promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_promptdojo_

Privilege as code, and the log that survives a sanctions motion — step 1 of 8

Privilege is a routing question

You're in the legal studio. What you're doing this lesson: decide which memos may go into which AI tools — before someone pastes at 11pm. This is a practice drill, not legal advice. You do not need the cite-check or clause lessons to start.

This lesson is a teaching fixture. The drills use invented matters and a simplified routing table (a written list: this kind of document may enter this kind of tool). They do not state what privilege or work-product law requires in any jurisdiction, and they are not a substitute for counsel judgment on a live matter.

Two terms, once, in plain English:

  • Attorney-client privilege generally protects confidential communications made for legal advice. Facts are not privileged. A fact that appears in a privileged communication can still be discovered from a non-privileged source.
  • Work product generally protects materials prepared in anticipation of litigation. Its waiver analysis is not the same as privilege waiver.

They are different doctrines. There is no special AI exception that collapses those two doctrines into one waiver test.

What early-2026 federal decisions actually did is narrower and fact-specific. United States v. Heppner (S.D.N.Y., written order Feb. 17, bench Feb. 10) held that a criminal defendant's consumer Claude use, without counsel direction, was protected by neither attorney-client privilege nor work product: privilege failed confidentiality given the consumer terms; work product failed because the documents were not prepared at counsel's direction and did not reflect counsel's strategy. Warner v. Gilbarco, Inc. (E.D. Mich.) treated a generative-AI program as a tool, not a person, and found no work-product waiver from a pro se plaintiff's ChatGPT use, because work-product waiver generally requires disclosure to an adversary. Morgan v. V2X Inc. (D. Colo.) treated a pro se party's AI litigation prep as work product, while still requiring the tool's identity and amending a protective order so confidential material may enter an AI tool only under no-training (the vendor will not use your inputs to train the model) and no-unauthorized-disclosure contract terms. These are not three opinions on the same facts announcing one waiver rule. They are fact-bound. Counsel still has to brief the actual facts.

The professional floor was already written. ABA Formal Opinion 512 (July 29, 2024) mapped generative-AI use onto the Model Rules: competence including technological competence (Rule 1.1), client communication (Rule 1.4), reasonable fees — you bill time actually spent, not the time AI saved you (Rule 1.5) — confidentiality with informed consent, where boilerplate consent is inadequate (Rule 1.6), candor toward tribunals (Rule 3.3), and supervision of both people and tools (Rules 5.1/5.3). Florida Bar Opinion 24-1 added the state-level pattern: generative AI is permitted with reasonable confidentiality precautions, informed client consent recommended before confidential disclosure to a third-party tool. Your state has or is writing its own opinion — verify it by name before you rely on it; secondhand lists of state guidance age badly.

Now the practical failure mode. The moment protection actually gets risked is not a policy meeting — it's 11pm before a deadline, when a tired associate with a strategy memo and a chat window makes a one-second decision from habit. Any rule that must be remembered at that moment will eventually be misremembered. So the team writes a conservative hygiene table once, by counsel, in daylight. The table is the fixture you will code. It is not a holding:

  • Every tool the team touches gets classified before use: cleared or not, trains on inputs or not, who cleared it and when. That's Op. 512's Rule 1.6 vetting, cached as data.
  • Every request gets two fixture flags, decided by counsel looking at the document: privileged (treat this as attorney-client communication or work product that should not leave on habit) and confidential (client confidences). Real matters need a lawyer to decide which doctrine applies. The drill uses one stricter flag so the lookup stays consistent under deadline.
  • The router does the rest. Material counsel marked privileged moves only through a cleared, no-training tool — and even then it gets logged and flagged for a human to check whether a Rule 502(d) order (a court order that can limit how a disclosure affects privilege) or ESI-agreement coverage (the parties' written rules for electronic evidence) is even available. Confidential material never enters an uncleared tool. That is a conservative practice some commentators recommend. It is not a court holding that every AI disclosure waives protection, and it is not a court holding that a no-training tool preserves it. The 11pm decision becomes a lookup.

One boundary before the table, for the non-lawyers this path also serves: these rules govern assisting legal work under attorney supervision. Using AI to produce legal advice for others without a license is unauthorized practice of law — a statutory line, not an etiquette one. The router can enforce tool hygiene; it cannot make anyone licensed.