Hello,
I know many of you want to keep up to date on developments at the intersection of AI tools and privilege, so I wanted to bring the following to your attention. In my last email, I mentioned Heppner. There have been a few new cases since then, which we’re sharing. And, as usual, remember that this post does not constitute legal advice.
No. 25-CR-503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026) · February 17, 2026 · Jed S. Rakoff, United States District Judge
Criminal U.S. District Court Client used AI
Criminal defendant Bradley Heppner used Anthropic’s consumer Claude AI platform on his own initiative (not at counsel’s direction) to analyze legal strategy and prepare defense reports after receiving grand jury subpoena
Former financial services CEO Bradley Heppner faced federal fraud charges when he turned to Anthropic’s Claude AI platform for legal guidance. Acting independently after receiving a grand jury subpoena, Heppner inputted information from his defense counsel into Claude, generating 31 strategy documents and defense analyses. When FBI agents executed a search warrant at his home in November 2025, they seized electronic devices containing these AI-generated materials. Defense counsel asserted privilege, but Judge Rakoff ruled on February 10 (with written opinion February 17) that the documents were not protected by attorney-client privilege or work product doctrine, marking the first federal ruling to definitively strip privilege protections from consumer AI interactions.
The Issue: Whether documents generated by criminal defendant using consumer AI platform without counsel’s direction are protected by attorney-client privilege and work product doctrine
The Ruling: Court denied privilege protection, holding AI documents failed all elements: (1) no attorney-client relationship with Claude; (2) no reasonable expectation of confidentiality due to Anthropic’s data collection/training policies; (3) not for purpose of obtaining legal advice since Claude disclaims providing legal counsel
Significance: First federal court ruling to categorically strip privilege protection from consumer AI interactions, establishing that traditional privilege doctrines apply strictly to AI tools with no special protections
⚖️ For Lawyers
Judge Rakoff applied traditional three-prong privilege test, finding Claude failed all elements: no attorney-client relationship possible with AI platform, Anthropic’s privacy policy destroyed confidentiality expectations by authorizing data collection/training/disclosure to third parties including government, and defendant could not obtain legal advice from tool that explicitly disclaims providing legal counsel. Work product doctrine also failed because materials weren’t prepared by or at direction of counsel, reflecting only defendant’s own analysis rather than attorney mental impressions.
💬 Plain English
A criminal defendant used Claude AI to help plan his legal defense strategy, but the court ruled those conversations weren’t confidential because Claude isn’t a lawyer and the company’s terms allow them to use that data. The judge said using public AI tools is like talking to any other non-lawyer—your conversations aren’t protected just because you later share them with your attorney.
Practice Points
Prohibit uploading privileged information into consumer AI tools (ChatGPT, Claude, Gemini)
Use only enterprise AI tools with contractual confidentiality protections
Require attorney direction/supervision for any AI use involving legal matters
Further Reading
Gibson Dunn — AI Privilege Waivers: SDNY Rules Against Privilege Protection for Consumer AI Outputs
Dorsey & Whitney — Federal Judge Rules AI-Generated Documents Are Not Privileged
Duane Morris — The Perils of Privilege Waivers Through AI
Perkins Coie — Federal Court Rules Client’s Use of Generative AI Is Not Privileged
Harvard Law Review: United States v. Heppner - Analysis
No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026) · February 10, 2026 · Anthony P. Patti, United States Magistrate Judge
Civil U.S. District Court Attorney used AI
Pro se plaintiff Sohyon Warner used ChatGPT and other generative AI tools to prepare litigation materials, draft filings, and analyze case strategy in employment discrimination lawsuit
Employment discrimination plaintiff Sohyon Warner, representing herself pro se, used ChatGPT and other AI tools to research legal questions, draft court filings, and develop case strategy. When defendants Gilbarco and Vontier discovered this AI usage during depositions, they moved to compel production of ‘all documents and information concerning her use of third-party AI tools.’ Magistrate Judge Patti denied the motion on February 10, 2026, ruling that Warner’s AI-generated materials were protected work product under Federal Rule 26(b)(3), reasoning that AI programs are ‘tools, not persons’ and disclosure to adversary wasn’t required for waiver.
The Issue: Whether pro se litigant’s use of consumer AI tools for litigation preparation waives work product protection under Federal Rule of Civil Procedure 26(b)(3)
The Ruling: Court protected AI materials as work product, finding no waiver because: (1) AI tools are ‘tools, not persons’; (2) work product waiver requires disclosure to adversary, not just third party; (3) pro se litigant acts as both party and advocate, eliminating attorney-direction requirement
Significance: First federal ruling to protect AI-generated litigation materials, creating circuit split with Heppner and establishing that consumer AI use doesn’t automatically waive work product protection for self-represented litigants
⚖️ For Lawyers
Judge Patti distinguished Heppner as criminal case where defendant acted separate from counsel, while pro se litigants simultaneously serve as party and advocate. Applied Sixth Circuit precedent requiring disclosure to adversary for work product waiver, finding AI platforms are intermediary tools rather than third persons. Noted Federal Rule 26(b)(3) protects materials prepared by parties, not just attorneys, supporting broader work product scope in civil litigation.
💬 Plain English
A woman representing herself in an employment lawsuit used ChatGPT to help prepare her case. When the company she sued tried to get copies of her AI conversations, the judge said no—ruling that AI tools are just software helping with her thinking, not people she was sharing secrets with. The court protected her AI work as litigation strategy.
Practice Points
Pro se litigants may claim work product protection over AI-assisted materials
Document attorney direction when using AI tools for represented clients
Consider whether civil vs. criminal context affects privilege analysis
Further Reading
Proskauer Rose — Michigan Federal Court Protects AI-Assisted Litigation Work Product
No. 25-cv-01991-SKC-MDB, 2026 WL 864223 (D. Colo. Mar. 30, 2026) · March 30, 2026 · Maritza Dominguez Braswell, United States Magistrate Judge
Civil U.S. District Court Attorney used AI
Pro se plaintiff Archie Morgan used AI tools for litigation preparation in employment discrimination case against V2X, Inc.
Pro se employment discrimination plaintiff Archie Morgan used AI tools to assist with litigation against V2X, Inc. When V2X discovered the AI usage, they moved to compel identification of AI platforms used with confidential discovery materials and sought broader protective order restrictions. Judge Braswell ruled on March 30, 2026, that Morgan’s AI materials were protected work product, following Warner’s reasoning that pro se litigants act as both party and advocate. However, the court ordered disclosure of AI platform names used with confidential information and amended the protective order to prohibit use of open AI tools that lack contractual confidentiality protections for processing discovery materials.
The Issue: Whether pro se litigant’s AI usage constitutes protected work product and what protective order restrictions should apply to AI tools processing confidential discovery materials
The Ruling: Court protected AI materials as work product for pro se litigant but ordered disclosure of AI platform names and amended protective order to require contractual confidentiality protections (prohibition on training, third-party disclosure restrictions, data deletion capability)
Significance: Extended Warner protection to second circuit while establishing framework for AI usage in protective orders, requiring contractual safeguards rather than blanket prohibitions on AI tools
⚖️ For Lawyers
Judge Braswell followed Warner, distinguishing Heppner as criminal case with attorney-client gap that doesn’t exist for pro se litigants. Applied Federal Rule 26(b)(3) to protect party-created materials while recognizing legitimate discovery concerns about confidential information exposure. Crafted nuanced protective order requiring contractual confidentiality safeguards rather than categorical AI prohibition, establishing practical framework for AI governance in litigation.
💬 Plain English
Another self-represented person used AI tools for their employment lawsuit, and the court again protected those materials as work strategy. But when it came to confidential documents shared in the case, the judge required disclosure of which AI tools were used and created new rules requiring AI companies to promise not to train on or share that confidential information.
Practice Points
Include AI usage restrictions in protective orders with specific contractual requirements
Distinguish between open AI tools (prohibited) and closed/enterprise tools (permitted)
Address AI disclosure requirements for confidential materials in discovery
Further Reading
Everlaw — Morgan v. V2X, Inc. Decision Sets Precedent on AI Disclosure in Discovery
Sheppard Mullin — A Third Court Addresses AI Privilege and Protective Order Issues
No. 2:25-cv-02352-KHV-ADM, 2026 WL 820218 (D. Kan. Mar. 25, 2026) · March 25, 2026 · Angel D. Mitchell, United States Magistrate Judge
Civil U.S. District Court Client & Attorney used AI
Putative class action where parties sought to use AI tools for eDiscovery processing and document review of discovery materials in environmental contamination case
In a class action against chemical company Harcros over environmental contamination, the court faced a novel question about AI use in discovery. Plaintiffs wanted to use open AI tools for eDiscovery processing and document review, while defendants sought expanded protective order restrictions. Judge Mitchell ruled on March 25, 2026, granting defendants’ motion to prohibit use of ‘open’ AI tools (like ChatGPT, Claude) for all discovery materials—even non-confidential documents—while permitting ‘closed’ AI tools with contractual safeguards. The court cited data privacy concerns, including GDPR compliance issues and inability to delete data once incorporated into training models.
The Issue: Whether protective orders should prohibit use of open AI tools for processing all discovery materials, including non-confidential documents, based on data privacy and security concerns
The Ruling: Court prohibited use of open AI tools for all discovery materials, requiring only closed/secure AI tools with contractual protections against data training, third-party disclosure, and providing data deletion capabilities
Significance: Most expansive AI restriction to date, extending beyond confidential information to all discovery materials and establishing framework for distinguishing open vs. closed AI tools in litigation context
⚖️ For Lawyers
Court distinguished between open AI systems that retain/train on data versus closed systems with controlled environments. Found open AI tools create unique risks including practical inability to delete data from models and potential violations of GDPR consent requirements for third-party data. Extended restrictions beyond confidential materials to all discovery documents based on cumulative privacy exposure and lack of consent from document creators/subjects.
💬 Plain English
In an environmental lawsuit, the court banned using public AI tools like ChatGPT to process any case documents—even non-confidential ones—because those AI companies keep and learn from uploaded data. The judge said only private AI systems with promises not to use the data could be used, protecting everyone whose information might be in the documents.
Practice Points
Draft protective orders to address open vs. closed AI tool distinctions
Consider GDPR and data privacy implications of AI tool usage
Evaluate contractual safeguards required for AI vendors
Further Reading

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.