Why Asking a Chatbot Legal Questions Can Waive Attorney-Client Privilege
Is your AI risk really a data-security problem?
The chatbot answers like your lawyer. It just files everything with the other side.
The Situation
When Krafton, Inc., a South Korean gaming company, bought the studio behind Subnautica, it promised the founders operational control and owed them up to $250 million if the sequel hit its targets. Rather than pay, Krafton's CEO asked an AI chatbot how to force the founders out, followed its playbook, and on March 16 a Delaware court unwound the whole maneuver, putting the ousted CEO back in charge and adding 258 days to the earnout measurement period. What sank Krafton was its own chat history, because a question asked of an AI tool doesn't carry the legal protection the same question gets when asked to a lawyer.
The Exposure
In February, a federal court in New York (United States v. Heppner) became the first in the country to rule that a person's written exchanges with an AI chatbot aren't covered by attorney-client privilege, which means the other side in a lawsuit can demand them and read them. That matters because a majority of employees admit to putting confidential information into public AI tools, and most workplace chatbot use runs through personal accounts, the classic shadow AI problem, that a company's litigation hold doesn't automatically capture. In regulated firms and high-stakes industries like private equity, where a majority of deal teams now use generative AI, the most sensitive questions that expose intent are being typed into a tool with no privilege at all. Krafton's CEO deleted some of those chats before trial, and the deletion itself compounded the exposure.
The Judgment Call
The conventional read is that AI risk is about data security, customer privacy, and wrong outputs, and that monitoring tools and an acceptable-use policy handle it. But that misses privilege entirely, because the exposure doesn't turn on the contents of the prompt exchange. It turns on courts treating legal and strategic questions asked to an outside tool as disclosure to a stranger - which means privilege never attaches and the other side can compel it in discovery and read it. In a regulated firm or deal dispute, the person asking an AI tool how to handle a delicate situation is usually the person whose thinking a regulator or opposing lawyer most wants to see, and the tool now hands them a written record of it. Treat legal and strategic questions put to AI as a privilege issue owned jointly by the CCO and the General Counsel, not as a technology housekeeping item.
Risk: Framing AI use as a privilege issue moves compliance into the GC's lane, and executives may try to resist the reality that their chatbot questions are now something legal has to manage.
Benefit: You close a gap that no monitoring tool addresses, and you close it before a dispute turns your team's chat history into the other side's evidence.
This Week’s Action
What to do: Ask your General Counsel whether anyone on your executive or deal team has used a public AI chatbot to think through a legal, regulatory, or negotiation-sensitive question in the last 90 days, and if so, document whether and where that exchange still exists.
Who to involve: General Counsel and the specific executive or deal lead, do not do a broad employee survey. You want candor about actual instances, not a policy discussion.
What outcome to achieve: A one-page list of any AI-routed conversations that touched legal strategy or negotiation, with a decision on whether each needs to be preserved, reviewed by counsel, or flagged as a going-forward risk.
Time required: 120 minutes.
Artifact
AI-to-Counsel Routing Check
Send this to anyone on your executive, deal, or compliance team with access to a public AI chatbot.
Have you asked an AI chatbot how to handle a legal, regulatory, disciplinary, or negotiation-sensitive situation in the past 90 days?
☐ YES ☐ NO ☐ UNSUREIf yes, did you also ask counsel the same question, before or after?
☐ YES ☐ NODo you know whether that chat history still exists, or whether it's been deleted or auto-expired?
☐ STILL EXISTS ☐ DELETED ☐ UNKNOWNWould you be comfortable if opposing counsel or a regulator read that exchange word for word?
☐ YES ☐ NO
A 'NO' on question 2 or question 4 means it's time to bring in your attorneys, not delete the exchange and hope it goes away.
When the stakes exceed your internal capacity:
AI Exposure Diagnostic: A 2-hour strategic evaluation for risk, compliance, and legal leaders to identify your highest-priority governance gaps and deliver a 90-day remediation roadmap.
12-Week Governance Sprint: Translate regulatory requirements into audit-ready policies, control frameworks, and accountability structures.
Ongoing Advisory Retainer: Embedded judgment for policy updates, vendor assessments, and board prep as regulations and technology evolve.
Reply with "Diagnostic" or “Sprint” to schedule a conversation for next month.
Chris Cook writes Judgment Call weekly for compliance and risk officers navigating AI governance.
Former IBM Vice President and Deputy Chief Auditor. Published in the AI Journal, speaker at Yale.
Chris Cook
Managing Partner & Founder
Blackbox Zero
Forwarded this by a colleague? Subscribe to Judgment Call