For attorney investigators, AI shouldn’t be avoided. Rather, it should be used deliberately with an understanding that traditional privilege principles still apply, Gorev Ahuja of Oppenheimer Investigations Group writes. Attorney investigators who maintain confidentiality safeguards, use approved platforms and exercise professional judgment will be best positioned to realize AI’s efficiencies while preserving protections workplace investigations require.
“Lawyers Sanctioned Over Fake AI Citations.” “AI Hallucinations Reach the Courtroom.” “Courts Warn: Attorneys Cannot Delegate Judgment to Chatbots.”
Headlines like these are increasingly common. Courts and ethics authorities have made clear that while AI can be a useful tool, it does not relieve lawyers of their duties of competence, accuracy and independent judgment. As AI becomes increasingly integrated into workplace investigations, attorneys must consider how its use affects confidentiality, privilege and work-product protections.
Investigations play a distinctive role in employment law. Employers frequently rely on attorneys to investigate allegations of discrimination, harassment, retaliation, fraud and other misconduct. When conducted by, or at the direction of, counsel for the purpose of rendering legal advice, these investigations are often protected by the attorney-client privilege and the work-product doctrine, which enable thorough and candid fact-gathering without fear of later disclosure.
AI is now reshaping the investigative process. AI tools can summarize interviews, organize large document sets, flag inconsistencies, build timelines and even draft reports. These efficiencies are significant, but they carry real legal risk.
What happens when privileged witness statements are entered into an AI platform? Are prompts and outputs discoverable? Does using AI undermine the confidentiality required to preserve privilege? These questions sit at the intersection of two rapidly evolving fields: investigations and generative AI. Although courts have not yet resolved many of these issues, existing privilege principles provide a clear starting point.
Privilege & work product for investigations
State and federal law provides significant protections for attorney-client communications and attorney work product. The attorney-client privilege safeguards confidential communications made to obtain or deliver legal advice. Separately, the work-product doctrine protects certain materials prepared by attorneys in connection with legal representation.
In the investigation context, these protections are important because effective legal advice often depends on thorough factual development. Courts have recognized that, under appropriate circumstances, an attorney-directed investigation is not separate from legal advice but is part of it.
The US Supreme Court’s decision in Upjohn Co. v. United States established that communications between employees and corporate counsel made to assist counsel in providing legal advice are protected under the attorney-client privilege. States, including California, have built on that principle. In City of Petaluma v. Superior Court, the appeals court held that an outside attorney’s investigative report into alleged misconduct was protected by both the attorney-client privilege and work-product doctrine, even though the attorney’s role was primarily limited to fact-gathering, because the investigation was conducted for the purpose of providing legal services.
Other decisions have reinforced the strength of these protections in California. For example, Costco Wholesale Corp. v. Superior Court underscores the broad scope of the attorney-client privilege once it applies, while Coito v. Superior Court recognizes robust work-product protections for attorney interview materials reflecting an attorney’s impressions, conclusions, opinions or legal theories.
The takeaway is that attorney-directed investigations may receive substantial protections. As with any privilege analysis, however, the availability and scope of those protections depend on the specific facts and circumstances, including whether confidentiality has been maintained.
AI & the fragility of confidentiality
Privilege exists only so long as confidentiality is maintained. That requirement becomes more complex in the context of AI. Traditionally, attorneys relied on human intermediaries, such as paralegals, consultants and eDiscovery vendors to assist with analysis. Courts have generally found that using these agents does not waive privilege when their involvement is reasonably necessary to facilitate the provision of legal advice.
AI presents different considerations. Many platforms rely on cloud-based systems operated by third-party providers. Depending on the platform and applicable terms of use, information entered into the system may be stored, processed or retained by the provider to improve the system. This raises a critical question: Does entering privileged information into an AI system constitute disclosure to a third party?
Courts have not yet provided a definitive answer, but emerging case law offers useful guidance regarding how traditional privilege principles may apply in this developing context.
In Tremblay v. OpenAI, Inc., a federal court addressed whether AI prompts are discoverable. The court recognized that attorney-crafted prompts can reveal legal theories, strategy and mental impressions. As a result, it suggested that such prompts may qualify as opinion work product, which receives near-absolute protection. Another court reached the same conclusion. In Concord Music Group, Inc. v. Anthropic PBC, the court similarly recognized work-product protections for attorney-crafted investigative prompts and related outputs under the circumstances presented.
For investigators, this is significant. Prompts used to draft or analyze witness testimony, assess credibility, organize evidence or develop findings often reflect the investigator’s mental impressions, strategy or approach to a matter. Under Tremblay, such prompts may qualify for work-product protection. However, that protection is not automatic. Courts will likely examine the content, context and purpose of the prompts to determine whether they reveal the attorney’s thought processes.
A more cautionary note appears in United States v. Heppner. There, a defendant used a public AI platform to generate materials discussing legal theories and defenses. When those materials were later seized, the court rejected claims of privilege and work-product protection. The reasoning was straightforward: The communications were not with an attorney; they were voluntarily disclosed to a third-party provider, and they were not created at counsel’s direction.
The implications are significant. Under Heppner, using a consumer AI platform to process privileged investigation materials may create a strong argument that confidentiality, and therefore privilege, has been waived.
Importantly, the case involved a public platform and did not involve an attorney performing legal work on behalf of a client. Thus, it left open the question of whether an attorney using enterprise AI systems with contractual confidentiality protections should be treated differently.
Warner v. Gilbarco, Inc. presented different facts and reached a different outcome. There, a self-represented plaintiff in an employment discrimination case used a generative AI tool to prepare litigation materials. The defendants moved to compel production of all materials related to that AI use, arguing that any applicable protections had been waived. The court denied the motion. In addressing work product, the court drew a key distinction: Attorney-client privilege is waived by disclosure to a third party, but work-product protection is waived only by disclosure to an adversary or by conduct likely to place the material in an adversary’s hands. Because AI tools are “tools, not persons,” the court held that entering litigation materials into such a tool did not constitute disclosure to an adversary. The court also concluded that the defendants improperly sought the plaintiff’s internal analysis and mental impressions, which qualified as work product because she prepared them in anticipation of litigation.
The most recent decision, Morgan v. V2X Inc., involved a pro se plaintiff in another employment discrimination case. In that case, the defendant sought to amend a protective order to include AI-specific restrictions and to compel disclosure of which AI platform Morgan used. Morgan argued that his tool selection was protected work product. The court granted the motion in part.
The Morgan court declined to adopt Heppner’s approach, concluding that intermediary access to data does not automatically waive protections. However, the court held that the identity of the AI tool was not protected and ordered its disclosure. It also crafted an AI-specific protective order: No party may input confidential information into an AI platform unless the provider’s contract prohibits using inputs for training or disclosing them to third parties.
Practical guidance
Courts are beginning to apply traditional privilege and work-product principles to AI-assisted work. In doing so, they continue to ask many of the same questions that have long governed privilege analyses: whether there was a qualifying relationship, whether confidentiality was maintained and whether the materials were prepared in anticipation of litigation and reflect a party’s, attorney’s or investigator’s mental processes.
AI presents a new factual context for these questions, not an entirely new set of rules. Many questions remain unsettled, however, and outcomes are likely to depend heavily on the specific facts, including the nature of the AI platform used and the confidentiality protections in place.
AI can improve efficiency in document review, evidence organization, chronology development and drafting. However, investigators remain responsible for evaluating credibility, weighing evidence, resolving conflicts in the record and reaching findings. AI-generated outputs should be independently reviewed and verified before being incorporated into an investigative process or report. AI may assist these processes, but it cannot substitute for professional judgment.
In the investigation context, these cases suggest that attorneys and organizations should take thoughtful steps when using AI to assist with investigations while preserving applicable privilege and work-product protections. Several principles emerge from the developing case law:
- Ensure that any AI-assisted investigative work is conducted by or under the direction and supervision of counsel. This may strengthen the argument that the work was undertaken in connection with the provision of legal services and therefore qualifies for attorney-client privilege or work-product protection.
- Choose platforms carefully. Not all AI systems are equal. Enterprise platforms with contractual confidentiality protections and restrictions on data use present far lower risk than public, consumer-facing tools.
- Adopt clear policies governing AI use. Organizations and attorneys should establish policies addressing approved tools, confidentiality safeguards, data handling practices, prompt retention and deletion, human review requirements and quality-control protocols.
- Assume that AI prompts, outputs and activity logs may be discoverable. As with emails, memoranda to clients and investigation reports users should approach AI-assisted work with the expectation that their inputs and outputs may later be subject to scrutiny.


Gorev Ahuja, AWI-CH, is an attorney with Oppenheimer Investigations Group, an investigations law firm that conducts impartial workplace and school investigations, trainings, executive coaching, expert testimony and mediations. 










