ARTIFICIAL INTELLIGENCE • WORK PRODUCT • DISCOVERY • PRO SE LITIGATION • PRIVACY
AI Prompts Are Becoming the Modern Litigation Notebook—But Protection Depends on How They Are Created and Shared
Educational legal analysis only—not legal advice. Work-product doctrine, privilege, waiver, discovery obligations, preservation rules, protective orders, and AI privacy requirements vary by jurisdiction. The law is developing rapidly.
Generative artificial intelligence has quietly created a new category of litigation record. Lawyers, represented clients, government parties, businesses, and self-represented litigants can now use AI to analyze evidence, compare authorities, draft arguments, test counterarguments, organize timelines, prepare witnesses, or explore settlement strategy.
Those interactions can reveal far more than the final document that eventually reaches the court.
An AI prompt history can expose not only what a litigant argued, but what the litigant considered, rejected, feared, prioritized, and planned to do next.
That is why courts are now confronting a question that did not exist in traditional electronic discovery: when does an AI conversation become protected trial preparation, and when does disclosure destroy that protection?
Several 2026 decisions provide the beginnings of an answer. They do not create an “AI privilege.” Instead, they apply traditional work-product doctrine to a new technological environment.
Table of Contents
The Work-Product Doctrine Comes Before AI
The foundational doctrine predates computers entirely. In Hickman v. Taylor, 329 U.S. 495 (1947), the Supreme Court recognized that an adversarial system cannot function properly if one side can routinely obtain the other side’s private preparation.
Federal Rule of Civil Procedure 26(b)(3) later codified broad protection for documents and tangible things prepared in anticipation of litigation or for trial by or for another party or its representative.
That language is important because the protection is not textually limited to documents written by attorneys. The doctrine protects litigation preparation, while Rule 26(b)(3)(B) gives additional protection to certain mental impressions, conclusions, opinions, and legal theories of attorneys and other representatives.
The basic policy is easy to understand. Discovery is meant to reveal relevant facts and evidence. It is not normally meant to allow an adversary to obtain the other side’s strategic roadmap for developing those facts and arguments.
Work Product Is Different From Attorney-Client Privilege
AI discussions often become confused because “privilege” is used as a catch-all term.
Attorney-client privilege generally concerns confidential legal communications between lawyer and client. An AI model is not transformed into an attorney because a user asks it legal questions.
Work-product protection concerns litigation preparation. That means an AI conversation may fail the attorney-client-privilege analysis and still present a work-product issue.
This distinction becomes especially important when the user has no attorney at all.
Why Pro Se Status Changes the Analysis
A self-represented party occupies an unusual position. The pro se litigant is both the party whose rights are at issue and the person performing much of the legal preparation that counsel would otherwise perform.
The litigant may:
- review thousands of pages of records;
- organize evidence;
- research procedural and substantive law;
- test legal theories;
- draft discovery requests;
- analyze opposing briefs;
- prepare examinations and hearings; and
- decide which arguments to reveal and which to abandon.
If those activities were written in notebooks or private draft memoranda, courts have long recognized that at least some of the material can qualify for work-product protection. AI now performs the role of an interactive notebook, research assistant, drafting environment, and issue-spotting tool at the same time.
The 2026 decisions ask whether changing the medium should change the doctrine.
Warner v. Gilbarco: AI Use Did Not Automatically Waive Work Product
In Warner v. Gilbarco, Inc., decided February 10, 2026, the U.S. District Court for the Eastern District of Michigan denied discovery seeking a pro se plaintiff’s AI-related litigation materials.
The court relied on Rule 26(b)(3)’s protection for material prepared in anticipation of litigation by a party. It recognized that the plaintiff, although unrepresented, could invoke work-product protection.
Just as important, the court rejected the argument that using ChatGPT automatically waived that protection. Traditional work-product waiver generally focuses on disclosure to an adversary or disclosure made in circumstances substantially likely to place the material in an adversary’s hands.
The court characterized generative AI programs as tools rather than adversaries and rejected an attempt to turn the plaintiff’s internal drafting process into ordinary discovery.
Morgan v. V2X: A Pro Se Litigant Is Both Party and Advocate
Morgan v. V2X, Inc., decided March 30, 2026, provides one of the clearest explanations of the issue.
The District of Colorado observed that courts routinely apply Rule 26(b)(3) to pro se work product and explained why AI makes that protection especially important. The self-represented litigant is forced to function simultaneously as party and advocate. Conditioning protection on attorney involvement would therefore disadvantage the person precisely because the person lacks counsel.
The court concluded that AI-assisted litigation preparation can receive work-product protection. It also rejected automatic waiver merely because widely available AI providers may collect or store user data, reasoning that work-product waiver ordinarily turns on disclosure to an adversary or on conduct substantially increasing the likelihood that an adversary will obtain the material.
But Morgan drew an equally important limit. The work-product doctrine did not allow the litigant to ignore a protective order governing the opponent’s confidential discovery. The court adopted stronger restrictions governing the use of AI systems to process confidential material.
Protection for your strategy and protection of someone else’s confidential information are separate legal questions.
Assini v. Hayward: Subpoenaing OpenAI Is Not a Discovery Shortcut
On June 4, 2026, the New York Supreme Court considered an unusually direct discovery tactic in Assini v. Hayward.
The plaintiffs had served subpoenas on OpenAI seeking a pro se defendant’s ChatGPT account materials. The requested material reached prompts, inputs, uploaded documents, outputs, drafting materials, and litigation-related queries.
The court found Morgan persuasive and granted the branch of the defendant’s motion seeking to quash the OpenAI subpoenas.
The significance is broader than one platform. AI providers may possess records of a litigant’s private analytical process. Assini demonstrates that third-party possession does not automatically turn those records into an open discovery channel.
Heppner and Shealy: The Protection Has Boundaries
Other 2026 cases show why no one should reduce the emerging doctrine to “AI prompts are privileged.”
In United States v. Heppner, a represented criminal defendant independently used an AI system without direction or involvement from his attorneys. The Southern District of New York concluded that the resulting material was protected by neither attorney-client privilege nor work product under the circumstances before it. Morgan later distinguished the case because the civil pro se litigant had no separation between party and advocate.
Massachusetts Superior Court’s Shealy v. Seaside Investments, LLC involved a represented party who shared dispute materials with his romantic partner, who then used ChatGPT outside counsel’s direction. The court ordered the materials produced and distinguished the pro se settings of Warner and Morgan.
These cases identify a recurring set of questions:
- Was the user pro se or represented?
- Was counsel directing the work?
- Was the AI activity actually undertaken because of litigation?
- Who else received or created the material?
- Was the material disclosed beyond those involved in litigation preparation?
Publicly Available AI vs. Publicly Disclosed Prompts
One of the most important distinctions is linguistic.
An AI service can be publicly available without the user’s individual prompts being publicly available.
A consumer can access a mainstream AI service without the resulting conversation appearing on a public website. The provider may store, process, or retain data according to its terms, but that is analytically different from the user intentionally publishing the transcript.
The emerging cases therefore require at least four categories to be kept separate:
- Private AI-assisted litigation preparation.
- AI-provider processing and retention under contractual terms.
- Voluntary public disclosure through a website, social platform, screenshot, or public sharing link.
- Transmission of another party’s protected or confidential information into the AI system.
Calling all four simply “public AI” obscures the legal issue.
The Waiver Question
Work-product waiver is generally not identical to attorney-client waiver. Courts often ask whether the disclosure was made to an adversary or in circumstances that materially increased the likelihood that an adversary would obtain the protected preparation.
That makes public posting particularly risky.
Suppose a plaintiff privately asks an AI system to identify weaknesses in a constitutional claim, rank the defendant’s likely defenses, and develop responses that have not yet been filed. The conversation may reveal litigation strategy far beyond the facts themselves.
If the conversation remains private, Warner and Morgan provide authority against automatic waiver merely because an AI system was used.
If the litigant posts the transcript publicly, creates an unrestricted public link, or sends it to an adversary, the waiver analysis becomes materially different. Public dissemination can substantially increase the likelihood that opposing counsel obtains exactly the strategic material the doctrine would otherwise protect.
That does not mean a public statement about a lawsuit automatically waives every work-product protection. The analysis is document- and disclosure-specific. But publishing the actual strategic conversation can be far more consequential than publishing the final argument.
Government Litigation and AI Discovery
The issue has implications beyond private civil disputes.
Government entities increasingly litigate against citizens in tax, licensing, regulatory, civil-rights, benefits, family-enforcement, property, and administrative matters. At the same time, citizens increasingly rely on low-cost AI tools to understand records and navigate complex procedural systems.
If government counsel could routinely demand every AI prompt used by a pro se opponent, the discovery demand could expose the citizen’s entire preparation process: what constitutional theories were considered, which government records were identified as significant, what weaknesses were recognized, and what arguments are planned next.
Rule 26 does not create a special exemption from discovery merely because government is the opposing party. Nor does it give pro se litigants immunity from ordinary discovery. But the same work-product principles apply. Discovery of facts is different from discovery of an adversary’s strategy for using those facts.
Protective Orders and Third-Party Confidential Information
Morgan should be read carefully by anyone using AI during discovery.
A litigant may have a protectable interest in private AI analysis and still violate a protective order by submitting confidential discovery into a platform that lacks the required safeguards.
Protective orders can restrict disclosure to specified people and systems. Their language controls. A platform’s popularity, usefulness, or general privacy settings do not override a court order.
Before placing protected discovery into an AI system, determine:
- whether the order permits transmission to third-party technology providers;
- whether the provider stores or trains on the data;
- whether human review is possible;
- whether contractual deletion rights exist;
- whether the information can leave the approved environment; and
- whether consent or further court authorization is required.
Underlying Facts Do Not Become Secret Because They Enter an AI Prompt
Work-product doctrine protects litigation preparation, not facts from discovery merely because they were placed inside a protected document.
A party cannot take an otherwise discoverable fact, type it into an AI conversation, and transform the fact into privileged information. The underlying evidence may remain discoverable through interrogatories, requests for production, depositions, subpoenas, or other lawful means.
The important distinction is between the fact and the strategic process surrounding the fact.
For example, an accident date may be discoverable. A private conversation ranking which witnesses most damage the party’s theory and how to impeach each one may present a different work-product question.
Preservation, Logs, and Discovery Objections
A valid work-product argument is not a license to delete AI records.
Once litigation is pending or reasonably anticipated, relevant electronic information may be subject to preservation duties. Deleting conversations because an adversary has requested them can create spoliation disputes.
The proper response may instead involve:
- a written work-product objection;
- a privilege or work-product log where required;
- a motion for protective order;
- a motion to quash a third-party subpoena;
- in camera review;
- narrowing the scope of the request; or
- producing nonprotected facts while withholding protected preparation.
The governing procedure depends on the jurisdiction and the discovery request.
An AI Work-Product Audit
Before asserting or challenging protection over AI material, ask:
- Who created it? Party, lawyer, consultant, employee, friend, partner, or unrelated third party?
- Why was it created? Ordinary research or because litigation was anticipated?
- What does it reveal? Facts, drafts, selections, mental impressions, legal theories, or strategy?
- Was the user pro se? The 2026 cases treat that fact as highly significant.
- Who received it? Counsel, litigation team, AI provider, public audience, or adversary?
- What were the platform’s terms and settings?
- Was confidential third-party material uploaded?
- Was the conversation intentionally made public?
- What discovery rule applies? Federal Rule 26, a state analogue, criminal discovery rules, or an administrative procedure?
- What remedy is appropriate? Objection, log, protective order, motion to quash, or production?
Research the Governing Authority
Use the State Citizen Trust Authority Library to research work-product doctrine, discovery rules, waiver standards, due process, and jurisdiction-specific procedural authority before relying on a generalized AI rule.
Primary Sources
- Hickman v. Taylor, 329 U.S. 495 (1947)
- Federal Rule of Civil Procedure 26(b)(3)
- Warner v. Gilbarco, Inc., E.D. Mich., Feb. 10, 2026
- Morgan v. V2X, Inc., D. Colo., Mar. 30, 2026
- Assini v. Hayward, 2026 NY Slip Op 26086 (June 4, 2026)
The Bottom Line
AI has not displaced the work-product doctrine. It has exposed why the doctrine exists.
A modern AI conversation can contain research decisions, strategic selections, drafts, mental impressions, discarded arguments, and plans for future litigation. For a pro se litigant, it can function as the digital equivalent of the attorney notebook the litigant does not have.
Warner, Morgan, and Assini demonstrate that courts are unwilling to adopt a rule under which use of mainstream AI automatically converts private litigation preparation into discoverable material. But the protection remains fact-dependent, and represented-party cases such as Heppner and Shealy show why attorney involvement, third-party disclosure, and the purpose of the work matter.
The emerging rule is not “AI prompts are privileged.” The better rule is: determine whether the material is protected litigation preparation, then ask whether the user handled it in a way consistent with preserving that protection.
Technology changes the container. The underlying question remains familiar: should an adversary be permitted to obtain the other side’s private preparation merely because the legal pad has become a conversation with a machine?
State Citizen Trust Legal Education: This article is for educational purposes only. It does not establish whether any particular AI conversation is protected, does not create an attorney-client relationship, and is not legal advice.

