Skip to main content

Approximately one-third of adults report interacting with AI tools several times a day. Free AI tools are available through ChatGPT, Google AI mode, Claude, and many other resources. Your employees are using AI even if you have not adopted a paid AI service, or trained employees in safe and appropriate use of AI tools.

AI tools that are not specifically set to maintain confidentiality convert user prompts into information to understand, identify patterns and generate relevant outputs (“machine learning”). Thus, your questions are not secret. Moreover, the resulting information generated by the tool is also not secret. Even proprietary AI tools, systems that require paid subscriptions, may have default terms that do not keep information confidential to your account.

In February 2026, in United States v. Heppner , the U.S. District Court for the Southern District of New York held that any information put into an AI tool that shares data for machine learning, and the information output from such tools is not confidential, and therefore, the use of AI tools strips the confidentiality over the information by using that tool.

In that case, the business used the AI tool Claude to summarize information to provide to its attorney when gathering information for an ongoing lawsuit. When the computer was seized, the data history from that tool was used against the company and considered not privileged.

The Court focused on the fact that Claude’s own terms of service disclaim any attorney-client relationship and state that user inputs are not confidential. Note though, the input and output of this tool is not searchable by any third party, nor is it disbursed to the world. Instead, Claude simply shares the data with certain third parties for purposes of machine learning.

When a business seeks to protect its confidential information from use by third parties, it must show that it has taken reasonable measures to maintain its secrecy (limitation on who has access, contractual confidentiality agreements, employee training, etc.). When maintaining the attorney-client privilege, the effort to maintain secrecy is even higher. Attorneys are trained to understand the sanctity of the attorney-client privilege, and any good attorney will control communications with a client to ensure the privilege remains intact. However, when a client business works internally to assist in its own defense, the business could, as it did in Heppner , unknowingly and unintentionally lose the privilege.

This case provides a valuable wakeup call to businesses who seek to keep its confidential information secret. Employees routinely use AI tools to review information and provide assistance in performing their duties. Information put into the AI tool could include highly sensitive, confidential information such as financial information, customer information, marketing plans, and internal employee data, just to name a small section of confidential information. All employees must be trained in how AI tools work, what tools to use and not use, and what information to share with the tools. We suggest businesses have clear demarcations of when AI can be used, and when it is impermissible, such as in taking notes during highly confidential meetings.

If your business uses a proprietary tool like Copilot, ensure you review its terms and keep information from being shared with any third parties. When the tool is updated, the settings should be checked and set again as necessary. To be sure you did not miss a change, we also recommend routinely checking the terms quarterly, to ensure the settings remain confidential.


If you need assistance in addressing confidentiality concerns in the workplace, please contact us at Carle Mackie Power & Ross LLP. Arif Virji , Justin D. Hein , Samantha Pungprakearti , Sarah Hirschfield-Sussman

00
Carle, Mackie, Power & Ross, LLP
Carle, Mackie, Power & Ross, LLP