Quick Answer
No. A Texas Business Court judge held in June 2026 that using ChatGPT did not itself waive work product protection over the resulting conversations. That framing is correct. But it omits two failure modes a federal court addressed four months earlier. In United States v. Heppner, Judge Rakoff of the SDNY held that 31 AI-generated documents were not protected: counsel had not directed the defendant's use of Claude, and the consumer privacy policy permitted disclosure to governmental authorities. The authorship element and the vendor's data settings are where work product risk actually lives. The tool itself does not decide the question. The terms of service might.
Work product protection under Rule 26(b)(3) of the Federal Rules of Civil Procedure codifies three requirements: a document or tangible thing, prepared in anticipation of litigation or for trial, by or for a party or its representative. The third requirement is the one AI tools put under pressure. Whether AI-generated material qualifies as "prepared by or for a party's representative" depends not on the AI itself but on who directed it and, more importantly, on what the vendor's service agreement permits the vendor to do with your inputs.
Two 2026 decisions frame the question precisely. In June 2026, a Texas Business Court judge ruled that using ChatGPT did not itself waive work product protection. In February 2026, Judge Jed S. Rakoff of the SDNY reached a result that looked different, not because AI was involved, but because counsel had not directed the use and the consumer privacy policy permitted disclosure to governmental authorities. The gap between those two outcomes is not a contradiction. It is a map of where the risk actually lives: in how the attorney engaged the tool, and in what the vendor's terms permit.
I have spent time with litigation teams working through these deployment questions, and I think the framing most practitioners encounter, that AI is a tool and tools do not constitute third parties, is correct as far as it goes. It does not go far enough. A photocopier does not retain your documents and train on them. A dictation service does not share transcripts with government authorities under its terms of service. The tool analogy holds for some AI deployments. It does not hold for all of them.
What This Article Answers
- Does using AI to analyze case files automatically waive work product protection under FRCP 26(b)(3)?
- Which specific vendor settings can convert a confidential AI tool into a third-party disclosure that risks waiver?
- How does a private, no-train deployment differ from a consumer AI product on the work product question, and what does a privilege-gate architecture look like in practice?
What the Work Product Test Actually Requires
Work product protection is not a doctrine about secrecy in the abstract. It has a structure.
The three-part test, as codified in FRCP 26(b)(3) and developed since Hickman v. Taylor, 329 U.S. 495 (1947), requires that a document or tangible thing be prepared in anticipation of litigation or for trial, by or for a party or its representative. Each element can fail independently. AI tools change the analysis on the third element in ways the first two do not touch, as of .
The first element is satisfied by almost any output an AI system produces. A draft chronology. A summary of deposition themes. A set of proposed issue codes. These are documents. The element is not in dispute when AI generates them in a litigation context.
The second element, anticipation of litigation, is determined by the context in which the material was prepared, not by the type of tool used. An attorney using AI to analyze active case files produces material in anticipation of litigation. A defendant using a consumer AI product on his own, without counsel, after receiving a grand jury subpoena, is a closer question. In United States v. Heppner, the court did not ultimately need to resolve whether the material was prepared in anticipation of litigation because the other elements failed first. The point is that the tool does not determine the context. The facts surrounding its use do.
The third element is where the analysis fractures. "By or for a party or its representative" means prepared by the attorney or someone acting under the attorney's direction. The requirement is not that the attorney used the output. The requirement is that the preparation was conducted under meaningful attorney direction. When an attorney crafts a prompt, reviews the output, and adopts or substantially revises it, the authorship element is plausibly satisfied. The attorney directed the process. The attorney exercised professional judgment on the result.
The Heppner facts isolate the failure mode. Defense counsel conceded that counsel had not directed the defendant to use Claude. The defendant had generated the documents himself, without attorney guidance, using a consumer product. The court held those documents were not protected, in part because the "by or for counsel" element was not satisfied. The AI did not direct the defendant. The attorney did not direct the defendant. No one who could claim the doctrine directed the defendant.
This matters for firms whose attorneys use AI as a passive intermediary. An attorney who uploads a document set and forwards the AI's summary without independent assessment has a weaker claim to "prepared by counsel" than an attorney who reviews, annotates, and substantially shapes the output. The difference is not the technology. The difference is whether counsel exercised judgment or merely transmitted a result. Courts have historically asked that question about associate memos and paralegal research. They will ask it about AI outputs as well.
| Work Product Element | AI Impact | Risk Level |
|---|---|---|
| Document or tangible thing | AI output qualifies as a document in virtually all configurations | Low |
| Anticipation of litigation | Determined by context of use, not by the tool | Low |
| By or for counsel (authorship) | Requires meaningful attorney direction and review; passive transmission of AI output weakens the claim | Moderate to High |
| No third-party disclosure (waiver) | Turns on vendor data retention and training settings; consumer terms may constitute third-party disclosure | High |
In summary, the first two elements of the work product test are largely unaffected by AI. The third element, and the waiver analysis that follows, are where the technology creates genuine doctrinal pressure.
Why the Vendor's Data Settings Change the Legal Analysis
The consensus framing that AI is a tool and tools do not constitute third parties depends on a specific assumption: that the AI vendor occupies the same functional role as a photocopier or a dictation service, receiving your data, processing it, and returning it without acquiring any independent rights over the material. That assumption is accurate for some AI deployments. It is not accurate for all of them, and the distinction turns almost entirely on the vendor's service agreement.
The work product waiver analysis follows the same structure as the attorney-client privilege waiver analysis: voluntary disclosure to a third party who is not an agent of the attorney or client destroys protection. The key word is "voluntary." If an attorney knowingly uses a service whose terms permit the vendor to retain, review, or train on inputs, the disclosure is voluntary. The attorney chose the service. The attorney agreed to the terms, whether or not the attorney read them.
In United States v. Heppner, the court relied on Claude's consumer privacy policy as part of its analysis. That policy, at the time, permitted collection of inputs and outputs, use of that data to improve the model, and disclosure to third parties including governmental authorities. The court reasoned that the defendant had used a service whose terms were inconsistent with the confidentiality the privilege and work product doctrine require. The vendor was not functioning as a confidential agent. The vendor had reserved rights over the data that a confidential agent would not have.
This is the one setting that can decide the question. OpenAI's enterprise API operates under terms that, by default, prohibit training on customer data. OpenAI's consumer product has operated under different terms. As the Medium analysis by Ross Brodskiy noted in March 2026, "OpenAI's enterprise privacy statement describes a default no-training posture for business data, and Microsoft's Copilot documentation states that prompts and responses are not used to train foundation models under enterprise data protection." These are not the same service. They should not be analyzed as if they were.
There is a secondary issue that is easier to overlook: retention of AI interaction logs. If a vendor retains logs of your prompts and outputs, those logs are potentially responsive to discovery requests. A Rule 34 request for "all documents relating to the preparation of Exhibit 14" could reach a vendor's retained logs of the prompts and outputs used to prepare that exhibit. Whether such logs are themselves protected work product, or whether they fall into a category of vendor transaction records outside the doctrine, is not resolved. Practitioners should not assume the resolution will favor them.
The ABA Litigation News piece from August 2026, "Communicating with AI Jeopardizes Privilege Claim," identified the risk correctly but did not fully isolate the mechanism. The risk is not in communicating with an AI system. The risk is in the terms under which the system received the communication and in what the provider is permitted to do with it afterward. Those terms vary by deployment type in ways that are legally significant.
| AI Deployment Type | Default Training on Your Data | Log Retention | Third-Party Risk |
|---|---|---|---|
| Consumer product (ChatGPT, Claude.ai) | Historically yes; varies by current settings | Vendor-controlled with vendor access | High: vendor may constitute a third party |
| Enterprise API (OpenAI, Anthropic) | No by default under business terms | Vendor-controlled with stricter policy | Moderate: no training, but log access remains |
| Private cloud (Azure OpenAI, AWS Bedrock) | No: contractually prohibited | Firm-controlled only | Low: vendor functions as confidential agent |
| On-premise model | No: model never contacts vendor | Internal only | Very low: no third party in the data chain |
In summary, the tool itself does not create third-party disclosure risk. The specific terms governing data retention and model training are the variable that determines whether a vendor is inside or outside the confidential-agent relationship the doctrine depends on.
How a Private Deployment Preserves the Confidential-Agent Relationship
A private deployment of an AI model is, from a privilege-preservation standpoint, a fundamentally different configuration than a consumer product or a standard enterprise API arrangement.
In a private deployment, the model runs on infrastructure that the firm or its trusted vendor controls. Inputs do not flow to the model provider's shared servers. The model does not train on case-specific data. Logs, if retained at all, are retained under the same confidentiality architecture that governs the firm's other work product.
The major cloud providers, Microsoft Azure OpenAI Service, Amazon Web Services Bedrock, and Google Cloud Vertex AI, each offer configurations in which the model is hosted within a private or virtual-private cloud environment. In each case, the provider contractually commits that customer data is not used for training the base model. The input reaches the compute resource. It does not flow back into the provider's model improvement pipeline. A vendor operating under that contractual commitment looks substantially more like a confidential agent and substantially less like a third party with independent data rights over your inputs.
From what I have observed working with litigation teams on AI deployment, the firms that have thought through the work product question tend to use a privilege-gate architecture built on three components. First, all case-specific AI workloads run within a private or enterprise deployment that contractually prohibits training-data use. Second, AI interaction logs are treated as work product from the moment they are created, subject to the same litigation hold procedures as any other case file. Third, a written attorney review protocol requires counsel to review, annotate, and take responsibility for all AI-generated analysis before it is shared internally or relied upon in any filing. Relevant eDiscovery processes case files under precisely this model: single-tenant processing, in-account AWS deployment under the client's own keys, with no vendor retention and no model training, so nothing that enters the system can train an external model or be accessed by vendor personnel.
The third component is not merely a quality-control measure. It is the mechanism by which AI-generated material acquires the "by or for counsel" character the work product doctrine requires. The Heppner court identified the failure mode in the negative: counsel had not directed the defendant's Claude use. The corrective is to document the affirmative. When an attorney directs an AI prompt strategy, reviews the outputs, and makes documented judgments about what to incorporate and what to discard, the attorney is the author of record in the same sense that a supervising partner is the author of record for an associate's research memorandum.
The court's dicta in Heppner pointed toward this result. As the Medium analysis noted, the court suggested the analysis "might differ if counsel had directed the AI use, noting that in that scenario the AI tool might function 'akin to a highly trained professional' acting as the lawyer's agent, with the court citing Kovel-type agency principles." The Kovel doctrine protects communications to third-party consultants when those consultants assist counsel in rendering legal advice. A properly deployed AI tool, directed by counsel and operating under terms that preserve confidentiality, is plausibly within that framework. A consumer product whose terms permit governmental disclosure is not.
The specific setting that most directly creates waiver risk is model-training data consent. This appears as a toggle in enterprise settings, as a default permission in consumer products, and sometimes as a provision buried in supplemental terms that practitioners do not read before uploading case files. Confirming the state of that setting, in writing, before any case material reaches an AI system is the single most consequential step a litigation team can take on the work product question.
In summary, the private deployment is not a luxury feature. It is the configuration that preserves the confidential-agent relationship on which the "AI is a tool" argument depends, and its absence is the condition under which that argument fails.
What Will Matter Most in the Next 12 to 24 Months
The next two years will almost certainly produce the first wave of reported decisions that directly address AI-generated work product in civil litigation, as distinct from the criminal context of Heppner. Civil litigation presents different fact patterns and different incentives for courts. In a civil context, opposing counsel who learns that work product was generated using a consumer AI product with permissive data terms will have a colorable argument for production that did not exist five years ago. That argument will be tested.
Three developments seem most likely to define the doctrine's direction.
First, a civil court will confront the specific fact pattern of a consumer AI product with model-training consent enabled. The question will not be abstract. It will be: did this firm's use of this specific product, under these specific terms of service, constitute voluntary disclosure to a third party? The answer will turn on what the firm agreed to when it accepted the service terms. Firms that relied on the general "AI is a tool" framing without examining specific terms will not have a credible counterargument once opposing counsel produces the vendor's privacy policy in discovery.
Second, discovery practice will adapt to AI workflow artifacts. As the r/Lawyertalk thread from the legal practitioner community observed in 2026, practitioners are already anticipating that opposing counsel will submit requests targeting AI tool usage, then subpoena AI providers. Rule 34 requests targeting vendor logs, AI-generated draft analyses, and prompt histories will become more common in the next 12 to 18 months. Whether those materials are protected work product, or vendor records outside the doctrine, will be contested. The outcome will depend on both the authorship question and the vendor terms question.
Third, bar guidance will begin to differentiate by deployment type. Current ethics opinions treat AI as a category. Within 24 months, I think we will see opinions that distinguish between consumer tools, enterprise API arrangements, and private deployments, because those configurations have materially different data-rights implications that are now visible in case law. The ABA's August 2026 article signals that the bar is beginning to recognize the distinction, even if the published guidance has not yet operationalized it. Firms that have already made this distinction in their AI governance protocols will have an easier compliance path when formal guidance arrives.
The underlying structural gap will not close on its own. AI tools are becoming central to litigation practice, and the work product doctrine was built for a world in which documents were prepared by human attorneys using tools that did not have contractual rights over the attorney's inputs. Closing that gap requires not a retreat from AI but a deployment approach that preserves the confidential-agent relationship the doctrine has always assumed. That approach exists. It requires choosing the right configuration and documenting the attorney's direction of it.
Outlook - next 12-24 months
Where AI Privilege Rules Head in Litigation
Three scored forecasts on how courts, vendors, and pricing reshape work-product protection and AI-assisted document review.
What courts and vendors do next
Use each forecast to judge how to deploy AI in a matter without losing work-product protection or overpaying for review.
Within 12-24 months, opposing counsel will routinely ask which AI tools a party used and subpoena the providers, pushing firms toward deployments with no vendor retention and no model training so that inputs cannot be held by a third party and pulled into discovery.
Contrary to the assumption that defensible document review requires an enterprise platform, AI-native review priced at cents per document will capture the solo and small-firm segment that Relativity and Everlaw price out, undercutting the roughly $19K/GB economics of manual review over the next 12-24 months.
Over the next 12-24 months, courts will increasingly protect AI-assisted work when an attorney directs and supervises it, while stripping protection from documents a party generates alone on public-facing chatbots after litigation is anticipated, extending the split between the Texas Business Court's work-product ruling and Judge Rakoff's Heppner decision.
Early indicators on the radar: A Texas Business Court judge shielded some AI chats as work product and held that AI use alone did not waive protection, while in United States v. Heppner the court refused protection for 31 documents a party generated on a consumer chatbot after a subpoena, with counsel conceding no attorney direction. Practitioners already describe opposing counsel serving interrogatories on AI tool use and subpoenaing providers, while single-tenant, in-account deployment under a client's own keys is marketed on the basis that nothing fed in is retained or used to train a model. Unanswered buyer demand centers on cutting document-review cost and comparing Relativity to alternatives, while AI-assisted review runs at cents per document against dollars-per-document manual work in a segment enterprise platforms cannot serve without a dedicated administrator.
Rulings and practitioner signals
Supporting court decisions and contrary practitioner sentiment are shown beside each forecast.
- Watch This Before You Use AI to Research Your Court Case supports this forecast. [Video]Rebecca Zung, who presents herself as "the leverage lawyer," states she has been a trial lawyer for 25 years. “The moment that you hand a third party without thinking about it information, you are now opening yourself up to what we call discovery.”
- Backing it: Texas Judge Shields Some ChatGPT Chats As Work Product. [Industry Publication]"A Texas Business Court judge shielded from discovery some of a party's personal ChatGPT conversations in car dealership buyout litigation, saying that the chats were protected work product and that using the OpenAI tool did not itself… “None available. No direct quotations (from the judge, counsel, or parties) appear in the extractable text; they are behind the paywall.”
- Brief on AI Tools (Otter.AI), Privilege, and Work Product in - Medium is what puts this forecast on the board. [Blog]In *United States v. Heppner*, Judge Jed S. Rakoff of the U.S. District Court for the Southern District of New York issued a memorandum opinion filed Feb. “The court held "AI is not an attorney" and emphasized that Claude "was not, and could not be, an attorney.”
- The case rests on Watch This Before You Use AI to Research Your Court Case. [Video]Courts have held that material entered into a public-facing AI can be discoverable, meaning attorney-client privilege/work product protection may not apply.
What could shift these calls
Scenarios such as an appellate reversal or new ethics rules that would change how privilege and AI review evolve.
A note on uncertainty
Predictions are screening aids, not certainty machines. The strongest signal here scores 95/100, and the minority view (95/100) reflects a real spread in what the sources report.
- Should buyers or regulators reverse course, Vendor retention becomes the discovery battleground gives way first.
- Stronger contrary evidence in the sources would make Small-matter defensibility goes cheap the sturdier forecast.
The Checklist Before Any Case File Touches an AI Tool
The question is not whether to use AI on case files. AI tools have demonstrable value in litigation analysis, and the work product doctrine does not prohibit their use. The question is which configuration preserves the confidential-agent relationship the doctrine depends on, and which does not.
Before deploying any AI system on case material, three questions should have written, documented answers.
- Does the vendor's service agreement prohibit training on customer data? If the answer is "I turned off chat history" or "I think so," those answers are not sufficient. The UI history setting governs the display of past conversations. It does not govern what the vendor does with your inputs in its training pipeline. The answer should be a specific contractual provision, confirmed in writing, before the first case file is uploaded.
- What is the vendor's log retention policy, and are those logs subject to enforceable confidentiality obligations? If the vendor retains logs of prompts and outputs, and vendor personnel can access them, those logs create discovery exposure regardless of work product claims. A Rule 34 request can reach vendor-retained records. The answer to this question should be verified against the service agreement, not assumed.
- Is there a written attorney review protocol for AI outputs? The Heppner court found no attorney direction of the defendant's Claude use. The corrective is documentation: a protocol that records that counsel directed the AI process and reviewed, evaluated, and took responsibility for the output. That documentation is the evidence that satisfies the "by or for counsel" element if the question is ever raised.
The setting that most directly creates waiver risk is not a dramatic choice. It is a configuration default in a service agreement that most attorneys have not examined. That is the one setting worth checking before the next document enters an AI tool. Also worth reading on this topic: our piece on why AI assistant logs will trigger Rule 37(e) motions by 2027, which addresses the related question of how AI-generated litigation artifacts are treated under the spoliation framework.
Written by
Michael
Kansky
Michael Kansky is a serial software entrepreneur who has spent more than two decades building and bootstrapping profitable SaaS and services companies.
Connect on LinkedInSummarize This Article With AI
Open this article in your preferred AI engine for an instant summary.
Frequently Asked Questions
Does uploading case documents to ChatGPT waive work product protection?
Not automatically. The protection is not voided by the act of uploading. But a court analyzing the question would ask what ChatGPT's current terms of service permitted the vendor to do with those inputs. If the terms permit training on customer data or disclosure to third parties including governmental authorities, as the Heppner court found in the consumer Claude terms, then the disclosure to the vendor may constitute a voluntary third-party disclosure that destroys the protection. The enterprise API and consumer versions of the same product often operate under materially different terms on this question.
What is the "by or for counsel" element and why does it matter for AI-generated work?
The work product doctrine requires that material be prepared by or for a party's representative, meaning counsel or someone acting under counsel's direction. For AI-generated material, the question is whether the attorney meaningfully directed the AI process and exercised professional judgment on the output. In United States v. Heppner, defense counsel conceded that counsel had not directed the defendant's use of Claude. The court held the documents unprotected in part on that basis. The corrective is a documented workflow in which counsel directs the AI prompts, reviews outputs, and takes affirmative responsibility for the analysis before it is shared or relied upon.
Does turning off "chat history" in a consumer AI tool protect my case files?
No. The chat history UI setting controls what is visible in your conversation interface. It does not govern the vendor's backend data retention, model training pipeline, or what vendor personnel can access. Those questions are governed by the service agreement, not by the interface. An attorney who relies on the chat history toggle without reading the underlying terms may have created the appearance of a protection that does not exist in the relevant contractual documents.
What makes a private deployment different from an enterprise API arrangement?
In an enterprise API arrangement, your inputs reach the vendor's servers but are governed by business terms that, for major providers, prohibit training on customer data by default. The vendor still processes your inputs on shared infrastructure, and some log retention may occur under vendor-controlled policies. In a private deployment, the model runs on infrastructure within the firm's own cloud environment or inside the firm's own cloud account, such as in-account AWS deployment. Inputs do not reach the vendor's shared servers at all. Logs are retained only within the firm's own controlled environment. The private deployment is the configuration that most closely replicates the confidential-agent relationship the doctrine depends on.
Will AI interaction logs be discoverable by opposing counsel?
They may be. Logs of prompts and outputs relating to the preparation of case materials are potentially responsive to Rule 34 document requests. Whether they are protected work product depends on whether they satisfy the three-part test and whether the vendor's data terms create a third-party disclosure argument. Firms using consumer AI tools should treat those vendor-retained logs as a discovery risk. Firms using private deployments with firm-controlled logs should treat those logs as work product from the moment they are created and apply litigation hold procedures accordingly.
What did the ABA's August 2026 article on AI and privilege actually say?
The ABA Litigation News piece, "Communicating with AI Jeopardizes Privilege Claim," published in August 2026, identified that attorneys who share privileged communications with AI systems may be creating privilege risk. The article is correct that risk exists. The mechanism it describes, however, is more specific than "communication with AI": the risk arises when the vendor's terms permit the provider to retain, use, or disclose the inputs in ways inconsistent with the confidentiality the privilege requires. The article is better read as a warning about vendor terms than as a warning about AI use generally.