A deposition has always been a memory test with a document check attached. The witness is asked what she knew and when she knew it, reconstructs an answer years later under oath, and the answer holds unless a writing contradicts it. The supply of contradicting writings was the natural limit. Most of what a person thought at the time left no trace at all.
For anyone who uses a chatbot, that limit is gone. A person working through a worry with an AI assistant types out the reasoning as it happens, in the register people reserve for when nobody is listening, and the platform files it with a timestamp. The witness has generated a contemporaneous record of her own state of mind and has no memory of generating it. Her lawyer has never seen it. Opposing counsel can ask for it in a single request.
Two federal courts reached the discovery question a week apart in February 2026 and came out differently. Both were arguing about the wrong category.
The request is ordinary
Nothing about the mechanics is novel. Rule 34 and its state analogues reach documents within a party’s possession, custody, or control, and a consumer account the party can log into and export satisfies that standard the way a personal email account does. The Stored Communications Act governs a different transaction. It tells a company holding its users’ messages when it may disclose the contents, and civil discovery is absent from the list of permitted disclosures, which is how providers of email and social media have defeated subpoenas for a user’s messages. Whether that analogy carries to OpenAI has never been litigated, a problem I have written about at length in the AI injury context. The Act regulates what the company may hand over, and it leaves untouched what the user must.
The defense bar has already worked this out. Tyson & Mendes published a discovery framework in 2026 that treats AI chat records as discoverable documents like any other, recommends going to the party rather than the platform precisely because the party can export, and supplies sample request language instructing the responding party to produce conversations with timestamps. The same framework pairs the written request with deposition questions and requests for admission that lock down which tools the deponent used, when, and on what subjects, so that the document request cannot later be characterized as a fishing expedition. Assume the request is drafted and in circulation, because it is.
Which rule the court reached for
In Warner v. Gilbarco, Inc., decided in the Eastern District of Michigan on February 10, 2026, the defendants in an employment discrimination action moved to compel a pro se plaintiff to produce everything concerning her use of third-party AI tools in connection with the lawsuit. Magistrate Judge Anthony P. Patti denied the motion. Rule 26(b)(3) covers materials prepared in anticipation of litigation by or for a party or her representative whether or not a lawyer drafted them, and the court held that generative AI programs are tools rather than persons, so running a draft through one is not disclosure to an adversary and waives nothing. Compelling production would have exposed the plaintiff’s own analysis and mental impressions. The court found the request disproportionate as well.
Seven weeks later a second court took the same route. Morgan v. V2X, Inc. is another pro se employment case, this one in the District of Colorado, where the defendant asked which AI tool the plaintiff had used and argued that using one forfeited work product. On March 30, 2026, Magistrate Judge Maritza Dominguez Braswell held that Rule 26(b)(3) broadly protects materials that any party rather than only counsel prepares in anticipation of litigation, and that conditioning the protection on attorney involvement “finds no support in the rule’s text.” She ordered the plaintiff to name the tool, reasoning that a product name by itself discloses no mental impressions. She also wrote an AI provision into the protective order, barring confidential material from any platform whose provider will not contractually forgo training on it, reselling it, or refusing deletion.
United States v. Heppner came out the other way, a week after Warner, on a criminal defendant in the Southern District of New York who had used a publicly available AI assistant to work up documents outlining potential defenses. How the government came by those documents shapes everything that follows. FBI agents executed a search warrant at Heppner’s home and carried out roughly thirty-one records of his exchanges with Claude, along with other papers and devices. The government never asked for them in pretrial discovery, which is why the court called his Rule 16 argument inapplicable on its face. That left the common-law doctrine, which the court described as protecting materials prepared by or at the behest of counsel, and his own lawyer conceded that Heppner had prepared these on his own volition. He had written them after receiving a grand jury subpoena, so anticipating litigation was never the difficulty. Working without a lawyer was. Attorney-client privilege failed as well, because the platform is not a lawyer, and the court found no reasonable expectation of confidentiality in a service whose privacy policy permits disclosure to third parties.
The write-ups call this a split. Put the two texts side by side and the results stop looking like a disagreement. Rule 26(b)(3), which governed Warner and Morgan, protects what is prepared “by or for another party or its representative,” and a pro se plaintiff building her own lawsuit is the party. The doctrine the Heppner court applied protects materials “prepared by or at the behest of counsel,” and a defendant who worked up his own defenses without counsel’s involvement had no counsel behind them. One chatbot session survives the party question and fails the counsel question. None of the three opinions says artificial intelligence changes either answer.
Heppner carries a further caution for anyone citing it. A court deciding what the government may use after executing a search warrant at a home answers a different question from a court deciding what a civil party must produce in discovery. Cite it for the proposition it actually holds: a litigant working alone gets no attorney work product, because no attorney was involved.
For a mass tort practitioner the useful thing is the boundary all three share. Protection starts when the party starts preparing her case. A plaintiff who spent the spring of 2024 asking an assistant what her new diagnosis meant, whether her prescription was connected to it, and what the label actually said was preparing nothing. She was frightened and looking things up. She produces those conversations the way she produces her emails and her text messages. Work product covers a party building a case, and she was two years from meeting a lawyer.
That distinction cuts against the plaintiff bar in a specific way. Counsel who reads Warner and Morgan as broad protection for AI conversations will advise a client accordingly, and the advice will be right about the four months since the complaint and wrong about the two years before it.
The date is the exhibit
In a mass tort, the damaging line in a plaintiff’s chat history is rarely an admission about the product. It is a timestamp.
The discovery rule asks when the plaintiff knew or should have known of her injury and its cause. Courts have always found that inquiry awkward to prove, because it asks what was inside a particular person’s head on a particular date and the available proof is a medical chart recording what the physician said rather than what the patient understood. A dated conversation in which the plaintiff asks an assistant whether her medication causes the condition she was diagnosed with last Tuesday answers the question directly, in her own words, on a date the defense does not have to establish through anyone’s testimony.
I have found no reported decision using a chatbot log that way, and practitioners should treat the point as a prediction rather than a holding. The underlying move is old. Defense counsel have built limitations arguments out of a plaintiff’s own dated statements for as long as plaintiffs have made dated statements. The chat log is a cleaner version of the same exhibit, because the plaintiff wrote it with no audience in mind and no reason to hedge.
The same record carries a second exposure on causation. A plaintiff who spent four months asking an assistant about every other possible explanation for her symptoms has assembled a list of alternative causes, in writing, under her own name. A defense expert will read that list before she does.
Preparing a witness for a document nobody has read
The practical burden lands on deposition preparation, and it lands early. Counsel cannot prepare a witness on a document neither of them has seen, and the client will not remember what she typed. She will remember the diagnosis and the conversation with her sister. She will not remember the eleven o’clock session in March where she asked the same question six different ways.
The only reliable answer is the export, taken at intake and read before the deposition rather than after the defense cites it. The mechanics, the chain-of-custody record, and the separate memory store that a conversation export leaves behind are covered in the preservation piece. Two additions belong here.
Ask about every assistant, not the obvious one. A client who used three platforms across two years has three archives, each with its own export path and its own retention schedule.
Ask whether she ever used a work account. A plaintiff who typed her medical questions into an employer-provisioned assistant cannot export that record, because her employer holds it rather than she does. The Stored Communications Act reaches companies that sell a messaging or storage service to the public, which is the ground OpenAI would stand on. An employer running an assistant for its own workforce sells that service to nobody, so the statute never reaches it, and the conversations are the company’s own records sitting in the company’s own hands. The objection OpenAI would raise leaves a staffing company in Fresno with nothing to say.
The corporate deponent has a log too
Every argument above runs in the other direction, and the plaintiff side has been slower to notice.
Microsoft’s own documentation states that Microsoft 365 Copilot prompts and responses are stored in the user’s mailbox. They are searchable in Purview eDiscovery by selecting a custodian’s mailbox and adding a condition for Copilot activity, or by querying the ItemClass property directly. They can be placed on eDiscovery hold, retained by policy, and exported for review. Which produces a question worth asking at the first meet and confer in any case against a defendant that has deployed Copilot: how was the custodial collection scoped, and did it capture Copilot interactions or exclude them? A standard mailbox collection sweeps them in unless somebody deliberately carved them out.
ChatGPT Enterprise works differently and the difference favors moving quickly. OpenAI’s compliance platform exposes conversation messages through a workspace-scoped admin key, and the company’s documentation states that only a workspace owner can grant broad compliance access or the conversation messages permission. The same documentation puts retention on the compliance logs platform at 30 days. A corporate defendant that has not connected an archiving integration is therefore shedding that content on a rolling monthly cycle, which makes this a preservation letter to send at the outset rather than a production dispute to have in a year.
The place to fix all of it is the protocol governing electronic evidence. An ESI protocol that lists email, messaging platforms, and shared drives, and says nothing about AI assistant interactions, leaves the question to the party holding the data. Name the source, name the platforms, and set the preservation date. Morgan shows a court willing to write the terms itself: Judge Dominguez Braswell barred confidential material from any platform whose provider will not contractually forgo training on it, and a party who proposes that language first is likelier to get it.
The expert’s prompts
The most developed ruling in this area concerns neither party. In Conservation Law Foundation, Inc. v. Shell Oil Co., No. 3:21-cv-00933 (VDO) in the District of Connecticut, Magistrate Judge Thomas O. Farrish ordered on May 18, 2026 that the Conservation Law Foundation produce the AI prompts its expert, Dr. Naomi Oreskes, used to narrow Shell’s document production into a working subset. The court held that the process by which she used AI to filter the production was part of her methodology and therefore discoverable under Rule 26(b). Her report had disclosed the use of the tool and some of the search terms, which the defense found insufficient, and her deposition on the subject prompted the motion. The foundation filed a Rule 72(a) objection on the June 3 compliance date, and the district court stayed the order pending its resolution.
The objection appears to remain pending. Counsel should confirm the current posture before relying on the order, and should change the retention letter without waiting for it. Ask every retained expert whether an AI tool touched the document review, the literature search, or the drafting. Record the answer in writing at retention. An expert who used one, said nothing, and is asked about it for the first time at deposition creates a problem considerably larger than her prompts.
What is unsettled
Four things, and anyone relying on this piece should check each against current authority.
The objection in Conservation Law Foundation. If the district judge sustains it, the methodology theory narrows to something closer to search terms. If he overrules it, the demand spreads through expert discovery on the federal docket within months, aimed at any expert who ran a corpus through a model. Getting the prompts is the opening move. Once opposing counsel has them, they feed a Rule 702 challenge to how that expert chose what she read.
The Warner and Heppner divergence. Both are district court decisions from February 2026 with no appellate treatment. Either framework could harden.
No court has yet fixed how far back into a plaintiff’s pre-suit conversations a defendant may reach. California’s constitutional privacy framework requires courts to weigh the seriousness of the intrusion against the requesting party’s need, and it favors narrow tailoring. The fight will be over time windows, topic limits, and which platforms are named, rather than over whether the material is discoverable at all.
Judge Schulman had entered no order governing electronic evidence in the coordinated ChatGPT proceeding when I last reviewed the register of actions in late August. A case management conference is calendared for September 23, and an evidence order is the natural sequel to a leadership order. Check the docket before building a collection protocol from anything written here.
The takeaway
Deposition preparation used to begin with the documents the other side produced. It now begins with the documents your client produced without knowing she was producing them, on a platform she chose, in a voice she uses with nobody else, dated to the minute.
Export first. Read what is there. Then prepare the witness.
The decisions described in this article are district court rulings that remain subject to further proceedings. This piece is editorial analysis of litigation practice and is not legal advice. Court status and platform documentation are current as of publication.