reportAI in CourtsAI Governance
AI chat logs, note-takers and privilege: what courts have compelled, protected and excluded, 2024 to 2026
17 rulings and opinions on AI privilege, discovery and AI-generated evidence, 2024 to 2026, coded by question, plus what five note-taker vendors say they keep.
Anthropic ClaudeMicrosoft CopilotOpenAI ChatGPT
Edited and verified by Cognesio LLP
Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓
In the United States, a federal judge held on 17 February 2026 that a defendant’s written exchanges with a consumer AI assistant were protected by neither attorney-client privilege nor the work-product doctrine, and a week earlier a magistrate judge in Michigan had held that a self-represented litigant’s ChatGPT queries and answers were protected work product. Those two decisions, United States v Heppner in the Southern District of New York and Warner v Gilbarco in the Eastern District of Michigan, are the first in which courts have said in terms whether what a person types into an AI tool can be kept from the other side. This report collects them and the fifteen other rulings, orders and ethics opinions from the United States, England and Wales and the European Union that decide, between 2024 and 5 September 2026, three questions: whether AI conversations and transcripts are privileged, whether they can be compelled in discovery, and whether AI-generated or AI-altered material can be put before a court as evidence.
It also reads what five meeting note-taker and assistant vendors say they keep and what they train on, because every privilege and discovery question in the register turns on a fact about retention that only the vendor’s terms answer. It is descriptive. It does not say what a lawyer or a client should do; it records what has been decided, ordered, published and promised, with dates.
Key findings
- Two federal courts reached opposite results on AI materials within a week of each other in February 2026. In Warner v Gilbarco (E.D. Mich., 10 February 2026) a self-represented plaintiff’s ChatGPT queries and responses were held to be work product, and disclosure to ChatGPT was held not to waive it because waiver “has to be a waiver to an adversary or in a way likely to get in an adversary’s hand”. In United States v Heppner (S.D.N.Y., bench ruling 10 February, written opinion 17 February 2026) about thirty-one documents recording a defendant’s exchanges with Anthropic’s Claude were held to be neither privileged nor work product, because the user “could have had no ‘reasonable expectation of confidentiality in his communications’ with Claude” given Anthropic’s privacy policy and because the documents were “not ‘prepared by or at the behest of counsel’”. A third court, in Morgan v V2X (D. Colo., 30 March 2026), followed Warner for a pro se plaintiff, distinguished Heppner because “no such gap exists in the pro se context” between party and advocate, and held that public AI tools’ data collection “does not eliminate all expectations of privacy or automatically waive protections”, while ordering the plaintiff to disclose the name of any AI tool he had used with confidential discovery material.
- The largest compelled production of AI conversations on the record is 20 million de-identified consumer ChatGPT logs, ordered by Magistrate Judge Wang on 7 November 2025 in the OpenAI copyright multidistrict litigation and affirmed by Judge Stein on 5 January 2026. The preservation order that preceded it, entered 13 May 2025, required OpenAI to “preserve and segregate all output log data that would otherwise be deleted”; it was terminated by stipulation on 9 October 2025 as of 26 September 2025, with the data preserved before that date retained except for requests originating in the European Economic Area, Switzerland or the United Kingdom.
- The Heppner court relied on the vendor’s own terms for the confidentiality finding: Anthropic’s privacy policy of 19 February 2025 said it collects “inputs” and “outputs”, uses them to “train” the model and may disclose data to “third parties” including “governmental regulatory authorities”. Of the five vendor statements read for this report on 5 September 2026, one (Otter.ai, policy effective 16 June 2026) says it trains its own models on de-identified recordings and transcripts; four (Fireflies, Zoom, Microsoft, Google Workspace) say customer content is not used to train models without permission.
- The first ruling on whether an AI note-taker is a party to the call or an eavesdropper came on 13 August 2026: in In re Otter.AI Privacy Litigation (N.D. Cal.) the court allowed federal Wiretap Act, California Invasion of Privacy Act and Illinois biometric claims to proceed because, as reported, “Otter does not just participate in meetings, it retains the recordings of the conversations and uses them to improve its own machine-learning models and services”. The order decides plausibility, not liability.
- Two bar opinions now govern lawyers’ use of AI recording tools in New York: the New York City Bar’s Formal Opinion 2025-6 (22 December 2025) requires that “clients must be notified, and their consent obtained, whenever their calls are being recorded by an AI-empowered system”, and Formal Opinion 2026-2 (5 August 2026) says the default with witnesses and opposing counsel “should be not to record” and that surreptitious recording breaches the conduct rules.
- Courts have excluded or sanctioned AI-generated evidence in four ways on the record: exclusion of AI-enhanced video after a Frye hearing (State v Puloka, Washington, 2024); terminating sanctions for deepfake exhibits (Mendones v Cushman and Wakefield, Alameda County, 9 September 2025, action dismissed with prejudice); exclusion of an expert declaration with AI-fabricated citations (Kohls v Ellison, D. Minn., 10 January 2025); and stopping an AI avatar mid-argument (Dewald, N.Y. App. Div., 26 March 2025). The one court that admitted AI-generated material, the Arizona sentencing court that played an AI video of a deceased victim on 1 May 2025, is under appeal; as of a 27 May 2026 report no decision had issued.
- No federal rule of evidence on machine-generated or AI evidence is in force. Proposed Federal Rule of Evidence 707 went to public comment on 15 August 2025, comment closed 16 February 2026, and on 3 to 4 June 2026 the Standing Committee declined to recommend it and returned it for further study with the deepfake question; the earliest effective date is after 1 December 2027. Louisiana’s Act 250 of 2025 (effective 1 August 2025) is the only statute in the Regulation Tracker that imposes a duty on counsel to verify exhibits for AI generation or alteration.
- The only rule anywhere in the record that requires AI-generated text to carry a machine-readable mark is Article 50(2) of the EU AI Act, in force since 2 August 2026 for providers, with generative systems on the market before that date given until 2 December 2026. The rule is written for transparency, not for evidence, but it is the first legal source of provenance data a court could ask for.
Why a client meeting is now a discovery problem
Three things changed between 2023 and 2026. First, the tools that record and summarise conversations moved from dictation software on a lawyer’s own machine to cloud services with their own retention and training terms; the recording is now held by a third party under a contract the client has not read. Second, litigants began using consumer AI to prepare for their own cases, and courts began to be asked whether those exchanges are the modern equivalent of notes to counsel or of a conversation with a stranger. Third, the largest AI providers became defendants in copyright litigation, and the discovery in those cases produced the first orders that treat hundreds of millions of people’s conversations as a corpus to be preserved and sampled.
The demand side shows the same shift. In the 5 September 2026 Semrush read for the US database, “ai legal defense evidence” carries 390 searches a month, “ai of deceased in court cases makes statement” 170 and “ai evidence” 110 (all in the published ai_court_us.csv); two AI-search fan-out strings, “ai chatbot legal liability” (390) and “ai note takers legal risks” (320), were read in the Keyword Magic view and recorded in the search-demand study rather than in a saved CSV. The first page for each is law-firm client alerts and vendor blogs. None of those pages lists the decisions. This report does.
Method and data
Primary documents read for this report, all on 5 September 2026 unless stated: United States v Heppner, No. 25-cr-503 (JSR), Dkt. 27 (S.D.N.Y. 17 February 2026), read from the CourtListener RECAP PDF by optical character recognition (the scan carries no text layer); Warner v Gilbarco, No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. 10 February 2026), read from a law-firm repost of the Lexis print; Morgan v V2X, No. 1:25-cv-01991, Dkt. 65 (D. Colo. 30 March 2026), read from the CourtListener RECAP PDF; In re OpenAI, Inc. Copyright Infringement Litigation, No. 25-md-3143 (SHS) (OTW), orders at ECF 551 (13 May 2025), ECF 559 (16 May 2025), ECF 688 (20 June 2025), ECF 922 (9 October 2025), ECF 734 (7 November 2025), ECF 910 (5 December 2025) and ECF 1021 (5 January 2026), read from CourtListener storage and two news-site mirrors; Mendones v Cushman and Wakefield, No. 23CV028772 (Alameda County Superior Court, order of 9 September 2025); the New York City Bar’s Formal Opinions 2025-6 and 2026-2; the Commission’s Article 50 guidelines and the transparency code as recorded in the Regulation Tracker; the June 2026 Standing Committee agenda book and September 2026 Judicial Conference reports for Rule 707 as recorded; the privacy or trust pages of Otter.ai (effective 16 June 2026), Fireflies.ai (updated 6 March 2026), Zoom (blog, 16 October 2025), Microsoft (learn.microsoft.com, page dated 9 July 2026, updated 18 August 2026) and Google Workspace (privacy hub, updated 14 August 2026).
Read as reported, not in the primary: the order in In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal. 13 August 2026), from the National Law Review’s account (the RECAP docket lists entries only to July 2026); the King County Superior Court’s ruling in State v Puloka (2024), from Greenberg Traurig’s alert of May 2024 and the ABA Litigation News report of autumn 2024; the Arizona appeal in State v Horcasitas, from Mealey’s report of 27 May 2026; the OpenAI chief executive’s remark on a podcast in July 2025, from Artificial Lawyer’s report of 28 July 2025.
Datasets: the SafeLegalAI incident collection, 150 records as of 5 September 2026 (/tracker/incidents.json), of which three concern AI-generated material put before a court rather than fabricated citations (Kohls v Ellison, Dewald, Elliott v New York Bariatric Group); the Regulation Tracker, 324 records (/regulation/documents.json), of which eight mention deepfakes and two (proposed Rule 707 and Louisiana Act 250) are evidence rules on AI-generated material. The tools directory covers legal-AI products and does not list general meeting assistants; the vendor table below was built from vendor pages for this report.
Classification. Each register entry is coded to one of three questions: privilege (does a rule of confidentiality attach), discovery (can the material be compelled or must it be preserved) and evidence (can AI-generated or AI-altered material be admitted or relied on). “Outcome” records what the court or body did, in its own words where a primary was read. Names of parties appear only as they appear in published decisions and orders.
Limits. Seventeen entries across three jurisdictions is a small record and a selection: it holds the decisions this site could find and read, not every discovery order that mentions AI. Three of the seventeen are read from secondary reports and are marked. Warner and Heppner are trial-level rulings with no appellate treatment. Vendor terms change without notice; each is dated. The report covers no jurisdiction outside the United States, England and Wales and the European Union, and it found no decided case in England and Wales on the privilege or discoverability of AI conversations.
The register
| # | Date | Matter | Court or body | Question | Tool | Outcome | Read |
|---|---|---|---|---|---|---|---|
| 1 | Mar 2024 | State v Puloka | Washington superior court (King County, per the ABA Litigation News report) | Evidence | Topaz Labs Video AI, Adobe | AI-enhanced Snapchat video excluded after a Frye hearing; the enhancement “did not show with integrity what actually happened, but instead used opaque methods to represent what the AI model thought should be shown” | Reported (GT alert, May 2024; ABA Litigation News, autumn 2024) |
| 2 | 10 Jan 2025 | Kohls v Ellison | D. Minn. | Evidence | GPT-4o | Expert declaration containing AI-fabricated citations excluded | Primary (tracker, verified) |
| 3 | 26 Mar 2025 | Dewald | N.Y. App. Div., 1st Dept | Evidence | AI avatar | Video stopped within seconds; appellant continued in person | Primary (argument record, tracker unverified) |
| 4 | 13 May 2025 | In re OpenAI Copyright Infringement Litig., ECF 551 | S.D.N.Y. (Wang, M.J.) | Discovery | ChatGPT | OpenAI ordered to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court” | Primary |
| 5 | 16 May 2025 | Same, ECF 559 | S.D.N.Y. (Wang, M.J.) | Discovery | ChatGPT | OpenAI’s motion for reconsideration denied without prejudice | Primary |
| 6 | 20 Jun 2025 | Same, ECF 688 | S.D.N.Y. (Wang, M.J.) | Discovery | ChatGPT | A ChatGPT user’s pro se motion to intervene to challenge the preservation order addressed | Primary |
| 7 | Jul 2025 | OpenAI chief executive’s podcast remark | None (public statement) | Privilege | ChatGPT | ”we haven’t figured that out yet for when you talk to ChatGPT” | Reported (Artificial Lawyer, 28 Jul 2025) |
| 8 | 9 Sep 2025 | Mendones v Cushman and Wakefield | Alameda County Superior Court, California | Evidence | Generative AI (deepfake video and altered images) | Terminating sanction: “The entire action is dismissed with prejudice”; the court identified “the lack of facial expressions, the looping video feed” as marks of generated video | Primary |
| 9 | 9 Oct 2025 | Same as 4, ECF 922 | S.D.N.Y. (Wang, M.J.) | Discovery | ChatGPT | Stipulation and order: the going-forward preservation duty “is terminated as of September 26, 2025”; data preserved before then retained, except EEA, Swiss and UK requests; named domains preserved going forward | Primary |
| 10 | 7 Nov 2025 | Same, ECF 734 | S.D.N.Y. (Wang, M.J.) | Discovery | ChatGPT | Production of “20 million retained, anonymized consumer ChatGPT output logs” ordered; OpenAI “has failed to explain how its consumers’ privacy rights are not adequately protected by” the protective order and de-identification | Primary |
| 11 | 22 Dec 2025 | NYC Bar Formal Opinion 2025-6 | New York City Bar Association, Professional Ethics Committee | Privilege | AI recording and transcription tools | Client consent required for AI recording; lawyers “should independently review any recording, transcript, or summary”; retainer provisions for client-selected tools; advise clients of “the risks of the loss of confidentiality and privilege” | Primary |
| 12 | 5 Jan 2026 | Same as 4, ECF 1021 | S.D.N.Y. (Stein, J.) | Discovery | ChatGPT | Objections to the 7 November and 5 December 2025 orders “denied and the orders are affirmed” | Primary |
| 13 | 10 Feb 2026 | Warner v Gilbarco | E.D. Mich. (Patti, M.J.) | Privilege | ChatGPT | Motion to compel a pro se plaintiff’s ChatGPT queries and responses denied: work product; no waiver by use of ChatGPT because waiver “has to be a waiver to an adversary or in a way likely to get in an adversary’s hand” | Primary |
| 14 | 17 Feb 2026 | United States v Heppner | S.D.N.Y. (Rakoff, J.) | Privilege | Claude | About thirty-one documents of a defendant’s exchanges with Claude held not privileged and not work product; question described as one “of first impression nationwide” | Primary (OCR) |
| 14a | 30 Mar 2026 | Morgan v V2X, Inc. | D. Colo. (Dominguez Braswell, M.J.) | Privilege and discovery (protective order) | ChatGPT, Claude, Gemini named as examples | Motion to amend protective order granted in part: Rule 26(b)(3) “can protect your mental impressions and litigation preparation materials, but you must disclose the name of any AI tool you used in connection with Confidential Information”; amended order bars putting confidential information “into any mainstream AI tool like standard ChatGPT, Claude, Gemini, or similar platforms” absent contractual safeguards | Primary |
| 15 | 5 Aug 2026 | NYC Bar Formal Opinion 2026-2 | New York City Bar Association | Privilege | AI recording tools | Consent of all parties before recording non-clients; with witnesses the “default practice should be not to record”; surreptitious recording breaches Rule 8.4 | Primary |
| 16 | 13 Aug 2026 | In re Otter.AI Privacy Litigation | N.D. Cal. | Discovery (retention and use of recordings) | Otter.ai | Motion to dismiss granted in part; Wiretap Act, CIPA, BIPA, unjust enrichment and UCL claims proceed; Otter treated as a third-party eavesdropper because it “retains the recordings” and “uses them to improve its own machine-learning models” | Reported (National Law Review) |
Two matters that belong beside the register but decide nothing yet: State v Horcasitas (Maricopa County Superior Court, sentencing 1 May 2025; appeal pending, briefing reported 27 May 2026), where an AI-generated video of the deceased victim was played at sentencing, and Elliott v New York Bariatric Group (Connecticut Superior Court, 6 August 2026, tracker unverified), where a self-represented litigant hid instructions to AI systems in white text in his filings.
Privilege
The privilege question has been answered twice, differently, and the difference is in the facts each court found about who prepared the material and what the vendor promised.
In Heppner the defendant, after receiving a grand jury subpoena and, the court found, “without any suggestion from counsel that he do so”, used Anthropic’s Claude to analyse his position; the government seized about thirty-one documents recording the exchanges. Judge Rakoff’s memorandum of 17 February 2026 rests the privilege holding on confidentiality. It quotes the privacy policy to which Claude users consent, “as of February 19, 2025”: Anthropic collects “inputs” and “outputs”, uses them to “train” Claude, and reserves the right to “disclose personal data to third parties in connection with claims, disputes[,] or litigation”. On that basis the defendant “could have had no ‘reasonable expectation of confidentiality in his communications’ with Claude”, and even if some inputs were privileged “he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party”. The memorandum also adopts the position that “all ‘[r]ecognized privileges’ require, among other things, ‘a trusting human relationship’”. On work product the holding is that the documents were “not ‘prepared by or at the behest of counsel’” and did not reflect defence counsel’s strategy. The court left a door open in one sentence: had counsel directed the use, “Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege”, citing the Kovel line of cases.
In Warner the plaintiff had no lawyer. The defendants moved to compel the ChatGPT queries and responses she had used to draft filings. Magistrate Judge Patti denied the motion on 10 February 2026: the material reflected her “internal analysis and mental impressions”, and under Sixth Circuit law “the work-product waiver has to be a waiver to an adversary or in a way likely to get in an adversary’s hand”. The opinion describes AI platforms as “tools, not persons, even if they may have administrators somewhere in the background”.
The third decision reconciles them. In Morgan v V2X, an employment case in the District of Colorado, the defendant asked the court to compel a pro se plaintiff to identify the AI tool he was using with confidential discovery and to amend the protective order. Magistrate Judge Dominguez Braswell’s order of 30 March 2026 (Dkt. 65) holds that the plaintiff “can assert work product protections in connection with his AI use”, as in Warner, and reads Heppner as a case where “there was a gap between the party and the attorney because the defendant acted entirely apart from his lawyer”, whereas “a pro se litigant is simultaneously the party and the advocate”. It accepts that public AI systems “collect user data for training and other purposes” but holds that this “does not eliminate all expectations of privacy or automatically waive protections”. The plaintiff was nonetheless ordered to disclose the name of any AI platform used with confidential information, because identifying the tool does not reveal his mental impressions, and the protective order was amended to bar confidential information from any AI service that transfers it onward or trains on it.
The two February decisions are consistent on their own terms. Heppner asks whether a client’s voluntary disclosure to a commercial third party destroys confidentiality and answers yes, citing the provider’s policy; Warner asks whether disclosure to a tool waives work product and answers no, because the tool is not an adversary. What separates them is not the AI but the doctrine invoked and the vendor’s terms in the record. Neither decision has been reviewed on appeal.
The lawyer-side rules arrived from the bar rather than the bench. Formal Opinion 2025-6 of the New York City Bar, issued 22 December 2025, answers “what ethical issues should attorneys consider when using, or when clients use, AI-enabled communications tools that can record, transcribe, and summarize conversations with clients”. It requires notice and consent for AI recording, independent review of transcripts and summaries, training and supervision under Rules 5.1 and 5.3, and, where a client brings its own tool, retainer provisions that recordings “prepared by AI tools selected or used by the client will not be deemed dispositive or binding as against the attorneys unless they are promptly provided”. It tells lawyers to “advise clients of the risks of the loss of confidentiality and privilege”. Formal Opinion 2026-2, issued 5 August 2026, covers non-clients: consent of all parties, no surreptitious recording, and a default of not recording witnesses. Neither opinion decides whether a transcript held by a vendor is privileged; both assume the risk exists and regulate the lawyer’s conduct around it.
The public statement most often quoted on the question is the one the OpenAI chief executive made on a podcast in July 2025, reported by Artificial Lawyer on 28 July 2025: “If you talk to a therapist or a lawyer or a doctor about those problems, there’s legal privilege for it … And we haven’t figured that out yet for when you talk to ChatGPT.” Seven months later the Heppner court cited the same absence of a “trusting human relationship” as a reason the privilege cannot attach.
Discovery of logs
The OpenAI copyright litigation produced the discovery record. On 13 May 2025 Magistrate Judge Wang ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court” (ECF 551 in the New York Times action, ECF 33 in the multidistrict docket). OpenAI moved for reconsideration; the motion was denied without prejudice on 16 May (ECF 559). On 20 June the court dealt with a ChatGPT user who had moved, pro se, to intervene “for the limited purpose of challenging discovery orders in this case that prejudice their rights” (ECF 688). The order was the subject of public statements by OpenAI and of press coverage describing it as reaching hundreds of millions of users; the court’s own orders do not put a number on it.
On 9 October 2025 the parties stipulated, and the court ordered, that the going-forward obligation “is terminated as of September 26, 2025” (ECF 922). The stipulation keeps the data segregated before that date, “except for output log data corresponding to user requests originating from within the European Economic Area, Switzerland, or the United Kingdom”, and commits OpenAI to preserve on a going-forward basis the logs of accounts associated with domains the plaintiffs listed. Paragraph 4 records that the stipulation “does not purport to waive, modify, or otherwise affect the parties’ obligations under Federal Rule of Civil Procedure 37(e)”.
The production order followed on 7 November 2025 (ECF 734). The dispute was over “20 million retained, anonymized consumer ChatGPT output logs”. OpenAI had proposed the 20 million sample itself in opposing a motion for 120 million, then in October offered to run search terms across it and produce only the hits. The court ordered the whole sample: OpenAI “has failed to explain how its consumers’ privacy rights are not adequately protected by: (1) the existing protective order in this multidistrict litigation or (2) OpenAI’s exhaustive de-identification of all of the 20 million Consumer ChatGPT Logs”, and had relied on a sampling decision in Concord Music Group v Anthropic without explaining why that court’s later order producing the entire five-million-record sample “is not similarly instructive here”. Judge Stein affirmed on 5 January 2026 (ECF 1021), recording that “in the ordinary course of its business, OpenAI has retained tens of billions of such logs”.
The Heppner court cited that affirmance for the proposition that AI users lack substantial privacy interests in conversations “voluntarily disclosed” to a platform that “retains [them] in the normal course of its business”. The discovery record and the privilege record therefore now point the same way for consumer tools: what the vendor keeps, a court can reach, and what a court can reach was not confidential.
The note-taker litigation asks the retention question from the other side. In In re Otter.AI Privacy Litigation, decided on the pleadings on 13 August 2026, the reported reasoning is that Otter “does not just participate in meetings, it retains the recordings of the conversations and uses them to improve its own machine-learning models and services”, which makes it “an independent party who uses the recordings to train its models for its own benefit” rather than an extension of the host. The claims that survived (federal Wiretap Act, California’s section 631 and 632, Illinois biometric privacy, unjust enrichment, unfair competition) will now proceed to discovery of Otter’s own retention; the claims dismissed were the computer-fraud, Washington privacy and most common-law privacy counts. A parallel biometric action against Fireflies.ai (Cruz v Fireflies.AI Corp., C.D. Ill., filed 18 December 2025) is at the pleading stage.
AI-generated and AI-altered evidence
The evidence entries divide into four outcomes.
Exclusion after a reliability hearing. In State v Puloka a Washington superior court judge (King County, per the ABA Litigation News report) held a Frye hearing on Snapchat video that the defence had enhanced with Topaz Labs’ Video AI and excluded it. As reported by Greenberg Traurig and the ABA’s Litigation News, the court found that the enhanced video “did not show with integrity what actually happened, but instead used opaque methods to represent what the AI model thought should be shown”, that the tools “have not been peer-reviewed by the forensic video analysis community, are not reproducible by that community, and are not accepted generally in that community”, and that admission would risk “a time-consuming trial within a trial”. The relevant community, the court held, was forensic video analysts; the product’s commercial adoption elsewhere did not establish acceptance in that community.
Terminating sanctions for fabricated exhibits. In Mendones v Cushman and Wakefield the Alameda County Superior Court suspected nine exhibits filed with a summary-judgment motion “of having been altered or created by generative artificial intelligence”. Of two videos purporting to show a witness, “certain characteristics … such as the lack of facial expressions, the looping video feed, among other things, suggested that these exhibits were products of GenAI—i.e., ‘deepfakes’”. After an order to show cause, a hearing on 9 September 2025 at which the plaintiffs did not appear, and findings that they had intentionally submitted false evidence, the court struck the complaint: “The entire action is dismissed with prejudice.” The order records that the question of a referral to the District Attorney was before the court.
Exclusion of AI-tainted expert evidence. In Kohls v Ellison the State of Minnesota’s expert on misinformation filed a declaration, drafted with GPT-4o, that cited two non-existent articles and misattributed a third; on 10 January 2025 the court excluded it. The tracker row records the court’s observation on the irony of an AI-misinformation expert relying on unverified AI output. The case is in the register because the declaration was evidence, not a brief.
Stopping AI in the courtroom. In Dewald a self-represented appellant had leave to play a video at oral argument on 26 March 2025 and played an AI-generated avatar; the presiding justice stopped it within seconds. No sanction followed; the appellant argued in person.
The one instance of AI-generated material admitted on the record is the Arizona sentencing in State v Horcasitas on 1 May 2025, where the court permitted the victim’s family to play a video in which an AI rendering of the deceased addressed the court in a script the family wrote. The defence announced an appeal within hours, as ABC15 reported; Mealey’s reported on 27 May 2026 that the defendant argues “the trial court erred in allowing an artificial intelligence-generated video of the victim to be played during the sentencing hearing” and that the state and victims answer that the video was identified as the sister’s work and “is no different than any other video shown at such proceedings”. No decision had issued on the last report read.
The rules that exist and the rules that do not
Proposed Rule 707. The Judicial Conference’s Advisory Committee on Evidence Rules proposed a new Federal Rule of Evidence 707 that would subject machine-generated evidence offered without an expert to the reliability requirements of Rule 702. The Standing Committee approved publication on 10 June 2025; comment ran from 15 August 2025 to 16 February 2026; the Advisory Committee reported “greater overall concerns” on 7 May 2026; and on 3 to 4 June 2026 the Standing Committee did not recommend action and returned the rule for revision alongside the separate deepfake proposal. The tracker record puts the earliest possible effective date after 1 December 2027. Until then, the federal courts decide AI-generated evidence under Rules 401, 403, 702 and 901 as they stand, which is what Puloka (under Washington’s equivalents) and Kohls did.
Louisiana Act 250 of 2025. Effective 1 August 2025, Louisiana added to its civil procedure a duty on counsel to “exercise reasonable diligence to verify the authenticity of evidence before offering it”, to disclose known falsification of the party’s own exhibits “including by AI generation or alteration”, and to raise a “reasonable suspicion” about an opponent’s exhibits at the pretrial stage, on pain of contempt and discipline. The tracker record notes that it applies to civil proceedings and does not address hallucinated citations. It is the only statute of its kind in the Regulation Tracker on 5 September 2026.
England and Wales. The judicial guidance on AI, version 3 of 31 October 2025, “addressed hallucinated case law and deepfake evidence” in the words of the tracker record and tells judges they may ask parties whether AI has been used. No practice direction on deepfake evidence exists in the civil or family courts, and this report found no reported decision in England and Wales on the privilege or discoverability of AI conversations. The Solicitors Regulation Authority’s warning notice of 17 August 2026 names client confidentiality among its concerns; the regulator outcomes report sets out its context.
European Union. Article 50(2) of the AI Act has required providers of generative systems, since 2 August 2026, to mark synthetic audio, image, video and text output “in a machine-readable format and detectable as artificially generated or manipulated”, with systems on the market before that date given until 2 December 2026 under new Article 111(4); Article 50(4) requires deployers to disclose deepfakes. The Code of Practice on Transparency of AI-generated Content, found adequate by the Commission on 8 July 2026, commits signatories to interoperable watermark detection by 2 February 2027. None of this is an evidence rule, and the EU AI Act report on this site records that no fine under the Act had been published by 5 September 2026. It is listed here because a court asked to authenticate a video from 2027 onward will, for the first time, have a legal source for provenance marks to look for.
What five vendors say they keep
Every privilege and discovery entry above turned on a fact about retention: Heppner on Anthropic’s policy, the OpenAI orders on what OpenAI “has retained” in the ordinary course, Otter on what Otter does with recordings. The table records what five widely used recording and assistant products said on the date read. It is a reading of published terms, not a test of practice, and it is not a ranking.
| Vendor and product | Document and date | Content used to train models | Retention as stated | Third-party model providers |
|---|---|---|---|---|
| Otter.ai | Privacy policy, effective 16 Jun 2026 | Yes: “training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”; no opt-out stated in the policy | ”for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law”; no period stated | ”Artificial intelligence service providers that provide backend support”; not named |
| Fireflies.ai | Privacy policy, updated 6 Mar 2026 | No: “We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training” | Meeting content “not … stored by any third-party vendor after processing”; account data deleted within 30 days of closure; no retention period stated for a live account’s transcripts | Listed on a separate sub-processor page (not read) |
| Zoom (AI Companion) | Blog post, 16 Oct 2025 | No: “we do not use any customer audio, video, chat, screen sharing, attachments, or other communications-like customer content … to train Zoom’s or its third-party artificial intelligence models” | Not stated on the page read; processing “within Zoom’s infrastructure” under the Zoom-models-only option | Third-party models used unless the Zoom-models-only option is selected |
| Microsoft (Copilot in Microsoft 365, incl. Teams) | learn.microsoft.com privacy page, dated 9 Jul 2026, updated 18 Aug 2026 | No: “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs” | Prompts and responses stored as “Copilot activity history”; “admins can also use Microsoft Purview to set retention policies”; users can delete their history; Copilot “opted out” of Azure OpenAI abuse monitoring with human review | OpenAI and Anthropic models as sub-processors; Anthropic models “currently excluded from the EU Data Boundary” |
| Google (Gemini for Workspace, incl. Meet) | Workspace privacy hub, updated 14 Aug 2026 | No without permission: “Workspace does not use customer data for training models without customer’s prior permission or instruction”; content “not human reviewed … without permission” | Gemini in Workspace prompts and responses “90 days to indefinite, as determined by admins”; Gemini app “up to 36 months, as determined by admins”; Meet notes retention not addressed on the page | Google models |
Two features of the table bear on the register. First, the one vendor that says it trains on recordings is the one whose retention and use is now the subject of a surviving wiretap claim; the Otter court’s reported reasoning turns on exactly that sentence in the terms. Second, the two enterprise suites put retention in the customer’s hands (Purview policies; admin-set periods), which is the fact the Heppner court said it did not have before it and hinted could change the privilege analysis for a tool used “at the direction of counsel”. None of the five pages states what the vendor does when served with a subpoena beyond the general privacy-policy language; Anthropic’s, as quoted in Heppner, does.
Timeline
| Date | Event | Source |
|---|---|---|
| Mar 2024 | State v Puloka: AI-enhanced video excluded after Frye hearing | Reported |
| 10 Jan 2025 | Kohls v Ellison: AI-tainted expert declaration excluded | Tracker (verified) |
| 26 Mar 2025 | Dewald: AI avatar stopped at oral argument | Tracker |
| 1 May 2025 | State v Horcasitas: AI video of deceased victim played at sentencing; defence appeal announced | Reported |
| 13 May 2025 | OpenAI preservation order (ECF 551 / ECF 33) | Primary |
| 16 May 2025 | Reconsideration denied (ECF 559) | Primary |
| 10 Jun 2025 | Standing Committee approves proposed Rule 707 for publication | Tracker record |
| 20 Jun 2025 | ChatGPT user’s intervention motion addressed (ECF 688) | Primary |
| Jul 2025 | OpenAI chief executive: no “legal privilege” for ChatGPT conversations yet | Reported |
| 1 Aug 2025 | Louisiana Act 250 in force | Tracker record |
| 15 Aug 2025 | Rule 707 comment period opens | Tracker record |
| 9 Sep 2025 | Mendones: terminating sanctions for deepfake exhibits | Primary |
| 9 Oct 2025 | Preservation duty terminated as of 26 Sep 2025 (ECF 922) | Primary |
| 31 Oct 2025 | England and Wales judicial guidance v3 addresses deepfake evidence | Tracker record |
| 7 Nov 2025 | 20 million consumer ChatGPT logs ordered produced (ECF 734) | Primary |
| 18 Dec 2025 | Cruz v Fireflies.AI filed (C.D. Ill.) | Reported |
| 22 Dec 2025 | NYC Bar Formal Opinion 2025-6 | Primary |
| 5 Jan 2026 | Judge Stein affirms the production orders (ECF 1021) | Primary |
| 10 Feb 2026 | Warner v Gilbarco: ChatGPT materials are work product; Heppner bench ruling | Primary |
| 16 Feb 2026 | Rule 707 comment closes | Tracker record |
| 17 Feb 2026 | Heppner written opinion: Claude exchanges not privileged | Primary |
| 30 Mar 2026 | Morgan v V2X: pro se AI use is work product; tool name must be disclosed; protective order amended | Primary |
| 3 to 4 Jun 2026 | Standing Committee declines to recommend Rule 707; returned for study | Tracker record |
| 2 Aug 2026 | EU AI Act Article 50 marking and deepfake disclosure apply | Tracker record |
| 5 Aug 2026 | NYC Bar Formal Opinion 2026-2 | Primary |
| 6 Aug 2026 | Elliott: hidden AI instructions in filings sanctioned | Tracker (unverified) |
| 13 Aug 2026 | In re Otter.AI: core wiretap and biometric claims proceed | Reported |
| 2 Dec 2026 | EU Article 50(2) marking mandatory for pre-existing generative systems | Tracker record |
What to watch
The Heppner opinion leaves the enterprise question open in one sentence, and the next case will be one in which counsel directed the use of a tool whose terms promise no training and customer-controlled retention. The two enterprise tables above are the facts such a case would turn on. Warner and Heppner may both be cited without either being reviewed; neither party has sought appellate review on the record read.
In the Otter litigation, the surviving claims proceed to discovery of Otter’s retention and training practices, which will put on a public docket the facts that vendor policies describe in general terms. The Fireflies action tests the biometric theory separately.
The Arizona Court of Appeals’ decision in Horcasitas will be the first appellate word on AI-generated victim material at sentencing. The Advisory Committee’s revised Rule 707 and its deepfake proposal will return to the Standing Committee no earlier than 2027. In the European Union, 2 December 2026 is the date from which every generative system on the market must mark its output, which is the first provenance signal an authentication argument could rely on.
The regulation tracker carries each instrument; the incident tracker will add rows for Heppner, Warner, Mendones and Puloka as evidence-side entries once the primary documents are attached to records.
Three sentences journalists can quote
Two federal courts decided in February 2026 whether a person’s exchanges with an AI tool can be kept from the other side and reached opposite results, with a Colorado court siding with the Michigan view for pro se litigants in March: a Michigan magistrate judge protected a pro se litigant’s ChatGPT drafts as work product, and a New York district judge held a defendant’s Claude exchanges neither privileged nor work product because the vendor’s terms allowed training and disclosure.
The largest compelled production of AI conversations on the record is 20 million de-identified consumer ChatGPT logs, ordered on 7 November 2025 and affirmed on 5 January 2026, after a preservation order that ran from 13 May to 26 September 2025.
Of five note-taker and assistant vendors’ published terms read on 5 September 2026, one says it trains its models on de-identified recordings and transcripts, and that vendor is the one whose wiretap claims survived a motion to dismiss on 13 August 2026.
Appendix A: data tables
A1. Register entries by question and jurisdiction
| Question | US federal | US state | Bar body | Other | Total |
|---|---|---|---|---|---|
| Privilege | 3 (Warner, Heppner, Morgan) | 0 | 2 (NYC Bar 2025-6, 2026-2) | 1 (public statement) | 6 |
| Discovery | 7 (six OpenAI orders, Otter) | 0 | 0 | 0 | 7 |
| Evidence | 1 (Kohls) | 3 (Puloka, Dewald, Mendones) | 0 | 0 | 4 |
| Total | 11 | 3 | 2 | 1 | 17 |
A2. Source status of the seventeen entries
| Status | Count | Entries |
|---|---|---|
| Primary document read | 14 | ECF 551, 559, 688, 922, 734, 1021; Mendones; NYC Bar 2025-6 and 2026-2; Warner; Heppner; Morgan; Kohls (tracker, verified); Dewald (tracker, argument record) |
| Reported only | 3 | Puloka; podcast remark; Otter order |
A3. Regulation Tracker records used
| Record | Type | Date |
|---|---|---|
| us-fre-707-machine-generated-evidence | Court rule (proposed) | 4 Jun 2026 |
| us-la-act-250-2025-ai-evidence | Statute | 1 Aug 2025 |
| uk-judiciary-ai-guidance | Guidance | 31 Oct 2025 |
| eu-ai-act | Statute | 27 Jul 2026 |
| eu-commission-article-50-transparency-guidelines | Guidance | 20 Jul 2026 |
| eu-code-of-practice-ai-generated-content | Guidance | 9 Jul 2026 |
| aba-formal-opinion-512 | Ethics opinion | 29 Jul 2024 |
Appendix B: sources
- United States v Heppner, No. 25-cr-503 (JSR), Dkt. 27 (S.D.N.Y. 17 Feb 2026): CourtListener RECAP PDF (scanned; read by OCR); docket: courtlistener.com
- Morgan v V2X, Inc., No. 1:25-cv-01991-SKC-MDB, Dkt. 65 (D. Colo. 30 Mar 2026): CourtListener RECAP PDF
- Warner v Gilbarco, Inc., No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. 10 Feb 2026): Justia, ECF 94 (Justia blocks scripts; archive); Lexis print reposted: darroweverett.com PDF
- In re OpenAI, Inc. Copyright Infringement Litigation, No. 25-md-3143 (SHS) (OTW): preservation order 13 May 2025, ECF 551; reconsideration denied 16 May 2025, ECF 559; intervention order 20 Jun 2025, ECF 688; stipulation and order 9 Oct 2025, ECF 922; production order 7 Nov 2025, ECF 734; order 5 Dec 2025, ECF 910; affirmance 5 Jan 2026, ECF 1021; docket: courtlistener.com
- Mendones v Cushman and Wakefield, Inc., No. 23CV028772 (Cal. Super. Ct., Alameda County, 9 Sep 2025), Order re Terminating Sanctions: PDF
- New York City Bar Association, Formal Opinion 2025-6 (22 Dec 2025): nycbar.org (archive); Formal Opinion 2026-2 (5 Aug 2026): nycbar.org (archive). nycbar.org returns 403 to scripts; both pages were read through a fetch tool on 5 Sep 2026
- In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal. 13 Aug 2026), as reported: National Law Review; docket: courtlistener.com
- State v Puloka (Wash. Super. Ct., King County per ABA Litigation News, 2024), as reported: Greenberg Traurig, May 2024; National Law Review
- State v Horcasitas (Maricopa County Super. Ct., Ariz., sentencing 1 May 2025), appeal as reported: Mealey’s, 27 May 2026; sentencing: NBC News, 7 May 2025; appeal announced: ABC15
- OpenAI chief executive’s podcast remark, as reported: Artificial Lawyer, 28 Jul 2025
- Vendor terms, read 5 Sep 2026: Otter.ai privacy policy; Fireflies.ai privacy policy; Zoom blog, 16 Oct 2025; Microsoft, Data, Privacy, and Security for Microsoft Copilot; Google Workspace generative AI privacy hub
- Rule 707: Standing Committee June 2026 agenda book; Reports to the Judicial Conference, September 2026
- SafeLegalAI datasets: /tracker/incidents.json, /regulation/documents.json, as of 5 September 2026; Semrush US database pull of 5 September 2026: /data/search-demand-2026-09/
Appendix C: changes to this report
None since first publication.