10 min read

Everything They Typed Before They Called You : The Explotations Stack 5 of 5

Nina Okafor spent two evenings on ChatGPT before she called a lawyer. The contract dispute with her former business partner had been building for months, and she wanted to understand her position before spending money on an attorney. She typed her version of the facts. She asked about breach of contract standards in her state. She described the partnership agreement’s key terms and asked whether they supported her claim. She laid out her strongest argument, then asked ChatGPT to identify the weaknesses in it. She typed the question she most feared: what would her partner say in response, and how strong would that argument be? She got useful answers. She felt prepared. She called Catherine’s office the next morning. What Okafor did not know, and what Catherine did not think to ask, was that every query Okafor had typed was stored on OpenAI’s servers. The two evenings of research, the vulnerability assessment she had run on her own case, the counterarguments she had identified and weighed, all of it sat in a database that a properly served civil subpoena could reach. Opposing counsel served that subpoena four months into discovery. *[Nina Okafor is a composite character representing patterns documented in AI platform terms of service, discovery practice, and the January 2026 OpenAI log production order. No specific individual or matter is depicted.]* This is Part 5 of The Exploitation Stack. The series has examined Section 702 government databases, wrong number calls that create surveillance entries, employer handbooks that function as pre-signed privilege waivers, and license plate cameras that cannot be destroyed because they are never owned. Part 5 examines the most intimate layer of the stack: the research your client conducted in their own home, on their own device, before they knew litigation was coming. [For the post-engagement dimension of AI and privilege, see “The Heppner Problem: When AI Destroys Attorney-Client Privilege,” Morris Legal Technology Blog, February 2026.] # The Research Before the Relationship Attorney-client privilege protects communications between a lawyer and client made for the purpose of seeking or providing legal advice. The protection requires an attorney-client relationship. It requires a communication. It requires an intent to keep the communication confidential. Pre-engagement AI research satisfies none of those requirements. When Okafor typed her facts into ChatGPT on a Tuesday evening, she had no attorney. She had no attorney-client relationship. She was not communicating with a lawyer. She was communicating with a commercial platform that had told her, in its terms of service, that it reserved the right to use her inputs for model training and to disclose information to third parties including government authorities. The communications were not confidential by design. They were submitted voluntarily to a platform that expressly disclaimed the obligation to protect them. The privilege question does not arise at all in this scenario. There is no privilege to waive, because there was no privileged relationship when the queries were made. The prior pieces in this series each involved some mechanism by which privilege that existed was stripped away. This piece involves research that was never privileged in the first place, but which reveals everything a litigant thought about their case before they understood the rules of the game they were entering. # What a Pre-Engagement Research Log Contains People who use AI to research their legal situation before calling an attorney tend to produce the most useful evidence opposing counsel could want. They are unguided by privilege warnings, unaware of litigation strategy, and entirely candid about their situation, their fears, and their weaknesses. A typical pre-engagement research session in a commercial dispute produces: a detailed factual narrative from the client’s perspective, stated as clearly as the client can manage because they are trying to get accurate answers; an identification of the client’s strongest claims, because that is what they ask about first; an analysis of the weaknesses in those claims, because a careful person asks the AI to stress-test their position; a description of what the opposing party is likely to argue, because the client wants to understand the full picture; and often a question about settlement value or litigation risk, because the client is trying to decide whether the dispute is worth pursuing. Opposing counsel who subpoenas those logs receives, in the client’s own words, the client’s unfiltered assessment of their case before any attorney shaped it. The client’s honest view of the dispute. The arguments they found most threatening. The weaknesses they already knew existed. Every alternative theory they considered and rejected. The litigation research memo that no attorney ever wrote, produced by the client themselves before they knew to be careful. # The Discovery Mechanism Is Established On January 5, 2026, U.S. District Judge Sidney Stein of the Southern District of New York affirmed a magistrate judge’s order compelling OpenAI to produce 20 million de-identified ChatGPT logs in consolidated copyright litigation brought by news organizations. OpenAI had retained, by its own admission, tens of billions of such logs in the ordinary course of business. The court found that the magistrate judge had adequately balanced user privacy against relevance, that the de-identification and protective order framework was sufficient, and that no authority required the court to order the least burdensome means of production rather than the full sample. The court’s framing of the privacy question is the element that matters for this series. Courts distinguish, it noted, between users who voluntarily share information with AI systems and subjects of covert surveillance. The distinction will shape discovery disputes across AI litigation. Okafor typed her case analysis into ChatGPT. She was not surveilled. She submitted that analysis voluntarily to a platform whose terms she had accepted. The privacy calculus that protects a wiretap victim does not protect a voluntary disclosure. The In re OpenAI ruling addressed a copyright case, not a commercial dispute between private parties. But the mechanism it confirms operates identically in both contexts. AI platform logs are discoverable records. They are subject to civil subpoena. They are producible under protective order with de-identification. The scale of the In re OpenAI production, 20 million logs in a single case, establishes that courts will not treat the production of AI log data as categorically burdensome or impermissible. # The Work-Product Argument and Why It Usually Fails Here The strongest counterargument runs through work-product doctrine. In November 2025, Magistrate Judge Anthony Patti of the Eastern District of Michigan held that a pro se civil litigant’s ChatGPT queries and the AI’s responses qualified for work-product protection. The court found that the materials reflected the plaintiff’s mental impressions prepared in anticipation of litigation, and that disclosure to ChatGPT did not waive work-product protection because waiver requires disclosure to an adversary or in a manner likely to reach an adversary’s hands. The Eastern District of Michigan ruling creates the strongest available defense for clients who used AI to research their legal situation. If the research was conducted in anticipation of litigation, and if the client can establish that ChatGPT was not the equivalent of an adversary, work-product doctrine might apply. Three problems collapse this defense in most pre-engagement scenarios. First, work-product doctrine protects materials prepared in anticipation of litigation. Okafor spent her two evenings researching before she decided whether to pursue the matter at all. Her research was conducted in anticipation of a decision, not in anticipation of litigation. The doctrine’s trigger had not yet fired. Second, work-product protection belongs to the attorney, not the client. A client conducting solo research before retaining counsel has no attorney whose work product is being protected. Third, the E.D. Michigan ruling involved a pro se litigant who was already a party to pending litigation. That fact pattern differs meaningfully from a potential client conducting pre-engagement research. The Heppner court in the Southern District reached the opposite conclusion, finding privilege and work-product arguments both failed when the defendant acted without counsel’s direction. The circuit tension is real and unresolved at the appellate level. The honest assessment: work-product protection for pre-engagement AI research is a plausible argument in some circuits, a losing argument in others, and untested at the appellate level everywhere. The attorney who assumes protection exists is making a bet on doctrine that has not been confirmed. The attorney who prepares for the possibility that opposing counsel will subpoena those logs is doing their job. # The Steelman: The Research That Helps Both Sides The argument for the other side has substance. Pre-engagement AI research often reflects a client’s honest attempt to understand their situation, not to conceal it. A client who researches their position and identifies its weaknesses before calling an attorney may be a better, more self-aware client than one who arrives with an unexamined account of events. The research is not inherently inculpatory. It is informational. The stronger steelman is structural. If pre-engagement AI research is freely discoverable, the chilling effect on legal self-education is real. People with legal problems need to understand their situation before they can decide whether to seek legal help, how urgently, and from whom. AI has democratized access to legal information in ways that benefit people who cannot afford immediate attorney consultation. A rule that treats that research as a free evidentiary gift to opposing counsel creates an incentive to remain ignorant, which serves no one. These concerns are genuine. They are also concerns for Congress, not for courts applying existing doctrine. The court in In re OpenAI applied existing discovery rules to a new technology. It did not invent new rules to disadvantage AI users. The question of whether pre-engagement AI research deserves categorical protection is a legislative question, not a judicial one under current law. The risk exists while the law catches up. # The Heppner Distinction: Before the Call Versus After The Heppner pieces in this blog series analyzed a specific fact pattern: Bradley Heppner typed his defense strategy into consumer AI after engaging Quinn Emanuel, after his attorneys had given him privileged advice that he then fed back into the platform. That fact pattern involved a privilege that existed and was destroyed by voluntary disclosure. # The Research That Mapped Her Own Weaknesses Okafor spent two evenings becoming an informed potential client. She identified what her partner would argue. She assessed how strong that argument was. She noted in one query that a particular term in the partnership agreement might cut against her. She asked whether that term was enforceable. She typed the answer she feared, then asked for confirmation. Catherine never saw those queries. Opposing counsel subpoenaed them in the fourth month of discovery and built their summary judgment motion around the weakness Okafor had identified herself, in her own words, before she had anyone to advise her that she should keep her concerns to herself. Okafor had done everything right. She had educated herself. She had stress-tested her position. She had called a lawyer. She had trusted the process. Nobody told her that her homework was the other side’s opening brief. # About the Author JD Morris is Co-Founder and COO of LexAxiom, an AI platform for the business of law. He holds a Master of Legal Studies from Texas A&M University School of Law, a Master of Engineering from George Washington University, and dual MBAs from Columbia Business School and UC Berkeley Haas. He writes the Morris Legal Technology Blog under the series banner “The Technology Blind Spot.” Connect with him on LinkedIn at[www.linkedin.com/in/jdavidmorris](http://www.linkedin.com/in/jdavidmorris), on X at @JDMorris_LTech, or on Bluesky at @JDMorris-ltech.bsky.social. # References 1. In re OpenAI, Inc. Copyright Infringement Litigation, No. 1:25-md-03143 (S.D.N.Y. Jan. 5, 2026) (affirming order to produce 20 million de-identified ChatGPT logs; courts distinguish voluntary AI submissions from covert surveillance; AI interaction logs subject to standard civil discovery rules). 2. Warner v. [defendant], E.D. Mich. (Nov. 5, 2025) (Magistrate Judge Anthony Patti) (pro se civil litigant’s ChatGPT queries and AI responses protected by work-product doctrine; materials reflected mental impressions prepared in anticipation of litigation; disclosure to ChatGPT did not constitute waiver because waiver requires disclosure to adversary or in manner likely to reach adversary). 3. United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 10, 2026) (oral ruling); Written Opinion (Feb. 17, 2026) (31 AI-generated documents not privileged; defendant acted without counsel’s direction; platform terms disclaimed confidentiality; no attorney-client relationship satisfying privilege elements; work-product doctrine also rejected). 4. In re OpenAI, Inc. Copyright Infringement Litigation, 802 F. Supp. 3d 688, 699 (S.D.N.Y. 2025) (cited in Heppner; AI users do not have substantial privacy interests in communications with publicly accessible AI platforms). 5. OpenAI, Terms of Use (consumer tier; data may be used for model training; company may disclose information to third parties including government authorities; warranty of security disclaimed). 6. OpenAI, Data Retention Statement (standard 30-day deletion; Zero Data Retention enterprise agreements carved out from preservation order; April-September 2025 historical data retained under legal hold). 7. Cleary Gottlieb, “Courts Grapple with Privilege Implications of AI” (March 2026) (analyzing Heppner and E.D. Michigan circuit tension on AI and privilege/work-product). 8. ABA Formal Opinion 512 (2024) (attorneys must assess likelihood of disclosure and unauthorized access when advising clients on AI tool use; client consent to AI requires more than boilerplate). 9. ABA Model Rule 1.6(c) (reasonable efforts to prevent unauthorized disclosure of client information). 10. ABA Model Rule 1.1, Comment [8] (2012 technology competence amendments). 11. Fed. R. Civ. P. 26(b)(1) (scope of civil discovery; relevance; proportionality). 12. Fed. R. Evid. 502(b) (inadvertent disclosure; reasonable steps to prevent disclosure required to support privilege claim). 13. Morris, JD. “The Heppner Problem: When AI Destroys Attorney-Client Privilege.” Morris Legal Technology Blog, February 2026 (post-engagement AI privilege destruction). 14. Morris, JD. “The Exploitation Stack, Parts 1-4.” Morris Legal Technology Blog, March 2026. 15. Morris, JD. “Your AI Tool Doesn’t Keep Secrets.” Morris Legal Technology Blog, 2025 (platform-by-platform confidentiality disclaimer analysis).

Originally published on LinkedIn Newsletter: The Technology Blind Spot

Leave a Reply

Discover more from The Technology Blind Spot

Subscribe now to keep reading and get access to the full archive.

Continue reading