Businesses, employees, lawyers, and parties to litigation are rapidly incorporating generative artificial intelligence into their daily practice to tackle legal issues and prepare for actual or anticipated litigation. But when a party uses an AI platform like ChatGPT or Claude, are those “communications” protected from discovery? Recent decisions show that lawyers and parties should use generative AI with caution, as at least some information about AI use could be disclosed in discovery. Additionally, sharing confidential information with AI tools could undermine the attorney-client privilege and may violate protective orders.
Warner v. Gilbarco: A Pro Se Litigant’s AI Use Constitutes Protected Work Product
In February 2026, the Eastern District of Michigan held that a pro se plaintiff’s AI communications were protected work product. Warner v. Gilbarco, 820 F. Supp. 3d 629 (E.D. Mich. 2026). The defendants sought disclosure of the plaintiff’s queries to ChatGPT, ChatGPT’s responses, and any documents uploaded to ChatGPT. The Court found that (i) the AI materials were prepared in anticipation of litigation and thus fell within the scope of Rule 26(b)(3)(A); (ii) the plaintiff’s use of AI involved her “internal analysis and mental impressions—i.e., her thought process,” which constituted protected opinion work product; and (iii) using a generative AI tool did not waive work product protection because such platforms “are tools, not persons, even if they may have administrators somewhere in the background,” and using AI programs is not akin to disclosing work product to an adversary. The Court concluded that the defendants’ theory “would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed.”
United States v. Heppner: No Privilege, No Work Product
Around the same time as the Warner decision, the Southern District of New York issued an opinion in a criminal case that confronted what the Court described as a question of first impression nationwide: whether a user’s communications with a publicly available AI platform in connection with a pending criminal investigation are protected by attorney-client privilege or the work product doctrine. United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. 2026). The Court answered no on both counts.
The defendant in that case had used Claude to prepare approximately thirty-one documents outlining defense strategy and potential legal arguments. Critically, he did so on his own initiative, without any direction from his counsel.
The Court held that the attorney-client privilege does not protect communications with AI platforms for several reasons. First, Claude is not an attorney, so no attorney-client relationship existed. Second, the communications were not confidential because Anthropic’s (the owner of Claude) privacy policy notified users that the company collects data on user inputs and outputs, uses that data for training, and reserves the right to disclose it to third parties, including governmental regulatory authorities. Third, the defendant did not communicate with Claude for the purpose of obtaining legal advice—Claude itself disclaims providing legal advice.
On work product, the Court was equally firm, stressing that the doctrine “shelters the mental processes of the attorney,” and its purpose is “to preserve a zone of privacy in which a lawyer can prepare and develop legal theories and strategy.” Because the AI documents were not prepared by or at the behest of counsel and did not reflect defense counsel’s strategy when the defendant created them, the documents fell outside the doctrine’s protection.
Morgan v. V2X: Splitting the Difference
On March 30, 2026, a Colorado federal court held that Rule 26(b)(3) applies to protect a pro se litigant’s AI-related materials. Morgan v. V2X, Inc., No. 25–CV–01991–SKC–MDB, 2026 WL 864223 (D. Colo. Mar. 30, 2026). The Court explained that the importance of applying these protections is “magnified in the context of AI—one of the most powerful knowledge tools ever to become available to the masses,” because pro se litigants “are forced to act as both party and advocate, simultaneously.” The Court analogized AI tools to Gmail accounts and found that using AI tools did not waive work product protections because it was reasonable to expect some privacy while using these tools, even if they are technically available to a third party, and it was highly unlikely that an adversary would gain access to the information without some legal process. The Court distinguished Heppner on two grounds: first, Heppner was a criminal matter, whereas civil Rule 26(b)(3) broadly protects the work product of a “party,” not merely counsel; and second, in Heppner there was a “gap between the party and the attorney” that does not exist where a pro se litigant is simultaneously the party and the advocate.
Notably, the Morgan Court did not extend work product protections to the identity of the AI tool used by the defendant—only to the substance of the AI interactions. Although the Court acknowledged that work product protection could protect the identity of the AI tool, the pro se plaintiff in that case had failed to demonstrate how disclosing the name of an AI tool would reveal his mental impressions or case strategy.
The Court also offered some practical insight by crafting an AI-specific provision for a protective order that effectively bars the use of mainstream, low-to-no-cost AI platforms for processing confidential information unless the AI provider is contractually prohibited from storing or using inputs for model training and from disclosing inputs to third parties.
Tate Group Automotive v. Legacy Automotive Capital: State Court Adoption
On June 3, 2026, the Texas Business Court weighed in on the question. In Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, the Court conducted an in camera review of ChatGPT conversations that the plaintiff had withheld based on attorney work product protection. The Texas Business Court expressly adopted the reasoning of Warner and Morgan and rejected Heppner. On the waiver question, the Court agreed with those cases’ recognition that “work product protections are typically waived by disclosure to an adversary, or in circumstances that substantially increase the likelihood that an adversary will obtain the materials”—and that sharing information with an AI tool does not meet that standard. The Court also emphasized that the Texas Rules of Civil Procedure set forth a different and potentially broader standard for protectable work product than the federal rules.
Following Morgan, the Court also ordered the plaintiff to disclose to defendants all discovery materials or products that it had shared with ChatGPT (by Bates number), including any materials produced pursuant to the protective order. The Court further recommended that the parties confer and negotiate amendments to the protective order that would “make unquestionably clear whether, how, and to what extent if so, Confidential Information may be shared with any AI tool or other Large Language Model system” and expressly directed the parties to the Morgan decision.
Practical Implications
The case law on AI continues to develop with practical implications for litigants and other parties using AI. The current case law offers the following practical insights:
- Create guardrails for AI use. Inputting privileged, confidential, sensitive, or investigation-related information into a consumer-grade AI platform risks waiving attorney-client privilege. Clients should be advised of this risk and warned against inputting any attorney-client communications or confidential documents into an AI platform. If AI must be used to process sensitive material, use an enterprise-tier platform with contractual guarantees against data retention and third-party disclosure.
- Avoid using AI without lawyer direction. Lawyers should warn their clients that using AI on their own initiative is risky. The outputs may still receive work product protection, but the analysis is context-dependent. If a lawyer directs a client to use an AI tool to assist with litigation preparation, that direction may help bring the resulting materials within the umbrella of work product protection.
- Proactively address AI usage in litigation. Lawyers should consider proactively addressing AI use in protective orders and discovery protocols at the outset of litigation, rather than scrambling to address it after the fact.
- Proceed with caution and awareness. Litigants should be aware that their choice of AI tools—and the materials they share with them—may themselves become subjects of discovery. While the substance of AI interactions may be protected, courts have ordered disclosure of the identity of the platform used and of materials shared with it, particularly where confidential information is at stake. Treat every AI interaction as if it could one day be scrutinized by opposing counsel—because, under the right circumstances, it very well might be.