Is Your AI Research Privileged? The Federal Courts Begin to Answer
Generative AI has become a daily tool in litigation. In the first half of 2026, three federal courts issued the first decisions on a question every practicing lawyer should be asking: when you run legal work through an AI platform, does the attorney-client privilege or the work-product doctrine still protect it?
The cases reach different results, but they share one message. The protections can survive AI use — but how you use the tool may determine whether you keep them.
Three cases, three outcomes
Although each case arose under different facts, together they illustrate how courts are beginning to distinguish between responsible AI use and conduct that risks waiving long-established legal protections.
In United States v. Heppner (S.D.N.Y., Feb. 2026), the court held that a criminal defendant's exchanges with a consumer AI tool were not privileged. The defendant generated defense-strategy documents on his own, using a consumer product whose terms let the provider store his inputs, train on them, and disclose them. No lawyer directed the work, and nothing kept it confidential. The court added two warnings: forwarding a non-privileged document to your lawyer does not make it privileged, and feeding your lawyer's advice into a consumer tool may waive privilege over that advice.
Two civil cases went the other way on work product. In Warner v. Gilbarco (E.D. Mich., Feb. 2026) and Morgan v. V2X (D. Colo., Mar. 2026), the courts treated AI as a "tool, not a person." Because disclosing material to a tool is not disclosure to an adversary, using AI did not waive work-product protection. But Morgan also required the litigant to reveal which AI tool he used, and the court rewrote the protective order to bar feeding confidential information into any public AI platform that can train on or disclose it.
Taken together, these decisions suggest that courts are less concerned with the mere use of AI than with the circumstances surrounding that use—including the platform selected, the confidentiality protections in place, and the attorney's role in supervising the work.
What it means for lawyers, not just pro se litigants
Each of these cases involved a self-represented party or a client acting on his own. Even so, the reasoning employed by the courts offers valuable guidance for attorneys who increasingly rely on generative AI during litigation. For attorneys building AI into their practice, the lessons are sharper.
Your terms of service matter as much as your prompts. Heppner turned on a consumer privacy policy. For confidential or privileged work, use enterprise tools whose contracts bar training on your data, bar third-party disclosure, and allow deletion.
Attorney direction strengthens your position. The cleanest record is AI used by you or at your direction, as part of litigation preparation, with outputs you review. That fits squarely within the work-product doctrine, which protects materials prepared by a party or its representative — not just by lawyers.
Treat your inputs as the real risk. Pasting privileged communications into a consumer tool could potentially waive privilege over the originals. What you put in matters more than what comes out.
The metadata may not be protected. Morgan shows that the name of the tool, and logs of when and how you used it, can be discoverable even when the substance is not.
Address AI before the dispute starts. Build AI terms into your ESI protocols, negotiate Rule 502(d) orders to limit waiver exposure, and expect courts to write AI restrictions into protective orders — sometimes on their own.
A regional caveat
None of these decisions binds Georgia courts or the Eleventh Circuit. They are persuasive authority in an area where the controlling law has not yet been written. Nevertheless, they provide an early roadmap for how courts may analyze privilege issues as generative AI becomes more deeply integrated into legal practice.
Perhaps the most important lesson emerging from these decisions is that privilege analysis will likely focus less on whether AI was used and more on how it was used. Courts are examining attorney involvement, contractual confidentiality protections, and whether the selected platform functions as a secure litigation tool or as a public third-party service. Lawyers who implement appropriate safeguards today will be in the strongest position to preserve privilege as the law continues to evolve.
If you have questions about using generative AI in your practice or protecting privileged material in litigation, our litigation team is here to help.