
Chris Seelinger
Counsel
201-899-2411 cseelinger@sh-law.comFirm Insights
Author: Chris Seelinger
Date: September 18, 2026

Counsel
201-899-2411 cseelinger@sh-law.com
Whether a client’s prompts to a generative AI tool and the documents it produces are protected from disclosure depends on the case type, who claims protection, and whether counsel was involved. In United States v. Heppner, a New York federal judge ruled that a criminal defendant’s communications with an AI platform were protected by neither the attorney-client privilege nor the work product doctrine. Since then, federal courts in civil cases have reached a different result, holding that a party can assert work product protection over AI-assisted materials. The safest course for businesses and individuals remains the same: treat AI platforms as third parties and involve counsel before using them in connection with a legal matter.
Under well-established law, to qualify for attorney-client privilege, a communication must satisfy three elements:
Meanwhile, the work product doctrine protects materials prepared in anticipation of litigation. In federal civil cases, Rule 26(b)(3) of the Federal Rules of Civil Procedure extends that protection to materials prepared by or for a party, not only by counsel. In the criminal context, courts have historically focused on shielding attorneys’ mental impressions and legal theories. As discussed below, that distinction has become central to how courts treat AI-generated materials.
Generative artificial intelligence tools have become increasingly prevalent, while AI’s implications for the law remain in their infancy. In United States v. Heppner, Judge Jed S. Rakoff of the Southern District of New York considered a question of first impression: when a user communicates with a publicly available AI platform in connection with a pending criminal investigation, are those communications protected by the attorney-client privilege or the work product doctrine?
As detailed in court documents, a grand jury indicted Bradley Heppner on charges of securities fraud, wire fraud, conspiracy, making false statements to auditors, and falsifying corporate records. In connection with Heppner’s arrest on November 4, 2025, FBI agents seized numerous documents and electronic devices. The seized materials included approximately 31 documents memorializing communications Heppner had with the generative AI platform Claude, operated by Anthropic.
Following his indictment, Heppner’s counsel asserted privilege over the AI documents, arguing that (1) Heppner had inputted into Claude information he had learned from counsel; (2) Heppner had created the documents for the purpose of speaking with counsel to obtain legal advice; and (3) Heppner had subsequently shared the contents with counsel. Counsel conceded, however, that they did not direct Heppner to run the AI searches. The Government sought a ruling that the documents were protected by neither the attorney-client privilege nor the work product doctrine.
Judge Rakoff agreed, ruling that the AI documents were not protected. His decision did not create new law; it applied existing privilege precedent to AI technology.
Judge Rakoff first determined that the AI documents lacked key elements of the attorney-client privilege. He found:
Notably, Judge Rakoff left open whether AI used at counsel’s direction or under secure, enterprise protocols could qualify for privilege.
Judge Rakoff also rejected work product protection. Although Heppner claimed he generated the materials in anticipation of litigation, counsel expressly did not direct him to use the AI tool. Judge Rakoff stressed that, in this context, work product must stem from or be at the direction of counsel. Independent client research, even if litigation-related, did not qualify.
Heppner made waves, but its reach is limited because it was a criminal case. In federal civil litigation, courts have declined to follow it. In Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 10, 2026), the court allowed a plaintiff to assert work-product protection for materials created using AI. More recently, the District of Colorado addressed Heppner directly in Morgan v. V2X, Inc. (D. Colo. Mar. 30, 2026).
Morgan is another formative case concerning discovery and generative AI. The immediate concern in Morgan was whether the pro se plaintiff could invoke Rule 26(b)(3) to shield his litigation-related AI work from disclosure. Magistrate Judge Maritza Dominguez Braswell addressed the recent Heppner decision at the outset, distinguishing it on two grounds: (1) Heppner was a criminal case, thus there was no work product protection for parties; and (2) the Heppner defendant’s independent AI use created a separation between client and counsel that simply does not exist when the litigant is pro se and therefore occupies both roles.
The first point follows from the text of Rule 26(b)(3), which, as noted above, protects materials prepared by or for a party. The second point is more nuanced: because this protection turns on whether a document was prepared “in anticipation of litigation,” a pro se party that must act as both party and an advocate is better positioned to make that claim, particularly “in the context of a pro se litigant’s use of AI to assist with their litigation preparation, the use of AI closely resembles the kind of confidential, strategy-laden iterative work product that Rule 26(b)(3) was designed to protect.” Morgan, at *5. The inverse scenario matters for represented parties: when a represented party decides to use AI, there may be more Heppner-style skepticism regarding whether the AI use was performed in connection with the litigation.
With those distinctions in place, the Court then addressed whether work product protections were waived by disclosing information to a third-party AI provider, which typically uses that information to help train its models. This is perhaps the most consequential portion of the opinion, as Judge Braswell took on the question for a new era, “when nearly all electronic interaction passes through third-party systems.” Id. at *4. Judge Braswell rejected the proposition that sending information to a commercial AI provider necessarily destroys every reasonable expectation of confidentiality or automatically waives work product protection. Warner rejected that argument as well, finding that it “would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed.” Warner, 820 F. Supp. 3d at 637. Judge Braswell agreed, finding that information given to these third-party electronic intermediaries does not mean the information has effectively been exposed to an adversary or that the user has surrendered an expectation of privacy.
Indeed, Judge Braswell suggested that the privacy argument may be especially strong for generative AI because these tools are not merely “passive” systems that return search results: they are designed to engage users iteratively, invite candid disclosures, and interact in a way that “feels genuine and intimate.” Id. at *5. A more recent New York state decision echoed that point and adopted that analysis, finding it “persuasive.” Assini v. Hayward, 2026 WL 1677232, at *3 (N.Y. Sup. Ct. June 4, 2026). The relevant waiver inquiry therefore remained whether disclosure was made to an adversary, or in circumstances substantially increasing the likelihood that the adversary would obtain the material, not merely whether a third-party technology provider technically received it. Still, others, like Judge Rakoff in Heppner, may view the waiver issue differently.
Finally, Judge Braswell turned to an AI-related protective order dispute concerning the use of AI with confidential information. This debate is playing out in boardrooms and law firms across the country as stakeholders weigh the benefits of AI against the cost of transmitting sensitive data to a wider array of sub-processors. In Morgan, Judge Braswell rejected both sides’ proposed language to address uploading confidential information to AI providers: the plaintiff’s “secure, closed-circuit” formulation focused too heavily on conventional cybersecurity, while the defendant’s proposal appeared to be so closely engineered around its own vendor arrangements that it became unnecessarily complex. The Court instead drafted a functional middle ground:
No party or authorized recipient may input, upload, or submit CONFIDENTIAL Information into any modern artificial intelligence platform, including any generative, analytical, or large language model-based tool (“AI”), unless the AI provider is contractually prohibited from: (1) storing or using inputs to train or improve its model; and (2) disclosing inputs to any third party except where such disclosure is essential to facilitating delivery of the service. Where disclosure to a third party is essential to service delivery, any such third party shall be bound by obligations no less protective than those required by this Order. In addition, the AI provider must contractually afford the party or authorized recipient the ability to remove or delete all CONFIDENTIAL information upon request. A party intending to use AI that it contends meets these requirements must retain written documentation of these contractual protections.
As Judge Braswell acknowledged, these requirements all but ruled out using confidential information with a consumer-level AI subscription. The plaintiff’s cavalier use of generative AI on confidential documents drew scrutiny, and the court ordered him to disclose every AI platform to which he had submitted confidential information.
No business or individual wants to justify their AI use to a judge. The practical steps below can help avoid that outcome.
Taken together, these decisions confirm that while AI is novel, it remains subject to the longstanding principles governing confidentiality and privilege, and that the outcome may turn on whether the matter is civil or criminal and on who is claiming protection. Until the law settles, preserving privilege requires the same discipline always required when engaging third parties. Below are a few practical tips:
Generative AI can be a powerful productivity tool, but it should never replace confidential communications with counsel. Courts are still working out when AI-assisted materials are protected, and the answer currently differs between criminal and civil matters. Rather than rely on a favorable ruling, organizations should align their AI usage with established privilege principles. For guidance, don’t hesitate to contact us.
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Director and officer liability increases sharply when a company is in financial distress. Decisions that would draw little attention in a healthy business can later be challenged by creditors, shareholders, bankruptcy trustees, and regulators as breaches of fiduciary duty, fraudulent transfers, or oversight failures. Understanding where that exposure comes from, and how to manage it, […]
Author: Michael Mietlicki

For developers pursuing battery energy storage system (BESS) projects, finding the right property is only the beginning. BESS site selection is as much a legal and transactional exercise as a real estate decision, with risk analysis central to the project’s ultimate success. Key Takeaways The core questions for BESS site selection in New York and […]
Author: Nicholas Wall

What should you expect when meeting a litigation attorney about a business dispute? You should expect to describe the dispute in your own words, hand over the most important documents, flag any deadlines or immediate threats, and leave with a clearer picture of the problem, what information is still needed, and the likely next steps. […]
Author: Michael Mietlicki

Arbitration resolves disputes privately before an arbitrator whose decision is usually final, while litigation resolves them in court with full rights of appeal. Whether a business ends up in arbitration or litigation is often decided when it signs the contract, long before any dispute arises. Key Takeaways When facing a contract dispute, carefully consider your […]
Author: Graham Staton

Can you own part of a business in New Jersey without a written agreement? Yes, it is possible. Under New Jersey’s Uniform Partnership Act, a partnership can arise when two or more people carry on a business as co-owners for profit, whether or not they ever intended to form one. Ownership doesn’t necessarily depend on […]
Author: Michael Mietlicki

For New Jersey businesses, crisis preparedness should be viewed as a legal and operational function, not simply an emergency-management exercise. A well-designed crisis response plan can help preserve evidence, protect confidential communications, meet reporting obligations, limit unnecessary exposure, and prevent an already difficult situation from becoming a larger legal problem. Key Takeaways A serious crisis […]
Author: Sean M. Pena
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.
Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.
Let`s get in touch!
Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!