The Intersection of Artificial Intelligence, Privacy, and Privilege
SUMMARY
The Task Force on Artificial Intelligence and Digital Technologies (Lorraine McGowen, Tiffany Smith and Jerome Walker, Co-Chairs) issued a report, “The Intersection of Artificial Intelligence, Privacy, and Privilege,” which provides initial guidance to practitioners, policymakers, and the courts regarding how various aspects of AI model training, usage and Privacy Policies intersect with potential expectations or assumptions of protectability under the attorney-client privilege and/or work product doctrine. The report describes the practical realities of how large language models work and explains why market participants, policymakers, counsel, and courts must have a basic understanding of the technology, including what it means to “disclose” confidential or privileged information in this context. The report also explains the key role of Privacy Policies and of attorneys in drafting, reviewing, implementing, and enforcing Privacy Policies and protecting privacy expectations in the context of the attorney-client privilege and work product doctrine, as well as the critical importance of the Third-Party Doctrine and why it is essential that counsel and courts take into account the evolution of the doctrine in framing the role of AI technology in analyses presented to the courts. The report also provides recommendations designed to help counsel and courts address challenges caused by the rapid advancement in generative AI technology and how courts must balance privacy issues with the policies underlying the attorney-client privilege and work product doctrine.
REPORT
REPORT BY THE PRESIDENTIAL TASK FORCE ON
ARTIFICIAL INTELLIGENCE AND DIGITAL TECHNOLOGIES
THE INTERSECTION OF ARTIFICIAL INTELLIGENCE,
PRIVACY, AND PRIVILEGE
I. INTRODUCTION
Companies and individuals are adopting artificial intelligence (AI) at a rapid rate, raising a host of important issues for market participants, policymakers, counsel, and courts. US survey data released by the Board of Governors of the Federal Reserve System on April 3, 2026, reveals that approximately 18 percent of companies throughout the US have adopted either an AI tool or a large language model (LLM), often powering a chatbot. This data reflects a stunning 68 percent increase in AI adoption measured year-over-year from September 2025. Work-related generative AI (GenAI)[1] adoption stands at approximately 41 percent; approximately 78 percent of the labor force are employed by companies that have adopted AI; and approximately 54 percent are employed at companies that specifically use LLMs.[2]
GenAI adoption has increased in the face of a fragmented landscape of AI laws – some of which are state-specific and others are sector-specific federal laws.[3] Unlike a number of countries and the European Union, the US federal government has not enacted a comprehensive AI scheme.[4] Many commenters have asserted that this fragmented legal landscape means market participants, policymakers, counsel, and courts have and will continue to face challenging AI issues without the benefit of legal clarity. Legal clarity, in turn, requires some basic understanding of AI model training, prompting (i.e., user inputs), output generation (i.e., inference), and the applicability, implementation, and enforceability of privacy laws and policies, and the contractual terms of service/terms of use (collectively, the application, implementation, and enforceability of privacy laws and policies (including privacy notices), and the contractual terms of service/terms of use are referred to as Privacy Policies).
Privacy Policies are particularly important for setting expectations as to both when use of a tool or an LLM might be protected from disclosure, and when it might not. Privacy Policies also set expectations as to when inputted data (and especially highly sensitive data) might be inadvertently disclosed to third parties through the use of GenAI – even if the user is never legally required to disclose the use of GenAI. Understanding these issues is a basic prerequisite to identifying applicable legal issues and developing an appropriate legal framework. The need for clarity and understanding is especially important for counsel and courts regularly facing complex and novel legal issues raised by GenAI models.[5]
Legal disputes over the applicability and boundaries of GenAI tools in the context of legal privilege are one example of how important issues can play out. On February 10, 2026, two federal district courts, one in New York and one in Michigan, reached seemingly opposite conclusions in disputes regarding whether a party’s use of a consumer GenAI tool was protected by attorney-client privilege or work-product protection. On March 30, 2026, a federal magistrate judge, in Colorado reached a conclusion closely aligned with the court in Michigan on a similar set of facts.[6] Collectively, the courts grappled with the impact of model training, the timing of usage by the consumer, and the Privacy Policies, though the specific focus varied. Together, these cases demonstrate the critical importance of understanding how GenAI models are trained and how the models operationally handle user inputs and outputs as well as how applicable Privacy Policies govern retention, reuse, and disclosure of that information.[7] Read as a group, these cases underscore why market participants, policymakers, counsel, and courts would benefit from careful attention to the technical operation of GenAI models, and the Privacy Policies involved.
To provide input into this important and emerging area, the New York City Bar Association (City Bar) Presidential Task Force on Artificial Intelligence and Digital Technologies[8] (Task Force) established a Working Group on the Intersection of AI and Privacy[9] (Working Group) to provide initial guidance to market participants, policymakers, counsel, and courts regarding how various aspects of AI model training, usage and Privacy Policies intersect with potential expectations or even assumptions of protectability pursuant to the attorney-client privilege or work product doctrine.[10] For instance, what does model training, the inputs and the outputs, and a given tool’s Privacy Policy mean for a user’s expectation of privacy and confidentiality?[11] As with so many issues counsel and courts encounter, much depends on context: the facts of a case; how an issue is raised and rebutted; and what is and is not briefed and measured against long-standing common-law principles.
Section II of this analysis, titled The Practical Realities of How Large Language Models Work, explains why market participants, policymakers, counsel, and courts must have a basic understanding of the technology, especially because changes in technology regarding what it means to “disclose” confidential or privileged information should inform the analysis. Section III of this analysis, titled The Practical Realities of How Privacy Policies Like Those Used by Anthropic and OpenAI Work, explains not only the key role of Privacy Policies, but also the key role of attorneys in drafting, reviewing, implementing, and enforcing Privacy Policies and protecting privacy expectations in the context of the attorney-client privilege and work product doctrine. Section IV of this analysis, titled Third-Party Doctrine: GenAI, Privacy, and Potential Erosion, explains the critical importance of the Third-Party Doctrine and why it is essential that counsel and courts take into account the evolution of the doctrine and make the correct judgment in framing the role of the technology in the analysis presented to the courts. Section V of this analysis, titled Practical Guidance for Counsel and Courts, provides recommendations designed to help counsel and courts address challenges caused by the rapid advancement in the technology and how courts must balance privacy issues with the policies underlying the attorney-client privilege and work product doctrine.
II. THE PRACTICAL REALITIES OF HOW LARGE LANGUAGE MODELS WORK
Market participants, policymakers, counsel, and courts would be well served by understanding the underlying GenAI technology sufficiently to spot and address relevant issues. In the case of counsel and the courts, this results in clear and relevant briefing. No one should assume that any other party has an adequate or even the same understanding of how a specific GenAI tool works and interacts with other tools or users. Similarly, Privacy Policies add another element of complexity because they include contractual arrangements that attempt to address privacy law issues often particular to a specific company and a specific industry, or even a specific GenAI model. Although GenAI is relatively new, the common law has proven again and again its adaptability and flexibility. Counsel and courts have been down the road of novel technologies before. The rise of remote computing; freely available email platforms; cellular communications; smartphones; ubiquitous GPS; cloud storage; social media; and modern advertising technology have required courts, policymakers, counsel, and other stakeholders to wrestle with the implications of the transfer of a person’s sensitive information to a third-party actor. The analysis of this issue has grown more nuanced as stakeholders have absorbed the changes these technologies have brought to everyday life. The same arc is likely as GenAI tools expand into ever-broader use.
This section explains how LLMs[12] are trained to provide stakeholders, including market participants, policymakers, counsel, pro se litigants, and courts, with relevant information about the technology. The Working Group analysis focuses on determining whether user inputs to an AI platform should be treated as if those inputs were “disclosed,” with respect to attorney-client privilege and the work product doctrine, in the same way that disclosure occurs when information is disclosed to a third-party through an email; during a telephone call; in the traditional physical delivery of documents; or during a voice exchange between two or more individuals.
Almost all of the GenAI models with which the Working Group is familiar (e.g., those from OpenAI, Anthropic, Google, Meta, xAI, and others) are based on the “transformer” architecture. At a very high level, these models work as follows. During model pre-training, enormous amounts of information are collected from multiple sources.[13] A GenAI model like OpenAI’s GPT-5.5 or Anthropic’s Claude Opus 4.7 may have on the order of hundreds of billions or even trillions of parameters (which can be thought of as information related to other information inside of a neural network). A model’s training data may comprise many trillions of words, electronic images, and other digital data. These GenAI models do not store all this data verbatim; rather, the data exist on a spectrum between generalization and memorization, with content that is repeated many times across the training corpus more likely to be retained in near-verbatim form, and unique, low-frequency content (such as an individual user’s privilege input) much more likely to be absorbed only as a contribution to general statistical patterns. Rather, the data is broken into pieces (or “tokenized”) during the training process, then translated into numerical values. These “tokens” are the input units on which the model operates; they are then ingested or fed into the model, which gradually adjusts its parameters (or “weights”) to better predict the next token in a sequence. The training data’s statistical structure (i.e., grammar, reasoning patterns, and factual associations) is encoded in those weights rather than as a retrievable copy of any particular document.[14] The AI system then identifies and prioritizes general patterns. Those patterns are encoded in mathematical parameters or weights.
How GenAI is trained is important for conceptualizing how it generates an output. An entirely separate, but key part of what is input into a model occurs when a user enters a query or question. When a user enters a request or question, the model does not conduct a search in the way Westlaw or Lexis would have conducted a search several years ago: there is no “hunt and peck” for the right case. Instead, the model also tokenizes the query as its own input and applies existing weights to generate an output that is responsive (one hopes) to the user’s query. These technical features are particularly important for stakeholders when evaluating whether an individual user’s input could be meaningfully “disclosed” in the same way as information transmitted to a human third party. The two processes are different, however, and should be kept distinct. During training, the data shapes the model’s parameters and is absorbed into general statistical patterns but is not stored in the model as retrievable text. During inference, by contrast, the query is tokenized and processed by the (now-fixed) model to generate a response; tokenization is a reversible numerical encoding and does not, by itself, change the information content of the query, which is present on the provider’s servers during processing and may be retained afterward depending on the provider’s retention policy and the product tier.
Neither the manner in which training data enters a model nor how the query process enters and is interpreted by a model was briefed in the Heppner case – and perhaps it would have mattered. The Working Group does not know if the court there assumed that the information that the defendant entered into Claude as his query was both retained verbatim on a server accessible to third parties and somehow extractable from the trained model itself by another user. Those are distinct technical questions, and they should not be conflated. That briefing was not part of the record, and it was not raised at oral argument. As a matter of technological process, when a user submits a query to a hosted GenAI tool such as Claude, the query is transmitted over an encrypted connection to the provider’s servers and processed there to generate a response. The provider therefore has access to the query during inference, and whether the query is retained after inference (and, if so, for how long) is governed by the provider’s retention policy and the product tier the user has chosen. Anthropic, for example, offers commercial customers a “Zero Data Retention” option under which inputs are processed in real time and immediately discarded, and Anthropic and OpenAI both exclude their enterprise, business, and API products from training by default; consumer-tier users may opt out of training. Retention practices vary across product tiers and may extend further than many users assume; for example, following Anthropic’s August 28, 2025, consumer-terms update, conversations for users who do not opt out of training contributions may be retained for up to five years. And the May 13, 2025, preservation order in In re: OpenAI, Inc., Copyright Infringement Litigation (S.D.N.Y.) illustrates that even when a provider’s standard practices contemplate deletion, those practices can be overridden by a litigation hold as to logs that exist – a point that underscores that the privilege-relevant artifact in many disputes will be the retained chat log, not the trained model.
A distinct and equally important point is that the act of generating a response does not, by itself, modify the model’s parameters. A single inference call leaves the weights unchanged; only periodic retraining runs, conducted separately on data the provider has elected to include, can do that. As the literature discussed below shows, even when a unique user input is incorporated into a retraining run, it contributes a negligible statistical signal to a model with billions of parameters and is unlikely to be memorized in a form that another user could extract or attribute. Perhaps (but the Working Group does not know because this was not briefed), the Heppner court may have assumed that the data input by the defendant into Claude was in fact available to, and even potentially disclosed voluntarily to, a third party or that the information was retained in a manner which the third party would be able to easily retrieve and trace back to the single user who had inputted the query in the first place. It is also possible that the court thought that since the prompt could potentially be in a chat log, the log input and output could be disclosed to third parties. But, again, this conflates the two questions. The trained model itself does not retain a unique user input in a form that another user could easily retrieve and attribute. Whether the provider retains the query in its own logs is a separate question, governed by the Privacy Policies and the product tier the user selected; it is not a function of how an LLM operates.[15] In fact, a unique user input is unlikely to be memorized in a retrievable form in the first place: the statistical signal contributed by any single, low-frequency input is distributed across billions of model parameters and is negligible relative to the broader training corpus. Even where memorization of widely duplicated content occurs, the memorized fragment carries no information indicating which user supplied it, when, or in what context.[16] As a result, the concept of meaningful disclosure through the query process should be discarded as an operative framework.
As Misunderstanding Memorization[17] explains, two findings from the computer science literature on training-stage behavior (a step that precedes the query process, although in-context learning gives rise to some analogous dynamics) are particularly relevant here: the duplication effect[18] and counterfactual memorization.[19] Based upon the duplication effect and counterfactual memorization, Misunderstanding Memorization posits that even if Heppner provided “privileged information to Claude, by definition, that privileged information from a single user would be unique content appearing at most once in any training dataset, and the empirical evidence indicates that such data would have a negligible probability of being memorized in retrievable form.” In other words, according to Misunderstanding Memorization, even if the privileged information were incorporated into training data, it is extremely unlikely that another user could prompt the model to reproduce, retrieve, or reconstruct the information through ordinary use of Claude or any other GenAI platform.[20]
III. THE PRACTICAL REALITIES OF HOW PRIVACY POLICIES LIKE THOSE USED BY ANTHROPIC AND OPENAI WORK
This section explains how Privacy Policies typically operate in practice, and why their structure, application, and enforcement can matter when stakeholders evaluate whether a user maintained, or relinquished, a substantial privacy interest and a reasonable expectation of confidentiality. To assist market participants, policymakers, counsel, and courts, the Working Group reviewed various publicly available Privacy Policies from organizations across industries to identify common drafting patterns and safeguards that organizations describe as part of their privacy and data governance programs.[21] The purpose of this review was to assess whether those safeguards reflect an intent to maintain a substantial privacy interest and a reasonable expectation of confidentiality rather than an intent to broadly disclose, publicly disseminate, or otherwise relinquish control over user data.[22]
In developing this section, the Working Group also considered various legal requirements that affirmatively mandate certain disclosures in Privacy Policies as well as legal obligations that can compel companies to disclose or produce personal data. These include discovery and preservation obligations in civil litigation, subpoenas and court orders, and other forms of legally compelled disclosure such as those from law enforcement agencies. Courts have long recognized that the privilege and work-product analyses turn on practical confidentiality and voluntariness, not on the mere possibility that a provider could be compelled to disclose information through legal process.[23] Consistent with that framework, routine compliance-with-law disclosures should not be read as dispositive. Such disclosures are common across consumer-facing and enterprise service providers and largely reflect an unavoidable reality that companies cannot contract around compulsory legal process.
Relatedly, stakeholders should be cautious about treating a provider’s generalized terms as dispositive of confidentiality or as a basis for concluding that a provider does not have a substantial interest in privacy in a way that would destabilize settled practice with cloud and communications services. McCormack and Klapper observe that the logic of Heppner’s privacy‑policy‑driven confidentiality analysis would not stop with consumer GenAI tools.[24] Major cloud platforms and email providers commonly reserve broad rights to process user content for service delivery and product improvement and to disclose data in response to legal process. Yet ethics authorities have long taken the position that lawyers may use cloud services to store and transmit client information without making a third‑party “disclosure,” provided they take reasonable precautions, and courts assessing confidentiality in technology settings have focused on practical expectations and safeguards rather than concluding that standard terms of service alone defeat confidentiality.[25] However, questions may remain about how instructive the rules applied to services such as these may be in the context of GenAI systems whose very purpose is to engage with the substantive content of user inputs in a way that cloud services or e-mail systems do not. This broader context supports a more calibrated approach: the fact that a provider truthfully describes legal‑process limits and internal processing does not, without more, establish that a user intended to place privileged information outside the privilege circle.
Against that backdrop, the Working Group also urges caution before concluding that language in a standard privacy notice is determinative of confidentiality and waiver in the privilege context.[26] Heppner offered multiple rationales for denying protection, including that the communications at issue were not between client and counsel and that the communications were not confidential given the provider’s disclosed practices regarding collection, training, and potential disclosure of inputs and outputs. The Working Group acknowledges that Heppner was decided on a specific factual record involving unsupervised use of an apparently free consumer tool[27] and an evidentiary dispute in a criminal case, and the decision has value in highlighting that tool selection and data practices can matter. At the same time, the Working Group cautions that privacy-notice-driven reasoning should be applied with care so that it does not effectively convert ubiquitous consumer-facing disclosures into a categorical rule that defeats confidentiality whenever a third-party service provider honestly describes the outer limits of confidentiality.
Two related points are important here. First, waiver doctrine generally focuses on whether the privilege holder purposefully or without appropriate care exposed communications to a third party in a manner inconsistent with maintaining confidentiality, and not whether a provider’s public statements acknowledge contingent, legally constrained scenarios in which disclosure could be compelled.[28] In other words, the question should be practical exposure and access, not abstract possibility. Second, privilege analysis should distinguish internal processing or retention from disclosure to an adversary or to an unrelated third party in a way that materially increases the likelihood an adversary will obtain the information.[29] Courts in Morgan and Warner underscored this distinction expressly by rejecting the idea that using a GenAI tool automatically waives work-product protection absent disclosure to an adversary or in a way likely to reach one. Nonetheless, the rules of waiver of attorney-client privilege tend to be less forgiving than the waiver rules that often are applied to work product disclosures. Moreover, waivers of attorney-client privilege can extend not just to the particular matter disclosed but to the entire subject matter generally of the disclosed communications. Thus, the treatment of work product waiver in the GenAI context may not necessarily extend equally to questions of privilege waiver.
The Working Group emphasizes that users typically consent to terms of service/terms of use (though the forms of that consent may differ, and that difference may have legal significance in certain circumstances), which function as contractual agreements governing access to and use of a service and often contain explicit dispute resolution provisions and bilateral terms. Privacy Policies, by contrast, are generally drafted to satisfy consumer privacy law requirements as unilateral public-facing notices describing a company’s use of personal data, not other data, handling practices and legal obligations rather than as bargained-for contractual commitments to which users provide affirmative consent. Treating disclosures in a Privacy Policy as if they reflected user “consent” to broad data sharing risks would be conflating notice of practices with consent to those practices, and personal data with all data. Additionally, in a privacy context, consent most often legally requires that a user could withdraw that consent at any time, which could be more protective of privacy and confidentiality. That distinction may seem minor, but it can matter in privilege and other confidentiality contexts because a statement that personal data may be disclosed to comply with legal obligations is better understood as an acknowledgment of external legal constraints rather than as evidence that the user intended to relinquish privacy and confidentiality.
This distinction is reinforced by more recent work-product decisions involving public GenAI tools. In Warner v. Gilbarco, the court declined to compel discovery into a pro se litigant’s use of third-party GenAI tools, reasoning that such discovery would improperly reach internal analysis and mental impressions and emphasizing that work-product waiver generally requires disclosure to an adversary or in a way likely to get in an adversary’s hands.[30] The Warner court also treated GenAI tools as “tools, not persons,” rejecting an overbroad waiver theory that would effectively nullify work-product protection in modern drafting environments. Similarly, in Morgan v. V2X, although the court required disclosure of the specific GenAI tool used to process information classified as “confidential,” the court also held that Rule 26(b)(3) can protect AI-assisted litigation materials for a pro se litigant and declined to adopt an automatic-waiver rule based solely on use of a mainstream GenAI platform.[31] These decisions do not resolve the privilege question directly, but they underscore a broader, practical point that the legal system routinely accommodates reliance on third-party technology without treating that reliance as a categorical forfeiture of protection.
The Working Group’s review also identified features of Privacy Policies that, in many contexts, support an inference of intent to preserve confidentiality rather than relinquish it. Perhaps among the most probative evidence on this point is what the Privacy Policies actually do. As discussed below, the Privacy Policies of the major providers expressly carve enterprise, business, and API inputs out of model training by default, offer Zero Data Retention options for commercial customers, permit consumer-tier opt-out, and deploy automated PII filtering. First, and as background, the overwhelming majority of Privacy Policies for major organizations are drafted or reviewed, implemented, administered, and enforced by attorneys, both in-house and outside counsel.[32] Second, those attorneys generally account for applicable US federal and state privacy laws and incorporate technical and organizational safeguards that limit access, reduce traceability, and support confidentiality expectations. For example, during a review of the Privacy Policies of Anthropic (i.e., Claude) and OpenAI (i.e., ChatGPT), the Working Group determined that both Privacy Policies explicitly exclude user data from GenAI model training for their enterprise, business, and API products by default. The training carve-out should not be confused with a categorical no-retention rule: for enterprise and API tiers, inputs and outputs are typically retained for a standard period (for example, seven days on the Anthropic API as of September 14, 2025) unless the customer affirmatively configures Zero Data Retention, which remains an opt-in arrangement.[33] In addition, Anthropic offers a Zero Data Retention option for commercial customers under which inputs are processed in real-time and immediately discarded,[34] and OpenAI excludes data from ChatGPT Enterprise, Business, Edu, Healthcare, and API platform products from AI model training.[35] Moreover, even for consumer products, Anthropic and OpenAI allow users to opt out of having their data used for AI model training[36] and both organizations employ automated tools to detect and filter PII and other sensitive data from AI model training pipelines, and train their models to decline many requests to reproduce PII (although, as the technical literature show, no such safeguard is perfect against determined adversarial extraction).[37] Third, as courts have noted in other confidentiality contexts, a reasonable expectation of confidentiality is a context-specific inquiry that should be grounded in how information is actually transmitted, stored, accessed, and protected in practice.[38] For example, when a user enters text into a mainstream GenAI platform, that input is typically transmitted over an encrypted connection to the provider’s servers, and other users generally cannot access, browse, or search that input.[39] Fourth, to the extent courts are concerned about inadvertent, technical, or collateral disclosure pathways, the Working Group notes that modern evidence rules reflect a policy preference against disproportionate waiver results where reasonable steps to maintain confidentiality were taken.[40] This principle aligns with a more calibrated approach that distinguishes between voluntary disclosure and legally compelled disclosure, and between real-world exposure and theoretical possibilities, when evaluating waiver in the GenAI context.
IV. THIRD-PARTY DOCTRINE: GENAI, PRIVACY, AND POTENTIAL EROSION
Counsel and courts are now confronted with applying legacy statutory and common law to rapidly evolving tools that defy easy analogies to more familiar technologies, which can create inconsistent results. GenAI can perform so many different functions that comparative shortcuts may mislead more than inform (e.g., storage as a “filing cabinet,” “communications as mail.”) But, in the absence of legislation or rulemaking, reasoning by analogy remains unavoidable. Trial courts have begun to address the application of attorney-client and work-product privileges to interactions with GenAI, specifically LLMs that include such tools as ChatGPT and Claude. One emerging issue is whether a disclosure of information to a GenAI tool should be analogized to other privilege-defeating disclosures to third parties. If courts understand GenAI as a proxy for a human third party, then finding that privilege has been waived is logical. If courts analogize GenAI to a piece of software, such as a spreadsheet or word processor, then finding a waiver seems equally illogical. The Working Group is not suggesting that confidentiality waiver under the attorney-client privilege and work product doctrine collapses with the third-party doctrine. Rather, the Working Group is emphasizing that the progression of the third-party doctrine serves as a parallel to show that courts recognize that expectations of confidentiality have changed. Thus, the Fourth Amendment case law is a floor that privilege waiver would never drop below and should, instead, stay meaningfully above.
Third-Party Analysis – Framing the Tools
Three recent court decisions demonstrate two different approaches to the third-party doctrine, and how the understanding of GenAI as a substitute-human, as opposed to a tool, drives different conclusions regarding waiver.
A. United States v. Heppner (S.D.N.Y. 2026): AI as Substitute-Human
In Heppner, the court addressed what it described as a question of first impression nationwide: whether communications with a publicly available GenAI platform, made in connection with a pending criminal investigation by a defendant who was represented by counsel, are protected by attorney-client privilege or the work-product doctrine.[41] On the facts before the court, limited briefing and a relatively short oral argument, Judge Rakoff’s answer was no. But cases are decided based upon their facts – and the facts presented to the court in that case are instructive. Heppner, a financial services executive charged with securities and wire fraud, received a grand jury subpoena and retained counsel. Without instruction from counsel, Heppner used what was apparently the publicly available version of Claude app (that is, not an “enterprise” version of the LLM that might have been subject to different and more restrictive privacy protections), to prepare material outlining potential defense strategies and legal arguments. The court characterized this usage as “communicat[ion] with” the AI model. Heppner subsequently shared those materials with his attorneys. Though this is not in the record, the Working Group assumes that the materials outputted from Claude were not “facts” that Heppner was providing to counsel as he sought “reports” “for the purpose of speaking with counsel to obtain legal advice,”[42] but rather statements (the Working Group hesitates to call them “mental impressions”) from Claude. The FBI later seized the documents as authorized by a search warrant.
The court held that neither the attorney-client privilege nor the work product doctrine applied to Heppner’s “communications” to Claude or Claude’s responses. In doing so, the court analogized Claude to a substitute human, analyzing the sharing of information with Claude as it would analyze communications with a person. “In the absence of an attorney-client relationship, the discussion of legal issues between two non-attorneys is not protected by attorney-client privilege’ . . . Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege.”[43] This analysis assumes without further explanation that inputting information into Claude constitutes “discussion” with a “non-attorney.” But, in fact, other ways of viewing the conduct are that Heppner was conferring with himself through a query he had entered into a tool or that Heppner was using Claude as an intermediate step in order to then discuss his defense with counsel. Recent commentary by McCormack and Klapper has argued that Heppner effectively “anthropomorphizes” the AI model by treating the GenAI system as an interlocutor and then asking whether the GenAI interaction itself satisfies the elements of attorney‑client privilege. On that framing, the answer predictably becomes “no” because the model is not an attorney and does not owe fiduciary duties.[44] The more conventional privilege analysis begins one step earlier by asking whether the underlying information is privileged or work product in the first place and then asking whether the user’s interaction with the technology waived those protections. Put differently, the question is not whether a GenAI system can itself be a privileged counterparty, but whether using a computational tool to process privileged material is meaningfully different from using other common software and infrastructure (such as a lawyer’s use of free email service to communicate with counsel) that lawyers and clients have long used without effecting waiver.
Based upon its reading of the Claude Privacy Policy, the court also found that the communication was not intended to be confidential and resulted in a waiver. The Privacy Policy, part of the LLM’s terms of service, advises users that Anthropic collects prompts and outputs, may use them for GenAI model training, and may disclose them to third parties, including government authorities. As the court found, this meant that Heppner had no “substantial privacy interest[]” in his use of a publicly accessible GenAI platform, and therefore that Heppner had no “reasonable expectation of confidentiality in his interactions based on uses for which Claude announced it may use that information.[45] In the court’s framing, Heppner had shared information with an entity operating under Privacy Policies expressly inconsistent with confidentiality, just as if Heppner had shared it with an unprotected human third party.[46] Critically, the Heppner court left open certain questions that will shape future litigation. Notably, the court wrote: “[h]ad counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.”[47] Also left open was whether the same conclusion would follow if the defendant had used a paid GenAI platform with different Privacy Policies, or one that did not train on user data or make other potentially public use of it – particularly because Judge Rakoff emphasized the “publicly accessible” nature of the GenAI tool at issue and its specific Privacy Policies permitting it to disclose personal data to third parties. Although Heppner arose in the criminal context, its logic extends to civil privilege analysis. If GenAI tools are substitute-humans and not licensed attorneys, then civil privilege would not apply either where communications to them are sufficiently disclosed such that no expectation of privacy exists, and a disclosure-based waiver follows.
B. Warner v. Gilbarco, Inc. and Morgan v. V2X, Inc.: AI as Tool
On the same day as the Heppner bench ruling (the court provided a written ruling a week later), in Warner v. Gilbarco, Inc., Magistrate Judge Patti reached the opposite conclusion. There the court held that a pro se civil plaintiff’s use of ChatGPT to draft litigation materials was in fact protected work product. The court squarely rejected the argument that disclosure to a GenAI platform constituted disclosure to a third party. “ChatGPT (and other AI programs) are tools, not persons, even if they may have administrators somewhere in the background.”[48] As the court observed, adopting the defendants’ theory “would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed.”[49] The Warner court distinguished attorney-client privilege waiver, which can flow from any disclosure to a third-party, and work-product waiver. Under Sixth Circuit precedent, the latter requires disclosure to an adversary or in a manner likely to reach an adversary’s hands.[50] Because a GenAI platform is not an adversary, nor the use of such a tool reasonably likely to result in an adversary acquiring protected information, the court concluded that no waiver occurred. The court further analogized the plaintiff’s use of ChatGPT to her “internal analysis and mental impressions – i.e., her thought process.”[51]
In yet a third case on this topic, on March 30, 2026, Magistrate Judge Braswell extended Warner’s reasoning in Morgan v. V2X, Inc. She described the problem as “AI…forcing litigants and courts to confront difficult questions about how and to what extent longstanding protections will apply when parties use AI to assist them in the litigation process.”[52] Judge Braswell held that Rule 26(b)(3)’s protection of “documents and tangible things . . . prepared in anticipation of litigation . . . by another party or its representative” encompasses a pro se litigant’s AI-assisted work product. The Morgan court also tackled the waiver question with direct reference to the Fourth Amendment’s third-party doctrine jurisprudence, analogizing to the principle that “routing information through a third-party system does not forfeit all privacy.” Responding to the defendant’s argument that disclosure to a commercial GenAI platform destroys confidentiality, Judge Braswell posed the question that frames the entire analysis: “Today, nearly all electronic interaction passes through third-party systems. Google, for example, hosts millions of accounts, and by extension, has access to millions of messages, emails, documents, videos, and more. Does that mean that anyone with a Gmail account has forfeited all rights to confidentiality and privacy?”[53] Her answer was clearly “No.” Drawing on Carpenter v. United States[54] and United States v. Warshak,[55] the court concluded that routing data through a third-party system does not, by itself, extinguish privacy expectations.
The Morgan court did find it necessary to amend the protective order to restrict the inputting of “confidential” information into any AI platform that lacked certain contractual prohibitions on training and disclosing inputs and outputs commonly present in enterprise-grade GenAI services (and commonly absent in consumer-grade equivalents). In that respect, the Morgan court seems to acknowledge the point made in Heppner: that Privacy Policies may indeed “compromise confidentiality.” Nevertheless, Magistrate Judge Braswell further opined that the case for privacy is “arguably stronger in the context of modern AI,” because AI tools are “specifically designed and trained to engage,” in contrast with search engines which “passively return[] results.”
C. The Analytical Divergence and Its Implications
Heppner, Warner, and Morgan were all decided within a few weeks of one another; yet they reach starkly different conclusions. The key to that divergence is not the quality of reasoning, but the facts, the framing adopted at the outset, and the briefing of the issues. As always, the facts matter. Where Heppner treated the GenAI platform as an entity capable of receiving disclosures (analogous to a person), Warner and Morgan treated it as a tool (analogous to a word processor or cloud-based email and file services). That framing, in turn, determined how waiver jurisprudence applied; the assumptions each court made about the technology were perhaps more dispositive than the idiosyncratic facts of the cases.
There are factual distinctions that merit attention.[56] However, the criminal/civil context may not be dispositive. The work-product rule in the Federal Rules of Criminal Procedure uses similar language that would extend privilege to a party, not just the party’s attorney.[57] The Second Circuit has held that Rule 16 applies even to grand jury subpoenas.[58] It remains to be seen whether the ultimate pro se nature of a litigant (which Heppner, unlike Warner and Morgan, was not) controls and whether the analysis would be extended to a pre-representation client.[59] In the criminal context, the court grounded work-product protection on “the mental processes of the attorney,” a formulation that logically excludes a defendant acting without counsel’s direction. The emerging consensus, to the extent one can be identified, is that the technology is new, but the doctrine is not.[60] Courts will apply privilege and waiver principles as they find them. Outcomes thus may be highly dependent on litigants’ ability to describe how the technology operates in support of their position, given the facts of their cases and the caselaw of their jurisdiction.
The Third-Party Doctrine and Fourth Amendment Expectations of Privacy
Over the past several decades and apart from the case law over waiver of confidentiality in the privilege context, courts have developed ever more nuanced views of the Fourth Amendment’s “reasonable expectations of privacy standard” when information is disclosed to third parties. Advances in consumer technology have stretched the doctrine. These decisions have often treated the sharing of information through a “tool” framing, over time, and less and less as the equivalent of sharing information with another human actor. That analysis, although born in a different context, can help inform how the analysis of GenAI systems and privilege develops.
A. The Traditional Third-Party Doctrine and Its Origins
The traditional third-party doctrine, forged in the 1970s, held that a person has no reasonable expectation of privacy in information voluntarily turned over to third parties. In United States v. Miller,[61] the Supreme Court held that bank customers have no Fourth Amendment protection in their financial records because they voluntarily conveyed that information to their banks. In Smith v. Maryland,[62] the Supreme Court extended this logic to telephone numbers dialed from a subscriber’s phone: because the subscriber “knowingly conveys” those numbers to the phone company as a necessary incident of placing calls, no constitutional protection attaches. These decisions, illustrative of the state of the law through the turn of the century, were grounded in a pre-digital world in which the categories of information voluntarily shared with third parties were relatively limited and discrete (e.g., a bank account, a telephone bill, or invoice records). As digital technology transformed commerce and communication, however, the logical endpoint of the doctrine became increasingly untenable. By the early years of this century, it implied that virtually all sensitive personal information, including emails stored with providers, location data logged by carriers, purchase histories aggregated by retailers, health information transmitted to insurers, and search histories, potentially fell outside Fourth Amendment protection simply because it passed through a corporate intermediary. Consumers had no choice; they could accept the sharing of this information or forego large parts of modern life. This approach created tension with the core of the Fourth Amendment – a person’s reasonable expectations of privacy – as the modern information economy changed the fundamental nature of those expectations.
B. The Erosion of Broad Third-Party Doctrine: Key Cases
Courts did not continue to force new digital square pegs into old round holes. Over the course of the 21st century, they have adapted the law to fit with changing reasonable expectations.
Email. In United States v. Warshak,[63] the Sixth Circuit became the first federal appellate court to hold that email subscribers have a reasonable expectation of privacy in the contents of emails stored with commercial internet service providers, and that a warrant supported by probable cause is required to compel their production. The court rejected the government’s reliance on the Stored Communications Act (SCA) lower “specific and articulable facts” standard, reasoning that “the Fourth Amendment must keep pace with the inexorable march of technological progress, or its guarantees will wither and perish.”[64] The mere fact that a service provider has access to stored email content, and that terms of service allow the provider to make commercial use of that content, does not eliminate all aspects of a user’s reasonable privacy interest, even when that user agrees to such terms.[65]
Historical Cell Phone Location Data. In Carpenter v. United States,[66] the Supreme Court further limited the third-party doctrine’s application to a new byproduct of the mobile communications era. The Court held (over multiple dissents) that the government must obtain a warrant to access historical cell-site location information (CSLI) from wireless carriers, even though users necessarily “share” that information voluntarily with carriers by agreeing to the terms of use of cellular service. Chief Justice Roberts explained that there is “a world of difference between the limited types of personal information addressed in Smith and Miller and the exhaustive chronicle of location information casually collected by wireless carriers today.”[67] Critical to the Court’s reasoning was that CSLI is not truly “shared” in any meaningful sense: cell phones are “such a pervasive and insistent part of daily life” that carrying one is indispensable to participation in modern society, and the phone logs location data continuously without any affirmative act by the user.[68] Carpenter did not overrule the third-party doctrine; its holding was explicitly limited to the CSLI context. But its reasoning has broader application. Rather than applying the third-party doctrine mechanically, the Carpenter majority required courts to examine: (1) the nature and comprehensiveness of the information at issue; (2) whether exposure was truly voluntary or was instead compelled by the realities of modern life; and (3) whether applying the doctrine would give the government a surveillance capability that the Founders could not have imagined. Those factors, rather than the formal structure of who “holds” data, now drive the analysis.
Geofence Warrants/Aggregated Location Data. The third-party doctrine’s application to aggregated, advertiser-collected location data is the subject of Chatrie v. United States, No. 25-112, presently before the Supreme Court.[69] The case arises from a “geofence warrant,” the colloquial term for a court order directing Google to search its entire “Location History” database, a collection of data from users’ devices which identifies all devices present within a defined geographic area during a specified time window. The Fourth Circuit, sitting en banc, declined to suppress evidence obtained via such a warrant, finding that a defendant who affirmatively opted into Google’s “Location History” service (which provides users of Google products the ability to search places they have previously visited) thereby voluntarily exposed his location to Google.[70] The Fifth Circuit reached the opposite conclusion in United States v. Smith,[71] holding that geofence warrants are “modern-day general warrants” categorically unconstitutional under the Fourth Amendment. The Supreme Court’s resolution of this circuit split will significantly affect the scope of third-party doctrine going forward and will provide guidance directly applicable to the GenAI context. Whether the Court chooses to view the act of sharing as a voluntary transmission to a human or as the necessary incident of the operation of a tool is likely to predict the outcome.
C. Further Examples: Social Media, Cloud Storage, and the Pattern of Narrowing Application
Beyond email and location data, courts have consistently held that the mere fact of third-party data storage does not extinguish privacy protections in a user’s content.[72] This principle has been applied across multiple technological contexts:
Social Media Content. Courts have generally held that the content of non-public social media content and communications, such as private messages, direct communications, and unpublished posts, are entitled to Fourth Amendment protection requiring a warrant, while publicly posted content is not.[73] The key distinction tracks the user’s own reasonable expectation: content shared with the world is not private; content shared within a limited social network or through private messaging channels, in contrast, carries a privacy interest analogous to the email content protected in Warshak, even though Facebook users agree to terms that allow the company to access their content.
Cloud Storage. Courts have extended certain protection to documents stored in personal cloud accounts. The government cannot compel cloud service providers to produce the contents of a user’s stored documents without a warrant, notwithstanding the provider’s technical access to those contents.[74] That the user has agreed to a service provider’s terms, which may reserve broad rights to access and analyze stored content, does not eliminate the constitutional protection and extinguish all expectations of privacy as to all potential interlocutors.
What cases addressing these modern categories of technology share is a focus not on the mechanics of where information flows, but on the reasonable expectations of the user and the recognition that some amount of information sharing is simply a reality of modern life. As Judge Braswell articulated in Morgan: “given how GenAI tools function, it is entirely reasonable for a person to expect some privacy and confidentiality when interacting with these tools, even though they understand a third party is behind the tool collecting and storing their information.”[75]
Application to GenAI
A. The Analogical Question
The Heppner, Warner, and Morgan decisions leave unresolved whether GenAI interactions should receive the same privacy protections that courts have extended to analogous digital technologies. What the progression of Fourth Amendment jurisprudence makes clear, however, is that the answer should not turn on a single factor, such as whether the service provider has access. That factor, applied mechanically, would eliminate nearly all digital privacy and fails to account for changes to what constitutes a “reasonable” expectation of privacy as technology itself evolves and adapts and becomes integrated into society. The framework derived from Carpenter over the years since 2018 examines the comprehensive nature of what is revealed, the degree to which the sharing is truly voluntary, and the surveillance capacity that would be granted if privacy were denied. Applied to GenAI interactions, this framework suggests that a person who uses a GenAI tool in connection with legal strategy, medical decision-making, or other highly sensitive personal matters may have a reasonable expectation that those interactions are not freely accessible to the government or adversaries in civil litigation. The mere fact that a commercial actor reserves rights to use that data does not end the analysis.
B. Enterprise vs. Consumer GenAI
The decisions to date have largely involved consumer-grade GenAI tools – public versions of Claude and ChatGPT whose terms of service expressly reserve rights to retain, train on, and disclose user data. The Heppner court made much of these terms, treating them as equivalent to a contractual waiver of confidentiality. Consumer products offered by Anthropic, OpenAI, and similar companies at the subscription tier typically do not offer the same data segregation and non-training guarantees available under enterprise agreements. Enterprise-tier (or other paid products) agreements can offer contractual prohibitions on using customer data for GenAI model training, promise not to retain user data, and establish audit rights. If the Heppner court’s analysis holds, then users of enterprise tools with robust confidentiality protections would stand in a materially different position. No court has yet resolved this question, but both the Heppner opinion itself and the Morgan protective order framework (which restricts the inputting of “confidential” information into AI tools that lack contractual guardrails on the use of that information) point in this direction.
Relatedly, these cases raise an unsettled question about the legal significance of “consent” to GenAI providers’ consumer terms. Some courts may treat acceptance of click-through terms as strong evidence that a user assumed the risk of provider retention or disclosure; others may ask whether the consent was meaningfully informed and voluntary in context, including whether the user had realistic alternatives, the user’s sophistication (e.g., consumer, pro se litigant, represented party), and whether the use of the tool was intertwined with participation in ordinary professional or civic life. Framing the issue in this way aligns the waiver inquiry with the broader judicial trend in digital-privacy cases to look beyond formal “acceptance” and evaluate what expectations are reasonable under modern conditions.
These unresolved issues have immediate practical implications for law firms, corporate legal departments, and other attorneys. For instance, the City Bar in Ethics Opinion 2024-5, emphasized that lawyers must understand the data-retention and disclosure practices of any GenAI tool used in connection with client matters and must advise clients of the risks of independent GenAI use if the lawyers expect to use systems that will share a client’s confidential information with third parties.[76] The issue also has important implications for access to justice. As Morgan noted, GenAI tools have made the task of representing oneself – initially or through the entirety of a proceeding – more feasible for the pro se litigant. To protect the use of commercial products available to well-resourced law firms while stripping pro se and other less-represented users of privacy protections threatens the access-to-justice promise of GenAI.
C. The Trajectory of Developing Law
The arc of Fourth Amendment jurisprudence around third-party data offers a predictive template for GenAI. Courts initially confronted with early internet technologies frequently found broad third-party doctrine waivers in email contents, cell phone location data, and cloud-stored documents. Over time, as courts better understood the technologies and their ever-expanding role in daily life, protections expanded. Warshak and Carpenter reflect the court’s growing skepticism of mechanical application of the Third Party Doctrine to digital communications; Carpenter’s reasoning has been extended to new surveillance technologies in cases like Chatrie. It seems unlikely, as the law develops and counsel and courts better understand GenAI, that interactions with these tools will receive categorically less protection than email or social media. If anything, the highly personal and often intimate nature of what users share with GenAI assistants – use cases like legal strategy, medical questions, financial anxieties, personal relationships, and the like – suggests that protections should be robust. As GenAI tools become more integrated into daily life and more essential to participation in modern commerce and society, the “voluntary” nature of sharing information with them will come to be viewed as analogous to the “voluntary” sharing of CSLI analyzed in Carpenter – one compelled by modern life, not a genuine choice.
D. The Rise of Agentic AI
One emerging implementation of AI are so-called “agentic AI” tools, which at least one court has described as a “software agent . . . operating automatically and without direct human oversight.”[77] Given the growing rise in both agentic AI’s adoption, and the possibility that it may “go rogue” and execute functions which the user did not expressly desire (such as the deletion of a company’s software database[78]), courts and litigants adopting the “AI as human substitute” analytical framework may be tempted to point to such technology as further support for such a paradigm. Nevertheless, agentic AI (in its current form) is still, at its core, software that – if not sufficiently understood – can be utilized in manners which create harmful or undesirable outcomes. And software, in turn, is inherently a tool that human users must employ, direct, and guide to achieve desired outcomes. Whether that software is simple (such as translating keystrokes on a keyboard into letters in a text document) or complex (such as translating user queries into automated execution of other software tasks), the inherent nature of that software – the fact that it is a tool, not an independent thinking human mind – remains the same, and parties can and should continue to point to comparable tool analogies if and when privilege questions begin to intersect with agentic AI use. That the tool framing applies, however, does not resolve every disclosure question raised by agentic deployments. An agent connected to email, calendar, document repositories, or external services may, in the course of executing a user’s instructions, route privileged information to actual third parties – a real-world disclosure that is distinct from the person/tool framing question and that should be analyzed separately under ordinary waiver principles.[79]
V. PRACTICAL GUIDANCE FOR COUNSEL AND COURTS
The Working Group analysis suggests several considerations that may be useful to market participants, policymakers, counsel, and courts addressing privilege disputes involving GenAI tools. At least in the near term, parties may continue to face arguments grounded in the reasoning reflected in Heppner. While the Working Group believes that broader privilege protections are doctrinally sound, stakeholders should recognize that similar reasoning may still be applied as courts grapple with these issues in early cases. As more and more courts understand the principles embodied in this analysis, this may become less of a concern. But, in the current environment, parties may be well served by developing clear factual records and targeted briefing on several recurring issues:
First, the framing question is dispositive and contested. Courts have split on whether GenAI is a tool or a substitute-human for third-party disclosure purposes. Counsel asserting privilege should affirmatively argue for the tool framing, supported by the Warner and Morgan decisions, the technical reality of how LLMs process information, and Misunderstanding Memorization. The framing adopted by the court will largely determine whether any further analysis is required. Even as agentic AI becomes more commonplace, and the temptation to analogize AI tools to persons grows, parties applying the law would do well to recognize that agentic AI remains mere computer code that executes user requests. While agentic AI’s methodology is more complex than entering text into a word-processing application, software’s ability to imitate more complex interactions and functions does not transform the tool into something more.
Second, market participants, policymakers, counsel, and courts may benefit from a clear description of the role the GenAI system plays in the communications at issue. Privilege law has long distinguished between the involvement of a necessary intermediary or agent and the involvement of an independent third party whose participation defeats confidentiality. In the Second Circuit, United States v. Kovel is often cited for the proposition that communications may remain privileged when a third party’s involvement is reasonably necessary to facilitate legal advice and is subject to counsel’s direction and supervision.[80] Where a litigant contends that a GenAI system functioned as an extension of counsel’s work, rather than as an audience for the communication itself, briefing that explains the tool’s configuration, contractual protections, and any supervision exercised by counsel can help sharpen that distinction.
Third, parties may benefit from articulating waiver in functional terms tied to the reasons third‑party waiver doctrine exists. The classic third‑party waiver rule is designed around the risks created when confidential information is placed in the hands of a person with independent agency and legal standing, including the possibility of testimony, volitional disclosure, or compelled production from that recipient. Briefing that focuses the court on whether the GenAI interaction actually created those risks, as opposed to relying on abstract characterizations of “sharing,” can help the court separate internal computational processing from disclosure in the privilege‑relevant sense. This functional framing can also be deployed in a tool‑neutral way as GenAI capabilities are integrated into ordinary office and cloud software.
Fourth, the nature of the platform and the applicable contractual terms matter, and they may compel different arguments. Consumer-grade GenAI tools with broad data collection and training terms raise issues that paid or enterprise products may not. Even for enterprise products, contractual terms may be critical to confidentiality protections. Counsel for parties using GenAI tools, and counsel who themselves use GenAI products as a part of their legal representation should obtain and present the specific Privacy Policies and related contractual terms applicable to the tool actually used (at the time it was used), and should explain why those terms are, or are not, relevant to the confidentiality and waiver inquiry. Where a waiver theory is framed in terms of “consent” via privacy notices or terms of service, focused briefing may help the court determine whether that consent was meaningfully informed and voluntary or instead resembles the constrained consent analysis courts have confronted in other modern third‑party settings.
Fifth, the Fourth Amendment body of law is robust and longstanding. Counsel should deploy it when appropriate. Drawing the court’s attention to decisions such as Warshak and Carpenter and the examples of the application that followed, with an explanation of how the trajectory of that doctrine applies to GenAI, ensures that twenty-five years of developed analysis of data sharing and privacy informs the ultimate ruling. The Morgan decision has made this connection explicit, and it provides a compelling framework to follow.
Sixth, counsel should consider seeking protective orders for discovery provided to adversaries who may input sensitive information into public tools. The Morgan court’s protective order provides a useful checklist: no training on inputs; no third-party disclosure beyond service delivery; and a right to delete confidential information upon request. Such measures can reduce uncertainty and prevent downstream disputes. In some disputes, the parties may mutually desire to affirmatively stipulate that certain GenAI tool uses do not constitute a waiver of attorney-client or work product privilege.
Seventh, counsel should advise clients proactively and in writing. The Heppner decision is a cautionary tale about clients using GenAI tools independently, without counsel direction, in ways that can expose privileged communications. Engagement letters and client onboarding should address GenAI use explicitly, and clients should be advised that consumer GenAI tools are not a substitute for attorney-client communications. Client guidance should also caution against using the “share” or “export” features now common in consumer GenAI tools for any conversation touching privileged matter: such features can create publicly accessible URLs whose downstream copies in third-party archives (such as the Internet Archive’s Wayback Machine) may persist even after the provider restricts indexing.
Presidential Task Force on Artificial Intelligence and Digital Technologies
Lorraine McGowen, Co-Chair
Tiffany Smith, Co-Chair
Jerome Walker, Co-Chair
Footnotes
[1] GenAI is a type of AI that creates new content such as text, images, code, audio, or video based upon patterns learned from existing data. Moreover, GenAI can be multimodal, which means a model can take in one type of data (e.g., text) and output a different type of data (e.g., audio). A GenAI model is the underlying system that generates outputs (e.g., ChatGPT 5.5), while a GenAI tool is an application or workflow built on top of one or more models to help people accomplish tasks (e.g., ChatGPT).
[2] See Monitoring AI Adoption in the US Economy (April 3, 2026) available at https://www.federalreserve.gov/econres/notes/feds-notes/monitoring-ai-adoption-in-the-u-s-economy-20260403.html. (All websites last accessed June 9, 2026)
[3] See Orrick U.S. AI Law Tracker – All States available at https://ai-law-center.orrick.com/us-ai-law-tracker-see-all-states/. See also National Conference of State Legislatures Artificial Intelligence 2025 Legislation (Updated July 10, 2025) available at https://www.ncsl.org/technology-and-communication/artificial-intelligence-2025-legislation; 18 U.S.C. 175 – Prohibitions with respect to biological weapons (The prohibitions related to biological weapons would apply to AI generated proteins); NIH, Artificial Intelligence in Research: Policy Considerations and Guidance https://osp.od.nih.gov/policies/artificial-intelligence/ (The NIH has various policies and initiatives. The Guidance covers biosafety and security and oversight of “dual use research of concern.”). The NIH has a current Biosecurity Modernization Initiative to improve protections and ensure oversight and adherence to the 2024 NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules, https://osp.od.nih.gov/wp-content/uploads/NIH_Guidelines.htm. If it passes, the US Biosecure Act would amend the National Defense Authorization Act. It would prevent federal procurement and grants to biotechnology firms with ties to foreign adversaries and restrict certain biological data from being shared with foreign adversaries. It passed the House in 2024 and the Senate in October 2025, https://www.congress.gov/bill/118th-congress/house-bill/8333/text.
[4] There have been bills introduced in Congress, but no such bill has passed. On March 18, 2026, U.S. Senator Marsha Blackburn (R-Tenn.) released a discussion draft of the TRUMP AMERICA AI Act, a broad legislative framework to codify President Trump’s national AI framework executive order into law. See Press Release Financial Services, Energy & Commerce Committees Partner to Strengthen American Data Privacy (April 22, 2026) available at https://financialservices.house.gov/news/documentsingle.aspx?DocumentID=411100 (The House Financial Services Committee and the House Energy and Commerce Committee announced a joint effort to advance two landmark data privacy bills, the GUARD Financial Data Act and the SECURE Data Act, to provide Americans more control over their personal data, create a uniform national framework to promote competition, and improve consumer choice by increasing access to financial products and services for all Americans).
[5] One of the main reasons for the existence of confusion is that there are numerous practical differences between traditional tools that were available to market participants and stakeholders, and the new tools created or enhanced by new and emerging technologies.
[6] In United States v. Heppner, No. 1:25-cr-00503-JSR (S.D.N.Y. Feb. 10, 2026), Southern District of New York Judge Jed Rakoff held that documents generated by the defendant Bradley Heppner, who was represented by counsel, using the consumer version of Anthropic’s Claude were not protected by privilege, reasoning in part that the AI platform’s privacy policy, which permits data collection and potential third-party disclosure, destroyed any reasonable expectation of confidentiality. In this criminal case, Judge Rakoff ruled from the bench on February 10, 2026, and issued a written memorandum on February 17, 2026, finding the documents unprotected on three grounds: (1) Claude is not a licensed attorney and cannot form an attorney-client relationship; (2) No confidentiality existed because Claude’s privacy policy permits data collection and potential third-party disclosure, destroying any “reasonable expectation of confidentiality;” and (3) The documents were not work product because Heppner prepared them on his own initiative, not “at the behest of counsel.” In Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026), Magistrate Judge Anthony P. Patti reached the opposite result, holding that ChatGPT-generated materials were protected under the work-product doctrine because AI tools are “tools, not persons,” and disclosure to them does not constitute disclosure to an adversary. Sohyon Warner, a pro se plaintiff in an employment dispute, used ChatGPT in connection with her litigation. Defendants moved to compel production of all documents related to her AI tool use. In Archie Morgan v. V2X, Inc., Civil Action No. 25–cv–01991–SKC–MDB (D. Colorado March 30, 2026), Magistrate Judge Maritza Dominguez Braswell ordered the plaintiff to disclose the name of any AI platform used to process information the defendant had designated “confidential” under a protective order, and also amended the protective order to prohibit the inputting of confidential information into “any mainstream AI tool.” Archie Morgan, a pro se plaintiff in an employment dispute action, used an unidentified GenAI platform to process discovery received from the defendant. Although the court reasoned that Federal Rule of Civil Procedure 26(b)(3) offers “some” level of work product protection for the use of GenAI, Magistrate Judge Braswell ultimately concluded that the uploading of “confidential” data to mainstream AI tools that “persistently collect and store data” and lack “contractual safeguards” may in turn compromise confidentiality.
[7] Terms of service and terms of use are not the same as privacy policies. Terms of service and terms of use are legal agreements between the parties that govern a wide range of issues related to how the product or service works and may be used. While a privacy policy is often incorporated into the terms of service and terms of use, a privacy policy is also a standalone document that is governed by both US federal and state laws, and potentially by international laws as well, such as the European Union’s General Data Protection Regulation. Privacy policies are now significant components of many organizations’ compliance programs and include risk and operations considerations and corresponding obligations for personnel. Privacy is also a critical component of most organizations’ cybersecurity and data protection programs. In traditional finance and in new and developing technologies such as AI, privacy is one of the major areas of concern.
[8] The Task Force is composed of approximately 260 representatives of more than 50 committees, councils, and other task forces of the City Bar and adjunct members, including lawyers, academics, computer scientists, trade association representatives, consultants, technologists, roboticists, neurotechnologists, ethicists, and others. Virtually every City Bar practice area is represented on the Task Force. The primary mission of the Task Force is to create a Center of Excellence and Thought Leadership in artificial intelligence and digital technologies, including innovative technologies that create new or enhanced products and services, digital assets, and more efficient, convenient, and effective ways of doing business. For more information on the Task Force, please visit the Task Force Overview Page at https://www.nycbar.org/committees/task-force-on-digital-technologies/ and the Task Force Leadership Page at https://www.nycbar.org/wp-content/uploads/2026/02/PTFAIDT-Leadership-260219.pdf.
[9] The members of the Working Group include (1) Clark Abrams, Task Force Subcommittee on Artificial Intelligence and National Security Co-Chair and Chief, Money Laundering and Financial Investigations Unit Special Narcotics Prosecutor for the City of New York; (2) Irene Byhovsky, Task Force Subcommittee on Privacy Co-Chair and Legislative Counsel at the New York City Council; (3) Elizabeth Diatz, Task Force Subcommittee on Artificial Intelligence and Civil Liberties Co-Chair and Assistant Commissioner of Police, Suffolk County Police Department; (4) The Honorable Judge Abena Darkeh, Task Force Subcommittee on the Use of Artificial Intelligence in the Judiciary Member and Criminal Court Judge of the City of New York; (5) Henk van Ess, Task Force Subcommittee on the Impact of Artificial Intelligence on Content Creators, Distributors, Users and Consumers and Founder, Digital Digging; (6) Azish Filabi, Task Force Subcommittee on Artificial Intelligence in Commerce and Finance Co-Chair and Executive Director, American College Cary M. Maguire Center for Ethics in Financial Services; (7) Katherine Forrest, Task Force Subcommittee on Artificial Intelligence and Access to Justice Member, former US District Court Judge, Southern District of New York, and Partner at Paul, Weiss; (8) Bryan Gividen, Task Force Subcommittee on Artificial Intelligence in Commerce and Finance Member and Vice President, Assistant General Counsel at JPMorgan Chase Legal Department; (9) Paul Grimm, Task Force Subcommittee on the Use of Artificial Intelligence in the Judiciary, Professor at Duke University School of Law, and former US District Court Judge, District Court for the District of Maryland; (10) Alona Katz, Task Force Subcommittee on Digital Technologies Issues for Law Enforcement and Regulatory Agencies Member and Chief of the Virtual Currency Unit at the Brooklyn District Attorney’s Office; (11) David Keyko, Task Force Subcommittee on Artificial Intelligence and Legal Ethics Co-Chair and Partner at Pillsbury Winthrop Shaw Pittman LLP; (12) Ruby Lang, Task Force Subcommittee on Privacy Member and Privacy and AI Counsel at Superhuman; (13) Robert Mahari, Task Force Subcommittee on Generative Artificial Intelligence and the Law Co-Chair, CEO and Founder, Akiva AI, and former Associate Director CODEX, Stanford University Center for Legal Informatics; (14) Amreeta Mathai, Task Force Subcommittee on Artificial Intelligence and Civil Liberties Co-Chair and Director of Strategy and Integrated Programs at the New York Civil Liberties Union; (15) The Honorable Xavier Rodriguez, Task Force Subcommittee on the Use of Artificial Intelligence in the Judiciary Member and US District Court Judge, Western District of Texas; (16) Robert Schwinger, Task Force Subcommittee on Distributed Ledger Technology and Blockchain Co-Chair and Partner at Norton Rose Fulbright US LLP; (17) Alexander Southwell, Task Force Subcommittee on Privacy Co-Chair and Partner at McDermott Will & Schulte; (18) Nichole Sterling, Task Force Subcommittee on the International Regulation of Artificial Intelligence Member and Partner at BakerHostetler; (19) Jerome Walker, Task Force Co-Chair and Partner at Jerome Walker PLLC; and (20) Andrew Warshawer, Task Force Subcommittee on Artificial Intelligence and Civil Liberties Co-Chair, former Deputy Chief of the Trial Division, Counsel for Emerging Technologies at the New York County District Attorney’s Office and Trial Attorney for the Beasly Firm LLC. The analysis by the Working Group was reviewed and approved by the Task Force Subcommittee on Publications and the Task Force members. The primary mission of the Subcommittee on Publications is to serve as a peer review for Task Force writings, especially articles, blogs, reports, statements and other writings. Subcommittee on Publications members include (1) Angelena Bradfield, Head of Policy at Financial Technology Association;(2) Rama G. Elluru, Senior Advisor for AI and Intellectual Property at the Special Competitive Studies Project; (3) Robert Mahari; (4) Lorraine McGowen, Partner at Orrick, Herrington & Sutcliffe LLP and Task Force Co-Chair; (5) Robert Schwinger; (6) Edwin Smith, Massachusetts Uniform Law Commissioner and Senior Consultant at Morgan Lewis; (7) Tiffany Smith, Partner at WilmerHale and Task Force Co-Chair; and (8) Jerome Walker. For more information on the Task Force, please visit the Task Force Overview Page at https://www.nycbar.org/committees/task-force-on-digital-technologies/ and the Task Force Leadership Page at https://www.nycbar.org/wp-content/uploads/2026/02/PTFAIDT-Leadership-260219.pdf.
[10] The Working Group focused very closely on language in United States v Heppner emphasizing that “AI users do not have substantial privacy interests in their ‘conversations with [another publicly accessible AI platform] which users voluntarily disclosed’ to the platform and which the platform ‘retains in the normal course of its business…. For these reasons, Heppner could have had no ‘reasonable expectation of confidentiality in his communications’ with Claude.”
[11] This analysis was drafted by the Working Group.
[12] This section of the analysis was based, in large part, on an analysis drafted by Robert Mahari, titled Misunderstanding Memorization: The Technical Nuances of AI Privilege Waiver (forthcoming June 2026) in Stanford University CODEX, The Stanford Center for Legal Informatics (Misunderstanding Memorization). According to Misunderstanding Memorization, an LLM is a mathematical function with billions of numerical parameters (weights) that has been trained to predict the next word in a sequence. See Misunderstanding Memorization at page 3.
[13] “Training proceeds by exposing the model to enormous text corpora: often hundreds of billions to trillions of words drawn from publicly available sources such as books, websites, and academic papers. During training, the model reads a passage, predicts the next word, compares its prediction to the actual next word, and adjusts its parameters slightly to improve future predictions. This process, called gradient descent, is repeated billions of times across the training corpus. The result is a set of parameters that encode statistical patterns about language (i.e., word associations, grammar, facts, reasoning patterns) rather than a deliberate copy of any particular training document.” Id pages 3-4.
[14] Misunderstanding Memorization has cautioned that this characterization requires an important caveat. The compression is not uniform. Research has shown that LLMs exist on a spectrum between generalization and memorization: for some inputs (especially those seen many times during training), the model retains near-verbatim representations; for others (especially unique, low-frequency inputs), the model retains only the general patterns they contribute to. The distinction between widely duplicated content and unique content is critical for the attorney-client privilege analysis. Id at page 4.
[15] Misunderstanding Memorization points out that incorporating a user’s unique input into an LLM training model is not the default for enterprise and commercial AI products. Id.
[16] Misunderstanding Memorization notes that there are at least four circumstances under which the probabilities of tracing the information back to a single user could theoretically occur. First, LLMs can reproduce widely available works as was demonstrated in January 2026. In that case, Ahmed et al. showed that several LLMs could reproduce near-verbatim copies of well-known copyrighted books when subjected to carefully designed prompting strategies; that extraction was possible only because those books appear thousands of times across the training corpus, a characteristic that unique user inputs by definition do not share. Second, a large-scale extraction attack has successfully extracted several megabytes of ChatGPT’s training data for approximately $200 and estimated that extracting roughly one gigabyte was feasible; that attack relied on a specialized adversarial “divergence” prompting strategy that does not reflect ordinary use, recovered random training sequences rather than targeted content, and yields no information identifying who had supplied any given sequence. Third, personally identifiable information can be extracted from LLMs at a cost of approximately $0.012 per item, with a 48.9% non-targeted extraction success rate; this work targets personally identifiable information (PII) present in the publicly scrapped pre-training corpus rather than user inputs , and the extracted PII likewise carries no attribution to any particular user or session. Fourth, research has also shown that supervised fine-tuning (SFT) techniques can be used to make LLMs produce greater memorization than reinforcement learning approaches; that finding applies to data the provider has elected to include in a fine-tuning dataset (typically a smaller, curated set in which an example may be seen multiple times) and does not bear on a consumer-tier input that is not retained or, if retained, is not selected for fine-tuning. None of these scenarios shows that a unique privileged input from an individual user can be extracted from a deployed model and traced back to that user through ordinary interaction with the platform. Id at page 6. See also https://www.cnbc.com/2024/04/30/eight-newspaper-publishers-sue-openai-over-copyright-infringement.html.
[17] See supra note 12.
[18] Misunderstanding Memorization explains that the duplication effect demonstrates that “memorization in LLMs follows a superlinear relationship with data duplication: a text sequence appearing 10 times in training data is approximately 1,000 times more likely to be reproduced by the model than a sequence appearing only once. A single user’s unique input (appearing once among billions of training examples) has a negligible probability of being memorized.” See Misunderstanding Memorization. Misunderstanding Memorization also points out that research on training data extraction has demonstrated that adversarial prompting techniques can extract verbatim training sequences from LLMs, and these studies confirm the centrality of duplication. Id at page 4.
[19] Counterfactual memorization measures whether a model would generate a sequence differently if that sequence were removed from training. Most apparent memorization is attributable to sequences that appear frequently across many sources; unique or low-frequency sequences exhibit minimal counterfactual memorization, and this does not occur when a single user is involved.
[20] Nevertheless, whether or not user inputs to GenAI systems are easily reproducible or reconstructable after the fact may not be determinative in analyzing questions of privilege waiver. Whether disclosure of privileged information outside the privileged attorney-client relationship results in a waiver does not typically turn on whether the outsider who received the disclosure is later able to remember or reproduce its details, but rather on the fact that the disclosure was made.
[21] Research and anecdotal data observed by the Working Group indicate that (1) the overwhelming majority of Privacy Policies for major organizations, especially regulated organizations, are drafted or reviewed, implemented, administered, and enforced by counsel; (2) counsel who draft or review, administer, implement, and enforce Privacy Policies specifically take into account US federal and state privacy laws, case law, enforcement actions, and best practices; and (3) the resulting privacy and confidentiality, access-control, and retention features of those Privacy Policies, while not necessarily specifically aimed at attorney-client privilege or the work product doctrine, are in many cases consistent with the safeguards on which confidentiality analysis would rely.
[22] As a part of its research and analysis, the Working Group compared Privacy Policies across multiple industries and concluded that a significant number of market participants use substantially the same language as Claude and ChatGPT in their privacy policies. The Task Force also concluded that a significant number of industry privacy policies were not only drafted by lawyers but were also administered and enforced by lawyers. See OpenAI/ChatGPT. OpenAI’s Privacy Policy authorizes the sharing of “your Personal Data, including information about your interaction with our Services, with government authorities, industry peers, or other third parties in compliance with the law” upon either a legal obligation or a “good faith belief that such action is necessary.” OpenAI, U.S. Privacy Policy (updated Feb. 9, 2026), “Disclosure of Personal Data,” subsection “Government Authorities or Other Third Parties,” https://openai.com/policies/us-privacy-policy/ (accessed Mar. 4, 2026). Google (including Google Drive)/Gemini. Google’s Privacy Policy authorizes disclosure outside of Google upon a “good-faith belief that [disclosure] is reasonably necessary to” respond to “any applicable law, regulation, legal process, or enforceable governmental request.” Google, Privacy Policy (effective July 1, 2025), “Sharing your information,” subsection “For legal reasons,” https://policies.google.com/privacy (accessed Mar. 4, 2026). Microsoft/Copilot/OneDrive. Microsoft’s Privacy Statement authorizes the company to “retain, access, transfer, disclose, and preserve personal data, including your content (such as the content of your emails in Outlook.com, or files in private folders on OneDrive)” upon a “good faith belief” that doing so is necessary to “[c]omply with applicable law or respond to valid legal process, including from law enforcement or other government agencies.” Microsoft, Privacy Statement (updated Feb. 2026), “Reasons We Share Personal Data,” https://privacy.microsoft.com/en-us/privacystatement (accessed Mar. 4, 2026). Dropbox. Dropbox’s Privacy Policy authorizes disclosure to third parties where “reasonably necessary” to “comply with any applicable law, regulation, legal process, or appropriate government request.” Dropbox, Privacy Policy (effective May 30, 2025), “Law & Order and the Public Interest,” https://www.dropbox.com/privacy (accessed Mar. 4, 2026). Box. Box’s Privacy Notice authorizes disclosure where “reasonably necessary to comply with any applicable law, regulation, legal process, or governmental request.” Box, Privacy Notice, “Compliance with Laws,” https://www.box.com/legal/privacypolicy (accessed Mar. 4, 2026); Box, Law Enforcement Guidelines, https://www.box.com/legal/lawenforcementguidelines (accessed Mar. 4, 2026).
[23] See, e.g., United States v. Warshak, 631 F.3d 266, 286–88 (6th Cir. 2010) (rejecting the argument that an ISP’s contractual right to access subscriber email defeated the user’s reasonable expectation of privacy).
[24] Bridget Mary McCormack and Shlomo Klapper, The Machine Isn’t the Interlocutor: Why United States v. Heppner Gets Privilege Wrong, 27 SEDONA CONF. J. ____ (forthcoming 2026), https://thesedonaconference.org/publication/The_Machine_Isnt_the_Interlocutor.
[25] See New York City Bar Ass’n s, Committee on Small Law Firms, The Cloud and the Small Law Firm: Business, Ethics and Privileged Consideration (Nov.2013) https://www2.nycbar.org/pdf/report/uploads/20072378-TheCloudandtheSmallLawFirm.pdf; NYSBA Ethics Op. 842 (Sept. 10, 2020) and 1020 (Sept. 12, 2014). See also ABA Comm. on Ethics & Prof’l Resp., Formal Op. 477R (2017) (concluding that lawyers may use cloud-based and other internet services to transmit and store confidential client information consistent with their duty of
confidentiality, provided they make reasonable efforts to prevent inadvertent or unauthorized access); ABA Comm. on Ethics & Prof’l Resp., Formal Op. 512 (2024) (extending the same framework to GenAI tools).
[26] United States v. Heppner, No. 1:25 cr-00503 JSR, Memorandum (S.D.N.Y. Feb. 17, 2026) (discussing privilege elements, confidentiality, and the role of the provider’s Privacy Policy and disclosed practices).
[27] Consumer tools that charge a subscription may have enhanced privacy protection.
[28] United States v. Mejia, 655 F.3d 126 (2d Cir. 2011) (reasonable expectation of confidentiality as a component of privilege analysis); United States v. DeFonte, 441 F.3d 92 (2d Cir. 2006) (privilege protection for certain notes and the importance of context in confidentiality analysis); see also Alldread v. City of Grenada, 988 F.2d 1425 (5th Cir.
1993) (collecting cases and noting that the majority of courts look to the “facts surrounding a particular disclosure”
and will not automatically find waiver for inadvertent, rather than voluntary, disclosures of privileged information).
[29] United States v. Stewart, 433 F.3d 273 (2d Cir. 2006) (work product waiver principles and disclosure considerations). See also Legal Information Institute, “Attorney work product privilege” (summary of work-product doctrine and waiver standards).
[30] Warner v. Gilbarco, Inc., No. 2:24-cv-12333, Order (E.D. Mich. Feb. 10, 2026) (denying motion to compel pro se litigant’s GenAI use; discussing work product, waiver standards, and “tools, not persons”).
[31] Morgan v. V2X, Inc., No. 25cv01991SKCMDB, (D. Colo. Mar. 30, 2026) (addressing AI-assisted work product for pro se litigant, rejecting automatic waiver, and amending protective order to address GenAI use with confidential information).
[32] Several members of the Working Group have themselves drafted, reviewed, implemented, and enforced hundreds of terms of service/terms of use and privacy policies and provided legal advice to a wide range of clients, including AI firms, financial institutions, insurance companies, broker dealers, investment advisers, fintech companies, healthcare providers, and other organizations on terms of service/terms of use and privacy policies.
[33] The terms of service/terms of use for Anthropic and Claude also expressly provide that users retain ownership of their inputs. Anthropic’s consumer terms note that users “retain any right, title, and interest” in their inputs, and Anthropic “assign[s]” all of its interest in outputs to the user. OpenAI’s terms of service/terms of use also indicate that, as between the user and OpenAI, the user “retain[s] ownership rights in Input and own[s] the Output.” At the commercial tier, both providers go further: Anthropic’s commercial terms classify all customer content as the customer’s “Confidential Information” subject to a duty of reasonable care and prohibit Anthropic from training models on customer content. These provisions are the opposite of abandonment – they are contractual commitments to recognize the user’s continuing ownership interest in the data. Finally, the subjective intent of a person using an AI tool is to obtain assistance – to analyze a document, draft a response, or research a question. See also pages 64-66 and 149 of Task Force April 2, 2026, annual report titled Recent Trends and Developments in Artificial Intelligence and Digital Technologies available at https://www.nycbar.org/reports/recent-trends-and-developments-in-artificial-intelligence-and-digital-technologies/?back=1.
[34]Id at page 5.
[35] Id.
[36] Id.
[37] Id.
[38] In that regard, lawyers who draft, review, implement, administer, and enforce Privacy Policies take into account, among other laws, the federal laws such as Title V of the Gramm-Leach-Bliley Act, Public Law 106–102 (November 12, 1999) accessible at https://www.govinfo.gov/content/pkg/PLAW-106publ102/pdf/PLAW-106publ102.pdf and a number of state privacy laws. Those lawyers design Privacy Policies and supporting practices to comply with the federal and state privacy laws (and, in some cases, international privacy laws and practices) and the resulting safeguards (such as access controls, retention limits, and confidentiality designations) are often consistent with the preservation of the attorney-client privilege and work product doctrine. While information may be deleted under certain privacy laws, that information is not discarded or made available to the public.
[39] When an AI platform uses inputs for training, the information is processed through gradient descent, a mathematical optimization process that distributes the statistical signal of each input across billions of model parameters. Even where memorization occurs, the memorized content is integrated into the rest of the AI model’s knowledge and is not stored as a discrete, addressable record.
[40] Fed. R. Evid. 502 (limitations on waiver, including inadvertent disclosure and court orders).
[41] The Working Group assumes that some of the information input was from Heppner’s counsel and must have been input while Heppner was represented by counsel. The opinion does not address whether any of the information was input before Heppner retained counsel.
[42] The court found that Heppner did not communicate with Claude to obtain legal advice. The court noted that the government asked Claude whether it could give legal advice and Claude responded that it was not a lawyer and could not provide legal advice or recommendations and recommended consultation with a qualified lawyer.
[43] Heppner, slip op. at 5.
[44] McCormack & Klapper, The Machine Isn’t the Interlocutor.
[45] Heppner, slip op. at 6.
[46]Judge Rakoff also found that work-product privilege did not apply because Heppner’s communications with Claude were not made at the behest of counsel. That holding is distinguishable from the civil context analyzed in Warner and Morgan, where courts have recognized that a pro se litigant’s self-directed use of AI may satisfy the “by or for a party” language of Fed. R. Civ. P. 26(b)(3)(A). See Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich. Feb. 10, 2026) and Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026).
[47] Heppner, slip op. at 9.
[48] Warner, slip op. at 11.
[49] Id.
[50] See In re Columbia/HCA Healthcare Corp. Billing Pracs. Litig., 293 F.3d 289, 306 n.28 (6th Cir. 2002).
[51] Warner, slip op. at 9; see also Federal Rule of Civil Procedure 26(b)(3)(B).
[52] Morgan, slip op. at 1.
[53] Morgan, slip op. at 15.
[54] 585 U.S. 296 (2018).
[55] 631 F.3d 266 (6th Cir. 2010).
[56] This distinction may carry weight and has with at least one judge.
[57] “Except for scientific or medical reports, Rule 16(b)(1) does not authorize discovery or inspection of: (A) reports, memoranda, or other documents made by the defendant, or the defendant’s attorney or agent, during the case’s investigation or defense” Fed. R. Crim. P. 16(b)(2)(A).
[58] See In re Grand Jury Subpoenas Dated Mar. 19, 2002 & Aug. 2, 2002, 318 F.3d 379, 384 (2d Cir. 2003) (“[W]e have entertained work product challenges to grand jury subpoenas even though neither Fed.R.Civ.P. 26(b)(3) nor Fed.R.Crim.P. 16(b)(2) strictly applies in that context.”).
[59] Corporations and other entities cannot appear in court pro se, but could be pre-representation.
[60] See Amy Jane Longo, Shannon Capone Kirk, Isaac Sommers and Jake Barr, Courts Demonstrate Growing Willingness to Sanction Courtroom Misuse of AI, AMERICAN LAWYER (Jan. 22, 2025), available at https://www.law.com/legaltechnews/2025/01/22/courts-demonstrate-growing-willingness-to-sanction-courtroom-misuse-of-ai/. (noting an increasing “notable willingness” of various courts to “apply existing rules to the abuse of
gen AI.”).
[61] 425 U.S. 435, 443 (1976).
[62] 442 U.S. 735, 743-44 (1979).
[63] 631 F.3d 266 (6th Cir. 2010).
[64] 631 F.3d at 285-86.
[65] Id.
[66] 585 U.S. 296 (2018).
[67] Carpenter, 585 U.S. at 315.
[68] Id. at 311.
[69]The SCA, 18 U.S.C. §§ 2701-2712, enacted as Title II of the Electronic Communications Privacy Act of 1986 (ECPA), provides a statutory framework governing government access to electronically stored communications and subscriber records held by third-party service providers. Prior to Carpenter, courts routinely applied SCA compelled-disclosure standards (requiring only a court order supported by “specific and articulable facts”) to obtain historical email content and subscriber records. See 18 U.S.C. § 2703(d). Warshak established that the Constitution requires more – a full warrant supported by probable cause – for email content, irrespective of the SCA’s lower threshold.
[70] United States v. Chatrie, 136 F.4th 100 (4th Cir. 2025).
[71] 110 F.4th 817 (5th Cir. 2024).
[72] “[T]he mere ability of a third-party intermediary to access the contents of a communication cannot be sufficient to extinguish a reasonable expectation of privacy” Warshak, 631 F.3d at 286; “A private party’s warning that it may monitor how someone uses its provided services to prevent misuse does not eliminate Fourth Amendment protections entirely.” Lowers, infra.
[73] See United States v. Zelaya-Veliz, 94 F.4th 321, 333 (4th Cir. 2024) (“Most federal courts to rule on the issue have agreed that Facebook and other social media users have a reasonable expectation of privacy in content that they exclude from public access, such as private messages.”)(collecting cases).
[74] United States v. Lowers, 2026 U.S. App. LEXIS 7013 (4th Cir. 2026); Heidi Grp., Inc. v. Tex. HHS Comm’n, 138 F.4th 920 (2025).
[75] Morgan, slip op. at 16.
[76] Formal Opinion 2024-5: Ethical Obligations of Lawyers and Law Firms Relating to the Use of Generative Artificial Intelligence in the Practice of Law, New York City Bar Association, https://www.nycbar.org/wp-content/uploads/2024/08/20221329_GenerativeAILawPractice.pdf; see also American Bar Association (ABA) Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512 (July 29, 2024), https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-opinion-512.pdf.
[77] Strike 3 Holdings, LLC v. Doe, No. 25-CV-05439-PHK (N.D. Cal. Nov. 6, 2025).
[78] See Thomas Claburn, Cursor-Opus agent snuffs out startup’s production database, THE REGISTER (Apr. 27, 2026), available at https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/5224442.
[79] In a companion report titled AI Agents – The Emerging Regulatory Challenges drafted by the Task Force Subcommittee on the International Regulation of Artificial Intelligence and expected to be published subsequently, the Task Force addresses agentic AI issues in more detail.
[80] 296 F.2d 918 (2d Cir. 1961).