Recent Court Decisions Highlight Privilege, Confidentiality, and Discovery Risks Associated With Public AI Platforms

|
Download Calendar

Recent federal court decisions signal that AI-generated documents, chat logs, and meeting transcripts are fair game in litigation — and the law is still being written.

Key Takeaways

  • Federal courts recently reached different conclusions regarding whether the use of generative AI affects attorney-client privilege and work product protection.
  • In United States v. Heppner, a federal court held that communications with a publicly available AI platform were protected by neither attorney-client privilege nor the work product doctrine.
  • In Warner v. Gilbarco, Inc., a federal court held that a litigant’s use of ChatGPT did not waive work product protection.
  • Recent commentary and court guidance have focused on the distinction between publicly available AI platforms and enterprise or closed AI systems.
  • Organizations using AI for legal, compliance, business, or operational functions should review their AI governance policies and evaluate how sensitive information is handled.

Recent court decisions have addressed whether communications with generative AI platforms remain protected by attorney-client privilege and the work product doctrine. At the same time, courts, litigants, and regulators are confronting a related question: whether AI-generated materials, prompts, chat logs, and transcripts may become discoverable in litigation.

Generative AI tools such as ChatGPT, Claude, Copilot, and Gemini are now routinely used to summarize documents, draft communications, analyze information, and assist with litigation preparation. At the same time, many publicly available AI platforms collect user inputs, retain prompts and outputs, use information to improve their models, or reserve rights to disclose information under specified circumstances.

These features have raised questions regarding whether information shared with AI systems remains confidential and whether traditional legal protections survive when information is transmitted through third-party platforms.

Recent Federal Decisions

United States v. Heppner (S.D.N.Y. Feb. 17, 2026)

On February 17, 2026, Judge Jed S. Rakoff of the United States District Court for the Southern District of New York held that documents generated through a criminal defendant's interactions with Anthropic's Claude platform were protected by neither attorney-client privilege nor the work product doctrine. United States v. Heppner, No. 25 Cr. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026).

The defendant argued that the documents incorporated information received from counsel, were prepared in anticipation of litigation, and were later shared with counsel. The court rejected those arguments.

With respect to attorney-client privilege, the court concluded that Claude was not an attorney, that the communications were not confidential, and that the defendant was not communicating with the platform for the purpose of obtaining legal advice. The court also relied on Anthropic's privacy policy, which disclosed that user inputs and outputs could be collected, used for training purposes, and disclosed under certain circumstances.

The court separately rejected work product protection because the documents were not prepared by or at the direction of counsel and did not reflect counsel's litigation strategy.

Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 10, 2026)

One week earlier, on February 10, 2026, Magistrate Judge Anthony P. Patti of the United States District Court for the Eastern District of Michigan reached a different result. Warner v. Gilbarco, Inc., No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026).

In Warner, defendants sought discovery concerning a pro se plaintiff's use of ChatGPT in connection with employment-discrimination litigation. The court denied the request.

The court concluded that the materials were protected by the work product doctrine and rejected the argument that the use of ChatGPT constituted waiver. In doing so, the court distinguished attorney-client privilege from work product protection and stated that work product waiver generally requires disclosure to an adversary or in a manner likely to place the information in an adversary's hands.

The court further stated that "ChatGPT (and other generative AI programs) are tools, not persons," and concluded that use of the platform did not automatically waive work product protection.

Additional Developments

Last week, we wrote about President Trump's June 2 executive order on AI and cybersecurity, which keeps the regulatory touch light at the federal level; these privilege and work-product decisions show the courts moving faster than the agencies, working out AI's place in litigation case by case.

Several recent developments have focused on how AI platforms handle user information rather than on the mere use of AI itself.

Publicly available AI platforms may retain prompts and outputs, use information for model training, and permit disclosure under specified circumstances. These features were relevant to the court's analysis in Heppner and have also appeared in subsequent commentary addressing confidentiality and privilege concerns.

By contrast, recent commentary and court orders have distinguished enterprise or closed AI systems operating under contractual safeguards that prohibit model training on user data, restrict third-party disclosures, and permit deletion of stored information. While courts have not adopted a uniform approach, the distinction between public and closed systems appears repeatedly in recent discussions of privilege and confidentiality.

What This Means

The recent decisions do not establish a uniform rule regarding privilege or work product protection in the context of generative AI. They do, however, highlight several issues organizations may wish to evaluate when adopting AI tools.

Organizations using generative AI should pay particular attention to:

  • Whether AI platforms retain prompts or outputs.
  • Whether information submitted to the platform may be used for model training.
  • Whether the provider may disclose information to third parties.
  • Whether legal or litigation-related uses of AI occur at the direction of counsel.
  • Whether confidential information is being entered into publicly available AI platforms.

Reuters recently reported that prompts, chat logs, and AI-generated materials may themselves become relevant evidence in litigation and that publicly available AI platforms may be subject to legal process seeking user information. Any organization incorporating AI into its legal, compliance, or operational functions benefits from a documented AI governance policy — covering tool selection, approval, supervision of output, and confidentiality — and should weigh these considerations when selecting and governing AI tools.

Sources

  • United States v. Heppner, No. 25 Cr. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026).
  • Warner v. Gilbarco, Inc., No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026).
  • Jennifer Ellis, When Does Client Use of AI Waive Privilege?, ABA Law Technology Today (May 20, 2026).
  • Andrew Judkins & Rebecca Vickers, Court Guidance That Use of Open-Source AI Waives Confidentiality and Legal Professional Privilege, Norton Rose Fulbright (Apr. 2026).
  • Marshall Baker et al., Federal Courts Issue Diverging Rulings on the Use of Generative AI in the Context of Privilege, Work Product and Protective Orders, Akin Gump Strauss Hauer & Feld LLP (June 1, 2026).
  • B. Stephanie Siegmann & Mackenzie C. McBurney, When Your AI Tool Becomes a Witness, Reuters / Westlaw Today (June 8, 2026).

Summer Associate Aliana Rivera assisted with this article.

Photo credit: PierreDesrosiers

2026 Congressional Calendar
The 2026 Congressional Calendar was officially released! Access the combined House and Senate schedules now — downloadable files with full-year and monthly below.