AI conversations and legal privilege: what United States v Heppner means for NZ boards

Is your board asking hard enough questions about what staff put into AI tools?

This article is general governance commentary, not legal advice. It works through how existing law might apply to a fast-moving area that New Zealand courts have not yet tested.

Your organisation is six months into an ERA claim. Discovery is underway. Someone asks: what AI tools did your managers use when they were developing the process that led to this dismissal, and what did they type into them?

There are two separate risks buried in that question. One needs a court case to materialise. The other is already biting.

What happened in New York

In February 2026, a US federal judge ordered a former company chief executive to hand over the records of conversations he had held with an AI platform to prosecutors pursuing fraud charges. His lawyers argued the conversations were legally protected. The judge disagreed. No attorney-client relationship exists between a user and an AI platform, and no recognised confidentiality attached to the exchanges. They were subject to disclosure.

The case is United States v Heppner, decided in the Southern District of New York by Judge Rakoff, who described it as a question of first impression nationwide. The platform was Claude, Anthropic’s AI assistant, used by the defendant on a consumer tier. In the interests of the transparency this article argues for: Ethos uses Claude in its own practice, under business terms that differ materially from the consumer tier at issue here. Investigators recovered roughly 31 documents recording the exchanges. The bench ruling came on 10 February 2026, with a written opinion following on 17 February.

The same month, a court in Michigan reached a different result. In Warner v Gilbarco, the Eastern District of Michigan declined to order production of documents a self-represented litigant had prepared using a public AI chatbot, finding that work product protection applied.

Two cases, two outcomes, weeks apart. But the divergence is not evidence that the law is a coin toss. It is the most useful part of the story, because the two cases turned on the things a board can actually influence. In Warner, the materials were treated as work product prepared in anticipation of litigation, and protection held. In Heppner, the defendant had used the AI tool on his own initiative rather than at the direction of counsel, and the consumer platform’s own terms, which permit the provider to collect inputs and outputs and disclose them to third parties, defeated any reasonable expectation of confidentiality. The protection failed not because AI was involved, but because of how the tool was used and what its terms allowed. That is a distinction about preparation, direction, and confidentiality, not about the brand of software.

Does it translate to New Zealand?

New Zealand does not use the phrase attorney-client privilege. We have legal professional privilege under the Evidence Act 2006, broadly similar in principle but different in doctrinal architecture. New Zealand civil proceedings are governed by the High Court Rules, and the Employment Relations Authority operates under its own disclosure regime. The US framework does not map cleanly onto either.

There is no New Zealand precedent on AI conversations and legal privilege. That uncertainty runs both ways: no confirmed exposure, but no settled protection either. The proposition that no confidential relationship exists between a user and an AI platform is available to any New Zealand court asked to consider it. Whether it would prevail here is open. What is not open is the practical question underneath it. If a manager used an AI tool to draft a redundancy rationale or develop a disciplinary process, and that decision is now being challenged, does your board know what was entered into that tool, and whether it is retained anywhere your organisation controls?

New Zealand law also recognises litigation privilege under section 56 of the Evidence Act 2006, which can protect material brought into existence for the dominant purpose of preparing for proceedings, not only communications with a lawyer. In principle that could reach AI-assisted litigation preparation. In practice it faces the same confidentiality obstacle: consumer AI platforms process conversations and retain broad rights under their terms of service, which undermines the confidentiality any form of privilege requires. And for most workplace AI use, the operational decisions, HR processes, and strategy documents that make up everyday work, preparing for litigation was never the dominant purpose. Litigation privilege does not reach that far.

The risk that does not need a court case

The litigation risk is prospective and doctrinally uncertain. The Privacy Act 2020 risk is operational, and it is present in many organisations right now, without any court being involved.

When a staff member pastes personal information about a client, a colleague, or a job applicant into a consumer AI tool, that information is transferred to a third-party platform overseas. Whether that engages information privacy principle 12, which governs cross-border disclosure, turns on what the platform does with the information. If a provider holds or processes the information solely on your behalf and does not use it for its own purposes, it may not be a disclosure at all. But where the provider’s terms permit it to use inputs for its own purposes, such as training its models, that is where the IPP 12 question arises, and if it is engaged, a cross-border disclosure requires one of its grounds: a recipient subject to comparable safeguards, contractual protections, or the individual’s express and informed consent. None of this has been tested against a specific AI tool in New Zealand, so the analysis is reasoned rather than settled.

What is worth noticing is that the privilege question in Heppner and the IPP 12 question here turn on the same feature of the terms. A provider that collects inputs, uses them to train, and reserves the right to disclose them is, for that reason, both unable to support confidentiality and harder to treat as a mere processor. The feature that defeated privilege is the feature that raises the privacy question. For most organisations using consumer tools informally, with no policy, no data processing agreement, and no staff awareness of what the terms of service say, neither question has been worked through at all.

The Office of the Privacy Commissioner published guidance on AI and the information privacy principles in 2023. The guidance is direct on this point: it warns that personal information entered into a generative AI tool may be retained or disclosed by the provider and used to continue training the model, and its overarching recommendation is that organisations do not upload personal or confidential information to these tools. The guidance is the Commissioner’s interpretation of how existing principles apply, non-binding and not yet tested in a formal proceeding. Organisations that have read it differently have not yet had to defend that position.

A further change tightens the wider picture: information privacy principle 3A, in force from 1 May 2026, now requires organisations to take reasonable steps to make people aware when their information is collected indirectly. It does not map neatly onto a staff member pasting data into a chatbot, but it is one more reason boards are being asked to account for where personal information flows.

Enterprise-grade tools with appropriate data processing agreements reduce the IPP 12 exposure materially. They do not resolve the litigation questions, where the tier of service matters less than the nature of the communications. And “we use an enterprise tool” is not the same as “we have an agreement in place, and our staff know what it permits.”

The questions

Not a checklist. Tests.

Does your board know what AI tools your managers were using six months ago, not in general but specifically, in the decisions now being challenged?

If a staff member used a consumer AI tool to draft a performance improvement plan last quarter, is that conversation retained anywhere your organisation controls?

Do you know whether personal information your staff entered into AI tools last week was processed in New Zealand or offshore, and under what terms?

Has anyone in your organisation actually read the terms of service of the AI tools your staff use daily?

Why it sits with the board

New Zealand has taken a proportionate, framework-based approach to AI, relying on existing law rather than dedicated AI legislation. The Privacy Act, the Evidence Act, and employment law all apply. They apply by analogy, without the consolidating guidance that specific regulation would provide.

There is no compliance checklist to point to. The question is whether a board has genuinely examined how existing legal obligations interact with how AI is actually being used across the organisation, and whether that examination is showing up in governance and reporting.

The board question is not whether your organisation has a policy on AI use. It is whether your board would know if staff are following it, and whether it knows what has already gone into these tools. The organisations most exposed to this risk are often the ones least able to see it.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top