A new and contested category of evidence - generative AI prompts and outputs - is taking shape in federal trial courts. Judges are ruling on individual discovery motions and, in doing so, are drawing the lines that will govern what litigants must hand over and what stays protected. Because no appellate court has weighed in yet, companies that wait for clarity risk learning the rules through a motion to compel or a sanctions order.
How courts are treating AI evidence
Courts are handling prompts and outputs as electronically stored information, or ESI. In Tremblay v. OpenAI, Inc., plaintiffs' lawyers used ChatGPT to test whether it would reproduce their copyrighted books. When the model returned detailed summaries matching the original works, counsel attached those results to the complaint as proof of infringement.
OpenAI demanded every prompt and output. The court protected the prompts as opinion work product and declined to compel undisclosed negative results, but ordered plaintiffs to turn over prompts, outputs, and account settings behind the favorable results they had already made public. The lesson is straightforward: once you share a favorable AI result, you may have to hand over unfavorable results too.
Other cases hinge on who directed the AI use. In United States v. Heppner, a represented criminal defendant used AI on his own initiative to outline his defense. A New York federal judge found no privilege because the platform is not a lawyer, and no work product because the material was not prepared by or at the direction of counsel. A Massachusetts judge reached the same result in Shealy v. Seaside Investments, LLC, where a represented party routed documents to ChatGPT with no attorney involved. The court declared the material unprotected.
Cases involving self-represented litigants add another layer. In Warner v. Gilbarco, Inc., a Michigan federal court protected a pro se plaintiff's AI-assisted work, reasoning that treating an upload as disclosure would gut work product protection in nearly every modern drafting environment. A Colorado federal court in Morgan v. V2X, Inc. agreed, finding the gap between party and attorney that doomed the claim in Heppner was not relevant.
A lawyer's prompt can carry mental impressions, but the output may not, placing it in a lower tier of protection. A prompt revealing what an attorney was thinking gets the strongest protection. A raw AI output, standing alone, is closer to fact work product and more vulnerable to a showing of substantial need.
Experts face new exposure
Experts must be cautioned. In Conservation Law Foundation v. Shell Oil Co., a magistrate judge held that a testifying expert's AI prompts are discoverable as part of their methodology. The decision remains under objection, but the direction is clear: when an expert uses AI, prompts and outputs may be fair game.
Setting the rules now
The duty to preserve now reaches AI prompts, outputs, and chat logs the same way it reaches email. A litigation hold that does not name them is deficient. Companies should sweep AI platforms into the hold, identify every location where that data lives, and direct IT to suspend automatic deletion when appropriate.
Opposing counsel are already writing requests for production and Rule 30(b)(6) topics aimed at AI prompts and outputs, the tools and vendors used, account and tenant settings, and AI governance policies. Depending on the case, a judge may compel a corporate designee to testify about retention periods and preservation steps.
Objections still matter, but overbreadth, proportionality, undue burden, and privilege must be framed with the emerging dividing lines in mind. In a meet-and-confer or on a motion to compel, counsel must be ready to explain who directed AI use, whether the fight is over a prompt or an output, why production may not be proportional to the case's needs, and whether the other side waived protection.
ESI protocols should account for AI-generated material by defining it as a category, identifying its sources and retention settings, and agreeing up front on the production format - native files, PDFs, or another form - before it becomes a mid-case fight. Protective orders should identify what each side can and cannot do with the other's confidential information inside an AI tool. The amended order in Morgan bars putting confidential material into any AI system unless the provider agreed not to train on the data, not to share it with third parties, and to delete it on request.
Why this matters for legal professionals
Five practice points carry weight until the circuits address these issues. Route legal AI work through counsel and closed enterprise systems, keeping confidential material out of consumer tools. Treat AI prompts and outputs as discoverable ESI and map them into your litigation hold and retention program. Build AI expressly into ESI protocols and stipulated protective orders. Craft objections and meet-and-confer positions around direction of use and proportionality to build resistance to targeted AI discovery requests. And serve AI discovery requests on opposing counsel - the responsive material may make your case. The record that the first appellate decision on AI privilege reviews will have been built by companies that either governed this material or did not.
Your membership also unlocks: