The Expectation Gap · Part 2 of 8

You can't give it your stuff. A federal court just proved why.

You can't give it your stuff. A federal court just proved why.

In Part 1 I said the reason almost nobody uses AI deeply isn't that the tools are bad — it's that two walls go up the moment the work gets real. This post is about the wall that matters most if you carry a duty of confidentiality: "I can't give it my stuff."

Most people treat that as a vibe. A queasy feeling about pasting a client's file into a chat box. As of February, it's not a vibe. It's case law.

United States v. Heppner (S.D.N.Y., Feb. 17, 2026, Rakoff, J.). The defendant had used a consumer AI assistant — Claude — as a kind of sounding board. The government got those exchanges. He argued they were privileged. Judge Rakoff said no, and the reasoning is the part every professional should read twice:

  1. Claude isn't an attorney. Attorney-client privilege protects communications between a client and a lawyer. A chatbot is not a lawyer, so the exchanges never qualified in the first place.
  2. There was no confidentiality. He typed into a third-party platform, and he'd agreed to a privacy policy that permits the vendor to collect his inputs and outputs and, in some circumstances, disclose them. That eliminates any reasonable expectation of confidentiality — the thing privilege is built on.
  3. He wasn't actually seeking legal advice from it. The tool itself disclaims giving legal advice, so the court found it implausible he was getting counsel from the machine.

Sit with number two. The thing that voided the protection was the architecture — a vendor in the middle, holding the data, under terms that let them keep and disclose it. Not misuse. Not a leak. The normal, intended, everyday way the product works.

Now here's the uncomfortable part for our professions. Ninety-six percent of legal professionals say they require confidentiality safeguards before using AI (Thomson Reuters, 2026). And yet 47–48% of small firms are using consumer-grade ChatGPT or Copilot anyway (Clio, 2026). Across all knowledge workers, 48% admit they've pasted sensitive company data into public AI tools (KPMG, 2025). The gap between what we say we require and what we actually do is enormous — and Heppner is the first published example of that gap turning into a courtroom problem.

96% of legal professionals require confidentiality safeguards; 47 to 48% of small firms use consumer ChatGPT anyway

It's not just a legal-privilege issue. If you're a physician, a therapist, a dentist, an accountant, the shape is identical: the material you most want help with is exactly the material you're not permitted to hand to a third party. And the HIPAA business-associate agreements that would let you do it safely? They exist only on the enterprise and healthcare tiers of these tools — not on the $20 consumer plans that most solo and small practices actually use. So people either don't use AI on the real work, or they use it and quietly hope nobody asks how.

Here's the thing I keep coming back to as a lawyer who builds this stuff: you cannot policy your way out of an architecture problem. You can write a beautiful AI-use policy. You can train everyone. But as long as the tool's design requires the confidential material to travel to someone else's servers under someone else's terms, the risk Heppner describes is baked in. The vendor is a third party in the privilege analysis because the vendor is, in fact, a third party.

So flip the architecture. If the model runs on a box that the firm owns, sitting in the firm's office, and the client's words never leave that box — there's no third party in the data path. Nobody else is collecting the inputs. Nobody else has terms that reserve a right to disclose. The specific facts Rakoff pointed to simply aren't present.

I want to be honest about the edge of this, because overselling it would be its own kind of malpractice: no court has yet ruled on privilege for an on-premise, self-hosted model. Heppner was about a consumer cloud tool, and courts are expected to distinguish consumer tools from enterprise and self-hosted ones (the New York State Bar has already flagged that distinction). I can't promise you a holding that doesn't exist yet. What I can tell you is that an owned box directly answers the three things the court actually cared about — no non-lawyer third party holding the data, no policy authorizing disclosure, a real expectation of confidentiality — in a way that a consumer chatbot structurally cannot.

That's the whole pitch, and it's a narrow, defensible one: the confidential work belongs on hardware you control. Not because local AI is smarter. Because the data never has to leave the room.

Next up, Part 3: the other reason to own the box instead of renting the cloud — a receipt-by-receipt look at how often these vendors have changed the terms after you built your practice around them.

If you've got an AI-use policy but you're honestly not sure what your people paste into ChatGPT on a Friday afternoon — that's the wall. Heppner is what's on the other side of it.

— Banksy AI

Practical AI, done for you. Runs on your hardware. Your data never leaves.

(Nothing here is legal advice; I'm a lawyer, but not your lawyer. Heppner is a real S.D.N.Y. opinion — read it before you cite it.)


Confidential AI that never leaves your office

The Banksy Box runs on hardware you own. Your clients' data never goes to anyone's cloud.

See the Banksy Box Talk to us
← Part 1 Part 3 → ↑ All 8 parts — The Expectation Gap