AI, Privilege, and Work Product: Where Client Confidentiality Is at Risk

|9 min read
The Lex Cloak workspace scanning a sample document — matches grouped by category in the sidebar, every sensitive field outlined in red on the page

There’s a comfortable assumption behind a lot of AI use in a law practice: that privilege travels with the document, so as long as you’re the one running the tool, your client’s material stays protected. The law is earlier and less settled than that. In 2026, three federal trial courts reached different results on AI-assisted litigation materials, and the differences turned on things like whether the person was represented or self-represented, whether the matter was civil or criminal, counsel’s role, which protection was claimed, and, in two of the three, the tool’s terms or a protective order. This is a plain-English look at the two protections at stake, what those early decisions actually show, where the risk arises in everyday practice, and the reasonable steps you can take while the law develops.

Two protections, two different waiver rules

When a client’s document meets an AI tool, two separate protections can be in play, and they are not lost the same way. Treating them as one rule is the most common mistake in this area.

The attorney-client privilege shields confidential communications between you and your client made to give or get legal advice. It is comparatively fragile: voluntarily disclosing a privileged communication to an unnecessary third party can waive it.1

The work-product doctrine shields materials you prepare in anticipation of litigation, including your mental impressions and strategy. It is generally more durable. Disclosure ordinarily waives work-product protection when the material reaches an adversary, or in circumstances that materially increase the chance an adversary obtains it, not merely because some outside party saw it.2

That distinction matters for AI, because some of what a lawyer or a self-represented litigant runs through an AI tool may be work product (a draft argument, a chronology, a set of questions prepared in anticipation of litigation) rather than a privileged attorney-client communication. The label doesn’t attach just because the material is legal in nature or passed through an AI tool, and which protection is even in play, and whether it survives, depends on the facts. One more rule is worth knowing and easy to overstate: in federal litigation, Federal Rule of Evidence 502 can limit the fallout from certain disclosures, but its main provisions reach disclosures made in a federal proceeding or to a federal office or agency, and it does not decide whether the material was protected to begin with. Even where it applies, it is narrow: it limits a broader subject-matter waiver to intentional disclosures of the same subject, and it spares an inadvertent disclosure only when reasonable precautions were taken and the error was promptly corrected. An ordinary, pre-litigation upload to a private AI service may fall outside it entirely.3

What the first decisions actually show

Three early federal rulings in 2026 don’t line up into a single rule. They are trial-court decisions on very different facts, and none is an appellate decision, so no controlling standard has been set.

  • In United States v. Heppner, a federal court in New York considered a represented criminal defendant who, on his own, used a public AI assistant to prepare documents for his defense. The court held the material was protected by neither the attorney-client privilege nor the work-product doctrine.4
  • In Warner v. Gilbarco, a federal court in Michigan reached a more protective result for a self-represented plaintiff who used third-party generative-AI tools in preparing for litigation. It treated the AI as a tool rather than a person, so that using it did not hand her work product to an adversary.5
  • In Morgan v. V2X, a federal court in Colorado held that the work-product doctrine could give a pro se litigant some protection in connection with his AI use, but it ordered him to identify the AI tool he had used on information covered by the case’s protective order, because he hadn’t shown that naming the tool would reveal his strategy.6

The throughline isn’t “AI waives” or “AI is safe.” It’s that the facts drove each outcome: who used the tool and in what role, which protection was claimed, and, in two of the cases, the tool’s terms or a protective order. A represented party’s independent, unsupervised use of a consumer tool is a different question from a pro se litigant’s own work product. Read together, these rulings are a caution, not a green light: the law is being written now, one fact pattern at a time.

Where the risk arises in everyday practice

  • Putting matter-related content into a consumer AI service. When the terms let the provider access, retain, or train on what you enter, that can create confidentiality and waiver risk. The result is fact-specific, and depends on the tool, the product tier, the terms in force when you use it, and what you enter.7
  • The “share” and “export” buttons. The New York City Bar’s 2026 report on AI and privilege flags that some of these features create links reaching beyond the intended participants. Depending on the tool and settings, such a link may be indexed or copied into third-party archives, and an archived copy may persist even after the provider restricts indexing or access to the original. Check the access controls before using the feature on anything matter-related.8
  • Uploading a file to an online tool to “clean” it. Some web-based services, including some online redactors, process the file on their own servers, which means sending the original before it is sanitized. Before using one, find out whether processing happens locally or remotely, and what the provider can access or retain.
  • Consumer tier versus enterprise tier. The tool you reach for is part of the analysis. The City Bar report notes that enterprise tools carrying contractual safeguards, such as no-training terms and deletion rights, present a stronger confidentiality case than their consumer counterparts.8

What the ethics rules ask of you

Two duties frame the practical response. Both are stated in the ABA Model Rules, which take effect as adopted, with variations, in each jurisdiction, so check your own state’s version.

  • Competence now includes the technology. Model Rule 1.1, Comment [8] says a lawyer should keep abreast of the benefits and risks of relevant technology, and ABA Formal Opinion 512 (2024) applies that duty to generative AI.7
  • Confidentiality and consent. Confidentiality under Model Rule 1.6 is broader than the evidentiary privilege. Opinion 512 calls for a fact-specific look at the particular tool: its terms, access, retention, training, and configuration. Where a self-learning tool creates a real risk that information relating to the representation could be exposed to others, the opinion states that the client’s informed consent is required before the lawyer enters that information, and that a general engagement-letter clause is not enough. Informed consent means explaining the proposed use, the material risks, the reasonable alternatives, and the benefits. Some uses that enter no matter-related information may not require consent at all.7
  • Raise it early. Consistent with that, the City Bar report advises addressing GenAI use in engagement letters and client onboarding, cautioning clients that a consumer AI tool is not a substitute for talking to their lawyer, and advising them against using share or export features on anything touching privileged matter.8

What handling it well looks like

No single step resolves the questions above, but a few reduce the exposure you can actually control.

Minimize what leaves your hands, and know what minimizing does and doesn’t do. Removing a client’s identifying and sensitive details before a document goes to an outside tool shrinks the information transmitted. It does not, by itself, remove the confidential legal question, the factual narrative, counsel’s advice, or the litigation strategy that may sit in the same document. Those are what the privilege and work-product doctrines are actually about, and they need a separate look: if protected substance remains, sending the redacted file may still raise a disclosure question.

Do the removal on your own machine. If sanitizing a file means uploading it to another online service first, you’ve added a disclosure to prevent one. A redaction workflow that runs on your own computer can avoid transmitting the unredacted original to a redaction provider at all. That is a real, controllable benefit. This is Lex Cloak’s job: it processes PDFs on your own machine and surfaces the categories of sensitive information it is configured to find, for you to confirm, dismiss, or supplement by hand. Automated detection is not exhaustive, so human review remains necessary. Local processing avoids uploading the original to a redaction service. Whether the resulting document is appropriate to send, and whether protected substance remains, is a separate, matter-specific judgment for you and, where needed, the client, counsel, or a court.

Keep a record of what you did. Being able to show which identifiers were found and removed, and that the file was handled locally, helps you demonstrate the care you took. It documents your precautions. It is not a substitute for the legal analysis, and it does not by itself bring a disclosure within any waiver-limiting rule.3

The bottom line

The privilege question AI raises is really the old question of what happens when confidential material leaves your control, asked about a new and fast-moving third party, and the early answers depend heavily on the facts. AI use can be lawful and genuinely useful in a practice. Whether a given use raises a confidentiality or waiver problem turns on the information entered, the tool and its tier, the terms in force at the time, your role, and the law of your jurisdiction. Data minimization and local redaction reduce what is transmitted and avoid an extra upload of the unredacted original. They do not preserve privilege on their own. For a decision on a specific matter, the governing authority is your jurisdiction’s law and ethics guidance, or your own counsel.

See how Lex Cloak redacts a file, start to finish →

This guide is general information about legal-ethics and evidentiary rules, not legal advice, and doesn’t create an attorney-client relationship. Privilege and waiver law varies by jurisdiction, the 2026 decisions discussed here are trial-level rulings on distinct facts, and the law on AI is developing quickly. How any of this applies to your situation is a question for your bar association or your own counsel.

Sources

  1. In federal court, Federal Rule of Evidence 501 provides that the attorney-client privilege is governed by the common law. Under that common law, voluntarily disclosing a privileged communication to a third party outside the privileged relationship can waive the privilege. State privilege law, which governs in many matters, varies. FRE 501 (Cornell LII). Current Federal Rules of Evidence, accessed July 24, 2026.
  2. Work-product doctrine: Federal Rule of Civil Procedure 26(b)(3), and Hickman v. Taylor, 329 U.S. 495 (1947), its origin. Unlike the attorney-client privilege, work-product protection is generally waived by disclosure only where the material is given to an adversary, or in a way that materially increases the likelihood an adversary will obtain it, not by disclosure to any third party. See In re Qwest Commc’ns Int’l Inc., 450 F.3d 1179 (10th Cir. 2006) (non-opinion work product waived by disclosure to an adversary), and United States v. AT&T, 642 F.2d 1285 (D.C. Cir. 1980) (disclosure waives work product where it substantially increases an adversary’s opportunity to obtain the material). FRCP 26 (Cornell LII). Current Federal Rules of Civil Procedure, accessed July 24, 2026.
  3. Federal Rule of Evidence 502, “Attorney-Client Privilege and Work Product; Limitations on Waiver.” Its principal provisions address the effect of a disclosure made in a federal proceeding or to a federal office or agency: subsection (a) limits subject-matter waiver to intentional disclosures where the disclosed and undisclosed material concern the same subject matter and fairness requires considering them together; subsection (b) provides that an inadvertent disclosure does not operate as a waiver where the holder took reasonable steps to prevent disclosure and promptly took reasonable steps to rectify the error. Rule 502 does not determine whether material was privileged in the first place, and an ordinary pre-litigation disclosure may fall outside it. FRE 502 (Cornell LII). Current Federal Rules of Evidence, accessed July 24, 2026.
  4. United States v. Heppner, No. 25 Cr. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.) — held that documents a represented criminal defendant prepared with a publicly available AI assistant, on his own and not at his counsel’s direction, were protected by neither the attorney-client privilege (the AI platform is not an attorney, and its terms permitting disclosure defeated any reasonable expectation of confidentiality) nor the work-product doctrine (the materials were not prepared by or at counsel’s direction and did not reflect counsel’s mental impressions). docket search (CourtListener). Trial-court decision; may be subject to further proceedings. Citation as reported, accessed July 24, 2026.
  5. Warner v. Gilbarco, Inc., No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. Feb. 10, 2026) — declined to compel a self-represented plaintiff’s AI prompts and outputs, holding they were protected work product, and reasoning that generative AI programs are “tools, not persons,” so that using one is not a disclosure to an adversary and does not waive work-product protection. docket search (CourtListener). Trial-court decision; may be subject to further proceedings. Citation as reported, accessed July 24, 2026.
  6. Morgan v. V2X, Inc., No. 25-cv-01991-SKC-MDB, 2026 WL 864223 (D. Colo. Mar. 30, 2026) (Dominguez Braswell, M.J.) — held that Federal Rule of Civil Procedure 26(b)(3) can give a pro se litigant some work-product protection in connection with AI use, because the rule reaches materials any party, not only counsel, prepares in anticipation of litigation, and declined to follow Heppner’s reasoning that intermediary access forfeits protection; the court nonetheless ordered the litigant to identify any AI platform used on information designated confidential under the case’s protective order, because he had not shown that naming the platform would reveal his mental impressions or strategy. docket search (CourtListener). Trial-court decision; may be subject to further proceedings. Citation as reported, accessed July 24, 2026.
  7. American Bar Association, Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, “Generative Artificial Intelligence Tools” (issued July 29, 2024) — the ABA’s first formal ethics opinion on lawyers’ use of generative AI. It applies the competence duty (Model Rule 1.1, including its technology comment) and the confidentiality duty (Model Rule 1.6) to GAI, calls for a fact-specific assessment of the particular tool, and advises obtaining informed client consent before inputting information relating to a representation into a self-learning tool that presents a risk of disclosure, noting that general engagement-letter consent is insufficient and that some uses require no consent. Model Rules are guidance unless and until adopted in a given jurisdiction. ABA Formal Opinion 512. Issued July 29, 2024; not superseded as of July 24, 2026.
  8. New York City Bar Association, Presidential Task Force on Artificial Intelligence and Digital Technologies, The Intersection of Artificial Intelligence, Privacy, and Privilege (June 2026) — a Task Force report (advocacy, not a court decision) analyzing how large language models and their privacy policies bear on confidential and privileged information. It urges courts to treat generative AI as a tool rather than a substitute-human for third-party-disclosure purposes, drawing an analogy to Fourth Amendment third-party- doctrine cases, and offers practical guidance on engagement letters, consumer versus enterprise tools, and the risk that share/export features create durable, broadly accessible links. Cited here for the Task Force’s analysis and recommendations, not as authority for any court’s holding. NYC Bar report. Published June 2026, accessed July 24, 2026.

The rules, opinions, decisions, and reports cited above are living authorities that are amended, appealed, and occasionally superseded over time, and the law on AI and privilege in particular is developing rapidly. The federal decisions cited are recent trial-level rulings on distinct facts and may be subject to appeal or further proceedings; their citations and holdings are stated as reported and were checked against multiple published analyses as of July 24, 2026 (the “as of” date for each citation). Confirm the current status of any authority before relying on it.