One of your employees pastes the details of a brewing contract dispute into ChatGPT and asks for a quick read on the company's exposure. No lawyer suggested it. Nobody in your legal department knows it happened.
Has your company just waived attorney-client privilege over the entire issue? The answer decides whether that chat is protected strategy or an exhibit in someone else's motion.
Three federal courts have answered since February. They do not agree.
- Federal courts are split on whether employee use of ChatGPT or Claude can destroy attorney-client privilege, creating major risk for companies handling sensitive legal issues through consumer AI tools.
- One court found no protection applied when a represented defendant used Claude without lawyer involvement, while two others preserved work product protections for self-represented litigants using ChatGPT.
- A separate lawsuit against OpenAI seeks $10 million in punitive damages over AI-generated legal filings, signaling growing litigation exposure tied to chatbot misuse and hallucinated case citations.
- Legal departments should act now by restricting approved AI tools, reviewing vendor data policies and tracking AI use before discovery requests expose confidential company information.
No Lawyer, No Privilege, No Protection
After learning he was the target of a federal securities fraud investigation, Bradley Heppner went to work on his own defense. Without his lawyers' direction or suggestion, he ran his defense questions through Anthropic's Claude and built about 31 documents of strategy and argument. His lawyers listed the documents on a privilege log.
The court ruled neither attorney-client privilege nor work product ever attached, so there was nothing to waive. No attorney-client relationship can exist with a chatbot. Nothing confidential passes through a consumer service whose terms then let Anthropic train on and share the queries. And Heppner was seeking no lawyer's advice. Claude disclaims giving legal advice at all.
Of the three rulings, this one's facts sit closest to the employee in the opening scenario: a sensitive legal question, a consumer chatbot, no lawyer in the loop.
Work Product Survives Pro Se AI Use
A court in Michigan ruled the other way. Sohyon Warner, handling an employment discrimination case pro se, had used ChatGPT to help draft her filings. The defense demanded every document touching her AI use.
The judge ruled that Warner's AI-assisted drafting stayed protected work product. That protection is lost only when material reaches an adversary or is likely to. A chatbot does not put a draft in an adversary's hands.
Colorado Draws the Line, But With Conditions
A federal court in Colorado extended that logic and drew its limits. Archie Morgan, also litigating his own employment case, kept work product protection over the thinking reflected in his AI use because the civil rules protect trial preparation material a party creates, whether or not a lawyer created it.
However, the judge still made him name the tool within 10 days and rewrote the case's protective order. Confidential material now stays out of any AI tool whose provider trains on user data, which in practice bars the major chatbots' consumer tiers.
The represented defendant lost and the self-represented plaintiffs won. The courts themselves drew two sharper distinctions.
Why the Outcomes Diverged
The first is doctrine. Heppner was a criminal case about attorney-client privilege, which disclosure to any outsider can destroy. Warner and Morgan were civil fights over work product, which survives anything short of disclosure to an adversary.
Distinguishing Heppner, the Morgan court pointed to what it called the "gap between the party and the attorney." Heppner acted entirely apart from his lawyers, while a litigant with no lawyer is party and advocate at once, so no gap can open.
The greatest risk is when a party, already represented by counsel, inputs legal questions into a consumer chatbot without their lawyers' knowledge. However, the law is evolving.
In June, a Texas Business Court largely protected a company executive's ChatGPT conversations under work product rules, expressly disagreeing with the Heppner ruling. This disagreement between courts shows that the risk of losing legal privilege remains a subject of active debate.
Nippon v. OpenAI: When AI Itself Becomes the Liability
The other half of the story is in Chicago, where the company is the plaintiff. Nippon Life Insurance Company of America settled a disability benefits dispute with Graciela Dela Torre, a claimant under one of its group policies. The case was dismissed for good in January 2024.
According to the complaint, Dela Torre began feeding the settled dispute into ChatGPT a year later: first a motion to reopen, denied, then a fresh lawsuit reasserting the released claims, then 44 motions, memoranda, demands and petitions plus 14 requests for judicial notice, all drafted with ChatGPT's help, by the complaint's count.
In March the insurer sued OpenAI itself in federal court, asking a court to hold ChatGPT's maker responsible for filings the complaint calls frivolous and meritless. One allegation is that her filings cited authority that does not exist. In the complaint's words: "Carr v. Gateway, Inc. 944 F.Supp.2d 602 (D.S.C. 2013) refers to a case and a decision that never happened. It only exists in Dela Torre's papers and the 'mind' of ChatGPT."
The suit pleads tortious interference with the settlement, abuse of process and a claim that OpenAI's product engaged in the unlicensed practice of law in Illinois. It seeks $300,000 in compensatory damages and $10 million in punitive damages.
OpenAI moved to dismiss in May, arguing that ChatGPT is statistical software that predicts words and cannot practice law. The motion is fully briefed, with no ruling as of this writing.
The three federal rulings are warnings about what employees might give away inside a chatbot. Nippon previews the next stage where your company is on the receiving end of litigation an AI tool helped generate, with the tool's maker answering for it as a defendant.
Why There's No Consensus Yet—And Won't Be Soon
Do not wait for the courts to define the rules of AI and privilege. Current laws are inconsistent because judges struggle to apply legacy concepts like privilege and work product to tools that operate entirely outside human legal relationships.
Because there is no appellate consensus, you cannot rely on privilege as a safe harbor when your employees use unauthorized AI tools. Relying on an unsettled doctrine is a liability, not a strategy.
It is true that most decisions so far protect the AI user. The lone loss came on narrow, avoidable facts where the takeaway is to bring counsel in before AI touches anything litigation-adjacent.
This record provides no guarantee of safety, because no federal court has yet addressed the scenario companies fear most: employees at a represented company using consumer chatbots to handle legal matters without counsel's direction. The only closely analogous case resulted in a total loss of privilege. Since judicial consensus is years away and your employees are already using these tools, you cannot wait for a definitive ruling.
What Every Legal Department Should Be Doing Right Now
The amended protective order in Morgan sets a floor: no confidential material goes into an AI tool unless the provider is contractually barred from training on it, barred from sharing it beyond what running the service requires, and bound to delete it on request. A federal court has already written that standard. Adopt it into policy nearly word for word.
Two of these rulings turned on the vendor's terms at the moment of use. Checking them is quick work. Anthropic's consumer privacy policy permits training on chats unless the user opts out, while its commercial terms bar training on business customers' content. OpenAI draws the same line noting that business and API account data stays out of training by default, while its consumer privacy policy reserves the right to train on users' chats unless they opt out. In a privilege fight, the consumer tier and the enterprise contract are different worlds.
Anthropic has updated its terms since the Heppner decision, proving these policies are not static. This volatility means you cannot rely on a one-time audit, and you must treat policy compliance as a continuous, recurring task.
Name the tools employees may use for anything touching a legal question and sort them into tiers. Train people on what never goes into a consumer chatbot. Add fields to the privilege log recording which AI tool touched a matter and under whose account. Put vendor terms review on a recurring calendar.
Rehearse Discovery Before It Arrives
Then rehearse the discovery fight before it arrives. Your company should be able to say within days which employees used which tools on a disputed matter, whose accounts they ran on, and what training and retention terms governed that day. None of that can be reconstructed under a motion to compel deadline.
Assume that the vendor's copy outlives the employee's. In the consolidated copyright litigation against OpenAI, a federal court ordered the company to preserve all user chats, including deleted conversations.
In January, a district judge affirmed an order producing a de-identified sample of 20 million user conversations. A chat an employee deleted in the spring may sit under another court's preservation order in the fall, retrievable in litigation the company is not party to.
After Nippon, the exposure runs in reverse too, which is why AI use belongs on the board's risk agenda rather than in an IT memo. The same tools that can leak privilege outbound can generate litigation inbound.
The Experiment Is Already Running
The question isn't whether your company is using AI. It is, even if you don't know it.
The only variable you control is whether you manage the fallout after a dispute begins or build the necessary infrastructure today. You have a narrow window to establish policy, define permitted tools, and audit your data retention before the next discovery request makes this choice for you.
Somewhere in your company, the next prompt is already being typed. Manage it now.