Co-author of the Utah Bar Journal article: Jonathan Bench | Enhanced Legal
See full article in Utah Bar Journal (submitted March 30, 2026, published September 1, 2026)
A federal judge in New York just handed every attorney in the country a wake-up call, and most of them haven’t heard it yet.

In United States v. Heppner, decided February 10, 2026, Judge Jed Rakoff of the Southern District of New York ruled that 31 documents a criminal defendant generated using Anthropic’s Claude were protected by neither attorney-client privilege nor the work product doctrine. The case made national legal headlines, and drew immediate attention from the Harvard Law Review. But the headline missed the most important part.
The documents weren’t unprotected because of something the attorney did wrong with AI.
They were unprotected because the attorney never said anything about AI at all.
Why did a federal judge rule that a client’s AI chats weren’t privileged?
Because the client used Claude entirely on his own, and nobody at his law firm had said a word to him about AI. Bradley Heppner used a consumer version of Claude to research his own defense after receiving a grand jury subpoena. His attorneys at Quinn Emanuel never told him not to. They never told him which platforms were acceptable. They never issued any directive about AI use in connection with the representation.
When the FBI seized Heppner’s devices and found the AI-generated documents, his defense counsel asserted privilege. Judge Rakoff found no basis for it.
Two things defeated the privilege claim. First, Anthropic’s standard privacy policy authorized voluntary disclosure of user data in civil litigation, no subpoena required. Second, because Heppner used the tool entirely on his own initiative, without any attorney direction, the Kovel doctrine, which can extend privilege to non-attorney agents acting under counsel’s direction, was simply not available. There was no direction to point to.
The lesson isn’t that AI destroys privilege. It’s that unaddressed AI use does.
Are clients in Utah already doing this?
Yes, and most of them don’t know it matters. A Kolmogorov Law survey of 1,000 U.S. adults who use AI chatbots (October 2025) found that 56 percent had already asked a chatbot for legal advice, and half didn’t know those conversations could be subpoenaed. A separate Rev.com survey of 1,002 American adults (December 2025) put the share who have turned to an AI chatbot for legal help at 65 percent. They are not doing this to circumvent their attorneys. They are doing it because no one told them the rules.
Heppner arose in a criminal proceeding in New York. But the underlying fact pattern, a client who turns to a consumer AI platform because their attorney never told them not to, has no jurisdiction. It is playing out in Utah matters right now, across every practice area, before any Utah court has weighed in.
This is, in most cases, an attorney communication problem. And it is one attorneys can solve.
What should attorneys do now?
Three things, all of them paperwork: a written client AI directive, a vendor agreement that removes voluntary disclosure, and documented attorney direction whenever AI use is authorized.
The good news is that Heppner is not a story about a technological problem that requires a technological solution. It is a story about a documentation gap that requires a documentation solution.
The core requirements are straightforward:
A written client AI directive. Every client, in every matter involving potentially privileged communications, should receive clear written guidance on whether and how they may use AI tools in connection with the representation. This belongs in the engagement letter, not as a buried paragraph, but as a clear directive the client will actually read and understand. ABA Opinion 512 requires informed consent before submitting client information to a self-learning AI tool. A written engagement letter provision is the right place to capture that consent.
A vendor agreement that holds up. The specific language that defeated privilege in Heppner was Anthropic’s reservation of the right to voluntarily disclose user data “to third parties in connection with claims, disputes or litigation.” Substantively identical language appeared in the standard terms of every major AI platform at the time of Heppner, with the notable exception of Grok. Anthropic narrowed its clause in the policy effective July 8, 2026, and a revised policy is no help to anyone whose data flowed under the old one. Upgrading to a paid tier does not remove it. Opting out of model training does not remove it. Only a negotiated enterprise agreement that specifically eliminates voluntary-disclosure authority closes this gap, and the version of the terms in force for your matter is the one that counts.
Documented attorney direction. When AI use is authorized, the authorization needs to specify the approved tool, the permitted purpose, and the basis for the direction. This is what the Kovel doctrine requires, and what its absence cost Heppner.
Why did two federal courts reach opposite results in the same week?
Because the facts differed on the two things that decide these cases: whether the vendor’s terms allowed voluntary disclosure, and whether the AI was used as a tool under direction or on the client’s own initiative.
The same day Heppner was decided, Magistrate Judge Anthony P. Patti of the Eastern District of Michigan reached the opposite conclusion in Warner v. Gilbarco, Inc. A pro se plaintiff’s use of ChatGPT to prepare litigation materials was protected as work product. The court treated AI as a tool, not a third party, and found no waiver.
Together, the two decisions establish that outcomes in AI privilege cases will turn on facts attorneys can control: what the vendor agreement says, whether attorney direction was documented, and what the client was, or wasn’t, told.
Courts are dividing on the analysis. The attorneys whose clients will fare best in that environment are the ones who addressed these questions before a dispute arose.
Can a directive and a good contract fully close the gap?
No. Even a fully ethics-compliant attorney with a negotiated enterprise agreement is relying on a vendor promise with no statutory backstop behind it.
There is a larger problem underneath the Heppner fact pattern that a written directive and a better vendor agreement cannot fully solve. AI vendors are not bound by the ethics rules that bind attorneys. They are not bound by the ABA opinions that require vendor due diligence. A fully ethics-compliant attorney using a fully negotiated enterprise agreement is still dependent on that vendor’s contractual commitment. It’s a commitment with no statutory backstop if it fails.
We argue in our Utah Bar Journal article that the right structural solution is a Legal Services Associate Agreement modeled on HIPAA’s Business Associate Agreement framework, a statutory instrument that would bind AI vendors to legal-professional confidentiality standards the way HIPAA binds healthcare vendors. That solution will take time to build.
In the meantime, the five steps every Utah attorney should take now, and the specific contractual language to look for in every AI vendor agreement, are the subject of that article.
What is the one thing to take away?
Silence. Heppner is not a cautionary tale about AI; it is a cautionary tale about an attorney who never addressed it.
Every client file that opens without a written AI directive is a Heppner opinion waiting to happen. The conversation is easy to have. The directive is easy to write. The window to have it, which is before the client makes their own choice, is the only thing that closes.
Kimberly R. Harris, PhD is the founder of Quantum Quill Digital, where she advises legal professionals on AI governance, data security, and the intersection of emerging technology and professional responsibility. Her article with co-author, Jonathan Bench, on client AI use and attorney obligations under RPC 1.6 is in the Utah Bar Journal, Vol. 39, No. 5.
Questions about Entity Engineering and/or AI governance for your practice? Contact us at Quantum Quill Digital.
