STOP. Do Not Paste Your Legal Documents Into ChatGPT or Claude
We get this question weekly. Your attorney sends back a marked up draft, full of comment balloons, and you want a second opinion. So you upload it to an AI chatbot and ask what it thinks.
Here is what you just did. ๐
๐ You probably waived the attorney client privilege over that document. The privilege protects a confidential relationship, not information. Take it outside the relationship and there is nothing left to protect. And the privilege belongs to you, so you can waive it on a Sunday night without your lawyer ever knowing.
โ๏ธ This is not theoretical anymore. In February 2026, Judge Rakoff of the Southern District of New York held that documents a defendant created by prompting a public AI assistant were protected by neither privilege nor work product. United States v. Heppner. His reasoning: a chatbot is not a licensed professional who owes you fiduciary duties, and the privacy policy lets the company retain your inputs, train on them, and hand them to regulators.
๐ Your chat log is discoverable. It is electronically stored information, same as email. Opposing counsel can request it from you or subpoena the provider. Deleting it does not help, and once a dispute is foreseeable, deleting it creates a spoliation problem on top of the waiver problem.
๐ฌ The prompt is usually worse than the document. "Is this indemnity really enforceable?" "What happens if I just stop paying?" Those are statements of a party opponent, written in the candid voice people use when they think nobody is listening. ๐ฌ
๐ And the redlined draft is the worst possible upload. Those comment balloons are your lawyer's unfiltered assessment of where you are weak and what you are prepared to give up. That is the whole negotiating file in one attachment. ๐
๐ค One more thing people miss: your NDA, your LOI, your loan documents. They restrict disclosure to representatives bound to confidentiality. A public chatbot is nobody's representative. The upload can be a straight breach of contract, privilege aside. ๐ฅ
So what should you do? โ
๐ข Use a business or enterprise account, never a personal one, and confirm training is off
๐งน Abstract the question. No names, no numbers, no addresses
๐ Or just call your lawyer. Counsel directed use is the fact pattern the court flagged as most likely to preserve protection
๐ Give your team a written policy. Most of the exposure I see comes from a junior employee with good intentions and zero instruction
I use these tools every day. ๐ They are genuinely useful. But the account tier, the terms, and whether your lawyer directed the use are what decide whether the tool costs you the protection you paid for. ๐
๐ฉ Questions about your own AI use, or want help writing a policy for your team? Reach us at team@kaliserlaw.com.
โ๏ธ General information, not legal advice. Talk to your own counsel about your own facts. ๐