The rapid integration of artificial intelligence (AI) into various professional domains, including the practice of law, has presented novel challenges for legal frameworks designed to protect confidential communications and preparatory work. As companies increasingly leverage AI tools for legal research, strategy development, and even direct consultation, questions surrounding the discoverability of these interactions in litigation are becoming paramount. A recent memorandum from Fried, Frank, Harris, Shriver & Jacobson LLP, authored by Senior Counsel Gail Weinstein, Partner and Co-Head of M&A and Private Equity Practice Philip Richter, Managing Partner Steven Epstein, and associates Steven J. Steinman, Randi Lally, and Colum J. Weiden, delves into this complex and evolving area of law. This analysis, part of the ongoing Delaware Law Series, highlights recent court decisions and offers crucial insights for corporate policy development in the age of AI.

The fundamental question facing courts is whether communications with AI platforms, particularly generative AI, are protected by established legal doctrines like the attorney-client privilege or the attorney work product doctrine. The intuitive response might be that AI, not being a human attorney, cannot be the recipient of privileged legal advice. However, the reality is far more nuanced, with courts grappling to apply existing legal principles to unprecedented technological scenarios. The outcomes thus far have been varied, underscoring the unsettled nature of this legal frontier.

What has become unequivocally clear is that when a non-lawyer utilizes an AI platform to seek legal advice concerning a company matter, there exists a significant risk that the queries made and the outputs received could be discoverable in subsequent litigation. Such AI-generated content can be particularly damaging to a litigant, potentially revealing their underlying motivations, mental state, risk assessments, and strategic thought processes. Ultimately, the judicial determination in these cases hinges on the specific court’s perspective on AI and the unique factual circumstances presented.

At the heart of the judicial debate lies a critical conceptual divide: should AI be viewed merely as a sophisticated "tool" for litigation, akin to legal research databases like Westlaw or LexisNexis, or should it be considered the functional equivalent of a "person," specifically an attorney, providing legal counsel? Courts have scrutinized various factors to guide their decisions. These include whether legal counsel directed the AI interactions, the specific terms of use of the AI platform, particularly concerning confidentiality provisions, and whether the AI usage created a plausible risk of the communications falling into the hands of a litigation adversary. The precise wording of applicable federal and state rules of civil procedure also plays a significant role.

Summary of Key Judicial Decisions

The legal landscape regarding AI and privilege is being shaped by a series of illuminating court decisions, each offering distinct perspectives and raising critical considerations for businesses.

Heppner v. The United States (New York Federal Court)

In a landmark ruling, the New York federal court in Heppner determined that legal advice received by a criminal defendant from Claude, a generative AI platform, was not protected by either the attorney-client privilege or the work product doctrine. The defendant had shared Claude’s output with his defense attorney, who admitted to being "influenced" by the AI’s advice in formulating his legal strategy, though he did not directly follow it. The attorney conceded he had not instructed the defendant to consult with the AI, but emphasized that the defendant’s purpose was to engage in dialogue akin to consulting counsel.

Judge Jed S. Rakoff underscored that the defendant lacked a reasonable expectation of confidentiality due to Claude’s terms of use. These terms explicitly stated that users consented to their queries and Claude’s responses being utilized by Anthropic, Claude’s creator, for training purposes and for disclosures to third parties, including government regulators or in the context of disputes.

Regarding the attorney-client privilege, the court reasoned that Claude was not a person and therefore not an attorney. Furthermore, the defendant’s lack of a reasonable expectation of confidentiality, coupled with Claude’s explicit disclaimers of being a lawyer or providing legal advice, precluded privilege. Notably, Judge Rakoff suggested that the outcome might have differed had the defense attorney directed the defendant’s interactions with Claude. In such a scenario, the AI might have been considered to function as an agent of the attorney, potentially falling under the protection of the attorney-client privilege. For the work product doctrine, the court found that while the exchanges might have occurred in anticipation of litigation, they were not prepared by or at the behest of counsel, nor did they reflect the legal strategy actually employed by the attorney.

Krafton, Inc. v. Emtek, Inc. (Delaware Court of Chancery)

The Krafton case offers a stark illustration of how AI-generated advice, when used to inform corporate actions, can become critical evidence in litigation, even if privilege is not formally asserted. In this instance, a CEO sought and largely followed legal advice from ChatGPT on how to avoid making an earnout payment to key employees of an acquired company. ChatGPT advised that legally avoiding the payment would be difficult but suggested creating "pressure points" by terminating the employees for cause, or, if unsuccessful, by taking control of the acquired company. The AI even provided a project name, detailed talking points, and draft communications for each step.

When litigation ensued, the terminated employees obtained discovery of the CEO’s exchanges with ChatGPT and introduced them as evidence. The issue of privilege was not raised, likely because the CEO had shared these communications with other non-lawyers within the company. The Delaware Court of Chancery, by comparing ChatGPT’s advice with the CEO’s subsequent actions, concluded that the employees were terminated for pretextual reasons and that the attempted takeover of control violated the acquisition agreement. Vice Chancellor Lori W. Will ordered the CEO’s reinstatement with operational control and extended the earnout period. Damages are still to be determined in this ongoing matter.

Warner v. Michigan Department of Health and Human Services (Michigan Federal Court)

In contrast to Heppner, the Michigan federal court in Warner held that a pro se plaintiff’s interactions with ChatGPT to obtain legal advice were protected under the work-product doctrine. The plaintiff, alleging racial discrimination by her employer, faced a motion from the defendants to compel production of all documents related to her use of third-party AI tools in connection with the lawsuit. The plaintiff asserted work product protection, while the defendants argued she had waived this protection by inputting litigation materials into a public version of an AI platform.

The court referenced Federal Rule of Civil Procedure 26(b)(3)(A), which shields materials prepared in anticipation of litigation or for trial by a party or their representative. The court’s plain reading indicated that the doctrine protects materials prepared "by [a] party," not exclusively by or at the direction of an attorney. Therefore, the plaintiff, as a party who prepared the materials in anticipation of litigation, was covered. The court also found that the plaintiff had not waived protection or her expectation of confidentiality by using ChatGPT. The court reasoned that waiver requires disclosure to an adversary or in a manner likely to reach an adversary, which was not the case with AI usage. The court further stated that accepting the defendants’ waiver theory would "nullify work-product protection in nearly every modern drafting environment."

Crucially, the Warner court emphasized that generative AI programs are "tools, not persons." The court criticized the defendants’ request as a "fishing expedition" aimed at discovering the plaintiff’s "internal analysis and mental impressions… rather than any existing document or evidence."

Morgan v. United States (Colorado Federal Court)

The Colorado federal court in Morgan also found work product protection for a pro se plaintiff’s AI interactions, but with a crucial caveat: the plaintiff had to disclose which AI platform was used, as the court determined that identifying the tool itself did not necessarily reveal mental impressions or case strategy. The court also provided guidance on amending protective orders to accommodate AI usage.

The plaintiff, alleging a hostile work environment, termination based on race and national origin, and retaliation for whistleblowing, had his AI interactions protected under the work product doctrine as applied to pro se litigants. The court stressed that Federal Rules of Civil Procedure protect materials "prepared in anticipation of litigation or for trial by or for another party," and a plain reading does not condition this protection on attorney involvement. The court found this particularly relevant for pro se litigants who must serve as both party and advocate, a dual role potentially made more manageable by accessible technology.

The court concluded that sharing information with an AI platform does not waive work product protection, likening it to sending emails that are not invalidated by being processed through an email server. While technically disclosing information to a third party, the court stated it was not in a manner likely to reach an adversary. The court found it "entirely reasonable for a person to expect some privacy and confidentiality when interacting with these tools."

The court distinguished Heppner by noting it involved a criminal matter not governed by the Federal Rules of Civil Procedure and a represented litigant acting independently of counsel, whereas Morgan involved a pro se litigant acting as their own advocate.

The Morgan court also addressed amendments to the existing protective order. It approved language prohibiting the input of confidential information into AI platforms unless their terms of use contractually prevented the provider from storing, using inputs for training, or disclosing them to third parties (except for essential service delivery), and allowed for deletion upon request. The court acknowledged these requirements would likely "bar the parties from using most, if not all, mainstream low-to-no-cost AI" for confidential information.

Tate v. Texas Business Court

In Tate, the Texas Business Court addressed a dispute arising during trial when defendants discovered the plaintiff’s principal had been uploading case-related materials to ChatGPT throughout the litigation. The defendants sought discovery of these uploaded materials, arguing, citing Heppner, that non-lawyer exchanges with AI lack an expectation of privacy and that sharing with AI waives any protection. The plaintiff asserted work product protection under Texas Rule of Civil Procedure 192.5, which uses broader language than the federal rule.

The court agreed with the plaintiff that the materials were not discoverable under Texas’s work product doctrine. Citing Warner and Morgan, the court held that uploading materials to ChatGPT did not constitute disclosure to an adversary or in a manner likely to reach one, analogizing it to using "Westlaw, LexisNexis, e-discovery platforms, or other litigation-support tools."

While the court did not order the plaintiff to produce the content of the uploaded materials, it mandated that the plaintiff identify, by Bates number, every discovery document shared with ChatGPT, including those designated as "Confidential" under a protective order. The court also recommended that the parties amend their protective order to address future AI tool usage.

Implications and Practice Points for Corporations

These decisions collectively paint a picture of an evolving legal landscape where the application of long-standing legal doctrines to emerging technologies is a dynamic process. The core takeaway for corporations is the imperative to proactively manage the risks associated with AI use in legal and business contexts.

Key Practice Points for Companies:

  • Develop Comprehensive AI Usage Policies: Companies must establish clear, written policies governing the use of AI tools, particularly for legal and sensitive business matters. These policies should delineate what types of information can be inputted into AI platforms, which platforms are permissible, and the procedures for obtaining legal counsel’s approval for certain uses.
  • Prioritize Confidentiality and Terms of Use: When selecting AI platforms, companies should meticulously review their terms of service, with a particular focus on data privacy, confidentiality, and data retention policies. Preferring platforms that offer robust contractual protections against data storage, training use, and third-party disclosure is crucial.
  • Involve Legal Counsel: For any significant legal strategy or analysis, direct engagement with qualified legal counsel remains the most secure path to privilege. If AI is to be used in conjunction with legal advice, it should be under the explicit direction and supervision of legal counsel, ensuring that the interactions are structured to maximize potential privilege protections.
  • Maintain Audit Trails and Documentation: Companies should implement systems to track and document AI usage, especially concerning sensitive information. This includes maintaining records of queries, outputs, and the individuals involved in AI interactions.
  • Educate Employees: Regular training for employees on the company’s AI usage policies, the potential risks of AI use, and the importance of confidentiality is essential to ensure compliance and mitigate risks.
  • Review and Amend Protective Orders: In ongoing or anticipated litigation, parties should proactively consider amending existing protective orders to explicitly address the use of AI tools, specifying permissible uses, disclosure requirements, and data handling protocols.

The judiciary’s ongoing efforts to reconcile traditional legal principles with the realities of AI integration highlight the critical need for businesses to adapt their internal practices. As AI technology continues to advance, so too will the legal challenges it presents, demanding a vigilant and informed approach to safeguard sensitive information and maintain legal integrity in the digital age. The decisions in Heppner, Krafton, Warner, Morgan, and Tate serve as critical benchmarks, guiding companies toward more responsible and secure utilization of artificial intelligence in their operations.

By