Earlier this month, Judge Rakoff of the Southern District of New York issued the first ruling of its kind. America vs. Heppner. The case involved criminal defendant Heppner, who allegedly used a publicly generated AI platform (Claude) to “produce a report outlining his defense strategy (arguments of fact and law).” [his attorneys] Heppner said the defendant created the document himself but later shared it with his attorney. Hepner argued that these AI-generated documents should be protected by the attorney-client privilege and the work product doctrine.
The court disagreed, and its reasoning will have important implications for everyone in the life sciences field, especially as AI tools become more widely used in regulatory and compliance operations.
Key points from the Heppner decision
- Narrow privileges: The judge reaffirmed that privilege protects only direct confidential communications between a client and attorney, or work produced at or at the attorney’s direction. Using publicly available AI tools breaks that chain, especially when used on your own initiative, away from the guidance of a lawyer.
- There is no reasonable expectation of confidentiality: Using a third-party AI platform means there is no reasonable expectation of confidentiality. The platform’s privacy policy may permit the storage, use, and even disclosure of user input information, including confidential business information (CBI) and trade secrets, to third parties and government authorities.
- No retroactive authority: Even if you later share these AI outputs with your attorney, you cannot “retroactively” privilege the attorney. Once CBI or sensitive regulatory information is entered into a public AI tool, that information is considered disclosed.
Why this is important for life sciences
Life sciences companies routinely handle sensitive data such as regulatory filings, audit responses, clinical trial results, and manufacturing records. As AI tools become increasingly integrated into daily workflows, there is a temptation to use them to summarize, analyze, or draft documents containing CBI or privileged information.
but, heppner As the case study shows, this can be dangerous.
- Regulatory and litigation risks: Disclosure of CBI or privileged information via public AI tools can result in a loss of protection not only in litigation but also in regulatory audits.
- Trade secret protection: Public disclosure can destroy trade secret status.
- Internal risk: Operations, safety, manufacturing, and research employees may not be aware of these risks, so training and policy updates are essential.
Practical steps to protect your company’s trade secrets
- Avoid public AI tools for sensitive content: Do not use public or commercial AI tools to process, summarize, or explain information that contains CBI or trade secrets.
- Train all teams: Ensure legal and regulatory teams, as well as operational, safety, manufacturing, and research teams, understand the risks of using AI tools and the importance of proper CBI tagging and handling.
- Update internal policies. Prohibit the use of unauthorized AI tools on sensitive information and ensure that the use of AI occurs within a secure, company-controlled environment.
- Incident response: Update your incident response plan to address scenarios where CBI or privileged information may be accidentally entered into public AI tools. This should include internal reporting, containment, and notification procedures.
- Document your AI governance. Now you can demonstrate to regulators and auditors how your organization is protecting CBI with AI-enabled workflows.
- Use only approved enterprise AI tools for sensitive information. Avoid public or consumer-grade AI platforms for content containing CBI, trade secrets, or privileged communications. Instead, deploy enterprise-grade AI solutions that are vetted and managed by your organization’s IT and compliance teams. Ensure these tools are configured to prevent external data sharing and that their use is governed by robust internal policies. This ensures that sensitive data is protected and kept within your control. Consider using the following warnings for your employees:
Caution: Do not enter confidential business information, trade secrets, or privileged communications into public AI tools (such as ChatGPT, Claude, or Gemini). Use only company-approved enterprise AI platforms for work-related tasks involving sensitive data.
- Vendor due diligence: If your team uses a third-party enterprise AI vendor, be sure to perform due diligence on the vendor. Review our privacy policy, data processing practices, and contractual commitments. Make sure your data is not used to train external models and that you retain control over output and data deletion. For more information on AI vendor agreements, please see this link.
Checklist: Update your internal AI policy
- Which AI tools are approved for use? Who decides what gets added to the list?
- What types of data are employees allowed (or not allowed) to input into AI tools?
- Who is responsible for reviewing and approving AI-generated output?
- What training will my staff need on using AI and protecting data?
- How is compliance monitored and enforced?
- What is the escalation process for AI-related incidents or errors?
Hint: Conduct a data inventory to identify where sensitive business information is stored and which teams and workflows are using (or attempting to use) AI tools. This helps target training and policy enforcement where it’s needed most.
For the future
The FDA and other agencies are increasingly leveraging AI in their review processes.[1] As these tools become more deeply integrated into regulatory workflows, the risk and need for robust internal AI policies will only increase.
conclusion: AI tools are transforming the way we work, but the fundamentals of privilege and confidentiality remain the same. Incorporating CBI and privileged information into public AI tools can lead to a loss of protection not only in litigation but also in regulatory audits and interactions with government agencies.
[1] See FDA press release, FDA launches agency-wide AI tool to optimize performance for Americans (June 2, 2025), https://www.fda.gov/news-events/press-payments/fda-launches-agency-wide-ai-tool-optimize-performance-american-people and FDA news release, FDA expands artificial intelligence capabilities with agenttic AI implementation (December 1). 2025) https://www.fda.gov/news-events/press-payments/fda-expands-artificial-intelligence-capabilities-agentic-ai-deployment. See also Kimberly Chew, Esq. and Michael Yang, Esq., “FDA’s Elsa AI Switches From Claude To Gemini: What Sponsors Need To Know,” Clinical Leader (March 12, 2026). https://www.clinicalleader.com/doc/fda-s-elsa-ai-switches-from-claude-to-gemini-what-sponsors-need-to-know-0001.
[View source.]
