If you have typed the details of a dispute into an AI chatbot, you probably assumed that conversation was yours. Three US federal courts looked at that assumption in early 2026 and reached three different answers. In one case prosecutors were allowed to read the chats. In two others, the person’s queries were protected. The difference was not the technology.
None of this is legal advice, and I am not a lawyer. But you do not need to be one to take the practical lesson, which is simpler than the case law: what you type to a general chatbot is not automatically private, and you get to decide what goes into it.
What the three courts decided
The one that got attention was United States v. Heppner, decided in the Southern District of New York on 17 February 2026 by Judge Jed Rakoff. A criminal defendant who had his own lawyer used a consumer AI assistant on his own initiative to work through material about his case. The court held that none of it was protected.
The reasoning had four parts. The assistant is not an attorney. Its privacy policy permitted the company to share what he typed with third parties, so he had no reasonable expectation of confidentiality. He had not used it at his lawyer’s direction. And the outputs did not reflect his counsel’s strategy, so they were not work product either. Prosecutors got to use them.
A week earlier, a magistrate judge in the Eastern District of Michigan had gone the other way. In Warner v. Gilbarco, decided 10 February 2026, the plaintiff had no lawyer. The court held that her queries and the answers she received were her work product, on the reasoning that these systems are tools rather than people, so using one is not the same as telling a stranger about your case.
Then on 30 March 2026 the District of Colorado sided with Warner. In Morgan v. V2X Inc. the court held that work product protection covers material a self-represented litigant prepares, and set Heppner aside as a criminal case governed by different rules. It attached a condition, though: she had to disclose which AI tool she had used.
What actually separates them
Read together, a few things seem to matter. Whether the case is civil or criminal. Whether you have a lawyer, and whether you were acting on their instructions. And, in Heppner at least, what the product’s own privacy policy says the company may do with what you type.
That last factor is the one most people never check, and it is the one you have the most control over. A court asked whether the defendant could reasonably have expected privacy, then read the terms he had agreed to and concluded that he could not.
I would not read any of this as settled. Three decisions in seven weeks, pointing in two directions, is the early stage of a question, not the end of one. If someone tells you confidently that AI chats are private, or that they definitely are not, they are ahead of the law.
There is a second risk, and it bites harder
Privacy is not the only way AI goes wrong in a legal matter. The bigger everyday problem is that these systems invent case names, quotes and citations that sound completely ordinary and do not exist.
Courts have been dealing with this for two years now, and the trackers that follow these cases show most of them involve people representing themselves. That makes sense. A self-represented person has no colleague to check the citation with, and no instinct that the case name looks slightly off.
Florida decided to do something about it. Rule 2.515(d)(2), effective 15 June 2026, requires whoever signs a filing to represent that the legal authorities identified exist and are accurately cited. It applies to attorneys and to self-represented litigants equally, and the court can respond to a filing inconsistent with that representation with a reprimand, contempt, striking the document, dismissal, costs or fees.
Notice what the rule does not do. It does not ban AI, and it does not ask you to disclose that you used it. It asks you to stand behind your citations, which was always the deal. The rule just says it out loud now because enough people forgot.
How to use AI for legal guidance without handing over your case
Here is the sorting question I would use, and it takes two seconds. Am I asking how something works, or am I telling it what happened to me?
General questions are fine. What a notice period usually means, how small claims works, the difference between two forms you have been handed, what a clause is trying to do. You are learning vocabulary so that the next conversation goes better, and none of it is evidence about you.
Your own facts are a different thing. Names, dates, amounts, the employer, what you said in the argument, what you signed. That material belongs with somebody who owes you a duty of confidence. A general chatbot owes you nothing of the kind, and as the three rulings show, whether the transcript stays yours is currently a coin toss that depends on a court you have not met yet.
If you are going to use AI anyway, and most people will, three habits cover most of the risk. Strip the identifying details before you paste anything. Keep a note of which tool you used and when, because a court may ask, as Colorado did. And check every case name and every quote against a real source before it goes anywhere near a filing.
Where a free AI assistant still earns its place
I do not want this to read as an argument against using AI for legal guidance, because it is not. Most people who need legal help do not have a lawyer and are not about to hire one for a question about a tenancy notice. Telling them to stay off AI is telling them to stay confused.
The useful role is the first twenty minutes. Working out what kind of problem you have, what the words mean, what questions to bring to a person. That is genuinely valuable and it costs nothing, which is why Roshni’s free AI assistant exists and why it is deliberately separate from the conversations you have with a professional.
What it is not is a stand-in for a consultation. The design point we keep coming back to, on the mental health side as much as the legal one, is that an assistant should know when to hand you over. A tool that will happily draft your court filing is not being helpful, it is being agreeable.
When you do move to a person, that conversation sits under a professional duty of confidence rather than a product’s privacy policy. That is the whole difference, and it is worth understanding before you decide where to type the hard part.
FAQ
Are my ChatGPT or AI assistant chats protected by attorney-client privilege?
Not on their own. Privilege attaches to communications with a lawyer for the purpose of getting legal advice. An AI assistant is not a lawyer, which is exactly what the court said in Heppner. Two other courts protected a self-represented person’s chats under the separate work product doctrine, which is a different and narrower thing.
Does it matter whether I have a lawyer?
It seems to. Both of the rulings that protected the chats involved self-represented litigants in civil cases. The ruling that did not involved a defendant who had counsel and used the tool without their direction. If you have a lawyer, ask them before you put case material into any AI tool.
Can I be sanctioned for using AI in a court filing?
You can be sanctioned for citing authorities that do not exist, whether AI produced them or not. Florida’s Rule 2.515(d)(2) makes that explicit from 15 June 2026 and applies it to self-represented litigants as well as lawyers. Check every citation yourself before you file.
Will I have to say I used AI?
It depends where you are. Florida’s rule asks you to certify your authorities are real, not to disclose the tool. The Colorado court did require the litigant to identify which AI tool she had used. Keeping a simple record of tool and date costs you nothing and answers the question if it comes.
What should I never put into a general chatbot?
Anything you would not want the other side reading. Full names, addresses, account numbers, the text of an agreement, medical details, and your own account of events. Ask the general version of your question instead, then take the specifics to a person.
Is Roshni’s AI assistant different?
It runs on our own infrastructure rather than a third party API, and the assistant conversation is kept separate from your consultations with a professional. That said, the honest answer to “is this privileged” is still no, because an assistant is not a lawyer anywhere. Use it to get oriented, then book the consultation for your facts.
If you have a legal question you have been circling for weeks, start a free chat to get your bearings, then talk to a verified professional about the part that is actually yours.


Recent Comments