Home/Blog/AI Prompts Are Becoming Discoverable: What Legal Teams Must Do Before the Next Matter
Industry AnalysisLegal AIPrivilegeeDiscoveryLitigationAI Governance

AI Prompts Are Becoming Discoverable: What Legal Teams Must Do Before the Next Matter

Courts are beginning to treat AI prompts as legal artifacts: expert methodology, potential evidence, privilege risk, and subjects for protective orders. Recent developments around expert prompt discovery, Florida AI filing disclosure rules, and cases addressing privilege and work product show that legal AI is moving from experimentation to governed infrastructure. For lawyers and corporate legal teams, the answer is not to ban AI, but to control it through approved tools, counsel-directed workflows, verification, retention, and discovery protocols. Defensible AI use now depends on process quality as much as model quality.

CourtifyAI Team
5/23/2026
7 min read

AI Prompts Are Becoming Discoverable: What Legal Teams Must Do Before the Next Matter

The most important legal AI story this week is not a new chatbot launch or another benchmark claim. It is a more practical and more consequential development: AI prompts are becoming legal artifacts. Courts, bar publications, and litigation practices are converging around a simple proposition that every lawyer and corporate legal department should internalize before the next dispute begins. The words typed into an AI system, the outputs received, and the way an AI tool was used may later matter in privilege fights, expert discovery, protective orders, sanctions analysis, and professional responsibility review.

That shift became especially visible in the week ending May 23, 2026. A federal court in Connecticut ordered production of an expert witness’s AI prompts in Conservation Law Foundation v. Shell Oil Co., treating them as part of the expert’s methodology under Rule 26.1 Florida’s Miami-Dade and Broward courts issued coordinated orders requiring lawyers and self-represented litigants to disclose and verify many AI-assisted court submissions, with sanctions available for noncompliance.2 At the same time, legal commentators continued to dissect cases such as United States v. Heppner, Warner v. Gilbarco, and Morgan v. V2X, which show that privilege and work product outcomes turn on who used the AI tool, for what purpose, under whose direction, and under what confidentiality terms.3 4

For lawyers and corporate legal teams, the point is not that AI has become unusable. The point is the opposite. AI is moving from experimentation to ordinary legal infrastructure, and ordinary legal infrastructure must be governed. The old question was, “Can this tool draft, summarize, or analyze?” The new question is, “If this interaction is later reviewed by a judge, regulator, opposing counsel, or client, will our process still look defensible?”

The news: prompts are no longer invisible

The clearest signal came from the Connecticut ruling discussed by Arnold & Porter. In Conservation Law Foundation v. Shell Oil Co., the plaintiff’s expert used AI tools to review a document production and identify materials for closer analysis. The defendants sought the prompts used in that process. The plaintiff resisted, arguing that the prompts were outside Rule 26 discovery, protected by a discovery agreement, or merely search terms already produced. The court disagreed and ordered production because the prompts were part of the expert’s methodology.1

That holding matters because it translates AI use into a familiar litigation category. Expert methodology has always been discoverable because the opposing party is entitled to test how an expert reached an opinion. If an expert uses AI to screen, rank, classify, or narrow a document set, the prompt can reveal assumptions, scope limits, relevance criteria, bias in the framing, and whether the expert’s stated methodology matches what actually happened. In other words, the prompt is not just a technical input. It may be the audit trail of the analysis.

A related Arnold & Porter companion analysis described an emerging four-part framework: attorney-crafted litigation prompts are likely to receive the strongest work product protection; party-generated prompts are fact-dependent; expert prompts may be discoverable as methodology; and protective orders are becoming the main vehicle for governing whether discovery materials may be processed through AI systems.4

AI-use contextEmerging legal treatmentPractical implication
Attorney-crafted prompts for litigation strategyOften argued to reflect counsel’s mental impressions and opinion work productPreserve them carefully and keep them within counsel-directed systems
Client or employee prompts without counsel directionHighly fact-specific; confidentiality terms and purpose matterDo not let business teams ask public chatbots for legal strategy
Expert witness promptsMay be discoverable as part of methodology under Rule 26Address AI use in expert engagement letters and discovery protocols
AI use on discovery materialsIncreasingly governed by protective orders and tool safeguardsNegotiate data retention, training, deletion, and disclosure rules early

This is why the week’s developments should be read together. The court filing disclosure story and the prompt-discovery story are not separate trends. They are two sides of the same governance movement. Courts are not banning legal AI. They are asking lawyers to take responsibility for it.

Why privilege is under pressure

Attorney-client privilege and work product protection were not designed around conversational systems that invite users to paste confidential facts, ask for strategy, iterate through weaknesses, and save everything in a vendor-controlled environment. Yet courts are applying existing doctrines to that new factual pattern.

In United States v. Heppner, a criminal defendant reportedly argued that AI-generated materials were privileged or protected because they were created for the purpose of obtaining legal advice. The court rejected that position where the defendant acted on his own, shared attorney communications with an AI tool, and used a platform whose terms did not promise confidentiality.3 The lesson is blunt: an AI system is not a lawyer, and a user’s hope that material will later be shared with counsel does not automatically make the interaction privileged.

By contrast, Morgan v. V2X and Warner v. Gilbarco reflect a more nuanced approach to work product. Courts have recognized that AI tools can assist litigation preparation and that routing material through a tool does not always equal disclosure to an adversary. In Morgan, however, the court also required disclosure of the AI tool’s identity and amended the protective order to restrict use of mainstream AI tools for confidential information unless contractual safeguards existed.5 That nuance is important. Courts are not saying AI use always waives protection. They are saying protection depends on facts that legal teams can and should control.

The Florida orders add a public-facing layer. According to The Florida Bar’s report, Miami-Dade and Broward courts now require many AI-generated court submissions to include a certification that the filer used generative AI and independently verified the accuracy of citations, quotations, factual assertions, and legal analysis. The orders also warn of sanctions ranging from denial of relief and striking filings to monetary sanctions and disciplinary referral.2

The operational message for legal teams is clear: human verification is not a courtesy layer added after AI output. It is the legal act that makes AI-assisted work usable.

For corporate legal departments, privilege risk is especially acute because AI use often starts outside the legal function. Sales, HR, product, compliance, and brand protection teams may paste dispute summaries, employee allegations, customer complaints, or infringement evidence into public AI tools before counsel is consulted. By the time legal becomes involved, the organization may already have created discoverable prompt histories, admissions, or inconsistent narratives. The legal department then inherits both the matter and the metadata of an uncontrolled process.

The governance lesson: treat prompts like evidence, not scraps

The mistake many organizations make is treating prompts as disposable drafts. That assumption is becoming unsafe. A prompt can reveal what the user thought was important, what facts were omitted, what theory was being tested, and what conclusion the user hoped the system would reach. In an expert setting, it can reveal methodology. In a privilege setting, it can reveal waiver. In a sanctions setting, it can reveal whether a lawyer verified the output or merely delegated judgment to a machine.

The right response is not a blanket ban. Bans usually fail because employees still use convenient tools, only without logging, training, or legal review. A better response is a matter-aware AI governance model that separates safe use from risky use and routes each category through the right controls.

Governance controlWhat it should requireWhy it matters
Approved-tool policyDefine which AI systems may process confidential, privileged, personal, or discovery dataTool terms drive confidentiality and waiver analysis
Prompt classificationLabel prompts as legal strategy, research, drafting, expert methodology, business analysis, or administrative supportDifferent categories receive different legal treatment
Counsel directionRequire counsel approval before AI is used for disputed matters, investigations, or litigation strategyCounsel involvement strengthens privilege and work product arguments
Verification workflowRequire source checking, citation validation, factual review, and responsibility sign-offCourts are focusing on candor, accuracy, and human accountability
Discovery protocol languageAddress AI use in protective orders, Rule 29 agreements, and expert protocolsSilence on AI is now a vulnerability
Retention and audit trailDecide when prompts and outputs must be preserved, logged, or segregatedAI interactions may become responsive ESI or expert materials

This governance model should be built before the first major dispute, not during a motion to compel. Protective orders should specify whether discovery materials can be uploaded to AI systems, whether the provider may train on inputs, whether data can be deleted, whether subcontractors can access it, and whether written documentation of safeguards must be retained. Expert engagement letters should require disclosure of AI use to counsel, preservation of prompts and outputs, and prior approval for tools used to filter or analyze case materials. Internal policies should tell employees that legal questions, threatened claims, regulatory inquiries, and litigation strategy do not belong in public chatbots.

What lawyers should do now

Law firms should update client intake, litigation hold, and expert management checklists to ask about prior AI use. A simple question—“Has anyone used an AI tool to analyze this dispute, draft a response, summarize facts, or evaluate exposure?”—may prevent unpleasant surprises later. Firms should also maintain approved AI environments that provide contractual confidentiality, no-training commitments, access controls, and matter-level segregation.

Corporate legal teams should partner with IT, security, compliance, and business units to distinguish ordinary productivity use from legally sensitive use. AI used for grammar edits or public research presents a different risk profile from AI used to analyze a termination decision, assess patentability, draft a litigation strategy, or prioritize counterfeit takedowns. The policy should be practical enough that employees follow it, but strict enough that sensitive legal work is routed into controlled workflows.

Most importantly, legal teams should stop thinking about AI governance as a technology procurement issue. It is now a litigation readiness issue. The discoverability of expert prompts, the uncertainty around privilege for party-generated prompts, and the rise of court disclosure rules all point to the same future: legal AI use will be evaluated by process quality. The legal team that can show tool diligence, counsel supervision, human verification, and preserved audit trails will be in a much stronger position than the team that can only say, “We used AI, but we are not sure how.”

CourtifyAI’s perspective

At CourtifyAI, we see this moment as a turning point from casual legal AI to governed legal AI. Legal teams do not need less automation; they need automation that respects the realities of privilege, evidence, verification, and enforcement. AI Copilot, our AI legal assistant, is designed to support lawyers in research, review, drafting, and matter workflows while keeping human judgment at the center of the legal process. Auto Pilot, our automated IP enforcement product, applies the same governance mindset to online infringement: identifying issues, preserving evidence, structuring enforcement steps, and helping legal teams move from scattered signals to repeatable action.

The lesson of this week’s news is not that AI prompts are dangerous by nature. The lesson is that prompts are work product, evidence, methodology, or risk depending on how they are created and controlled. For lawyers and corporate legal teams, the competitive advantage will belong to those who make AI both powerful and defensible.

References