Sophisticated generative AI (Gen AI) models are increasing in use both by counsel and clients. Two recent US District Court decisions released one week apart in February of 2026, addressed claims of privilege related to Gen AI use, but came to opposite conclusions. In this article, we summarize the two US decisions and assess how Canadian privilege principles might apply on these facts.


United States v. Heppner (S.D.N.Y. 2026)

Heppner is a criminal case dealing with investor fraud. When the FBI executed a search warrant at the defendant’s home, it seized documents containing exchanges between him and Anthropic’s Gen AI platform, Claude, that occurred after he had received a grand jury subpoena.

On a production motion, the defendant asserted that these “AI Documents” were protected by attorney-client privilege and (i) included information learned from counsel; (ii) were made for the purpose of speaking with counsel to obtain legal advice; and (iii) were subsequently shared with counsel. The court disagreed, finding that the AI Documents were not privileged, because:

Claude is not an attorney.
The terms of Anthropic’s privacy policy precluded any reasonable expectation of privacy.
The defendant did not communicate with Claude to obtain legal advice: non-privileged communications do not become privileged by later sharing them with counsel.

The court focused on the fact that there was no reasonable expectation of confidentiality in using Claude, as a public, consumer-grade model. Moreover, the defendant was represented by counsel but was engaging with Gen AI independently. The court explicitly considered Claude a “third party” to whom disclosure was made by the defendant.

The court also held the documents were not protected by the work product doctrine (similar to litigation privilege in Canada) because they were not prepared “by or at the behest of counsel.”




Warner v. Gilbarco, Inc. (E.D. Mich. 2026)

The defendants in Warner sought to compel production of the self-represented plaintiff’s communications with ChatGPT and other AI tools. The court denied this request, holding that the information sought was “not discoverable” as it was prepared by a party in anticipation of litigation, and, even if it were discoverable, it would be subject to protection under the work product doctrine.

The court held that the plaintiff had not waived work-product protection, because such a waiver must be made to an adversary or in a way likely to reach an adversary. The court held that Gen AI programs are “tools, not persons” and agreed with the plaintiff that the exchanges were the plaintiff’s “internal analysis and mental impressions—i.e., her thought process.”

This provides an interesting contrast to Heppner, where the court seemed to treat Claude as more akin to a person than a tool. The different results in Heppner and Warner may also be explained by the fact that the plaintiff in Warner was self-represented and, in this way, was acting as his own attorney, whereas in Heppner, the defendant was independently engaging with Gen AI while he was represented.




Privilege under Canadian law

Solicitor-client privilege: Much like the US counterpart, the Canadian test for solicitor-client privilege requires that there be (i) communication with a lawyer, (ii) for the purpose of seeking or receiving legal advice, and (iii) an intent that the communication be confidential. As such, Canadian solicitor-client privilege would likely not protect the AI-exchanges in Heppner and Warner as the first and third elements of the test for this class privilege are not met.
Litigation privilege: In Canada, litigation privilege applies to material obtained, gathered, or prepared for the dominant purpose of existing or reasonably anticipated litigation. It applies for self-represented litigants and extends to non-confidential documents.1 Canadian litigation privilege is therefore broader than the work product protection in the US and could potentially cover the AI exchanges in both Heppner and Warner.

There has been no clear guidance yet on the application of privilege to uses of Gen AI in Canada. As a best practice, litigants should minimize disclosing prejudicial or confidential information to publicly available Gen AI platforms to minimize any risk of inadvertent waiver of privilege. Further, parties can expect documents containing exchanges with Gen AI platforms to become routine discovery requests.




Practical considerations and risk management

Clients are increasingly turning to Gen AI for legal advice on a broad spectrum of use cases, topics and issues. Some are using it to help engage with their counsel. Others are using it to devise their own legal strategies (and in some cases, contrary to the express advice of legal counsel). What these cases demonstrate is a risk to privilege when clients engage with Gen AI. These considerations require clear defensive guidance to clients and create new strategies to pursue in discovery.