Skip to content
Back to Insights

After Heppner: Why Your Law Firm's AI Strategy Just Became a Privilege Liability

Mike O'Brien10 min read

If you're a managing partner or firm administrator who approved a ChatGPT Enterprise subscription for your attorneys last year, you need to read this carefully. The ground shifted, and most firms haven't noticed yet.

Heppner v. Raggio & Raggio didn't make headlines outside the legal tech community. It should have. The ruling established a principle that has implications for every law firm using cloud-based AI tools: an attorney's choice of AI technology is a matter of professional competence under ABA Model Rule 1.1, and failure to understand how that technology handles client data can constitute a breach of the duty of competence.

This isn't about whether AI is useful for legal work. It is — we've written about the real-world workflows for AI document review and the results speak for themselves. The question is whether your firm's AI infrastructure creates an unacceptable risk to attorney-client privilege. For most firms using cloud AI, the honest answer is: probably.

What Heppner Actually Established

The Heppner v. Raggio & Raggio case centered on an attorney's use of AI tools to process client materials without adequate understanding of the tool's data handling practices. The court's reasoning extended the duty of competence — which already required lawyers to understand the technology they use in practice — to encompass AI-specific considerations: Where does the data go? Who has access to it? Is it retained? Could it be used to train future models?

The ruling aligned with a broader trajectory in legal ethics. ABA Model Rule 1.1, Comment 8, already required lawyers to "keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology." Heppner made explicit what was implicit: AI tools are "relevant technology," and understanding their data architecture is part of competence.

This matters because it transforms AI tool selection from an IT decision into a professional responsibility decision. The managing partner who approved the cloud AI subscription is now potentially on the hook if that tool's data handling practices create a privilege issue.

The Privilege Problem, Spelled Out

Attorney-client privilege is fragile. It requires that communications between attorney and client remain confidential. The moment a privileged communication is disclosed to a third party — voluntarily or not — the privilege can be waived.

Here's what happens when an attorney sends a privileged document through a cloud AI API for review, summarization, or analysis:

  1. The document is transmitted from the firm's network to the AI provider's infrastructure.
  2. The AI provider decrypts and processes the document on shared compute infrastructure.
  3. The document content — or representations of it — may be logged, cached, or temporarily stored by the provider.
  4. Depending on the provider's terms of service, the content may be accessible to the provider's employees for safety review, abuse monitoring, or model improvement.

Each of these steps introduces a third party into the communication chain. The AI provider's engineers who can access logged requests. The cloud infrastructure provider hosting the AI service. Any subprocessors involved in the data pipeline.

The traditional test for privilege waiver asks whether the client took reasonable steps to maintain confidentiality. "We sent it to a third-party AI company's servers where it was processed on shared infrastructure" is not a strong answer to that question.

To be clear: no court has yet ruled that cloud AI processing per se constitutes a privilege waiver. But the risk framework is established, and Heppner signals that courts will scrutinize AI data practices with increasing rigor. Waiting for a definitive ruling is not a risk management strategy — it's a gamble with your clients' privilege.

ABA Formal Opinion 512 and Rule 1.6

ABA Formal Opinion 512 (2024) addressed AI use in legal practice directly. The opinion emphasized several obligations that are relevant here:

Competence (Rule 1.1). Lawyers must understand the AI tools they use, including how those tools process, store, and potentially share client data. "I didn't know the AI provider retained our data" is not a defense.

Confidentiality (Rule 1.6). Lawyers must make reasonable efforts to prevent the inadvertent or unauthorized disclosure of client information. When client data is sent to a cloud AI provider, the lawyer must understand and evaluate the provider's data handling practices. Rule 1.6(c) requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."

Supervision (Rules 5.1, 5.3). Partners and supervising attorneys have an obligation to ensure that subordinate lawyers and nonlawyer assistants use AI tools in compliance with the Rules of Professional Conduct. If a junior associate sends privileged documents through an unapproved AI tool, the supervising partner may share responsibility.

The opinion stopped short of prohibiting cloud AI for privileged work. But it established a due diligence framework that's difficult to satisfy when the data processing occurs on infrastructure the firm doesn't control.

State Bars Are Moving

The ABA opinion isn't the only guidance firms need to track. Multiple state bars have issued AI-specific guidance, and the trend is toward more scrutiny, not less.

California (Practical Guidance for the Use of Generative AI in the Practice of Law, 2024) requires lawyers to understand AI data handling, evaluate confidentiality risks before using AI tools with client data, and inform clients about AI use when appropriate.

New York (NYSBA Task Force on AI, 2024) emphasizes that attorneys must exercise independent judgment when using AI, verify AI outputs, and ensure that AI use complies with confidentiality obligations.

Florida (Proposed Advisory Opinion 24-1) addresses AI use in the context of competence and confidentiality, with particular attention to the risk of inadvertent disclosure through AI platforms.

The common thread: every state bar that has addressed the issue has emphasized that sending client data to AI providers requires due diligence that most firms aren't performing. And the burden of proof is on the firm to demonstrate that their AI practices protect client confidentiality.

The Gray Area Your Firm Is Operating In

Let's be direct about what's happening in practice.

Associates are using ChatGPT to summarize deposition transcripts. Partners are pasting contract sections into Claude to identify risk provisions. Paralegals are running privileged document sets through AI-powered review platforms. In many cases, the firm has an enterprise license with data processing agreements in place.

But here's the question that Heppner forces you to confront: does the existence of a data processing agreement eliminate the privilege risk, or does it merely document the disclosure?

A DPA establishes a contractual relationship with the AI provider. It may include provisions for data deletion, use restrictions, and security obligations. But from a privilege analysis perspective, the data was still transmitted to and processed by a third party. The DPA doesn't make the third party disappear — it just governs how the third party handles the data.

The conservative position — and the one that malpractice insurers are increasingly interested in — is that privileged data should never leave the firm's control. Not because cloud providers are untrustworthy, but because the privilege analysis is cleaner when no third-party transmission occurs.

The Air-Gapped Solution for Legal

The technical solution is the same one that solves CMMC compliance for defense contractors: on-premise AI inference where data never leaves the firm's network.

Here's what this looks like in practice:

  • Hardware: NVIDIA DGX Spark or RTX Pro 6000 workstations deployed in the firm's server room or a secured closet. These systems run production-grade language models locally.
  • Models: Open-weight models (Llama, Qwen, DeepSeek, Mistral) running through Ollama. Different models for different tasks — a larger model for complex legal analysis, a faster model for routine summarization and screening.
  • Network isolation: The AI inference system operates on the firm's internal network with no outbound internet connectivity. Privileged documents are processed entirely within the firm's physical and network boundary.
  • Access controls: Role-based access matching the firm's existing document management permissions. Partners access partner-level work product. Associates access what they're cleared for. No different from how you manage your DMS today.

The privilege story becomes airtight: "Privileged documents were processed by AI systems running on hardware owned by the firm, located in our offices, connected to our internal network, with no third-party data transmission of any kind." No DPA required. No third-party risk analysis. No privilege waiver argument.

PropelAI's Translation Matrix

This is what we call the Translation Matrix in our Automated Sales Engineer architecture. The underlying technical capability — on-premise inference on air-gapped hardware — is identical whether we're deploying for a defense contractor or a law firm. But the value proposition is completely different.

For GovCon, the value is CMMC compliance without cloud AI liability. The technical feature maps to audit readiness, CUI protection, and NIST SP 800-171 controls.

For Legal, the same technical feature maps to privilege protection, Rule 1.6 compliance, and malpractice risk reduction. Same hardware. Same models. Same deployment architecture. Different language, different buyer, different urgency.

This is why vertical specialization matters in AI operations. A generic AI vendor will sell you a chatbot. A vertical operator translates the same capability into the specific risk framework your industry cares about.

The Malpractice Insurance Dimension

Here's a development that should get every managing partner's attention: malpractice carriers are starting to ask about AI.

Renewal questionnaires are adding questions about AI tool usage, data handling practices, and governance policies. Carriers want to know whether your firm has an AI use policy, whether attorneys are trained on AI risks, and — increasingly — whether client data is being processed through third-party AI services.

Firms that can demonstrate air-gapped AI processing have a materially stronger position in these conversations. "We process all client data on hardware we own, in our offices, with no third-party data transmission" is a sentence that underwriters like. "We have enterprise agreements with three AI providers and our attorneys use them at their discretion" is a sentence that triggers follow-up questions and potential premium adjustments.

The insurance math isn't hypothetical. A single privilege waiver finding on a significant matter can generate malpractice exposure that dwarfs the cost of on-premise AI infrastructure by orders of magnitude. A DGX Spark lease costs less per month than a single hour of partner time defending a privilege waiver motion.

What to Do Now

If your firm is using cloud AI tools for any work involving privileged documents, you have three immediate action items:

  1. Audit your AI usage. Find out what tools your attorneys are actually using, not just what's approved. Shadow AI is rampant in law firms. Associates are using personal ChatGPT accounts on firm matters. You can't govern what you can't see.

  2. Classify your workflows by privilege sensitivity. General legal research and public document analysis can stay on cloud AI. Anything touching privileged communications, work product, or confidential client data needs a different infrastructure path.

  3. Evaluate on-premise alternatives. The hardware exists. The models are capable. The deployment is straightforward. The question isn't technical feasibility — it's whether your firm treats privilege protection as a technology infrastructure decision or continues treating it as a terms-of-service negotiation.

Heppner drew a line. ABA Formal Opinion 512 drew it darker. The state bars are filling in the details. The direction is clear: firms that handle privileged data with AI must demonstrate competence in how that AI processes the data. On-premise inference is the most defensible answer the technology currently offers.


Read the full Automated Sales Engineer case study to see how PropelAI's Translation Matrix maps technical capabilities to legal-specific value → The Automated Sales Engineer

See what AI operations looks like for your firm → Get Your AI Opportunity Brief


You might also like

All Insights