On February 10, 2026, two federal courts issued rulings on the same question — does using generative AI waive privilege or work-product protection? — and reached opposite conclusions. In Warner v. Gilbarco, Inc. out of the Eastern District of Michigan, Magistrate Judge Anthony P. Patti held that ChatGPT is a tool, not a person, and that a litigant's AI-generated materials are protected work product. That same day, in United States v. Heppner out of the Southern District of New York, Judge Jed S. Rakoff held that documents created using Anthropic's Claude were not privileged, in part because the AI platform's privacy policy destroyed any reasonable expectation of confidentiality.
Same question. Same day. Opposite answers.
This split is now the defining fault line in legal technology ethics. And I believe one of these courts got it right — and the other fundamentally misunderstood how modern legal practice works.
Warner v. Gilbarco: AI Is a Tool, Not a Witness
The facts of Warner are straightforward. Sohyon Warner, a pro se plaintiff in an employment discrimination case, used ChatGPT to research legal questions and draft filings after her attorney withdrew. During discovery, the defendants moved to compel production of every prompt Warner entered into ChatGPT and every response she received — essentially demanding access to her entire internal thought process as filtered through a software tool. This, despite the fact that the court had already modified its protective order on October 30, 2025 to prohibit uploading confidential discovery materials to any AI platform — and the defendants produced no evidence Warner had ever violated that order.
Judge Patti denied the motion on three independent grounds, and each one matters.
Work Product Protection
The court held that Warner's AI interactions constituted work product under Federal Rule of Civil Procedure 26(b)(3)(A). Citing Upjohn Co. v. United States, the court recognized that forcing disclosure of litigation preparation materials reveals a party's mental processes — regardless of whether those processes were filtered through a lawyer's dictation, a word processor, or a generative AI tool.
No Waiver — AI Is Not a Third Party
Under established Sixth Circuit precedent, work-product waiver requires disclosure to an adversary or in a manner likely to reach an adversary. But Judge Patti went further: the waiver question was moot because AI is not a third party at all. As the court put it, "ChatGPT (and other generative AI programs) are tools, not persons, even if they may have administrators somewhere in the background." Accepting the defendants' theory would "nullify work-product protection in nearly every modern drafting environment."
Disproportionate Discovery
The court found the request was a "fishing expedition" seeking "a litigant's internal mental impressions reformatted through software," untethered from Rule 26 relevance. The court's final admonition was blunt: the defendants' "preoccupation with Plaintiff's use of AI needs to abate."
"The defendants' preoccupation with Plaintiff's use of AI needs to abate."
Heppner: A Cautionary Tale, Not a Controlling Principle
United States v. Heppner reached the opposite result, but its facts are extreme — and that matters. Bradley Heppner, the former CEO of Beneficient Company Group, was indicted on securities fraud charges involving over $150 million in alleged losses. Before his arrest but after retaining Quinn Emanuel as defense counsel, Heppner independently used the free consumer version of Anthropic's Claude to create approximately 31 documents outlining defense strategies and legal arguments. Critically, he fed information into Claude that his attorneys at Quinn Emanuel had shared with him — effectively uploading privileged attorney-client communications into a consumer AI platform. Federal agents later seized both the documents and the AI interaction logs from his home.
Judge Rakoff denied privilege on multiple grounds. Claude is not an attorney, so no attorney-client relationship exists. Anthropic's consumer privacy policy permits the collection of inputs and outputs, training on user data, and disclosure to third parties including government authorities — destroying any reasonable expectation of confidentiality. And because defense counsel did not direct Heppner's AI use, the documents were not prepared "by or at the behest of counsel," failing the work-product test as well.
The Door Left Open
In a significant passage of dicta, Judge Rakoff acknowledged that had counsel directed Heppner to use Claude, the AI tool "might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent within the protection of the attorney-client privilege" — a direct reference to the Kovel doctrine. Even the judge who ruled against privilege conceded that attorney-directed AI use changes the calculus entirely.
The important distinction is this: Heppner is not a case about whether AI tools waive privilege as a categorical matter. It is a case about a represented criminal defendant who, acting independently of counsel, fed privileged attorney communications into a consumer platform with no contractual confidentiality protections. As DLA Piper aptly observed, the ruling ultimately stands for a relatively conventional proposition — that unprivileged documents created by a non-lawyer using a public tool that disclaimed privacy expectations are not privileged. That is not revolutionary. That is standard privilege doctrine applied to bad facts.
The Real Question: Tool or Third Party?
The tension between these two decisions collapses once you ask the right question. The issue is not whether AI is "special" or "different." The issue is whether a software tool used to process, organize, and articulate a litigant's own thoughts should be treated as an adversarial third party for purposes of privilege analysis.
The answer should be self-evident: no.
The Warner court is not alone in reaching this conclusion. In Tremblay v. OpenAI, Inc., decided in the Northern District of California in August 2024, District Judge Martínez-Olguín reversed a magistrate's order compelling the production of AI prompts, holding that the prompts were "queries crafted by counsel and contain counsel's mental impressions and opinions about how to interrogate ChatGPT." The court classified them as opinion work product — the highest category of protection, entitled to near-absolute immunity from discovery.
Treating AI as a third party to whom disclosure is made ignores how modern legal practice functions. Every law firm in America uses cloud-based document management, email servers hosted by third parties, and legal research platforms that process confidential queries. More than 30 states have issued ethics opinions permitting cloud computing for lawyers, applying the ABA's "reasonable efforts" standard from Formal Opinion 477R. No court has held that uploading a privileged memorandum to Google Drive, sending it through Gmail, or running a search on Westlaw waives the privilege — even though those platforms' terms of service contain language functionally identical to the Anthropic privacy policy that Judge Rakoff found dispositive in Heppner.
Warner (E.D. Mich.)
AI is a tool, not a person.
Work product protection applies.
No waiver — AI is not a third party.
Heppner (S.D.N.Y.)
Consumer AI platform destroyed confidentiality.
Client acted independently of counsel.
Bad facts — not a categorical rule.
Contractual Terms Matter More Than Labels
Legal technology expert Jennifer Ellis has made this point forcefully, arguing that Rakoff's confidentiality analysis "applies a framework that might make sense for social media but does not fit the way AI tools actually work." Her critique cuts to the core: Google, Microsoft, Apple, and Dropbox all reserve similar rights in their privacy policies to those Anthropic disclosed — including the right to share data with government authorities. If Rakoff's standard were applied consistently, uploading a privileged memo to Google Drive would also waive privilege. The entire cloud computing infrastructure of the modern law firm would be at risk.
The reasonable expectation of confidentiality does not exist in a vacuum. If a platform's terms allow user inputs to be stored, reviewed, or used for model training beyond the immediate interaction, courts may view that differently than a system with strict contractual restrictions on data use. This is the one area where Heppner's analysis has practical value: it highlights the critical distinction between consumer AI tools and enterprise deployments.
Enterprise-grade AI tools — the ones sophisticated law firms and legal technology companies are deploying — contractually prohibit training on user data, restrict human review of inputs, include data processing agreements, and offer SOC 2 compliance certifications. The ABA recognized this distinction in Formal Opinion 512, its first formal guidance on generative AI in legal practice, which explicitly tied ethical AI use to the same reasonable-efforts framework that governs cloud computing and outsourcing.
Technology providers should be viewed as service vendors or agents that facilitate representation — not as hostile third parties waiting to betray their users' confidences. To hold otherwise would impose a standard on AI tools that we do not impose on any other technology lawyers use daily.
The Profession Must Evolve — For Our Clients' Sake
There is a deeper principle at work here, one that extends beyond the privilege doctrine. The legal profession's concept of what it means to serve clients is changing, and the privilege debate is a symptom of a broader institutional resistance to that change.
"Legal professionals should be planning for the legal market as it will be and not as it once was … most lawyers are currently skating to where the puck used to be."
That observation reframes the entire privilege debate. The question is not whether lawyers should be permitted to use AI tools. The question is whether lawyers can fulfill their professional obligations to their clients without them. For a solo practitioner preparing a domestic relations case with limited resources, AI tools are not a luxury — they are the difference between a client who receives competent, thorough representation and one who does not. For a pro se litigant like Ms. Warner, they may be the only way to meaningfully access the legal system at all.
The tension of privilege doctrine must ultimately cede to the practical necessity for lawyers to use AI tools to more efficiently help their clients. We are moving from a model in which the lawyer is the exclusive gatekeeper of legal knowledge to one in which the lawyer's role is to help clients help themselves — to be a guide through an increasingly technology-enabled legal landscape rather than a bottleneck standing between people and justice.
Lawyers who resist this transformation are not protecting privilege. They are protecting obsolescence.
Where We Go From Here
The Warner/Heppner split will not be the last word on this question. But for practitioners navigating the current landscape, the path forward is clear.
Use enterprise-grade AI tools with contractual confidentiality protections.
Ensure your platform's data practices align with the reasonable-efforts standard established by ABA Opinions 477R and 512.
When AI is used in litigation preparation, document attorney direction and supervision — Heppner itself tells us that attorney-directed use may qualify for Kovel protection.
Treat AI interaction logs as electronically stored information subject to preservation obligations.
Focus on whether confidentiality was reasonably maintained — not on whether the word "AI" appears somewhere in the workflow.
Bottom Line
Judge Patti had it right. The legal profession's preoccupation with the AI label needs to abate. The focus should remain on what it has always been: whether the attorney or litigant took reasonable steps to maintain the confidentiality of privileged communications. That standard has governed email, cloud computing, outsourcing, and every other technological transformation the profession has absorbed. There is no reason it should not govern AI as well.
The tools change. The obligation does not.
Download the Full Article
Get the complete article as a Word document for offline reading, sharing with colleagues, or CLE reference.
Case References
Warner v. Gilbarco, Inc., No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026) (ECF No. 94)
United States v. Heppner, No. 25-cr-00503-JSR, 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026)
Tremblay v. OpenAI, Inc., 2024 WL 3748003 (N.D. Cal. Aug. 8, 2024)
United States v. Kovel, 296 F.2d 918 (2d Cir. 1961)
Upjohn Co. v. United States, 449 U.S. 383 (1981)
ABA Formal Opinion 512 (July 29, 2024)
ABA Formal Opinion 477R (2017)
Matt Mishak, Esq.
Matt Mishak is a practicing attorney with 20 years of experience in Ohio family law and domestic relations, and a former Chief Prosecutor and criminal defense attorney. He is the Founder and CEO of LegalTek.ai LLC, operating as SilverTung, an AI-powered legal document automation platform. He also serves as Law Director for the Village of South Amherst, Ohio. A longstanding advocate for the intersection of technology and law, Matt was an early pioneer in drone technology as founder of DroneWerx and Dronelaw.us. The views expressed in this article are his own and do not constitute legal advice.
Not legal advice; this is general education and risk-spotting. For specific issues, talk to counsel in your jurisdiction.
AI Disclosure: This article was human-reviewed but may contain AI-generated elements. Readers should conduct their own research and remain skeptical of potential factual errors.








