Three federal rulings issued in early 2026 do not establish that every prompt is discoverable. They establish something narrower and more useful. A claim of protection depends on the governing doctrine, how the material was created, and the relationship between the person, counsel, and the AI system.

In United States v. Heppner, a district judge rejected attorney-client privilege and work-product claims over documents seized from a criminal defendant who had generated them with the publicly available version of Claude. In Warner v. Gilbarco, Inc., a magistrate judge denied an attempt to obtain a civil plaintiff’s materials concerning third-party AI use and held that using ChatGPT did not itself waive work-product protection. On March 30, Morgan v. V2X, Inc. distinguished Heppner and applied the civil rule protecting materials prepared by or for a party.

The first two decisions can look like a judicial split. That framing is incomplete. The courts examined different procedural settings, different sources of law, and partly different protections. Morgan makes that distinction explicit. Read together, the rulings offer a practical map for legal teams deciding where AI-assisted work fits within privilege, work product, and ordinary discovery.

The documents in Heppner began outside counsel’s direction

Federal agents executed a search warrant at Bradley Heppner’s home in November 2025 and seized documents and electronic devices. According to defense counsel’s representation recorded in the court’s February 17 memorandum, the seized materials included approximately 31 documents memorializing exchanges with Anthropic’s publicly available Claude service. Heppner created reports concerning anticipated charges, possible defenses, and factual and legal arguments after he had received a grand jury subpoena.

Counsel later claimed attorney-client privilege and work-product protection. The record contained two limiting facts. Counsel had not directed Heppner to run the Claude searches, and the documents did not reflect counsel’s strategy when Heppner created them. Later sharing the documents with counsel did not change the circumstances of their creation.

The court first rejected the attorney-client privilege claim. Claude was not an attorney, the exchanges did not occur within an attorney-client relationship, and the service’s privacy policy defeated the asserted expectation of confidentiality. The court also found that Heppner had acted on his own initiative rather than using the service at counsel’s direction to obtain legal advice.

The privilege consequence extended beyond the AI documents. In footnote 3, the court reasoned that even if Heppner had entered information learned from counsel, he waived privilege over that information by sharing it with Claude and Anthropic as he would by sharing it with another third party. A user can therefore put underlying legal advice at risk, not merely expose the prompt and output.

The court separately rejected work-product protection. Even assuming the documents were prepared in anticipation of litigation, they were not prepared by or at the behest of counsel and did not reveal counsel’s strategy at the time. The work-product holding therefore rested on a specific chain of facts, not on a universal rule that an AI-related document can never receive protection.

The court also confronted contrary work-product authority. It expressly disagreed with Shih v. Petal Card, Inc., which had protected party-prepared material without requiring attorney direction. Heppner instead emphasized the Second Circuit’s counsel-centered account of work product and the protection of lawyers’ mental processes. That disagreement reveals a real doctrinal fault line even if the results in Heppner and Warner can be reconciled on other grounds.

Warner asked a different discovery question

The dispute in Warner v. Gilbarco, Inc. arose from an employment case that the plaintiff filed through counsel and later litigated pro se after counsel withdrew. The defendants sought all documents and information concerning her use of third-party AI tools in connection with the litigation. The February 10 discovery order denied that request on several grounds.

The request was untimely. The court also found the requested material not relevant or proportional. It noted that the defendants had no evidence that the plaintiff uploaded material covered by the protective order to an AI platform.

The court then addressed work product as an alternative basis. Federal Rule of Civil Procedure 26(b)(3) protects material prepared in anticipation of litigation or for trial by or for another party or its representative. A pro se litigant may assert that protection. The court concluded that the requested AI-related material fell within it. The protection is qualified, and ordinary work product may still be discoverable upon the rule’s showing of substantial need and undue hardship.

The waiver analysis was equally important. Work-product waiver ordinarily asks whether a disclosure reached an adversary or made it likely that the material would reach one. The court reasoned that using ChatGPT, a tool rather than an adversary, did not by itself satisfy that standard. It did not decide that every AI exchange is confidential, privileged, or beyond discovery.

The order’s institutional posture matters. A magistrate judge resolved the AI issue through alternative work-product reasoning after denying the request as untimely and outside ordinary discovery limits. Heppner, by comparison, was a district judge’s memorandum addressing a claimed question of first impression after the government obtained the materials through a search warrant.

Morgan identified the source-of-law distinction

The March 30 order in Morgan v. V2X, Inc. considered whether a pro se employment plaintiff had to identify an AI platform used in connection with confidential discovery material. The magistrate judge required disclosure of the platform’s name and amended the protective order to restrict the use of confidential material in AI systems lacking specified contractual safeguards.

At the same time, the court held that Rule 26(b)(3) could protect the plaintiff’s AI-assisted litigation material. It distinguished Heppner on two grounds. Heppner arose in a criminal case rather than under the civil rule, and its represented defendant acted independently of counsel. A civil pro se litigant, by contrast, acts as both party and advocate. The court aligned its work-product analysis with Warner and concluded that using an AI system does not automatically waive protection.

Morgan does not make AI activity categorically immune. It required the plaintiff to identify the tool because he had not shown that its name revealed protected strategy, and because the defendant had a legitimate need to assess whether confidential information was compromised. The order separates protection for litigation preparation from compliance with a protective order and the security characteristics of the system used.

Attorney-client privilege and work product overlap, but they are not interchangeable. Privilege protects qualifying confidential communications made to obtain or provide legal advice within an attorney-client relationship. Work product protects qualifying material prepared in anticipation of litigation and gives special weight to the mental impressions and strategies developed for an adversarial process.

That difference explains part of the apparent conflict. Heppner asked whether self-directed use of a publicly available AI service qualified as privileged communication and whether the resulting documents were tied closely enough to counsel’s work to receive work-product protection under the law governing a criminal matter. On the record before it, the court answered no.

Warner and Morgan applied the text of the civil rule to litigation preparation by pro se parties. Their waiver discussions focused on adversary access, not on whether a chatbot can enter an attorney-client relationship. Neither decision preserves attorney-client privilege for direct user-to-AI exchanges.

None of the rulings created a complete rule for enterprise AI. Heppner suggested that counsel-directed use might present a different agency argument, but it did not decide that question. Warner did not hold that sharing confidential material with a provider preserves attorney-client privilege. Morgan treated contractual safeguards as relevant to whether confidential discovery material could be entered into a system, not as a substitute for the elements of privilege. An enterprise contract, a retention setting, or a confidentiality clause may affect the facts, but none automatically creates privilege.

The operational question is provenance

Translucent sheets overlap a cream page, with graphite lines and muted blue, ochre and rust marks.

AI-generated editorial illustration · A record of its making. A layered paper composition exploring the origins and context of a document.

The strongest governance response is a record of provenance. A legal team should be able to identify who initiated the AI-assisted work, whether counsel directed it, what litigation or advisory purpose it served, which service and account type were used, what information entered the system, and who could access the resulting material.

That record cannot create attorney-client privilege where the required relationship and confidentiality do not exist. It can, however, supply evidence relevant to work product, a counsel-agency argument, discovery scope, waiver, preservation, and compliance with a protective order. It also helps an organization separate legal work from ordinary business analysis and decide whether a particular system is suitable for sensitive use.

The same provenance record should preserve doctrinal distinctions. Labeling every AI-assisted document “privileged” does not make it so. A document created for a business purpose does not become work product merely because litigation later develops, and material created independently does not become privileged merely because it is sent to a lawyer.

The opposite error is also costly. Treating every prompt as automatically discoverable can lead teams to surrender protection that the facts support. Warner and Morgan show why the analysis should begin with the governing rule, relevance, proportionality, anticipation of litigation, and adversary access rather than the presence of an AI tool alone.

The criminal case moved, but the protection ruling remains

The procedural posture of Heppner changed after the February ruling. According to the U.S. Attorney’s official case page, a jury convicted Heppner on May 7, 2026 after a three-week trial. Sentencing is scheduled for October 7, 2026.

That later development does not establish that the Claude documents caused the conviction, and this analysis draws no such inference. It matters because a current account should not describe the criminal case as awaiting trial. The February memorandum remains the court’s ruling that the seized materials were not protected from government inspection on the record then before it.

Practical implications

  1. Do not place legal advice into a public AI service without assessing waiver. Heppner shows that a prompt can expose information learned from counsel as well as the prompt and output themselves.

  2. Record counsel’s role and the litigation purpose before sensitive work begins. A contemporaneous instruction, defined purpose, and review path provide better evidence than a privilege label added after a dispute starts.

  3. Separate privilege from work product in policy and training. The doctrines protect different interests and apply different waiver rules. Work product is qualified, and a single “confidential AI” category obscures the questions a court will ask.

  4. Review the service, account, data terms, and governing protective orders. Contractual controls may affect confidentiality and permitted use, but they do not substitute for the elements of privilege or work product.

  5. Preserve AI-related material when a legal hold applies. A concern about discoverability is not a reason to delete prompts, outputs, logs, or related records. Preservation and protection are separate issues.

Case citations

  • United States v. Heppner, No. 25 Cr. 503 (JSR), ECF No. 27 (S.D.N.Y. Feb. 17, 2026).
  • Warner v. Gilbarco, Inc., No. 2:24-cv-12333, ECF No. 94 (E.D. Mich. Feb. 10, 2026).
  • Morgan v. V2X, Inc., No. 1:25-cv-01991-SKC-MDB, ECF No. 65 (D. Colo. Mar. 30, 2026).

Disclaimer: AI Lex Intelligence is published for informational purposes only. It does not constitute legal advice, and no attorney-client relationship is formed by reading or receiving this publication. Readers should consult qualified legal counsel about specific legal matters.

AI Lex Intelligence with Zola Valashiya. Independent analysis of artificial intelligence and the law.