AI & Technology

AI and Privilege: When AI Becomes Evidence

By Matt Lafferman and Rick Shearer, Partners, Dentons

I. Introduction 

In Fortis Advisors v. Krafton, an executive’s exchanges with an AI chatbot became trial evidence bearing on the company’s intent.1 The executive had used the chatbot to develop a strategy for avoiding an earnout obligation, and the exchanges ultimately became powerful evidence in the adversary’s case. 

Generative artificial intelligence is no longer an emerging technology—it is part of the ordinary working environment. Employees use it to draft, summarize, test ideas, and assess business problems. Lawyers use it to organize facts, analyze issues, develop strategy, and draft legal documents. In-house counsel use it while advising business units that may already be using the same tools for operational purposes. 

As reliance on AI increases, new litigation risks are emerging around attorney-client privilege, work product protection, waiver, and discovery. The decisions to date do not establish a uniform rule. They suggest instead that courts will examine the purpose of the AI interaction, the user’s role, the confidentiality of the platform, the involvement of counsel, and the use ultimately made of the resulting material. Those fact-intensive inquiries create significant and still-unresolved questions for businesses, in-house counsel, and litigation counsel. 

II. The Legal Frame: Privilege, Work Product, and Business Use 

AI use can implicate two foundational doctrines. Attorney-client privilege protects confidential communications between lawyers and clients made for the purpose of seeking or providing legal advice. The work product doctrine generally protects materials prepared in anticipation of litigation, with protection more likely to be recognized for materials revealing counsel’s mental impressions, conclusions, opinions, or legal theories. AI can complicate the application of those protections. 

AI raises novel questions under each doctrine, particularly where employees use AI without attorney involvement or where legal and business functions overlap. For example, entering sensitive information into certain tools may raise confidentiality and waiver questions. And AI inputs and outputs generated by business users—including operational analyses, internal reports, compliance assessments, and internal communications—may (or may not) be treated differently than those generated for purposes of obtaining legal advice or in anticipation of litigation. 

III. What the Early Decisions Show 

The early AI-discovery decisions point in different directions. Some decisions treat AI exchanges as unprotected where the circumstances do not otherwise satisfy traditional privilege or work-product requirements. Others recognize that AI-assisted litigation work may fall within work product principles. The common theme is not a settled AI rule, but a familiar set of questions about purpose, confidentiality, counsel’s involvement, and the role the material played in litigation. 

IV. Emerging Fault Lines and Open Questions 

1. Confidentiality and Waiver 

United States v. Heppner presents one side of the emerging divide.2 The court denied privilege and work product protection for materials a criminal defendant generated using a consumer AI platform, emphasizing that the defendant acted on his own, not at counsel’s direction—but also that the platform’s privacy policy permitted the provider to collect inputs and outputs, use them for model training, and disclose them to third parties—including government authorities. Days earlier, however, the court in Warner v. Gilbarco rejected broad discovery into a pro se litigant’s use of AI in preparing her case, concluding that the request targeted her protected internal analysis and thought process rather than existing evidence.3 

Together, the cases underscore that courts are not asking whether AI was used in the abstract; they are asking how, why, by whom, and under what circumstances. 

The differing results may also reflect procedural context. Heppner arose in a criminal prosecution, while Warner applied Fed.R.Civ.P. 26(b)(3), the text of which protects qualifying materials prepared by or for a party or its representative. That distinction does not resolve the broader question, but it reinforces the central point: AI-related privilege and work-product disputes will turn on doctrine, context, and record—not on the mere presence of AI. 

Morgan v. V2X, Inc. added another fault line: tool identity.4 The court agreed that a pro se litigant’s AI-assisted litigation work could receive work product protection, but required disclosure of the AI tool’s identity because that fact did not itself reveal mental impressions or legal strategy. The court also entered AI-specific protective-order language governing the submission of designated confidential information to AI tools. Morgan therefore suggests that even where substantive AI exchanges may receive protection, surrounding facts—such as the tool’s identity and its handling of confidential information—may remain discoverable. 

Expert use raises a different concern. In Conservation Law Foundation, Inc. v. Shell Oil Co., a magistrate judge ordered disclosure of prompts used in connection with an expert’s review and analysis of materials relevant to her report.5 Although that order has been challenged and is pending review, the dispute illustrates why AI use in expert analysis may present distinct disclosure questions when prompts or outputs are treated as part of the expert’s methodology. 

These decisions point toward three recurring variables: First, who used the tool and why? Counsel-directed litigation work may raise different questions than business use, individual use, or expert methodology. Second, was confidentiality reasonably maintained? Platform terms, retention practices, and disclosure rights may affect privilege and waiver arguments. Third, how was the material used in the litigation? An AI exchange may be a protected internal drafting aid in one posture and discoverable evidence, tool information, or expert methodology in another. 

2. Can an AI Platform Function as an Agent of Counsel? 

One consequential open question is whether an AI platform can occupy a role analogous to a third-party agent of counsel. In dicta, Heppner left that possibility open, suggesting that attorney-directed use might resemble the use of a professional who assists counsel in providing legal advice. That suggestion invites comparison to United States v. Kovel, under which privilege may extend to communications involving a nonlawyer whose assistance enables or facilitates counsel’s provision of legal advice.6 

United States v. Adlman shows why that analogy is not automatic.7 There, the court rejected privilege for an accountant’s tax analysis where the record showed that the company consulted the accounting firm directly for business and tax advice, rather than counsel retaining the accountant to help provide legal advice. The court looked to the actual arrangement, not the label later attached to it. 

Whether courts will extend the Kovel rationale to AI systems remains unsettled. The analogy raises difficult questions about agency, confidentiality, legal purpose, and the distinction between a tool used by counsel and an independent source of analysis. Those questions are likely to turn on facts courts have only begun to encounter. 

3. Prompts, Outputs, and Work Product 

Even where work product protection applies, the character of the material matters. Opinion work product protects counsel’s mental impressions, conclusions, opinions, and legal theories. Ordinary or fact work product receives qualified protection and may be discoverable upon a showing of substantial need and undue hardship. AI materials may implicate both categories, but the governing inquiry should remain what the material reveals. 

Future disputes may require courts to distinguish between attorney-authored prompts that reveal litigation strategy and AI-generated outputs that principally summarize facts. Depending on its content and context, an attorney-authored prompt may reveal judgment about what to ask, how to frame a problem, and which legal theories to test. An output may instead be a machine-generated synthesis of information. But the early cases do not yet establish a clear rule, and the character of the material (not merely the use of AI) should remain central to the analysis. 

That distinction also cautions against assuming that attorney review alone transforms AI-generated material into opinion work product. The question is not simply whether a lawyer interacted with the output. It is whether the material itself reveals protected legal judgment. 

4. In-House Counsel and Mixed-Purpose AI Use 

In-house counsel face particular challenges because corporate legal departments often operate close to business decision-making. When a communication reflects both legal and business considerations, the business aspects do not become privileged merely because legal considerations are present. AI use can intensify that problem by producing risk assessments, compliance analyses, and internal reports that may sit uneasily between legal advice and business analysis. 

5. The Aggregation Problem 

AI interactions also raise a risk of scale. A single chat session can compress iterative drafts, factual narratives, strategic reflections, and rejected approaches into one continuous exchange. That structure may complicate privilege review because protected and unprotected material can appear in the same thread. Depending on the circumstances—including whether any disclosure was intentional and whether fairness considerations are implicated—disputes may extend beyond an isolated prompt or response to surrounding portions of the interaction. 

6. Applying Familiar Doctrine to New Technology 

Courts are beginning to fit AI interactions into familiar privilege and discovery doctrines, but the technology does not map neatly onto traditional categories. That said, some of the decisions to date suggest that courts have reached for familiar analogies precisely because the technology resists easy classification. Privilege claims over AI materials may be tested against traditional markers: privilege legends, engagement documentation, attorney authorship. The resulting disputes are likely to turn not on AI-specific labels, but on whether the substantive requirements of privilege and work-product protection are satisfied in the particular circumstances. 

V. Why Existing Governance and Discovery Practices May Need Reassessment 

The decisions to date may prompt organizations to examine whether existing AI governance adequately distinguishes business uses from legal uses, accounts for platform confidentiality, and anticipates litigation obligations. The appropriate analysis will depend on the organization’s technology, risk profile, legal needs, and the disputes it faces. Courts may examine who directed the use, why the system was used, what information was supplied, what records were created, and how the resulting material was used or distributed. Because those circumstances vary across platforms, organizations, and disputes, AI-related privilege and discovery issues require a fact-specific assessment. But many open questions remain, such as: 

  • Permitted Platforms: Which platforms are appropriate for business workflows, and which for legal ones? Should legal work be confined to particular platforms? Morgan suggests that courts may prohibit organizations from inputting the opposing party’s confidential litigation materials into consumer AI platforms. Meanwhile, Heppner reflects that the key factors for protecting against disclosure risk involve how the platform operates, which may not always be determined by whether the AI platform is closed or an enterprise version. 
  • Human Review and Supervision: What role should attorneys play in reviewing AI outputs? Should attorneys be required to incorporate their mental processes, opinions, and thoughts into all AI-generated outputs? How attorneys interact with AI work product may be considered as a factor in determining whether such work is opinion, not fact, work product. 
  • Prompt and Output Practices: Should there be limitations on who drafts prompts for legally sensitive work? How should outputs containing privileged analysis or strategy be marked and circulated? Should the same marking and handling requirements be used as for other privileged documents? Traditional markers such as privilege legends, engagement documentation, and attorney authorship may impact how courts view whether such prompts and outputs are privileged.   
  • Training: What do legal and business users need to understand about privilege, confidentiality, and disclosure risk? Is there value to organizational-wide training on prompt structure, appropriate use cases, and documentation of legal purpose?  
  • AI Workflow Considerations: Should there be specific practices for building legal AI agents? Are there disclosure risks for AI-generated analysis evaluating organizational liability on specific issues? Can legal prompts incorporate instructions that can improve arguments for privilege (e.g., directing legal AI tools to treat all inputs as attorney work product and marking outputs accordingly)? Should legal AI tools be directed to filter out potentially privileged information for business or operational workflows? As in Heppner, courts may examine the operational aspects of the legal AI tool or agent when determining whether to extend privilege.    

In contrast, a different set of questions arises for litigators. AI interactions may present unfamiliar preservation, collection, privilege-review, protective-order, and expert-discovery issues, such as: 

  • Preservation: Fortis suggests that AI prompts and outputs are discoverable. In light of this risk, how is AI-related ESI being identified, preserved, collected, and reviewed within existing discovery workflows? And how should litigation hold templates be revised to account for preservation? 
  • Treatment in Litigation: How should litigators account for AI work product in litigation? Morgan suggests that courts may enter protective orders governing such work product. But questions about how to structure such orders remain. Should confidential information be uploaded by opposing parties into their AI tools? What notice and remediation procedures should apply to inadvertent transmission through AI platforms? Should an expert’s AI use be limited? 

Conclusion 

The law governing AI privilege and discovery remains in flux. The early cases are fact-specific, platform-specific, and posture-specific. Yet they already illustrate one point: AI interactions are entering the litigation record. Organizations that use AI in legal, business, investigative, or expert contexts should understand that courts may ask traditional privilege and discovery questions in unfamiliar technological settings. The technology is new. The task of establishing protection is not. For businesses and counsel, the challenge is not to apply a generic checklist, but to evaluate how particular AI systems, use cases, and litigation demands fit within doctrines that are only beginning to adapt. 

About the Authors 

 

Matt Lafferman is a partner at Dentons, where he focuses on complex commercial litigation, regulatory investigations, and technology-related disputes. A member of the firm’s AI Task Force, he advises clients on AI governance and the integration of AI into legal workflows and publishes and speaks on emerging issues at the intersection of AI and legal practice. 

 

 

 

Rick Shearer is a partner in Dentons’ Litigation and Dispute Resolution practice, where he represents clients in complex commercial and real estate litigation and arbitrations nationwide. He also advises clients on emerging issues at the intersection of AI and litigation, including AI governance, privilege, discovery, and risk management. 

Related Articles

Back to top button