
Corporate employees now draft, summarize, and analyze with generative AI as a matter of routine. Each of those interactions creates a new category of electronically stored information: the prompt the user typed, the output the tool returned, and the log of when and how the tool was used. Courts have begun to treat that information as discoverable, and the early decisions make clear that novelty is no exemption. The question for a corporate defendant is no longer whether AI-generated ESI can be reached in discovery, but on what terms, and what a company should do now to be ready.
Two preservation frontiers are converging. Courts are ordering production of employee AI prompts and outputs, while the privilege and work-product protections companies might hope to assert over AI use remain unsettled and, in some contexts, unavailable. At the same time, preservation obligations and spoliation doctrine under the Federal Rules continue to govern this new data exactly as they govern any other ESI. This paper explains how courts are treating AI-generated material, maps the emerging split on protection, and shows how to structure AI usage, legal holds, and preservation now so that a later discovery or spoliation fight is winnable.
AI Data Is ESI, and the Rules Already Govern It
The foundational point in the early case law is that generative-AI data is electronically stored information like any other. Prompts, outputs, and activity logs are subject to the same discovery framework that governs email, documents, and chat. Courts have been explicit that a new source of ESI is not exempt from discovery merely because it is novel.
The governing standard is Rule 26(b)(1) of the Federal Rules of Civil Procedure, which permits discovery of any nonprivileged matter that is relevant to a claim or defense and proportional to the needs of the case. Courts applying this standard to AI data have done so with rigor in both directions. They have ordered production where the AI material is relevant, and they have denied motions to compel where the requesting party failed to demonstrate specific relevance, treating speculative demands for an adversary's AI use as outside the proportionality boundary.
The corporate-employee prompt is the central exposure. In Concord Music Group, Inc. v. Anthropic PBC, 2025 WL 2267950 (N.D. Cal. Aug. 8, 2025), the court ordered production of prompts and outputs generated by the defendant's identified employees, subject to ordinary proportionality constraints, while recognizing that irrelevant prompts and their results are by definition not discoverable. The lesson for corporate defendants is direct: when employees use generative AI in connection with matters that become relevant to litigation, those prompts and outputs are exposed.
The Emerging Split on Privilege and Work Product
The harder questions concern whether AI prompts and outputs can be protected from discovery at all. The answer depends heavily on who used the tool, for what purpose, and into what kind of system. The 2026 decisions reveal a genuine and developing divide that a corporate defendant must understand before relying on any protection.
The skeptical line: public tools may defeat privilege. In United States v. Heppner (S.D.N.Y. 2026), the court applied the established three-element test for attorney-client privilege, protecting confidential communications between client and attorney made to obtain legal advice, and found that the AI communications at issue failed all three elements. Inputting information into a public generative-AI tool can be treated as a disclosure inconsistent with the confidentiality the privilege requires. The reasoning signals that a company cannot assume that running sensitive analysis through a public AI system preserves any privilege over the result.
The protective line: AI as a tool, not an adversary. A contrasting set of decisions reaches a more protective result, at least on work product. In Warner v. Gilbarco, Inc., 2026 WL 373043 (E.D. Mich. Feb. 10, 2026), and in a parallel decision from the District of Colorado, courts declined to find waiver of work-product protection merely because a litigant used a public AI tool. The reasoning drew a critical distinction: attorney-client privilege is waived by disclosure to any third party, but work-product protection is waived only by disclosure to an adversary or conduct likely to deliver the material to an adversary. Because an AI tool is a tool and not a person, inputting material into it is not disclosure to an adversary. These cases arose in the context of self-represented litigants, and courts have signaled that the analysis may differ for represented parties and corporate use.
Lawyer prompts may be opinion work product. Separately, courts have recognized that prompts written by lawyers for litigation purposes can constitute work product. In Tremblay v. OpenAI, Inc., 2024 WL 3748003 (N.D. Cal. Aug. 8, 2024), the court held that AI prompts authored by lawyers can constitute opinion work product when used for litigation-related purposes. The protection, where it exists, tracks the traditional work-product framework rather than any AI-specific rule.
The Enterprise-Tool Distinction
Running through the case law is a distinction that should drive corporate policy: the difference between a public AI tool and an enterprise tool that contractually preserves the confidentiality of user inputs. Where a company communicates sensitive information to an enterprise system that maintains confidentiality, the outcome of a privilege or waiver analysis may differ from the outcome where the same information is fed into a public tool that retains and may use the inputs.
This distinction is one a company controls in advance. The choice of AI infrastructure, public or enterprise, confidential or not, shapes the protection available later. A defendant that has routed sensitive analysis through a confidentiality-preserving enterprise system is in a materially stronger position to assert protection than one whose employees used public tools. The protective-order practice now developing, in which courts proactively update protective orders to address the data-retention and privacy risks of open AI systems, reinforces that the system matters as much as the content.
Legal Holds and the Erosion of Presumptive Protection
The second preservation frontier concerns the legal hold itself. A company's litigation-hold notices and preservation decisions have traditionally enjoyed a degree of work-product protection. That protection is not absolute, and a defendant should understand where it can erode, because the same proportionality and relevance principles that govern AI prompts govern preservation disputes.
When a party makes a preliminary showing that spoliation may have occurred, the details of a hold, its timing, its scope, and its execution, can become subject to inquiry. Preservation policy and the adequacy of a hold's implementation are increasingly examined when an adversary contends that relevant ESI was lost. For AI data specifically, this convergence is acute. The novelty of the data source, the variety of systems in which it lives, and the speed at which logs may be overwritten all heighten the risk that a preservation gap becomes a spoliation question.
Rule 37(e) remains the anchor. For electronically stored information that should have been preserved and was lost because a party failed to take reasonable steps, Rule 37(e) governs the consequences. The most severe sanctions, including adverse-inference instructions, require a finding that the party acted with the intent to deprive another of the information's use. That intent requirement is the defense's anchor. A company that took reasonable preservation steps, even if some data was lost, is positioned to resist the most serious sanctions by showing the absence of intent to deprive.
Structuring AI Use and Preservation Now
The decisions in this area reward preparation and punish improvisation. A company that has structured its AI usage and preservation deliberately enters any dispute on far stronger footing. The following measures reflect that discipline.
Govern the choice of AI systems. Direct sensitive and litigation-related work to enterprise tools that contractually preserve the confidentiality of inputs, and restrict the use of public tools for such work. The system choice is the single most consequential lever a company controls before any dispute arises, because it shapes whether protection is even available.
Map AI data sources for preservation. Identify where prompts, outputs, and activity logs are generated and stored across the organization's AI tools. A company cannot preserve what it has not catalogued. Our discovery strategy and management teams build AI data into the preservation map so that a legal hold reaches these sources rather than overlooking them.
Issue holds that expressly reach AI data. A legal hold drafted before generative AI was ubiquitous may not capture prompts, outputs, and logs. Holds should name these data categories expressly and account for the short retention windows some systems apply, so that relevant material is preserved before it is overwritten.
Document the compliance judgment. Because both the privilege analysis and the Rule 37(e) analysis turn on what the company did and why, contemporaneous documentation is decisive. Our internal investigations and pre-litigation counseling teams help companies establish AI-use governance and preservation protocols before litigation, and reconstruct the relevant record when a dispute arises, so that the company can demonstrate reasonable steps and contest waiver from a position of evidence rather than assertion.
Conclusion
Generative-AI data has entered discovery as a first-class category of ESI, and the early decisions apply the familiar Rule 26(b)(1) framework to it without special solicitude. Corporate prompts and outputs are being ordered into production, the protections a company might assert over them are genuinely unsettled, and the legal hold that should capture this data is itself subject to scrutiny when preservation fails. The companies best positioned are those that act before any of this is tested: governing which AI systems handle sensitive work, mapping and preserving AI data sources, issuing holds that reach prompts and logs expressly, and documenting the reasonable steps that Rule 37(e) rewards. In this area, the discovery fight is won or lost long before the motion is filed, by the structure a company put in place when it had the chance.
The record, structured early.
Before the Next Hold
Governance decisions made now shape what a court sees later. Our eDiscovery team works with clients on legal hold structure and preservation protocols. That includes how new AI tools fit into both.