216.696.8700

When ChatGPT Joins the Conversation: AI Access to Your Text Messages and the Attorney-Client Privilege

October 1, 2026
NCAA

If you text your lawyer, you probably assume the conversation stays between the two of you. A new ChatGPT feature is a reason to check that assumption.

On August 20, 2026, OpenAI released an Apple Messages plugin for the ChatGPT desktop app on Mac. Once a user installs it and grants the required permissions, ChatGPT can search the user’s iMessage, SMS, and RCS history, summarize conversations, draft replies, and send messages on the user’s behalf. The plugin is available across ChatGPT plans, including consumer accounts, and works through ChatGPT Work and Codex on Apple Silicon Macs.

The feature is convenient, but it also puts a third party in a position to read communications that were never meant for anyone but the sender and the recipient, including communications with counsel. The plugin raises a question most clients have never had to consider: can the way you store or manage a privileged text message cost you the privilege?

The Privilege, Briefly

The attorney-client privilege protects confidential communications between a client and a lawyer made for the purpose of obtaining legal advice. Upjohn Co. v. United States, 449 U.S. 383, 389 (1981). Its purpose is to encourage clients to speak candidly with counsel, and confidentiality is the price of the protection. A communication that the client voluntarily shares with someone outside the privileged relationship generally loses the privilege, because the client can no longer claim it was meant to stay confidential.

Ohio law adds a wrinkle to that general rule. The privilege for direct attorney-client communications arises under R.C. 2317.02(A), and the Ohio Supreme Court has held that the statute supplies the exclusive means of waiving it: the client either expressly consents or voluntarily reveals the substance of the communication in a nonprivileged context. Jackson v. Greger, 110 Ohio St.3d 488, 2006-Ohio-4968, paragraph one of the syllabus; State v. Brunson, 2022-Ohio-4299, ¶ 2. Whether handing a privileged text to an AI tool amounts to “voluntarily revealing” it in a “nonprivileged context” is a question no Ohio court has answered, as far as we are aware. The federal decisions discussed below suggest how the argument has been interpreted by other courts.

What the Plugin Actually Does

The technical details matter, because they will shape any privilege fight. According to OpenAI, the plugin runs locally on the Mac, does not build an index of the user’s message history, and reads a conversation only when the user asks ChatGPT for something that requires it. Simply installing the plugin does not send texts to OpenAI.

The exposure comes at the next step. When a user asks ChatGPT to “summarize my texts with my lawyer about the lawsuit,” the content of that thread is pulled into the ChatGPT conversation. ChatGPT desktop conversations are stored locally by default, but if the user’s conversations sync to the cloud, the message content follows OpenAI’s standard retention policies and may inform the memories ChatGPT stores about the user. On a consumer account, that content is then governed by a privacy policy that permits OpenAI to retain it, review it for safety and abuse monitoring, use it to improve its models unless the user opts out, and disclose it in response to legal process.

Two other aspects of the plugin deserve attention. The person on the other end of the thread, including your lawyer, receives no notice that the plugin is active and has no way to opt out. And the plugin’s read access is not limited to recent messages; it extends to whatever Messages history is stored on the Mac, which for many users spans years.

What Courts Have Said So Far

Three federal decisions this year addressed whether a client’s use of consumer AI waives privilege or work-product protection. The three courts split on the answer.

In United States v. Heppner, a criminal defendant used the consumer version of Anthropic’s Claude to analyze information he had received from his lawyers and generated dozens of documents he later shared with his defense team. No. 25 Cr. 503 (S.D.N.Y. Feb. 2026). Judge Rakoff held that neither the privilege nor the work-product doctrine protected them. The AI tool was not a lawyer, the documents were not prepared at counsel’s direction, and the provider’s consumer privacy policy, which allowed it to collect inputs, train on them, and disclose them, defeated any reasonable expectation of confidentiality.

Warner v. Gilbarco, Inc. reached the opposite conclusion. No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026). A magistrate judge denied a motion to compel a pro se plaintiff’s ChatGPT materials, reasoning that they were prepared in anticipation of litigation and that ChatGPT is a tool, not a person, so using it is not a disclosure to a third party for waiver purposes. Morgan v. V2X, Inc. followed Warner on work product and rejected the argument that routing information through a third-party system automatically forfeits a privacy expectation. No. 25-cv-01991 (D. Colo. Mar. 30, 2026). The same court, however, amended its protective order to bar uploading confidential material to any AI platform whose provider is not contractually prohibited from training on inputs and restricted from third-party disclosure.

Two cautions apply here. Heppner is a district court opinion and Warner and Morgan are magistrate rulings, so none of the three binds an Ohio court. None of the decisions involved the precise scenario here: an existing, undisputedly privileged attorney-client exchange later exposed to AI. Warner and Morgan concerned the litigant’s own AI-assisted work, and Heppner involved documents the client created himself. The Apple Messages plugin presents a cleaner test case, because the underlying communication was privileged before the AI ever saw it.

Why This Feature Changes the Risk

Clients have always been able to forward a lawyer’s email or paste a screenshot of a text into ChatGPT. The difference now is that the plugin removes the deliberate step of copying, forwarding, or pasting the communication. A single request, “catch me up on everything I missed yesterday,” can sweep a privileged thread into an AI conversation without the client ever consciously deciding to disclose it. And under a Heppner-style analysis, the client’s expectation of confidentiality is measured against the provider’s terms of service, which on a consumer account give the provider broad rights to retain, review, and disclose whatever it reads.

The argument against waiver is real. Under Warner, ChatGPT is a tool rather than a third person; under Morgan, intermediary access does not by itself destroy confidentiality; and under Ohio’s statutory framework, a court would have to find that the client voluntarily revealed the communication in a nonprivileged context. A client who did not appreciate what the plugin would read has a plausible position. A plausible position, however, is not the same as a safe one, and no client wants the privilege decided by a judge, and the opposing party in your case will cite Heppner.

Practical Steps

For clients who communicate with counsel by text, the safest course is to keep AI tools away from those threads. Specifically, we recommend the following:

  • Do not install the Apple Messages plugin, or any comparable integration, on a device that contains communications with your lawyer unless you are using a business-tier account whose terms prohibit training on your data, restrict third-party disclosure, and permit deletion on request.
  • If the plugin is already installed, do not ask ChatGPT to read, summarize, or reply to messages in any thread with counsel.
  • Businesses should update device and acceptable-use policies so that employees may not authorize AI applications to access attorney-client communications without sign-off from legal and IT.
  • Tell your lawyer which AI tools have access to your messages and email. Counsel can adjust how sensitive advice is delivered.
  • If a privileged thread has already gone through ChatGPT, tell your lawyer rather than trying to sort out the consequences on your own. Counsel can evaluate what was exposed and what protections remain available.

For lawyers, the ABA’s Formal Opinion 512 makes clear that the duty to protect client information extends to understanding how generative AI tools handle data. That duty now includes asking clients what tools have access to the channels the lawyer is using to reach them.

Conclusion

Encryption protects a message in transit. Encryption does nothing, however, once the message arrives on a device where the recipient has invited an AI assistant to read it. Whether that invitation waives the attorney-client privilege is unsettled, and the early decisions cut both ways. Until courts provide clearer guidance, the prudent approach is to assume that what an AI tool can read, a third party can read, and to keep privileged communications out of its reach. Texting your lawyer remains as safe as it has always been; the risk arises only when a client grants an AI tool access to those threads.

For questions about protecting privileged communications, or for matters involving litigation or the potential for litigation, please contact Michael R. Cantu (mrc@kjk.com) and Josie F. Forney (jff@kjk.com).