Skip to main content
    Issue #27•31 March 2026

    Thought AI chats stayed between you and the model?

    Your enterprise tier doesn't protect against lawyers.

    Every prompt your team has typed into AI is one subpoena away from a courtroom. Enterprise tools fix one problem. They don't fix the one your GC should be losing sleep over...

    $40 million deal. A CFO typing his negotiation position into Claude at 11pm the night before the call.

    Thought AI chats stayed between you and the model? Your enterprise tier doesn't protect you from lawyers.

    A New York court ruled in February 2026 that AI conversations aren't automatically privileged. **Daniel Kiley**HWL Ebsworth confirmed in March 2026 the same reasoning applies in Australia.

    The enterprise data, governance, and security conversation should be sorted by now. Most boards have it handled. API access, data retention off, private instances. IT has it, BUT legal exposure is a different conversation entirely.

    Have you told AI things you'd never type in Slack? Board tensions. M&A thinking. Negotiation strategy before the call. Something a little more "creative"?

    None of that breaks your data policy.

    All of it could be subpoenaed.

    Under Australian law, there's no settled privilege protection for AI-generated threads. What you typed today could be read aloud in court tomorrow. For most Australian organisations now, your enterprise tier doesn't change that.

    The Gap

    There's a feeling most executives won't say out loud: they've already used AI for exactly the things you're not supposed to type into it. Why? It works. You get better thinking faster. Nobody sees it. It feels safe.

    PwC's 29th Global CEO Survey, released January 2026, found transforming fast enough for technological change, including AI, is the number one concern for Australian CEOs. The pressure to use AI is real and accelerating, but it's accelerating into consumer tools, personal accounts, and free tiers, without any classification of what can and can't go in. The prompts are accumulating as a legal record. The board hasn't been told, there is a gap between "we have an enterprise AI policy" and "we've classified which prompts are privileged and which aren't".


    What's Inside

    1. What your vendors' terms of service actually say, quoted verbatim
    2. What Judge Rakoff ruled in February 2026 and why it's directly relevant in Australia
    3. The three-layer exposure model: where your organisation sits
    4. The 12 prompts most likely to become exhibits
    5. Five copy-paste deliverables: the GC audit, the classification test, the ToS kill-shot, the board paper, and the personal audit
    6. Three things your board should never type into public AI
    7. Australian governance: what the Privacy Act and OAIC already require before you get to litigation

    The Fix

    One policy document, one GC audit, one owner. Your organisation can start in 48 hours.

    Before / After


    Section 1. What your vendors' terms actually say

    Boards (most) assume IT has handled this. IT has handled the data security part. Nobody has read the paragraph that explains what happens when a court, a regulator, or a law enforcement agency asks your AI vendor for your prompts.

    Anthropic (Claude), consumer tier

    Source: Anthropic Consumer Terms of Service, current. anthropic.com/legal/consumer-terms

    Section 4, "Our use of Materials":

    "We may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings."

    Training opt-out is available. it's not the default, your team is almost certainly opted in.

    Section 12, "Legal Compliance":

    "We may comply with governmental, court, and law enforcement requests or requirements relating to provision or use of the Services, or to information provided to or collected under our Terms. We reserve the right, at our sole discretion, to report information from or about you, including but not limited to Inputs, Outputs, or Actions to law enforcement."

    The terms reserve that right, no court order is specified as a precondition. No notice to you is required under these terms.

    OpenAI (ChatGPT), consumer tier

    Source: OpenAI Privacy Policy, updated June 27, 2025. openai.com/policies/privacy-policy

    "Government Authorities or Other Third Parties" section:

    "We may share your Personal Data, including information about your interaction with our Services, with government authorities, industry peers, or other third parties... (i) if required to do so to comply with a legal obligation, or in the good faith belief that such action is necessary... (iii) if we determine, in our sole discretion, that there is a violation of our terms, policies, or the law."

    Multiple grounds to share your prompt data with government or third parties. Ground (iii), "in our sole discretion", does not specify a court order as a precondition.

    What Enterprise Contracts Fix:

    OpenAI's Business Terms and Microsoft's Customer Data Protection Addendum contractually remove the training-on-inputs clause and restrict government disclosure to legally compelled requests only. That matters. It closes the vendor-disclosure door.

    However it doesn't create privilege, this requires a human lawyer in the loop. Enterprise contracts address data handling, not the separate question of legal professional privilege.

    Your GC needs to confirm in writing which tools your organisation uses have contractual confidentiality clauses covering inputs.


    Section 2. What Judge Rakoff ruled and why it's directly relevant in Australia

    On 17 February 2026, Judge Jed Rakoff of the Southern District of New York issued the first US ruling that AI-generated documents are not automatically protected by attorney-client privilege or work product doctrine.

    The case was United States v. Heppner, No. 25-cr-00503-JSR. Bradley Heppner, a defendant under federal indictment, used the consumer version of Anthropic's Claude to generate 31 documents after receiving a grand jury subpoena. The documents analysed his legal exposure and drafted defence arguments. He subsequently shared them with his lawyers and claimed privilege.

    Rakoff rejected both claims.

    Leg 1. Claude is not a lawyer.

    Rakoff held recognised privileges require "a trusting human relationship" with "a licensed professional who owes fiduciary duties and is subject to discipline." No AI platform meets that test. This leg has direct relevance regardless of jurisdiction, tier, vendor, or contract.

    Leg 2. Consumer tools undermine confidentiality.

    Rakoff found Heppner "could have had no reasonable expectation of confidentiality in his communications with Claude" because Anthropic's consumer terms permit disclosure to governmental regulatory authorities and in "claims, disputes, or litigation." Those are the exact clauses in Section 1.

    Leg 3. Counsel didn't direct the work.

    Work product requires documents prepared "by or at the behest of counsel." Heppner was acting "of his own volition." His lawyers hadn't asked him to use Claude. Work product didn't attach.

    The one door Rakoff left open:

    If Heppner had been acting on counsel's instructions, Claude could have functioned as a lawyer's agent within the protection of privilege (Heppner memorandum at 7, citing the Kovel doctrine and United States v. Adlman, 68 F.3d 1495 (2d Cir. 1995)). But only assuming there had been confidentiality and Heppner was acting on instructions from his counsel. He wasn't.

    Enterprise tool with contractual confidentiality, plus a human lawyer directing the work. Is the only arguable safe zone.

    The Australian position.

    Heppner is a US decision. It isn't binding in Australian courts, but its reasoning is directly applicable to how Australian courts are likely to approach the same question, and Australian legal practitioners have said so explicitly. Lander & Rogers published their analysis in March 2026. Partners Philip Aitken, Helen Sims, Matthew McMillan, Margaret Gigliotti, and Scott Traeger:

    On advice privilege: "Advice and recommendations provided by an AI tool are therefore not protected by legal professional privilege." Australian legal practice requires a current practising certificate. AI tools don't have one. That pathway is effectively closed.

    On litigation privilege: *"If, however, there is no lawyer in the loop and the communications are occurring solely between client and AI, it is unlikely that the 'professional legal services' element will be met, meaning the communications will not be privileged."*There is no equivalent Australian case to Heppner yet.

    Based on current Australian legal commentary, consumer AI prompts are unlikely to attract privilege.


    Section 3. The Three-Layer Exposure Model

    Australian organisations think they're in Layer 3. I say most are Layer 2.

    Layer 1: Consumer AI, no governance

    Vendor terms permit training on your inputs by default. Vendor terms permit disclosure to law enforcement at their discretion, without specifying a court order as a precondition. Privilege is unlikely on both the advice and litigation tests. OAIC explicitly warns against putting sensitive personal information into publicly available AI tools.

    This is claude.ai, chatgpt.com, gemini.google.com. Free accounts. Personal accounts. The ones your team logs into from their phones at 11pm.

    Layer 2: Enterprise AI, no lawyer in the loop

    Vendor can't train on inputs, can't disclose to government without legal compulsion. Still no privilege. Heppner Leg 1 remains relevant regardless of tier. Lander & Rogers: no lawyer in the loop means the "professional legal services" test is unlikely to be met, meaning no privilege.

    This is where MOST Australian enterprises currently sit. Safer on data, not safe on privilege. The executive typing alone on a properly configured enterprise tool is still generating discoverable records of their thinking.

    Layer 3: Enterprise AI, lawyer directing the work

    Vendor contractual confidentiality. Lawyer directing the work, or client completing a task the lawyer assigned. Privilege is arguable under Heppner's Kovel carve-out and Lander & Rogers Scenarios A and B.

    This is the only configuration where privilege is a serious argument. It requires two things simultaneously: the right tool and a human lawyer in the loop. Most sensitive AI use cases in Australian organisations have neither.

    Even if every employee in your organisation is on enterprise tools, almost none of your sensitive AI work is likely to attract privilege. It requires a lawyer in the loop.


    Section 4. The prompts most likely to become exhibits

    Each maps to a litigation category. The test for every row is one question:

    This reveals what you were considering before legal, HR, or governance was in the room.


    Prefer these executive briefs land directly in your inbox?

    Apple Podcasts | Spotify


    Section 5. Five deliverables

    Deliverable 1: The one-question GC audit (send today)

    Send this to your General Counsel in writing:

    "Which of our AI tools has a contractual confidentiality obligation covering inputs and explicitly restricts the vendor from discretionary government disclosure? I need the confirmed list in 48 hours, not a general answer."

    If they can't produce it, that gap is your audit.


    Deliverable 2: The prompt classification test (this week)

    This generates a Red / Amber / Green classification for your organisation. Paste it, fill in the brackets, and the output is an AI input policy your GC can review and your exec team can follow.

    ☐ COPY AND PASTE THIS ENTIRE PROMPT

    I need a Red / Amber / Green AI prompt classification table for my organisation.
    
    My organisation: [your industry, size, and key risk areas]
    Our AI tools: [list tools and whether each is consumer or enterprise tier]
    Our current AI acceptable use policy: [paste it here, or write "we don't have one"]
    
    Context:
    - United States v. Heppner (S.D.N.Y. Feb 2026): consumer AI chats ruled not privileged. Enterprise tier fixes vendor disclosure but does not create privilege. Only lawyer-directed use creates privilege.
    - Lander & Rogers (March 2026): "Advice and recommendations provided by an AI tool are not protected by legal professional privilege."
    - Three layers: (1) Consumer, vendor can disclose AND no privilege. (2) Enterprise without lawyer, vendor restricted BUT no privilege. (3) Enterprise with lawyer directing, privilege may attach.
    
    Classify each of the following prompt categories as:
    - RED: Never type into any AI tool without legal counsel directing the work. Enterprise + lawyer only.
    - AMBER: Enterprise tool required. No lawyer needed, but no sensitive names, numbers, or positions.
    - GREEN: Any tool, unrestricted.
    
    Categories to classify for our specific industry and risk profile:
    1. Employment decisions (terminations, PIPs, restructures, selection criteria, named individuals)
    2. Legal exposure, disputes, regulatory response
    3. M&A strategy, negotiation positions, deal structures, counterparty tactics
    4. Financial disclosures, guidance, investor communications
    5. Board strategy, governance, board minute content, director liability
    6. Content referencing named individuals or personal information
    7. Competitive intelligence and market positioning
    8. Customer or supplier contract negotiations
    9. Internal restructuring and workforce planning
    10. General research, drafting, analysis (no sensitive content)
    
    For each category, produce:
    - The classification (RED / AMBER / GREEN)
    - One example prompt that falls in that category for our industry
    - The litigation risk if that prompt were produced in discovery
    - The rule: what conditions must be met before typing it
    
    Format as a table suitable for executive distribution. Add a one-paragraph summary explaining the three layers and why enterprise alone doesn't equal privileged.
    
    

    Deliverable 3: The ToS kill-shot test (this week)

    Pull the terms of service for every AI tool your team uses. Search for three phrases:

    1. "governmental regulatory authorities"
    2. "claims, disputes, or litigation"
    3. "improve our services" or "train our models"

    Anthropic's consumer terms contain all three (section 4 and section 12). OpenAI's consumer terms contain equivalent language. If any appear in relation to user inputs, those prompts have weak confidentiality protection and a fragile privilege foundation at best. Your enterprise contract should expressly remove all three.


    Deliverable 4: The board paper (before your next board meeting)

    This generates a one-page briefing showing your board which risk categories hit your organisation hardest and explains the three-layer model.

    ☐ COPY AND PASTE THIS ENTIRE PROMPT

    I'm preparing a one-page board briefing on AI chat discoverability and privilege risk.
    
    My organisation: [your industry, size, and approximate number of employees using AI tools]
    Our biggest exposure area: [employment / M&A / board governance / regulatory]
    Our current AI setup: [consumer plans / enterprise plans / mix of both]
    
    Context (cite these in the briefing):
    - United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb 17, 2026): 31 AI-generated documents ruled not privileged. Three-part test failed: AI is not an attorney, consumer privacy policy allowed government disclosure, work was not directed by counsel.
    - In re OpenAI Copyright Litigation, No. 25-md-3143 (S.D.N.Y. Jan 5, 2026): 20 million de-identified ChatGPT logs ordered produced.
    - Lander & Rogers (Aitken, Sims, McMillan, Gigliotti, Traeger), March 2026: "Advice and recommendations provided by an AI tool are not protected by legal professional privilege." Enterprise tools fix vendor disclosure but do not create privilege. Only lawyer-directed use creates privilege.
    - Three layers: (1) Consumer, vendor can disclose AND no privilege. (2) Enterprise without lawyer, vendor restricted BUT no privilege. (3) Enterprise with lawyer directing work, privilege may attach.
    - OAIC Guidance (Oct 2024): privacy obligations apply to AI inputs containing personal information. OAIC compliance sweep active Jan 2026. ADM transparency obligations (APP 1.7-1.9) commence 10 Dec 2026.
    
    Draft a one-page board briefing:
    1. Why AI chat logs are discoverable regardless of enterprise tier
    2. The three-layer model with our likely current position
    3. Three highest-risk prompt categories for our organisation with one example each
    4. Three recommendations the board should approve this quarter
    
    Format for an ASX board pack. Plain language. Under 500 words.
    
    

    Deliverable 5: The personal audit (before Friday)

    This one's for you, not your board, not your team. You.

    The 2-minute version. Open your ChatGPT, Claude, or Gemini history. Search for these terms:

    • "terminate" / "exit" / "fire" / "PIP" / "manage out"
    • "disclose" / "ASX" / "board" / "minutes"
    • "valuation" / "diligence" / "acquisition" / "bidder"
    • "compliance" / "regulator" / "OAIC" / "delete"
    • "exposure" / "liability" / "privilege" / "discoverable"

    If anything comes back, was a lawyer directing that work?

    If the answer is no, you're at Layer 2. The prompt exists, it's not privileged, and it's one subpoena away from a courtroom.

    The full version (if the 2-minute search worried you). Export your data and review it properly with legal oversight.

    • ChatGPT: Settings → Data Controls → Export Data. OpenAI emails you a zip file containing every conversation.
    • Claude: Settings → Export Data. Anthropic emails you a download link.
    • Gemini: Google Takeout (takeout.google.com) → select Gemini Apps.

    Once you have the export, don't review it alone. Share it with your legal team under privilege. Have counsel direct the review. That way the review itself is privileged, even if the original prompts aren't.


    How To Use This Newsletter As An AI Input

    Upload this issue into Claude or ChatGPT Enterprise. Then type:

    "Based on this newsletter, assess our current AI tool usage policy against the privilege and disclosure risks described. Flag the three highest-risk gaps. My role is [your role]. Our industry is [your industry]. Our AI tools are [list tools]."
    
    Use the output as your first-pass risk register before your next board meeting.
    

    The Board Rule

    Three categories never go into public AI.

    No tool where your GC hasn't confirmed contractual confidentiality over inputs in writing.

    • Strategy: Negotiating position, deal structure, competitive response, board positions
    • Liability: Legal exposure, regulatory response, dispute analysis
    • Personnel: HR decisions, termination rationale, performance management, named individuals

    Everything else is a judgement call. These three aren't.


    Australian Governance

    ⚠️ What Australian law already requires. Before you get to litigation.

    Privacy Act 1988 (Cth), APPs 3, 6, and 11. OAIC confirmed in October 2024 that privacy obligations apply to both inputs into and outputs from commercially available AI products where personal information is involved. Sensitive information typed into consumer AI tools triggers collection (APP 3), use and disclosure (APP 6), and security (APP 11) obligations. The OAIC's explicit guidance: organisations should not input sensitive personal information into publicly available AI tools.

    APP 1.7, effective 10 December 2026. Passed as part of the Privacy and Other Legislation Amendment Act 2024 (Cth). From that date, APP entities must include in their privacy policy information about automated decision-making that uses personal information to make or substantially support decisions affecting an individual's rights or interests. AI-assisted HR decisions. AI-assisted credit assessments. AI-assisted performance management. All captured.

    Enforcement posture has changed. The OAIC launched its first-ever privacy compliance sweep in January 2026, reviewing 60 entities across six sectors for compliance with APP 1.4. It's not AI-specific. But the same regulator, same Act, and same principles apply when AI inputs contain personal information. The Federal Court confirmed a $5.8 million penalty against Australian Clinical Labs in October 2025, the first civil penalty under the Privacy Act. Infringement notices are now available without needing to cross the old "serious interference" threshold.

    The connection your board needs to understand: an OAIC enforcement action surfacing your AI inputs makes it much easier for plaintiff's counsel to target discovery around the same prompts. One audit covers both fronts. Most organisations haven't started either.


    Closing

    Your enterprise tier solved the vendor disclosure, not privilege - this is still open.

    Three legs brought down Heppner's claim: the AI wasn't a lawyer, the consumer tool undermined confidentiality, and no lawyer had directed the work. Two of those three legs are directly relevant to every employee in your organisation using AI alone, regardless of tier.

    The $5.8 million Federal Court penalty tells you the regulator is ready. The Heppner reasoning tells you courts will treat AI chats as evidence. Lander & Rogers tell you Australian privilege is unlikely to protect what your people typed privately.

    Forward this to your General Counsel with one question: "Which of our AI tools has a contractual confidentiality clause covering inputs, and for which sensitive use cases do we have a lawyer directing the work?"


    About Applied AI Australia

    AI moves fast. Unless you want to spend five hours a day reading research papers, sitting through vendor briefings, and speaking to 100+ CEOs and boards, the way I've spent the last 90 days, you need a filter.

    That's what Applied AI Australia is. One podcast. One newsletter. Every week. Built for Australian executives at companies between $50M and $2B. We only cover what matters: growth, margins, time, and risk. Less than one hour of your week to stay on the right side of history.

    Apple Podcasts | Spotify | Newsletter (Exec Brief)


    Disclaimer: Nothing in this newsletter is legal advice. It's research, pattern recognition, and publicly available information organised for executives who don't have five hours a day to read court filings. Before you act on any of this, talk to your GC and external counsel. The irony of a newsletter about AI privilege reminding you to see a lawyer is not lost on me.


    Primary sources

    • United States v. Heppner, No. 25-cr-00503-JSR, S.D.N.Y., Judge Jed Rakoff, written opinion February 17, 2026
    • In re OpenAI, Inc., Copyright Infringement Litigation, No. 25-md-3143 (S.D.N.Y. Jan 5, 2026)
    • Lander & Rogers, "AI and Privilege: are your AI chatbot conversations protected?", March 2026
    • Lander & Rogers, "Australian Privacy Law Update 2026," February 2026
    • Anthropic Consumer Terms of Service, sections 4, 12
    • OpenAI Terms of Use, effective December 11, 2024
    • OpenAI Privacy Policy, updated June 27, 2025
    • Google Terms of Service, effective May 22, 2024
    • OAIC, "Privacy and commercially available AI products," October 2024
    • Debevoise & Plimpton, Heppner analysis, February 17, 2026
    • Privacy Act 1988 (Cth); Privacy and Other Legislation Amendment Act 2024 (Cth)

    #enterpriseAI #riskmanagement #generalcounsel

    Ready to deploy AI with confidence?

    Get board-ready frameworks and strategic guidance for Australian executives navigating AI transformation.

    Discuss your AI problem

    The Executive Brief

    Practical AI strategy for Australian executives. No fluff. No jargon. Just what matters.

    We send one brief per week. Unsubscribe any time.