The attorney-client privilege and work-product doctrine were designed for a world of paper files, phone calls, and human litigation teams, not generative AI systems capable of generating, storing, processing, and potentially distributing confidential information with unprecedented speed and convenience. Yet as litigants increasingly rely on GenAI to assist with research, drafting, and strategy, courts must answer a difficult question: when legal analysis is shared with an AI platform, has confidentiality been preserved or conceded?
Three recent court cases, U.S. v. Heppner, Warner v. Gilbarco, Inc., and Morgan v. V2X, Inc., demonstrate that there is no definitive answer. Instead, emerging case law reveals a fragile and rapidly evolving framework in which privilege may depend less on traditional doctrine and more on how an AI system is designed, deployed, and governed.
U.S. v. Heppner
In this 2026 criminal case, a grand jury in the Southern District of New York indicted the defendant with various charges involving securities and wire fraud. The defendant, despite being represented by legal counsel, used the GenAI tool Claude on his own without direction or oversight from his attorney. Heppner input information learned from his attorney into Claude, prepared arguments outlining his potential defense strategy and legal arguments, and subsequently asserted privilege over the AI documents.
The Heppner Judge ruled that the written prompts between the defendant and Claude were not protected by attorney-client privilege or the work product doctrine, finding that the documents lacked two, “if not all three,” of the required elements: (1) the communications were not between a client and his attorney, (2) the documents were not (and were not intended to be) kept confidential, and (3) the documents were not prepared to obtain legal advice and the AI tool was not used at the direction of counsel.
A critical fact was that Heppner did not use an enterprise Claude solution and the licensing model he did use specifically included a notification to users that any information users input into Claude would be turned over to law enforcement upon request.
Warner v. Gilbarco, Inc.
In this recent federal employment discrimination case, the pro se plaintiff acknowledged during discovery that she had used ChatGPT to assist in drafting court filings. In response, the defendant requested “all documents and information” concerning the plaintiff’s use of third-party AI tools but the plaintiff objected, stating that the materials included her internal analysis and mental impressions and were thus protected from disclosure.
The court rejected the defendant’s arguments and sided with the plaintiff, concluding that the plaintiff’s interactions with ChatGPT were protected by the work-product doctrine the use of an AI tool did not constitute waiver of the privilege. The court also stated that ruling otherwise could undermine work-product protections in “nearly every modern drafting environment.”
Morgan v. V2X, Inc.
In this 2026 employment discrimination case, a pro se Plaintiff alleged that he was exposed to a hostile work environment and fired based upon his race. A discovery dispute arose when the defendant made a motion to amend an existing protective order to restrict the Plaintiff’s AI use. The pro se Plaintiff could only afford free consumer AI tools, while the corporate defendant maintained its own enterprise AI infrastructure.
According to the Morgan court, the dispute called into question: “(1) to what extent will work product protections apply to a pro se litigant’s use of AI, and (2) to what extent should a protective order expressly restrict the use of AI?” In response, the protective order was modified, the court restricted which AI systems could be used, and also required contractual safeguards before confidential discovery could be uploaded.
Courts Diverge in the Treatment of Privilege Related to GenAI
These three cases illustrate the challenge courts face when they struggle to fit GenAI into doctrines built for human communications and traditional third-party disclosures:
Tool or Person?
In Heppner, the judge treated AI much like a human third party—not an attorney, not confidential, and therefore not protected by attorney-client privilege. The Warner court explicitly framed ChatGPT and other GenAI platforms as “tools, not persons,” rendering it comparable to word processing and legal research software or drafting assistance. However, the Morgan court did not put all GenAI tools in one basket. Instead, it distinguished between properly controlled enterprise AI and uncontrolled public systems.
Attorney-Client Privilege or Work Product?
The cases illustrate the importance of what we learned in law school about privilege: the work product doctrine provides more limited protection from disclosures while the attorney client privilege is a more comprehensive protection against disclosure but is more fragile and lacks the resiliency of the work product doctrine – a distinction that is critical to any privilege analysis in the context of GenAI:
- Attorney-client privilege didn’t apply in Heppner, where the court ruled that AI is not a lawyer, the communications were not confidential, and the disclosures were voluntary. Work product also failed because the court found that the materials were not attorney-directed, the defendant used AI independently, and the disclosure made to the AI vendor destroyed the protection.
- Work-product protection survived in Warner, where the court protected litigation strategy, internal drafting, and AI-assisted thought processes, and found that using ChatGPT did not waive work-product protection because waiver generally requires disclosure to an adversary.
- The Morgan court also preserved work-product protections, but only where confidentiality safeguards exist, the AI provider is contractually restricted, and the system is not training on user data.
Litigation teams that understand how the courts are defining privilege in the context of GenAI will be best positioned to navigate the elements of privilege and how the technological complexities of GenAI ESI can impact protecting privilege. Wondering how the courts might view your current litigation and eDiscovery strategy regarding GenAI ESI and privilege? Contact us at .


