A Federal Judge Just Read a Man's AI Chats Into Evidence episode artwork

EPISODE · Jul 7, 2026 · 20 MIN

A Federal Judge Just Read a Man's AI Chats Into Evidence

from Tatsu’s Newsletter Podcast · host Tatsu Ikeda

In February 2026, a fraud defendant in the Southern District of New York did something that felt, at the time, entirely reasonable. He had received a grand jury subpoena. He knew he was a target. So he opened the consumer version of Claude and worked through his own legal exposure: what the government might have, what he could argue, where the facts cut against him.Judge Jed Rakoff ordered those documents produced to the prosecution.[1]The ruling was a question of first impression, and the reasoning was blunt. The AI is not a lawyer, so nothing the man typed into it was a privileged attorney-client communication. The provider's own terms of service defeated any reasonable expectation that the exchange was confidential. And because he acted on his own rather than at the direction of counsel, the work product doctrine did not protect it either. The tool he trusted to analyze his risk became the evidence against him.That case is not an outlier. It is the shape of things.Yesterday, a client asked me a simple question. Are my AI chats private? I spend most of my time at the intersection of technology, capital, and risk, and I expected to give a quick reassurance. Instead the honest answer turned out to be so alarming, and so poorly understood even by sophisticated people, that answering it properly became a practice.Today I am proud to introduce Chatham by THV (chatham.techhealthventures.com), the AI-governance and data-privacy practice of Tech Health Ventures LLC. Chatham helps private-capital principals understand exactly what their AI use exposes them to, on privacy and on legal discovery, and builds the governance to control it, working alongside their own lawyers. It is the productized version of that first alarming answer.This post is public. Share it with anyone whose AI chats contain things they would not want read aloud in a deposition.Rules Changed in 2026. Habits Did Not.Most people picture an AI chat as something between a private diary and a search query. It is neither. It is a written record, stored on someone else's servers, produced under someone else's policy, and increasingly reachable by courts and counsel. Here is what actually changed while everyone was busy being impressed by the technology.* AI chats are discoverable business records, and a court has said so. Heppner is the first federal ruling to say it plainly, but the logic is portable to any civil dispute, regulatory inquiry, or investigation: what you typed is a document, and documents get produced.* Providers can be compelled to hand over chats at scale. In the copyright litigation against OpenAI, a federal judge affirmed an order requiring the company to produce roughly twenty million de-identified ChatGPT conversation logs, overriding OpenAI's own objection that doing so would invade its users' privacy.[2] The privacy of the person typing is not the provider's priority when the provider is the one being sued.* Consumer AI keeps your chats, and can now hand them over. Anthropic's consumer tiers (Free, Pro, and Max) train on your conversations unless you turn that off, retain them for up to five years when training is on, and, under a policy effective July 8, 2026, permit disclosure to law enforcement on the company's own good-faith belief, without a court order.[3] Commercial and enterprise tiers are governed separately. This is not a knock on one company; it is the direction the whole consumer market is moving.* Connected AI is an exfiltration surface. The moment you link an AI tool to your email or your drive, through connectors or the emerging plumbing people call MCP, a single prompt-injection attack can quietly reach everything that connection can read. The convenience and the exposure are the same wire.* The folk remedies do not work. Incognito mode is still retained, commonly around thirty days. A VPN hides an IP address, not a logged-in identity. Deleting your chats and opening a fresh account does not purge the provider's copy. And once litigation is reasonably foreseeable, deletion stops being hygiene and becomes spoliation. It converts a privacy worry into a sanctions problem.The rules changed in 2025 and 2026. Most people's habits did not. That gap is the entire reason Chatham exists.Nobody Can Sell You Immunity From DiscoveryLet me be precise about what governance can and cannot do, because the distinction is the whole business.Nobody can sell you immunity from discovery, and anyone who claims to is selling you a sanctions motion. There is no product, no setting, and no clever deletion routine that makes a legitimate legal request go away. What exists instead is lawful, ordinary, and boring: minimizing what you needlessly create, keeping genuinely privileged material inside the channels where privilege actually attaches, and running defensible retention and legal-hold procedures so that when you are asked, you can answer cleanly rather than looking like you hid something.None of this is legal advice, and Chatham is not a law firm. It is governance and technical exposure work that makes your lawyer's job faster and your position defensible. The goal is not to beat discovery. The goal is to never be the easiest, most careless target in the room. That is the work, and it starts at chatham.techhealthventures.com.What Chatham DoesThe work runs as a ladder, and you can step off at any rung.Exposure Assessment. A fixed-fee diagnostic, roughly two weeks. We map every AI tool, account, and connector in use, trace where your sensitive data actually ends up, and deliver a written Exposure Report with a prioritized risk map. The report cleanly separates the governance findings, which are ours to fix, from the questions that belong with your lawyer.Governance Program. The build. An AI-use policy with real data tiers, a written information security program, a data-retention and legal-hold procedure, communications hygiene across every channel you actually use, and a counsel handoff pack so your attorney finalizes the legal layer from finished drafts instead of a blank page and a running clock.Ongoing advisory. AI providers rewrite their terms constantly, as the July 8 policy change illustrates. Chatham keeps your program current so last quarter's governance does not quietly expire.Everything is fixed fee, quoted before you sign. Never hourly. You will always know the number before the work starts.Why Chatham Is DifferentThe framing nobody else leads with. Consultancies sell "AI adoption for wealthy families." Law firms publish client alerts. Both are useful, and neither starts where you actually are. Chatham leads with the inverted, evidence-backed message: you are already exposed, here is precisely where, and here is the governed way out. When I scanned the market for anyone else planting a flag on that exact ground, I found it unclaimed.Not a law firm, on purpose. Chatham does the governance and technical work and hands every legal question to your own counsel, packaged and pre-briefed. There is no conflict with your existing lawyer. Your lawyer receives finished drafts to redline, not a new bill to open a new matter.We practice what we sell. The Chatham site stores no lead data anywhere. An inquiry exists only as two emails. There are no cookies, no trackers beyond an anonymous aggregate visit counter, and no third-party form vendors sitting quietly in the middle of your first confidential message. Sensitive drafting happens on local models. The privacy pitch is not marketing. It is the operating model.Fixed fees and boutique scale. You get a named advisor who read your file, not a rotating bench that re-learns your situation on your dime.Who It Is ForEmerging fund managers and syndicate leads. Single-family offices. RIAs and advisers. Angel investors. Founders holding sensitive cap tables. In short, anyone whose AI chats contain investor names, capital commitments, deal terms, valuations, or their own private legal worries. If you have ever pasted something into a chatbot that you would not want read aloud in a deposition, this is for you.What This Costs Everywhere ElseI will not quote Chatham's fees here, because the number belongs in a private conversation about your specific scope. But the market gives you the shape of it.Comparable fixed-scope privacy and compliance assessments start around eight thousand dollars and run far higher; published GDPR gap assessments are a useful public benchmark. Fractional chief information security officer and compliance-officer retainers are commonly quoted between fifteen hundred and ten thousand dollars a month. Law-firm review of the same ground runs at partner hourly rates, and much of that time is spent producing the very first drafts that Chatham's process hands to your counsel already written.The honest comparison is this. One Chatham engagement typically costs less than the billable hours a lawyer would spend just getting oriented in this space, and the deliverables arrive lawyer-ready. Chatham sits well below what this work costs anywhere else, without being cheap, because cheap is not what you want standing between your chat history and a subpoena.How to Reach MeThere is one path in: chatham.techhealthventures.com.The form asks four things: your name, your email, your role, and your single biggest concern. A real person, me, reads every request. If it is a fit, you receive a private booking link for a confidential call. You are covered by an NDA from first contact. There is no sales sequence, no drip campaign, and no junior associate assigned to warm you up.A federal judge has already demonstrated what happens when you treat a consumer AI like a private advisor. The delete button is not going to save the next person, and neither is a VPN. What works is knowing exactly what you have exposed and governing it before anyone asks. That is the entire job. If it is on your mind, start at chatham.techhealthventures.com.I write about technology, capital, and risk. Subscribe if you want the analysis that sits behind a practice like this.Notes[1] "United States v. Heppner." Harvard Law Review, March 2026. Judge Jed Rakoff of the Southern District of New York ruled on February 10, 2026 that documents a fraud defendant generated using the consumer version of Claude to analyze his own legal exposure were protected by neither the attorney-client privilege nor the work product doctrine, on three independent grounds: the AI is not a lawyer, the provider's terms defeated any expectation of confidentiality, and the defendant acted without counsel's direction. The first federal ruling of its kind.[2] "ChatGPT creator must turn over 20M chat logs in copyright litigation, federal judge says." ABA Journal, 2026. U.S. District Judge Sidney Stein affirmed a magistrate's order compelling OpenAI to produce a sample of roughly twenty million de-identified ChatGPT conversation logs to plaintiffs in the consolidated copyright litigation, rejecting OpenAI's argument that production would unnecessarily invade its users' privacy.[3] "Updates to Our Consumer Terms and Privacy Policy." Anthropic, June 2026. Anthropic's consumer tiers (Free, Pro, and Max) train on user conversations unless the user opts out, extend data retention to five years when training is enabled, and, effective July 8, 2026, permit proactive disclosure of user data to law enforcement based on the company's own good-faith belief without a court order; Enterprise, Team, and API accounts are excluded. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit tatsuikeda.substack.com/subscribe

Episode metadata supplied by the publisher feed · Published Jul 7, 2026

Embed this episode

NOW PLAYING

A Federal Judge Just Read a Man's AI Chats Into Evidence

0:00 20:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Tatsu’s Newsletter Podcast?

This episode is 20 minutes long.

When was this Tatsu’s Newsletter Podcast episode published?

This episode was published on July 7, 2026.

Can I download this Tatsu’s Newsletter Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!