Yes. No bar rule prohibits it, and ABA Formal Opinion 512 does not tell lawyers to avoid generative AI; it applies the duties you already have. The February 2026 decision in United States v. Heppner is being read far more broadly than it holds: a federal court found that a defendant's own chats with a consumer AI tool were not privileged, and it expressly left open the questions of lawyer-directed use and enterprise tiers.

Not legal advice: a plain reading of the guidance and one court opinion. Your state's rules govern.

Know which rules actually bind you

Most of what has been written about lawyers and AI is advisory. Bar ethics opinions persuade; Florida prints the point on its own face: "Advisory ethics opinions are not binding." State bar practical guidance sits in the same tier. Court orders bind the parties before that court. Only your state's Rules of Professional Conduct bind you directly, with discipline behind them. So the confidentiality duty is binding, and almost every AI-specific reading of it is not.

Exhibit 1

Almost everything written about lawyers and AI sits on the advisory rungs.

Weaker authority Bar ethics opinions ABA Formal Opinion 512 ADVISORY State bar practical guidance California COPRAC, 2026 guidance ADVISORY Court orders and sanctions rulings United States v. Heppner, 2026 BINDS THE PARTIES Rules of Professional Conduct Your state's Rule 1.6 BINDING Stronger authority
Note: this ladder is the framework used in this article, not a ranking anyone publishes. Examples are one per rung and are not exhaustive. Rules of Professional Conduct are adopted state by state, so the bottom rung is your state's, not the ABA's model text.

Opinion 512 is a checklist, not a ban

The duty attaches before you type: "Before lawyers input information relating to the representation of a client into a GAI tool, they must evaluate the risks that the information will be disclosed to or accessed by others outside the firm."

Consent is narrower than it sounds. 512 requires it for self-learning tools, and closes the shortcut, since "merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient." Where you enter no client information, consent is not required at all.

Reading each tool's terms of use and privacy policy is a literal obligation, though 512 accepts a colleague or expert doing it for you. You stay responsible for whatever it produces. The opinion dates itself, in footnote 34: "This conclusion is based on the risks and capabilities of GAI tools as of the publication of this opinion."

Confidentiality and privilege are two different problems

Confidentiality is an ethics rule covering "all information relating to the representation of a client, regardless of its source"; breaching it produces a bar complaint. Privilege is evidentiary: a voluntary disclosure to a third party can destroy it, handing the material to the opposing side. One costs you a disciplinary problem. The other costs your client the case.

Opinion 512 is a confidentiality document: its full text contains one instance of the word privileged, in the introduction, about e-discovery. Articles saying the ABA warned AI could waive privilege describe a document that never raises it.

What Heppner actually held

United States v. Heppner, No. 25-cr-00503 (JSR), was decided by Judge Rakoff in the Southern District of New York on February 17, 2026. The opinion is not publicly retrievable, so the quotations below come from firm analyses: Proskauer, McDermott and Venable.

The defendant used the tool, not his lawyer: counsel "did not direct [Heppner] to run Claude searches". He put material learned from his attorneys into a consumer tool on his own initiative, and the court treated that as it would telling any third party. The documents were not work product either.

The reasoning ran through the vendor's terms, which the court noted permitted the provider "to disclose user data to regulators and to use users' prompts and outputs for model training". The outcome turned on the contract, not the category "AI".

It reserved the other case in as many words: "Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent within the protection of the attorney-client privilege." The opinion says of itself: "It does not declare Gen AI incompatible with legal privileges". No lawyer was sanctioned; the loss was the client's privilege.

Exhibit 2

The headline version of Heppner drops every fact that limited it.

What the court held What it left open The defendant, not his lawyer, ran the searches himself. Putting the material into a consumer tool waived privilege over what he typed. Not work product either, since counsel did not direct them. The terms allowed training and disclosure to regulators. Whether lawyer-directed use is protected. The tool "might act as a lawyer's agent". Whether enterprise tiers with contractual confidentiality change the analysis. Any general rule. The opinion "does not declare Gen AI incompatible with legal privileges". One district court. One consumer tier. One client, not his lawyer.
Note: the docket is confirmed against the court's own record, but the February 17, 2026 written opinion is not publicly retrievable, so quoted phrases come from law firm analyses of it. An appeal or a second decision would change this picture, so treat it as the state of play on 2026-08-12.

The tier decides, not the technology

A consumer tier sits on a privacy policy the vendor can amend on its own; a commercial tier sits on a contract. Anthropic's Commercial Terms say "Anthropic may not train models on Customer Content from Services" and, more useful for a firm, "Customer Content is Customer's Confidential Information". Google tells users of its unpaid tier, in bold: "Do not submit sensitive, confidential, or personal information to the Unpaid Services."

When the New York Times litigation forced OpenAI to preserve consumer and standard API content, business customers sat outside it: "This does not impact ChatGPT Enterprise or ChatGPT Edu customers", nor those on zero data retention endpoints. A court overrode a stated retention policy and the contract held. Those obligations ended on September 26, 2025.

Vendor terms move; these were read 2026-08-13.

Where lawyers actually get caught, and it is not confidentiality

Every documented sanction here is about accuracy and candor, not leaked confidences. Judge Castel, in Mata v. Avianca, wrote close to the opposite: "there is nothing inherently improper about using a reliable artificial intelligence tool for assistance." The $5,000 sanction landed because they stood by the fake opinions after the court questioned them.

Wadsworth v. Walmart is worth showing your partners: three lawyers were sanctioned over eight fabricated citations, and the firm was not, because it had already required independent verification of AI output. A written policy is a documented mitigating factor.

The AI Hallucination Cases database, last updated 11 August 2026, counts 1,870 court decisions worldwide addressing hallucinated material, many with no sanction attached. Searching on 2026-08-13, we found no lawyer sanctioned or disciplined for putting client confidences into an AI tool.

Does keeping it in-house help?

One state says yes, about one duty. Florida Opinion 24-1 notes that "confidentiality concerns may be mitigated by use of an inhouse generative AI rather than an outside generative AI where the data is hosted and stored by a third-party", and that consent is then not required. Advisory, one jurisdiction, consent duty only. No other jurisdiction surveyed addresses where the model runs.

California points the other way, warning that even where a product does not use your inputs, "it may lack reasonable or adequate security". Harvard JOLT's Steve Leben sets the honest limit: Rule 1.6 "does not require lawyers to buy the maximum safeguard available in the market, regardless of cost." We have written separately about a model that never leaves your network and which matters actually need to stay in-house.

What a four-person firm can do this month

Move client work off consumer accounts onto a business or API tier. Run the D.C. Bar's two questions against whatever you use: will what I put in be visible to the provider or to strangers to the relationship, and will it change the answers later users get in a way that reveals it. Write the policy down; it is what protected the firm in Wadsworth. Require verification of every citation and factual claim before anything leaves the office.

Heppner was a client's mistake, so warn clients about their own AI use. The New York State Bar Association suggests engagement letter and email signature warnings, and advising clients "to disable AI notetakers during confidential conference calls." If you want a hand writing the firm's AI policy, that is work we do.

Common questions

Is it ethical for lawyers to use ChatGPT?

Yes. No bar rule prohibits it. ABA Formal Opinion 512 applies duties you already owe rather than banning the tool: competence, confidentiality, client communication, candor, supervision, and reasonable fees. What is not ethical is entering client information without working out where it goes, or filing output nobody verified.

Does using AI waive attorney-client privilege?

Not on its own. In United States v. Heppner a defendant waived privilege over material he put into a consumer AI tool himself. The court reserved the lawyer-directed and enterprise-tier questions, and said of the opinion that "It does not declare Gen AI incompatible with legal privileges". Nothing has been held the other way: an enterprise tier is not a proven safe harbor.

Can lawyers use ChatGPT in California?

Yes, on California's own terms. Its State Bar guidance states that "This 2026 Practical Guidance replaces the 2023 version" most articles still quote. The rule is conditional: a lawyer "must not input any confidential information of the client into a generative AI solution that may present material risks to confidentiality or security, absent informed client consent." California has also proposed amendments to six Rules of Professional Conduct. Those are proposed, not law.

Start a conversation

All notes Start a conversation