A running log of how U.S. courts treat one question: when you put your words into a generative-AI tool, do they stay privileged — or private — at all? The body of law is young, fast-moving, and already split. This page tracks it, case by case.
Courts holding that routing material through a third-party AI vendor's servers stripped privilege, work-product protection, or any reasonable expectation of privacy.
Courts extending work-product protection to a litigant's interactions with generative AI — the other side of the split.
On a motion to amend the protective order, the court barred the parties from uploading any produced discovery material — even documents not marked confidential — into public, "open loop" AI tools. Its reasoning: data fed to open tools can't be clawed back, which makes the standard "return or destroy" obligation impossible to satisfy. But the order didn't ban AI. It drew a line through the middle of it.
"Defendants' proposal does not foreclose a party from using any AI Tools; it only prohibits using open AI Tools while allowing the use of closed AI Tools."
The court kept AI squarely on the table for the real work — document review, summarization, privilege review, entity extraction, and drafting — so long as it runs in a closed system.
Read the cases together and the fault line is clear. The courts that preserved protection (Warner, Morgan) treated AI as a tool used in the litigation's own protected workspace — often at counsel's direction, with the output kept in-house. The courts that broke protection (Heppner, Shealy, Fry) all turned on the same fact: the material was handed to a third-party, for-profit company whose terms let it keep and disclose what it receives.
Two of the three "broke" cases involved pro se or non-lawyer users reaching for the most helpful tool they had — and losing protection because of where that tool sends the data. That's a structural problem, not a prompting one. No paid-tier privacy toggle changes the core fact that the file traveled.
The one architecture the split can't reach is the one where nothing travels — where the model runs on hardware you own and the confidential file never reaches an AI vendor at all. In Jeffries, a court said as much out loud: closed, private AI stays on the table; open, public AI does not.
The Banksy Box runs the AI on hardware in your office — a closed system, not an "open loop." Your clients' words never reach a "private, for-profit research and artificial intelligence company."
See the Banksy Box Read the privilege deep-diveThis tracker is legal-news commentary by Banksy AI, not legal advice, and does not create an attorney-client relationship. Case summaries are drawn from the opinions and reputable secondary coverage; confirm any citation against the slip opinion before relying on it. Last updated September 2026.