Four months ago, a federal judge in New York ruled that a defendant’s conversations with a public AI tool were protected by nothing at all — not attorney-client privilege, not work product. In June, a Texas judge looked at similar conduct and reached the opposite conclusion, expressly disagreeing with the New York court.
Both rulings are good law. Neither controls the other. If your organization operates in more than one state, that’s not a technicality — it’s the whole problem. Burt Garland, shareholder at Ogletree Deakins, joined Phil Brandt to walk through what the Texas court actually held, why it doesn’t cancel the earlier ruling, and what an employer does with a legal question the courts haven’t finished answering.
What’s Inside
2. Why this doesn’t erase the Heppner ruling
What the Texas court ruled
The Texas court held that purpose, not profession, decides whether an AI chat is work product. On June 3, 2026, Judge Grant Dorfman of the Business Court of Texas, Eleventh Division, issued a minute entry in Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, denying a demand that a party produce its conversations with an AI tool.
The reasoning sits in how Texas defines work product: material prepared or mental impressions developed in anticipation of litigation or for trial, by or for a party. Lawyers aren’t the only people who generate it. An HR leader who sits down with an AI tool because litigation is reasonably anticipated may be inside the protection, even though no attorney typed the prompt.
Two limits matter as much as the holding. The judge suggested that using a public AI tool did not automatically waive protection, because work product is generally waived only when material reaches an adversary or is substantially likely to. And he still ordered some AI-related material produced — including material covered by a protective order that had been fed into the tool.
“Routine business analysis does not become protected merely because a dispute later develops.”
— Burt Garland, Shareholder, Ogletree Deakins
Why this doesn’t erase the Heppner ruling
The two decisions are narrower than the headlines and they answer different questions. In United States v. Heppner, Judge Jed S. Rakoff found that a defendant’s independent use of a consumer AI platform destroyed confidentiality and forfeited both privilege and work product — reasoning we covered in When AI Becomes Evidence and that Garland analyzed in his own write-up of the case. The Texas court addressed only work product, only under Texas procedural rules, and only where the material was prepared in anticipation of litigation.
Read together, three variables decide the outcome: which doctrine you’re claiming, whether the work was directed toward anticipated litigation, and where you’re being sued. What both courts agree on is that the platform matters and the purpose matters more. That agreement is the part employers can actually build on. The disagreement is the part they can’t.
What a split means for a multi-state employer
Don’t build policy on the ruling you like. Garland’s guidance on the episode was direct: the governing law, the facts, the platform, the purpose, and how the information is handled can each change the analysis — and there are very few decisions in this area nationally, so the next one may move the line again.
The practical exposure isn’t the privilege fight anyway. It’s discovery. AI prompts, responses, and chat histories are electronically stored information, and ESI requests are now routine. Even when the content stays protected, the other side can often see that AI was used — and that alone can support further discovery into what it was used for.
And the obvious workaround doesn’t work. Phil floated it on the episode: just declare litigation at the top of every chat.
“If you start off every one of your prompts with ‘I am doing this in anticipation of litigation,’ the court is going to see through that fairly transparently.”
— Burt Garland, Shareholder, Ogletree Deakins
How to govern while the law is still moving
Govern to the strictest reading, because you don’t choose the forum. Anything you’d only do if the Texas rule applied is a bet on where the complaint gets filed.
Start where the exposure actually lives: investigations. Using AI to summarize witness statements, weigh credibility, draft findings, or evaluate a complaint creates stored material that can become relevant later — and unlike a hallway conversation, it has a timestamp.
Draw the escalation line now, while nothing is pending. Threatened litigation, a serious harassment or discrimination complaint, an agency charge, a whistleblower issue, or anything that triggers preservation obligations moves a matter out of everyday HR work. Your position is meaningfully stronger when counsel directed the work than when counsel reviewed it afterward.
Then handle the inputs. Sensitive facts — medical details, identified complainants, protective-order material — shouldn’t enter a public AI system because the prompt was convenient. Anonymize what you can. Enterprise platforms with contractual privacy, security, retention, and training controls reduce risk; they don’t create privilege.
Finally, put AI in writing. Name approved tools, restrict confidential and litigation-sensitive inputs, define escalation to counsel, and address retention and litigation holds. Protective orders should state explicitly whether discovery material can touch an AI system and which systems qualify. Then train HR and managers on the distinction that carries the most weight: using AI to work faster is not the same as using it inside a legal dispute.
Asked whether this is a technology problem, a policy problem, or a judgment problem, Garland didn’t hedge. It’s judgment — a policy cannot anticipate every prompt.
Frequently Asked Questions About AI Chats and Privilege
Are AI chats covered by attorney-client privilege?
No. AI is not counsel, and no ruling to date creates an attorney-client relationship with a tool. The Texas question was narrower: whether litigation-related material a party created could qualify as work product.
Does using a public AI tool automatically waive protection?
Not in Texas, on these facts. A federal court reached the opposite conclusion in February. Assume more risk on consumer platforms than on enterprise systems until the courts converge.
If we are sued in another state, does the Texas ruling help us?
Not directly. It is one minute entry from one court applying Texas procedural rules. Treat it as a signal, not a shield.
Do we have to preserve AI chats in litigation?
Assume yes when they are relevant. Litigation-hold procedures should address where AI chats live, who controls them, and whether they can actually be preserved.
The Bottom Line
The law here will keep moving, probably faster than your policy review cycle. What employers control today is governance: approved tools, a clear escalation line, retention rules, and people who can tell when a routine question has turned into a legal one.
Garland’s one-sentence rule is the one worth repeating to your team.
“Treat it like a postcard. Assume the prompt could someday be examined by a lawyer, a court, or an adversary — and make sure your people know when to stop typing and call counsel.”
— Burt Garland, Shareholder, Ogletree Deakins
If you’re unsure whether a situation has crossed that line, that’s what the AAIM hotline is for. Members can reach the Solutions Team at solutions.team@aaimea.org, and when a matter needs an attorney, we’ll say so plainly.
Want to hear the full conversation?
Burt also explains why an investigation can’t be used as both a sword and a shield, and what happens when the other side challenges your privilege log. Watch or listen to the full episode of This Week at Work.
AAIM in the Community
July 31: Central Illinois HR Conference
Aug 4 – 7: MOSHRM State Conference
Aug 24 – 26: SHRM Indiana Conference
Aug 30 – Sept 2: HR Florida Conference & Expo
Oct 9: Greater St. Louis SHRM Conference
Training
Contact Us
Headquarters
12851 Manchester Rd
Suite 150
St. Louis, MO 63131
Toll-Free: 800.948.5700


