Is It Still Privileged If You Told the AI?

That AI is everywhere is old news. What’s new is how quickly its use is colliding with the rules of privilege. According to Deloitte, in just one year, companies have expanded worker access to AI from fewer than 40% to roughly 60% of their workforce. Yet, while nearly three in four plan to deploy autonomous AI agents within two years, only one in five has a mature model for governing them.

Technology is diffusing faster than the controls meant to contain it. The core risk for companies is that employees – not just lawyers – will increasingly turn to AI to analyze sensitive or contentious situations. Potential litigants, including current and former employees, will be increasingly tempted to use AI to assess their exposure, and it is precisely in those contentious situations that inputs and outputs may be deemed unprivileged and discoverable.

The treatment of generative AI in the privilege and work-product context has recently drawn the attention of courts and litigators. Two U.S. federal court decisions in February 2026 addressed the use of generative AI and whether the resulting materials retain (or lose) the protection of the attorney-client privilege and the work-product doctrine.

This article analyzes those decisions and summarizes the precautions companies should take to avoid inadvertently losing these protections.

Privilege and Work-Product

A useful starting point is that neither decision changed the law; each simply applied existing principles to a new set of facts. As a general rule, under U.S. law, parties may obtain discovery of any nonprivileged information that is relevant to a claim or defense and proportional to the needs of the case. Two long-standing protections limit that reach: the attorney-client privilege, which protects confidential communications between clients and their attorneys made for the purpose of obtaining or providing legal advice, and the work-product doctrine, which protects materials prepared by or at the direction of counsel in anticipation of litigation (including arbitration), whether the litigation is already in progress or reasonably anticipated.

The Two Decisions

In United States v. Heppner, a criminal defendant facing securities fraud charges used the consumer version of an AI chatbot to prepare his defense, generating dozens of documents on his own initiative and later sharing them with his lawyers. The FBI recovered the documents in a search of his home. The U.S. District Court for the Southern District of New York held that the documents were protected by neither the attorney-client privilege nor the work-product doctrine.

On privilege, the Court reasoned that a chatbot is not an attorney, so no confidential lawyer-client communication existed, and the chatbot’s privacy policy (which allowed the provider to collect users’ inputs and outputs and share them with third parties, including regulators) defeated any reasonable expectation of confidentiality. On work-product, the documents were not prepared at counsel’s direction and did not reflect litigation strategy. The Court noted, however, that had counsel directed the defendant to use the tool, it might have functioned as the lawyer’s agent, potentially bringing the materials within the attorney-client privilege and, more likely, the work-product doctrine.

In Warner v. Gilbarco, Inc., a pro se plaintiff in an employment discrimination case used a public AI chatbot to help prepare her case, and the defendants moved to compel production of everything concerning her AI use. The U.S. District Court for the Eastern District of Michigan denied the motion, holding that the materials were work-product prepared in anticipation of litigation and, in any event, that the request was neither relevant nor proportional.

Crucially, the Court drew a distinction Heppner did not: voluntary disclosure to a third party waives the attorney-client privilege, but work-product is waived only by disclosure to an adversary or in a manner likely to reach an adversary. As a self-represented litigant acting as her own counsel, the plaintiff could assert work-product over her trial-preparation materials, and sharing them with an AI tool did not waive that protection. The Court went further, reasoning that AI is not a third party at all: “ChatGPT (and other generative AI programs) are tools, not persons, even if they may have administrators somewhere in the background.”

As a side note, it is worth paying attention to the fact that work-product analysis can vary by jurisdiction: some courts ask whether the materials were prepared at counsel’s direction, while others ask whether disclosure made it likely they would reach an adversary.

Practical Takeaway

Both decisions recognize that the use of a consumer AI tool raises legitimate concerns, and neither endorsed unrestricted use. Together, however, they point to a set of practical steps organizations should consider to preserve privilege and confidentiality while still benefiting from generative AI.

Conclusion

For now, although there may be arguments to the contrary, the cautious approach is to assume that, when using a public or direct-to-consumer tool, there is no reasonable expectation of confidentiality and so no basis for claiming privilege regardless of how the tool is used or who it is used by.

Without confidentiality, privilege cannot arise, even when a lawyer is using the tool and even when the inputs or outputs evidence the content of a pre-existing privileged communication.

The central takeaway is not that AI adoption is incompatible with privilege and work-product protections, but that unexamined use creates avoidable risk. Thoughtful evaluation, contractual diligence, and structured deployment can substantially mitigate it.

The Briefing

New essays in your inbox, roughly monthly.

Legal analysis on the AI and privacy regulations that actually affect technology businesses. No noise, no boilerplate.

This article is for informational purposes only and does not constitute legal advice. Reading this essay does not create an attorney-client relationship.