Opposing counsel wants every prompt your client typed into ChatGPT about the case. Do you have to produce them?
Yes, the relevant ones, and privilege will not stop it. A client's solo conversation with a consumer AI tool has no lawyer in it, so it is not a confidential communication under Evidence Code section 952 and the section 954 privilege never attaches. The chat is a writing under section 250 and electronically stored information under Code of Civil Procedure section 2031.010(e), and if it is relevant it is discoverable under section 2017.010. The objections that hold are relevance under section 2017.010 and burden and intrusiveness under section 2017.020(a). The trap is the client who reacts to the request by clearing the history, because that turns a production problem into a spoliation problem.
- Is the client's chat privileged
- No. The privilege protects a confidential communication between client and lawyer, and there is no lawyer in a conversation with a chatbot Evid. Code 952, 954; United States v. Heppner (S.D.N.Y. Feb. 17, 2026, No. 25 Cr. 503 (JSR)) slip op. at p. 5, "the discussion of legal issues between two non-attorneys is not protected by attorney-client privilege"
- Is it work product
- Not in a California court. The statute protects the work product of an attorney, and a party's own session is neither an attorney's writing nor an attorney's work CCP 2018.030(a), (b). Elsewhere the courts have split four to one and Heppner is the one: Heppner at p. 9 against, Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 10, 2026), Morgan v. V2X, Inc. (D. Colo. Mar. 30, 2026), Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC (Tex. Bus. Ct. June 3, 2026) and Assini v. Hayward (Sup. Ct., Nassau County, June 4, 2026) for
- Is it discoverable
- Yes, if relevant. A prompt and an output are writings, the account history is electronically stored information, and both are within the general scope of discovery Evid. Code 250; CCP 2017.010; CCP 2031.010(e)
- The client pasted your advice letter into the tool
- Waiver risk, and it is real. Disclosing a significant part of the communication to a third party waives the privilege in that communication Evid. Code 912(a); Heppner, slip op. at pp. 7-8, fn. 3; Evid. Code 917(b) does not save it, Holmes v. Petrovich Development Co. (2011) 191 Cal.App.4th 1047, 1068
- The objections that hold
- Relevance, overbreadth, intrusiveness. The court shall limit discovery whose burden, expense or intrusiveness clearly outweighs the likelihood of leading to admissible evidence CCP 2017.010, 2017.020(a); protective order terms, CCP 2031.060(b). A privilege objection standing alone loses
- The client deleted the chats after the request arrived
- Spoliation exposure. Manual deletion is outside the routine, good faith operation safe harbor CCP 2023.030(f)(1), 2017.020(c); willful suppression inference, Evid. Code 413, CACI No. 204
- You produced an export with your own emails inside it
- Claw it back. Notice of the claim obliges the receiving party to sequester and return or lodge under seal CCP 2031.285(a), (b); the receiving party has 30 days to contest, (d)(1)
On this page
Why there is no privilege
Section 952 requires a lawyer at one end of the communication. A chatbot is not one, and no court has pretended otherwise.
A set of requests for production arrived on my desk this month asking for every prompt my clients had submitted to any generative AI tool about the dispute, and every output. My first instinct was privilege. It lasted about as long as it took to reread the statute.
"As used in this article, 'confidential communication between client and lawyer' means information transmitted between a client and his or her lawyer in the course of that relationship and in confidence by a means which, so far as the client is aware, discloses the information to no third persons other than those who are present to further the interest of the client in the consultation or those to whom disclosure is reasonably necessary for the transmission of the information or the accomplishment of the purpose for which the lawyer is consulted, and includes a legal opinion formed and the advice given by the lawyer in the course of that relationship." Evid. Code 952
Every element points at the lawyer. The information moves between a client and his or her lawyer, in the course of that relationship, by a means that keeps it from third persons. A client alone with ChatGPT at eleven at night satisfies none of it. There is no lawyer, no relationship, and the only other party to the exchange is a company whose terms of service say what it does with the text. Section 954 gives the client a privilege to refuse to disclose "a confidential communication between client and lawyer," and the chat is not one. The analysis ends there. Nothing about waiver has to be reached, because nothing attached in the first place.
The one decision that has faced the privilege question directly says exactly that. In United States v. Heppner (S.D.N.Y. Feb. 17, 2026, No. 25 Cr. 503 (JSR)) 2026 WL 436479, a securities fraud defendant who had already retained counsel and received a grand jury subpoena used the consumer version of Claude to generate about thirty-one documents of defense strategy, then gave them to his lawyers. Agents seized them at his arrest. Judge Rakoff held them neither privileged nor work product. "Heppner does not, and indeed could not, maintain that Claude is an attorney," and "[i]n the absence of an attorney-client relationship, the discussion of legal issues between two non-attorneys is not protected by attorney-client privilege." (Slip op. at p. 5.) The communications were also not confidential, because Anthropic's consumer privacy policy told users it collects inputs and outputs, trains the model on them, and may disclose personal data to third parties, so Heppner "could have had no 'reasonable expectation of confidentiality in his communications' with Claude." (Id. at p. 6.) Sending the documents to his lawyers afterward did not help: "non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel." (Id. at p. 7.)
California has no appellate decision on a party's AI chats yet. The closest analogy is Holmes v. Petrovich Development Co. (2011) 191 Cal.App.4th 1047, where an employee emailed her lawyer from a company computer under a policy that warned the system was monitored. The court called the emails "akin to consulting her lawyer in her employer's conference room, in a loud voice, with the door open" (id. at pp. 1051-1052) and held them not privileged (id. at p. 1072). A consumer AI account whose terms permit retention, human review and training is the conference room with the door open, and the client agreed to the terms the same way the Holmes plaintiff agreed to the monitoring policy.
Where a third party is in the exchange, the client also loses the presumption of confidentiality and has to prove the disclosure was reasonably necessary to the lawyer's purpose. Behunin v. Superior Court (2017) 9 Cal.App.5th 833 applied that rule to a client's communications with a public relations firm his own lawyer had retained, and the client failed to carry it. A client who typed the question into a chatbot instead of emailing the office is not going to do better.
Heppner is a federal criminal case. Why it still governs the analysis here
Heppner applied the federal common law of privilege and the federal work product rule, and a California court is bound by neither. What travels is the structure of the reasoning, because the two elements the court found missing are the two that section 952 makes explicit: a lawyer in the communication, and a means of transmission that keeps it from third persons. A California court applying section 952 to the same facts reaches the same place by a shorter road, since it does not have to reason from case law to the elements. The statute states them.
The federal posture matters in one direction only. If your case is in federal court, Heppner is the decision the other side will cite on privilege, and no court has yet disagreed with it there. Its work product half is a different story: three courts have declined to follow it, two of them federal, and the next section sets them out. Note also that Heppner is a criminal case, which is the ground the civil courts have used to distinguish it.
The client who pasted your advice letter into the tool
A solo chat was never privileged. Your letter was, until the client fed it to a company that keeps what it is given.
The second scenario is worse than the first and it is the common one. The client receives a four-page letter explaining the settlement recommendation, does not follow it, and pastes it into Gemini with the prompt "explain this to me." Section 912(a) waives the privilege "with respect to a communication protected by the privilege if any holder of the privilege, without coercion, has disclosed a significant part of the communication or has consented to disclosure made by anyone." The whole letter is a significant part of the communication. The provider is a third party. That is the waiver.
Two arguments against waiver exist, and both fail on these facts. Section 912(d) preserves the privilege for a disclosure in confidence that is "reasonably necessary for the accomplishment of the purpose for which the lawyer ... was consulted." The client will have to prove the chatbot was reasonably necessary to the representation, which is the Behunin burden again, and having the lawyer's letter explained by a machine instead of by the lawyer is not it. Section 917(b) says a communication does not lose its privileged character "for the sole reason that it is communicated by electronic means or because persons involved in the delivery, facilitation, or storage of electronic communication may have access to the content of the communication." Holmes confronted the same subdivision and held it "does not mean that an electronic communication is privileged when" the electronic means belongs to a third party, the user has been told it is not private and may be monitored, and the user agreed to those conditions. (191 Cal.App.4th at p. 1068.) An AI provider that trains on user content is not a passive carrier storing a message in transit, and the user clicked through the terms that said so.
Heppner reached the point in a footnote. Counsel argued the AI documents were privileged because they "incorporated information that we had conveyed to Mr. Heppner over the course of our representation." The court's answer: "even if certain information that Heppner input into Claude was privileged, he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party." (Slip op. at pp. 7-8, fn. 3.)
What the waiver reaches is the disclosed communication. Section 912(a) speaks of waiver "with respect to a communication," and the letter the client pasted is that communication. Your other letters, your file, and your conversations with the client are not automatically gone with it. Log the pasted letter as waived, since a motion to protect it will lose, and turn your attention to the copies of it sitting in the provider's account, which are now producible writings in the client's possession, custody or control under section 2031.010(b).
Work product, and why California is different
Other jurisdictions protect material prepared by or for a party. California protects the work product of an attorney. The word choice decides the AI chat question.
Four courts protected a party's own AI sessions as work product in 2026, each under a rule that protects what a party prepares. Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 10, 2026, No. 2:24-cv-12333) 2026 WL 373043 held that a work product waiver has to run to an adversary or in a way likely to put the material in an adversary's hands, and using ChatGPT is neither. Morgan v. V2X, Inc. (D. Colo. Mar. 30, 2026, No. 25-cv-01991-SKC-MDB) 2026 WL 864223 applied Federal Rule of Civil Procedure 26(b)(3), which covers a party's own preparation, to a pro se plaintiff's AI use, and ordered the identity of the tool disclosed. Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC (Tex. Bus. Ct., 11th Div., June 3, 2026, No. 25-BC11B-0020) held a company principal's ChatGPT conversations protected under Texas Rule of Civil Procedure 192.5(a)(1), which reaches material prepared "by or for a party," ordered a block of pages produced because they were not work product, and ordered the plaintiff to identify by Bates number every discovery material it had shared with the tool. Assini v. Hayward (Sup. Ct., Nassau County, June 4, 2026, No. 607683/2024) 2026 NY Slip Op 26086 quashed a subpoena served on OpenAI for a pro se defendant's entire ChatGPT account, on the conditional privilege for material prepared in anticipation of litigation in CPLR 3101(d). Heppner went the other way under the federal doctrine, because the documents "were prepared by the defendant on his own volition" and were not "prepared by or at the behest of counsel." (Slip op. at p. 9.) The Morgan court read Heppner as a criminal case and declined to follow it, and the Tate court said it disagreed with it outright. Outside California the question is contested, and Heppner is now the minority view on work product, whatever its standing on privilege.
California's statute does not have the "by or for a party" language, and the difference is decisive in state court.
"(a) A writing that reflects an attorney's impressions, conclusions, opinions, or legal research or theories is not discoverable under any circumstances. (b) The work product of an attorney, other than a writing described in subdivision (a), is not discoverable unless the court determines that denial of discovery will unfairly prejudice the party seeking discovery in preparing that party's claim or defense or will result in an injustice." CCP 2018.030
A homeowner's midnight session with ChatGPT is not "a writing that reflects an attorney's impressions" and it is not "the work product of an attorney." It is the work product of the homeowner, and the statute does not protect that. The only route back in is agency: a client who runs the tool at the lawyer's direction, on the lawyer's instructions, to produce something for the lawyer, has an argument that the output is the attorney's work product made through an agent. Heppner itself left that door open, noting the defendant "was not acting as his counsel's agent when he communicated with Claude." (Slip op. at p. 10.) No California decision has walked through it. Until one does, treat a client's self-directed session as unprotected and a counsel-directed one as an argument you may have to make. It is not yet a protection you have.
Even where the sessions were protected, something came out
The protective decisions are not clean wins. Tate Group protected the content of the sessions, ordered part of one document produced as not work product, and then required the plaintiff to identify by Bates number which discovery materials had been submitted to ChatGPT, which is an invitation to a protective order fight over whether confidential documents were handed to a third party. That court also told the parties to negotiate protective order language spelling out whether and how confidential information may go into an AI tool at all. Morgan protected the substance and ordered the identity of the tool disclosed. A responding party that wins the work product argument should expect to lose the metadata: which tool, which account, when, and what went in.
Read the posture before relying on any of them. Tate Group is a minute entry the court described as not final, with leave to any party to move for a formal ruling, and Assini is a trial court decision published uncorrected and subject to revision. Neither is appellate authority anywhere, and neither binds a California court.
What the requests look like
The sets now arriving define the tool, expand "document," and instruct preservation. Respond to the definitions in the set. Your template's definitions do not control.
The competent version has four parts. A definition of the tool, naming ChatGPT, Copilot, Gemini, Claude, Grok, Meta AI and Perplexity and reaching any comparable product whether used through a website, an app, or a feature built into a search engine, an email client, a word processor or a phone. A definition of "document" that starts from Evidence Code section 250 and adds every prompt, question or upload submitted to such a tool, every output, and every saved, edited or circulated version of an output. An instruction that prompts and outputs are documents and that the responding party is to preserve the account and conversation history of each tool and produce responsive material in the form the tool stores or exports it, with dates. And two categories: all prompts and outputs relating to the subject of the case, other than communications between the party and its counsel, and all documents created in whole or in part with such a tool that were sent to or received from anyone other than counsel.
Some sets add a fifth piece, an instruction that the responding party state whether any AI or technology-assisted review tool was used to identify, rank or withhold documents in responding. Nothing in the Civil Discovery Act requires that disclosure, and how counsel reviewed a production is counsel's impressions and legal theories under section 2018.030(a). Object to it and disclose nothing. It is a meet and confer tool for the propounding party and will not carry a motion.
The two categories, by contrast, are proper. They are particularized to a subject, they carve out communications with counsel, and they describe writings the party controls. The definition of "document" is proper too. Section 250 already reaches "every other means of recording upon any tangible thing, any form of communication or representation ... regardless of the manner in which the record has been stored," and an expanded definition only spells out what the statute already covers. An objection that the definition is overbroad because it names AI tools will not go anywhere.
How to respond
Privilege alone loses. The response that holds is built on section 2017.020(a) and a narrowed production.
Start with the set's definition of "document" and respond to the categories as defined. A response that asserts privilege over the client's solo chats and stops there invites a motion to compel further responses that the propounding party wins, with the mandatory monetary sanction that follows under Code of Civil Procedure section 2031.310(h) unless you acted with substantial justification or other circumstances make the sanction unjust. The 45-day clock on that motion is the propounding party's problem. A losing objection is yours.
The objections that do work are the ordinary ones, applied with some care. Section 2017.020(a) requires the court to limit discovery "if it determines that the burden, expense, or intrusiveness of that discovery clearly outweighs the likelihood that the information sought will lead to the discovery of admissible evidence." A request for a client's entire chat history across every AI account, untethered to the subject of the case, is the request that subdivision was written for: it reaches medical questions, the client's children's homework, and everything else a person types into a chatbot in a year. Object to scope and time, and produce the conversations that relate to the pleaded subject. A protective order under section 2031.060(b) is available if the propounding party will not narrow, and subdivision (b)(5) covers confidential commercial information where the party is a business.
Privacy is the other objection with teeth, because the material is personal in a way an email account often is not. Assert it, but understand what it does: it narrows the production to relevant conversations and supports confidentiality terms, and it does not exempt the relevant conversations from production. California's privacy balancing has its own body of law and this page does not restate it. The point here is that privacy is a scope objection. It is not a shield.
Then produce in the form the tool exports. The major consumer tools have export functions that return the conversation history with dates, and a demand that specifies that form is asking for something the client can produce in an afternoon. Review the export before it goes out, because a client who pasted your emails into the tool has put your emails inside the export. Redact or withhold those as attorney-client communications, log them, and remember that the ones the client pasted in are the ones section 912(a) has already taken. If a privileged communication goes out inside an export anyway, section 2031.285(a) lets you notify the receiving party of the claim, subdivision (b) obliges them to sequester the information immediately and either return it or lodge it conditionally under seal, and subdivision (d)(1) gives them 30 days to contest the claim by motion.
Preservation, and the client who clears the history
The chats were discoverable. The deleted chats become an inference the jury is told it may draw. The second is worse.
A client who gets the request, feels exposed, and deletes the account has converted a discovery response into a spoliation record. The Civil Discovery Act nowhere states when an obligation to preserve begins, but it legislates around one: sections 2023.030(f)(2) and 2017.020(c)(2) each provide that the safe harbor "shall not be construed to alter any obligation to preserve discoverable information." A party holding a served request for the very material it is deleting does not need the trigger date litigated. And the safe harbor does not reach a person clicking "delete." Sections 2023.030(f)(1) and 2017.020(c)(1) say that "absent exceptional circumstances, the court shall not impose sanctions on a party or any attorney of a party for failure to provide electronically stored information that has been lost, damaged, altered, or overwritten as the result of the routine, good faith operation of an electronic information system." A deliberate deletion is neither routine nor the operation of a system.
What follows is the ordinary spoliation toolkit. Evidence Code section 413 permits the trier of fact to consider a party's "willful suppression of evidence relating thereto," CACI No. 204 puts that inference in front of the jury in a sentence, and section 2023.030 supplies monetary, issue, evidence and terminating sanctions for misuse of the discovery process. The California Supreme Court refused to create a tort for a party's intentional spoliation in Cedars-Sinai Medical Center v. Superior Court (1998) 18 Cal.4th 1 in part because these remedies inside the case were thought sufficient, and Williams v. Russ (2008) 167 Cal.App.4th 1215 shifts the burden, once the loss is shown, to the party who lost the evidence, to establish a satisfactory excuse and the absence of prejudice. A homeowner who deleted a chat history the week after the request arrived will not enjoy explaining that at deposition.
The prevention is a sentence in an email. The day the request arrives, and preferably the day the engagement begins, tell the client in writing not to delete, edit or "clear" any AI conversation, account or history, whether it was created before or after the dispute began, and have them export the history now so the production is not dependent on a provider's retention settings.
Put it in the engagement letter
Every source that has spoken on it says the same thing: the engagement agreement is where the client learns this, before the client has done it.
The State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, approved November 16, 2023 and revised May 14, 2026, tells lawyers they "must consider disclosure to their client that they intend to use AI in the representation, including how the technology will be used, and the benefits and risks of such use," and that "[f]ee agreements should clearly communicate how fees and costs are calculated and the extent to which generative AI factors into the lawyer's rates." ABA Formal Opinion 512 (July 29, 2024) calls the engagement agreement "a logical place" for AI disclosures and client instructions (p. 9). Both are about the lawyer's use of the tools. Neither says a word about the client's, and the client's use is where the exposure is.
A working paragraph does four jobs in plain language. It names the tools the client actually uses and reaches the AI features built into search, phones, email and word processors, because a homeowner who thinks of Gemini as Google will not recognize "generative artificial intelligence." It states the legal facts: a conversation with the tool is a communication with an outside company, it is not privileged, it is not the lawyer's work product, and the provider may keep it, review it, train on it and disclose it. It tells the client what to do: do not put the case into these tools, do not paste the lawyer's communications into them, tell the lawyer now if you already have, and do not delete anything. And it discloses the lawyer's own use and how it bears on fees, which is the part the State Bar guidance and Opinion 512 actually require.
Two developments are worth watching and neither is law today. The State Bar's Committee on Professional Responsibility and Conduct has proposed amendments to rules 1.1, 1.4, 1.6, 3.3, 5.1 and 5.3 addressed to AI, including a definition of "reveal" in rule 1.6 that would reach exposing confidential information to a technological system where the exposure creates a material risk that the information is used inconsistently with the duty of confidentiality; public comment closed May 4, 2026 and nothing has been adopted. And SB 574 (Umberg), which passed the Legislature on August 31, 2026 and awaited the Governor's signature as this page was written, would add Business and Professions Code section 6068.1 and amend Code of Civil Procedure section 128.7 to bar inputting confidential client information into certain generative AI systems and to require verification of AI output in court filings. If it is signed, the lawyer-side half of the engagement paragraph stops being guidance and becomes a statutory duty.
What breaks if you get this wrong
The client deleted the chat history after the request arrived
Deliberate deletion is outside the routine-operation safe harbor of CCP 2023.030(f)(1) and 2017.020(c). The willful suppression inference under Evid. Code 413 and CACI No. 204 goes to the jury, and issue or evidence sanctions under CCP 2023.030(b), (c) are on the table. The content is gone and so is the client's credibility about what it said.
The client pasted your advice letter into a consumer tool
A significant part of a privileged communication was disclosed to a third party, Evid. Code 912(a), and neither the 912(d) safe harbor nor 917(b) rescues it on these facts. Holmes, 191 Cal.App.4th at p. 1068; Heppner, slip op. at pp. 7-8, fn. 3. The letter is producible. Log it as waived and contain the damage to that communication.
You objected on privilege alone and produced nothing
The objection is not sustainable for a solo chat, Evid. Code 952, 954, and an unsuccessful opposition to the motion to compel further draws a mandatory monetary sanction, CCP 2031.310(h). Serve a supplemental response before the motion is filed: scope and intrusiveness objections under CCP 2017.020(a), and a production of the relevant conversations.
The export went out with your own emails inside it
Notify the receiving party of the privilege claim under CCP 2031.285(a). They must sequester immediately and return the material or lodge it conditionally under seal, (b), and may not use it while a claim is pending, (c)(1). Excluding the ones the client had already pasted into the tool, which 912(a) has taken regardless.
The client used AI to draft their emails to you
The email the client sent you is a communication to a lawyer and remains privileged under Evid. Code 952, 954. The drafting session in the tool is a separate writing and is not.
Before the response goes out
Responding to a request for the client's AI conversations
- Ask the client, in writing, which AI tools and accounts they have used about the case, and instruct them in writing not to delete, edit or clear anything.
- Export the history from each tool now, dated, before any retention setting or a nervous client does it for you.
- Read the set's definition of "document" and respond to the categories as defined, not as your template defines them.
- Object to scope, time and intrusiveness under CCP 2017.020(a) for any category that reaches beyond the pleaded subject, and assert privacy as a scope objection.
- Object to any instruction demanding disclosure of your review methodology as attorney work product under CCP 2018.030(a), and disclose nothing.
- Review the export for your own communications before it goes out; withhold and log the ones the client received from you, and treat the ones the client pasted into the tool as waived under Evid. Code 912(a).
- Produce the relevant conversations in the tool's export form, with dates, and consider a protective order under CCP 2031.060(b) for the rest.
- Prepare the client for the deposition question, because the answer about a solo session is not privileged.
- Amend the engagement letter for the next client so the conversation happens before the chat does.