Calyx Signal
Issue 02 · August 2026
A monthly read on where AI is actually landing for legal, tax, and financial practices — the rulings, rules, and shifts your clients will ask you about.
New here? Get the monthly brief in your inbox.
Subscribe →
Issues 02 · August 2026 01 · June 2026
The case we opened with in June has an ending. It is worse than the ruling, and the reason it's worse has nothing to do with artificial intelligence.
The Signal

The privilege log is what gave him away.

United States v. Heppner · S.D.N.Y. · privilege ruling Feb. 17, 2026 · verdict May 7, 2026

Issue 01 covered Judge Rakoff's holding that a defendant's exchanges with a public AI chatbot were not privileged. That was the legal question. Here is what happened next, and it is the part practitioners should carry.

On May 7, a federal jury convicted Bradley Heppner on all counts after a three-week trial. Prosecutors introduced his unprivileged AI prompts as evidence. Material he created while working through his own legal exposure, alone, on a consumer tool, was read to the jury that convicted him.

But the detail that should stop every practitioner is how the government found it in the first place.

The instrument that was supposed to protect it
  1. Defense counsel produced a privilege log. Standard practice. One entry described the material as artificial-intelligence-generated analysis conveying facts to counsel for the purpose of obtaining legal advice.
  2. That description is what flagged it. Prosecutors read the log, identified the entry, and moved to compel production.
  3. The court agreed the material was never privileged — so the log had catalogued, in writing, the existence of documents the defense could not protect.

The privilege log exists to shield material from disclosure. Here it functioned as an index. Nobody did anything improper; counsel logged what counsel is required to log. The failure happened months earlier, at a keyboard, before any lawyer was involved.

The honest read — and what actually changed since June

The headline version is still wrong. Rakoff applied settled doctrine to a narrow fact pattern: a party using a public, consumer tool, on his own volition, not at counsel's direction. Among the reasons the claim failed: the platform is not an attorney, its consumer terms permitted the provider to collect and share inputs and outputs, the defendant did not use it at counsel's direction, and the outputs did not reflect defense strategy.

The split has deepened rather than resolved. Courts in the Eastern District of Michigan and the District of Colorado declined to find waiver by civil litigants using public AI tools, treating the platforms as software rather than as adversaries. A Texas business court has weighed in. Every one of these decisions turns on the vendor's data practices — which is a fact about your stack, not a question you brief your way out of.

And in one Q1 protective-order decision, a federal court declined to permit an open AI tool and ordered that only closed AI tools could be used in the litigation. A court has now specified the architecture.

The conversation to have with clients: not "don't use AI." It's that anything they work through on a public tool exists, is discoverable, and cannot be retroactively protected by showing it to you afterward. The waiver happens at the keyboard.

Also on the radar

They bought the purpose-built legal AI. It didn't save them.

For litigators & managing partners

In Fletcher v. Experian (5th Cir. 2026), the sanctioned attorney had used vLex and Thomson Reuters CoCounsel — legal-specific platforms, not a consumer chatbot — and still filed fabricated quotations. The court's framing: generative AI may be new, but the existing sanctions rules are well equipped to handle it. Sanctions in these matters have escalated from roughly $5,000 in 2023 to over $55,000 in 2025, and the "the tool was responsible" defense has been rejected in multiple jurisdictions. Buying the right tool is not the control. Being able to show the review happened is the control.

A bankrupt company's internal email sold at auction for $10 million.

For every practice with a server

In the Spirit Airlines bankruptcy, Google won an auction for roughly 100 million emails, 500 million Teams messages, and more than 175,000 employee records dating to 1986, intended for AI model training. No breach, no leak — a trustee has a fiduciary duty to maximise the estate, and internal corporate communications now have a market price. Every AI policy governs the firm as a going concern; none of it binds a trustee. The question worth asking: what is on your server that you would not want sold? Not the client files — the deliberations.

Documents are now written to be read by machines.

For anyone who ingests an opposing party's file

A Connecticut court sanctioned a litigant who embedded hidden white-on-white instructions in his filings, aimed not at the judge but at any AI system that might later process them. Judge Spader analogised it to an ex parte communication — a channel the other side cannot see or answer. Days later, a venture investor found a machine-readable payload hidden in a pitch deck instructing diligence agents how to characterise the company. The technique is now documented in court filings, résumés, and investor materials. Treat every file you did not create as untrusted input, and screen it before anything reads it on your behalf.

Your quality-management evaluation is due December 15.

For CPA firms, including sole practitioners

SQMS No. 1 took effect December 2025, and the first required evaluation of the system must be completed by December 15, 2026. It reaches any firm performing engagements under AICPA standards — reviews, compilations, attestation — scaled to size, with no small-firm exemption. The AICPA's own practice aid notes the obvious: when a sole practitioner performs the evaluation, it is an evaluation of their own work. If you are the one evaluating your own system, the useful question is what evidence exists that you did.

The Signal, in one line

Every item this month is the same shape: a record that existed but pointed the wrong way, a control that was never a control, or an artifact nobody thought to keep. The technology question is settled enough. What is being decided now — in courtrooms, in bankruptcies, in standards — is who can prove what happened, and when they had to start writing it down.

Previous issue
Calyx Signal
Issue 01 · June 2026
The first issue — a federal judge in Manhattan answered a question no court had, and the answer should change how you talk to clients about AI.
This issue: a federal judge in Manhattan just answered a question no court had — and the answer should change how you talk to clients about AI.
The Signal

A client used a public AI tool. The court said his privilege was already gone.

United States v. Heppner · S.D.N.Y. · Judge Jed Rakoff · opinion issued Feb. 17, 2026

In what the court itself called a question of first impression nationwide, Judge Rakoff ruled that a criminal defendant's written exchanges with a public generative-AI platform were not protected by attorney-client privilege or the work-product doctrine — and that handing those exchanges to his lawyers afterward did nothing to protect them.

The facts are simple enough to make every practitioner wince. The defendant used a consumer AI chatbot on his own to work through his legal situation. Investigators later seized the device. He claimed the material was privileged legal strategy. The government disagreed, and the court sided with the government.

The court's reasoning
  1. The AI is not a lawyer. Privilege protects communications between a client and an attorney. A chatbot is neither, so no attorney-client relationship existed — and that alone disposed of the claim.
  2. No reasonable expectation of confidentiality. The platform's consumer privacy terms disclosed that inputs and outputs could be used to train the model. Voluntarily handing information to a third party on those terms is not confidential.
  3. He wasn't acting at counsel's direction. The defendant used the tool on his own initiative, and the outputs did not reflect defense counsel's strategy.
  4. Privilege cannot attach retroactively. It must exist at the moment of the communication. Routing already-disclosed material through an attorney later cannot manufacture protection after the fact.

That last point is the one worth sitting with. The instinct — "I'll just have my attorney review it" — does not cure the problem. The waiver happened the moment the words went into the public tool.

Postscript. On May 7, 2026, a federal jury convicted Heppner on all counts after a three-week trial, and prosecutors introduced the unprivileged AI prompts as evidence. Issue 02 covers how the government found them →

Before you forward the alarmist version — the honest read

The headlines say "AI destroys privilege." The opinion does not. Rakoff applied settled privilege doctrine to a specific fact pattern: a party using a public, consumer tool, on his own volition, not at counsel's direction. He expressly left open whether a non-public or enterprise tool, or use directed by counsel, would come out differently.

And there's already a split: an Eastern District of Michigan court reached the opposite result for a pro se litigant on ChatGPT, treating the AI as a drafting tool rather than a third party. So the law is unsettled — but the practical lesson is not. The dividing line the court drew was governance: public, untracked, no confidentiality, no control — versus private, directed, and controlled.

The takeaway for your practice: your clients are almost certainly using public AI tools to work through legal, tax, and financial questions right now — and creating discoverable records while they do it. The conversation to have isn't "don't use AI." It's "where, and under whose control."

Also on the radar

The patent office has already been read — by everyone's AI.

For IP & technology counsel

The old bargain of patent and trademark protection is disclosure: you publish to protect. But public registries are now training data — the entire IP record has been ingested by models that can search, recombine, and approximate it instantly. For some clients, the calculus is shifting toward proving authorship and provenance privately rather than disclosing first. Worth raising with clients who assume "file it" is the only path to protection. Full analysis →

Regulators want AI decisions to be explainable — in writing.

For wealth, insurance & advisory practices

The NAIC's model bulletin on AI use by insurers has been adopted in roughly two dozen states, with a multi-state evaluation-tool pilot underway in 2026. New York, Colorado, and California have layered on their own requirements. The throughline: when an AI system contributes to a decision about a person — underwriting, eligibility, advice — the firm must increasingly be able to document and explain how. "The model decided" is not becoming a defense. It's becoming a liability. More field notes →

The Signal, in one line

AI is no longer just a productivity question. Across privilege, IP, and regulation, the same principle is hardening into law at once: a decision or a record touched by AI now has to be provable — who did it, under what control, with what expectation of confidentiality. The firms that treat that as a discipline, not an afterthought, will be the ones whose clients don't get surprised.

Subscribe to Calyx Signal

One email a month. The AI rulings, rules, and shifts that matter to legal, tax, and financial practices — and one practitioner's read on what they mean. No noise, no pitch. Forwardable.

You'll get Calyx Signal once a month. Nothing else. Unsubscribe anytime by replying. This isn't legal, tax, or financial advice — just the signal, and one practitioner's read.
You're on the list. Watch for the next issue of Calyx Signal. In the meantime, this issue is yours to forward.