Practice Lab

The Discovery of Your Prompts

May 11, 2026· David J.S. Madgett · 14 min read

Here is a question I would not want to answer in a deposition.

“Counsel, when you prepared the summary judgment brief in this matter, did you use an AI system? What did you ask it? What documents did you give it? What did it tell you before you wrote what you wrote? Do those records still exist?”

Every one of those questions has an answer sitting on a disk somewhere in most firms now using these tools. Very few firms have decided what that answer should be, where those records live, how long they persist, or what happens to them when a litigation hold lands.

This piece is about the artifacts. It is deliberately more question than answer, because the honest state of the law here is unsettled — and a piece that pretended otherwise would be exactly the kind of confident wrongness this section keeps warning about.


What actually gets created

Start by cataloguing, because most lawyers underestimate the trail by an order of magnitude.

A single AI-assisted drafting session generates:

  • The prompt. What you asked, in your words, including the framing — which routinely contains your assessment of the case.
  • The context you supplied. Documents, excerpts, facts, and often your characterization of them.
  • Retrieved material. If a retrieval system fed the model documents, there is a record of which documents were selected and why.
  • The output, including drafts you rejected.
  • Your iterations. “That’s too aggressive.” “Take out the part about the estoppel argument.” “Assume we lose the motion to dismiss.”
  • The transcript, timestamped, which reconstructs when you worked and on what.
  • Tool call logs, if you have built the kind of connector I have described elsewhere in this section.

Read that list again with an adversary’s eyes. The iteration history in particular is a nearly perfect record of counsel’s evolving assessment of the case — which arguments were considered and discarded, which weaknesses were flagged, what you thought the exposure was before you refined it into a filing.

That is either the most protected category of material in litigation or a discovery problem of unusual magnitude, depending on questions nobody has definitively answered.


The doctrinal starting point

Work product in Minnesota lives at Rule 26.02(d), “Trial Preparation: Materials.” Documents prepared in anticipation of litigation are discoverable

“only upon a showing that the party seeking discovery has substantial need of the materials in the preparation of the party’s case and that the party is unable without undue hardship to obtain the substantial equivalent of the materials by other means.”

And critically, the rule directs that courts “shall protect against disclosure of the mental impressions, conclusions, opinions, or legal theories of an attorney or other representative of a party concerning the litigation.” That heightened protection for opinion work product is the doctrinal home for most of what an AI transcript contains.

My read, and I hold it with moderate confidence: a lawyer’s prompts and iterations in a matter are classic opinion work product. They are the lawyer’s own words, prepared in anticipation of litigation, reflecting mental impressions and legal theories directly. A prompt saying “draft an argument that the notice was untimely, but be careful because the estoppel certificate cuts against us” is about as pure an expression of counsel’s mental impressions as exists.

The doctrine was built for a lawyer’s notes, and this is a lawyer’s notes. That it was typed into a chat box rather than a legal pad should not change the analysis, any more than dictation did.

That is the easy part. Now the parts that are not easy.


Five questions without settled answers

1. Does the model output inherit the protection?

The prompt is your words. Is the output your mental impressions, or is it something a machine generated that merely passed through your hands?

The natural analogy is a draft prepared by an associate or a paralegal at counsel’s direction, which is protected. The disanalogy is that the associate is a person within the privileged circle and the model is a service. Where a lawyer’s judgment did the selecting — you asked for it, you evaluated it, you kept some and discarded the rest — the reflection-of-mental-impressions argument seems strong. Where a workflow ran automatically overnight with no lawyer in the loop until morning, it is noticeably weaker.

I would expect the answer to turn on human involvement, which means the way you build the workflow may determine the protection available to its outputs. That is an unusual and underappreciated design consideration.

2. Does using a third-party service waive anything?

Privilege is generally not waived by disclosure to agents assisting counsel — the analysis that protects sharing with experts, vendors, and litigation-support providers. A model provider under a contract that forbids training on your inputs and limits retention looks much like a litigation-support vendor.

It looks much less like one if the terms permit the provider to use your inputs to improve its models, or if there is no confidentiality undertaking at all, or if you used a consumer product with terms you never read. The vendor contract may end up doing more work in the privilege analysis than any doctrine.

This is a reason — separate from every ordinary confidentiality reason — to know exactly what your provider’s terms say about inputs and retention.

3. Does a litigation hold reach it?

Almost certainly yes, and this is the question I think will surprise firms most.

A hold reaches relevant electronically stored information in your possession, custody, or control. An AI transcript recording your work on a matter is plainly ESI about that matter. If your system rotates transcripts out after 30 days and a hold attaches, you have a spoliation exposure created by a retention setting nobody chose deliberately — someone accepted a default.

The mirror problem is worse in the aggregate: many firms retain everything, forever, by default. Every session on every matter, timestamped, in a folder nobody has ever inventoried. That is a discovery obligation growing quietly on a disk.

4. Whose records are they?

If the connector runs on your machine, they are yours. If it runs on a vendor’s infrastructure, the vendor has them, and the vendor can be subpoenaed. If the assistant is a consumer product with server-side history, your client’s confidences and your mental impressions sit in a third party’s retention system on that party’s schedule.

The architecture determines the answer, which means this is a question you settled when you chose your tools, whether or not you knew you were settling it.

5. What about the retrieval log?

The subtlest one. A retrieval system records which documents were surfaced for a query and which were not. In a discovery dispute about the adequacy of a search, that log is evidence about your process — potentially helpful, potentially not.

There is a real tension here with what I have argued elsewhere in this section. I have said that a system should log what it retrieved, so you can answer for what it did. That is right for competence and for supervision. It also creates a record that could be discoverable. I do not think that changes the recommendation — the alternative is being unable to describe your own process, which is worse — but it should be a decision rather than an accident.


What to do while the law catches up

None of the above is a reason for paralysis. It is a reason for five decisions you should make on purpose.

1. Decide your retention period, in writing. Not the default. Pick a period, document why, apply it consistently, and make sure your hold process can override it. A defensible policy applied consistently is worth far more than any particular number of days.

2. Keep matter work in matter-scoped sessions. A single sprawling conversation covering six clients is a discovery nightmare: you cannot produce material about one matter without exposing five others, and you cannot claim protection cleanly for any of it. Matter-scoped work is separable work. This is one more argument for the board-and-cards architecture, and I did not anticipate it when I built it.

3. Read your provider’s terms on inputs, retention, and training. Then write down what they say and when you checked. If the answer changes — and it will — you want to know what you were relying on and when.

4. Assume it is all discoverable and write accordingly. This is the oldest advice in litigation and it applies without modification. Do not type into a prompt anything you would not write in an email about the case. The chat interface feels ephemeral and conversational, which is precisely why people write things there they would never put in a memo. It is not ephemeral. It is a file.

5. Inventory what you already have. Most firms that have been using these tools for a year have a retained corpus they have never looked at. Find out where it is, how much there is, and what is in it — before somebody asks you in a deposition.


The prediction

I said elsewhere in this section that I expect meaningful appellate authority on this within a few years, and that firms will be badly surprised by how much they retained without deciding to. I would add a second expectation here.

The first real fight will not be about privilege. It will be about spoliation. The privilege questions are interesting and will take years to work through carefully. The spoliation question is simple, mechanical, and will arrive the first time a party asks for AI transcripts in a matter where the other side’s retention setting quietly deleted them.

That is not a doctrinal puzzle. It is a records-management failure, and courts have a well-developed and unsympathetic vocabulary for those.

Which means the highest-value thing to do about all of this is also the least intellectually interesting: know where the records are and how long they last. Everything else can wait for the case law. That cannot.


Sources

Rules quoted were verified against the Revisor of Statutes. This is commentary on unsettled questions and is expressly not legal advice; the views above are the author’s reading and there is limited authority on most of them. Consult counsel in your own jurisdiction before relying on any of it.

The only thing we ask

If something here saves you time, spend some of it on people who could not otherwise afford you.

Everything in the Practice Lab is free. No signup, no subscription, no donations — just take a case you would otherwise have to turn down on economics. More from the Practice Lab →

← All Practice Lab articles