> ## Content Index
> Fetch the complete content index at: https://www.realaigovernance.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# The Silent Way AI Chatbots Leak Privileged Client Data
- URL: https://www.realaigovernance.com/the-silent-way-ai-chatbots-leak-privileged-client-data/
- Published: 2026-08-15T13:00:35.000Z
- Updated: 2026-08-15T13:00:35.000Z
- Description: The moment client facts go into that box, you may have already treated them as disclosed to a third party
- Author: Robert T. Boyer Ph.D.
- Tags: Fear Consequences, AI Governance, AI risk, AI Risk Management, Attorney Client Privilege, AI Policy, system trust, Vendor TOS

You didn't disclose anything to opposing counsel. Your chatbot's privacy policy just did.

On February 10, 2026, a federal judge in the Southern District of New York ruled that 31 documents created using a consumer AI tool weren't protected by attorney-client privilege or the work-product doctrine, not because anyone hacked anything, but because of two facts: no lawyer was part of the exchange, and the tool's own terms of service allowed the company to retain the inputs and disclose them to third parties, including government agencies. (United States v. Heppner.)

That's the part most lawyers miss. Privilege doesn't just require a confidential intent, it requires a confidential channel. A public AI tool, used the default way most of us use them, isn't one. The moment client facts go into that box, you may have already treated them as disclosed to a third party.

The ABA said as much in Formal Opinion 512: tools that train on what you feed them require informed client consent before any confidential information goes in and a line in your engagement letter doesn't count as informed consent.

This isn't settled law yet. One week before Heppner, a different federal court reached a different practical result on a different fact pattern. That inconsistency is exactly the problem, you can't count on drawing a sympathetic judge after the fact.

Here's what makes this risk different from a data breach: there's no hacker, no ransom note, no incident to detect. It's a decision that already happened, quietly, the moment someone hit enter. And once privilege is waived, it doesn't come back.

Before your next client call goes into any AI tool: do you actually know what that tool's privacy policy says about your inputs?