Legal briefings

Case law, analysis, and governance references

Companies are rolling out Copilot and ChatGPT Enterprise, then learning in discovery that unsupervised employee prompts are ordinary evidence — not privileged legal work. Across federal, state, and equity courts, attorney direction and confidentiality posture decide whether AI-assisted work is protected. Updated September 2026.

Executive summary

Enterprise AI is not privileged AI

Buying Copilot or ChatGPT Enterprise and telling staff to use it does not create attorney-client privilege. Privilege turns on counsel direction and confidentiality — not on the procurement channel.

Companies are already losing on the record

Krafton (CEO ChatGPT into Slack), Heppner (executive Claude use), and Shealy (represented-party ChatGPT) show unsupervised corporate AI becoming discoverable evidence or compelled production.

Copilot chats are ESI by design

Microsoft stores Copilot prompts and responses in hidden mailbox locations searchable through Purview eDiscovery. The archive exists whether legal wants it or not.

Courts are closing the open-loop door

Jeffries/Harcros and Morgan write protective orders that bar open AI for discovery materials. The tools companies rolled out for productivity are the ones courts are now fencing off.

The corporate exposure pattern

Companies buy enterprise Copilot and ChatGPT, tell employees to use them for speed, then discover in litigation that the prompts are ordinary business records — not privileged legal work.

1. Rollout without counsel

IT enables Microsoft 365 Copilot, ChatGPT Enterprise, Slack AI, or Gemini. Employees are told to use AI for drafting, strategy, HR, and deal work. No one routes legal-adjacent prompts through the GC.

2. A written record of intent

Prompts about firing someone, avoiding an earnout, or responding to a regulator become contemporaneous state-of-mind evidence. Pasting outputs into Slack or email waives any residual privilege argument before discovery starts.

3. Discovery finds it anyway

Consumer chats sit with the vendor. Enterprise Copilot chats sit in Exchange, searchable via Purview. Either way, opposing counsel now asks for AI interaction histories as routine ESI.

What the cases actually show

  • Krafton — CEO ChatGPT strategy about a $250M earnout quoted at trial after it was shared internally on Slack; logs deleted, motives imputed.
  • Heppner — company executive’s unsupervised Claude documents neither privileged nor work product; later sharing with counsel did not cure it.
  • Shealy — represented commercial party’s ChatGPT work compelled because counsel did not direct it.
  • Jeffries / Harcros — court barred open AI (including consumer Copilot/ChatGPT) for all discovery materials, not just confidential ones.
  • Employment guidance — MoFo and Wilentz warn that HR/manager prompts about terminations and investigations are discoverable and quotable in the suit that follows.

Saidebar’s answer is the structural fix those opinions describe: attorney direction from the first prompt, confidential tooling, review before anything leaves the channel, and an auditable trail of who signed off.

Latest updates

Corporate AI discoverability is no longer theoretical: Delaware equity used CEO chatbot strategy as evidence, Massachusetts compelled represented-party ChatGPT work, and Kansas barred open AI across discovery productions.

Fortis Advisors v. Krafton remains the headline corporate case: a buyer CEO’s ChatGPT earnout-avoidance playbook, shared on Slack, became the evidentiary spine of a Delaware judgment. Privilege was never realistically available once non-lawyers received the outputs.

Shealy v. Seaside Investments (Mass. Super. Ct. BLS, Jun. 16, 2026) extends the same logic to commercial litigants who are represented but still run ChatGPT without counsel directing the work — production compelled.

Jeffries v. Harcros Chemicals (D. Kan., Mar. 25, 2026), 2026 WL 820218, shows the other half of the corporate problem: courts are amending protective orders to ban open-loop GenAI for discovery materials. Companies that already rolled out consumer-style Copilot workflows now face orders that conflict with how their employees actually work.

Lnu v. Blanche (9th Cir.) and White v. Walmart (S.D. Ind.) make the oversight point for outside and in-house counsel alike: unverified AI filings and unreviewed AI discovery positions are process failures with real consequences.

Governance firms are catching up in public: Redgrave documents that Microsoft 365 Copilot Chat stores prompts for Purview collection by default; Orrick advises that even private LLMs do not privilege employee legal queries without counsel direction.

Where the courts stand

The central divide is whether the AI user was acting under counsel direction (or as their own advocate) versus using GenAI independently while represented — the typical corporate fact pattern.

DecisionCourtAttorney directed?Outcome
HeppnerS.D.N.Y. (criminal)NoNot protected
KraftonDel. Ch. (equity)NoUsed as evidence
ShealyMass. Super. (civil)No (represented)Compelled
WarnerE.D. Mich. (civil)Pro se partyWork product held
MorganD. Colo. (civil)Pro se partyHeld; tool disclosed
AssiniN.Y. Sup. Ct. (civil)Pro se partyOpenAI subpoena quashed
Tate GroupTex. Bus. Ct. (state)Non-lawyer principalHeld; scope disclosed
JeffriesD. Kan. (civil)N/A (protective order)Open AI barred
WhiteS.D. Ind. (civil)Counsel, unreviewedMeet-and-confer failed
Lnu9th Cir. (appellate)Counsel, unverifiedSanctions + firm order
CLF / ShellD. Conn. (civil)Expert witnessPrompts compelled
TremblayN.D. Cal. (civil)NoProduction compelled

Every decision leaving material unprotected involved AI use outside attorney direction, outside attorney verification, or in an expert/methodology context.

Primary case materials

Federal, state, equity, and appellate decisions that directly address AI privilege, work product, discovery, sanctions, and oversight.

Showing 12 of 12

PrivilegeFeb 17, 2026

United States v. Heppner

S.D.N.Y.

A company executive under criminal investigation used Claude to draft defense strategies without attorney direction. The court held that privilege did not attach because no attorney was involved at the front end, the AI platform is not an attorney, and the platform’s privacy policy permitted data disclosure. Sharing the outputs with counsel afterward did not cure the defect. Cited as 2026 WL 436479; 820 F. Supp. 3d 292. Practitioners read the opinion as a warning for corporate employees who put legal or regulatory questions into consumer or even private LLMs without counsel directing the work.

Takeaway: Enterprise deployment alone does not create privilege. Without counsel direction, AI legal analysis by employees is ordinary evidence.

View document
EvidenceMar 16, 2026

Fortis Advisors LLC v. Krafton, Inc.

Del. Ch.

The leading corporate AI-evidence case. Facing a projected $250 million earnout, Krafton’s CEO asked ChatGPT how to take control of the acquired studio and avoid the payment — after counsel had already told him a for-cause strategy would not work. He pasted the chatbot outputs into Slack with colleagues, so any privilege claim was waived before discovery even started. Vice Chancellor Lori W. Will quoted the exchanges at length, matched the AI playbook to what the company actually did, found pretext and bad faith, reinstated the target CEO, and extended the earnout period by 258 days. The CEO also admitted deleting the original chat logs. Cited as 2026 WL 730977; 354 A.3d 906; C.A. No. 2025-0805-LWW.

Takeaway: This is what happens when a company encourages AI use without routing sensitive strategy through counsel: the prompts become Exhibit A. Copilot and ChatGPT Enterprise do not change the privilege analysis if no attorney directed the work.

View document
Work productJun 16, 2026

Shealy v. Seaside Investments, LLC

Mass. Super. Ct. (BLS)

Massachusetts first-impression ruling in a commercial note dispute. A represented plaintiff had his romantic partner upload transaction documents to ChatGPT and draft a response without consulting counsel. Judge Debra A. Squires-Lee compelled production: neither the partner nor ChatGPT was a qualifying “representative,” and AI output is not opinion work product because “AI is a tool not a person.” The court distinguished Warner and Morgan as pro se cases and aligned with Heppner. No. 2684CV00799-BLS2.

Takeaway: Companies that tell staff to “just use ChatGPT” on live disputes create the Shealy fact pattern: represented-party AI work, no counsel direction, production compelled.

View document
Work productFeb 10, 2026

Warner v. Gilbarco, Inc.

E.D. Mich.

A pro se plaintiff used AI tools in litigation preparation. The court protected the materials as work product, rejecting the argument that AI platform use constituted waiver. ChatGPT and similar programs “are tools, not persons,” so using them is not disclosure to an adversary. Cited as 2026 WL 373043; 820 F. Supp. 3d 629.

Takeaway: Work product outcomes are fact-specific. Pro se status and treating AI as a tool, not a person, drive the protective civil line.

View document
Work productMar 30, 2026

Morgan v. V2X, Inc.

D. Colo.

Magistrate Judge Dominguez Braswell held that a pro se litigant’s AI-assisted preparation is protected work product under Rule 26(b)(3), but that the identity of the AI tool is not protected and must be disclosed. The court also imposed an AI-specific protective order barring confidential information from any AI platform unless the provider is contractually prohibited from training on inputs or disclosing them, and permits deletion on request. Cited as 2026 WL 864223.

Takeaway: Even where work product holds, the choice of AI tool can be discoverable, and confidential material may not enter consumer AI absent contractual safeguards — precisely the controls Saidebar builds into the workflow.

View document
Work productJun 4, 2026

Assini v. Hayward

N.Y. Sup. Ct. (Nassau Cty.)

First major New York state decision on GenAI discovery. The court quashed a non-party subpoena to OpenAI seeking a pro se defendant’s prompts, uploads, and outputs used to prepare filings. Citing Morgan as persuasive and distinguishing Heppner, the court treated AI-assisted litigation preparation as conditionally protected under CPLR 3101(d). Cited as 2026 NY Slip Op 26086; 2026 WL 1677232.

Takeaway: State courts are extending the Warner/Morgan line for pro se litigants, while still warning that unverified AI filings can draw sanctions.

View document
Work productJun 3, 2026

Tate Group Automotive v. Legacy Automotive Capital

Tex. Bus. Ct., 11th Div.

First state business-court work-product ruling on GenAI. After in camera review, Judge Dorfman held that a non-lawyer principal’s ChatGPT conversations prepared in anticipation of litigation are protected under Tex. R. Civ. P. 192.5(a)(1), and that using the tool did not waive protection. As in Morgan, the court still ordered disclosure, by Bates number, of every discovery document fed into ChatGPT. Cause No. 25-BC11B-0020.

Takeaway: Courts increasingly protect AI-assisted work product but treat the fact and scope of AI use as discoverable. Feeding confidential discovery into consumer AI can breach a protective order.

View document
Protective orderMar 25, 2026

Jeffries v. Harcros Chemicals, Inc.

D. Kan.

In a putative toxic-tort class action against a chemical facility operator, Magistrate Judge Angel D. Mitchell amended the protective order to bar parties from uploading any discovery materials — including non-confidential documents — into public or “open-loop” generative AI tools such as consumer ChatGPT or Copilot. Closed, secure tools with no-training, no-disclosure, and deletion controls remained permitted. The court cited irretrievable training exposure, privacy/GDPR risk, and the incentive for parties to under-produce if open AI were allowed. Cited as 2026 WL 820218; Nos. 25-2352 / 25-2569.

Takeaway: Courts are no longer treating consumer AI as a free discovery workspace. Companies that rolled out enterprise Copilot without closed-loop controls now face protective orders that effectively ban the tools their employees already use.

View document
OversightApr 14, 2026

White v. Walmart, Inc.

S.D. Ind.

Plaintiff’s counsel uploaded Walmart’s discovery responses into an AI tool, asked it to identify deficiencies, and copied the unreviewed output to opposing counsel and the court. Magistrate Judge Tim A. Baker held that exclusive reliance on AI does not satisfy Rule 37(a)(1)’s good-faith meet-and-confer duty: AI “can be a useful discovery tool” but “is not a substitute for good lawyering.” No. 1:25-cv-01120-RLY-TAB.

Takeaway: Attorney judgment remains non-delegable even in routine discovery. Unreviewed AI output sent to the court or opposing counsel is a process failure, not a productivity gain.

View document
SanctionsJun 3, 2026

Lnu v. Blanche

9th Cir.

The Ninth Circuit sanctioned and suspended two attorneys for filing briefs with nonexistent cases, misattributed quotations, and gross misrepresentations, then failing to candidly disclose that generative AI hallucinations were the source. The court stressed it was not punishing AI use itself — the violation is signing and filing unverified material. For two years, every attorney at their firm must disclose AI use in filings and certify personal citation review under penalty of perjury. No. 24-4790.

Takeaway: Appellate courts now treat unverified AI filings as professional misconduct with firm-wide operating consequences. Supervised verification before sign-off is the compliance baseline.

View document
DiscoveryMay 18, 2026

Conservation Law Foundation v. Shell Oil Co.

D. Conn.

Magistrate Judge Farrish ordered production of generative AI prompts an expert witness used to cull and analyze document productions. Expert methodology remains fair ground for discovery; protections that may shield a party’s litigation strategy do not extend to a testifying expert’s AI process. Case No. 3:21-cv-00933.

Takeaway: Wall off testifying experts from privileged attorney-directed AI workflows. Expert prompts and queries are methodology, not strategy.

View document
DiscoveryJun 24, 2024

Tremblay v. OpenAI

N.D. Cal.

In a discovery dispute, the court compelled production of AI prompts, outputs, account settings, and testing process. The court held that placing a subset of test results in the complaint waived work product protection over related negative results.

Takeaway: AI prompts, outputs, and testing process can become central evidence. Account settings and interaction history are discoverable.

View document

Analysis and market context

Secondary sources explaining why attorney-supervised AI workflows are accelerating.

Showing 17 of 17

Orrick: Court rules AI conversations are not privileged — what Heppner means for companies

March 2026 corporate advisory: unless working at the express direction of counsel, non-lawyers should not use even private AI tools for legal or regulatory analysis. C-suite and junior employees alike create discoverable records when they query AI about legal exposure — enterprise firewall alone does not fix it.

Read analysis

Potomac Law: The CEO’s chatbot history at trial

Detailed reconstruction of Krafton: ChatGPT outputs pasted into Slack waived any privilege argument; deletion of original logs became additional motive evidence. Explicitly flags Microsoft 365 Copilot, Google Workspace AI, Slack AI, and Notion AI as hold-scope data.

Read analysis

Morrison Foerster: Algorithms as Exhibit A in workplace disputes

March 2026 employment guide: HR and manager prompts like “how to document a problem employee before firing her” are discoverable, unprivileged, and quotable in the discrimination suit that follows. Train staff that privilege does not attach to AI use.

Read analysis

Redgrave: The horse is out of the barn with Microsoft 365 Copilot Chat

Information-governance alert: Copilot Chat is enabled by default and quietly captures prompts, responses, referenced files, and linked documents in hidden Exchange locations searchable via Purview eDiscovery. Rolling out enterprise Copilot without retention and hold workflows creates a discoverable archive by design.

Read analysis

Wilentz: Is your AI chat history discoverable? Heppner says yes

August 2026 employment-side brief translating Heppner for employers: supervisor and HR consumer-AI chats about terminations and investigations are ordinary ESI. Litigation holds must reach prompts, outputs, and activity logs.

Read analysis

Baker Donelson: Are your AI chats discoverable?

July 2026 synthesis of eight opinions in four months mapping the Heppner outlier against the Warner/Morgan/Assini/Tate civil line, plus expert-prompt, protective-order, and deposition-misuse cases. Practical checklist: direct the use, choose closed tools, assume tool identity is discoverable, wall off experts.

Read analysis

Sidley: Generative AI in discovery — protective orders as an emerging dispute

April 2026 analysis of Morgan and Jeffries: courts are writing AI restrictions into protective orders, distinguishing open consumer tools from closed enterprise systems with contractual no-training terms.

Read analysis

Nixon Peabody: Lessons from Shealy v. Seaside

July 2026 alert explaining why represented-party AI use routed through a non-attorney sank work product, and why courts favorably cite Heppner when counsel did not direct the work.

Read analysis

Epstein Becker Green: Powerful tool, but not an attorney

August 2026 analysis of Shealy as Massachusetts first impression: AI output is not opinion work product absent attorney direction or input.

Read analysis

Venable: AI, privilege, and the Heppner ruling

Structural reading of Judge Rakoff’s memorandum: GenAI is not incompatible with privilege; unsupervised consumer use is. Points to Kovel-style protection where counsel directs a confidential AI workflow.

Read analysis

NYC Bar: The intersection of AI, privacy, and privilege

Comprehensive bar association report on how model training, retention, and privacy policies interact with privilege and work product, surveying Heppner, Warner, and Morgan.

Read analysis

Harvard Law School Forum: Are AI legal chats by non-lawyer officers discoverable?

July 2026 Fried Frank analysis synthesizing Heppner, Krafton, Warner, Morgan, and Tate. Identifies the central divide as whether AI is a litigation tool or the equivalent of a person giving legal advice, and recommends that companies require counsel to direct GenAI use on legal matters.

Read analysis

Harvard Law School Forum: How a buyer’s AI conversations sank its earnout strategy

April 2026 analysis of Fortis Advisors v. Krafton detailing how the Court of Chancery quoted the buyer’s AI prompts and how the absence of counsel direction removed any privilege claim.

Read analysis

Paul, Weiss: Federal courts reach different outcomes on AI work product

Side-by-side of Warner and Heppner decided the same day, framing the tool-versus-person split and the counsel-direction requirement.

Read analysis

California Lawyers Association: Ninth Circuit AI filing sanctions

Practitioner summary of Lnu v. Blanche: the misconduct is signing and filing unverified material and lack of candor, not AI use itself; firm-wide disclosure and verification orders follow.

Read analysis

Mintz: Three courts, no consensus on GenAI privilege

Comparative analysis of Heppner, Warner, and Morgan, noting the open question of how courts will treat a represented party who uses AI without counsel — later answered in part by Shealy.

Read analysis

Law.com: Florida becomes the first state to sue OpenAI

Coverage of State of Florida v. OpenAI (June 1, 2026), the first state attorney general action against OpenAI and Sam Altman, signaling escalating enforcement pressure on unsupervised consumer AI.

Read analysis

Standards and governance

Professional duty and risk management frameworks that inform our operational approach.

Fed. R. Civ. P. 26

Federal discovery rules and work product doctrine framework.

View reference

ABA Model Rule 1.6

Confidentiality of information and duty to prevent unauthorized disclosure.

View reference

ABA Formal Opinion 512

National ethics framework for lawyers using generative AI: informed client consent before confidential data enters self-learning tools, plus competence and supervision duties.

View reference

NIST AI Risk Management Framework

Federal framework for trustworthy AI controls, risk management, and governance.

View reference

Policy watchlist

Legislative proposals, standing orders, and enforcement actions that harden the case for attorney-supervised AI channels.

Protective orders are catching up. Morgan and Jeffries/Harcros restrict confidential (and in Kansas, even non-confidential) discovery materials from open-loop AI tools unless the provider is contractually barred from training and disclosure and permits deletion — terms that exclude most consumer chatbots and conflict with many enterprise Copilot rollouts that were never configured for closed-loop litigation use.

Individual judges are also issuing standing AI certification orders. W.D. Tex. examples require counsel to disclose GenAI assistance and certify independent verification plus no unauthorized disclosure of confidential or privileged information.

Enforcement pressure continues: Florida’s June 2026 attorney-general action against OpenAI, combined with appellate sanctions in Lnu, signals that unsupervised consumer AI is no longer a soft ethics topic.

ABA Formal Opinion 512 and guidance from dozens of state bars still require lawyers to vet AI data-handling and obtain informed client consent before entering confidential information into self-learning tools — obligations that favor attorney-supervised channels with enforceable vendor confidentiality terms.

Brief your team

We provide custom briefings for law firm leadership, legal operations, compliance, and procurement.