AI & Emerging Tech

Courts Begin Shielding AI Prompts and Outputs From Discovery: Federal and State Courts Recognize Work-Product Protection for AI-Assisted Litigation Work

By Arnold D. Lee · July 28, 2026 · Originally published on Spencer Fane

Every litigator now confronts a question that did not exist five years ago: when a party uses a generative artificial intelligence (AI) tool to help prepare its case – drafting motions, testing arguments, organizing facts – are the prompts it typed and the outputs it received discoverable by the other side? For opponents, an adversary’s AI chat log is a tantalizing target: a candid, time-stamped record of theories considered and abandoned, weaknesses acknowledged, and strategies in development. For the party that created it, that same log is the digital equivalent of a legal pad covered in case-strategy notes.

The federal courts got there first. On February 10, 2026, Magistrate Judge Anthony P. Patti of the Eastern District of Michigan denied a motion to compel “all documents and information concerning [the plaintiff’s] use of third-party AI tools” in Warner v. Gilbarco, Inc., holding that the material was not discoverable and that, even if it were, it was protected work product – and that using ChatGPT worked no waiver, because “ChatGPT (and other generative AI programs) are tools, not persons,” so the disclosure was not one to an adversary.1 The doctrinal engine was Federal Rule of Civil Procedure 26(b)(3), which protects documents and tangible things prepared in anticipation of litigation “by or for another party or its representative” – not by lawyers alone.2 Seven weeks later, on March 30, 2026, Magistrate Judge Maritza Dominguez Braswell of the District of Colorado reached the same conclusion in Morgan v. V2X, Inc., holding that Rule 26(b)(3) protected a self-represented plaintiff’s AI-assisted litigation preparation – while ordering him to disclose the name of the AI platform he had used and amending the protective order to bar uploading confidential information into mainstream consumer AI tools.3

Two state-court decisions followed in June, two days apart, and both followed the federal lead rather than breaking new ground. On June 3, 2026, Judge Grant Dorfman of the Business Court of Texas, Eleventh Division, issued a minute entry in Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC stating that the court “agrees with the analysis and reasoning” of Warner and Morgan, and concluding that most – though not all – of a party principal’s ChatGPT conversations were protectable attorney work product under the Texas rule.4 The next day, June 4, Supreme Court, Nassau County (Fischer, J.) quashed non-party subpoenas seeking a self-represented litigant’s AI prompts, uploads, and outputs in Assini v. Hayward, expressly finding “the rationale presented in Morgan persuasive.”5

None of these rulings is settled law, and none is binding beyond its own case. Warner and Morgan are magistrate-judge discovery orders; Tate Group is an expressly non-final minute entry; Assini is an uncorrected trial-level decision subject to revision before official publication. What makes the group worth attention is the convergence: four courts, applying three different bodies of work-product law, arrived at the same basic proposition – AI-assisted litigation preparation is trial-preparation material in substance, and routing it through a commercial chatbot does not by itself hand it to the adversary. That gives litigators citable persuasive authority in both federal and state forums, along with a fairly clear roadmap for the practices that make protection stick.

Assini v. Hayward: New York Quashes Subpoenas Aimed at a Pro Se Litigant’s AI Account

Assini arose from a members’ dispute pending in Supreme Court, Nassau County, under Index No. 607683/2024. The plaintiffs took direct aim at an adversary’s AI account, serving a non-party subpoena – and then an amended subpoena – on OpenAI OpCo, LLC, seeking materials tied to the accounts of a self-represented defendant: all prompts, inputs, uploaded materials, and corresponding outputs used to draft, revise, or generate filings, motions, sworn statements, or communications transmitted in the case, plus all prompts and outputs referencing the plaintiffs, the entity at the center of the dispute, or the claims and defenses asserted.6

The disposition was narrower than the result might suggest. The court granted only the branch of the defendant’s motion seeking to quash; on that branch, the subpoena and amended subpoena were quashed in their entirety under Civil Practice Law and Rules (CPLR) 2304.7 The motion’s other branches – a protective order, conditions on production, costs, fees, and sanctions – were swept up in the court’s catch-all direction that “all requests for relief not expressly addressed herein is DENIED.” A parallel order to show cause seeking substantially the same relief was denied outright for defective service: the movant filed no affidavits of service, and the method of service specified in an order to show cause is jurisdictional, so non-compliance deprived the court of authority to entertain it. The plaintiffs’ cross-motion to so-order the amended subpoena was denied as well.8

The governing standard is not the federal one, and the difference matters. New York treats material prepared in anticipation of litigation as subject to a conditional privilege under CPLR 3101(d)(2); the Second Department requires the party asserting it to show that the material was prepared solely in anticipation of litigation, a stricter threshold than the federal “because of litigation” formulation. Once that showing is made, the material is still discoverable if the requesting party demonstrates substantial need and an inability to obtain the substantial equivalent without undue hardship. The absolute protection for an attorney’s work product under CPLR 3101(c) was not the vehicle here; the AI materials were analyzed as conditionally protected trial-preparation material under 3101(d).9

On that standard, the court held the AI materials protected. The defendant’s own showing was thin – the opinion records only that he “contends that the Subpoena and Amended Subpoena should be quashed, and a protective order issued, as the materials sought are privileged as ‘litigation-preparation’” – but the court supplied the reasoning by adopting Morgan: in the hands of a pro se litigant, the use of AI “closely resembles the kind of confidential, strategy-laden iterative work product that Rule 26(b)(3) was designed to protect,” and it is “entirely reasonable for a person to expect some privacy and confidentiality when interacting with these tools, even though they understand a third party is behind the tool collecting and storing their information.” The plaintiffs’ contrary authority, United States v. Heppner, did not carry the day. As the court noted – and as Morgan had held before it – Heppner was a criminal matter involving a represented defendant who used an AI tool on his own initiative, entirely apart from his lawyer. No comparable gap exists where the litigant is simultaneously the party and the advocate.10

At the same time, the court made clear that AI-assisted litigation is not a supervision-free zone. Observing that the defendant’s “use of AI frustrates the litigation” and “cannot go unfettered,” it referred him to the New York court system’s rules on AI use in 22 NYCRR Part 161 and directed him to be governed accordingly, warning that “[f]ailure to abide by the Court Rules may result in sanctions.”11 Protection for AI work product, in other words, coexists with accountability for AI misuse – hallucinated citations and unverified filings remain sanctionable regardless of how the underlying chats are classified.

Tate Group: Texas Protects a Represented Party’s Chats – in Part, and Not Finally

The Texas ruling reaches further than Assini in one respect and rests on weaker procedural footing in another. It extends work-product protection to ChatGPT conversations conducted by a party principal – not a lawyer, and not a pro se litigant acting as his own counsel. But it is a minute entry issued after in camera review, and it is framed in the language of opinion rather than holding: the court “is of the opinion that” certain pages should be produced, and it expressly cautioned that “entry of these less formal orders is not intended to be final,” giving any party that wants an appealable determination leave to file an appropriate motion to quash, for protection, or for reconsideration. It is not a final order, and it is not precedential authority; it should be cited for the persuasive force of its reasoning, not for its command.12

On the substance, Judge Dorfman began by agreeing with Warner and Morgan, and in particular with their recognition that “work product protections are typically waived by disclosure to an adversary, or in circumstances that substantially increase the likelihood that an adversary will obtain the materials” – which use of a chatbot is not. He then addressed Heppner, the defendants’ primary authority, in two distinct steps: first, he “disagree[d] with” it on the merits; only then did he add that Warner, Morgan, and Heppner “are all federal cases, whereas the Texas rules set forth a different standard for protectable attorney work product.”13 Texas Rule of Civil Procedure 192.5(a)(1) defines work product to include “material prepared or mental impressions developed in anticipation of litigation or for trial by or for a party” – language that, the court concluded, “plainly appear[s] on [its] face” to extend to the ChatGPT conversations at issue.14

The outcome was a split decision, not a clean win. The court identified specific pages – “Document #81, pp. 198-218, 260-283, 287-309, 311-331,” roughly 100 pages in all – that “should be produced because they do not constitute protectable attorney work product within the meaning of TEX. R. CIV. P. 192.5(a)(1).” The remainder could be withheld. Two further disclosure obligations followed. The court ordered the plaintiff to disclose to the defendants all discovery materials or products it had shared with ChatGPT, including any produced under the protective order. And, voicing “serious concerns about the intelligibility” of the plaintiff’s in camera submission and privilege log, it ordered production of every document submitted for review that had been withheld solely on relevance or non-responsiveness grounds. The court also recommended that the parties negotiate protective-order amendments addressing AI use directly.15 The lesson is triple-edged: the strategic content of AI sessions may be protected, an unintelligible privilege log will cost a party pages regardless, and feeding an opponent’s confidential documents into a third-party AI tool carries consequences of its own.

The Emerging Doctrine – and Its Limits

Read together, Warner, Morgan, Tate Group, and Assini sketch the outline of an emerging doctrine. AI prompts and outputs created to draft filings, develop strategy, and marshal facts are trial-preparation materials in substance, and courts applying federal, Texas, and New York work-product law have now said so. The medium does not control; the purpose and content do. And in each case, the court rejected the argument that involving a commercial AI provider automatically destroys confidentiality – a conclusion with obvious analogues in the treatment of other third-party litigation vendors, from copy services to e-discovery platforms.

The standards, however, are not interchangeable, and the differences will decide cases. Federal Rule 26(b)(3)(A) protects documents prepared “in anticipation of litigation or for trial” by or for a party, and Texas Rule 192.5(a) uses comparable language. New York is stricter: under CPLR 3101(d) as construed in the Second Department, the material must have been prepared solely in anticipation of litigation. A mixed-purpose chat thread – part case strategy, part business question – is considerably more vulnerable in Nassau County than in Denver or Houston. Just as important, the protection recognized in all four cases is conditional, not absolute. Assini shields nothing that a plaintiff can still reach by showing substantial need and undue hardship under CPLR 3101(d)(2), and the same is true of ordinary work product under Rule 26(b)(3)(A)(ii) and Texas Rule 192.5(b)(3)–(4). A litigant who wins the “is it work product” fight has won the first round only.16

Several other fault lines are already visible. It is not accurate to describe federal courts as the stingier forum: Warner and Morgan are the two most protective decisions in this group, and both are federal. The one decision refusing protection, Heppner, was a criminal case in which a represented defendant used an AI tool without any involvement from his lawyer – the ground on which both Morgan and Assini distinguished it, and the ground on which the Texas court disagreed with it outright. What Heppner illustrates is not that federal work-product law is less generous, but that the doctrine tracks the litigant’s relationship to counsel and the procedural setting in which the claim arises. Waiver questions remain fact-intensive: a litigant who uses an AI tool’s default settings – under which prompts may be retained, reviewed, or used for model training – presents a harder confidentiality case than one using an enterprise deployment with contractual confidentiality protections, and future opinions will surely probe those details. Attorney-client privilege, as distinct from work product, raises separate problems: a conversation with a chatbot is not a communication with counsel, and litigants should not assume that rules designed to protect confidential communications with a lawyer will automatically protect exchanges with an AI tool. And where AI outputs are used for purposes beyond case preparation – business decision-making, regulatory compliance, communications later placed at issue – the protection analysis changes entirely.

The protection also runs up against a different discovery regime: expert practice. In Conservation Law Foundation, Inc. v. Shell Oil Co., a Connecticut federal magistrate judge ordered a party to produce the generative-AI prompts its testifying expert used to cull the document universe underlying her report, reasoning that the prompts were part of the expert’s discoverable methodology rather than protected notes, drafts, or communications.17 That order should not be read as drawing a clean doctrinal line. As I noted when it issued, the court “did not squarely resolve” whether the prompts were protected by the attorney-client privilege or the work-product doctrine, and it confronted a comparatively narrow use case – prompts used to identify documents rather than to generate analysis or substantive conclusions. The order also remains stayed, as of this writing, pending the district court’s resolution of the plaintiff’s objection. What it supplies is a direction of travel rather than a rule: an expert’s facts, data, and methods are broadly disclosable and discoverable under Rules 26(a)(2)(B) and 26(b)(4), even though the 2010 amendments extended work-product protection to most draft reports and many attorney-expert communications.18 Read that way, the order coexists comfortably with Assini and Tate Group, which likewise paired protection with targeted disclosure – in Tate Group, of the documents fed into the tool; in Morgan, of the tool’s identity. The working principle is that AI used privately to think through a case is likely protected, while AI used to produce the evidence or opinions a party puts before the court is likely not. Counsel retaining experts should assume the expert’s AI use may be discoverable and preserve the prompts and outputs from the start.

There is also the “substantial need” back door. Work-product protection, unlike privilege, can be overcome on a showing of substantial need and undue hardship, and ordinary (non-core) work product receives materially less protection than mental impressions, conclusions, opinions, and legal theories, which are near-absolute in federal court, categorically non-discoverable as core work product in Texas, and absolutely immune as attorney work product in New York. Opponents will argue that AI outputs are mere factual compilations subject to the lower tier. Expect the fights to move from “is it protected at all” to “which tier, and is the showing met.”19

Practical Guidance for Litigants and Counsel

The decisions reward litigants who treat AI use with the same discipline they apply to other privileged workstreams, and they suggest several concrete practices.

Segregate litigation AI use. Prompts and outputs earn protection because they are created for litigation. Mixing case-strategy sessions with general business queries in a single account or thread invites line-drawing disputes and partial disclosure. Dedicated matters, dedicated accounts, and clear labeling strengthen the anticipation-of-litigation showing – and in New York, where the material must have been prepared solely in anticipation of litigation, a mixed-use thread may forfeit the protection altogether.

Mind the confidentiality settings. Enterprise AI deployments with no-training commitments, retention controls, and confidentiality terms materially improve the waiver analysis – and, after Morgan, may be the only deployments a protective order permits for confidential material at all. Consumer-grade tools with default data-sharing settings are the weakest footing on which to claim confidential work product – and, as Tate Group shows, sharing an opponent’s protected documents with any third-party tool can trigger disclosure obligations of its own.

Build the privilege log before the fight. Tate Group lost roughly 100 pages of chat material in part because the court could not tell from the submission what was being withheld or why. AI chat logs are long, iterative, and mixed in content; a log that treats an entire conversation as a single undifferentiated entry invites in camera review and adverse line-drawing.

Counsel clients – including non-lawyers – early. Tate Group’s extension of protection to a party principal’s own chats is encouraging, but it is a non-final minute entry from a single trial court. Clients should be instructed at the outset of a matter about which AI tools may be used for case-related work, under what settings, and with what materials. Protective orders should be updated to address AI tools expressly – as the courts in both Morgan and Tate Group urged – both to restrict feeding produced documents into them and to anticipate discovery requests aimed at AI usage.

Prepare for both sides of the fight. The same doctrine that shields a client’s AI sessions will shield the adversaries. Litigators should calibrate discovery requests accordingly – targeting AI-related information that falls outside protection, such as the identity of the tool used and what produced documents were uploaded to it – and should be ready to log and defend their own clients’ AI materials with the specificity privilege logs require.

Looking Ahead

Warner, Morgan, Tate Group, and Assini are all trial-level discovery rulings – two magistrate-judge orders, one expressly non-final minute entry, and one uncorrected state trial court decision – and the questions they answer will be relitigated in other states, in other federal districts, and eventually on appeal. Early decisions frame a field, though, and these four frame it favorably for parties that use generative AI thoughtfully in litigation. Courts, meanwhile, are pairing protection with supervision: New York’s Part 161 rules and the sanctions warning in Assini, the AI-specific protective order provision entered in Morgan, and the disclosure obligations imposed in both Morgan and Tate Group together make plain that shielded chats are not a license for unverified filings or careless handling of an opponent’s documents. For clients and counsel alike, the moment calls for deliberate AI governance in litigation: the protection is real, but it belongs to those who build the record to support it.

This article was written by Arnold D. Lee, an attorney in the Phoenix, Arizona office of Spencer Fane. For more information, visit spencerfane.com.

The views expressed are those of the author alone and do not represent the views of Spencer Fane LLP or its clients. This article is for general informational purposes only and is not legal advice.

  1. Warner v. Gilbarco, Inc., No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026) (Patti, M.J.) (ECF No. 94), available at source. ↑
  2. Fed. R. Civ. P. 26(b)(3)(A)–(B), available at source. ↑
  3. Morgan v. V2X, Inc., No. 1:25-cv-01991-SKC-MDB, 2026 WL 864223 (D. Colo. Mar. 30, 2026) (Dominguez Braswell, M.J.) (ECF No. 65), available at source. ↑
  4. Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, Cause No. 25-BC11B-0020 (Tex. Bus. Ct., 11th Div. June 3, 2026) (court minute entry regarding ChatGPT materials in camera review) at 2, available at source. ↑
  5. Assini v Hayward, 2026 NY Slip Op 26086 (Sup Ct, Nassau County June 4, 2026) (Fischer, J.), Index No. 607683/2024, available at source. ↑
  6. Assini, 2026 NY Slip Op 26086 (quoting the amended subpoena directed to non-party OpenAI OpCo, LLC), available at source. ↑
  7. CPLR 2304, available at source. ↑
  8. Assini, 2026 NY Slip Op 26086 (ordering paragraphs; denying mot. seq. no. 006 for failure to comply with the service provisions of the order to show cause, and denying plaintiffs’ cross-motion, mot. seq. no. 007), available at source. ↑
  9. CPLR 3101(c), (d)(2), available at source; Agovino v. Taco Bell 5083, 225 AD2d 569 (2d Dept 1996) (material must be “prepared solely in anticipation of litigation”), cited in Assini, 2026 NY Slip Op 26086. ↑
  10. United States v. Heppner, 2026 WL 436479, 2026 U.S. Dist. LEXIS 32697 (S.D.N.Y. Feb. 17, 2026); Morgan, 2026 WL 864223 (distinguishing Heppner as a criminal matter in which the defendant “acted entirely apart from his lawyer”); Assini, 2026 NY Slip Op 26086 (same, quoting Morgan). ↑
  11. 22 NYCRR Part 161 (Use of Artificial Intelligence Technology), available at source; Assini, 2026 NY Slip Op 26086. ↑
  12. Tate Group, Cause No. 25-BC11B-0020, minute entry at 3–4 (“the Court is of the opinion that”; “entry of these less formal orders is not intended to be final”), available at source. ↑
  13. Tate Group, minute entry at 2 (quoting Morgan, 2026 WL 864223, at *5, and Warner, 2026 WL 373043, at *4; disagreeing with Heppner), available at source. ↑
  14. Tex. R. Civ. P. 192.5(a)(1); Tate Group, minute entry at 2–3. ↑
  15. Tate Group, minute entry at 3 & n.1, 4, available at source. ↑
  16. Fed. R. Civ. P. 26(b)(3)(A)(ii); Tex. R. Civ. P. 192.5(b)(3)–(4); CPLR 3101(d)(2). ↑
  17. Conservation Law Foundation, Inc. v. Shell Oil Co., No. 3:21-cv-00933 (D. Conn. May 18, 2026) (ECF No. 970) (order stayed as of this writing pending district court review of plaintiff’s objection); see Arnold D. Lee, Court Orders Disclosure of Expert Witness’s AI Prompts: What Litigators Need to Know, Spencer Fane (July 8, 2026) (noting that the court “did not squarely resolve” the privilege and work-product questions). ↑
  18. Fed. R. Civ. P. 26(a)(2)(B) (expert report must disclose the facts, data, and methods relied on) and 26(b)(4) (expert trial-preparation protections, including for drafts and most attorney-expert communications), available at source. ↑
  19. Fed. R. Civ. P. 26(b)(3)(A)(ii), (B); Tex. R. Civ. P. 192.5(b)(1)–(4) (core work product not discoverable; other work product discoverable on a showing of substantial need and undue hardship); CPLR 3101(c), (d)(2). ↑