Quick answer (updated August 2026): Whether ChatGPT is safe for legal work depends entirely on which tier you use. Consumer ChatGPT (Free and Plus) can retain your chats and train on them, which threatens client confidentiality and, after United States v. Heppner (S.D.N.Y. 2026), possibly privilege itself. Business and enterprise tiers with training off change the analysis. Legal-specific zero-retention tools change it further. Client matters belong only in the upper tiers.

Lawyers are not late to AI; they are early and unsupervised. In MIT Project NANDA’s preliminary 2025 research, workers from over 90% of the companies surveyed reported regularly using personal AI tools for work, whatever official policy said. A U.S. Chamber of Commerce/Teneo survey found 58% of small businesses using generative AI in 2025, up from 23% in 2023. Someone at your firm is already pasting things into a chatbot. The question is what tier of chatbot, and what is in the paste.

What United States v. Heppner changed

In February 2026, Judge Jed Rakoff of the Southern District of New York ruled that documents a securities-fraud defendant had generated with a consumer-tier AI chatbot (Anthropic’s Claude) were protected by neither attorney-client privilege nor the work product doctrine. United States v. Heppner, No. 25-cr-503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 2026). Privilege is the rule that keeps what you tell your lawyer out of the other side’s hands; the court gave three reasons it did not apply. The chatbot is not an attorney. The chats were not confidential, because the consumer privacy policy let the vendor collect inputs and outputs, train on them, and disclose them to third parties, including government regulators. And Heppner was not seeking legal advice from the chatbot itself, which disclaims giving any. The court left a door open: had counsel directed the client’s use of the tool, it might have functioned like a lawyer’s agent, and the analysis might differ. The tier’s data terms decided the case.

The 3-tier rule: what client information can touch which tool

One rule sorts every AI decision a firm faces. Classify the tool by what happens to your data, then let the tier set what may go in.

Tier Examples Training default Retention Client matters?
1. Consumer ChatGPT Free/Plus, Claude Free/Pro May train on your chats Vendor retains; discoverable Never. No client names, facts, or documents
2. Business/enterprise ChatGPT Team/Enterprise, Claude for Work, API Off by default (per OpenAI’s published policy) Controlled; OpenAI API up to 30 days, zero-data-retention available for eligible endpoints Yes, with a firm policy and consent where required
3. Legal-specific, zero-retention CoCounsel, Harvey Vendor states no training on your content Vendor states zero retention by model providers Yes; still verify every output

OpenAI’s enterprise privacy page states, “By default, we do not use your business data for training our models,” while data from its individual consumer products is used. Thomson Reuters states CoCounsel prompts “are not used to train or improve” its products or the underlying models; Harvey states, “We don’t use inputs, outputs, or uploaded documents to train underlying models” and requires zero data retention from its model providers. Those are the vendors’ published commitments as of July 2026, not our warranty. Read the current terms before you rely on them.

What ABA Formal Opinion 512 actually requires

The ABA’s July 2024 opinion on generative AI is narrower and more practical than its reputation. On confidentiality: before inputting information relating to a representation, lawyers “must evaluate the risks that the information will be disclosed to or accessed by others outside the firm.” On consent: because many self-learning tools could leak client information through their outputs, “a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool.” Boilerplate consent in an engagement letter “is not sufficient.” On fees: lawyers billing hourly “must bill for their actual time.” Time the tool saves belongs to the client, and so does time you spend learning it. Note what the opinion does not say: it does not require consent for all AI use, only for self-learning tools receiving client information. New York’s state bar task force declined to mandate consent at all.

The litigation-hold wrinkle

Even “deleted” consumer chats may not be gone. In the New York Times copyright litigation, a federal magistrate judge’s May 13, 2025 preservation order required OpenAI to preserve consumer ChatGPT output logs that would otherwise have been deleted. By OpenAI’s own account, zero-data-retention API traffic was never covered by the order, and the going-forward hold was lifted on October 9, 2025, though litigation continues as of mid-2026. The lesson for a law firm is structural, not about one case: a consumer chat log sits on someone else’s server, subject to someone else’s court orders. A zero-retention deployment has nothing to preserve. That difference is exactly what separates tier 1 from tier 3 when opposing counsel starts drafting subpoenas.

What your state bar says

Five states’ guidance, paraphrased; read the originals, linked below, and check your own jurisdiction before adopting a policy.

State Guidance In one line
California COPRAC Practical Guidance (2023) Keep confidential client information out of tools lacking adequate confidentiality and security protections
Florida Ethics Opinion 24-1 (2024) Generative AI permitted with confidentiality protection, output verification, and honest billing
New York NYSBA AI Task Force Report (2024) Existing rules govern; declined to mandate client consent for AI use
D.C. Ethics Opinion 388 (2024) Competence includes understanding the technology; protect confidences in prompts; bill actual time
Texas Opinion 705 (2025) Basic tech competence; protect confidential information; verify outputs; no billing for AI-saved time

California proposed AI-focused rule amendments in May 2026, so confirm the current status there.

A 5-line firm AI policy you can adopt today

  1. No client names, client facts, or client documents ever enter a consumer AI tool.
  2. Client work runs only on the firm’s business-tier account with training disabled, or on a legal-specific zero-retention tool.
  3. A lawyer verifies every citation and factual claim in AI-assisted work before it leaves the firm. (Mata v. Avianca: $5,000 in sanctions for six fabricated cases.)
  4. Before client information goes into any self-learning tool, the client gives informed consent, per ABA Opinion 512.
  5. We bill actual time. Hours the tool saves are the client’s savings, not ours.

Adopt it, circulate it, and you are ahead of most firms. Deciding which tier-2 or tier-3 tools fit your practice, and which workflows justify them, is the harder call. That is the work of an AI opportunity assessment, and the same gate logic runs through our broader guide to AI for law, CPA, and agency firms. CPAs face a parallel gate under IRC §7216, covered in our guide to AI for CPA firms. We sell no software and take no commissions, so the tier a tool lands in is the tier it earns.

Bottom line: ChatGPT is safe for legal work only above the consumer tier. Consumer accounts can retain and train on chats, which cost a defendant privilege in U.S. v. Heppner (S.D.N.Y. 2026). Business tiers with training off, and zero-retention legal tools like CoCounsel or Harvey, are built for client work, provided you verify outputs, bill honestly, and get informed consent where Opinion 512 requires it.

This article is general information, not legal advice. Consult your own counsel and your state bar’s guidance.

Sources