When Your ChatGPT Logs Become Evidence Against You
A conversation with an AI chatbot is not a conversation with your lawyer. It is not privileged, it is stored, and prosecutors around the country are now pulling those logs into criminal files through warrants, subpoenas, and discovery orders. Courts are treating them like any other electronic record. If you are under investigation, the safest assumption is that anything you type into ChatGPT could one day be read aloud to a jury.

The Questions That Ended Up in a Murder File
In late August 2026, reporting by The Washington Post and CNN documented a sharp rise in AI chatbot logs surfacing in both civil and criminal cases. The example that traveled fastest came out of Florida. In a University of South Florida double-homicide prosecution, the arrest affidavit quotes what investigators say were the defendant’s own ChatGPT queries in the days before the victims disappeared.
According to the charging documents, the defendant allegedly asked the chatbot what happens when a body is placed in a garbage bag and left in a dumpster, and then asked how anyone would find out. He faces two counts of first-degree murder and, as of this writing, has not entered a plea. Those are allegations in a charging instrument, not proof, and he is presumed innocent. But the lesson for everyone else is simpler and colder. Those questions were sitting in a database, and the State went and got them.
There Is No AI Privilege
The law protects a short list of confidential relationships. What you tell your lawyer, your doctor, your spouse, or your clergy member is generally shielded from disclosure. An AI chatbot is on none of those lists. Courts are treating chatbot conversations the way they treat email, text messages, and server logs: as ordinary records that can be subpoenaed, searched under a warrant, and produced in discovery.
A federal judge has now said so directly. In United States v. Heppner, No. 25 Cr. 503 (S.D.N.Y.), Judge Jed Rakoff ruled on February 10, 2026, in a memorandum issued a week later, that a criminal defendant’s written exchanges with a generative AI platform were protected by neither the attorney-client privilege nor the work product doctrine. The court called it a question of first impression nationwide, and the answer was no. The privilege failed for three reasons. An AI platform is not a licensed professional who owes fiduciary duties and can be disciplined, so no attorney-client relationship exists or could exist. The exchanges were not confidential, because the platform’s own privacy policy told users it collects inputs and outputs, trains on them, and may disclose them to third parties including government regulators. And the defendant was not seeking legal advice when he typed. The work product claim failed as well, because the defendant ran the searches on his own and his lawyers had not directed him to. Handing the printouts to his attorney afterward did not help, since material that would not be privileged in the client’s hands does not acquire protection merely by being passed to counsel. As the court put it, the novelty of the technology does not exempt it from longstanding legal principles.
OpenAI’s own chief executive said the same thing in 2025, warning that people share deeply personal things with ChatGPT under no legal confidentiality at all. The litigation has borne that out. In the New York Times copyright case against OpenAI, a federal magistrate judge ordered the company in May 2025 to preserve essentially all ChatGPT output logs, including chats users had deleted. That order was lifted in October 2025, and OpenAI resumed its ordinary practice of purging deleted chats within about thirty days. But the episode proved two things that matter to a criminal defendant. First, a court can override a delete button. Second, the court later ordered roughly twenty million de-identified conversations produced in discovery, and reaffirmed that order in January 2026, reasoning that users had voluntarily disclosed those conversations to the platform, which retains them in the normal course of its business. Deleting a chat is a housekeeping setting, not a legal shield.
How a Chat Log Actually Gets into Your Case
There are two main routes.
The first is your own phone. The ChatGPT app keeps your history, and a modern forensic extraction of a seized phone pulls that history along with everything else. Police still need lawful access to the device. The Supreme Court held in Riley v. California that officers generally need a warrant to search a phone seized during an arrest, and we cover the current fight over device access in our post on whether police can unlock your iPhone. Once they are lawfully inside the phone, the app data is right there.
The second is the provider. Investigators can serve OpenAI directly. As a general matter, the content of stored communications is obtained with a warrant, while subscriber and transactional records can be sought with a subpoena or court order. This is the same third-party-records terrain the Supreme Court has been reshaping in cases like Carpenter and, this year, Chatrie, which we break down in our explainer on geofence warrants. The doctrine is unsettled, which is exactly why it is worth litigating rather than conceding.
Either way, a log does not authenticate itself. Someone has to tie the account to the person, line up the timestamps, and rule out an edited or selectively exported copy. That authentication step is a place where a forensically trained defense pushes back, and our firm’s digital forensics work, led by Douglas Huff, exists for exactly this kind of record.
This Is Bigger Than One Case
The Florida prosecution is not an outlier. Federal prosecutors cited a ChatGPT conversation in the arson case tied to the Palisades fire in Los Angeles. A Snapchat AI conversation was central evidence in a 2024 murder trial in Virginia. Investigators in South Korea built an upgraded murder case around a suspect’s chatbot search trail. One cybersecurity lawyer quoted in the coverage called chatbot histories a “treasure trove” for law enforcement. The technology is new. The instinct behind it, that people put their intentions in writing, is very old.
The Flip Side: If the State’s Expert Used AI, You Can Ask What They Typed
The same logic that turns your chats into evidence cuts the other way when the State leans on software. In May 2026, a federal court in Connecticut became the first to squarely address whether an expert witness’s AI prompts are discoverable. In Conservation Law Foundation v. Shell Oil, No. 3:21-cv-00933 (D. Conn.), Magistrate Judge Farrish held that the AI tool and the prompts the expert fed it were part of her methodology and were, for that reason, fair ground for discovery. Be precise about what happened next, because the trade-press write-ups were not. The court did not order the prompts handed over. It granted a motion to compel and directed the plaintiff to revise its sworn interrogatory and document responses under Rules 33 and 34 to disclose any AI prompts the expert had used, or to state under oath that none existed, with Rule 37(b) sanctions available if that proved false. The plaintiff had maintained that the expert used only search terms. That is a disclosure and verification order, not a production order, and a brief that describes it the other way will be corrected.
Two honest caveats. That was a civil environmental case, not a criminal one. And the order is not final even in its own case: on June 3, 2026, Judge Oliver stayed it on a Rule 72(a) objection, briefing closed on June 29, and nothing has been decided since. One magistrate judge, stayed, is not settled law. But the reasoning is what matters, and the argument the opposing party made for the prompts is the same argument a defense lawyer makes. Without the inputs, you cannot test whether the tool excluded relevant material, introduced bias, or simply made something up. Say the next part out loud before relying on any of this. No Texas court has published a decision on whether an expert’s AI prompts are discoverable, and neither has any federal criminal court. Not one. The reasoning from a civil discovery ruling travels, and the argument is worth making, but it is persuasive reasoning rather than authority, and presenting it as more than that is how a good motion gets embarrassed. We cover that broader problem of trusting digital forensic output in our post on whether DNA results can be hacked.
Texas gives defense counsel the tools to press the point. Texas criminal courts do not apply the federal Daubert standard. They apply Kelly v. State for hard science and Nenno v. State for experience-based fields. Kelly was decided in 1992, a year before Daubert, and Texas has kept its own framework ever since. Under Kelly the State must show by clear and convincing evidence not only that a method is valid but that it was applied properly on this occasion. If a State’s analyst used an AI tool to review data, summarize records, or help generate an opinion, how that tool was used is part of the method. Article 39.14, the Michael Morton Act, is the discovery mechanism. When the State’s expert leaned on software, defense counsel should be demanding the specific tool and version, the actual prompts and queries, whether the outputs were independently verified, and confirmation that none of it was quietly deleted.
What This Means for You
- A chatbot is not private. Do not type anything into an AI tool that you would not be comfortable seeing on a screen in front of a jury.
- Deleting the chat does not make it disappear. The provider may retain it, and a court can order it preserved and produced.
- If you are under investigation or charged, talk to a lawyer, not a chatbot. Attorney-client privilege protects what you tell your lawyer. It does not protect what you tell an AI, and running your situation past a chatbot can create the very record the State is looking for.
- If the State’s case leans on AI-assisted analysis, treat that as a discovery and reliability fight, not something to accept at face value.
Everything you type into an AI leaves a record, and the courts are deciding, case by case, that those records are fair game. That is a warning when the record is yours and an opportunity when the record belongs to the State’s expert. Either way, it rewards a defense team that understands the forensics. For the mirror-image problem, AI-generated material offered against you, see our post on deepfake evidence.
If you are facing a criminal charge in Texas and digital evidence is part of the case, call Deandra Grant Law at (214) 225-7117 for a free, confidential consultation.
Deandra Grant holds a Master of Science in Pharmaceutical Science, a Graduate Certificate in Forensic Toxicology, and the ACS-CHAL Forensic Lawyer-Scientist designation. Deandra Grant Law handles DWI and criminal defense across North and Central Texas.
This article is for general informational purposes only and is not legal advice. Verify all citations before relying on them in any filing.
Sources and Further Reading
- CNN, How ChatGPT conversations became evidence in criminal investigations (May 2, 2026).
- CBS News, College students’ killings latest case to rely on ChatGPT as evidence (April 2026).
- The Washington Post, ChatGPT chats are being swept into civil and criminal court cases (Aug. 27, 2026).
- Forensic Resources (NC Office of Indigent Defense Services), AI Prompts Are Discoverable as Expert’s Methodology (Aug. 2026).
- Conservation Law Foundation Inc. v. Shell Oil Co., docket on CourtListener, No. 3:21-cv-00933 (D. Conn.).
- United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026) (memorandum explaining Feb. 10, 2026 ruling that a defendant’s AI exchanges are not privileged or work product), docket on CourtListener.
- Riley v. California, 573 U.S. 373 (2014), opinion on CourtListener.
- Carpenter v. United States, 585 U.S. 296 (2018), opinion on CourtListener.
- Chatrie v. United States, No. 25-112 (U.S. June 29, 2026), opinion on CourtListener.
- Kelly v. State, 824 S.W.2d 568 (Tex. Crim. App. 1992), opinion on CourtListener.
- Nenno v. State, 970 S.W.2d 549 (Tex. Crim. App. 1998), opinion on CourtListener.
- Daubert v. Merrell Dow Pharmaceuticals, Inc., 509 U.S. 579 (1993), opinion on CourtListener.
- Federal Rule of Civil Procedure 26, Cornell Legal Information Institute.
- Texas Code of Criminal Procedure Article 39.14 (Michael Morton Act).
Which county your case is filed in changes how it is charged, who prosecutes it, and which court hears it.
Charged With a Crime?
Whatever you're facing, a DWI or any criminal charge, the sooner you have a forensic-trained team on it the more we can do. Tell us what happened and we'll review your options, at no cost and no obligation. We're available 24/7 across all six Texas offices.
Request a Free Case Evaluation
Tell us what happened. We'll respond as soon as possible.