Mark R. Osherow, Esq.

Artificial intelligence is a threat to privacy rights, but not simply because it collects more information. Its deeper threat is doctrinal. AI changes what counts as a privacy injury. Traditional privacy law often focused on collection, disclosure, and misuse of identifiable information. AI shifts the problem toward inference, aggregation, prediction, and replication, which are extremely difficult to detect. A system may learn intimate facts without a direct disclosure, generate a synthetic substitute for a person, or affect a person through automated scoring and categorization. Whether these are theoretical or real concerns, will be a subject for the future, but they are certainly worth considering.
The best doctrinal starting point remains Carpenter v. United States, 585 U.S. 296, 310–13 (2018), where the Supreme Court held that historical cell-site location information is so revealing that government access generally requires a warrant, emphasizing that such records can disclose the “privacies of life.” Although Carpenter is a Fourth Amendment case rather than an AI case, its logic maps onto the AI era because AI systems are built to combine ordinary digital fragments into encyclopedic portraits.
That logic is visible in civil privacy doctrine as well. In In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589, 601–05, 611–15 (9th Cir. 2020), the Ninth Circuit held that users plausibly alleged privacy harms where Facebook allegedly tracked their browsing activity after logout, compiled the data into personal profiles, and monetized the resulting information. The Ninth Circuit specifically treated the alleged breadth and hidden nature of the tracking as relevant to whether users had a reasonable expectation of privacy. The importance of In re Facebook for AI is that it treats large-scale, mostly invisible behavioral collection as legally significant precisely because it enables profile-building. That is the bridge from ordinary tracking doctrine to AI-driven inferential privacy.
Biometric privacy cases make the AI problem even clearer. In Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, ¶¶ 31–34, 129 N.E.3d 1197, 1206–07 (2019), the Illinois Supreme Court held that a person may be “aggrieved” under the Illinois Biometric Information Privacy Act even without alleging some additional consequential injury, because an invasion of a legal right can itself suffice. In Cothron v. White Castle System, Inc., 2023 IL 128004, ¶ 2, 216 N.E.3d 918, 921 (2023), the same court held that a separate claim accrues each time a private entity scans or transmits biometric information in violation of the Act. In Patel v. Facebook, Inc., 932 F.3d 1264, 1272–75 (9th Cir. 2019), cert. denied, 140 S. Ct. 937 (2020), the Ninth Circuit held that alleged violations of BIPA involving Facebook’s face-template system were concrete enough to satisfy Article III standing. But in Zellmer v. Meta Platforms, Inc., 104 F.4th 1117, 1121–31 (9th Cir. 2024), the Ninth Circuit affirmed dismissal of a BIPA § 15(a) claim for lack of standing and concluded that Meta’s “face signatures,” on the record before it, were not biometric identifiers or biometric information under BIPA. Taken together, these cases show both the seriousness of potential AI-enabled biometric harms and the continuing doctrinal instability over standing, statutory scope, and technological classification.
Federal standing doctrine remains one of the sharpest limits on privacy suits. In Spokeo, Inc. v. Robins, 578 U.S. 330, 339–41 (2016), the Supreme Court held that Article III requires a concrete injury even when a statute creates a private right of action. In TransUnion LLC v. Ramirez, 594 U.S. 413, 425–26, 442–43 (2021), the Court sharpened the point: “No concrete harm, no standing,” and “only those plaintiffs who have been concretely harmed by a defendant’s statutory violation may sue” in federal court. AI privacy harms are often diffuse, predictive, or risk-based rather than immediately tangible. The standing problem, then, is not just procedural. It is structural: AI can produce serious dignity and autonomy harms that do not always fit neatly into older judicial categories of injury.
There is a related tension between public availability and privacy harm. In hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180, 1187–89, 1197–1201 (9th Cir. 2022), the Ninth Circuit held, after remand from the Supreme Court, that Van Buren v. United States, 593 U.S. 374 (2021), reinforced hiQ’s argument that scraping data from the public-facing portions of LinkedIn likely did not violate the Computer Fraud and Abuse Act (CFAA). In Van Buren, 593 U.S. at 391–94, the Supreme Court construed “exceeds authorized access” narrowly and adopted the now-familiar “gates-up-or-down” approach. The Ninth Circuit in hiQ then reasoned that public websites have “erected no gates to lift or lower in the first place.” These are not classic privacy-rights decisions, but they are indispensable to AI privacy analysis because they show why “public” data can still generate profound privacy concerns once scraped, aggregated, and modeled at scale. The extent to which these profound privacy concerns, actually result in injury such that the average consumer suffers actual harm is yet to be determined.
The newest and perhaps most important privacy problem is the privacy of AI prompts themselves. United States v. Heppner, No. 25 Cr. 503 (JSR), memorandum at 7–10 (S.D.N.Y. Feb. 17, 2026), is the leading current case. Judge Rakoff held that a criminal defendant’s exchanges with Anthropic’s Claude were not protected by the attorney-client privilege and were not protected by the work-product doctrine on the facts before him. The court reasoned, first, that Heppner had “no reasonable expectation of confidentiality” in his communications with Claude in light of the platform’s privacy policy and the fact that he had disclosed the equivalent of his notes to a third party. Second, the court held that Heppner was not communicating with Claude for the purpose of obtaining legal advice from a lawyer; Claude itself disclaimed providing legal advice. Third, the court held that documents not privileged when created do not become privileged merely because they are later shared with counsel, citing Gould, Inc. v. Mitsui Mining & Smelting Co., 825 F.2d 676, 679–80 (2d Cir. 1987). On work product, the court relied on United States v. Nobles, 422 U.S. 225, 238 (1975), and In re Grand Jury Subpoenas Dated March 19, 2002, and August 2, 2002, 318 F.3d 379, 383–85 (2d Cir. 2003), to emphasize that the doctrine protects materials prepared by or at the behest of counsel in anticipation of litigation and exists chiefly to shelter counsel’s mental processes. Because Heppner used Claude “on his own volition,” the court held that he was not acting as counsel’s agent when he created the materials. Note that commentators and other courts are beginning to analyze Heppner, with some finding it outright wrong.
Heppner is important because it treats public-model prompting as a confidentiality problem, not just a productivity question. It also carefully limits itself. Judge Rakoff expressly suggested that the result might be different if counsel had directed the client’s use of Claude in a way analogous to an agent relationship, citing United States v. Adlman, 68 F.3d 1495, 1498–99 (2d Cir. 1995), and United States v. Kovel, 296 F.2d 918 (2d Cir. 1961). He also distinguished Shih v. Petal Card, Inc., 565 F. Supp. 3d 557 (S.D.N.Y. 2021), describing Shih as a case involving communications with a person who was then the plaintiff’s lawyer and later her husband, rather than self-initiated exchanges with a consumer AI platform. So Heppner should not be overstated. It is not a categorical holding that all AI prompts are unprotected. It is a fact-specific but highly consequential warning that public-model use can defeat assumed confidentiality.
The counterpoint at least so far is Warner v. Gilbarco, Inc., No. 2:24-cv-12333-GAD-APP, ECF No. 94, at 10–13 (E.D. Mich. Feb. 10, 2026). There, the court denied a motion to compel the plaintiff’s “AI materials,” held that even if the information were discoverable it was protected work product, and rejected the argument that using ChatGPT necessarily waived work-product protection. The court reasoned that work-product waiver must be to an adversary or in a way likely to put the material in an adversary’s hands, citing In re Columbia/HCA Healthcare Corp. Billing Practices Litigation, 293 F.3d 289, 306 n.28 (6th Cir. 2002), and United States v. American Telephone & Telegraph Co., 642 F.2d 1285, 1299 (D.C. Cir. 1980). It also stated that “ChatGPT (and other generative AI programs) are tools, not persons,” and emphasized that defendants had no evidence the plaintiff uploaded confidential protective-order material to an AI platform. The court further characterized the requested materials as the plaintiff’s “internal analysis and mental impressions.” Properly read, Warner does not establish that all prompt/response materials are protected. It does show that, on its facts, AI-assisted drafting was treated as protected work product rather than waived material.
These cases together make the central point. AI threatens privacy rights because it expands surveillance into inference, identification into replication, and drafting into disclosure risk. Carpenter and In re Facebook show why aggregated data can be deeply revealing. Rosenbach, Cothron, Patel, and Zellmer show that biometric extraction is both legally significant and doctrinally unstable. Spokeo and TransUnion show that many privacy wrongs still face a remedy bottleneck in federal court. hiQ and Van Buren show why public accessibility does not eliminate privacy concerns in an era of scraping and modeling. And Heppner and Warner show that the privacy of AI prompts depends on the exact relationship among user, lawyer, platform, and waiver doctrine. In that sense, AI is not merely a threat to privacy because it “uses data.” It is a threat because it changes what privacy is: no longer just secrecy, but also control over inference, identity, and legally cognizable exposure.
Index
For aggregation, longitudinal surveillance, and inferential privacy: Carpenter v. United States, 585 U.S. 296 (2018); In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589 (9th Cir. 2020).
For standing and remedies in statutory privacy suits: Spokeo, Inc. v. Robins, 578 U.S. 330 (2016); TransUnion LLC v. Ramirez, 594 U.S. 413 (2021).
For biometrics and AI-enabled identification: Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, 129 N.E.3d 1197; Cothron v. White Castle System, Inc., 2023 IL 128004, 216 N.E.3d 918; Patel v. Facebook, Inc., 932 F.3d 1264 (9th Cir. 2019), cert. denied, 140 S. Ct. 937 (2020); Zellmer v. Meta Platforms, Inc., 104 F.4th 1117 (9th Cir. 2024).
For public-data scraping and the limits of CFAA “authorization”: hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022); Van Buren v. United States, 593 U.S. 374 (2021).
For AI prompt privacy, privilege, and work product: United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026); Warner v. Gilbarco, Inc., No. 2:24-cv-12333-GAD-APP, ECF No. 94 (E.D. Mich. Feb. 10, 2026). The doctrinal support cases expressly invoked in that discussion include United States v. Mejia, 655 F.3d 126 (2d Cir. 2011); United States v. DeFonte, 441 F.3d 92 (2d Cir. 2006) (per curiam); Gould, Inc. v. Mitsui Mining & Smelting Co., 825 F.2d 676 (2d Cir. 1987); United States v. Nobles, 422 U.S. 225 (1975); In re Grand Jury Subpoenas Dated March 19, 2002, and August 2, 2002, 318 F.3d 379 (2d Cir. 2003); United States v. Adlman, 68 F.3d 1495 (2d Cir. 1995); United States v. Kovel, 296 F.2d 918 (2d Cir. 1961); Shih v. Petal Card, Inc., 565 F. Supp. 3d 557 (S.D.N.Y. 2021); In re Columbia/HCA Healthcare Corp. Billing Practices Litigation, 293 F.3d 289 (6th Cir. 2002); and United States v. American Telephone & Telegraph Co., 642 F.2d 1285 (D.C. Cir. 1980).

