Today, the use of generative artificial intelligence in professional settings, while offering new opportunities for analysis and operational support, raises significant concerns regarding the protection of confidentiality guarantees.
On this point, the recent ruling by the United States District Court for the Southern District of New York in the case United States v. Heppner of February 17, 2026, is of particular interest, addressing the issue of protecting conversations between a user and a generative AI platform.
In the case at hand, the Court held that documents containing exchanges between a person involved in a criminal investigation and Claude AI, prepared independently by the defendant in preparation for their defense, were not covered by professional secrecy (the so-called attorney-client privilege) nor by the protection of legal work product (the so-called work-product doctrine), even though such materials had been created for the purpose of preparing their defense and subsequently shared with their attorneys.
In particular, the Court clarified that:
- conversation with an AI platform does not equate to communication with an attorney: the tool is not a professional, is not subject to ethical obligations, and does not establish with the user any fiduciary relationship comparable to that between client and counsel;
- confidentiality cannot be presumed when the user enters information into a third-party platform, especially where the terms of use allow the provider to access, store, use, or communicate the data under certain circumstances;
- subsequent transmission to an attorney of documents already created through AI does not automatically render confidential that which, at the time of creation, was not;
- entering information received from counsel into the platform may entail the risk of waiver (the so-called waiver) of the protection originally afforded to such information.
While not binding on our legal system, the New York Court’s decision is of absolute relevance. U.S. case law often addresses the impact of new technologies in advance, and this ruling anticipates crucial issues destined to guide the European and Italian debate as well. The underlying principle, in fact, is universal: sharing confidential information with a consumer-grade AI is equivalent to transferring it to a third party, unbound by the strict constraints of professional secrecy.
It should be noted that in our legal system, the relationship between client and attorney is governed by specific and rigorous rules. Professional secrecy is protected, among other provisions, by Article 200 of the Code of Criminal Procedure, Article 622 of the Criminal Code, and Article 28 of the Code of Forensic Ethics, which requires attorneys to maintain secrecy and the utmost discretion regarding information learned in the course of professional activity.
Conversely, the independent use of a publicly accessible AI platform does not, in itself, offer guarantees comparable to those inherent in the professional relationship with an attorney, especially when the relevant terms of use allow the provider to access, store, use, or communicate data entered by the user. Even if the interface may appear to be a closed and private environment, sharing information subject to legal protection may entail a risk of compromising its confidentiality.

