Confidentiality7 min read

Are your AI prompts discoverable? What the 2026 rulings actually protect

Two courts said in June that AI chat logs are work product. The protection turns on who typed the prompt, and the exceptions swallow a lot of it.

The Redline, legal AI guidance
By The Redline Editors

Mostly protected, if you typed them for a case and kept them confidential. In June 2026 two courts said so within twenty four hours of each other. A Texas judge held a party's ChatGPT conversations were work product. The next day a New York judge quashed subpoenas aimed at a litigant's prompts and outputs. Neither accepted that running case strategy through a commercial AI tool destroys the confidentiality the doctrine requires.

That is the American answer. It arrives with holes big enough to lose a file in, and if you practise in England and Wales it inverts.

Who typed it decides how much protection you get

The strongest protection on record belongs to lawyers, and it predates the June rulings by almost two years. In Tremblay v. OpenAI, Judge Araceli Martinez-Olguin held that ChatGPT prompts used to test a copyright theory were opinion work product, because they "were queries crafted by counsel and contain counsel's mental impressions and opinions about how to interrogate ChatGPT." That is the top tier, and it comes out only where mental impressions are themselves at issue.

One rung down sits the party who is not a lawyer. In the Texas case the chats belonged to a company principal, in the New York case to a self-represented defendant. Both got ordinary work product, which an opponent can still defeat by showing substantial need and undue hardship.

The floor matters because it is where most AI use in a small firm actually lives. In re OpenAI, Inc., Copyright Infringement Litigation, 802 F. Supp. 3d 688 (S.D.N.Y. 2025), a spreadsheet of employee prompts assembled supposedly at in-house counsel's direction was held not privileged: no privileged legend, no entries from counsel, no legal advice. Collecting prompts because a lawyer suggested it does not make the collection privileged.

What the June rulings held, and the sting in the Texas one

In Assini v Hayward, 2026 NY Slip Op 26086 (Sup Ct, Nassau County, 4 June 2026), the plaintiffs went straight at the provider. They served a non-party subpoena, then an amended one, demanding every prompt and output tied to a self-represented defendant's account. Justice Rhonda E. Fischer quashed both in full. The defendant compared his use of the tool to jotting notes on a legal pad, and the court agreed: confidential, strategy-focused preparation is what the doctrine exists to shield, whatever the sounding board happens to be.

The Texas decision, Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, No. 25-BC11B-0020 (Tex. Bus. Ct., 11th Div., 3 June 2026), reaches further. Judge Grant Dorfman applied Texas Rule of Civil Procedure 192.5 to a represented party's own chats and found them protected. The defendants pressed United States v. Heppner, the federal decision that went the other way, and the court treated it as inapposite: the Texas rule is broader than the federal standard Heppner construed.

Then came the qualification, and it is the part to plan around. While shielding the chat logs, the court ordered the plaintiff to disclose everything it had shared with ChatGPT, including documents produced under the protective order. What comes out of the tool may be yours. What you fed in, if it belonged to your opponent, is still theirs, and a court will make you list it.

The waiver that catches small firms is the screenshot you send in good faith

This is the section to read twice.

In T.B. v. Big Brothers Big Sisters of N.Y.C., No. 452864/2021 (N.Y. Sup. Ct., 21 August 2025), plaintiff's counsel disclosed a portion of a ChatGPT transcript at a deposition. The court held that the partial disclosure placed the exchange at issue and waived work product. It ordered production of the full transcript.

Picture how that happens in a two-lawyer firm. Opposing counsel emails to say a citation in your brief looks wrong. You want to show you acted in good faith, so you screenshot the part of the thread where you asked the model for real authorities and send it over. You have just put the whole thread at issue, including the exchange where you asked whether your client's account of the meeting would survive cross.

Our piece on what the 2026 discipline cases actually punished says to disclose fast when a fabricated citation surfaces, and that is still right. Disclose in your own words, in a filing. Do not disclose by handing anyone a slice of the log.

You can also put AI work at issue without handing over anything. In Concord Music Group, Inc. v. Anthropic PBC (N.D. Cal., 18 December 2025) protection over post-suit investigation prompts fell away once the party signalled its investigators would testify about that investigation.

Put an expert on the stand and their prompts become methodology

Work product shields the thinking you keep to yourself. It does not shield the method behind an opinion you ask a judge to rely on. In Conservation Law Foundation, Inc. v. Shell Oil Co., No. 3:21-cv-00933 (D. Conn.), a magistrate judge ordered production of the AI prompts a testifying expert used to cull the documents behind her report, treating them as discoverable methodology under Rule 26. Be careful with this one: it is a magistrate order, and it was stayed pending review of the objection.

The consequence lands hardest on small firms, because your experts are usually solo practitioners too. The vocational evaluator, the forensic accountant who tidied a spreadsheet with Copilot and closed the tab. Put a clause in the engagement letter requiring any AI use to be recorded and the prompts kept. Ask before you designate, not at the deposition.

In England and Wales the answer runs the other way

If you are a solicitor reading American coverage of these rulings, stop transplanting it. In UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the Upper Tribunal held at paragraph 60 that uploading confidential documents into an open-source AI tool such as ChatGPT "is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and any such conduct might itself warrant referral to the regulatory body and should, in any event, be referred to the Information Commissioner's Office." The paragraph is quoted in full in the Chancellor's published speech.

Look at what the adviser had actually done. He used ChatGPT to improve emails to clients, and uploaded Home Office decision letters so the model could summarise them. Summarising a decision letter for a worried client is the most ordinary task in an immigration practice. It is also, on this ruling, a waiver and a regulatory referral.

Sir Colin Birss, Chancellor of the High Court, endorsed that reasoning on 22 April 2026. Confidentiality has always been a precondition of privilege, so even if the doctrine were stretched to cover advice from a machine, "it would not seem to attach to the interactions with these public AI systems because they do not appear to be confidential."

He drew the line that matters in the same speech. Where the lawyer uses a secure system to help produce advice for a client, "it is hard to see how that could have an impact on privilege," because legal professionals have always been entitled to consult other sources of legal advice, textbooks included. The English question is not whether you used AI. It is which deployment. And there is no substantial-need fallback here: privilege is absolute once it attaches, and gone once it does not.

What to do about it this week

Five things, in the order I would do them.

  • Split your accounts. Client matter work in one workspace, firm administration and general reading in another. Mixed threads are where partial protection turns into partial production.
  • Move off the consumer tier for anything touching a file. A paid tier with a data processing agreement and no training on inputs strengthens the waiver analysis in America and is the whole ball game in England and Wales.
  • Never disclose part of a chat log to anyone, including a judge asking a fair question. Describe it in your own words instead.
  • Add an AI preservation clause to every expert engagement letter you send from now on.
  • Export the threads that matter once litigation is reasonably anticipated. Consumer chat histories were built to be deleted, and a litigation hold does not reach into a vendor's retention schedule on its own.

The doctrine is moving in your favour. Two trial courts have now said that thinking out loud to a machine is still thinking, and one said it about a litigant with no lawyer at all. What none of them said is that the protection maintains itself. It belongs to whoever can say in one sentence which account held the material.

Our free guide covers what to check before client material goes near a model, and the toolkit lists which tiers actually carry the contractual terms this article assumes you have.

FAQ

Does deleting my chat history protect me?

No, and it can hurt. Once litigation is reasonably anticipated the duty to preserve attaches to AI logs the same way it attaches to any other electronically stored information, and courts have applied the ordinary Rule 37(e) framework rather than inventing an AI-specific one. Consumer chat histories sit on short default retention windows that conflict with a hold. In the OpenAI copyright litigation the New York Times found its own AI logs were on a 90 day retention partition while the person implementing the hold believed the period was a year. Export the thread. Do not clear it.

My client used ChatGPT before hiring me. Is that protected?

Almost certainly not. Work product covers material prepared because of anticipated litigation, and a client asking a chatbot general questions before any dispute existed fails that test. There is no attorney-client privilege either, because a chatbot is not a lawyer. That was the ground of United States v. Heppner in the Southern District of New York. Ask at intake what the client has already typed and into which account, because the other side will.

Can the other side subpoena the AI provider instead of me?

They can try, and in Assini v Hayward they did exactly that, serving the provider rather than the litigant. The subpoenas were quashed, but the lesson is that someone has to assert the protection in time. A provider served with a non-party subpoena has no way of knowing that a given account holds your trial preparation. Check what address your AI vendor uses for legal process notifications and make sure it reaches a human who will act on it within days.

ShareX / TwitterLinkedIn
Was this useful?

Disclaimer · Educational content about software and productivity, not legal advice. AI tools and regulatory guidance change frequently, so always evaluate any tool against your own firm's obligations and your regulator's current guidance (e.g. the SRA in England & Wales, or your state bar / the ABA in the US) before using it with client data.

Free starter kit

Want the safe-tools shortlist as a PDF?

10 lawyer-safe AI tools, 12 ready-to-use prompts, and a client-confidentiality checklist for the SRA (UK) and ABA Rule 1.6 (US). Free, no spam.

Get the free Starter Kit →

Go deeper: The Lawyer's AI Toolkit (£29) →