What the courts have decided, why it applies in Maryland, and five rules for every client
In February 2026, a federal judge in New York decided a question that no court had faced before. A man who knew he was the target of a federal investigation had used an AI chatbot to write about his defense strategy and the charges he expected. Agents searched his home and seized about thirty documents recording those chats. His lawyers argued that the attorney-client privilege protected the documents, because he had typed some of what they had told him into the chatbot and had written the documents to prepare for meetings with them. That privilege normally keeps what a client says to a lawyer out of court. The judge held that none of the documents were protected. Even if some had been, the man gave up that protection when he typed that information into the chatbot, “just as if he had shared it with any other third party.” 1
Since then, courts across the country have been deciding what happens when people put their legal problems into these tools. No Maryland court has decided whether putting your case into one of these tools costs you the privilege. When Maryland courts face a new question, they consider rulings like this one, and Maryland’s own law answers most of the rest. The answers matter to anyone with a legal matter of any kind, from a divorce to a criminal charge to a dispute over a will.
The law is the same in every kind of case this firm handles. A person charged with a crime who asks a chatbot what the police can recover from his phone has written the question the prosecutor will read. A parent in a school discipline case who pastes the district’s confidential evaluation of her child into a chatbot has given it to a company. A person contesting a will, or expecting one to be contested, who types out what a parent said before death has created a statement the other heirs can demand. And someone facing a commitment hearing, or helping a family member through one, has put the most sensitive facts of all where a court can order them produced. The examples below come from divorce and custody cases because those are the most common, but every rule in this post applies to all of them.
The other side may get whatever you type into an AI tool
What you type into ChatGPT, Claude, Gemini, Copilot, or any similar tool is your own statement. It is not privileged, because you were not talking to a lawyer. It is not confidential, because the company that runs the tool keeps a copy, and its terms let it read that copy, train the product on it, and give it to the government when the law requires. And it is evidence, because the words are your own, so the other side can make you produce it in discovery and read it to the judge. Paste something your lawyer sent you into one of these tools and you probably lose the protection that message had, whatever you meant to keep private.
Five rules for using AI tools while your case is open
- Treat anything you type into an AI tool as something the other side may read, and keep names, dates, and other identifying details out of it.
- Do not put your lawyer’s advice, a draft your lawyer is writing, or your spouse’s private messages into any AI tool, and do not connect your email, documents, or calendar to one.
- Do not run an AI note-taker or recording app during any call or meeting, including calls with your lawyer. In Maryland that is not only a privilege problem. Recording a conversation without the permission of everyone in it is a crime here. 22
- If you use a tool, use a temporary or incognito mode, which keeps the chat out of your saved history and out of what the tool remembers. Do not use a work AI account for anything about your case, and do not share a chat about your case by link. The company still keeps a copy for a time, and a court can order it produced.
- If you have already done any of this, tell your lawyer now, and do not delete anything. Experts can recover deleted chats, and in Maryland a jury can be told to hold the deletion against you even if you were only careless.
No privilege covers a chat you have with a chatbot without your lawyer, for three reasons
Any one of the three is enough to let the other side use your chat.
Your chat is not privileged, because you were not talking to a lawyer
The attorney-client privilege works as a test with three parts. If you communicate with a lawyer, in confidence, to get legal advice, then neither of you can be made to repeat it in court. Fail any one of the three and nothing is protected. Maryland’s highest court has said the privilege is “narrowly construed,” and it places the burden of proving every part on the person claiming it. 2 To keep a chat out of court, you would have to prove that the chatbot was working for your lawyer. A chatbot is not a lawyer, so a chat with one fails the first requirement, communication with a lawyer.
Writing something for your lawyer does protect it. Maryland has held since 1909 that the privilege covers documents a client prepares at the lawyer’s request. In 2003 the Appellate Court applied that rule to maps and notes a defendant drew because his lawyer asked for them. 3 But a chat you have with a chatbot to get its answer is not that kind of document, and nobody asked you to create it.
Sending the chat to your lawyer afterward does not protect it. Maryland’s highest court has held that a party “cannot shield materials from discovery, and confer on them the cloak of confidentiality, simply by routing them through its legal counsel.” 2 The New York court said the same of AI chats. They are “not somehow alchemically changed into privileged ones upon being shared with counsel.” 1
The privilege covers a non-lawyer only as the lawyer’s agent, someone whose services the lawyer required in order to prepare the case. 4 Maryland applies that exception to people brought inside the representation and refuses it to people outside it. A man once gave a recorded statement to his own insurance company’s adjuster. The Appellate Court held it unprivileged, because the adjuster took the statement “not as an agent of appellant or appellant’s privately retained counsel,” and the statement “was not requested by, and was not for the use of,” his counsel. 5 A chatbot you signed up for yourself, without your lawyer’s direction, is even less connected to your case than that adjuster was. A chat with a chatbot is not a privileged communication, and nothing you do with it afterward makes it one.
Your chat is not confidential, because the company keeps a copy
The privilege protects only a communication made in confidence. Maryland’s highest court has said that “generally the presence of a third party will destroy the attorney-client privilege,” and that the question is whether you could reasonably understand the conversation to be confidential given what you knew. 6 It has also adopted the rule that if you communicate information “with the understanding that the information will be revealed to others,” that information does not enjoy the privilege. 2
You accepted an understanding of exactly that kind when you opened the account. Each of the major AI companies, the makers of ChatGPT, Claude, Gemini, Copilot, and Grok, publishes terms that say the same thing. In the normal setting the company keeps your chats and may use them to train its models unless you opt out. 7 Four of the five offer a private mode that is not used for training. Those chats are deleted after seventy-two hours to thirty days, depending on the company. The details differ in two places. Google has human reviewers who read a subset of chats, and Microsoft’s personal Copilot has no private mode at all. Every one of them also lets you download your entire history from your account settings, which means the other side can make you produce it.
The companies also produce chats themselves. Each set of terms reserves the right to disclose content to comply with law or legal process, and Meta’s policy names “civil litigants” alongside government requesters, which means the other side in your case. 8 In the copyright lawsuit against OpenAI, the company behind ChatGPT, a federal court ordered it to keep users’ deleted chats and later to produce twenty million conversations. 9
Your chat is evidence, because the words are your own
Even where no privilege was ever in play, your chat is discoverable if it relates to the case, and your own words in it are admissible against you as your own statement. 10 The tool’s answers can be admitted as well, as the context for your questions.
Courts have already done this. In June 2025 a Michigan defendant asked ChatGPT whether deleted emails could be recovered under a subpoena. A forensic examiner found the question on his devices, and the court called it “compelling evidence of intentional deprivation of information” and ordered him to pay the other side’s fees. 11 Nobody argued the conversation was privileged. It was his own statement, and the question was the proof of what he was thinking. In a Los Angeles case, a court ruled that a teenage plaintiff’s ChatGPT chat could be used against him at trial as his own statement; he withdrew the case before the trial began. 12 Federal agents in California seized a defendant’s phone and found ChatGPT open on the screen, and his prompts became evidence. 13
The larger risk is not losing a privilege but creating a record that never had one.
Pasting what your lawyer sent you into an AI tool probably costs the privilege for that message
Maryland does not ask whether you meant to lose it
Many people believe you cannot lose the privilege unless you intend to give it up. Maryland has never required that, and its highest court has said so twice. It has held that “[o]nce the confidential matter has been disclosed, it is no longer secret and the privilege which might be claimed disappears.” 14 And it has adopted the rule that “when his [the client’s] conduct touches a certain point of disclosure, fairness requires that his privileges shall cease whether he intended that result or not.” 15 Lawyers call that loss a waiver. Your conduct decides it, and pasting a privileged message into a tool whose terms let the company keep and share the message is exactly that conduct.
An accident does not save you either. The Appellate Court has held that an inadvertent disclosure can waive the privilege, and the first thing it looks at is how reasonable your precautions were. 16 Maryland’s discovery rule says the same for material produced in a lawsuit. An inadvertent disclosure does not waive the privilege only if you took reasonable precautions to prevent it and moved promptly to fix it once you knew. 17 Accepting terms that let a company keep your words, have its staff read them, train on them, and give them to the government is not a reasonable precaution against disclosure. It is consent to it.
Maryland also does not require proof that anyone actually read what you exposed. Its highest court has said that a “reasonable expectation of third party disclosure” is one of the “quintessential situations negating any reasonable expectation of confidentiality.” 20 A man left a message on an answering machine in a home he knew was shared with two other people. No one proved that anyone else heard it, and there was no evidence about where the machine sat or who could reach it. The Appellate Court held he had no reasonable expectation that the message was confidential, because “he ran the risk that someone other than [the recipient] would retrieve the message.” 18 A consumer AI account, whose terms tell you in advance that staff may read your chats, is a shared machine you were warned about.
No Maryland court has ruled on AI tools, and two Maryland decisions cut the other way
No Maryland court has applied any of this to a company like OpenAI or Anthropic, and honesty requires naming the two Maryland decisions that point the other way.
In 2003 the Appellate Court held that documents a defendant prepared at his lawyer’s request stayed privileged even after a correctional officer lawfully searched his cell, found them, and read them. The court agreed he had no expectation of privacy in the cell at all, and held the privilege survived anyway. 3 That case is different in the way that decides it. Nothing was disclosed. His papers were taken from him. Maryland’s waiver rule asks what you disclosed, and a man in a cell disclosed nothing. A client who types a privileged message into a chatbot has given it to a company, on terms she accepted, with other options available.
In 2018 the Appellate Court rejected an argument that a wireless carrier’s privacy agreement, which allowed disclosure under subpoenas and court orders, destroyed the confidentiality of a customer’s text messages. 19 Three things limit that ruling. The higher court reversed the decision, so the passage is no longer binding on anyone. 20 A carrier that transmits and stores a message is not the same as a company that reads it, trains its product on it, and says so in the terms you accepted. And in the same case the higher court said the thing that matters most here. “[T]hird party disclosure, and reasonable expectation of third party disclosure, are quintessential situations negating any reasonable expectation of confidentiality.” 20 Expectation, not proof.
None of the situations clients ask about makes a chat private, and deleting makes things worse
Temporary chats and business accounts reduce the risk without removing it
A temporary or incognito chat is better than a normal one. It stays out of your saved history and out of what the tool remembers, and it is not used for training. It is not private. Each company that offers one keeps a copy for a period, from seventy-two hours to thirty days, and keeps it longer when the law requires. 7 A business or enterprise account is better still, because those terms usually bar training on your content. Neither one keeps a court from ordering the chat produced.
Using a tool without logging in feels safer, and it can cost you the ability to opt out of training. 7
Pasting your spouse’s private messages costs you the privilege for those messages
Maryland protects confidential communications between spouses by statute. 21 The protection is lost the same way the attorney-client privilege is, by exposing the communication where someone else can reach it. That exposure is what the answering-machine case decided, and Maryland courts apply the same confidentiality test to both privileges. 18 Paste your spouse’s private message into a chatbot and you have exposed it to the company on terms you accepted.
An AI note-taker on a call is a crime in Maryland, not just a privilege problem
Do not run one. In some states this is only a privilege question, because an outsider present for a conversation destroys its confidentiality. Maryland is stricter.
Maryland law makes it lawful for a party to record a conversation only where “all of the parties to the communication have given prior consent.” 22 Recording without that consent is a felony, punishable by up to five years in prison, a fine of up to $10,000, or both. 22 And the person you recorded can sue you for actual damages, but never less than $100 for each day of the violation or $1,000, whichever is higher, plus punitive damages and attorney’s fees. 23
An AI note-taker joining a call records the call. If everyone on the call has not agreed, you are exposed on a footing that has nothing to do with any privilege, and the exposure is criminal as well as civil. Turn it off for any call about your case, including calls with your lawyer.
Using a work AI account for a personal matter puts your chat under your employer’s control
Your employer can search a work AI account and produce what it finds. Microsoft tells business customers to use its compliance tools to “search, preserve, and produce” Copilot conversations, which are kept in the same system as company email. 24 A personal matter typed into a work account is a document your employer holds and can be made to produce.
Connecting your email or files gives the tool access to everything in them
These tools offer to connect your email, documents, calendar, and browser. Connecting gives the tool access to everything inside, not just what you type. 25 These tools are also starting to act rather than only read, and a tool that can send an email in your name can create a record in your case that you never wrote. 8
The tool remembers one chat when you start another
Memory features carry information between conversations. OpenAI says that with memory on it “may remember details you’ve shared across conversations.” 26 Its own instructions say that to remove something the tool knows about you, “you’ll need to delete every source where it appears, including past chats, archived chats, files, the memory summary, and disconnect any connected apps.” The company also says the summary you can see is not everything the tool remembers. 26 Turn memory off, but do not mistake that for deleting the information. And deleting that chat does not delete the memory.
Sharing a chat by link gives it to anyone who has the link
Sharing a chat creates a copy at a web address anyone can open. Anthropic’s own help page explains that a shared link is a snapshot that stays available until you unshare it. 27 You cannot control who receives the link next.
Deleting the chat makes your position worse
Maryland treats destroyed evidence seriously, and it does so on two tracks. A judge can sanction a party who intentionally destroys evidence. The duty to preserve starts before any case is filed, as soon as a lawsuit “is fairly perceived as imminent.” 28 The second track is the one clients most often overlook. A Maryland jury can be instructed that if a party negligently failed to preserve evidence, the jury “may, but [is] not required to, infer that the evidence, if preserved, would have been unfavorable to that party.” 29 Careless is enough for that instruction. If you meant to conceal it, the inference becomes mandatory. 29
The Michigan man in the earlier example had no innocent explanation, because his own ChatGPT question showed why the emails were gone. 11 Your chat can be the evidence that defeats your explanation.
Deleting also does less than clients assume. Every one of these companies keeps some chats past the point where you deleted them, and every one makes an exception for what it must keep for legal reasons. Google keeps a chat that a human reviewer has seen for up to three years even after you delete your activity. Anthropic keeps a flagged chat for two, and Meta takes up to 90 days to delete and “up to another 90 days” to clear its backups. 7 8 If you have already typed something about your case into ChatGPT or any similar tool, tell your lawyer now and leave the chat where it is.
The work-product rule covers only what you wrote because a lawsuit was coming
Work product, a second protection, covers less than clients expect. Maryland’s rule protects material prepared in anticipation of litigation “by or for another party,” so you can create it yourself without your lawyer’s direction. But the other side can get it by showing both that it needs what you wrote and that it cannot get the same information any other way, and the burden of proving the protection applies is yours. 30 Maryland’s highest court has held that the question is one of fact, decided at a hearing if it is disputed. A party who offers no evidence that a document was prepared for litigation rather than in the ordinary course loses the protection. 31
Two consequences follow for chats. A chat from before any dispute existed is not protected, because no lawsuit was coming when you typed it. And the facts you typed can still be asked about at a deposition or in writing, even when the document itself is protected.
Two courts elsewhere have protected the AI research of people who had no lawyer, and one of them barred confidential information from “any mainstream AI tool like standard ChatGPT, Claude, Gemini, or similar platforms” even as it protected the research. 32 None of this is a reason to relax any of the five rules.
You can still use a chatbot to understand a court form, but not to talk about your case
We have told co-parents they can use these tools to make a court form or an order easier to read, and that advice stands. 33 The line is the same one it always was. Use a chatbot to learn what a word means or how a process works. Do not use it to talk about your case, your spouse, your children, or anything your lawyer sent you.
If you have already done it, say so today. The options available depend on how fast anyone knows, and the worst version of this problem is the one your lawyer learns about from the other side’s exhibit list.
And do not even tell the McDonald’s Drive-Thru AI about your custody case. 34
This post describes Maryland law as of August 2026 and is general information rather than legal advice about your situation.
Sources
- United States v. Heppner, 820 F. Supp. 3d 292, 296-98 & n.3 (S.D.N.Y. 2026). https://storage.courtlistener.com/recap/gov.uscourts.nysd.652138/gov.uscourts.nysd.652138.27.0.pdf
- E.I. du Pont de Nemours & Co. v. Forma-Pack, Inc., 351 Md. 396, 718 A.2d 1129 (1998) (privilege “narrowly construed” at 406; burden on the proponent at 412-13; adopting at 416 the rule that information communicated with the understanding it will be revealed to others is not privileged; and holding at 424 that a party cannot “shield materials from discovery, and confer on them the cloak of confidentiality, simply by routing them through its legal counsel”). https://law.justia.com/cases/maryland/court-of-appeals/1998/99a97-1.html
- Carter v. State, 149 Md. App. 509, 519-20, 817 A.2d 277 (2003) (documents prepared by a client at counsel’s request are privileged; privilege survived a lawful search of the defendant’s cell) (https://www.courtlistener.com/opinion/1889276/carter-v-state/), citing Lanasa v. State, 109 Md. 602, 617, 71 A. 1058 (1909) (https://www.courtlistener.com/opinion/3487624/lanasa-v-state/).
- State v. Pratt, 284 Md. 516, 520-21, 398 A.2d 421 (1979) (holding that the privilege “embraces those agents whose services are required by the attorney in order that he may properly prepare his client’s case,” a rule the court framed as applying “at least in criminal causes”) (https://www.casemine.com/judgement/us/5914c541add7b049347d2da1); Rubin v. State, 325 Md. 552, 566-67, 602 A.2d 677 (1992). https://www.courtlistener.com/opinion/2105031/rubin-v-state/
- Cutchin v. State, 143 Md. App. 81, 94-96, 792 A.2d 359 (2002). https://www.courtlistener.com/opinion/2305608/cutchin-v-state/
- Newman v. State, 384 Md. 285, 306-09, 863 A.2d 321 (2004). https://www.courtlistener.com/opinion/1890026/newman-v-state/
- The companies’ own pages, captured August 25 and 26, 2026. OpenAI Terms of Use (https://openai.com/policies/terms-of-use/), US Privacy Policy of May 18, 2026 (https://openai.com/policies/us-privacy-policy/), and Temporary Chat FAQ (https://help.openai.com/en/articles/8914046-temporary-chat-faq); Anthropic Consumer Terms (https://support.claude.com/en/articles/12260368-use-incognito-chats) and retention page (https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data); Google Gemini Apps Privacy Hub (https://support.google.com/gemini/answer/13594961); Microsoft privacy and protections for Copilot Chat (https://learn.microsoft.com/en-us/copilot/privacy-and-protections); SpaceXAI LLC Terms of Service and Consumer FAQs (https://x.ai/legal).
- Meta Privacy Policy, effective July 23, 2026. https://www.facebook.com/privacy/policy
- In re OpenAI, Inc. Copyright Infringement Litigation (S.D.N.Y.), order of Jan. 5, 2026. https://storage.courtlistener.com/recap/gov.uscourts.nysd.612697/gov.uscourts.nysd.612697.1087.0.pdf
- Md. Rule 2-402(a) (scope of discovery); Md. Rule 5-803(a)(1) (a party’s own statement offered against that party).
- Conlan Tire Co. v. Gonzales (E.D. Mich. Aug. 11, 2025). https://storage.courtlistener.com/recap/gov.uscourts.mied.383405/gov.uscourts.mied.383405.38.0.pdf
- Ruling on R.K.C.’s Motion in Limine No. 3, No. 22STCV21355 (Los Angeles Superior Court, Apr. 20, 2026), available on Lexis at 2026 Cal. Super. LEXIS 31075. The plaintiff withdrew his claims before trial on July 22, 2026. Mitchell Black, LA Social Media Trial Dismissal Leaves Vast Landscape of Cases, Bloomberg Law (July 24, 2026). https://news.bloomberglaw.com/litigation/la-social-media-trial-dismissal-leaves-vast-landscape-of-cases
- United States v. Bauer (N.D. Cal. Sept. 2, 2025). https://storage.courtlistener.com/recap/gov.uscourts.cand.446768/gov.uscourts.cand.446768.51.0.pdf
- Harrison v. State, 276 Md. 122, 137-38, 345 A.2d 830 (1975). https://www.courtlistener.com/opinion/2311166/harrison-v-state/
- Parler & Wobber v. Miles & Stockbridge, P.C., 359 Md. 671, 692, 756 A.2d 526 (2000) (quoting Wigmore). https://www.courtlistener.com/opinion/1922148/parler-wobber-v-miles-stockbridge-pc/
- Elkton Care Center Associates Ltd. Partnership v. Quality Care Management, Inc., 145 Md. App. 532, 543-47, 805 A.2d 1177 (2002). Maryland’s highest court has not decided the question, and Elkton remains the only reported Maryland appellate authority on it. https://www.courtlistener.com/opinion/1435312/elkton-care-center-associates-ltd-partnership-v-quality-care-management/
- Md. Rule 2-402(e)(4).
- Wong-Wing v. State, 156 Md. App. 597, 607-10, 847 A.2d 1206 (2004). https://www.courtlistener.com/opinion/1481939/wong-wing-v-state/
- Sewell v. State, 236 Md. App. 96, 114 n.8, 180 A.3d 670 (2018). https://www.courtlistener.com/opinion/4474600/sewell-v-state/
- State v. Sewell, 463 Md. 291, 311-12, 319, 205 A.3d 966 (2019) (reversing on another ground; the opinion does not address the carrier). (https://www.courtlistener.com/opinion/4606084/state-v-sewell/). Under West v. State, 369 Md. 150, 157-58, 797 A.2d 1278 (2002), an intermediate court opinion reversed in its entirety on another ground “is only dicta” and “in no manner an authoritative precedent.” https://www.courtlistener.com/opinion/1537298/west-v-state/
- Md. Code Ann., Cts. & Jud. Proc. § 9-105. https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcj§ion=9-105
- Md. Code Ann., Cts. & Jud. Proc. § 10-402(b), (c)(3). https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcj§ion=10-402
- Md. Code Ann., Cts. & Jud. Proc. § 10-410. https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcj§ion=10-410
- Microsoft Purview guidance on Copilot data. https://learn.microsoft.com/en-us/purview/ediscovery-search-copilot-data
- Google, Connected Apps (https://support.google.com/gemini/answer/13695044) and personalization with Connected Apps (https://support.google.com/gemini/answer/16836988).
- OpenAI, Memory FAQ (https://help.openai.com/en/articles/8590148-memory-faq) and US Privacy Policy (https://openai.com/policies/us-privacy-policy/).
- Anthropic, Share and unshare chats (updated June 15, 2026). https://privacy.claude.com/en/articles/10593882-share-and-unshare-chats
- Klupt v. Krongard, 126 Md. App. 179, 199-201, 728 A.2d 727 (1999). https://www.courtlistener.com/opinion/1441759/klupt-v-krongard/
- Maryland Civil Pattern Jury Instruction 1:16, quoted in Webb v. Giant of Maryland, LLC, 477 Md. 121, 143, 266 A.3d 339 (2021). https://www.courtlistener.com/opinion/5313540/webb-v-giant-of-maryland/
- Md. Rule 2-402(d).
- Kelch v. Mass Transit Administration, 287 Md. 223, 228-31, 411 A.2d 449 (1980) (https://www.courtlistener.com/opinion/2112433/kelch-v-mass-transit-administration/); Forma-Pack, 351 Md. at 412-13.
- Warner v. Gilbarco, Inc., 820 F. Supp. 3d 629 (E.D. Mich. 2026) (https://storage.courtlistener.com/recap/gov.uscourts.mied.379552/gov.uscourts.mied.379552.94.0.pdf); Morgan v. V2X, Inc. (D. Colo. Mar. 30, 2026) (https://storage.courtlistener.com/recap/gov.uscourts.cod.245077/gov.uscourts.cod.245077.65.0.pdf).
- Can Co-Parents Use ChatGPT to Navigate the Legal System? (Aug. 5, 2024). https://wblaws.com/can-co-parents-use-chatgpt-to-navigate-the-legal-system/
- Brie Stimson, McDonald’s testing AI drive-thru order-taking system called ArchIQ at five locations across country, Fox Business (June 5, 2026). https://www.foxbusiness.com/retail/mcdonalds-testing-ai-drive-thru-order-taking-system-called-archiq-five-locations-country
