Courts shield AI prompts and outputs from discovery 13-Aug 20:27

Every litigator now confronts a question that did not exist five years ago: When a party uses a generative artificial intelligence (AI) tool to help prepare its case — drafting motions, testing arguments, organizing facts — are the prompts it typed and the outputs it received discoverable by the other side?

For opponents, an adversary's AI chat log is a record of theories considered, weaknesses acknowledged, and strategies in development. For the party that created it, the log is the digital equivalent of a ​legal pad covered in case-strategy notes.

In the space of two days this June, courts in two jurisdictions gave the first reasoned answers — and both came down on the side of protection. On June 3, 2026, the Texas Business Court held in Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, ‌No. 25-BC11B-0020 (Tex. Bus. Ct., 11th Div. June 3, 2026), that a litigant's ChatGPT conversations were protected work product.

The next day, the Supreme Court of New York, Nassau County, quashed non-party subpoenas seeking a litigant's AI prompts, uploads, and outputs in Assini v. Hayward, 2026 NY Slip Op 26086 (Sup. Ct., Nassau County June 4, 2026), recognizing that AI-assisted litigation preparation can qualify as protected trial-preparation material. Together, the decisions provide citable authority for protecting AI-assisted litigation work — and a roadmap for preserving that protection.

Assini v. Hayward: New York protects the pro se litigant's AI workspace

In Assini v. Hayward, the plaintiffs took direct aim at an adversary's AI account. They served a non-party subpoena on an AI provider seeking the self-represented defendant's prompts, uploaded materials, and outputs used to prepare filings and other case-related documents.

The court granted the motion to quash under Civil Practice Law and Rules (CPLR) 2304. The ruling rested on two key conclusions. First, the court ​held that a self-represented litigant may claim work-product and trial-preparation protection for AI-assisted case preparation.

Adopting the reasoning of Morgan v. V2X, Inc., 2026 WL 864223 (D. Colo. Mar. 30, 2026), the court agreed that confidential, strategy-focused AI use falls within the trial-preparation doctrine, whether the litigant's sounding board is a colleague, notebook, or chatbot. Second, the ​court held that using a commercial AI tool does not itself waive protection. The court rejected the argument that entering case strategy into a third-party AI service forfeits confidentiality.

The court also emphasized compliance with New York's AI rules (22 NYCRR Part 161) and warned that ⁠AI misuse remains sanctionable. Protection for AI work product, in other words, coexists with accountability for AI misuse — hallucinated citations and unverified filings remain sanctionable regardless of how the underlying chats are classified.

Tate Group: Texas extends work product to a represented party's chats

The Texas decision reaches further in one important respect. In Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, Judge Grant Dorfman held that ChatGPT conversations conducted by a ​party principal — not a lawyer, and not a pro se litigant acting as his own counsel — were protected attorney work product under the Texas rule, and that using ChatGPT did not waive the protection.

The defendants pressed United States v. Heppner, No. 23-cr-00321, 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), a federal decision rejecting similar privilege claims, but the court found it inapposite: The question ​was governed by the Texas work-product rule, not the federal standard Heppner construed.Texas Rule of Civil Procedure 192.5 defines work product to include material prepared or mental impressions developed in anticipation of litigation by or for a party or its representatives — language broad enough, the court concluded, to reach a party's own AI-assisted litigation preparation.

The ruling came with a significant qualification. While the chat logs themselves were shielded, the court ordered the plaintiff to disclose all discovery materials and work products that had been shared with ChatGPT — including materials produced under the protective order. The lesson is double-edged: The strategic content of AI sessions may be protected, but feeding an opponent's confidential documents into a third-party AI tool has consequences, and courts will use their supervisory powers to police what goes into the machine even as they protect what comes out.

The emerging doctrine – and its limits

Together, ​Assini and Tate Group sketch an emerging doctrine. AI prompts and outputs created for litigation are trial-preparation materials under the work-product rules applied in New York and Texas. The medium does not control; the purpose and content do. Both courts also rejected the argument that using a commercial AI provider automatically destroys confidentiality.

But the protection is neither absolute nor uniform. Federal ​courts may take a different path: Heppner suggests the federal work-product standard may be less protective, making forum selection significant until appellate courts provide further guidance. Waiver questions also remain fact-intensive.

Consumer AI tools with default data-retention or training settings present a harder confidentiality case than enterprise platforms with contractual confidentiality protections. Attorney-client privilege raises separate issues because a chatbot is not counsel, and litigants should not assume ‌communications with AI receive ⁠the same protection as communications with a lawyer. The analysis also changes when AI outputs are used for purposes beyond case preparation.

The protection also stops where a different discovery regime begins: expert practice. In Conservation Law Foundation, Inc. v. Shell Oil Co., No. 3:21-cv-00933, ECF No. 970 (D. Conn. May 18, 2026), a Connecticut federal magistrate judge ordered a party to produce the generative-AI prompts its testifying expert used to cull the document universe underlying her report, reasoning that the prompts were part of the expert's discoverable methodology under Rule 26 rather than protected notes, drafts, or communications.

The order, which remains stayed pending the district court's resolution of the plaintiff's objection, is consistent with Assini and Tate Group: Work product protects confidential litigation preparation, but a testifying expert's methods are discoverable so opposing parties can evaluate the reliability of an opinion.

As Tate Group also demonstrates, protected AI chats do not shield documents uploaded into the tool. The dividing line is simple: AI used privately to develop litigation strategy may be protected; AI used to generate evidence or expert opinions may be discoverable. Counsel should assume expert AI use will be ​discoverable and preserve prompts and outputs accordingly.

There is also the "substantial need" back door. Work-product protection, ​unlike privilege, can be overcome on a showing of substantial need and undue ⁠hardship, and ordinary (non-core) work product receives less protection than mental impressions and strategy. Opponents will argue that AI outputs are mere factual compilations subject to the lower tier. Expect the fights to move from "is it protected at all" to "which tier, and is the showing met."

Practical guidance for litigants and counsel

The decisions reward litigants who treat AI use with the same discipline they apply to other privileged workstreams, and they suggest several concrete practices.

Segregate litigation AI use. Prompts and outputs earn protection because they are created for litigation. Mixing case-strategy sessions with general business queries in a single account or ​thread invites line-drawing disputes and partial disclosure. Dedicated matters, dedicated accounts, and clear labeling strengthen the "because of litigation" showing.

Mind the confidentiality settings. Enterprise AI deployments with no-training commitments, retention controls, and confidentiality terms materially improve the waiver analysis. Consumer-grade tools with default data-sharing ​settings are the weakest footing on which to claim ⁠confidential work product — and, as Tate Group shows, sharing an opponent's protected documents with any third-party tool can trigger disclosure obligations of its own.

Counsel clients — including non-lawyers — early. Tate Group's extension of protection to a party principal's own chats is encouraging, but it is one trial-court decision. Clients should be instructed at the outset of a matter about which AI tools may be used for case-related work, under what settings, and with what materials. Protective orders should be updated to address AI tools expressly, both to restrict feeding produced documents into them and to anticipate discovery requests aimed at AI usage.

Prepare for both sides of the fight. The same doctrine that shields a client's AI sessions will shield the adversaries. Litigators should calibrate discovery requests accordingly — targeting AI-related information that falls outside ⁠protection, such as what produced ​documents were uploaded to third-party tools — and should be ready to log and defend their own clients' AI materials with the specificity privilege logs require.

Looking ahead

Assini and Tate Group are trial-court decisions, and the questions they answer ​will be relitigated in other states, in federal court, and eventually on appeal. But first decisions frame the field, and these two frame it favorably for parties that use generative AI thoughtfully in litigation.

Courts, meanwhile, are pairing protection with supervision — New York's Part 161 rules and the sanctions warnings in both jurisdictions make plain that shielded chats are not a license for unverified filings. For clients and counsel alike, the moment calls for deliberate AI ​governance in litigation: The protection is real, but it belongs to those who build the record to support it.