AI Privilege Risk Is Becoming a Workflow Problem, Not Just a Confidentiality Warning

Litigation team reviewing confidential documents and a secure AI analysis workflow while assessing privilege, work product, and protective-order risk.

For a while, the standard legal-AI warning sounded simple:

Do not put privileged or confidential information into public AI tools.

That warning is still right. It is also no longer enough.

Recent federal decisions suggest that AI privilege and work-product issues are turning into workflow questions. Courts are not just asking whether AI was used. They are asking what tool was used, who used it, under whose direction, on what material, with what confidentiality protections, and whether discovery or protective-order obligations changed the analysis.

That is a much more operational problem than a generic confidentiality lecture.

The Short Answer

  • AI does not create one uniform privilege or work-product rule.
  • Courts are splitting at least three separate questions: whether confidentiality was lost, whether work-product protection survived, and whether a protective order independently restricted the upload.
  • The practical risk is shifting from abstract “AI waiver” language to concrete questions about tool choice, confidentiality, discovery material, and who approved the use.

The Cases Are Not Moving In One Direction

The early federal decisions do not create one simple rule.

In United States v. Heppner, the Southern District of New York rejected privilege and work-product claims tied to a criminal defendant's use of a consumer AI tool outside counsel's direction.

In Warner v. Gilbarco Inc., the Eastern District of Michigan treated a pro se civil plaintiff's AI-related materials as protected work product and rejected the idea that AI use automatically destroyed the protection.

In Morgan v. V2X Inc., the District of Colorado reportedly protected AI-assisted work product but still required disclosure of the AI tool identity and amended the protective order around AI use.

In Jeffries v. Harcros Chemicals Inc., the District of Kansas approved protective-order restrictions on open AI tools for discovery materials based on retention, training, deletion, privacy, security, and clawback concerns.

That is the pattern to focus on. The cases are not asking whether AI is good or bad. They are sorting AI use into different legal buckets based on workflow facts.

That split is the point. A team can lose on confidentiality and privilege, still argue about work product, and separately face protective-order limits on what can be uploaded. It can preserve work-product protection and still be ordered to identify the tool or comply with AI-specific restrictions on discovery material. Treating all of that as one generic waiver question hides the real problem.

The New Question Is “What Exactly Happened?”

When AI becomes part of litigation work, the risk analysis turns on details such as:

  • Was the tool public, consumer-facing, or enterprise?
  • Did the platform reserve rights to retain, review, or train on the material?
  • Was the use directed by counsel?
  • Was the material privileged, attorney work product, or discovery produced under a protective order?
  • Did the user expose legal theories or mental impressions?
  • Is the identity of the tool itself discoverable?
  • Did a protective order prohibit or restrict uploads?

Those are workflow questions. A legal department or law firm cannot answer them well if its internal policy is just “use AI carefully.”

Privilege, Work Product, And Protective Orders Are Separate Questions

Another reason the workflow framing matters is that privilege, work product, and protective-order restrictions are not the same issue.

Attorney-client privilege turns heavily on confidentiality and protected communications made for the purpose of obtaining or providing legal advice. Work product turns on anticipation of litigation, mental impressions, and whether the disclosure was made in a way that substantially increases the likelihood the material will reach an adversary.

Protective-order restrictions can cut across both. A court may not need to decide that privilege was waived or work product was destroyed before it limits the use of public or open AI tools on produced material.

That means an AI workflow can create different results across the three lanes. One use pattern may be disastrous for privilege because it undermines confidentiality, while still leaving room for work-product arguments in some civil settings. Another use pattern may preserve internal confidentiality but run straight into a protective-order problem if discovery material was uploaded into a tool that the order does not permit.

The practical lesson is that “AI waiver” is often the wrong level of abstraction. Teams need to ask which doctrine or restriction is at issue and how the actual workflow maps onto it.

Protective Orders May Become The Fastest Constraint

The protective-order cases may be the most immediately important for everyday litigation.

Even when courts do not say AI use destroys privilege or work product automatically, they may still restrict what can be uploaded into public or open AI tools. That is especially true for discovery material, confidential business information, and materials produced subject to Rule 26(c) orders.

That makes protective orders one of the fastest ways AI use gets limited in practice.

Counsel may find that the immediate issue is not abstract doctrine, but whether the governing order:

  • bans public AI tools entirely;
  • bans AI uploads for confidential materials only;
  • permits only closed enterprise tools;
  • requires notice or agreement before AI use;
  • distinguishes between model providers and internal review tools; or
  • treats tool identity as discoverable information in later disputes.

In many matters, the protective order will be the first real AI policy that matters.

The Real Failure Mode Is Operational Drift

Most teams do not deliberately decide to waive privilege.

The more common failure mode is operational drift.

Someone uses a familiar public tool to summarize notes. A client pastes in sensitive facts without realizing the downstream implications. A pro se litigant relies on a chatbot to organize case strategy. A discovery team uses AI summarization before anyone asks whether the protective order permits it. Outside counsel and client assume the other side checked the tool terms.

Each step looks small on its own. Together, they can create a record that is hard to defend later.

That is why the problem is now better understood as workflow design. If the workflow does not force the right questions early, the doctrine gets tested later under bad facts.

What A Better AI Litigation Workflow Looks Like

A usable workflow should answer at least five questions before AI gets used in a matter:

1. What kind of material is involved? Privileged communications, counsel work product, confidential discovery, trade secrets, personal data, and public material should not all be treated the same way.

2. What kind of tool is being used? Consumer/public AI, enterprise AI, vendor-hosted tools, internal models, and matter-specific review tools carry different risk profiles.

3. What do the tool terms say? Retention, training, deletion, human review, security, auditability, and downstream sharing matter.

4. What do the court orders and client instructions say? Protective orders, outside-counsel guidelines, engagement terms, and client policies may impose stricter limits than the general law.

5. Who owns the decision? Someone needs to decide whether a particular AI use is allowed, defensible, and documented.

Without those checkpoints, telling people to "use AI carefully" is not much of a governance system.

What Firms And Legal Departments Should Do Now

Legal teams should consider:

  • separating rules for public AI, enterprise AI, and discovery-review tools;
  • prohibiting public-tool use for privileged, confidential, or discovery-protected material unless expressly approved;
  • building matter-opening questions around AI use, tool type, and protective-order restrictions;
  • reviewing outside-counsel guidelines and client instructions for AI-specific terms;
  • preserving enough workflow information to answer later questions about what tool was used and why;
  • training lawyers and staff on the difference between privilege, work product, and protective-order risk; and
  • updating protective-order negotiation positions to address open versus closed AI tools explicitly.

This is one of those areas where governance that sounds boring is actually what keeps the problem from becoming urgent later.

Bottom Line

AI privilege risk is no longer just a warning about confidentiality.

It is becoming a workflow problem shaped by tool choice, user role, litigation posture, protective-order language, and the facts of how the system was used.

The early cases do not say “AI always waives protection.” They say something harder and more useful: the legal result depends on what actually happened.

That means firms and legal departments need workflows that can answer those questions before a court does.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *