Subscribe

New ideas, straight to your inbox.

No spam. Unsubscribe anytime.

← Back to Blog
He Tried to Save Himself With Claude. Then the FBI Read Everything.

He Tried to Save Himself With Claude. Then the FBI Read Everything.

A $150 Million Conversation With AI

What is the most dangerous thing a man can leave behind after siphoning more than $150 million out of a public company?

A hidden ledger. A careless email. A recording he forgot to delete. Maybe an insider who suddenly decides to cooperate with the government.

Bradley Heppner left behind something far more current: roughly 31 documents containing his conversations with Claude.

On November 4, 2025, FBI agents arrived at Heppner’s home in Dallas with a search warrant. They arrested him and seized his electronic devices. By then, Heppner had already received a grand jury subpoena and knew he was a target of the investigation. Instead of waiting for an indictment, he opened Claude and began working on his defense.

He told Claude about the case, the charges he might face, and information he had received from his lawyers. He asked the AI to analyze the law, anticipate the prosecution’s strategy, find weaknesses, and turn the results into reports he could share with counsel.

Before the FBI ever reached his door, Heppner had already rehearsed the trial with Claude.

It is tempting to dismiss this as a rich man making an obviously foolish mistake. But the appeal is easy to understand. The lawyer’s meter was running. Claude’s wasn’t. A lawyer would not sit with him at 2 a.m. and answer the same question ten different ways. Claude would. And the things that feel uncomfortable to say to another person can come out remarkably easily in front of a blank chat box.

We think we are using a tool. Without noticing, we begin talking to it like a confidant.

Months later, prosecutors sought access to the files. Heppner’s lawyers objected. They argued that the documents had been created to prepare his defense and obtain legal advice, and that some of them incorporated information from counsel. In their view, the materials should be protected by attorney-client privilege.

The judge disagreed. The court’s answer came down to one brutal fact: Claude is not your lawyer.

Heppner was later convicted of securities fraud, wire fraud, conspiracy, and making false statements to auditors. According to the U.S. Department of Justice, he used a shell company he controlled to fraudulently extract more than $150 million from GWG Holdings. The company later filed for bankruptcy, unable to meet more than $1 billion in obligations, affecting large numbers of retail investors and retirees.

As of this writing, Heppner has not received his final sentence or fine. Sentencing is scheduled for October 2026. Each of the major fraud and false-statement counts can carry a maximum sentence of twenty years.

At this point, most readers will have the same question: Did Anthropic hand his conversations to the FBI?

Perhaps Claude detected criminal content and triggered an internal reporting system. Perhaps Anthropic received a subpoena, opened its servers, and delivered his chat history to the government. Either possibility would be enough to make anyone who has ever shared a secret with an AI deeply uncomfortable.

But that is not what happened.

Anthropic did not provide Heppner’s conversations to the government. The FBI did not need to subpoena his Claude account. The documents were sitting on his own electronic devices, where agents found them while executing the search warrant.

Nobody had to betray him. He had already preserved the material for them.

Want more practical breakdowns?

AI, engineering, and experiments—1–2 useful emails a month.

No spam. Unsubscribe anytime.

The court later ruled that the documents were protected by neither attorney-client privilege nor the work-product doctrine, allowing the government to inspect them. That ruling did not automatically make every line admissible at trial, and the public record does not establish that the Claude files caused his conviction.

Still, the most important door had been opened. Heppner believed he was creating private defense notes. The law saw a collection of ordinary electronic files.

Attorney-client privilege does not cover everything related to a legal problem. It protects confidential communications made for the purpose of obtaining legal advice from an attorney. Lawyers have fiduciary duties, professional discipline, and enforceable confidentiality obligations. Claude has none of those things. It can sound like a lawyer, analyze a case like a lawyer, and sometimes identify issues a lawyer might miss. But it cannot lose its license for mishandling your secrets.

Heppner had another problem: his lawyers had not instructed him to use Claude or supervised how he used it. He entered the information into a consumer AI product on his own and sent the reports to counsel afterward. Forwarding an unprotected document to a lawyer does not magically make it privileged.

The Harvard Law Review analysis argues that the court may have drawn the line too aggressively. Is Claude really a third person joining the conversation, or is it a tool the client used to organize his thoughts?

People email their lawyers through Gmail, draft questions in Google Docs, and store case files in iCloud. Google and Apple are third parties too, yet courts do not automatically destroy privilege whenever their infrastructure touches a document. If Claude is only restructuring notes, cleaning up language, or generating a list of questions, how different is it from a much smarter word processor?

Courts will spend years answering that question. Consumer AI used independently by a client may be treated as an unprotected third party. AI selected by counsel and operated inside a controlled legal workflow may eventually be treated more like a translator, accountant, or professional agent.

Until the line becomes clearer, most people should not gamble their company, money, or freedom on how the next judge chooses to define AI.

What to Do When You Have Secrets to Tell an AI

If you are working on something confidential, what is the safest way to use AI?

There is no magic privacy switch. The practical answer begins with controlling the two places most likely to expose you: the AI account and the device in your hand.

In services such as ChatGPT and Claude, it is worth disabling model training, using temporary or incognito chats, and deleting conversations you no longer need. These controls are imperfect, but they reduce how much data remains available for future use. When a sensitive project ends, review uploaded files, clear unnecessary memories, disconnect third-party integrations, and check which devices still have active sessions.

Turning off training, however, is not the same as deleting data. OpenAI says Temporary Chats do not appear in normal history and are not used for model training, but copies may still be retained for up to thirty days for safety purposes. Anthropic similarly says deleted consumer chats are normally removed from back-end storage within thirty days, with exceptions for safety reviews and legal obligations.

Training, retention, deletion, and legal disclosure are separate systems. Switching off one does not make the others disappear.

There is also an important legal boundary. Routine deletion can be sensible privacy hygiene. But once you have received a subpoena, a litigation hold, or clear notice of an investigation, deleting potentially relevant material can create a much more serious problem. At that point, stop cleaning and talk to a lawyer.

The second weak point is your phone or computer. The lesson from Heppner is that the cloud may not be the easiest route to your data. An AI company can provide nothing, while the same information remains in chat history, downloads, screenshots, browser caches, and device backups.

Use a long, unique alphanumeric passcode rather than a short or recycled password. Enable multi-factor authentication and a short automatic-lock interval. Review which apps are backing up data and where those backups live. iPhone users can consider enabling Advanced Data Protection so that most iCloud categories receive end-to-end encryption. For exceptionally sensitive work, a separate device or isolated workspace is cleaner than mixing private photos, personal email, messaging apps, and confidential documents on the same phone.

For information that could materially affect a company, a career, or someone’s freedom, running AI locally remains one of the strongest options. Local deployment keeps the original material away from a consumer AI provider and gives the user more control over logs, retention, and access.

But self-hosting is a stack, not a checkbox. The model may run locally while the interface writes logs, the vector database stores source documents, the operating system uploads crash reports, and the laptop syncs everything to iCloud or OneDrive. A serious local setup also has to control networking, telemetry, caches, backups, encryption, and access to the device.

Using an AI provider in another country can also be part of the strategy. If you live in the United States, placing data with a provider in another jurisdiction may add procedural friction to certain government requests. The same logic can apply in reverse for users elsewhere. It can also prevent every piece of sensitive work from sitting inside one legal and infrastructure environment.

But jurisdictional diversification is not the same as immunity. Foreign providers remain subject to their own laws, may operate servers or affiliates in multiple countries, and can still receive cross-border legal requests. More importantly, if a local copy remains on your phone, the nationality of the AI company may not matter at all.

The most sensible approach is layered. Ordinary work can stay in cloud AI. Business-sensitive material should be stripped of names, company identifiers, and unnecessary details before being sent to a provider with clear enterprise data terms. Highly sensitive work should move toward local, offline, encrypted, and minimal-retention environments. A foreign provider can add jurisdictional diversification, but it should supplement local control and device security, not replace them. And anything connected to real litigation or a government investigation should go through counsel first.

The point is not to use AI less. It is to use AI with enough control that its value does not come at the cost of your most important information.

AI is making capabilities that were once expensive and scarce available to almost everyone. It can help a small business understand a contract, help a founder inspect code, and help someone facing a legal problem organize a terrifying amount of information. We should not give that up.

We should simply develop better habits around it: know where a prompt is going, delete what no longer needs to exist, treat the account and the device as parts of the same security system, move truly sensitive work into environments we control, and involve a lawyer before feeding legal strategy into a consumer chatbot.

The best AI users of the next decade may not be the people who write the cleverest prompts. They may be the people who understand boundaries: when to ask freely, when to anonymize, and when to stop before pressing Send.

New ideas, straight to your inbox.

AI, engineering, and experiments—1–2 useful emails a month.

No spam. Unsubscribe anytime.