If a client types something about their case into ChatGPT, is that conversation privileged? In February 2026, two federal courts answered that question within ten days of each other, and reached opposite results. A Massachusetts state court added a third data point in July. Taken together, they’re often described as a split in the law. Read closely, they’re something more useful than that: a consistent test, applied to three different sets of facts.
The two February rulings
Warner v. Gilbarco, Inc. (E.D. Mich., decided February 10, 2026): A pro se plaintiff in an employment discrimination case had used a generative AI tool to help prepare litigation materials. The defendants moved to compel production of everything related to that AI use, and asked the court to overrule any privilege or work product objection. Magistrate Judge Anthony Patti denied the motion, protecting the plaintiff’s AI-assisted materials as work product. The court’s reasoning centered on a simple idea: generative AI tools are, in the court’s words, tools, not persons, and using one doesn’t waive protection over a party’s own litigation-related thinking. Compelling production of that material, the court noted, would risk nullifying work product protection in nearly every modern drafting environment.
United States v. Heppner (S.D.N.Y., oral ruling February 10, written opinion February 17, 2026): A criminal defendant facing securities and wire fraud charges had used the AI platform Claude to prepare materials related to his defense, then asserted privilege over them. Judge Jed Rakoff disagreed, ruling from the bench that he saw no basis for any claim of attorney-client privilege. His written opinion, addressing what he called a question of first impression nationwide, held that the AI documents failed on multiple grounds: Claude is not an attorney, so the communications were never between a client and counsel in the first place, and the materials weren’t prepared at counsel’s direction or shown to reflect defense strategy. Both privilege and work product protection were denied.
The distinction that actually matters
On the surface, these look contradictory: one court protected AI-assisted materials, the other stripped protection entirely. But the facts differ in exactly the way that matters under existing doctrine. In Warner, the litigant’s own use of AI to organize her own thinking was treated the way any self-prepared litigation material would be treated. In Heppner, the defendant’s AI use was not directed by counsel, did not involve counsel at all in its creation, and the court found no indication it reflected legal strategy. Several law firms tracking these decisions have made the same point: neither ruling changes privilege law. Each applies the same, decades-old test, involvement of counsel, purpose of the communication, expectation of confidentiality, to a new kind of tool.
A Massachusetts state court reinforced the same pattern in Shealy v. Seaside Investments, LLC, a commercial dispute decided in the Business Litigation Session of the Superior Court. There, a party’s romantic partner, not an attorney, had used ChatGPT to help prepare materials related to the case. The court held that neither the partner nor the AI tool qualified as a “representative” for work product purposes, so the resulting materials were not protected. Again, the deciding factor wasn’t the presence of AI. It was the absence of counsel.
What this means in practice
For litigators, the practical takeaway is specific: if you want AI-assisted work product to be protected, the involvement of counsel needs to be real and demonstrable, not assumed. That means directing the AI use, or at minimum being able to show the materials were prepared in anticipation of litigation and reflect legal strategy, not just a client or employee thinking out loud into a chatbot.
For General Counsel and in-house teams, this is a policy problem as much as a legal one. A blanket instruction to avoid AI entirely doesn’t reflect how these rulings actually work, and it’s also increasingly unrealistic given how embedded these tools already are in day-to-day work. The more useful policy question is narrower: for any matter where privilege might eventually matter, is AI use happening under attorney direction, documented as such, and kept within tools whose confidentiality terms have actually been reviewed. Consumer-grade AI platforms, several firms tracking this area have noted, often retain user inputs for model training under their own terms of service, which raises a separate confidentiality problem even before privilege is considered.
For legal operations and legal technology teams, the practical distinction between a public AI tool and an enterprise instance with contractual confidentiality protections is becoming a real compliance line, not just a preference. Several of the law firm client alerts tracking this area draw exactly that distinction: enterprise AI tools used at the direction of counsel tend to fare better under these emerging rulings than consumer tools used independently.
Where this goes next
These are early decisions, not settled law, and legal commentators tracking the issue are explicit that many other courts have yet to weigh in. Some have noted the doctrinal questions could extend beyond attorney-client and work product privilege into other protected relationships as AI tools become more embedded in personal and professional life generally. Worth watching, and worth updating internal AI-use guidance for now rather than waiting for a definitive answer that may be a while coming.
This article reflects the status of these rulings as of the publication date below. As with any actively developing area of law, readers should confirm current status and consult counsel before relying on this piece for compliance purposes.