Written by: Pavla Vitkova, Esq.
Introduction
In recent years, Artificial Intelligence (“AI”) has become increasingly common in legal practice. While AI can make lawyers faster and more efficient, hallucinated cases and fake citations have become a real concern in litigation, as well as reckless dissemination of potentially confidential information. Courts have responded by adopting AI rules and policies requiring lawyers to take responsibility for the accuracy of their filings. Effective June 15, 2026, Florida Rule of General Practice and Judicial Administration 2.515 was amended so that every signature, whether by attorney or self-represented party, certifies that the cited authorities identified “exist and are accurately cited,” and courts may impose sanctions for any filing inconsistent with that representation.
The issue is not limited to lawyers. Clients and self-represented parties are also using generative AI to understand their cases, develop strategy, or test their lawyer’s advice. They often upload contracts, pleadings, discovery, court orders, or confidential communications from their attorney and ask AI to analyze or summarize them.
This is understandable. AI is a tool that can help translate complicated legal jargon into plain English. But the convenience carries real risks. AI may give confident but inaccurate answers, misunderstand the facts, misstate the law, or miss important procedural issues. More importantly, clients may unknowingly disclose privileged or confidential information to a third-party platform, raising serious questions about confidentiality, privilege, and waiver.
There have been only a few court decisions addressing the use of AI by clients or self-represented parties. This article summarizes them and offers a few key takeaways and tips for using AI as a client of Barakat + Bossa.
United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. 2026)
Perhaps the most alarming example comes from the Southern District of New York, where a federal judge held that strategy materials a criminal defendant generated using Claude were not protected by or attorney-client privilege or the work-product doctrine. Heppner learned he was the target of a federal investigation, and (on his own, without his lawyer’s direction) used Claude to prepare reports outlining his defense strategy, using information he had learned from his counsel. The reports were later seized during a search of his residence. At the onset, the Court expressly declined to apply Fed. R. Crim. P. 16 (b)(2)(A) (“[R]eports, memoranda, or other documents made by the defendant, or the defendant’s attorney or agent, during the case’s investigation or defense,” are not discoverable.) As such, the Court limited its analysis to the common law privilege issues.
Attorney-Client Privilege
The Court said that the attorney-client privilege is narrowly construed and protects only confidential communications between a client and an attorney made for the purpose of obtaining or providing legal advice. Heppner’s conversations with Claude failed on all three fronts.
First, the Court found that Claude is not an attorney, so the first prong failed. The privilege requires a trusting human relationship between the client and a licensed professional who owes the client fiduciary duties.
Second, the communications were not confidential because the version of Claude Heppner used was the free consumer product, and Antropic’s consumer privacy policy provides that inputs and outputs may be used to train the AI model, and Anthropic reserves the right to disclose such data to third parties even in the absence of a subpoena. As such, there could be no reasonable expectation of confidentiality. The Court emphasized AI-generated documents were not like confidential notes that a client prepares for counsel, because Heppner first shared the equivalent of his notes with a third party, Claude.
Third, the Court found that Heppner did not communicate with Claude for the purpose of obtaining legal advice. The key fact was that Heppner used Claude on his own, not at counsel’s direction. Had counsel directed the use, Claude might have been considered counsel’s agent. But later sharing the AI-generated documents with counsel did not make them privileged, because non-privileged communications do not become privileged simply by being shared with an attorney. The Court also noted that AI expressly disclaims providing legal advice.
Work Product Doctrine
The Court also rejected Heppner’s backup argument that the documents were protected “work product.” Work-product protection exists to protect counsel’s mental impressions and materials prepared by, or at counsel’s direction, in anticipation of litigation. Even if Heppner created the AI-generated documents because litigation was anticipated and he intended to share them with counsel, they were not prepared by counsel, at counsel’s direction, or by counsel’s agent. Even though they may have affected counsel’s strategy going forward, they did not reflect counsel’s strategy when created. Accordingly, work-product protection did not apply.
Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629 (E.D. Mich. 2026)
A different result was reached in the employment dispute Warner v. Gilbarco, Inc., where defendants sought discovery from a self-represented plaintiff concerning “all documents and information” related to her use of AI tools in the lawsuit. The Court denied the motion to compel, reasoning that materials a party prepares in anticipation of litigation are ordinarily protected from discovery, and because the plaintiff was representing herself, she was entitled to assert that protection over her own trial preparation, including preparation done with an AI tool.
The Defendants argued that the protection was waived by using the third-party platform ChatGPT, but the Court strongly rejected this notion. The Court said that “a work-product waiver has to be a waiver to an adversary or in a way likely to get in an adversary’s hand,” and ChatGPT is a tool, not a person. The Court found that the request was a fishing expedition into the Plaintiff’s mental impressions and thought processes. The Court agreed with Plaintiff that the pursuit of this information was “a distraction from the merits of this case[,]” and noted that Defendant’s theory “would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed.”
Morgan v. V2X, Inc., 2026 U.S. Dist. LEXIS 67939 (D. Colo. March 30, 2026)
Another case warranting discussion is Morgan v. V2X, Inc., another employment lawsuit with a self-represented plaintiff. There, the Court extended work-product protection to AI-generated materials prepared by the pro se plaintiff. The Court distinguished Heppner on two grounds: this was a civil case in the discovery stage, where Rule 26 (b)(3) protects the trial preparation of a party, not just a lawyer. The Court also distinguished Heppner based on the fact that Heppner acted entirely apart from his lawyer. In this case, there was a pro se party, acting both as a “lawyer” and party.
However, the plaintiff was compelled to disclose the name of the AI platform used, as this alone would not reveal any mental impressions the protection aims to shield. The plaintiff had already inputted confidential information into an AI platform, therefore defendant was entitled to know which AI platform was used, to review its user agreement, and to assess whether confidentiality was compromised.
The Court then crafted a protective order governing confidential information and AI use. The order barred parties from uploading confidential information to any AI platforms unless the provider was contractually 1) prohibited from using inputs for training, 2) prohibited from disclosing them to third parties except as necessary for service delivery, and 3) required to delete the data upon request.
The Court acknowledged that the rule may effectively bar most low- or no-cost AI tools from handling confidential data, potentially disadvantaging pro se litigants. Still, it found that the confidentiality risks posed by mainstream AI tools could not be ignored.
Jeffries v. Harcros Chemicals Inc., 2026 U.S. LEXIS 63182 (D. Kan. March 25, 2026)
Finally, in Jeffries v. Harcros Chemicals Inc., the Court took an even broader approach in a putative environmental class action involving alleged toxic emissions from a chemical facility. The Court amended the protective order to prohibit parties from uploading any discovery materials (not merely documents marked confidential) into public or “open loop” generative AI tools. The Court reasoned that open AI tools create unique security and control risks because information submitted to them may be used to train the model, making later clawback or deletion practically impossible. The Court also gave weight to case-specific concerns that the defendants operated in the chemical sector, which implicates critical infrastructure, essential services, data privacy obligations, and national-security-related risks. On that basis, the Court found good cause to require parties to use only closed or secure AI tools for all discovery materials.
Morgan and Jeffries signal a trend that matters even for parties represented by counsel: courts are writing AI restrictions directly into protective orders. If your case has a protective order, uploading case materials to an AI platform may violate that order, regardless of whether privilege would survive.
Key Takeaways
First, AI is not your lawyer. It may misunderstand the law, overlook deadlines or procedural requirements, or give confident but wrong answers. Using AI may also create privilege risks. Courts are still developing the rules, and some have held that materials shared with AI are not privileged. The safest approach is to speak to your attorney before using AI for your case. Your lawyer can help determine whether AI use is appropriate and give you directions on how to use it safely for litigation purposes. As Heppner shows, that direction is not a formality, whether your lawyer directed the use may just be the difference between protected and unprotected.
Second, do not upload confidential case materials into free or public AI tools, and confirm that none of your inputs will be used to train the model. Confidential materials include contracts, documents containing personal information, emails with your lawyer, and strategy notes. When in doubt, do not upload it. If a document would not be shared publicly, it should not be shared with an open AI platform.
Third, if you use AI anyway, keep your attorney informed. Do not assume that AI-generated notes, summaries, timelines, or strategy documents are automatically privileged. Courts may treat AI use differently depending on who used the tool, whether counsel directed it, what platform was used, and whether confidential information was disclosed. The safest course is to ask your attorney first, use only approved tools, and use them only the way your lawyer approved. The goal is not to avoid AI altogether, but to use it carefully, with attorney guidance, so that it helps your case rather than creating avoidable problems.
Pavla Vitkova is an attorney at Barakat + Bossa PLLC, located in Coral Gables. Vitkova commenced her legal career in the Czech Republic, where she earned her first law degree. Subsequently, she transitioned to the U.S. She graduated summa cum laude from Nova Southeastern University and now specializes in business litigation. Vitkova can be reached at pvitkova@b2b.legal.
This post is intended to provide general information regarding the use of artificial intelligence in legal matters, including potential confidentiality and privilege considerations. It does not constitute legal advice. For guidance tailored to your specific circumstances, please contact our team directly.




