IoniumMEMOS

MEMO · AUGUST 2026

Whose system, whose terms.

Most people assume sensitive information carries its protection with it — that because something was meant to stay private, it will. Institutions know otherwise. A trade secret, an NDA, regulatory confidentiality, a family’s expectation of discretion: every one of these depends on the information having been handled in a way consistent with the protection being claimed. The protection lives in the structure. AI tools are testing that principle in every kind of organization right now, and a federal ruling this year showed the mechanics with unusual clarity.

In February, Judge Jed Rakoff of the Southern District of New York decided United States v. Heppner. The defendant had used a consumer chatbot to think through matters that later became the subject of a federal prosecution, and the FBI seized roughly thirty-one of those conversations. He argued they deserved the protection a conversation with a lawyer would get. The court said no: not with counsel, not at counsel’s direction, and conducted in a consumer service outside any relationship the law protects. The chats could be used against him.

Read carefully, the ruling is narrower than the alarm it set off. The court did not hold that using AI destroys legal protection. It held that protection never attached, because of what the tool was and how it was used. His intention — to think privately — counted for nothing. What counted was whose system held the conversation, whose terms governed it, and at whose direction it happened.

Take away the courtroom and the same reasoning reaches any organization with information worth keeping close. An investor holds deal material under NDAs that assume controlled handling. A business has client information under contract, and its own edge — the models, the documents, the correspondence — whose trade-secret status depends on reasonable measures to keep it close. A family office exists so certain things never circulate at all. Whoever eventually tests the claim, whether a court, a counterparty, a regulator, or someone adverse who simply obtained the record, will ask the questions Rakoff asked. Whose system held this, on whose terms, at whose direction.

What keeps this from being theoretical is that chat logs are records, and organizations are accumulating them without ever deciding to. Every prompt typed into a consumer tool is a document held by a third party, on that party’s terms, reachable by legal process the organization does not control. Thinking that used to happen out loud, or on a legal pad, now leaves a transcript. An organization that cannot say which tools its people use is collecting facts it has not chosen — and records get read, eventually, by people with adverse interests.

What follows is not dramatic. Find out which tools are actually in use; honest inventories usually contain surprises. Keep protected matters out of consumer services — not because those services are malicious, but because they sit outside every structure that professional and commercial protection depends on. Where these tools touch sensitive work, arrange the facts on purpose: an environment the organization controls, terms someone has actually read, use someone has actually directed. No guarantee comes with any of this; a controlled system gives you a different set of facts, not an automatic win. But the questions can be answered in advance, by design, at leisure — or afterward, under compulsion. The ruling is mostly advice about which to prefer.

The opinion is United States v. Heppner, S.D.N.Y., February 17, 2026 (Rakoff, J.). Analysis: Covington, Inside Privacy.