Hashlogics
Answers

Can opposing counsel discover your firm's AI prompts in litigation?

Sometimes, and the deciding facts are who typed the prompt, where it lives, and what the vendor's terms allow. Counsel's prompts inside a system the firm controls are work product. A client's chats with a consumer tool were not.

Answered in short

5 things that decide this

  1. 01A lawyer's prompts to an AI tool, written in anticipation of litigation, are ordinarily opinion work product under Federal Rule of Civil Procedure 26(b)(3), because they record counsel's mental impressions and strategy. That protection is the strongest discovery shield a firm has.
  2. 02Prompts lose work-product protection when a client wrote them alone. In United States v. Heppner (S.D.N.Y., February 2026), a federal court held a defendant's chats with a consumer AI tool were neither privileged nor work product: the tool's terms allowed training on inputs, and no lawyer had directed the work.
  3. 03A firm also makes its prompts discoverable when it puts them at issue. Courts in sanction hearings over fabricated citations have ordered lawyers to explain which tool produced the filing and how, and a defence of 'the AI did it' waives protection over the prompts that prove it.
  4. 04AI prompts and outputs are electronically stored information. Once a litigation hold applies, your firm's AI logs are in scope like email, and a vendor that keeps its own copy can be subpoenaed. In 2025 a federal court in the New York Times case ordered OpenAI to preserve ChatGPT output logs, including chats users had deleted.
  5. 05The build that keeps prompts protected has three parts: counsel authors or directs them, they live in a matter-scoped system the firm controls, and the vendor's terms bar training and third-party access. Skip one and the shield has a hole.
The law

Two shields, and which one covers a prompt

Two doctrines protect a firm's litigation thinking. Attorney-client privilege covers confidential communications between lawyer and client for the purpose of legal advice. Work product, under Rule 26(b)(3) and its state equivalents, covers materials prepared in anticipation of litigation by or for a party or its representative. A prompt is rarely a communication with a client, so work product is the shield that matters.

Work product has a strong form and a weak form. Opinion work product, which holds counsel's mental impressions and legal theories, is almost never discoverable. Fact work product can be ordered produced if the other side shows substantial need. A prompt asking a model to attack the weak points in a witness statement is opinion work product in its purest form. Output from the model, edited by counsel, follows the same analysis.

That shield holds only while the material stays confidential. That's the lesson of Heppner. Judge Rakoff reasoned from the tool's own privacy policy, which permitted training on inputs, that no reasonable expectation of confidentiality existed. It reasoned from the fact that the defendant ran the tool himself, without counsel's direction, that nothing he produced was work product. Both findings reach the software a firm runs today.

Practice

Where firms lose the shield, and how to keep it

Firms lose protection over prompts in four recognisable ways. The client runs their own AI research and shares it later, which is Heppner. The tool's terms allow the vendor to retain, review or train on inputs, so a third party held the material all along. The firm relies on the AI's role to excuse an error, which puts the prompts at issue. Or the prompts sit in a personal account outside the firm's retention and hold process, where nobody can find or protect them.

Your fix is architectural rather than a policy memo. Every prompt is authored by or at the direction of counsel. It lives inside a matter-scoped system your firm owns, under vendor terms that bar training and third-party access. Your log labels each prompt with the matter and the lawyer, which is what a work-product assertion needs later. And the retention rule for AI logs matches your document retention, so a hold captures them the same way it captures email.

Visibility is what makes that defensible. LexPair, a legal platform Hashlogics built, gives admins full visibility into every lead, with role-based access control over who sees what. Your firm's AI layer wants the same properties. Every prompt is tied to a matter, access is limited to the matter team, and a partner can produce or withhold the record on a principled basis.

Tell clients not to run their own AI on the matter. Heppner's documents were seized from his own devices, and no engagement-letter clause reaches a client's private chatbot account. A sentence in the intake conversation does.

A prompt that survives a discovery fightLive
  1. Counsel authorsOr directs, in anticipation of litigation.
  2. Matter-scopedFirm-controlled system, not a personal account.
  3. Terms checkedNo training, no third-party access.
  4. LoggedMatter, lawyer, time, output.
  5. Hold appliesPreserved and withheld on the log.

One log proves supervision, and it doubles as the privilege log when the request arrives.

Questions, answered
01Do we have to produce our AI logs in discovery?+

You have to preserve them once a hold applies, and you may have to log them. Whether you produce them depends on whether counsel prepared them in anticipation of litigation and kept them confidential. Prompts that meet both tests are withheld as work product like any other draft.

02Are prompts protected if a paralegal or associate typed them?+

Yes, when they worked at a lawyer's direction on a matter in anticipation of litigation. Work product covers material prepared by a party's representative, not only by the lead lawyer. The record should show the direction, which a matter-scoped log does automatically.

03Is an intake chatbot transcript with a prospective client discoverable?+

A prospective client's communications with the firm are confidential under Rule 1.18 even if no engagement follows. Keep the transcript in your firm's own system under no-training terms. Leave it in a vendor's consumer product and the Heppner reasoning applies to it.

Updated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter