Members of a local Texas defense bar discussed the practicalities of using AI to assist in workplace investigations. I can understand the attraction because an HR specialist or an employment lawyer can submit investigation records and statements into AI to generate questions for witness interviews and to issue spots.
I began thinking about something they weren’t focused on: “what happens when an employer’s AI use becomes discoverable in litigation?”
The defense panel’s answer was straightforward and, for their purposes, comforting: if you stay within your law firm’s closed AI system, using generative AI to brainstorm interview questions for witness interviews is probably fine. No privilege waiver, no work product exposure.
But here’s what they didn’t dwell on, and what every plaintiff and plaintiff’s lawyer should be asking about: what happens when the investigation is led by HR, not counsel?
The Privilege Waiver Problem: Why Cloud-Based LLMs Change Everything
The legal landscape on AI and privilege shifted dramatically in early 2026. In United States v. Heppner, Case No. 1:24-cr-00410 (S.D.N.Y. Jan. 30, 2026), a federal court in the Southern District of New York held that a defendant’s communications with the public AI platform Claude were not protected by attorney-client privilege or the work product doctrine. The court’s reasoning was devastating for anyone who has casually used a chatbot for legal strategy:
1. No attorney-client relationship with software. The court emphasized that privilege requires “a trusting human relationship” and LLM like Chat GPT and laude is not a lawyer.
2. No reasonable expectation of confidentiality. Claude’s privacy policy explicitly allows the company to collect user inputs and outputs, use them for model training, and disclose them to third parties, including regulators. The court found that under these terms, “nobody can reasonably claim they expected the conversation to stay private.”
3. No counsel direction. The defendant used Claude of his own volition, not at his lawyer’s direction. The court noted that had counsel directed the AI use, the result “might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent”, but even that was left as an open question.
Critically, the court held that “even information that started out privileged loses its protection once it is pasted into a public chatbot.” As one analysis put it, “he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party.”
**You can review the full opinion here:** [United States v. Heppner, 1:24-cr-00410 (S.D.N.Y. Jan. 30, 2026)](https://www.courtlistener.com/docket/68865228/united-states-v-heppner/) via CourtListener, or through the [Southern District of New York’s PACER system](https://www.nysd.uscourts.gov/).
OpenAI’s Terms of Service: The Training Data Trap
The Heppner court’s analysis of Claude’s privacy policy applies with equal force to the dominant consumer AI platform: OpenAI’s ChatGPT. OpenAI’s Terms of Use and Business Terms explicitly address what happens to the data users upload—and the answer should alarm any employer using it for sensitive workplace investigations.
Under OpenAI’s current terms, unless an organization is on an explicit “zero data retention” or enterprise API agreement with contractual exclusions, **user inputs and outputs may be used to train and improve OpenAI’s models.** This means that an HR manager’s query about how to terminate a pregnant employee, or how to draft an investigation report to withstand legal scrutiny, could theoretically be incorporated into future model training data. While OpenAI has implemented some safeguards and offers opt-out mechanisms for certain account tiers, the default position for consumer and many business accounts is that content may be retained and used for model development.
Even more troubling for privilege analysis: OpenAI’s terms reserve broad rights to disclose content to comply with legal process, to enforce terms, to protect rights and safety, and to affiliates and service providers. The company explicitly states it may share information with “vendors and service providers” who support its business operations. Under traditional privilege doctrine, each of these categories constitutes a third party whose presence destroys confidentiality.
For employers conducting investigations, the practical implication is stark: **unless they have negotiated a specific enterprise agreement with explicit zero-retention and no-training clauses, their HR team’s use of ChatGPT is creating a record that OpenAI may retain, analyze, and potentially incorporate into future model outputs.** This is not theoretical. It is contractual. And it is exactly the type of third-party access that privilege doctrine has always treated as fatal to confidentiality.
—
Local vs. Cloud LLMs: The Architecture Matters
To understand why privilege analysis differs so dramatically, you need to understand how generative AI is actually deployed. There are two fundamentally different models:
**Cloud-Based LLMs (The Public Chatbot Model)**
These are the consumer-facing tools most people know: ChatGPT, Claude, Gemini, Perplexity. When an HR manager types a prompt into ChatGPT, here’s what happens:
– Her input travels across the internet to servers owned by OpenAI, Anthropic, or Google
– The company processes her query on their infrastructure, using their proprietary model
– The terms of service explicitly grant the company rights to retain, review, train on, and in some cases disclose the content
– The data may be stored indefinitely, subject to the provider’s data retention policies and potential government requests
– Even “private” or “team” tiers often reserve rights for abuse monitoring, safety review, and model improvement
This is the architecture that doomed privilege in *Heppner*. The user is functionally sharing their legal strategy with a third-party corporation that has contractual and legal rights to access, use, and disclose that information.
Locally-Deployed LLMs (The On-Premises Model)
At the other end of the spectrum, an organization can download an open-source model (like Llama, Mistral, or Falcon) and run it entirely on their own servers or individual workstations:
– The model weights and inference engine reside on hardware the organization controls
– No data leaves the organization’s network—prompts are processed locally, outputs are generated locally
– There is no third-party AI provider with contractual rights to the data
– The organization controls data retention, access logs, and security protocols
– Even if the model is connected to the internet for updates, the actual query processing happens on local infrastructure
This architecture is functionally equivalent to using a word processor or spreadsheet on a company laptop. The privilege analysis changes dramatically because there is no third-party intermediary with independent rights to the content.
The Hybrid Models: Where It Gets Complicated
Between these two poles sits a growing ecosystem of hybrid deployments:
Enterprise API Access with Confidentiality Terms
Some organizations contract directly with OpenAI, Anthropic, or Microsoft for enterprise API access with negotiated data protection terms. These agreements typically include:
– Explicit commitments that customer data will not be used for model training
– Restrictions on third-party access
– Geographic restrictions on data storage
– Audit rights and security certifications
The Heppner court explicitly left open the possibility that “counsel-directed AI use on a secure enterprise platform—with contractual confidentiality terms—could yield a different result.” This is the architecture the defense bar is betting on.
Private Cloud / Virtual Private Cloud Deployments
Organizations can deploy models on cloud infrastructure (AWS, Azure, Google Cloud) within isolated environments where the cloud provider has no access to the data or model operations. The hardware is rented, but the data never touches the provider’s general systems.
The HR Investigation Scenario: Where Privilege Fails
This is where the defense bar’s comfortable “closed system” advice breaks down for the typical employer investigation.
Most workplace investigations are not attorney-led. They are conducted by HR professionals, compliance officers, or line managers who have never done an investigation before and are operating under pressure. When that HR manager opens ChatGPT and types:
“How do I fire a pregnant employee without getting sued for discrimination?”
“What questions should I ask in a retaliation investigation to make the complaint look unfounded?”
“Draft an investigation report that shows we had legitimate business reasons for termination.”
…she is not in a law firm’s closed system. She is not on an enterprise API with confidentiality terms. She is not running a local model on an air-gapped workstation. She is on a consumer AI platform with terms of service that explicitly disclaim confidentiality, reserve rights to retain, train on, and disclose her inputs, and permit broad disclosure to affiliates and service providers. She is waiving any privilege that might otherwise attach. She is creating a discoverable record of her intent, her strategy, and her potential bias—and she may be contributing that record to the AI provider’s training data for future model improvement.
For plaintiff’s employment lawyers, this creates an entirely new category of discovery that most of us are not currently requesting.
The defense bar is right about one thing: AI is coming to employer investigations, and the legal profession needs to grapple with it. But their comfort with closed-system, attorney-directed AI use should not lull plaintiff’s lawyers into complacency.
The real action is in the gap between what the defense panel discussed and what actually happens in most workplaces: HR professionals using public cloud AI tools without counsel oversight, without confidentiality protections, without understanding the architectural differences between cloud and local deployment, without reading the terms of service that permit training data use, and without any realization that they are waiving privilege and creating discoverable evidence.
Add AI use to your discovery requests. Ask about deployment architecture. Ask about terms of service. Ask about it in depositions. Treat it as standard discovery in any case involving an employer investigation. The defense bar is already thinking about how to protect their clients from this risk. It’s time we started thinking about how to exploit it.
#EmploymentLaw #AI #Discovery #AttorneyClientPrivilege #WorkProduct #EmployerInvestigations #PlaintiffLawyer #LaborAndEmployment #LegalTech #Heppner #LocalLLM #CloudAI #OpenAI*