AI Compliance Starts Before the Prompt Is Sent
Before an AI system generates an answer, a compliance decision may already have been made.
Someone decided what information to give the system. That decision deserves more attention.
A recent U.S. federal court decision illustrates why.
In United States v. Heppner, a criminal defendant used the public version of Claude while preparing materials relating to an ongoing criminal investigation. Some of the information entered into the system had come from discussions with his lawyers.
The court held that 31 AI-related documents were protected by neither attorney-client privilege nor the work-product doctrine. The decision was fact-specific. It does not mean that using AI automatically destroys legal privilege.
But it highlights a broader compliance issue:
A prompt can also be an information-handling decision.
The question is not only:
“Is this information confidential?”
A broader question may be:
“Am I authorized to give this information to this AI system?”
That authorization may depend on more than internal policy. It may also involve legal duties, contractual restrictions, professional obligations, the terms governing the AI system, and the safeguards surrounding its use.
The question becomes particularly important when AI use involves:
→ Confidential business information
→ Personal or customer data
→ Trade secrets and proprietary material
→ Legally privileged information
→ Credentials and security-sensitive information
→ Information subject to contractual restrictions
This does not mean these categories can never be used with AI.
The answer may depend on the AI system, deployment model, purpose, contractual terms, security controls, organizational policy, and applicable law.
That is why an approved-tools list alone is not enough.
Organizations also need practical guidance explaining:
What information may be used with which AI systems, for which purposes, and under what safeguards?
Employees should not have to interpret complex privacy, confidentiality, security, contractual, and legal requirements every time they open an AI tool.
Compliance should help make those boundaries clear before the interaction happens.
Human review of AI outputs remains important. But by the time an output reaches a reviewer, one important compliance decision may already have been made.
AI compliance starts before the prompt is sent.
Source: United States v. Heppner, 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026)