AI tools have become part of the daily workflow for school administrators, board members, and staff, whether they are used to draft emails, organize information, or research questions that might otherwise go to a lawyer. However, a fast-moving line of court decisions is drawing a hard line: what you type into a public AI platform may not stay private. In the education context, where legal exposure touches everything from employment decisions to student discipline and everything in between, that risk matters more than most schools realize.
The Case Everyone in K-12 Should Know
In February 2026, a federal court in New York decided United States v. Heppner. After learning he was the target of a federal investigation, the defendant used Anthropic’s AI platform, Claude, to create dozens of documents outlining his defense strategy, potential legal arguments, and case analysis. He later shared those documents with his attorneys. When the government sought access to them, he argued they were protected by attorney-client privilege or the work product doctrine.
The court granted the government’s motion and ruled that the documents were protected by neither privilege: the AI was not an attorney, the communications were not confidential under Anthropic’s own privacy policy, and the documents were not prepared at counsel’s direction, amounting to three independent grounds, any one of which was sufficient to defeat the defendant’s claim.
Why Attorney-Client Privilege Did Not Apply
Attorney-client privilege has three requirements: the communication must be between a client and an attorney, it must be kept confidential, and it must be for the purpose of obtaining legal advice. The Heppner court found that AI conversations fail all three.
First, Claude is not a lawyer. No attorney-client relationship exists with an AI platform, and “the discussion of legal issues between two non-attorneys is not protected by attorney-client privilege.” United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026), slip op. at 5, quoting In re OpenAI, Inc., Copyright Infringement Litig., 802 F. Supp. 3d 688, 699 (S.D.N.Y. 2025).
Second, the communications were not confidential. Anthropic’s own privacy policy discloses that it collects user inputs and outputs, uses that data to train its models, and may share it with third parties, including government authorities. The court was direct: a user who agrees to those terms “could have had no reasonable expectation of confidentiality” in what they typed. United States v. Heppner, slip op. at 7, citing United States v. Mejia, 655 F.3d 126, 132–34 (2d Cir. 2011). The analysis applied specifically to the free, publicly available consumer version of Claude and not an enterprise or closed subscription variant, which can contractually prohibit providers from retaining inputs or using them for model training.
Third, the defendant was not acting at his attorney’s direction. He used Claude on his own initiative, and Claude itself tells users it cannot provide legal advice.
Perhaps most importantly for anyone thinking about sharing AI outputs with counsel after the fact: the court held that non-privileged communications do not become privileged simply by being handed to an attorney. Sharing your Claude output with a lawyer does not retroactively protect it.
Why Work Product Protection Did Not Apply
Work product protection shields materials prepared by or at the direction of counsel in anticipation of litigation. In Heppner, the defendant’s own counsel confirmed the defendant created the AI documents entirely on his own, not at counsel’s direction, and not reflecting counsel’s strategy. Because no attorney had any hand in creating the materials, the work product doctrine protection did not apply.
Other Court Decisions
Not every court has reached the same result as Heppner. In June 2026, the Business Court of Texas reached a different result in Tate Group Automotive LLC v. Legacy Automotive Capital LLC, finding that ChatGPT conversations created in anticipation of litigation were protected work product under Texas’s civil procedure rules, which extend protection to material prepared “by or for a party,” not just by or for an attorney. Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, Cause No. 25-BC11B-0020 (Tex. Bus. Ct. 11th Div. June 3, 2026), slip op. at 2–3, quoting Tex. R. Civ. P. 192.5(a)(1). That ruling, however, was a preliminary procedural order, not a binding written opinion, and the court still required the party to disclose exactly which case documents had been uploaded to the AI tool.
Two federal district courts reached similar conclusions in civil cases decided earlier in 2026. In Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026), the court held that a pro se plaintiff’s use of ChatGPT to assist with litigation preparation was protected work product, reasoning that disclosure to an AI tool is not disclosure to an adversary and does not waive the protection. The District of Colorado reached the same conclusion in Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026), distinguishing Heppner on two grounds: it was a criminal case, not a civil one, and the defendant acted entirely apart from his attorneys.
What none of these decisions resolve is a scenario increasingly common in organizational settings. When a non-lawyer employee uses an AI tool to summarize a confidential communication from outside counsel, it is not yet clear whether that act waives privilege. The analysis may turn on whether the employee used the same enterprise AI platform as the organization’s in-house counsel or a different consumer-grade tool, and whether it matters if those tools vary across business units. Courts have not yet addressed these questions directly, and clients should approach AI-assisted interaction with privileged legal communications with caution until they do.
Furthermore, the takeaway for schools is the same regardless of jurisdiction: whether AI-generated materials are protected depends on who directed the work, what platform was used, and what was shared. That is not a question to leave to chance.
What this Means for You
Although most schools do not often respond to federal criminal indictments, the privilege principles at stake apply just as directly to investigations, grievances, Office of Civil Rights complaints, employment disputes, and litigation that arise in the ordinary course of school operations.
For example, staff and administrators often use AI to document incidents. When a principal uses ChatGPT to draft a summary of a student discipline incident, or an HR coordinator uses an AI tool to organize notes from an employee investigation, those documents may be discoverable, and the underlying facts certainly are. If those summaries contain admissions, characterizations, or strategy, they could appear in litigation in ways the drafter may not have anticipated.
The Tate court specifically flagged the risk that confidential discovery materials or protected-order documents had been uploaded to ChatGPT. Schools dealing with active litigation or investigations should treat any AI platform’s data practices as a disclosure to a third party, which is exactly what the terms of service typically say it is.
The Heppner court noted that Claude itself disclaims providing legal advice. When school staff use these AI tools and others that disclaim providing legal advice to analyze whether a policy is legally compliant, draft a response to a complaint, or assess litigation exposure, they are not receiving legal advice. They are also not creating attorney-client privilege, no matter how legal the questions feel.
None of this necessarily means staff should stop using AI tools. It means they should use them thoughtfully and that legal counsel should be involved before AI-assisted work product ends up on a privilege log. Practically speaking:
- Involve counsel early. If a matter is heading toward litigation, a formal complaint, or a regulatory inquiry, get your attorney in the loop before staff begin using AI to document, analyze, or strategize. Materials created at counsel’s direction have a much stronger claim to protection.
- Do not upload sensitive documents to consumer AI platforms. Student records, personnel files, investigation notes, and any materials covered by a confidentiality agreement or protective order should not be processed through a public AI tool without explicit guidance from legal counsel.
- Treat AI outputs as potentially discoverable. For planning purposes, assume that anything your staff types into a public AI platform could end up in front of a judge. Draft accordingly.
- Review your AI use policies. If your district does not have a policy governing staff use of AI tools in connection with legal matters and sensitive information, now is the time to develop one in consultation with counsel.
The law in this area is moving fast. What courts have made clear is that AI’s novelty does not exempt its use from longstanding legal principles. The privilege belongs to the lawyer-client relationship, not to the technology, and keeping the privilege requires keeping lawyers involved.
The Education team at Husch Blackwell continues to closely monitor how courts are treating AI-generated materials and what those developments mean for schools and districts navigating legal risk. If you have questions about how these developments could impact your state, school, or district, please reach out to the authors or your Husch Blackwell attorney.
