
On Feb. 6, a federal court determined that a defendant’s communications with a Large Language Model (LLM or AI) – specifically, Claude – regarding pending criminal charges against him were discoverable and unprotected by attorney-client privilege.
This ruling, in United States v. Heppner, 820 F. Supp. 3d 292, 297 (S.D.N.Y. 2026), is in keeping with longstanding attorney-client privilege interpretations; chiefly, that only communications between counsel and the client can be subject to the attorney-client privilege. The U.S. District Court for the Southern District of New York (SDNY) held that: “AI Documents are not like confidential notes that a client prepares with the intent of sharing them with an attorney because Heppner first shared the equivalent of his notes with a third party, Claude.”

Much has been written about the increasing reliance on AI chatbots, AI personal assistants and AI even serving as a companion. The risk here is that clients believe their AI tools are an essential part of their work and, therefore, also believe their interactions with the LLM are privileged. But a client’s communications with open-source LLMs are likely not privileged. In a different federal ruling, the SDNY held that “[i]n the absence of an attorney-client relationship, the discussion of legal issues between two non-attorneys is not protected by attorney-client privilege.”
Increasingly, litigating attorneys are explicitly asking for the opposing party’s prompts submitted to AI platforms. These prompts can reveal a client’s mental impressions, as well as their attorney’s.

This remains an evolving area of law, especially in civil cases with self-representing (pro se) litigants. For example, in the U.S. District Court for the Eastern District of Michigan, Magistrate Judge Anthony P. Patti characterized a pro se litigant’s use of a generative AI program as protected under the Work Product Doctrine. Judge Patti reasoned that AI programs functioned as “tools, not persons” and therefore the Work Product Doctrine could still prevent disclosure. Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629, 636 (E.D. Mich. 2026).
A federal court in Colorado adopted this reasoning, holding that a pro se plaintiff “can assert work product protections in connection with his AI use.” In reaching this conclusion, the court expressly distinguished Heppner on two key grounds. First, Heppner arose in the criminal context, whereas Federal Rule of Civil Procedure Rule 26(b)(3) in civil litigation broadly protects a party’s work product, not just that of counsel. Morgan v. V2X, Inc., No. 25–CV–01991–SKC–MDB, 2026 WL 864223, at *4 (D. Colo. Mar. 30, 2026). Second, “there was a gap between the party and the attorney” in Heppner because the defendant consulted the Claude AI platform independently of his lawyer. Id. By contrast, there is no such gap when a plaintiff proceeds pro se.
While these decisions are based on separate legal issues, the fact remains that privilege and the protection of documents generated with open source AI is not a settled matter, and everyone should be worried about risking unintentional waiver.
In sum, people who are in active litigation, are considering litigation, or have ongoing concerns about discovery disclosures should be wary of asking any AI platform for legal advice. For litigants to protect themselves against unintentionally waiving privilege, legal questions should be directed to counsel and only to counsel.
Authors

Thomas G. French
Senior Attorney
221 N. La Salle St., Suite 3500
Chicago, IL 60601
T: (312) 970-3490
tfrench@plunkettcooney.com

Grace Reily
Associate
38505 Woodward Ave., Suite 100
Bloomfield Hills, MI 48304
T: (248) 433-7193
greilly@plunkettcooney.com








