is living right now?
If that hasn't got a comfortable answer, it's worth a quiet conversation about moving inference in-house, and I'll come to you.