RankShield Legal
Citation checker Request access
Discovery exposure

Are Your AI Prompts Discoverable? Two Courts Answered on the Same Day and Disagreed

On February 10, 2026, two federal courts ruled on whether AI-assisted litigation materials are protected from discovery. Judge Rakoff in the Southern District of New York held that AI-generated documents received neither attorney-client privilege nor work product protection. The same day, a magistrate judge in the Eastern District of Michigan denied a motion to compel exactly that category of material. Both opinions are defensible, and the gap between them is where your firm's AI records currently sit.

By Jamie Kloncz, Founder, RankShield 22 min read Published

This site has spent forty-seven articles telling law firms to keep records: verify your citations and log the verification, inventory your AI tools, document who reviewed what and when. The obvious objection has gone unanswered, and it is the one a skeptical managing partner raises first. If we create that record, are we manufacturing discoverable evidence against ourselves?

The honest answer as of August 2026 is that the law is unsettled, and unusually so. Two federal courts decided the question on the same day and reached opposite results. In U.S. v. Heppner, Judge Jed S. Rakoff of the Southern District of New York held that AI-generated documents were neither privileged nor protected as work product [1]. In Warner v. Gilbarco, Inc., Magistrate Judge Anthony P. Patti of the Eastern District of Michigan denied a motion to compel a pro se plaintiff's AI prompts, outputs, and activity logs, holding the material protected [1][2].

Two state decisions in June pushed further toward protection. The Texas Business Court held in Tate Group Automotive that a party principal's ChatGPT conversations were protected work product under the Texas rule, though it ordered disclosure of the discovery material that had been shared with the tool [3]. A day later, a New York court in Assini v. Hayward quashed non-party subpoenas seeking a litigant's AI prompts, uploads, and outputs [3][6].

The split is real, but it is not random. The decisions turn on a small number of facts that a firm can actually control, and the practical guidance that falls out of them cuts almost the opposite way from what most people assume. This article is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. This area is moving quickly and no appellate court has resolved it; confirm the current state of the law with counsel before relying on any of it.

What Heppner and Warner actually decided

Both were decided February 10, 2026. Heppner (S.D.N.Y., Rakoff, J.) denied both privilege and work product to AI-generated documents. Warner (E.D. Mich., Patti, M.J.) denied a motion to compel a pro se plaintiff's AI prompts, outputs, and activity logs, applying work product protection. The facts, not the technology, drove the difference [1][2].

Heppner arose in a criminal matter. Judge Rakoff gave three reasons for denying protection, and each is worth separating because they fail independently. The AI platform is not an attorney, so the attorney-client privilege had nothing to attach to. The communications lacked confidentiality because the platform's privacy policy reserved the right to disclose user data. And the defendant created the documents independently, without counsel's direction [1].

The governing principle Rakoff articulated is orthodox work product doctrine rather than anything AI-specific: the doctrine "shelters the mental process of the attorney," and does not protect materials "prepared neither by the attorney nor his agents" [1]. On those facts, a defendant querying a commercial chatbot on his own was not producing an attorney's mental impressions.

Warner was an employment discrimination case in which the defendants moved to compel a pro se plaintiff to produce all documents and information concerning her use of third-party AI tools, including prompts, outputs, and activity logs. Judge Patti denied the motion [2].

His reasoning ran the other direction on the technology question specifically. Generative AI programs, he wrote, are "tools, not persons," and treating the act of uploading information onto an AI platform as a waiver "would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed" [2]. There was no evidence the plaintiff had uploaded confidential information, and the court did not undertake the privacy-policy analysis that did decisive work in Heppner.

Read together, the two opinions are less contradictory than they first appear. Heppner asked who prepared the material and whether confidentiality survived the platform's terms. Warner asked whether using a tool forfeits a protection that would otherwise apply. Those are different questions, and a court can answer both correctly and land in different places.

FactorHeppner (S.D.N.Y.)Warner (E.D. Mich.)
DateFebruary 10, 2026February 10, 2026
OutcomeNo privilege, no work productWork product applied; motion to compel denied
Who prepared itDefendant, without counsel's directionPro se litigant preparing for trial
Confidential material uploadedYes, and the privacy policy reserved disclosure rightsNo evidence of confidential uploads
Privacy policy analysedYes, and it defeated confidentialityNo such analysis undertaken
Framing of the toolNot an attorney, not an agent"Tools, not persons"

The two state decisions that pushed toward protection

In June 2026 two state courts extended protection further. The Texas Business Court held in Tate Group Automotive that a party principal's ChatGPT conversations were protected work product under Texas Rule of Civil Procedure 192.5, and that using ChatGPT did not waive it. A day later, a New York court in Assini v. Hayward quashed non-party subpoenas seeking AI prompts, uploads, and outputs under CPLR 2304 [3][6].

Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC came from the Texas Business Court, Eleventh Division, on June 3, 2026. The court found the Texas work-product rule "broad enough to reach a party's own AI-assisted preparation undertaken in connection with the litigation," and held that using ChatGPT did not waive protection [3].

The qualification in Tate Group matters more than the holding for most firms. While protecting the conversations themselves, the court ordered disclosure of all discovery materials and work product that had been shared with ChatGPT, including materials covered by protective orders [3]. The dialogue was shielded; what was fed into it was not.

Assini v. Hayward followed on June 4, 2026 in the Supreme Court of New York, Nassau County. The court quashed non-party subpoenas seeking a litigant's AI prompts, inputs, and outputs, holding that a self-represented litigant may claim work-product protection for AI-assisted case preparation and that using a commercial AI tool does not automatically waive it [3][6].

The court's framing is the most quotable statement available on the underlying intuition: confidential, strategy-focused preparation "is exactly what the trial-preparation doctrine exists to shield, whether the litigant's sounding board is a colleague, a notebook, or a chatbot" [3].

Four decisions in four months, from four different courts, in two different systems, without an appellate ruling to reconcile them. That is the actual state of the question, and any source presenting a settled answer is overstating what exists. Practitioner commentary has converged on the same reading, with one survey of the early federal decisions titled simply "Three Courts, No Consensus" [5].

Tate Group and Assini are state trial-level decisions applying Texas and New York procedure respectively. Heppner and Warner are federal district court decisions binding on no one else. No appellate court has resolved this, and outcomes will vary by jurisdiction and by facts.

RANKSHIELD LEGAL AI work product: four decisions, no consensus Two federal courts split on the same day. The facts, not the technology, decided it. Feb 10 Heppner (S.D.N.Y.) and Warner (E.D. Mich.) decided the same day, opposite results 2026, both district levelNo / Yes Heppner: neither privilege nor work product. Warner: motion to compel denied 3 reasons Heppner: platform is not an attorney, privacy policy defeated confidentiality, no counsel direction 192.5 Tate Group: ChatGPT conversations protected under the Texas rule But inputs shared with the tool had to be disclosedQuashed Assini v. Hayward: non-party subpoenas for AI prompts quashed under CPLR 2304 0 appeals No appellate court has resolved the split as of August 2026 RankShield Legal rankshieldlegal.com
Source: Heppner (SDNY); Warner v. Gilbarco (E.D. Mich.); Tate Group (Tex. Bus. Ct.); Assini (Sup. Ct. Nassau Cty.)

What actually predicts the outcome

Across the four decisions, three facts do most of the work: who wrote the prompt, whether the material was created for litigation, and whether the tool's terms preserved confidentiality. The technology is not the variable. A firm controls all three of these, which is what makes the split actionable rather than merely interesting.

The first factor is authorship. Attorney-crafted prompts made in furtherance of litigation strategy sit closest to the core of the doctrine, because work product exists to shelter the attorney's mental process. Client-generated and expert-generated prompts sit further out, and in some circumstances receive no protection at all. Heppner turned substantially on the defendant having created the documents without counsel's direction [1].

The second is purpose. Work product protects material prepared in anticipation of litigation, which is the standard Federal Rule of Civil Procedure 26(b)(3) sets for documents and tangible things prepared by or for a party or its representative [4]. A prompt written to develop a litigation position is a different artifact from a prompt written to summarise a contract in the ordinary course of business, and the second was never going to be protected regardless of what tool produced it.

The third is confidentiality, and this is the one firms most often overlook. Heppner found confidentiality defeated by the platform's privacy policy, which reserved the right to disclose user data [1]. That is not a fact about AI. It is a fact about the specific vendor agreement, and it means the enforceable terms in your contract may determine whether a protection survives.

That third factor connects this question directly to vendor selection. A written no-training commitment covering inputs and outputs, a data-processing agreement, and terms that do not reserve broad disclosure rights are ordinarily framed as confidentiality protections. Heppner suggests they may also be doing work in a future privilege analysis, which raises the stakes on verifying a vendor's no-training claim rather than accepting it.

What does not appear to matter much is which model or product was used. No court in these four decisions rested on the identity of the tool. The analysis ran on who, why, and under what terms, which are the same questions courts have always asked.

The consumer-tool problem, stated precisely

The sharpest practical lesson in Heppner has nothing to do with litigation strategy. A platform whose terms reserve the right to disclose user data can defeat the confidentiality that both privilege and work product depend on. A lawyer using a personal consumer account is making a privilege decision without knowing it [1].

Firms generally treat shadow AI as a confidentiality problem, which it is. Heppner indicates it may also be a privilege problem, and that framing tends to land harder with litigators than a general warning about data handling.

The mechanism is straightforward. Both privilege and work product depend on material remaining confidential. If the terms governing a platform reserve the right to disclose what is submitted to it, an adversary has an argument that confidentiality was never maintained, entirely apart from whether disclosure actually occurred. Rakoff's analysis reached exactly that conclusion on the platform's privacy policy [1].

The consequence is that the choice between an enterprise agreement and a personal consumer account is not only a data-security decision. It may determine whether an argument for protection is available at all, and that decision is currently being made by individual lawyers, one account signup at a time, without anyone framing it as a privilege question.

This gives a firm a much stronger internal argument than the usual policy language. "Do not use personal AI accounts because it violates the AI policy" is a compliance instruction. "Do not use personal AI accounts because a court has already found that a consumer platform's terms defeated confidentiality" is a litigation argument, and it tends to change behaviour among people who did not respond to the first version. Our guide on shadow AI in a small firm covers how the tools get in.

The scope caveat is important and cuts both ways. Heppner is one district court decision, its privacy-policy reasoning was not adopted in Warner, and no court has held that enterprise terms guarantee protection. The honest statement is that the terms may matter, which is enough to justify choosing them deliberately.

Does a verification record create discovery exposure?

This is the objection to everything this site recommends, and it deserves a straight answer. A verification record is a business record of a process, not litigation strategy, and its discoverability is a different question from the discoverability of prompts. The more useful question is what the record shows if it is produced.

Take the objection at its strongest. A firm logs that it checked forty citations across a brief. That log exists, and in some proceeding an adversary might obtain it. Has the firm created a weapon against itself?

Start with what the record is. A verification log records that a defined process ran: which authorities were checked, by whom, on what date, with what result. It is closer to a business record of a quality-control step than to an attorney's mental impressions about case strategy, which is the material Rule 26(b)(3) is aimed at [4]. Prompts sit nearer the strategy end of that spectrum, which is why the four decisions above are about prompts rather than about process logs.

Then ask the question that actually matters, which is not whether the record can be obtained but what it says. A complete verification log shows that every cited authority was checked and by whom. That is a document a firm should want an adversary or a court to read. The alternative is not the absence of a record; it is the absence of the ability to demonstrate that the work was done.

The asymmetry is the point. If the verification happened and was logged, the record is favourable. If the verification happened and was not logged, the firm is reduced to assertion, which is the position that produced sanctions in the cases this site has covered. If the verification did not happen, the exposure is the conduct rather than the record.

There is one genuine caution. A partial record can be worse than none, because a log showing extensive AI use with verification entries for only some filings invites the question of what happened on the others. Consistency is what makes the record protective. That is an argument for making logging automatic rather than discretionary, which is the same conclusion the record-keeping analysis reaches from a different direction.

To be clear about scope: none of the four decisions here addressed verification logs specifically, and whether any given record is discoverable in a particular matter is a question for counsel on the facts. What the case law does establish is that the analysis turns on authorship, purpose, and confidentiality rather than on the involvement of AI, and a process log is a different artifact from a strategy prompt under every one of those factors.

3 factors what the decisions turn on: who wrote it, whether it was for litigation, and whether the tool's terms preserved confidentiality

What to do while the law is unsettled

Four steps are defensible regardless of how the split resolves: route litigation-related AI use through counsel-directed workflows, use tools whose terms preserve confidentiality, separate strategy prompts from ordinary-course use, and understand that material fed into a tool may be treated differently from the dialogue itself, as Tate Group shows [3].

The temptation with an unsettled question is to wait for clarity. That is not available here on any useful timescale, and the steps below hold up under either line of authority, which is the test worth applying while a split is live.

The Tate Group qualification deserves specific attention because it is the least intuitive result of the four. The court protected the ChatGPT conversations and then ordered disclosure of the discovery materials and work product that had been shared with the tool, including material under protective orders [3]. A firm reading only the headline would take away that its AI conversations are safe. The more accurate reading is that the dialogue and the inputs can be treated separately, and that pasting produced documents into a tool may create an obligation independent of the conversation's protected status.

That is also a reminder that a protective order in the matter is its own constraint. Where an order restricts how produced material may be handled, feeding it into an AI tool can raise a compliance question entirely separate from privilege, which our guide on AI restrictions in protective orders addresses.

Preservation is the other practical consequence. If AI prompts and outputs may be discoverable in some circumstances, they may also be subject to a litigation hold, and a firm that cannot preserve them because they live in individual consumer accounts has a problem that is procedural rather than substantive. That is one more reason the account question is worth settling before it is tested.

  1. Route litigation AI use through counsel directionAuthorship is the factor most consistently doing work across these decisions. Material prepared at counsel's direction in anticipation of litigation sits closest to the core of the doctrine; material a client generated independently sits furthest from it [1].
  2. Choose tools whose terms preserve confidentialityHeppner found a platform's privacy policy defeated confidentiality because it reserved the right to disclose user data. Enterprise terms with a written no-training commitment and no broad disclosure reservation are the ones to be using [1].
  3. Separate strategy prompts from ordinary-course useA prompt developing a litigation position and a prompt summarising a contract in the ordinary course are different artifacts. Keeping them in different systems makes the distinction visible later rather than arguable.
  4. Treat inputs separately from the dialogueTate Group protected the conversations and still ordered disclosure of the discovery material shared with the tool. Track what gets fed into an AI system, particularly anything covered by a protective order [3].
  5. Make sure prompts can be preservedIf this material may be discoverable, it may also be subject to a litigation hold. Prompts living in individual consumer accounts cannot be reliably preserved, collected, or produced.

Why this is likely to stay unsettled for a while

Four trial-level decisions in four months, across state and federal systems, with no appellate ruling. The doctrines involved are fact-intensive by design, which means appellate resolution is unlikely to produce a bright-line rule even when it arrives. Firms should plan for a period of jurisdictional variation rather than a single answer.

It is tempting to read a split as a temporary condition awaiting correction. The structure of these doctrines suggests otherwise.

Work product analysis is fact-intensive by design. Rule 26(b)(3) asks whether material was prepared in anticipation of litigation by or for a party or its representative, and that inquiry resists categorical answers [4]. An appellate court resolving one of these cases would most likely announce a framework and remand, leaving the outcome in the next case to depend on its own facts.

The decisions also arise under different bodies of law. Tate Group applied Texas Rule of Civil Procedure 192.5, Assini turned on CPLR 2304, and Heppner and Warner applied federal doctrine [1][3]. State work-product rules are not uniform, so even a definitive federal answer would leave state practice to develop separately.

The facts will also keep changing underneath the doctrine. Heppner's confidentiality analysis rested on a platform's privacy policy, and platform terms change. Enterprise offerings with contractual confidentiality commitments did not exist in their current form when much of the surrounding doctrine developed, and a decision resting on a 2026 privacy policy tells you less than it appears to about a product with different terms.

The planning consequence is to build for variation rather than for an answer. The four steps above are defensible under either line of authority precisely because they do not depend on which one prevails, and a firm that adopts them is not making a bet on how the split resolves.

Watch the question rather than assuming it is settled, and re-check before relying on any characterisation of the law, including this one. This article reflects the position as of August 2026, in an area that produced four significant decisions in the preceding six months.

Test yourself

Test yourself on the AI work product split

Five questions on what the 2026 decisions actually turned on.

  1. 1What is unusual about Heppner and Warner?

    Answer: They were decided the same day and reached opposite results

    Both were decided February 10, 2026. Heppner (S.D.N.Y., Rakoff, J.) denied privilege and work product; Warner (E.D. Mich., Patti, M.J.) denied a motion to compel AI prompts, outputs and logs. Both are district-level and bind no other court.

  2. 2Which Heppner reason is most actionable for a firm choosing tools?

    Answer: The privacy policy reserved the right to disclose user data, defeating confidentiality

    That is not a fact about AI; it is a fact about a specific vendor agreement. It means the enforceable terms in your contract may determine whether a protection argument is even available, which makes tool selection a privilege question.

  3. 3Does uploading material to an AI tool automatically waive work product?

    Answer: No court has held that, and Warner rejected it explicitly

    Warner reasoned that such a rule "would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed." Tate Group and Assini also held that using a commercial AI tool does not automatically waive protection.

  4. 4What did Tate Group order disclosed despite protecting the ChatGPT conversations?

    Answer: The discovery materials and work product that had been shared with the tool

    The dialogue was shielded; the inputs were not. The court ordered disclosure of discovery materials shared with ChatGPT, including material under protective orders, so pasting produced documents into a tool can create an obligation independent of the conversation's status.

  5. 5Which three facts most consistently drive these outcomes?

    Answer: Who wrote the prompt, whether it was for litigation, and whether the terms preserved confidentiality

    No court in the four decisions rested on the identity of the tool. The analysis ran on authorship, purpose, and confidentiality, which are the questions courts have always asked about work product.

Honest self-check. There is no sign-up, and nothing is stored.

Questions answered

Straight answers to the common questions

The questions readers ask about this topic, answered directly. No forms, no sales pitch.

JAMIE KLONCZ · SEO AGENCY NAPLES ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →

References

  1. Paul, Weiss, Rifkind, Wharton & Garrison. Federal Courts Reach Different Outcomes on Whether AI-Generated Materials Warrant Work Product Protection. 2026. https://www.paulweiss.com/insights/client-memos/federal-courts-reach-different-outcomes-on-whether-ai-generated-materials-warrant-work-product-protection
  2. Proskauer Rose. Michigan Federal Court Protects AI-Assisted Litigation Work Product (Warner v. Gilbarco, Inc., E.D. Mich. Feb. 10, 2026). 2026. https://www.proskauer.com/alert/michigan-federal-court-protects-ai-assisted-litigation-work-product
  3. Spencer Fane. Courts Begin Shielding AI Prompts and Outputs From Discovery: New York and Texas Recognize Work-Product Protection. 2026. https://www.spencerfane.com/insight/courts-begin-shielding-ai-prompts-and-outputs-from-discovery-new-york-and-texas-recognize-work-product-protection-for-ai-assisted-litigation-work/
  4. Legal Information Institute, Cornell Law School. Federal Rule of Civil Procedure 26(b)(3): Trial Preparation, Materials. 2026. https://www.law.cornell.edu/rules/frcp/rule_26
  5. Mintz. Three Courts, No Consensus: The Evolving Privilege Landscape for GenAI-Generated Legal Materials. April 2026. https://www.mintz.com/insights-center/viewpoints/54731/2026-04-29-three-courts-no-consensus-evolving-privilege-landscape
  6. Greenberg Traurig, eDiscovery Watch. New York Court Recognizes Work-Product Protection for AI Prompts and Outputs in Discovery (Assini v. Hayward). July 2026. https://www.gtlaw-ediscoverywatch.com/2026/07/new-york-court-recognizes-work-product-protection-for-ai-prompts-and-outputs-in-discovery/
Written by

Jamie Kloncz

Founder, RankShield

Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.

More about Jamie →
Try it · Free

Check a citation against live case-law

Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.

Try the citation checker