Signato signato.ai

Does putting client information into ChatGPT break attorney-client privilege?

A guide for lawyers and firm leaders. About 6 minutes.

The honest answer is: it can, and the more useful answer is that privilege is only half the question. There are two separate risks in the same act. One is whether your conversation with a public AI tool is itself privileged. The other is your professional duty of confidentiality, which binds you long before any court ever weighs in on privilege.

This page is a plain-English read of what the ABA's own ethics guidance actually says, what a 2026 federal ruling added, and what a firm can do about it. It is not legal advice, and it does not assume you have a general counsel down the hall.

The two questions people run together

Privilege and confidentiality are not the same duty, and conflating them is where a lot of the anxiety comes from.

You can satisfy neither, one, or both. A tool can leave your confidentiality duty intact while a court still finds no privilege, and you can breach confidentiality in a matter that never sees a courtroom at all. So "does ChatGPT break privilege" is the wrong first question. The first question is confidentiality, and the ABA has answered it directly.

What ABA Formal Opinion 512 actually says

On July 29, 2024, the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first comprehensive guidance on lawyers using generative AI. It is worth reading for what it does not say as much as for what it does. It does not ban these tools, and it does not tell you which product to buy. It maps the existing duties onto the new tool.

The opinion works through six areas: competence (Model Rule 1.1), confidentiality (Model Rule 1.6), communication with clients (Rule 1.4), meritorious claims and candor to the tribunal (Rules 3.1, 3.3), supervision (Rules 5.1 and 5.3), and reasonable fees (Rule 1.5). On the confidentiality question that drives most of the worry, three points stand out.

First, the duty is broad and it is yours. Under Model Rule 1.6, a lawyer using AI "must be cognizant of the duty ... to keep confidential all information relating to the representation of a client, regardless of its source, unless the client gives informed consent." Before inputting that information into an AI tool, the opinion says, lawyers "must evaluate the risks that the information will be disclosed to or accessed by others outside the firm," and also by others inside the firm who should not see it.

Second, self-learning tools trigger a consent requirement. This is the sentence that matters most for anyone typing a client's facts into a consumer chatbot. Because many of today's self-learning AI tools are designed so their output could lead to disclosure of information relating to a representation, the opinion concludes that "a client's informed consent is required prior to inputting information relating to the representation into such a GAI tool."

Third, the fine print in your engagement letter does not cover you. For that consent to count, it has to be genuinely informed: the client needs your best judgment on why the tool is used, the specific risk, and how others might use the information against their interests. The opinion is explicit that "merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient."

There is a narrower point in Opinion 512 that most summaries skip, and it is the one that turns out to be the crux. The committee flags that a self-learning tool can surface one client's information later, in response to another lawyer's prompt, and reveal it to someone "prohibited from access to said information because of an ethical wall." In other words, the risk is not only that data leaves the building. It is that the wrong person on the inside sees the wrong matter. Confidentiality here is a question of who, crossed with what.

What the 2026 SDNY ruling added on privilege

Confidentiality is the duty you owe now. Privilege is the protection you may be counting on later, and a federal court has now spoken to it.

In United States v. Heppner, Judge Rakoff of the Southern District of New York ruled, in an opinion issued February 17, 2026, that a defendant's written exchanges with a public generative AI platform were not protected by attorney-client privilege or the work-product doctrine. Two grounds drove it. The tool is not a lawyer, which alone defeats the privilege claim. And the communications were not confidential in the first place, because the platform's privacy policy told users it collects their inputs and outputs, uses them to train the model, and may disclose them to third parties, including the government. That disclosure, the reasoning goes, means there was never a reasonable expectation of confidentiality to protect.

The ruling went one step further, and this is the part that should give any lawyer pause: feeding privileged material from your client into a public tool can risk waiving privilege over the original attorney-client communications, not just the AI exchange. Sharing with a third party is sharing with a third party.

Two honest caveats, because the ground is still moving. The Heppner reasoning turned heavily on the public nature of the tool and its training-and-disclosure policy; commentators reading the opinion note that an enterprise or closed deployment, one that does not train on your inputs and restricts provider access, sits on different facts, though the opinion itself did not draw that line as a holding. And there appears to be an emerging split, with courts in the civil context reaching more protective results on work product. Treat Heppner as a strong signal about consumer tools, not as the last word for every deployment.

Where this actually leaves you

Put the two together and a clean rule falls out. The problem is not "AI." The problem is a specific input reaching a place it should not, and the two failure modes are the same two the ABA and the SDNY each described from their own angle:

Both are the same shape: a who crossed with a what, checked at the moment information is about to move. Notice what neither the opinion nor the ruling asks you to do. Neither says stop using these tools. Both say know where the information is going before it goes.

What to do with this

None of this is a reason to unplug. It is a reason to be able to show, on demand, that you controlled where client information went. A few practical steps, in plain terms:

  1. Separate the two questions in your own policy. Decide your confidentiality position (what may be entered, and into which tools) independently of any hope that a chat is privileged. Opinion 512 governs the first; do not let privilege assumptions do the work of a confidentiality rule.
  2. Prefer deployments that do not train on your inputs. A tool that does not learn from what you type, and does not reserve the right to disclose it, changes the risk analysis materially, both under Rule 1.6 and under the Heppner reasoning. Read the terms, or have someone who understands them read them.
  3. Get informed consent where the rules call for it, and make it real. If client information is going into a self-learning tool, boilerplate will not carry you. Explain the tool, the risk, and the reason, and keep the record that you did.
  4. Watch the wall, not just the door. Most controls check whether data leaves. The ethical-wall risk in Opinion 512 is about the wrong colleague seeing the wrong matter. Your safeguards should test the person against the subject, not only scan for sensitive content.
  5. Keep the evidence. The duty that survives every new ruling is being able to show what you allowed, what you blocked, and why. That record is your defense when someone asks the question after the fact.

That last point is where a lot of firms find the gap. Policies live in a memo; the actual moment of risk is a person about to send or paste something, in real time, with no check between the intent and the act. What the duties describe, and what a memo cannot enforce, is a determinate check at that moment: a layer that knows who may see which matter, crosses the two, and stops the forbidden pair before it moves, without the information itself leaving your machine to be checked. That is the shape of the problem Opinion 512 and Heppner both point at, from the confidentiality side and the privilege side.

That determinate, local check is what we built Signato to be. It holds your ethical walls as a live rule, verifies each outbound piece of information against who may see which matter, and blocks the forbidden pair before it leaves, with nothing sent to the cloud to run the check. If you want to see it against your own walls, the 30-day local trial runs entirely on your own machine, with only synthetic data, so you can test it without exposing a single real client fact.

This page is general information, not legal advice. Whether a specific tool, input, or client relationship meets your confidentiality obligations or preserves privilege is a fact-specific legal question, and it is exactly the kind of question where qualified counsel earns the fee. For how ABA Formal Opinion 512, your state's rules, or United States v. Heppner apply to your practice, consult a lawyer admitted in your jurisdiction.


Sources

Forward this to a partner or GC who has been asked "can we put this into ChatGPT?" and did not have a clean answer.

The practical next step is to see the check itself. The 30-day trial runs entirely on your own machine, with synthetic data only: you declare who cannot know what, and watch the chamber block the forbidden pair before anything leaves.

Start the free 30-day local trial

Prefer the shape of the offer first? Signato is priced by operation, not by seat.


This is educational material and a starting point, not legal advice. Whether a particular tool is covered, and which obligations apply to your organisation, depend on the facts of that tool and on the rules in force where you operate. For your situation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.

Signato · Minas Gerais, Brazil · hello@signato.ai