Although an interaction with a chatbot may seem private, especially when discussing personal issues, work queries, or relationship problems, all content can be recorded in the account history. The central issue lies in what happens when these conversations are no longer restricted to the user and the tool.
It is possible that dialogues maintained with ChatGPT or other Artificial Intelligence chatbots can be accessed and used in a legal proceeding, potentially serving as evidence against those who wrote them. A survey conducted by the Washington Post confirmed this possibility, identifying 12 civil and criminal cases in the last two years where records of conversations with chatbots were attached to legal documents.
In one of these reported cases, a teenager used ChatGPT to understand a conversation with his father, and the personal dialogues resulted in the inclusion of the content in a lawsuit filed against social media companies.
Legal Situation in Brazil
In the Brazilian context, there is no legislation that automatically renders a conversation with AI inadmissible simply because it occurred with a chatbot. However, there is also no professional secrecy comparable to that established between lawyer and client. The determination regarding the use of this content depends on a combination of regulations related to privacy, data access, and the validity of digital evidence.
The fundamental legal point to clarify is how the State obtained access to this conversation. Christiano Gonzaga, a criminal prosecutor, points out that a simple question asked to ChatGPT does not necessarily imply the commission of a crime. He cites the example of someone asking how to erase traces of a file during a homicide investigation; the content may be relevant, but requires joint analysis with factors such as the context and time of the investigation.
Gonzaga also emphasizes that if a user questions the chatbot about how to commit a crime without actually doing so, there is, in principle, no specific rule of inadmissibility solely because the conversation was with an artificial intelligence.
Conversations as Digital Evidence
André Coura, a criminal lawyer and partner at Coura Advogados, clarifies that such interactions can be classified as digital evidence and extracted from electronic devices to be used in litigation. This can occur with the consent of the person involved or through judicial authorization, even when a device seized during a search is submitted to technical expertise for data extraction.
A conversation with a chatbot may address topics that would only be shared in high-trust relationships, but this does not grant the interaction the same guarantees of confidentiality present in certain professional relationships. There is no legal secrecy provided for this type of content, unlike cases involving confidential information exchanged with lawyers, doctors, or religious ministers.
André Coura emphasizes that even if the user reports a crime, seeks legal advice, or describes a medical condition to the chatbot, the nature of the question does not transform the AI into a professional subject to confidentiality. As Christiano Gonzaga summarizes, ChatGPT does not assume the role of a lawyer, doctor, psychologist, or priest due to the nature of the consultation.
Constitutional Protection and Data Access
Despite this, the conversation remains within the sphere of privacy. The Federal Constitution guarantees the inviolability of intimacy and private life, while the Civil Internet Framework defines rules for protecting the secrecy of stored private communications, allowing disclosure of the content upon judicial order. The Constitution also guarantees data secrecy.
This distinction prevents conflicting interpretations: the conversation with ChatGPT lacks the professional secrecy of a legal consultation, but it also cannot be treated as entirely unprotected legally.
The mere seizure of a cell phone does not authorize access to the conversations stored on it. The Superior Court of Justice (STJ) reiterated in April of this year that it is illegal for the police to access data, including messages in messaging applications, directly on a cell phone seized in flagrante delicto without prior judicial authorization, unless there is voluntary consent from the owner.
Gonzaga differentiates the actions: 'The physical seizure of the cell phone and access to its content are different acts.' Therefore, the possession of the device by authorities does not imply that they can unlock it and freely examine the data.
In June, the STJ analyzed data collection procedures during the execution of search and seizure warrants, recognizing that police officers can perform preliminary checks and data collection from the device without the immediate presence of an official expert, provided the limits of the diligence and the rules for evidence preservation are respected.
The mode of access is also crucial: intercepting a communication in real time differs from accessing an already archived conversation. Law 9.296/1996 requires a judicial order for telephone interception, and its rules apply to the interception of communication flows in computer and telematics systems, requiring reasonable indications of authorship or participation and the impossibility of obtaining the evidence by other means.
If the conversation with ChatGPT occurred months ago and the history is saved, it is not technically considered ongoing interception, but rather access to stored private data and communications. The STJ also distinguishes between the content of stored communications and other digital data, reinforcing that obtaining static connection data does not constitute telephone interception, following the regime of the Civil Internet Framework.
There is the possibility of the user granting access, and Gonzaga emphasizes that this consent must be genuinely voluntary. STJ jurisprudence accepts the voluntary consent of the holder as an exception to the rule requiring judicial authorization for police access to stored data.
Evidentiary Value Versus Admissibility
Even if a conversation legally reaches the hands of the authorities or one of the parties in a lawsuit, its isolated content does not guarantee that it proves a crime. Gonzaga explains the distinction between the admissibility of evidence and its evidentiary value. For the prosecutor, the conversation can be documentary or digital evidence or act as an indicial element, but its weight depends on factors such as authenticity, integrity, authorship, context, and convergence with other evidence.
Coura agrees that no evidence should be viewed as absolute in isolation; the judge bases their conviction on the set of evidence, under the system of free motivated conviction. Thus, the content gains relevance when corroborated by other elements.
Gonzaga illustrates with the example of a generic question about how to kill someone with poison: it alone does not prove homicide. The situation changes if the conversation states that a substance was put in the victim's drink and the investigation finds the substance, images of the suspect manipulating the drink, device data, and a compatible toxicological examination. In this scenario, the weight will depend on authenticity, integrity, authorship, context, and convergence with other evidence.
The reliability of the material is also vital. In a case judged in 2024, the STJ deemed WhatsApp screenshots obtained by the police without following adequate procedures to ensure data integrity inadmissible, as it was not possible to guarantee the authenticity and integrity of the material.
In March of this year, the Sixth Panel of the STJ revisited the topic, deciding that if there is reasonable doubt about the integrity and authenticity of digital evidence, it is essential to conduct an expert examination to confirm the reliability of the material and ensure due process. In June, the court also emphasized the importance of preserving the chain of custody and the possibility of independent technical examination to guarantee the integrity and auditability of the digital evidence, differentiating an isolated screenshot from a forensic extraction.
The cases raised by the Washington Post demonstrate that chatbot content does not need to be a confession to be relevant. In a civil case in the US, a seller asked ChatGPT if his email provider would recover a deleted message. His former employer used this conversation to contest his statements, alleging that he omitted information during the dispute.
In another case, related to threats against an ex-girlfriend, the Post reported that conversations with ChatGPT were considered by the police along with other messages sent to the victim, and the content reinforced the credibility of the threats attributed to the suspect.
For the user, the main recommendation is not to treat the chatbot as a confidential professional. Gonzaga advises avoiding the unnecessary sharing of extremely sensitive information, considering that what is digitally recorded can become the subject of investigation within legally acceptable means. Coura reinforces this caution regarding personal and sensitive data, warning about the risks of leaks or misuse, especially concerning passwords, bank credentials, private keys, confidential documents, procedural strategies, and third-party information.
