Generative artificial intelligence has rapidly become part of modern litigation. Lawyers and litigants increasingly use AI platforms to organize facts, summarize discovery, develop arguments, draft filings, and perform legal research. As use of these tools grows, courts are beginning to confront a new question: Are AI prompts, inputs, uploads, outputs, and chat histories discoverable?
Four recent decisions underscore the emerging debate. Importantly, these orders do not exist in independent silos. The courts are already engaging with, and testing, one another’s reasoning. The central issue is whether AI interactions should be viewed primarily as discoverable communications with a third party or as protected litigation work product.
In Warner v. Gilbarco, Inc., an employment discrimination claim, defendants sought discovery concerning a pro se plaintiff’s use of AI in connection with pending litigation. The U.S. District Court for the Eastern District of Michigan denied the request in February 2026. It found that the materials sought implicated the plaintiff’s mental impressions, thought processes, and litigation strategy and were therefore protected under the work-product doctrine. The court also rejected the argument that inputting privileged information into ChatGPT automatically waived work-product protection, noting that ChatGPT and similar systems are “tools, not persons.”
Just one week later, the Southern District of New York took a markedly different approach in United States v. Heppner. There, a white-collar criminal defendant asserted attorney-client privilege and work-product protection over communications he had with Anthropic’s Claude after learning he was the target of a federal criminal investigation. The court rejected both claims. On the attorney-client privilege claim, Judge Rakoff emphasized three points: first, Claude was not a lawyer, meaning communications with Claude were not attorney-client communications; second, Anthropic’s published privacy policies disclosed that user inputs and outputs could be collected, retained, and disclosed, undermining any claim of confidentiality; and third, Heppner did not communicate with Claude for purposes of obtaining legal advice. On the work-product claim, the court held that the defendant acted independently of counsel: defense counsel did not direct the client to use Claude, and the resulting materials did not reflect counsel’s mental impressions or litigation strategy when created. As a result, the court held the materials were neither privileged nor protected work product.
Approximately six weeks later, in March 2026, AI issues resurfaced in Morgan v. V2X, Inc. Like Warner, the Morgan case involved a pro se litigant. The Morgan court (in the District of Colorado) commented on the Heppner order, writing that:
The Heppner decision is of course not binding on this Court, but even if it were, the case is distinguishable for at least two reasons. First, Heppner was a criminal matter; this is a civil case governed by the Federal Rules of Civil Procedure, and the text of Rule 26(b)(3) broadly protects the work product of a party, not merely counsel. Second, in Heppner, there was a gap between the party and the attorney because the defendant acted entirely apart from his lawyer. No such gap exists in the pro se context. A pro se litigant is simultaneously the party and the advocate.
The Morgan court, relying on the Warner order, concluded that Rule 26 work-product protection could apply to a pro se litigant’s AI-assisted litigation preparation. It reasoned that AI interactions frequently resemble the same type of iterative case analysis, strategy development, and litigation preparation that the work-product doctrine has historically protected. The court further rejected the argument that use of AI automatically waives work-product protection merely because a third-party provider receives and stores the information. More broadly, the court held that “[g]iven how AI tools function, it is entirely reasonable for a person to expect some privacy and confidentiality when interacting with these tools, even though they understand a third party is behind the tool collecting and storing their information.”
By March 2026, therefore, two federal courts had adopted a substantially more protective view of AI-assisted litigation preparation than the one articulated in Heppner, albeit in the context of civil pro se litigants as opposed to Heppner’s criminal defendant represented by counsel.
In an even more recent order, Assini v. Hayward, a plaintiff served a subpoena on OpenAI seeking prompts, uploads, outputs, drafts, and other AI-related materials associated with a pro se defendant’s AI account. The New York court referenced both Heppner and Morgan, ultimately siding with the Morgan court’s reasoning: AI-assisted litigation preparation closely resembles “confidential, strategy-laden iterative work product.” The court quashed plaintiff’s subpoena.
Although these cases do not establish bright-line rules, several themes are beginning to emerge.
First, courts remain reluctant to extend traditional attorney-client privilege to communications with public AI systems. Heppner suggests that communications with AI providers may lack the confidentiality necessary to support privilege claims, particularly where the provider’s terms of service contemplate retention, training, or disclosure of user information.
Second, courts appear considerably more willing to protect AI-assisted litigation preparation under work-product principles. Warner, Morgan, and Assini all recognize that AI prompts, drafting iterations, research exchanges, and strategy discussions may reveal mental impressions, legal theories, and litigation strategy, at least for pro se litigants.
Third, the courts are increasingly focusing on why AI was used. Discovery requests aimed at uncovering a party’s thought process, litigation strategy, or legal theories have generally been met with skepticism. By contrast, courts may be more receptive where AI-related discovery is sought for a specific evidentiary purpose, such as determining whether confidential information was improperly uploaded to a third-party system. Morgan, for example, protected AI-assisted work product while still requiring disclosure of the identity of the AI platform used with confidential information.
The most noteworthy feature of the current case law is not consensus but interaction. Morgan directly distinguished Heppner and instead relied on Warner. Assini expressly adopted Morgan's reasoning and declined to follow the broader implications of Heppner. As additional courts confront AI-discovery disputes, they are likely to choose between these competing approaches.
If you have any questions about the issues raised in this alert, please contact Ryan Ellard or the Womble Bond Dickinson attorney with whom you normally work.

/Passle/678034865f458907b06ca7a9/SearchServiceImages/2026-06-25-15-58-57-572-6a3d50411150189b8ac26f9f.jpg)
/Passle/678034865f458907b06ca7a9/SearchServiceImages/2026-06-08-18-42-18-875-6a270d0a732d4df5ed36c0d5.jpg)
/Passle/678034865f458907b06ca7a9/SearchServiceImages/2026-06-08-15-27-40-322-6a26df6ce92742e48e73dbeb.jpg)