Generative AI has quickly become part of everyday business. Employees are now regularly using tools like ChatGPT, Claude, Gemini, and Copilot, and turning to AI for help in summarizing documents, organizing thoughts, drafting communications, and even preparing for meetings with legal counsel.
However, what many users might not understand yet is that conversations with AI tools are not always private.
In fact, courts are increasingly being asked to decide whether AI prompts, chat histories, and AI-generated outputs can be discovered in litigation, whether entering confidential information into an AI platform risks privilege protections, and what obligations parties assume when using AI during a legal dispute. While the law is still developing, one thing is clear: businesses should think carefully before treating AI tools as private brainstorming partners.
What Are the Biggest Legal Risks Businesses Face When Using AI Tools?
Risk #1: Your AI Conversations May Be Discoverable
One of this year’s most significant recent decision addressing this issue is United States v. Heppner.
In Heppner, a criminal defendant used Anthropic’s Claude AI platform after learning he was the target of a federal investigation. According to the court, he gave Claude facts about the case, discussed defense theories, and generated materials intended to help him communicate with counsel. Those AI-generated materials later came into the Government’s possession.
The defendant argued the conversations were protected by attorney-client privilege and the work-product doctrine, but the court disagreed.
The court ultimately held that the communications with Claude were not privileged and were not protected work product because Claude was not an attorney, the communications were made through a third-party platform, and the defendant was not using the tool at the direction of counsel. As a result, the materials were discoverable.
For businesses, the takeaway is that information entered into an AI system may not receive the same protections users assume apply to private communications with their counsel.
That said, not every court has reached the same conclusion. For example, in Warner v. Gilbarco, Inc., the court issued an order finding certain AI-generated materials qualified as protected work product where the litigant used the tool at the counsel’s direction. And in Morgan v. V2X, Inc., the court reached a similar result even without counsel involved at all, reasoning that AI tools are “tools, not persons,” and that a pro se litigant’s use of one did not waive work-product protection over his underlying legal strategy. Even so, those courts still closely examined how the AI tools were used and expressed concerns regarding confidentiality and disclosure.
Risk #2: You May Jeopardize Privilege or Confidentiality
Even when AI-generated content is not ultimately produced in litigation, the use of AI tools can still create privilege and confidentiality concerns.
In Heppner, the court emphasized that Anthropic’s terms and privacy policies contemplated the collection and retention of user inputs and outputs and allowed disclosure under certain circumstances. Relying in part on those features, the court found that the defendant lacked a reasonable expectation of confidentiality.
Whether other courts will follow that approach remains to be seen, but businesses should assume that any information entered into a public AI platform may later be scrutinized by opposing counsel, regulators, or courts.
Risk #3: Sensitive Business Information May Leave Your Control
Companies have increasingly recognized that employees may inadvertently expose sensitive business information through AI tools.
In 2023, in one of the most widely reported examples, Samsung employees reportedly uploaded confidential company information and source code into ChatGPT. Following the incident, Samsung implemented restrictions on generative AI usage and reportedly reevaluated its internal AI policies.
Public companies have also begun warning investors about AI-related confidentiality risks. A growing number of SEC filings identify concerns that employees, contractors, or vendors could input proprietary business information into third-party AI systems. These disclosures highlight potential risks involving disclosure of trade secrets, exposure of confidential customer information, loss of intellectual property protections, contractual breaches, privacy and cybersecurity concerns, and increased regulatory or litigation exposure.
For organizations engaged in litigation, these risks can become even more significant. Internal investigations, dispute analyses, settlement discussions, and litigation strategies often contain highly sensitive information that could create serious problems if entered into an inadequately protected AI platform.
How Are Courts Responding?
Courts are increasingly addressing AI use proactively through protective orders and discovery management.
For example, in the Morgan case, the court modified the parties’ protective order to restrict the use of confidential information with AI tools unless specific contractual safeguards were in place, including limitations on data retention, training, and third-party disclosures.
Other courts have similarly approved or imposed restrictions designed to prevent parties from uploading confidential litigation materials into AI systems that may store, reuse, or disclose that information. As AI usage becomes more widespread, it is likely that protective orders, ESI protocols, and discovery agreements will increasingly contain AI-specific provisions.
Five Best Practices When Using AI During a Legal Matter
Businesses can reduce the risks introduced through use of AI platforms by adopting several best practices:
- Never upload privileged communications or sensitive litigation materials into public AI platforms.
- Use enterprise-grade AI tools that provide contractual safeguards regarding confidentiality, retention, and training, rather than publicly available tools.
- Understand how the platform stores, processes, and uses your data before entering sensitive information.
- Assume that every prompt could someday be reviewed by a regulator, judge, or opposing counsel.
- Consult legal counsel regarding your business AI usage when litigation, investigations, or regulatory matters are involved.
AI can be a powerful tool in litigation, but it’s paramount that businesses stop treating AI conversations like private brainstorming sessions. Courts are increasingly treating AI-generated content like any other form of electronically stored information, and what is entered into an AI platform today could become a key exhibit tomorrow.
As the law continues to develop, companies that adopt thoughtful AI governance practices and approach AI-assisted legal work with caution will be far better positioned than those who assume their AI chats are automatically private.
*Adham Hamed contributed to this article.