Introduction
As generative AI platforms become embedded in everyday legal workflows, a critical question has emerged: when you share confidential information with an AI chatbot, do attorney-client privilege or the work product doctrine still protect those communications? Recent US court decisions reveal that the answer is not necessarily straightforward—and that the two doctrines apply differently depending on the circumstances.
In the US, two distinct legal protections are relevant to AI communications. Attorney-client privilege protects confidential communications between clients and their attorneys (or their agents) made for the purpose of seeking or providing legal advice.[1] It belongs to the client, applies only when an attorney is involved, and can be waived by disclosure to third parties. Work product doctrine, by contrast, shields materials prepared in anticipation of litigation from disclosure.[2] It can protect a party’s own litigation preparation—even without an attorney—and has a different waiver standard: disclosure to a non-adversary does not necessarily destroy the protection.
AI platforms are not attorneys, owe no duties of loyalty or confidentiality, and often expressly disclaim any attorney-client relationship. When a client or attorney inputs sensitive information into a generative AI tool, both doctrines require careful analysis: who is communicating, for what purpose, under what terms, and with what expectation of confidentiality.
In this article, we examine recent split rulings from US federal courts addressing both privilege and work product, compare the US framework with Taiwan’s approach to confidentiality and evidentiary protections, and offer practical recommendations for multinational clients navigating this evolving landscape.
Split rulings from US federal courts on privilege and work product
Recent federal court decisions in New York and Michigan have produced divergent outcomes that demonstrate the fact-intensive nature of both the privilege and work product inquiries when AI is involved.
In United States v. Heppner, the defendant, who was represented by counsel, had his prompts to Anthropic’s Claude seized by the government upon arrest.[3] The court held that the AI exchanges were neither privileged nor protected work product for three key reasons. First, attorney-client privilege did not apply because the defendant communicated directly with an AI platform—not with his attorney or at his attorney’s direction—so there was no privileged attorney-client communication. Second, the defendant lacked a reasonable expectation of confidentiality because Anthropic’s terms of service and privacy policy permit disclosure of user prompts to third parties; by agreeing to those terms, the defendant effectively consented to potential disclosure. Third, the work product doctrine did not apply because the exchanges were not prepared in anticipation of litigation at counsel’s direction; merely sharing AI-generated responses with counsel after the fact could not retroactively convert them into protected work product.
In Warner v. Gilbarco, a civil employment discrimination case where the plaintiff proceeded without an attorney (pro se), the court found that the plaintiff’s exchanges with ChatGPT were protected under the work product doctrine.[4] Because the plaintiff used AI to prepare her legal arguments in anticipation of litigation, the court treated her exchanges as analogous to private notes or research—materials she created to prepare her own case. The court observed that sharing information with an AI tool did not waive protection because the plaintiff had no reason to believe her adversary would gain access to the exchanges, and there was no evidence that OpenAI’s terms required disclosure to adverse parties. As a result, the defendants’ request for production of the AI communications was dismissed as irrelevant and disproportionate, with the court calling the request a “fishing expedition.”[5]
The most important takeaway from these cases is that a user who agrees to platform terms permitting third-party disclosure may be found to have waived any protection that might otherwise apply. Beyond that threshold issue, the analysis is highly fact-specific: courts will consider whether the material was prepared in anticipation of litigation, whether counsel directed the AI use, and whether the user otherwise had a reasonable expectation of confidentiality. What remains unsettled is whether AI should be treated as a “third party” (whose involvement destroys confidentiality) or as a “tool” (that preserves it)—a question that future cases will need to resolve.
Taiwan’s framework: attorney confidentiality, evidentiary protections, and AI
Taiwan’s legal system, rooted in the civil law tradition, approaches confidentiality and evidentiary protections through a different lens than the US common law doctrines of privilege and work product. Under Article 36 of the Attorney Regulation Act, an attorney has both the right and the obligation to keep confidential any information learned in the course of performing professional duties and may not disclose or use it except as required by law or with the client’s consent.[6] This is an attorney’s professional duty of confidentiality—not a client-held evidentiary privilege in the US sense—though it serves a similar protective function. While Taiwan’s courts do not have a line of AI‑specific cases yet, they will likely look to the terms of service governing AI platforms and any confidentiality agreements in place between users and those platforms to evaluate whether protections apply. Restrictive user terms and proper audit controls will likely improve the chances that AI‑related communications remain protected from compelled disclosure in litigation.
Comparing US and Taiwan approaches
Notwithstanding some functional similarities, several aspects of the protective framework diverge between the two jurisdictions. In the US, the split outcomes in Heppner and Warner turned on different doctrines: Heppner rejected both privilege (no attorney involvement) and work product (no litigation preparation at counsel’s direction), while Warner applied work product protection to a pro se litigant’s own case preparation. Taiwan’s civil law system does not draw the same doctrinal distinctions. Instead, a Taiwan court would likely focus on whether AI-related material is relevant to a disputed fact, whether production is necessary to resolve that issue, and whether disclosure leads to undue harm to privacy, business secrets, or other protected interests.
The scope of discovery also differs. In the US, the Heppner court permitted seizure of the criminal defendant’s AI communications, while the Warner court dismissed AI-related discovery requests as a “fishing expedition.” Taiwan’s evidentiary and discovery-equivalent procedures are narrower and more court-controlled. Under the Code of Civil Procedure, a party seeking document production must identify: (i) the document; (ii) the disputed fact to be proved; (iii) the document’s content; (iv) the opposing party’s possession; and (v) the legal basis for a duty to produce it. The court orders production only where the disputed fact is material and the motion is justified. As applied to AI communications, this framework should make a blanket request for “all AI communications” more difficult than in the US, while still allowing a targeted request where the AI material is specifically identified and probative of a disputed issue.
Taiwan law also builds confidentiality and proportionality considerations into the evidentiary analysis. The duty to produce documents is enumerated, and documents relating to the action may still be withheld where disclosure would materially harm a party’s or third party’s privacy or business secrets.[7] Unjustified non-production may lead to adverse evidentiary inferences, but the court retains tools to condition the production. In practice, a Taiwan court considering AI-related materials would likely ask whether the requested material can be produced through redactions, non-public hearings, or other protective measures, rather than treating the material as categorically privileged or discoverable.
Where AI materials contain personal data, Taiwan’s Personal Data Protection Act (PDPA) adds a separate compliance layer. Collection, processing, and use of materials containing protected data must remain within the necessary scope of a specific purpose and be protected by appropriate security and maintenance measures.[8] An AI-related production request may raise not only evidentiary questions but also data protection issues, particularly where the material includes client identity, litigation strategy, or detailed communication logs. A court or regulator would therefore likely consider whether disclosure is necessary for litigation purposes and whether safeguards are needed.
Finally, the Heppner court’s finding that Anthropic’s privacy policy defeated the defendant’s expectation of confidentiality is a reminder that the terms governing a user’s relationship with an AI platform can have direct evidentiary consequences. In Taiwan, those terms would likely be considered alongside the PDPA, contractual confidentiality obligations, and any internal AI-use policies or vendor agreements. If the platform terms permit broad access, retention, or third-party disclosure, it may be harder to argue that the user reasonably preserved confidentiality. Conversely, enterprise terms, confidentiality agreements, and documented data protection safeguards may demonstrate to the court the confidential nature of AI-related material.
Conclusion
The US precedents discussed above demonstrate a universal risk: information exchanged with AI platforms may ultimately be subject to compelled disclosure in litigation, regardless of the user’s subjective intent to keep it confidential. Neither attorney-client privilege nor the work product doctrine provides automatic protection when AI is involved—each requires careful attention to the circumstances of use. This risk is not confined to the American legal system. Clients operating in Taiwan face their own challenges, particularly where Taiwanese courts may apply different analytical frameworks than US courts when evaluating confidentiality and evidentiary protections.
For multinational corporations and individuals, the safest course is to treat AI-generated communications as potentially discoverable in any jurisdiction until the law provides clearer guidance. This means adopting proactive policies that govern AI use in connection with legal matters. Best practices include:
- reviewing AI vendor terms and privacy policies carefully before using any tool in connection with legal matters, as Heppner demonstrates that such terms can be outcome-determinative;
- involving counsel in directing AI use for litigation-related work so that the resulting materials may qualify for work product protection, and ensuring that communications with counsel about legal advice remain privileged;
- implementing internal AI governance policies that address what information may be shared with AI platforms and how outputs are stored;
- considering enterprise-grade AI deployments that offer enhanced data privacy protections, including contractual commitments against third-party data sharing; and
- seeking jurisdiction-specific advice, as the applicable protections vary not only between the US and Taiwan but potentially between US federal circuits and different areas of Taiwanese law.
Amid this constantly evolving landscape, AI developers, legal practitioners, and clients alike are well-advised to keep a watchful eye on these developments, and we will continue to monitor them closely.
Because the content of this article involves foreign regulations that are subject to rapid change, we recommend that readers independently verify original sources.
This article was written by written by Gregory Buxton and Chi-hsien Nieh.
If you have any questions or require additional information on AI and its implications for attorney-client privilege, work product protection, and confidentiality, please contact Greg Buxton at gbuxton@winklerpartners.com.
[1] https://www.law.cornell.edu/wex/attorney-client_privilege
[2] https://www.law.cornell.edu/wex/attorney_work_product_privilege
[3] United States v. HEPPNER, 1:25-cr-00503, (S.D.N.Y.)
[4] Warner v. Gilbarco, Inc., No. 24-cv-12333, E.D. Mich.
[5] Id. at 12.
[6] https://law.moj.gov.tw/ENG/LawClass/LawSearchContent.aspx?pcode=I0020006&norge=36
[7] https://law.moj.gov.tw/ENG/LawClass/LawSearchContent.aspx?pcode=B0010001&norge=344
[8] https://law.moj.gov.tw/Eng/LawClass/LawSearchContent.aspx?pcode=I0050021&norge=6

