
On February 10, 2026, in United States v. Heppner (No. 25-cr-00503-JSR, Southern District of New York), Judge Jed Rakoff held that roughly thirty-one documents a defendant prepared using the consumer version of a generative AI platform were not covered by attorney-client privilege (the confidentiality protection on lawyer-client communications) or the work-product doctrine (the protection on material prepared for litigation). The defendant had used a public AI chatbot to work on his own defense. The court’s reasoning reaches far beyond one criminal docket: putting information into a public AI platform is disclosure to a third party, and disclosure to a third party is how confidentiality dies.
It was not an isolated signal. In a separate matter, a federal court ordered roughly 20 million ChatGPT conversation logs produced to the plaintiffs in the consolidated copyright litigation against OpenAI, over the platform’s objections that production would invade its users’ privacy. Two different courtrooms, one consistent message: every prompt your team types into a rented AI service is a business record on someone else’s server, kept under someone else’s retention policy, reachable by someone else’s litigation.
The privilege analysis in Heppner turns on a doctrine every first-year law student learns: confidentiality protections survive only as long as the communication stays inside the protected circle. Hand a draft to an outside party with no duty of confidentiality and the protection is waived. The court treated the consumer AI platform as exactly that kind of outside party: its privacy policy gave the user no reasonable expectation of confidentiality, so material routed through it was shared with a stranger to the privilege. The work-product claim failed separately, because the documents were not prepared by or at the direction of counsel.
The holding was expressly tied to those facts: a public, non-enterprise platform, used without counsel’s direction. That is the door left open, and legal commentators analyzing the ruling have walked straight through it: tools that contractually or architecturally guarantee confidentiality can support a different analysis. On-premise AI is the strongest form of that guarantee, because the data never leaves the organization’s control and no third party ever holds it. Confidentiality by the system’s design, not by a vendor’s promise.
Privilege is the sharpest version of the issue, but the underlying logic applies to any confidential information: client lists, financials, personnel matters, unfiled patents, M&A discussions, source code. If it is confidential, and your team pastes it into a public AI prompt box, you have shared it with a third party whose logs are discoverable and whose retention policy you do not control. The 20-million-logs production order makes that concrete: the logs existed, so they were produced.
A private AI server dissolves the third-party problem instead of papering over it. The model runs inside your walls. Prompts, drafts, and outputs never cross the internet. The only logs are on your hardware, under your retention policy, inside your discovery perimeter, exactly like the rest of your files.
What that looks like in practice on an eRacks system:
One necessary caveat: we build architecture, not legal opinions. Whether and how the Heppner analysis applies to your practice is a question for your counsel. What we can say is that the technical side of the answer is now the easy part.
The full breakdown for legal practices, including the ruling timeline and an architecture comparison, is at eracks.com/law-firm-ai-server. For everyone else wondering what it would take to bring confidential AI work inside the building: tell us what your team runs through AI today, and we will tell you straight which box does it, or whether you need one at all.
joe July 28th, 2026
Posted In: AI Servers, News
Tags: AI confidentiality, AI provisioning, AILSA, air-gapped AI, attorney-client privilege, ChatGPT logs, law firm AI, legal AI server, on-premise AI, private AI, US v Heppner, work product