← AIM · contents
Chapter 14

Ask What Could Go Wrong

What you type into an AI chatbot isn't privileged. Not now, and on the court's reasoning, not ever.

In February 2026, a judge in New York answered a question he believed no court had been asked before.

A man had been indicted. Securities fraud, wire fraud, and more. After he received the grand jury subpoena, and after it was clear he was the target of the investigation, he did something that will feel completely ordinary to you.

He opened an AI chatbot and started thinking out loud.

He worked through what the government might charge. He drafted what he might argue. He talked himself through his own situation, the way you would with a colleague you trusted, except there was no colleague. His own lawyer later confirmed nobody had told him to do it. In the court's phrase, it was done “without any suggestion from counsel that he do so.”

Then the FBI executed a search warrant at his home and seized, among everything else, 31 documents containing those conversations.

His lawyers argued they were privileged. Confidential. The sort of thinking a person does preparing a legal defence, protected the way notes to your own lawyer are protected.

Judge Jed Rakoff wrote that this appeared to be “a question of first impression nationwide.” Nobody had ever asked a court whether what you type into an AI chatbot is privileged.

His answer, in five words: “the answer is no.”

Why it was no, and why it applies to you

You are not under federal indictment. Stay with me anyway, because the reasoning is not about him.

The court gave two grounds, and the first disposed of the case on its own.

It is not a lawyer. Obvious once said, and yet nobody thinks about it while typing. The court went past the technicality, and this is the sentence to keep. Recognised privileges require “a trusting human relationship” with “a licensed professional who owes fiduciary duties and is subject to discipline.” And then:

“No such relationship exists, or could exist, between an AI user and a platform such as Claude.”

Not does not yet. Could not.

And it was not confidential. The court read the privacy policy the user had agreed to. It provides that the company collects data on inputs and outputs, uses that data to train the system, and reserves the right to disclose it to “a host of 'third parties,' including 'governmental regulatory authorities.'” Even without a subpoena compelling it.

Then the line that reaches past this one case, the court quoting another court. Users “do not have substantial privacy interests in their conversations with [a publicly accessible AI platform] which users voluntarily disclosed to the platform and which the platform retains in the normal course.”

Voluntarily disclosed. That's what your typing is, legally. Not private thinking that happens to occur in a text box. Disclosure, to a third party, retained in the normal course of their business.

I should be accurate about the limits, because this chapter is about not overclaiming. One district court, on privilege, in a criminal matter. It binds nobody elsewhere and doesn't say chat logs are public. But the court believed no one had answered the question before, and the reasoning was not narrow.

The same opinion notes, from published research, that more than half of American households now use these tools in some form, and that one platform alone is used by more than 800 million people a week.

Almost none of them know what that judge decided.

The second case

In January 2026, in the same district, another judge affirmed an order in a copyright case against an AI company.

The order requires production of twenty million conversations.

Not twenty million belonging to the parties. Twenty million belonging to ordinary people who had nothing to do with the lawsuit, had never heard of it, and were never asked.

Be precise about this one, because the version circulating is more alarming than the truth. The sample is de-identified, and a protective order limits who can see it. Your account name isn't attached, and a stranger can't go and read it. Though anything identifying that you typed into the conversation is still sitting inside it.

That still leaves the fact. Twenty million private conversations became discoverable material in litigation between other people, and every decision about them was made in rooms none of those twenty million were in.

The exposure isn't that somebody is reading your messages. It is that what happens to them is decided entirely by people who are not you, in proceedings you will never hear about.

The ten questions

None of these is technical. There's the point. Every one can be asked by somebody who's never written a line of code, and asking three of them will change how a room sees you.

1. Where does this go when I press enter? Which company, which country, which servers. Most people using a tool daily cannot answer this about the tool.

2. Is what I type used to train it? Usually a setting. Usually the default isn't the one you would choose. Almost nobody has looked.

3. How long is it kept, and who decides? Not what the marketing page implies. What the terms say, and whether the company can change them next quarter without telling you.

4. Under what circumstances would they hand it over? The privacy policy in that New York case answered this in advance, in writing, and everybody had agreed to it.

5. Whose account is it under? A personal account and a company contract are different legal objects with different terms. If your team is doing work in personal accounts, your organisation has obligations it doesn't know about.

6. What is the most sensitive thing already typed into it? Not hypothetically. Actually, by your team, last month. Almost no manager can answer this, and it is not a policy failure. Nobody built a way to know.

7. If we had to reconstruct how this was made, could we? Which question was asked, which system answered, what came back. If a regulator, an insurer or a client asks how a piece of work was produced, someone used AI and then edited it isn't an answer.

8. What happens if this tool disappears in six months? Companies retire products. If your process only works because one specific thing exists, that's a dependency, not a workflow.

9. What is the worst single output that could reach a customer? Not the likeliest. The worst. Then: what stands between that output and the customer, and is it a system, or is it somebody remembering?

That question has a failure mode worth guarding against, which is that you will answer it from whichever direction you were already worried about. Ask it seven ways instead; it takes a minute and it will find something the single question doesn't.

Emotional. Could this upset, offend or embarrass somebody. Legal. Could this create an obligation, a breach, or something quotable in a dispute. Financial. Could this cost money directly, or commit us to something. Relationship. Could this damage a connection we depend on. Timeline. Could this be late in a way that matters, or create a deadline we can't meet. Competitive. Does this hand anything useful to somebody we compete with. Information. Does this reveal something we did not intend to reveal.

Seven categories, most of which will be empty on any given piece of work. The value is entirely in the ones you wouldn't have looked at, and for most people that's the third and the seventh.

10. Who is accountable when it is wrong? If the answer is the AI got it wrong, there's no answer, and everybody in the room already knows it.

Why asking these gets you into rooms

I want to be direct about the career mechanics, because that's what this book is for.

Senior people are worried about this and most can't articulate why. They sense that something is being adopted fast, that the risk is real, and that everyone briefing them is either selling something or explaining the technology instead of the exposure.

Walk into that meeting and ask question six. What is the most sensitive thing our team has already typed into one of these?

You have not claimed expertise. You haven't needed any. You asked the question the room was circling, and you will be the person they think of next time, because you did the thing nobody else did, which was to come at it from the direction of what goes wrong.

There's the whole move. Available to you today, and it costs nothing.

The part where I stop making it sound solvable

The instinct after reading this is to go and find the safe tool. The compliant one, with the right badges.

Wrong move, and it's the most common one.

Every one of these tools is a product, made by a company that will change, be sued, be acquired, or update its terms. Picking the current best one is a decision with a shelf life, and it puts your protection in the hands of somebody whose incentives aren't yours.

The better move is the boring one. Change what you send. Not whether you use it. What it receives.

If the sensitive part never leaves, you don't have to trust anybody's terms of service about the sensitive part. That is the only protection in this chapter that doesn't depend on a company continuing to behave well.

And be honest about what it buys, because the overclaiming version of this argument is its own kind of failure. It reduces what leaves your control. It doesn't erase your obligations, doesn't make you compliant, and doesn't replace somebody reading the output before it goes out. Reducing what leaves your control is where every privacy framework starts, and it is a thing you can explain to a nervous client in one sentence.

There is a working rule inside it, smaller than a policy. If you would not be comfortable with the sentence you are about to type appearing in a legal filing with your name on it, do not type it. Rewrite it so the identifying part isn't there. Four seconds, and that is the whole discipline.

Here is what four seconds looks like.

You are about to type this:

Draft a firm but fair note to Sarah Chen at Meridian about the overdue invoice, reference 7741-B, for $240,000, and mention that her team missed the same deadline in March.

You type this instead:

Draft a firm but fair note to a long-standing client contact about an overdue six-figure invoice, and mention that their team missed the same deadline earlier this year.

Read both. The second one produces a letter you can use without changing a word of the argument. None of the useful instruction was in the name, the reference number, or the amount. You put those back yourself, in about ten seconds, in the document where they belong.

That is the whole idea and it's smaller than people expect. The identifying details are almost never the part doing the work. They feel essential because they're what the task is about, but the tool isn't writing about Sarah Chen. It is writing a firm but fair note about an overdue invoice, and it will do that just as well without ever learning who she is.

Try it once on something real and you will notice the same thing everybody notices: the output doesn't get worse.

Why a policy will not save you

One more thing worth understanding, because it explains why every attempt to fix this with a memo fails.

Most organisations respond to all of the above by writing a rule. Do not put client information into AI tools. It goes in the handbook. Everybody nods.

Then people use the tools anyway, on their phones, on personal accounts, with no controls at all, because the rule made the tools useless for the work that actually matters and the work still has to get done.

That is not a failure of policy. It is a failure of design.

A rule that forbids the only version of the task worth doing does not get followed. It gets routed around, invisibly, by people who aren't being defiant. They are being practical, and now the same exposure exists with none of the visibility.

The fix is not a stricter rule; it is changing what gets sent, so the rule becomes unnecessary. When the sensitive part never leaves in the first place, there's nothing to forbid, and the working instruction flips from do not paste the important stuff to paste it, it's handled.

That flip is what brings the real work into scope. And the real work is the only work that made any of this worth adopting.

Nobody decided anything

There is one failure mode in all of this that I want you to see clearly, because it is the one that actually happens and it looks nothing like negligence.

I know of a meeting-transcription tool, built by a team who had already written redaction layers into their other products, that went out without one.

Meeting transcripts are among the most sensitive text any organisation produces. Personnel discussions, commercial terms, things said out loud that nobody would ever write down.

Nobody argued for leaving the protection out. Nobody raised it and was overruled. There is no meeting where a decision was taken.

The thing got built for what it does. The privacy layer was somebody's job later. And later does not arrive on its own.

Nobody decided to ship it without protection. Nobody decided anything.

Which is exactly why the ten questions have to be asked out loud, by a person. Every one of them is a decision that will otherwise be made by default, and defaults are not decisions. They are just what happened while everybody was busy.

The one to ask tomorrow

If you take one thing from this chapter, take question six, and ask it about yourself before you ask anybody else.

What's the most sensitive thing you have personally typed into one of these tools?

You will remember something. Everybody does. A client name, a salary figure, a contract clause, a paragraph about a colleague that you would never have put in an email.

It is still there. It was, in the words of a federal judge, voluntarily disclosed, and retained in the normal course.

Nothing bad has happened. Which isn't the same as nothing being at risk, and you now know the difference, which is more than almost anyone you work with knows.

Which leaves you somewhere strange; you are doing careful work now. Checked properly, scored honestly, produced safely.

All of which protects you.

---

### ▪ DO THIS > > Ask yourself the question you are about to ask the room: what is the most sensitive thing already typed into one of these? > > 1. What's the most sensitive thing you've personally typed into one of these tools? Sit with it rather than moving on. You'll remember something. > > 2. Go and look at two settings on the tool you use most: whether your inputs train it, and how long they're kept. Two minutes. > > 3. Rewrite one thing before you send it. The name becomes a long-standing client. The number becomes a six-figure invoice. Send only that version, and compare what comes back against what you already had. > > 4. Take one question into your next meeting. What's the most sensitive thing our team has already typed into one of these? Almost no manager can answer it. > > Steps 1 to 3 take ten minutes. Step 4 goes into your next team meeting. > > When the answer to step 1 frightens you: it has been disclosed. You may still be able to delete the record. Go and look, in the same settings as step 2. Then change what you type next week. > > You will know it worked when the outputs from step 3 come back the same, and you realise the identifying details were never doing the work.

---

None of which protects the company you work for, because while you were asking where your own typing goes, a great deal of law was quietly written about what your employer does with everybody else's.

Watch this chapter
A short illustrated film of Chapter 14. The narration is the author’s own words from the chapter. The animation, the voice and the score are AI-generated.
2,748 words