Skip to content

reportAI in CourtsAI Governance

AI chat logs, note-takers and privilege: what courts have compelled, protected and excluded, 2024 to 2026

17 rulings and opinions on AI privilege, discovery and AI-generated evidence, 2024 to 2026, coded by question, plus what five note-taker vendors say they keep.

Anthropic ClaudeMicrosoft CopilotOpenAI ChatGPT

Edited and verified by Cognesio LLP

Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓

In the United States, a federal judge held on 17 February 2026 that a defendant’s written exchanges with a consumer AI assistant were protected by neither attorney-client privilege nor the work-product doctrine, and a week earlier a magistrate judge in Michigan had held that a self-represented litigant’s ChatGPT queries and answers were protected work product. Those two decisions, United States v Heppner in the Southern District of New York and Warner v Gilbarco in the Eastern District of Michigan, are the first in which courts have said in terms whether what a person types into an AI tool can be kept from the other side. This report collects them and the fifteen other rulings, orders and ethics opinions from the United States, England and Wales and the European Union that decide, between 2024 and 5 September 2026, three questions: whether AI conversations and transcripts are privileged, whether they can be compelled in discovery, and whether AI-generated or AI-altered material can be put before a court as evidence.

It also reads what five meeting note-taker and assistant vendors say they keep and what they train on, because every privilege and discovery question in the register turns on a fact about retention that only the vendor’s terms answer. It is descriptive. It does not say what a lawyer or a client should do; it records what has been decided, ordered, published and promised, with dates.

Key findings

  1. Two federal courts reached opposite results on AI materials within a week of each other in February 2026. In Warner v Gilbarco (E.D. Mich., 10 February 2026) a self-represented plaintiff’s ChatGPT queries and responses were held to be work product, and disclosure to ChatGPT was held not to waive it because waiver “has to be a waiver to an adversary or in a way likely to get in an adversary’s hand”. In United States v Heppner (S.D.N.Y., bench ruling 10 February, written opinion 17 February 2026) about thirty-one documents recording a defendant’s exchanges with Anthropic’s Claude were held to be neither privileged nor work product, because the user “could have had no ‘reasonable expectation of confidentiality in his communications’ with Claude” given Anthropic’s privacy policy and because the documents were “not ‘prepared by or at the behest of counsel’”. A third court, in Morgan v V2X (D. Colo., 30 March 2026), followed Warner for a pro se plaintiff, distinguished Heppner because “no such gap exists in the pro se context” between party and advocate, and held that public AI tools’ data collection “does not eliminate all expectations of privacy or automatically waive protections”, while ordering the plaintiff to disclose the name of any AI tool he had used with confidential discovery material.
  2. The largest compelled production of AI conversations on the record is 20 million de-identified consumer ChatGPT logs, ordered by Magistrate Judge Wang on 7 November 2025 in the OpenAI copyright multidistrict litigation and affirmed by Judge Stein on 5 January 2026. The preservation order that preceded it, entered 13 May 2025, required OpenAI to “preserve and segregate all output log data that would otherwise be deleted”; it was terminated by stipulation on 9 October 2025 as of 26 September 2025, with the data preserved before that date retained except for requests originating in the European Economic Area, Switzerland or the United Kingdom.
  3. The Heppner court relied on the vendor’s own terms for the confidentiality finding: Anthropic’s privacy policy of 19 February 2025 said it collects “inputs” and “outputs”, uses them to “train” the model and may disclose data to “third parties” including “governmental regulatory authorities”. Of the five vendor statements read for this report on 5 September 2026, one (Otter.ai, policy effective 16 June 2026) says it trains its own models on de-identified recordings and transcripts; four (Fireflies, Zoom, Microsoft, Google Workspace) say customer content is not used to train models without permission.
  4. The first ruling on whether an AI note-taker is a party to the call or an eavesdropper came on 13 August 2026: in In re Otter.AI Privacy Litigation (N.D. Cal.) the court allowed federal Wiretap Act, California Invasion of Privacy Act and Illinois biometric claims to proceed because, as reported, “Otter does not just participate in meetings, it retains the recordings of the conversations and uses them to improve its own machine-learning models and services”. The order decides plausibility, not liability.
  5. Two bar opinions now govern lawyers’ use of AI recording tools in New York: the New York City Bar’s Formal Opinion 2025-6 (22 December 2025) requires that “clients must be notified, and their consent obtained, whenever their calls are being recorded by an AI-empowered system”, and Formal Opinion 2026-2 (5 August 2026) says the default with witnesses and opposing counsel “should be not to record” and that surreptitious recording breaches the conduct rules.
  6. Courts have excluded or sanctioned AI-generated evidence in four ways on the record: exclusion of AI-enhanced video after a Frye hearing (State v Puloka, Washington, 2024); terminating sanctions for deepfake exhibits (Mendones v Cushman and Wakefield, Alameda County, 9 September 2025, action dismissed with prejudice); exclusion of an expert declaration with AI-fabricated citations (Kohls v Ellison, D. Minn., 10 January 2025); and stopping an AI avatar mid-argument (Dewald, N.Y. App. Div., 26 March 2025). The one court that admitted AI-generated material, the Arizona sentencing court that played an AI video of a deceased victim on 1 May 2025, is under appeal; as of a 27 May 2026 report no decision had issued.
  7. No federal rule of evidence on machine-generated or AI evidence is in force. Proposed Federal Rule of Evidence 707 went to public comment on 15 August 2025, comment closed 16 February 2026, and on 3 to 4 June 2026 the Standing Committee declined to recommend it and returned it for further study with the deepfake question; the earliest effective date is after 1 December 2027. Louisiana’s Act 250 of 2025 (effective 1 August 2025) is the only statute in the Regulation Tracker that imposes a duty on counsel to verify exhibits for AI generation or alteration.
  8. The only rule anywhere in the record that requires AI-generated text to carry a machine-readable mark is Article 50(2) of the EU AI Act, in force since 2 August 2026 for providers, with generative systems on the market before that date given until 2 December 2026. The rule is written for transparency, not for evidence, but it is the first legal source of provenance data a court could ask for.

Why a client meeting is now a discovery problem

Three things changed between 2023 and 2026. First, the tools that record and summarise conversations moved from dictation software on a lawyer’s own machine to cloud services with their own retention and training terms; the recording is now held by a third party under a contract the client has not read. Second, litigants began using consumer AI to prepare for their own cases, and courts began to be asked whether those exchanges are the modern equivalent of notes to counsel or of a conversation with a stranger. Third, the largest AI providers became defendants in copyright litigation, and the discovery in those cases produced the first orders that treat hundreds of millions of people’s conversations as a corpus to be preserved and sampled.

The demand side shows the same shift. In the 5 September 2026 Semrush read for the US database, “ai legal defense evidence” carries 390 searches a month, “ai of deceased in court cases makes statement” 170 and “ai evidence” 110 (all in the published ai_court_us.csv); two AI-search fan-out strings, “ai chatbot legal liability” (390) and “ai note takers legal risks” (320), were read in the Keyword Magic view and recorded in the search-demand study rather than in a saved CSV. The first page for each is law-firm client alerts and vendor blogs. None of those pages lists the decisions. This report does.

Method and data

Primary documents read for this report, all on 5 September 2026 unless stated: United States v Heppner, No. 25-cr-503 (JSR), Dkt. 27 (S.D.N.Y. 17 February 2026), read from the CourtListener RECAP PDF by optical character recognition (the scan carries no text layer); Warner v Gilbarco, No. 2:24-cv-12333, 2026 WL 373043 (E.D. Mich. 10 February 2026), read from a law-firm repost of the Lexis print; Morgan v V2X, No. 1:25-cv-01991, Dkt. 65 (D. Colo. 30 March 2026), read from the CourtListener RECAP PDF; In re OpenAI, Inc. Copyright Infringement Litigation, No. 25-md-3143 (SHS) (OTW), orders at ECF 551 (13 May 2025), ECF 559 (16 May 2025), ECF 688 (20 June 2025), ECF 922 (9 October 2025), ECF 734 (7 November 2025), ECF 910 (5 December 2025) and ECF 1021 (5 January 2026), read from CourtListener storage and two news-site mirrors; Mendones v Cushman and Wakefield, No. 23CV028772 (Alameda County Superior Court, order of 9 September 2025); the New York City Bar’s Formal Opinions 2025-6 and 2026-2; the Commission’s Article 50 guidelines and the transparency code as recorded in the Regulation Tracker; the June 2026 Standing Committee agenda book and September 2026 Judicial Conference reports for Rule 707 as recorded; the privacy or trust pages of Otter.ai (effective 16 June 2026), Fireflies.ai (updated 6 March 2026), Zoom (blog, 16 October 2025), Microsoft (learn.microsoft.com, page dated 9 July 2026, updated 18 August 2026) and Google Workspace (privacy hub, updated 14 August 2026).

Read as reported, not in the primary: the order in In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal. 13 August 2026), from the National Law Review’s account (the RECAP docket lists entries only to July 2026); the King County Superior Court’s ruling in State v Puloka (2024), from Greenberg Traurig’s alert of May 2024 and the ABA Litigation News report of autumn 2024; the Arizona appeal in State v Horcasitas, from Mealey’s report of 27 May 2026; the OpenAI chief executive’s remark on a podcast in July 2025, from Artificial Lawyer’s report of 28 July 2025.

Datasets: the SafeLegalAI incident collection, 150 records as of 5 September 2026 (/tracker/incidents.json), of which three concern AI-generated material put before a court rather than fabricated citations (Kohls v Ellison, Dewald, Elliott v New York Bariatric Group); the Regulation Tracker, 324 records (/regulation/documents.json), of which eight mention deepfakes and two (proposed Rule 707 and Louisiana Act 250) are evidence rules on AI-generated material. The tools directory covers legal-AI products and does not list general meeting assistants; the vendor table below was built from vendor pages for this report.

Classification. Each register entry is coded to one of three questions: privilege (does a rule of confidentiality attach), discovery (can the material be compelled or must it be preserved) and evidence (can AI-generated or AI-altered material be admitted or relied on). “Outcome” records what the court or body did, in its own words where a primary was read. Names of parties appear only as they appear in published decisions and orders.

Limits. Seventeen entries across three jurisdictions is a small record and a selection: it holds the decisions this site could find and read, not every discovery order that mentions AI. Three of the seventeen are read from secondary reports and are marked. Warner and Heppner are trial-level rulings with no appellate treatment. Vendor terms change without notice; each is dated. The report covers no jurisdiction outside the United States, England and Wales and the European Union, and it found no decided case in England and Wales on the privilege or discoverability of AI conversations.

The register

#DateMatterCourt or bodyQuestionToolOutcomeRead
1Mar 2024State v PulokaWashington superior court (King County, per the ABA Litigation News report)EvidenceTopaz Labs Video AI, AdobeAI-enhanced Snapchat video excluded after a Frye hearing; the enhancement “did not show with integrity what actually happened, but instead used opaque methods to represent what the AI model thought should be shown”Reported (GT alert, May 2024; ABA Litigation News, autumn 2024)
210 Jan 2025Kohls v EllisonD. Minn.EvidenceGPT-4oExpert declaration containing AI-fabricated citations excludedPrimary (tracker, verified)
326 Mar 2025DewaldN.Y. App. Div., 1st DeptEvidenceAI avatarVideo stopped within seconds; appellant continued in personPrimary (argument record, tracker unverified)
413 May 2025In re OpenAI Copyright Infringement Litig., ECF 551S.D.N.Y. (Wang, M.J.)DiscoveryChatGPTOpenAI ordered to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court”Primary
516 May 2025Same, ECF 559S.D.N.Y. (Wang, M.J.)DiscoveryChatGPTOpenAI’s motion for reconsideration denied without prejudicePrimary
620 Jun 2025Same, ECF 688S.D.N.Y. (Wang, M.J.)DiscoveryChatGPTA ChatGPT user’s pro se motion to intervene to challenge the preservation order addressedPrimary
7Jul 2025OpenAI chief executive’s podcast remarkNone (public statement)PrivilegeChatGPT”we haven’t figured that out yet for when you talk to ChatGPT”Reported (Artificial Lawyer, 28 Jul 2025)
89 Sep 2025Mendones v Cushman and WakefieldAlameda County Superior Court, CaliforniaEvidenceGenerative AI (deepfake video and altered images)Terminating sanction: “The entire action is dismissed with prejudice”; the court identified “the lack of facial expressions, the looping video feed” as marks of generated videoPrimary
99 Oct 2025Same as 4, ECF 922S.D.N.Y. (Wang, M.J.)DiscoveryChatGPTStipulation and order: the going-forward preservation duty “is terminated as of September 26, 2025”; data preserved before then retained, except EEA, Swiss and UK requests; named domains preserved going forwardPrimary
107 Nov 2025Same, ECF 734S.D.N.Y. (Wang, M.J.)DiscoveryChatGPTProduction of “20 million retained, anonymized consumer ChatGPT output logs” ordered; OpenAI “has failed to explain how its consumers’ privacy rights are not adequately protected by” the protective order and de-identificationPrimary
1122 Dec 2025NYC Bar Formal Opinion 2025-6New York City Bar Association, Professional Ethics CommitteePrivilegeAI recording and transcription toolsClient consent required for AI recording; lawyers “should independently review any recording, transcript, or summary”; retainer provisions for client-selected tools; advise clients of “the risks of the loss of confidentiality and privilege”Primary
125 Jan 2026Same as 4, ECF 1021S.D.N.Y. (Stein, J.)DiscoveryChatGPTObjections to the 7 November and 5 December 2025 orders “denied and the orders are affirmed”Primary
1310 Feb 2026Warner v GilbarcoE.D. Mich. (Patti, M.J.)PrivilegeChatGPTMotion to compel a pro se plaintiff’s ChatGPT queries and responses denied: work product; no waiver by use of ChatGPT because waiver “has to be a waiver to an adversary or in a way likely to get in an adversary’s hand”Primary
1417 Feb 2026United States v HeppnerS.D.N.Y. (Rakoff, J.)PrivilegeClaudeAbout thirty-one documents of a defendant’s exchanges with Claude held not privileged and not work product; question described as one “of first impression nationwide”Primary (OCR)
14a30 Mar 2026Morgan v V2X, Inc.D. Colo. (Dominguez Braswell, M.J.)Privilege and discovery (protective order)ChatGPT, Claude, Gemini named as examplesMotion to amend protective order granted in part: Rule 26(b)(3) “can protect your mental impressions and litigation preparation materials, but you must disclose the name of any AI tool you used in connection with Confidential Information”; amended order bars putting confidential information “into any mainstream AI tool like standard ChatGPT, Claude, Gemini, or similar platforms” absent contractual safeguardsPrimary
155 Aug 2026NYC Bar Formal Opinion 2026-2New York City Bar AssociationPrivilegeAI recording toolsConsent of all parties before recording non-clients; with witnesses the “default practice should be not to record”; surreptitious recording breaches Rule 8.4Primary
1613 Aug 2026In re Otter.AI Privacy LitigationN.D. Cal.Discovery (retention and use of recordings)Otter.aiMotion to dismiss granted in part; Wiretap Act, CIPA, BIPA, unjust enrichment and UCL claims proceed; Otter treated as a third-party eavesdropper because it “retains the recordings” and “uses them to improve its own machine-learning models”Reported (National Law Review)

Two matters that belong beside the register but decide nothing yet: State v Horcasitas (Maricopa County Superior Court, sentencing 1 May 2025; appeal pending, briefing reported 27 May 2026), where an AI-generated video of the deceased victim was played at sentencing, and Elliott v New York Bariatric Group (Connecticut Superior Court, 6 August 2026, tracker unverified), where a self-represented litigant hid instructions to AI systems in white text in his filings.

Privilege

The privilege question has been answered twice, differently, and the difference is in the facts each court found about who prepared the material and what the vendor promised.

In Heppner the defendant, after receiving a grand jury subpoena and, the court found, “without any suggestion from counsel that he do so”, used Anthropic’s Claude to analyse his position; the government seized about thirty-one documents recording the exchanges. Judge Rakoff’s memorandum of 17 February 2026 rests the privilege holding on confidentiality. It quotes the privacy policy to which Claude users consent, “as of February 19, 2025”: Anthropic collects “inputs” and “outputs”, uses them to “train” Claude, and reserves the right to “disclose personal data to third parties in connection with claims, disputes[,] or litigation”. On that basis the defendant “could have had no ‘reasonable expectation of confidentiality in his communications’ with Claude”, and even if some inputs were privileged “he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party”. The memorandum also adopts the position that “all ‘[r]ecognized privileges’ require, among other things, ‘a trusting human relationship’”. On work product the holding is that the documents were “not ‘prepared by or at the behest of counsel’” and did not reflect defence counsel’s strategy. The court left a door open in one sentence: had counsel directed the use, “Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege”, citing the Kovel line of cases.

In Warner the plaintiff had no lawyer. The defendants moved to compel the ChatGPT queries and responses she had used to draft filings. Magistrate Judge Patti denied the motion on 10 February 2026: the material reflected her “internal analysis and mental impressions”, and under Sixth Circuit law “the work-product waiver has to be a waiver to an adversary or in a way likely to get in an adversary’s hand”. The opinion describes AI platforms as “tools, not persons, even if they may have administrators somewhere in the background”.

The third decision reconciles them. In Morgan v V2X, an employment case in the District of Colorado, the defendant asked the court to compel a pro se plaintiff to identify the AI tool he was using with confidential discovery and to amend the protective order. Magistrate Judge Dominguez Braswell’s order of 30 March 2026 (Dkt. 65) holds that the plaintiff “can assert work product protections in connection with his AI use”, as in Warner, and reads Heppner as a case where “there was a gap between the party and the attorney because the defendant acted entirely apart from his lawyer”, whereas “a pro se litigant is simultaneously the party and the advocate”. It accepts that public AI systems “collect user data for training and other purposes” but holds that this “does not eliminate all expectations of privacy or automatically waive protections”. The plaintiff was nonetheless ordered to disclose the name of any AI platform used with confidential information, because identifying the tool does not reveal his mental impressions, and the protective order was amended to bar confidential information from any AI service that transfers it onward or trains on it.

The two February decisions are consistent on their own terms. Heppner asks whether a client’s voluntary disclosure to a commercial third party destroys confidentiality and answers yes, citing the provider’s policy; Warner asks whether disclosure to a tool waives work product and answers no, because the tool is not an adversary. What separates them is not the AI but the doctrine invoked and the vendor’s terms in the record. Neither decision has been reviewed on appeal.

The lawyer-side rules arrived from the bar rather than the bench. Formal Opinion 2025-6 of the New York City Bar, issued 22 December 2025, answers “what ethical issues should attorneys consider when using, or when clients use, AI-enabled communications tools that can record, transcribe, and summarize conversations with clients”. It requires notice and consent for AI recording, independent review of transcripts and summaries, training and supervision under Rules 5.1 and 5.3, and, where a client brings its own tool, retainer provisions that recordings “prepared by AI tools selected or used by the client will not be deemed dispositive or binding as against the attorneys unless they are promptly provided”. It tells lawyers to “advise clients of the risks of the loss of confidentiality and privilege”. Formal Opinion 2026-2, issued 5 August 2026, covers non-clients: consent of all parties, no surreptitious recording, and a default of not recording witnesses. Neither opinion decides whether a transcript held by a vendor is privileged; both assume the risk exists and regulate the lawyer’s conduct around it.

The public statement most often quoted on the question is the one the OpenAI chief executive made on a podcast in July 2025, reported by Artificial Lawyer on 28 July 2025: “If you talk to a therapist or a lawyer or a doctor about those problems, there’s legal privilege for it … And we haven’t figured that out yet for when you talk to ChatGPT.” Seven months later the Heppner court cited the same absence of a “trusting human relationship” as a reason the privilege cannot attach.

Discovery of logs

The OpenAI copyright litigation produced the discovery record. On 13 May 2025 Magistrate Judge Wang ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court” (ECF 551 in the New York Times action, ECF 33 in the multidistrict docket). OpenAI moved for reconsideration; the motion was denied without prejudice on 16 May (ECF 559). On 20 June the court dealt with a ChatGPT user who had moved, pro se, to intervene “for the limited purpose of challenging discovery orders in this case that prejudice their rights” (ECF 688). The order was the subject of public statements by OpenAI and of press coverage describing it as reaching hundreds of millions of users; the court’s own orders do not put a number on it.

On 9 October 2025 the parties stipulated, and the court ordered, that the going-forward obligation “is terminated as of September 26, 2025” (ECF 922). The stipulation keeps the data segregated before that date, “except for output log data corresponding to user requests originating from within the European Economic Area, Switzerland, or the United Kingdom”, and commits OpenAI to preserve on a going-forward basis the logs of accounts associated with domains the plaintiffs listed. Paragraph 4 records that the stipulation “does not purport to waive, modify, or otherwise affect the parties’ obligations under Federal Rule of Civil Procedure 37(e)”.

The production order followed on 7 November 2025 (ECF 734). The dispute was over “20 million retained, anonymized consumer ChatGPT output logs”. OpenAI had proposed the 20 million sample itself in opposing a motion for 120 million, then in October offered to run search terms across it and produce only the hits. The court ordered the whole sample: OpenAI “has failed to explain how its consumers’ privacy rights are not adequately protected by: (1) the existing protective order in this multidistrict litigation or (2) OpenAI’s exhaustive de-identification of all of the 20 million Consumer ChatGPT Logs”, and had relied on a sampling decision in Concord Music Group v Anthropic without explaining why that court’s later order producing the entire five-million-record sample “is not similarly instructive here”. Judge Stein affirmed on 5 January 2026 (ECF 1021), recording that “in the ordinary course of its business, OpenAI has retained tens of billions of such logs”.

The Heppner court cited that affirmance for the proposition that AI users lack substantial privacy interests in conversations “voluntarily disclosed” to a platform that “retains [them] in the normal course of its business”. The discovery record and the privilege record therefore now point the same way for consumer tools: what the vendor keeps, a court can reach, and what a court can reach was not confidential.

The note-taker litigation asks the retention question from the other side. In In re Otter.AI Privacy Litigation, decided on the pleadings on 13 August 2026, the reported reasoning is that Otter “does not just participate in meetings, it retains the recordings of the conversations and uses them to improve its own machine-learning models and services”, which makes it “an independent party who uses the recordings to train its models for its own benefit” rather than an extension of the host. The claims that survived (federal Wiretap Act, California’s section 631 and 632, Illinois biometric privacy, unjust enrichment, unfair competition) will now proceed to discovery of Otter’s own retention; the claims dismissed were the computer-fraud, Washington privacy and most common-law privacy counts. A parallel biometric action against Fireflies.ai (Cruz v Fireflies.AI Corp., C.D. Ill., filed 18 December 2025) is at the pleading stage.

AI-generated and AI-altered evidence

The evidence entries divide into four outcomes.

Exclusion after a reliability hearing. In State v Puloka a Washington superior court judge (King County, per the ABA Litigation News report) held a Frye hearing on Snapchat video that the defence had enhanced with Topaz Labs’ Video AI and excluded it. As reported by Greenberg Traurig and the ABA’s Litigation News, the court found that the enhanced video “did not show with integrity what actually happened, but instead used opaque methods to represent what the AI model thought should be shown”, that the tools “have not been peer-reviewed by the forensic video analysis community, are not reproducible by that community, and are not accepted generally in that community”, and that admission would risk “a time-consuming trial within a trial”. The relevant community, the court held, was forensic video analysts; the product’s commercial adoption elsewhere did not establish acceptance in that community.

Terminating sanctions for fabricated exhibits. In Mendones v Cushman and Wakefield the Alameda County Superior Court suspected nine exhibits filed with a summary-judgment motion “of having been altered or created by generative artificial intelligence”. Of two videos purporting to show a witness, “certain characteristics … such as the lack of facial expressions, the looping video feed, among other things, suggested that these exhibits were products of GenAI—i.e., ‘deepfakes’”. After an order to show cause, a hearing on 9 September 2025 at which the plaintiffs did not appear, and findings that they had intentionally submitted false evidence, the court struck the complaint: “The entire action is dismissed with prejudice.” The order records that the question of a referral to the District Attorney was before the court.

Exclusion of AI-tainted expert evidence. In Kohls v Ellison the State of Minnesota’s expert on misinformation filed a declaration, drafted with GPT-4o, that cited two non-existent articles and misattributed a third; on 10 January 2025 the court excluded it. The tracker row records the court’s observation on the irony of an AI-misinformation expert relying on unverified AI output. The case is in the register because the declaration was evidence, not a brief.

Stopping AI in the courtroom. In Dewald a self-represented appellant had leave to play a video at oral argument on 26 March 2025 and played an AI-generated avatar; the presiding justice stopped it within seconds. No sanction followed; the appellant argued in person.

The one instance of AI-generated material admitted on the record is the Arizona sentencing in State v Horcasitas on 1 May 2025, where the court permitted the victim’s family to play a video in which an AI rendering of the deceased addressed the court in a script the family wrote. The defence announced an appeal within hours, as ABC15 reported; Mealey’s reported on 27 May 2026 that the defendant argues “the trial court erred in allowing an artificial intelligence-generated video of the victim to be played during the sentencing hearing” and that the state and victims answer that the video was identified as the sister’s work and “is no different than any other video shown at such proceedings”. No decision had issued on the last report read.

The rules that exist and the rules that do not

Proposed Rule 707. The Judicial Conference’s Advisory Committee on Evidence Rules proposed a new Federal Rule of Evidence 707 that would subject machine-generated evidence offered without an expert to the reliability requirements of Rule 702. The Standing Committee approved publication on 10 June 2025; comment ran from 15 August 2025 to 16 February 2026; the Advisory Committee reported “greater overall concerns” on 7 May 2026; and on 3 to 4 June 2026 the Standing Committee did not recommend action and returned the rule for revision alongside the separate deepfake proposal. The tracker record puts the earliest possible effective date after 1 December 2027. Until then, the federal courts decide AI-generated evidence under Rules 401, 403, 702 and 901 as they stand, which is what Puloka (under Washington’s equivalents) and Kohls did.

Louisiana Act 250 of 2025. Effective 1 August 2025, Louisiana added to its civil procedure a duty on counsel to “exercise reasonable diligence to verify the authenticity of evidence before offering it”, to disclose known falsification of the party’s own exhibits “including by AI generation or alteration”, and to raise a “reasonable suspicion” about an opponent’s exhibits at the pretrial stage, on pain of contempt and discipline. The tracker record notes that it applies to civil proceedings and does not address hallucinated citations. It is the only statute of its kind in the Regulation Tracker on 5 September 2026.

England and Wales. The judicial guidance on AI, version 3 of 31 October 2025, “addressed hallucinated case law and deepfake evidence” in the words of the tracker record and tells judges they may ask parties whether AI has been used. No practice direction on deepfake evidence exists in the civil or family courts, and this report found no reported decision in England and Wales on the privilege or discoverability of AI conversations. The Solicitors Regulation Authority’s warning notice of 17 August 2026 names client confidentiality among its concerns; the regulator outcomes report sets out its context.

European Union. Article 50(2) of the AI Act has required providers of generative systems, since 2 August 2026, to mark synthetic audio, image, video and text output “in a machine-readable format and detectable as artificially generated or manipulated”, with systems on the market before that date given until 2 December 2026 under new Article 111(4); Article 50(4) requires deployers to disclose deepfakes. The Code of Practice on Transparency of AI-generated Content, found adequate by the Commission on 8 July 2026, commits signatories to interoperable watermark detection by 2 February 2027. None of this is an evidence rule, and the EU AI Act report on this site records that no fine under the Act had been published by 5 September 2026. It is listed here because a court asked to authenticate a video from 2027 onward will, for the first time, have a legal source for provenance marks to look for.

What five vendors say they keep

Every privilege and discovery entry above turned on a fact about retention: Heppner on Anthropic’s policy, the OpenAI orders on what OpenAI “has retained” in the ordinary course, Otter on what Otter does with recordings. The table records what five widely used recording and assistant products said on the date read. It is a reading of published terms, not a test of practice, and it is not a ranking.

Vendor and productDocument and dateContent used to train modelsRetention as statedThird-party model providers
Otter.aiPrivacy policy, effective 16 Jun 2026Yes: “training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”; no opt-out stated in the policy”for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law”; no period stated”Artificial intelligence service providers that provide backend support”; not named
Fireflies.aiPrivacy policy, updated 6 Mar 2026No: “We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training”Meeting content “not … stored by any third-party vendor after processing”; account data deleted within 30 days of closure; no retention period stated for a live account’s transcriptsListed on a separate sub-processor page (not read)
Zoom (AI Companion)Blog post, 16 Oct 2025No: “we do not use any customer audio, video, chat, screen sharing, attachments, or other communications-like customer content … to train Zoom’s or its third-party artificial intelligence models”Not stated on the page read; processing “within Zoom’s infrastructure” under the Zoom-models-only optionThird-party models used unless the Zoom-models-only option is selected
Microsoft (Copilot in Microsoft 365, incl. Teams)learn.microsoft.com privacy page, dated 9 Jul 2026, updated 18 Aug 2026No: “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs”Prompts and responses stored as “Copilot activity history”; “admins can also use Microsoft Purview to set retention policies”; users can delete their history; Copilot “opted out” of Azure OpenAI abuse monitoring with human reviewOpenAI and Anthropic models as sub-processors; Anthropic models “currently excluded from the EU Data Boundary”
Google (Gemini for Workspace, incl. Meet)Workspace privacy hub, updated 14 Aug 2026No without permission: “Workspace does not use customer data for training models without customer’s prior permission or instruction”; content “not human reviewed … without permission”Gemini in Workspace prompts and responses “90 days to indefinite, as determined by admins”; Gemini app “up to 36 months, as determined by admins”; Meet notes retention not addressed on the pageGoogle models

Two features of the table bear on the register. First, the one vendor that says it trains on recordings is the one whose retention and use is now the subject of a surviving wiretap claim; the Otter court’s reported reasoning turns on exactly that sentence in the terms. Second, the two enterprise suites put retention in the customer’s hands (Purview policies; admin-set periods), which is the fact the Heppner court said it did not have before it and hinted could change the privilege analysis for a tool used “at the direction of counsel”. None of the five pages states what the vendor does when served with a subpoena beyond the general privacy-policy language; Anthropic’s, as quoted in Heppner, does.

Timeline

DateEventSource
Mar 2024State v Puloka: AI-enhanced video excluded after Frye hearingReported
10 Jan 2025Kohls v Ellison: AI-tainted expert declaration excludedTracker (verified)
26 Mar 2025Dewald: AI avatar stopped at oral argumentTracker
1 May 2025State v Horcasitas: AI video of deceased victim played at sentencing; defence appeal announcedReported
13 May 2025OpenAI preservation order (ECF 551 / ECF 33)Primary
16 May 2025Reconsideration denied (ECF 559)Primary
10 Jun 2025Standing Committee approves proposed Rule 707 for publicationTracker record
20 Jun 2025ChatGPT user’s intervention motion addressed (ECF 688)Primary
Jul 2025OpenAI chief executive: no “legal privilege” for ChatGPT conversations yetReported
1 Aug 2025Louisiana Act 250 in forceTracker record
15 Aug 2025Rule 707 comment period opensTracker record
9 Sep 2025Mendones: terminating sanctions for deepfake exhibitsPrimary
9 Oct 2025Preservation duty terminated as of 26 Sep 2025 (ECF 922)Primary
31 Oct 2025England and Wales judicial guidance v3 addresses deepfake evidenceTracker record
7 Nov 202520 million consumer ChatGPT logs ordered produced (ECF 734)Primary
18 Dec 2025Cruz v Fireflies.AI filed (C.D. Ill.)Reported
22 Dec 2025NYC Bar Formal Opinion 2025-6Primary
5 Jan 2026Judge Stein affirms the production orders (ECF 1021)Primary
10 Feb 2026Warner v Gilbarco: ChatGPT materials are work product; Heppner bench rulingPrimary
16 Feb 2026Rule 707 comment closesTracker record
17 Feb 2026Heppner written opinion: Claude exchanges not privilegedPrimary
30 Mar 2026Morgan v V2X: pro se AI use is work product; tool name must be disclosed; protective order amendedPrimary
3 to 4 Jun 2026Standing Committee declines to recommend Rule 707; returned for studyTracker record
2 Aug 2026EU AI Act Article 50 marking and deepfake disclosure applyTracker record
5 Aug 2026NYC Bar Formal Opinion 2026-2Primary
6 Aug 2026Elliott: hidden AI instructions in filings sanctionedTracker (unverified)
13 Aug 2026In re Otter.AI: core wiretap and biometric claims proceedReported
2 Dec 2026EU Article 50(2) marking mandatory for pre-existing generative systemsTracker record

What to watch

The Heppner opinion leaves the enterprise question open in one sentence, and the next case will be one in which counsel directed the use of a tool whose terms promise no training and customer-controlled retention. The two enterprise tables above are the facts such a case would turn on. Warner and Heppner may both be cited without either being reviewed; neither party has sought appellate review on the record read.

In the Otter litigation, the surviving claims proceed to discovery of Otter’s retention and training practices, which will put on a public docket the facts that vendor policies describe in general terms. The Fireflies action tests the biometric theory separately.

The Arizona Court of Appeals’ decision in Horcasitas will be the first appellate word on AI-generated victim material at sentencing. The Advisory Committee’s revised Rule 707 and its deepfake proposal will return to the Standing Committee no earlier than 2027. In the European Union, 2 December 2026 is the date from which every generative system on the market must mark its output, which is the first provenance signal an authentication argument could rely on.

The regulation tracker carries each instrument; the incident tracker will add rows for Heppner, Warner, Mendones and Puloka as evidence-side entries once the primary documents are attached to records.

Three sentences journalists can quote

Two federal courts decided in February 2026 whether a person’s exchanges with an AI tool can be kept from the other side and reached opposite results, with a Colorado court siding with the Michigan view for pro se litigants in March: a Michigan magistrate judge protected a pro se litigant’s ChatGPT drafts as work product, and a New York district judge held a defendant’s Claude exchanges neither privileged nor work product because the vendor’s terms allowed training and disclosure.

The largest compelled production of AI conversations on the record is 20 million de-identified consumer ChatGPT logs, ordered on 7 November 2025 and affirmed on 5 January 2026, after a preservation order that ran from 13 May to 26 September 2025.

Of five note-taker and assistant vendors’ published terms read on 5 September 2026, one says it trains its models on de-identified recordings and transcripts, and that vendor is the one whose wiretap claims survived a motion to dismiss on 13 August 2026.

Appendix A: data tables

A1. Register entries by question and jurisdiction

QuestionUS federalUS stateBar bodyOtherTotal
Privilege3 (Warner, Heppner, Morgan)02 (NYC Bar 2025-6, 2026-2)1 (public statement)6
Discovery7 (six OpenAI orders, Otter)0007
Evidence1 (Kohls)3 (Puloka, Dewald, Mendones)004
Total1132117

A2. Source status of the seventeen entries

StatusCountEntries
Primary document read14ECF 551, 559, 688, 922, 734, 1021; Mendones; NYC Bar 2025-6 and 2026-2; Warner; Heppner; Morgan; Kohls (tracker, verified); Dewald (tracker, argument record)
Reported only3Puloka; podcast remark; Otter order

A3. Regulation Tracker records used

RecordTypeDate
us-fre-707-machine-generated-evidenceCourt rule (proposed)4 Jun 2026
us-la-act-250-2025-ai-evidenceStatute1 Aug 2025
uk-judiciary-ai-guidanceGuidance31 Oct 2025
eu-ai-actStatute27 Jul 2026
eu-commission-article-50-transparency-guidelinesGuidance20 Jul 2026
eu-code-of-practice-ai-generated-contentGuidance9 Jul 2026
aba-formal-opinion-512Ethics opinion29 Jul 2024

Appendix B: sources

Appendix C: changes to this report

None since first publication.