Skip to content

Regulation

Sam Altman said ChatGPT has no legal privilege—courts agree

By Editorial TeamUpdated Jul 27, 2026
Authority
US federal and state courts
Rule type
judicial decisions
Jurisdiction scope
US federal and state
Effective date
Jan 1, 2026
Source text
Read primary rule text ↗

Assume ChatGPT prompts and logs are not privileged; implement protective orders and enterprise AI governance.

This is a Q3 2026 legal-risk briefing, not legal advice. The issue is narrower than the broader debate over AI power, platform governance, or Sam Altman’s public warnings. The operational question for lawyers is whether a ChatGPT exchange can be treated like a confidential conversation, a privileged attorney work file, a discoverable business record, or something that should never have been typed into a consumer chatbot in the first place.

Sam Altman’s July 2025 podcast admission became useful because it was blunt: ChatGPT conversations are not legally confidential in the way many users assume, and they may be produced in litigation if the right discovery demand or court order reaches them.[1][2] The statement is not the law. It is more practical than that. It is a warning label from the platform side that now lines up with a fast-moving set of 2026 court fights.

The mistake is to turn that warning into an absolute rule. The 2026 record does not support “all prompts are discoverable” any more than it supports “all attorney AI use is privileged.” What it does show is uncomfortable enough: courts are willing to examine prompts, logs, outputs, platform settings, attorney involvement, and preservation decisions, and they are not reaching uniform conclusions.

Courtroom gavel with a glowing ChatGPT conversation bubble presented as evidence

The 2026 cases are a risk map, not a clean rulebook

The main case cluster now cited in privilege and discovery planning is Heppner in the Southern District of New York, Warner in the Eastern District of Michigan, Morgan in the District of Colorado, and Conservation Law Foundation v. Shell in the District of Connecticut. Arnold & Porter’s May 2026 practice guide and Reuters’ June 8, 2026 legal-industry reporting treat these rulings as conflicting signals on whether AI prompts and related logs are privileged, work product, discoverable, or subject to closer judicial review.[3][4]

That distinction matters. These are not appellate holdings that settle the issue nationwide. They are district-court rulings across different federal courts, with different procedural records and different theories of relevance, waiver, confidentiality, and attorney direction. For a litigation team, that is still enough to change behavior. A prompt history can no longer be ignored as an informal side channel.

CaseCourtWhy it matters for AI privilege and discovery
HeppnerSouthern District of New YorkPart of the 2026 federal cluster showing that AI prompts can become a discovery and privilege issue rather than an off-record research aid.[3][4]
WarnerEastern District of MichiganA separate federal signal that courts may test claims about AI-generated or AI-assisted materials through ordinary discovery mechanics instead of accepting broad confidentiality assumptions.[3][4]
MorganDistrict of ColoradoOne of the rulings contributing to the disagreement over when attorney direction, work-product doctrine, or privilege analysis may protect AI-related materials.[3][4]
Conservation Law Foundation v. ShellDistrict of ConnecticutShows the issue arising in complex civil litigation, where prompts, logs, and outputs may be examined as part of the factual record or discovery dispute.[3][4]

The source material supports a careful conclusion: the courts are split on treatment, not merely on rhetoric. Some rulings make it harder to argue that an AI exchange is categorically shielded. Others leave room for protection where the use is attorney-directed and fits within existing privilege or work-product principles. None creates a safe harbor for dumping client facts into a general-purpose consumer chatbot and assuming the result will be treated like a memo to counsel.

Why courts are pulling in different directions

The conflict is unsurprising because “AI prompt” is not a single legal category. One prompt may be a lawyer testing deposition themes under explicit attorney direction. Another may be an executive asking for deal strategy. Another may be a nonlawyer employee summarizing sensitive facts in a consumer account with unclear retention settings. A court looking at those records is not answering an abstract technology question. It is asking familiar procedural questions in an unfamiliar wrapper.

  • Who typed the prompt: outside counsel, in-house counsel, a business executive, a paralegal, or a nonlegal employee.
  • Why it was typed: legal advice, factual investigation, business planning, drafting, negotiations, or ordinary research.
  • What was disclosed: client confidences, litigation strategy, public facts, contract language, source material, or privileged analysis.
  • Where it was typed: a consumer account, an enterprise tenant, a law-firm-controlled environment, or another system with different retention and training settings.
  • How it was preserved and logged: whether prompts, outputs, audit trails, and account metadata still exist and can be collected.
  • What the discovery request seeks: the prompt text, the generated output, the underlying documents, user metadata, model settings, or all AI-assisted drafting history.

Those variables explain why a protective order negotiated in January can be inadequate by July. If the order says nothing about generative AI prompts, outputs, model logs, vendor retention, or AI-assisted summaries, counsel may be left arguing by analogy after the records already exist. That is a poor moment to discover that the platform settings, engagement letter, and internal AI policy do not line up.

Fortis v. Krafton shows how chat logs become damages evidence

Doctrine can sound abstract until a chat log walks into trial. Fortis Advisors v. Krafton, decided by the Delaware Court of Chancery in 2026, supplies the damages-scale example now missing from many AI governance decks. In that case, a CEO’s ChatGPT logs became trial evidence, and the decision voided a $250 million earnout.[5]

Smartphone ChatGPT conversation connected to courtroom documents and a dollar symbol

The lesson is not that every executive AI exchange will decide a case. Fortis is a single Delaware Chancery decision, with its own record and posture. Its value is more concrete: it shows the path from casual tool use to formal evidence. A conversation that may have felt like brainstorming became something a court could read, weigh, and connect to a major business consequence.

That path should worry legal departments more than a generic privacy warning. Business leaders often treat chat interfaces as transient. Litigation treats stored text differently. If logs exist, if they can be tied to a custodian, if they bear on intent or performance, and if no privilege theory fits, they may become part of the evidentiary record. Fortis gives in-house counsel a board-level example: the exposure is not limited to sanctions skirmishes or embarrassing production. It can reach deal economics.

The Fortis fact pattern also changes how acceptable-use policies should be explained. The point is not simply “do not use ChatGPT for sensitive work.” That instruction is too broad to enforce and too vague to audit. The clearer warning is that executive prompts can later be characterized as evidence of knowledge, motive, planning, valuation assumptions, negotiation posture, or performance expectations. Once framed that way, the policy stops looking like IT caution and starts looking like litigation hygiene.

The Florida AG complaint is serious, but it is not a ruling

The Florida Attorney General’s June 1, 2026 suit against OpenAI belongs in a separate bucket. The complaint alleges that ChatGPT acted as an accomplice to murder, a novel liability theory that extends well beyond ordinary discovery and privilege disputes.[6] It is serious enough to track, especially for product-liability, platform-safety, and consumer-protection lawyers. It is not, as of the source record available here, a judicial finding that establishes a settled legal standard.

That procedural posture matters. A complaint is an allegation. Without a ruling on the theory and without the defense filing in the available record, it should not be blended with Heppner, Warner, Morgan, Conservation Law Foundation v. Shell, or Fortis as if all are equivalent legal authorities. For privilege planning, the federal discovery cluster and the Delaware trial-evidence example carry the immediate operational weight. The Florida case is a watch item for a different kind of liability frontier.

Governance has to match the failure mode

The practical response is not a poster that says “be careful with AI.” The 2026 cases point to specific failure modes: unclear attorney direction, consumer-account use, missing protective-order language, unexamined retention settings, and prompt histories that were never mapped into a discovery plan. Arnold & Porter and Blank Rome’s mid-2026 practice guidance both support treating AI governance as a litigation-control problem, not only a technology-adoption problem.[3][7]

Failure modeGovernance response
Lawyers or business users paste sensitive facts into consumer AI accounts.Restrict privileged, confidential, regulated, and deal-sensitive work to approved environments with documented retention, training-use, access, and audit settings.
A party later claims prompts are privileged without a record of attorney direction.Document who directed the AI use, the legal purpose, the custodians involved, and how prompts and outputs were reviewed.
Protective orders do not mention generative AI materials.Add language covering prompts, outputs, logs, metadata, AI-assisted summaries, inadvertent disclosure, clawback procedures, and treatment of vendor-held records.
Discovery plans ignore AI systems used by executives, legal teams, or key custodians.Ask early whether relevant custodians used generative AI for disputed transactions, investigations, drafting, analysis, or communications.
AI outputs are copied into legal work product without tracking the source.Preserve enough context to distinguish attorney analysis, source documents, AI-generated text, and later human edits.
Policies ban sensitive AI use in theory but are never operationalized.Convert policy into intake questions, matter-opening checklists, approved-tool lists, training, and escalation paths for exceptions.

Enterprise tools reduce some risks; they do not create privilege

Moving from a consumer chatbot to an enterprise AI platform can matter. It may improve administrative controls, logging, retention choices, user management, contractual protections, and the ability to show that the organization made deliberate governance decisions. Those facts can help when counsel later has to explain how information was handled.

But enterprise status is not a privilege stamp. A court will still ask why the material was created, who created it, what was disclosed, whether confidentiality was maintained, and whether the privilege or work-product doctrine applies. The safer enterprise environment is a control layer. It is not a substitute for legal analysis.

Protective orders should stop treating AI as an afterthought

A protective order drafted for email, shared drives, and conventional document review may not answer what happens to AI prompts and outputs. The better draft anticipates the dispute before the collection fight starts. It should address whether parties must disclose generative AI use in document review or expert work, whether prompts and logs are within the scope of production, how inadvertent disclosure is handled, and whether court review will occur in camera when privilege is contested.

There is no single clause that fits every matter. A trade-secret case, a mass-tort matter, a government investigation, and a post-closing earnout dispute will not need the same language. The drafting question is narrower: if the other side asks for prompts, outputs, logs, or AI-assisted summaries six months from now, does the order give counsel a procedure, or only an argument?

Attorney direction has to be visible before privilege is challenged

If a lawyer directs AI use as part of legal analysis, the record should show that. Matter teams can document the legal purpose, identify the supervising attorney, specify the approved tool, restrict what information may be entered, and keep prompt-output records in the same governed environment as other work product. That documentation will not guarantee protection. It gives counsel something better than a retroactive affidavit trying to reconstruct why a prompt was written.

The same discipline applies to privilege logs. If AI-assisted materials are withheld, counsel should be prepared to describe them without revealing protected substance. If they are produced, counsel should understand whether the production includes prompt text, output text, metadata, account information, or only documents later drafted with AI assistance. Those are not interchangeable categories.

Acceptable-use policies should name the records they are trying to prevent

A useful policy does not need to describe every model. It needs to tell employees which records should not be created in the first place. Client confidences, unreleased financials, settlement strategy, merger negotiations, investigation notes, witness summaries, litigation theories, regulated personal data, and board materials should not be pasted into unapproved tools. If exceptions exist, they should require legal or compliance approval before use, not after a subpoena arrives.

Training should be built around examples people recognize. A partner asking ChatGPT to rewrite a public article is not the same risk as a partner pasting a privileged chronology into a consumer account. A CEO asking for generic negotiation tips is not the same as asking the system to analyze an earnout strategy tied to a live dispute. The policy should make those lines visible enough that business users do not have to invent them under deadline pressure.

The current operating judgment

Altman’s admission was not a privilege ruling. The 2026 cases are not a uniform national rule. Fortis is not proof that every AI log will decide a transaction dispute. The Florida complaint is not a liability holding. Those limits are exactly why lawyers should act now rather than wait for appellate neatness.

The defensible position in Q3 2026 is that ChatGPT conversations are not reliably privileged, courts are increasingly willing to examine or compel AI-related materials, and legal teams need governance that treats prompts, outputs, logs, and platform settings as potential litigation records from the moment they are created.

References

  1. TechCrunch report on Sam Altman’s Theo Von podcast comments, TechCrunch, July 2025.
  2. Tech Law Crossroads report on Sam Altman’s ChatGPT privilege comments, Tech Law Crossroads, July 2025.
  3. May 2026 practice guide on AI prompts, privilege, and discoverability, Arnold & Porter, May 2026.
  4. June 8, 2026 legal-industry report on AI prompts and discovery rulings, Reuters, June 8, 2026.
  5. Fortis Advisors v. Krafton, Delaware Court of Chancery, 2026.
  6. Reuters report on Florida Attorney General complaint against OpenAI, Reuters, June 1, 2026.
  7. Mid-2026 practice guide on generative AI governance and litigation controls, Blank Rome, 2026.

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory