Skip to Main Content
Publications

Are Your AI Chats Discoverable? Courts Begin to Map Work Product and Privilege in the Age of Generative AI

In a remarkably short span, courts across the country have begun answering a question that did not exist a few years ago: when a litigant types case-related information into a publicly available generative artificial intelligence (AI) platform, are those interactions protected from discovery? Beginning with United States v. Heppner's "question of first impression nationwide" decided in February 2026, federal and state courts have issued at least eight opinions in roughly four months addressing AI inputs and outputs under the attorney-client privilege, the work product doctrine, and protective orders. The decisions do not all point in the same direction, but together they sketch an emerging framework that every litigator and in-house team should understand now. Because these are trial-level and magistrate decisions with no appellate review to date, none is binding outside the court that issued it, and the law remains unsettled.

The Outlier: No Protection Without Counsel's Hand

The starting point is Heppner, where the court held that a criminal defendant's exchanges with Claude, the AI assistant built by Anthropic, were protected by neither the attorney-client privilege nor the work product doctrine. The privilege failed because Claude is not an attorney, the inputs were not confidential in light of the provider's privacy policy, and the defendant did not communicate with the tool to obtain legal advice. The work product claim failed for a more consequential reason: the defendant ran the AI searches of his own volition, without any direction from his counsel, so the materials were not prepared "by or at the behest of counsel" and did not reflect his counsel's strategy. The court stressed that even if non-lawyers can generate work product, the doctrine's purpose is to shield the lawyer's mental processes. Critically, the court also confirmed that sharing otherwise non-privileged inputs with his counsel afterward did not transform them into protected material.

The Emerging Civil Consensus: AI Use Can Be Work Product

A line of civil decisions has charted a more protective course, and several decided after Heppner have expressly declined to follow it. The throughline is that using a public AI tool is not, by itself, a waiver, because the tool is not an adversary. The critical distinction these courts draw is not civil versus criminal, but whether the AI user is simultaneously the party and the advocate, as opposed to a represented party who runs AI searches independently of counsel's direction.

  • Warner v. Gilbarco, Inc: The court denied a motion to compel a pro se plaintiff's AI materials, holding that ChatGPT and similar programs "are tools, not persons," so disclosure to them is not a waiver to an adversary or in a manner likely to reach one. The court pointedly told the defendants their "preoccupation with Plaintiff's use of AI needs to abate."
     
  • Morgan v. V2X, Inc: The court held that Rule 26(b)(3) work product protection extends to a pro se litigant's AI use, distinguishing Heppner as a criminal case involving a gap between Heppner and his legal representation that does not exist when a pro se litigant is both party and advocate. The court reasoned that routing information through a third-party system "does not eliminate all expectations of privacy."
     
  • Tym v. Cerno: Adopting Morgan's reasoning "at this time and for this case only," the court held that "AI interactions do not automatically compromise work product protections," and that "if Plaintiff used generative AI to prepare his filings . . . those interactions would be shielded by the work product doctrine."
     
  • Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC: Following in camera review of a party representative's ChatGPT conversations, the court agreed with Warner and Morgan, disagreed with Heppner, and applied Texas's broad work product rule to protect most – though not all – of the chats. Quoting Morgan, the court affirmed that "work product protections are typically waived by disclosure to an adversary," and recognized that the AI tool in this case did not qualify.
     
  • Assini v. Hayward: The court quashed a subpoena to OpenAI seeking a pro se defendant's ChatGPT account materials, finding Morgan persuasive and Heppner distinguishable. The court agreed with Morgan that "in the context of a pro se litigant's use of AI to assist with their litigation preparation, the use of AI closely resembles the kind of confidential, strategy-laden iterative work product that Rule 26(b)(3) was designed to protect."

The Limits: What Remains Discoverable

Even courts that protect the contents of AI interactions have drawn firm boundaries. Three limits recur:

Tool identity and scope of disclosure: In Morgan, the court ordered the plaintiff to disclose the name of any AI platform into which he uploaded confidential information, finding he had not carried his burden to show that the tool's identity itself revealed strategy. Tate Group went further, requiring the party to identify, by Bates number, every discovery material shared with ChatGPT so the court could police protective-order compliance.

Expert witnesses remain different: In Conservation Law Foundation, Inc. v. Shell Oil Co., the court ordered production of the AI prompts and queries an expert witness used in her analysis, reaffirming settled authority that "an expert witness's methodology is fair ground for discovery." The protections that shield a party's litigation strategy do not extend to the methodology of a testifying expert. The court stated, "the process by which [the expert] culled down the defendants' document production into a subset to be worked with is an aspect of methodology."

Misuse draws scrutiny: In Jones v. Delta Air Lines, Inc., a pro se plaintiff kept ChatGPT open during her deposition and invoked "attorney-client privilege" to avoid answering whether she was feeding it questions. The court barred the practice and reminded her there was no privilege without an attorney; the case was ultimately dismissed on other grounds. Assini, a case involving a pro se defendant's use of AI, likewise cautioned that unfettered AI use that "frustrates the litigation" may invite sanctions under applicable court rules.

Protective Orders Are Catching Up

Separately, courts are amending protective orders to govern AI directly. In Jeffries v. Harcros Chemicals, Inc., a consolidated proceeding with Tucker v. Harcros Chemicals, Inc., the court found good cause to bar parties from uploading even non-confidential discovery materials into open or "open loop" AI tools, while permitting closed, secure tools – citing the practical impossibility of clawing back data used to train a model, data-privacy and GDPR exposure, and critical-infrastructure security. Morgan entered a parallel provision to the protective order permitting AI use with confidential information only where the provider is contractually barred from training on or disclosing inputs and allows deletion on request – restrictions that, the court acknowledged, effectively exclude most "mainstream low-to-no-cost" AI consumer tools and may disadvantage parties who cannot afford enterprise platforms, particularly pro se litigants who must act as their own counsel.

Practical Takeaways

  • Direct the use: Work product protection is strongest when counsel directs and integrates the AI work. Heppner turned on the absence of retained counsel's involvement; the protective civil cases involved litigants acting as their own advocates.
     
  • Choose tools deliberately: Use closed or enterprise AI platforms with contractual no-training, no-disclosure, and deletion terms – and retain documentation of those terms, as several orders now require.
     
  • Assume the tool's name and the fact of use are fair game: Protect the contents, but be prepared to disclose which platform was used and what materials were shared with it.
     
  • Wall off experts: Treat a testifying expert's AI prompts, queries, and related methodology as discoverable and counsel experts accordingly.
     
  • Negotiate AI provisions early: Address AI use – open versus closed tools, training, deletion, and disclosure – at the protective-order stage, before a dispute crystallizes. Avoid over-designating material as confidential, which several courts have flagged.

This case law is developing rapidly and is not yet uniform across jurisdictions. We're continuing to monitor these developments and advising clients on AI-use policies, protective-order strategy, and discovery planning. For guidance tailored to your matters, please contact Edward D. Lanquist, Nicole Imhof, or any member of Baker Donelson's Intellectual Property Group.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept