Host Justin Pierce talks to partner Calvin Nelson and former Venable counsel David Levie about how generative AI is creating a new and fast-moving set of questions about discoverability and attorney-client privilege.
Host: Justin Pierce
Guest: Calvin Nelson and David Levie
About AI and IP: The Legal Frontier
Venable's AI and IP: The Legal Frontier is a podcast to help your company use AI and IP law to gain a competitive edge. This season's episodes examine topics from AI and copyright to data licensing, trade secrets, and confidentiality.
Transcript
Read the transcript for AI and IP: The Legal Frontier - Season 2, Episode 3
Justin Pierce: 00:13
If you're a business leader or general counsel, you already know AI isn't just another tech trend. It's the next frontier reimagining and reshaping how companies operate and compete. With that transformation comes complexity around intellectual property, data rights, regulatory oversight, litigation exposure, and brand integrity. This podcast is designed to give you clarity. I'm Justin Pierce, cochair of Venable's intellectual property division.
Justin Pierce: 00:43
In this season, I'll talk with colleagues and industry leaders about how AI is reshaping business, ecommerce platforms, toy companies, industrial automation, luxury brands, beyond, and the legal strategies companies need to protect innovation while moving fast. Our goal is simple, to help you turn our legal insight into your competitive advantage. Welcome to season two of AI and IP, the Legal Frontier. This week, we're talking about AI chatbots and attorney client privilege. Hi, I'm Justin Pierce, a partner at Venable and co-chair of the firm's Intellectual Property Division.
Justin Pierce: 01:28
As generative AI becomes a day to day tool in business and legal workflows, it's also creating a new and fast moving set of questions about discoverability and privilege. Recent federal decisions are beginning to test whether prompts entered into AI chatbots can be protected, as attorney client communications or attorney work product, and when using AI may inadvertently waive or even destroy those protections.
Justin Pierce: 01:57
In this episode, venerable litigators David Levie and Calvin Nelson break down two February 2026 rulings that reach different conclusions, and explain why terms of service, confidentiality expectations, and attorney direction all matter. We'll also discuss practical steps companies and individuals can take to reduce risk before an AI prompt becomes an exhibit in litigation. With me are my colleagues, Calvin Nelson, a partner in Venable's IP division, and David Levie, a litigator in Venable who focuses on antitrust matters.
Justin Pierce: 02:37
So with that, let's start with you, David. Talk to us about this most recent case here in February 2026, the Heffner case.
David Levie: 02:45
Yeah. So I think what's interesting about these and Justin, your intro brought up a good point is these cases are coming out where the courts are exploring how does privilege play with respect to generative AI. And one of the issues that and this is why I said what what you said framing it as a communication is key here. Because I think before these cases, people may have looked at AI and thought, oh, it's like Google. It's not a communication.
David Levie: 03:19
Interesting. So how would this even come in how would privilege come into play? But when you drill down on it with most of these generative AIs, it's a chatbot. You are going back and forth or you're giving it information which distinguishes it from something like Google. So now you come into, alright, does privilege apply?
David Levie: 03:37
But on the flip side, could I also be waiving privilege?
Justin Pierce: 03:42
Big questions. Calvin, your thoughts.
Calvin Nelson: 03:44
Yeah. And then in the Hepner case, what you had was a criminal case pending in the Southern District Of New York where, the government seized the defendant's computers. And on those computers were basically the entire chat history. This particular defendant was, you know, feeding prompts into a generative AI model, just trying to figure out a a defense strategy that that defendant could ultimately share with his attorneys. So, that is a a big difference to, you know, as as David mentioned, Google where, you know, you do a search and it's kind of out there in the ether.
Calvin Nelson: 04:22
These were, you know, communications that were essentially being stored on a computer and were ultimately obtained by the government. And the question is, are those communications discoverable?
Justin Pierce: 04:35
In that particular case, that criminal defendant, I'm guessing would likely argue, hey, I was just doing this to get prepared to talk to my attorney. What did the court think of that kind of response?
Calvin Nelson: 04:48
Alright. Well, the court looked at it for through a couple of different lenses. Right? Number one was, you know, the lens of attorney client privilege, and that was pretty easily dismissed that that theory, because, Judge Rakoff said, look, this generative AI is not a lawyer.
Calvin Nelson: 05:05
So your communications with the AI is not a a conversation with an attorney. Right? The next step is, well, analyzing it as a attorney work product. The question there is, well, how involved were actual attorneys? Right?
Calvin Nelson: 05:21
The defendant himself was not an attorney. And some of the facts of the case showed that these communications with the AI chatbot were not directed by the defendant's attorneys. And and some of these communications actually predated the engagement of outside counsel. So, you know, Judge Rakoff in that case determined, well, it's questionable whether attorney work product would even apply to this in the first instance. But I think the real key in this case is the issue of waiver, which we can get into.
David Levie: 05:54
Yeah. And I think to be clear, Rakoff first ruled from the bench in about a two line opinion that came out and everyone sort of didn't know what to do with because it was the first of these types of opinions. And then about a week later, issued a written opinion actually analyzing all the issues. And so for instance, with respect to attorney client privilege, Rakoff did start out saying, it's not an attorney, so no privilege even don't pass go. But I think the more crucial aspect because a lot of people say, yeah, we know generative AI is not an attorney, that that's fine.
David Levie: 06:29
But the confidentiality aspect of it was really I think the the the aspect that our clients should pay attention to.
Justin Pierce: 06:37
And how so? Is that because there should or should not be a reasonable expectation of confidentiality?
David Levie: 06:44
Well, I think it depends. It's it's a creature of contract actually is what it's turned out to be. So in the Hepner case, the defendant was using a consumer level product, something that you'd get from the app store, something that maybe you buy or upgrade your plan, and they differentiated between an enterprise version, which for those that don't know would be something where your organization contracts with one of the AI generative AI vendors to allow for your entire company to use. And in those circumstances, one of the key aspects was confidentiality can be negotiated. So I think a lot of people might or might not know that with these LLM, the large language model generative AI, you can click a button that says allow my inputs to train the model.
David Levie: 07:39
Or you can turn that off. Right. That's supposed to be like the privacy safeguard for those that can't see. I'm doing air quotes here for privacy safeguard. But then I think that that's about the extent of privacy safeguards in those models.
David Levie: 07:55
Whereas with an enterprise version as I understand it, you can negotiate basically for it to be in what some people term like a sandbox.
Justin Pierce: 08:03
Yes.
David Levie: 08:03
Which means that none of it exits your version that is being used by your company. And those are the key differentiators for confidentiality. Rakoff said, in a consumer level, no expectation of privacy, no confidentiality. Whereas in an enterprise version, you might have negotiated it. So the information you're putting in, let's say your privilege information is not going out to anyone else.
Justin Pierce: 08:27
That's an important distinction between that public AI chatbot and enterprise one. One question I have for you just kind of on the fly as we think through this, what about right in between those two? Certain of our users, in fact, probably many are paying for a private or subscription basis use of one of the AI chatbots. Any thoughts on where that might sit?
Calvin Nelson: 08:53
Well, you know, I think Dave touched on that earlier. It's really about what do the terms say. And Judge Rakoff spent quite a bit of time, you know, highlighting the fact that this particular, AI that the defendant used, that it was pretty explicit in his terms to say, look. We may use your data to train. We, you know, there is no expectation of privacy there.
Calvin Nelson: 09:17
So you really need to look at the terms of service for whatever service you're you're using. And the fact of the matter is most consumer facing AI, those terms are pretty consistent where they're not they're making no secret about, look, we're gonna train on your data. There may be third parties that are able to view some of these prompts. And those are the things that you can negotiate in a enterprise, or, you know, if you're working for a large company, they they can actually contract with the AI developer to make sure that none of this data leaves the sandbox, so to speak.
Justin Pierce: 09:54
I suspect many of our clients and many people at this point in time probably are not aware that they should be looking at the terms and conditions of whatever AI chatbot they're using, whether it's a public one, whether it's a paid subscription, or even enterprise to try to understand the scope of confidentiality or what would be considered even a reasonable level of expectation when it comes to confidentiality.
Justin Pierce: 10:20
So in terms of what does this holding mean in the Hepner ruling, I have a couple questions. From a practical standpoint, how would a client, let's say a client of a law firm, work best with an attorney going forward in this age of AI to keep the most or at least the majority of their communications and input to their attorney or they're seeking advice protected underprivilege? And that's a question for both of you.
Calvin Nelson: 10:50
None of this is really a departure from what we've normally been advising our clients about. Right? You know, when we provide advice to our clients, we're typically giving them those admonitions to, you know, this is attorney client privilege. You don't want to disclose it to any any third parties, certainly.
Calvin Nelson: 11:09
So the question is kind of making sure that you tighten up all of those steps in the chain. The communication between the attorney and the client needs to be secure. You know, for attorney work product, you need to make sure that anything that the client is doing on any sort of AI back at their their system, it's a best practice would be to to make sure you can show that this was attorney directed. And maybe it's showing that, you know, an attorney asked me this question or gave me this information, making sure that's all documented right there.
Calvin Nelson: 11:43
Because what what I can see in the future, you know, when we have these privileged fights down the road, you're gonna need to produce some information to to really establish the privilege and the fact that the privilege was maintained. So it's really documenting where the information came from, who directed it. Hopefully, in most cases, it was directed by an attorney.
Justin Pierce: 12:06
David, your thoughts?
David Levie: 12:07
Yeah. I mean, I think adding on to what Calvin's saying, and we've talked a lot about this recently. So I think you look at Hepner in a way, and Justin, you brought up early on about how it's a criminal matter. I would say it's it's not setting up a bright line rule that we can say, okay, if you follow this, this is what you need to do, you're safe. I think what it is really doing is highlighting how this is a true issue for our clients.
David Levie: 12:31
And so they need to look at it from a number of ways and and I think some clients have started to approach this, but this really adds some expediency to it. So for instance, having an AI policy, I think is is very important, saying giving the rules of the road for companies using AI. And I think when I look at okay. What is my one of my worst fears coming out of this? It is privileged information.
David Levie: 12:59
I don't really worry about the attorneys at companies dealing with this, but it's really the, say, executives who because one of the ways that AI is being built as as being more efficient for everyone is that it can summarize information faster than a human can.
Justin Pierce: 13:16
That's true.
David Levie: 13:17
So one of my fears is you have some type of memo prepared by us at Venable, your outside attorney, your in house attorney, and an executive, a board member, anyone wants that, like how do I summarize this into three bullets. And they put that into an AI model and say summarize it, arguably depending on all the circumstances we've already discussed here, that memo may no longer be privileged.
Justin Pierce: 13:46
I think that's a big revelation and something that a lot of our audience probably like to hear more about or how to avoid that. So one area you mentioned right off the bat was having an AI policy. I think that's good, and it helps at least be one more rung on the ladder towards protecting yourself. I do wonder in scenarios where whether you're dealing with an executive at a company or just an individual client who's not at a company dealing with a personal matter, what might be some things that you would give them in terms of advice to pay attention to to maintain privilege?
David Levie: 14:21
So I think from one of the things, and this is just almost spitballing in terms of what could be best practices going forward given what's happening in the law, and I think it's gonna continue to evolve, is to when you give a client advice, we typically will put Privilege and Confidential Attorney Work Product. And we all know that that those are no those are not really magic words because it it the law is more complicated than that. But that you should also put some type of statement as in do not insert into generative AI or or something like that as part of that header. It's just a reminder to everyone. I think sometimes when I give privileged information, I'll put do not disseminate, but I think you need to be more specific.
David Levie: 15:07
And I'm not sure that's gonna save the day, but it will at least remind people as they're reading it to not necessarily potentially waive privilege.
Narrator: 15:19
Advertising law regulations are getting tougher and harder to navigate. On Venable's Ad Law Toolkit Show, hosts Len Gordon, Shahin Rothermel and their colleagues break down the latest risks and trends. From FTC investigations and privacy rules, to influencer marketing, green claims and state AG actions. Actions. Each episode gives brands practical insights to spot issues early and move forward with confidence. Search for the Ad Law Toolkit Show wherever you listen.
Justin Pierce: 15:54
Okay. Let's transition to the other case that came out on the same day in February, and this is the recent ruling in Warner, the Warner versus Gilbarco case. I'll start with Calvin on that. You wanna give us a quick summary of what that case was about?
Calvin Nelson: 16:12
Sure. You know, this is a like like you said, a case that came out coincidentally the same day. Right? Eastern District Of Michigan. He had a pro se plaintiff who's bringing an employment discrimination suit, and, they're pro se.
Calvin Nelson: 16:28
So they were essentially being their own lawyer. Right? So already, we have facts that are very different from the Hebner case, where arguably that pro se plaintiff should be given some protection for their litigation strategy. They used an AI model to, you know, put notes in, try to come up with theories, things like that for their litigation strategy. Where the Heffner case and the Warner case really diverge is in the treatment of the AI, the generative AI, where Judge Rakoff felt that I'm looking at these terms of service.
Calvin Nelson: 17:08
There is no reasonable expectation of privacy. You know, Judge Patti in in the Warner case is looking at generative AI just as any other tool that we use every day, particularly in the legal field. Right? So Judge Patti found that there is no real disclosure because it's no different from any other tool that you can use on the Internet to to assist you. And I thought that was very it kinda sets up the tension that will will you know, these are the first two cases.
Calvin Nelson: 17:38
I'm sure this will play out in the next few. It's funny because in the the first AI cases that come to court were all about basically attorney blunders, right, where they're filing briefs with hallucinations and things and not really dealing with the the the core issue of how this will impact legal work. And now we're finally getting to that here. How will courts view these AI tools?
Calvin Nelson: 17:59
Are they merely tools? Are they a means of waiver? Are they disclosure? I wouldn't be surprised if at some point down the road, we're looking at AI, like, well, could they qualify as providing legal advice such that, you you know, there could be some sort of attorney client privilege that could be asserted over the results of an AI prompt? We don't know, but we're we're gonna figure that out and these are just the first of what I'm sure are many cases to come down the road.
Justin Pierce: 18:27
Right. I expect the same. David, let me turn it to you on that particular case on some of the differences between Warner and Hepner. Can you talk to us a little bit, not only about the differences, but some of the takeaways in the holding in Warner and why they might be perceived as being different from what happened in the Hepner case.
David Levie: 18:48
Yeah. So I think the distinguishing factor comes down to whether or not the plaintiff was acting as their own attorney. So so the pro se aspect of it because while the confidentiality aspect was a little bit glossed over by Judge Patti in the Warner case, That was definitely an issue in Hepner that was somewhat of the death knell on the work product protection that could have been there. So this provided an extra layer of protection in the Warner case. I do think some people will try to distinguish the two between one being criminal and one being civil.
David Levie: 19:29
And the applicability of Rule 26, so Federal Rule Civil Procedure 26 which codifies attorney client privilege. But I don't think that that's necessary and I I don't buy into that distinction because the law about attorney client privilege is the same. And it's all just the common law.
Justin Pierce: 19:50
I want to explore that discussion. Calvin started it about AI being a tool and not a person. Certainly, that was a key factor in some of the reasoning of the the Warner ruling. For our audience sake, if AI is a tool, can you foresee any situation where still if it's viewed as a tool, you can end up in a situation where you waive privilege?
David Levie: 20:17
I mean, I think even viewed as a tool, if you follow Hepner, it's gonna come down to confidentiality. In the expectation of whether it's confidential. I mean, you you also have to remember, with respect to waiver of privilege, you have to be able to waive the privilege. So the person doing the searching has to be able to be someone within the company that can waive the privilege. So less likely that you really need to be concerned about whether, I don't know, some receptionist is out there doing something versus, as I said in my original example, a board member or the CEO is trying to summarize something.
Justin Pierce: 20:54
Sure. Sure.
Calvin Nelson: 20:57
And I think one other thing to I mean, I think we'll see how this plays out in future cases. But to me, the the Rakoff decision basically looking at, well, do you have a expectation of privacy in this whatever the platform is? That's a very interesting question in today's world where so many of our applications are cloud based. So we are no longer in the world of I type out a memo and I throw it in a filing cabinet and I have a key to that cabinet. I mean, we we are in a world where all my documents are saved on the cloud. I'm using search tools and every manner of tool I use in my day to day life is at some point probably cloud based. And using the Rakoff analysis that that has the tendency to kind of destabilize some of that a little bit because you're kind of like, well, is there any expectation of privacy anymore? Right?
Calvin Nelson: 21:55
You know, I I know for me in a law firm, probably I do have a higher expectation, a greater expectation of privacy.
Justin Pierce: 22:02
That's right.
Calvin Nelson: 22:03
If I am in house counsel at, you know, at a company, you know, are there safeguards in place? I mean, like, my documents, can they be viewed by other people? Right? Because if they're saved on the cloud or saved saved in some document management system. And would that be enough under the the Rakoff rubric to destroy that privilege?
Justin Pierce: 22:25
Yeah. Good input. Well, we've had a good discussion today. Covered a lot of topics and subtopics relevant to privilege in AI. I'd like to get into a couple of takeaways.
Justin Pierce: 22:35
As I see it, I see a couple and I'll ask you all for yours. But one that I walk away with for sure is you've got to get out of consumer level AI if you want any expectation of privacy, any expectation of the application of privilege or work product privilege. The other piece that I see with public chatbots or consumer AI is that distinction when you move towards enterprise or negotiated levels, which are much higher for confidentiality, then you move into the area where your communications with an attorney, certainly at a company level, would be regarded as privileged. So with that, I'll start with David. Takeaways for our audience today?
David Levie: 23:16
Sure. I think the main takeaway, and this is what I've seen more recently since the decision with my clients is there is a necessity to inform and educate clients in the entire company on these issues, not necessarily getting into the privilege nuance of it, but really explaining to them the importance of what we're talking about here and having those safeguards in place because there are we're seeing it. There are real life implications here that could result in a memo that talks about the entire legal strategy for a case on both sides, highlighting strengths and weaknesses that is then ultimately deemed to not be privileged.
Justin Pierce: 23:59
That definitely would be a, as you presented before, a nightmare or worst case scenario.
Calvin Nelson: 24:06
I completely agree with Dave. I think an ounce of prevention is worth a pound of cure in this this sense here. And the only thing I would add to that is kind of foresee the the potential privilege battle down the road and just document, you know, to the extent you're using an AI in your office environment, and it's based on, you know, you're getting direction from counsel, like, note that in your in your prompts. So it's very easy down the road where, you know, if you're gonna give it to a judge in camera to evaluate the the assertion of the privilege, it's very easy from the face of that those documents that, hey, this was done at the at the direction of an attorney, and that will give you a little bit sure foot to stand on with respect to privilege.
Justin Pierce: 24:51
Great point. Well, in closing here, thank you, Calvin. Thank you, David. It's been a great discussion today and look forward to having more.
Calvin Nelson: 25:00
Thank you. Thank you for having us.
Justin Pierce: 25:01
That's about all we have time for today. I want to thank David Levie and Calvin Nelson for helping us understand how courts are starting to treat AI chatbot communications, what that means for privilege and work product, and how organizations can avoid unintentionally waiving protections in litigation. You can read more about how Venable is helping businesses navigate the AI frontier by visiting venable.com/ai.
Justin Pierce: 25:31
Please join me next week when I sit down with Venable partner, Claudia Lewis, to talk about how AI is reshaping health, wellness, and beauty industries, how federal and state regulators are responding, and what companies must do to stay compliant while staying competitive.
Justin Pierce: 25:49
I'm Justin Pierce. Thanks for listening to AI and IP, the Legal Frontier.
