Benchmarking

AI Agent Security: Companies See Rogue Incidents but Lag on Controls


At many organizations, AI agents are no longer experimental. Eighty-one percent of technical teams are actively using or producing agents capable of autonomous actions on behalf of employees, according to a February 2026 report on AI agent security released by vendor Gravitee.

This growing set of autonomous AI tools is insufficiently governed at many organizations, according to Gravitee and two other 2025 and 2026 security vendor surveys. The three reports agree that unintended incidents and breaches are already occurring. They found similar shortcomings among surveyed companies, including partial policies, limited monitoring and inadequate treatment of agents as risky identities circulating in their systems.

NIST has advanced AI agent governance efforts by officially requesting information about methodologies for improving the secure use of AI agent systems, with responses that were due March 9, 2026. Additionally, comments on a proposed NIST paper about managing agents’ privileges in computer systems are due April 2, 2026.

This article, the first in a two-part series on AI agent security, examines early AI agent governance benchmarks, incident types and origins, maturity of tailored controls and data access concerns. Part two will provide a playbook for CISOs and their colleagues to strengthen security and reduce risks around AI agents.

See “From CEO Deepfakes to AI Slop, AI Incident Tracking Ramps Up” (Jul. 30, 2025).

The Three Studies

Each of the three studies on AI agents is based on surveys conducted during 2025. NeuralTrust based its “The State of AI Agent Security 2026” (NeuralTrust Report) on surveys that were conducted in August and September 2025. Gravitee rooted its “State of AI Agent Security 2026” (Gravitee Report) in surveys conducted in December 2025 and January 2026. SailPoint issued its “AI agents: The new attack surface” (SailPoint Report) in May 2025.

SailPoint procured responses from 353 IT/security practitioners or leaders, while Gravitee surveyed 919 technology executives and technical practitioners, and NeuralTrust gathered information from more than 160 CISOs and security leaders.

The findings in the three reports broadly align on companies’ level of usage, oversight gaps and incident prevalence. The reports also revealed that while many companies have already witnessed rogue behavior from their AI agents, their leaders are not deterred from advancing agent development.

See “Risk and Compliance Survey Highlights the Role of Compliance in AI Governance” (Oct. 29, 2025).

Adoption Outpacing Security Measures

The three surveys each illuminate a structural gap between use and controls, describing a shared pattern: roughly four out of five companies now use AI agents to a significant degree, but only half implemented some initial governance for agents.

The reports’ usage statistics line up. SailPoint found “82% of companies are already using AI agents,” while Gravitee said that “81% of teams are past the planning phase.” NeuralTrust concluded that “enterprises are deploying AI agents faster than they can secure them. 72% have implemented or are scaling AI agents.”

NeuralTrust conveyed the nuance that many organizations are moving cautiously with agent implementation rather than letting a herd of AI agents run amok on the job. Only 10% of companies stated they had fully deployed agents, and only 4% reported scaling agents across multiple departments.

The reports had parallel findings on companies’ central governance levels for AI agents as well, although the authors gathered slightly different data.

  • Sailpoint reported on policies. “Only 44% currently have any governance policies in place for AI agents,” it found.
  • Gravitee assessed monitoring and security approval. “On average, only 47.1% of an organization’s AI agents are actively monitored or secured,” Gravitee reported. “Only 14.4% have achieved ‘full’ IT and security approval for their entire agent fleet,” and 45% obtained a “good” level of approval, it noted. The rest had approval for some agents or “hardly any.”
  • NeuralTrust looked at security controls. “Only 29% report comprehensive AI-specific security controls,” it found. “A quarter (25%) have no AI-specific controls at all.”

See “How Under Armour and People Inc. Took AI Governance From Crawl to Walk to Run” (Sep. 24, 2025).

Internal and External Incidents Reported

The reports reveal some troubling agent interactions with external players, but also treat many episodes that occurred inside organizations, where deployed agents took unintended or unauthorized actions, as “incidents.”

Prevalence of Incidents

“An overwhelming 88% of organizations report either confirmed or suspected AI agent security or privacy incidents within the last year,” the Gravitee Report states. Likewise, 80% of those surveyed by SailPoint revealed that “AI agents have performed unintended actions of accessing and sharing inappropriate data.”

NeuralTrust gathered fewer tales of incidents, sharing that “1 in 5 organizations report at least one AI agent–related breach, mostly from prompt injection or data exposure.”

Types of Incidents

The agent-fueled incidents reported by those surveyed by NeuralTrust include:

  • “prompt injection/adversarial manipulation” (68%);
  • “data leakage of sensitive or regulated data” (61%);
  • “harmful or false customer interactions” (46%);
  • “misuse or abuse by users or end customers” (41%); and
  • “compromise of third-party plugin/model/API (application programming interface)” (28%).

Of those incidents, respondents characterized 36% as “a compliance or regulatory breach.” The NeuralTrust Report notes that only 3% of the incidents involved “unauthorized actions/privilege escalation.”

Many episodes that NeuralTrust sees in its work involve agents unexpectedly pulling data from internal sources or misusing data internally, company researcher Alessandro Pignati told the Cybersecurity Law Report.

Gravitee shared with the Cybersecurity Law Report a further breakdown of the incidents set forth in its report. A company representative cautioned that AI produced the following analysis of the 919 responses. In order of seriousness, the incidents include:

  • adversarial attacks and malicious exploitation, labeled highly serious (5%);
  • data retention and privacy violations (15%), some highly serious because they involved data regulated under HIPAA or the GDPR;
  • data leakage and unauthorized exposures (25%), some labeled highly serious;
  • excessive privileges or access control misfires, generally allowing the agent unauthorized access to systems (15%), which carried medium to high seriousness;
  • “third-party and vendor risks,” averaging a medium level of seriousness (10%); and
  • systemic risks in “governance, oversight and shadow AI” (30%), generally of low or medium seriousness and typically considered “near-misses” or policy violations.

Both the NeuralTrust and Gravitee Reports highlight broadly similar categories of agent‑driven risk – adversarial manipulation, privacy and data‑handling failures, unauthorized access and third‑party exposure – though they use different labels and severity scales. Each report also underscores that many incidents involve data leakage or inappropriate internal data use rather than dramatic, autonomous, high-level takeovers of systems.

See “Recent Developments and Upcoming Obligations Under the E.U. AI Act” (Feb. 4, 2026).

Sample Incidents

The Gravitee Report elaborates on the list of incident types by providing examples. In one example, a financial services practitioner reported that an agent programmed with read-only privileges used elevated permissions to adjust workflows and pursue administrative functions outside its original scope.

In another example, a life sciences startup used an agent that gained “write” privileges in user databases because the human’s instructions “bypassed our input sanitization layer,” an executive told Gravitee, adding that a circuit-breaker control halted the breach in two seconds.

Additionally, a telecom company reported than an internal agent used for task automation “attached some sensitive information and was trying to send outside the organization,” the Gravitee Report recounts.

Cyber vendor Lakera, in a December 2025 report, noted that key attack patterns included prompts designed to convince agents to access confidential internal data, asking an agent to process webpages or files embedded with malicious instructions, and burying executable code into text to travel “through an agent pipeline.” Other incident examples can be found in non-profit OWASP Foundation’s database for agentic AI incidents and vulnerabilities.

Companies discovered agents’ misbehavior by logging account access and monitoring for unexpected calls to APIs, the Gravitee Report states.

See “Defending Against Faster, Stealthier and More Sophisticated Cyber Adversaries” (Sep. 10, 2025).

Partial Progress on Safeguards for Agents

NeuralTrust concluded that 29% of organizations had achieved mature safeguards for agents. Components of maturity, the report enumerates, included dedicated oversight frameworks for agents, some continuous monitoring of agent activity, regular testing of agents and integration of AI oversight into enterprise risk management.

Companies’ Initial Moves to Secure Agent Activity

Many companies (46%) have adapted their legacy security frameworks to address AI agent risks, rather than building an agent-first security approach, NeuralTrust discovered. Because existing security tools were not designed for autonomous systems, they may leave important gaps in monitoring agents' behavior and decisions, Pignati observed.

Companies often begin their agent security efforts with the prompts, which flows from their 2024 and 2025 efforts to control large language models (LLMs), Pignati reported. “They work on the system prompts because they don’t have specific security solutions implemented for agents,” he said. Setting tasks that the agents cannot perform is often the first move, he elaborated. The LLM "legacy" security leads organizations to concentrate on stopping prompts that leak data, hallucinated model outputs and attacks deploying prompts.

Other common initial steps include restricting agents from accepting requests for sensitive information or forcing them to process information only from designated knowledge bases, Pignati observed.

See “How Do You Put a System of Controls in Place When Your Target Keeps Moving?” (Mar. 31, 2021).

Security Focus Shifts to Misuse and Excessive Agency

AI security teams are broadly shifting focus from hallucinations to misuse, a turn back to traditional cybersecurity concerns, Gravitee observed. “Notably, nearly half of respondents now consider ‘misuse or unauthorized access of LLMs’ as a top-tier concern” for AI security efforts, it found.

Security teams also focus on evaluating whether an agent “is too efficient at performing actions it was never intended to do,” Gravitee said. OWASP’s “Top 10 For Agentic Applications 2026” similarly lists “excessive agency” as a top risk, along with prompt injection attacks.

When organizations create safeguards for AI agents, “the focus shifts overwhelmingly toward observability" and controlling their access, Gravitee noted. NeuralTrust agreed, saying that “visibility is the new perimeter” for AI defense.

See “Steps to Address the New California Audit Rule That Seeks to Reset Reasonable Security” (Nov. 5, 2025).

Fragmented Monitoring

The most common safeguard that companies use is monitoring agent activity (42% are doing some agent monitoring), reflecting the prioritization of observability, NeuralTrust found. However, respondents reported their companies' monitoring includes little analysis of agents' behavior.

Although monitoring generally is common, many companies only track a portion of the agents they use, according to the Gravitee Report. Only 3.9% of organizations report that they monitor more than 80% of their AI agents and one-third of organizations (30.9%) actively monitor 40% of their deployed agent fleet, Gravitee reported.

Further, although the ability to monitor AI agents in action is crucial to establishing a user’s trust in the tool, only 7.7% of the Gravitee Report’s respondents audit daily. Many companies (37%) audit monthly and 22% audit weekly, “leaving a significant window for undetected misuse or errors,” Gravitee found.

Monitoring agent-to-agent (A2A) communication, an area of high peril, should be a top concern for companies, but there is limited scrutiny of this by companies as well. “Only 24.4% of organizations report having full visibility into which AI agents are interacting with others,” while 46% claim to have “good” visibility. Thus, many organizations remain “blind to how authority is being delegated internally,” Gravitee noted.

See “Checklist for Selecting Privacy Tech Solutions” (Nov. 1, 2023).

Identity Management Prevalent but Weak

Due to the considerable risk of AI agents taking unintended actions, structural controls are very important. Identity management and credential control is the foremost structural option. SailPoint found that 62% of organizations use their systems to “provision and govern” AI agents. NeuralTrust found that 38% of companies applied their role-based access control software (RBAC) to the new "AI employees." 

Yet the reports all concluded that identity management is a major weakness for agent security. Most organizations still treat agents as extensions of human users or generic service accounts, Gravitee reported. Only 21.9% of respondents currently treat AI agents as independent, identity-bearing entities within their security model, which is “the foundational security principle of unique identity,” it cautioned. The rest treated agents as extensions of their users, which leaves significant gaps in auditability and granular access control, it added.

One Gravitee respondent described a situation that many companies may be experiencing. “Honestly, general LLM security is still a concern on an enterprise level, so we have all been using our own personal accounts with the agents,” and will not focus on agent security until the automated workflows are more finalized, the practitioner said.

Some of the companies attempting to follow security principles by giving agents their own identity are creating fresh trouble. Troublingly, in 64% of organizations, "AI agents often rely on several access identities, complicating efforts to track and correlate data usage and sharing,” the SailPoint Report states.

See “Staying Ahead of Rising Identity-Based and Cloud Intrusions” (Mar. 19, 2025).

Controls for Agent-to-Agent Credential Sharing

Whether existing identity solutions can operate as effective structural safeguards for AI agents remains a key issue. Model Context Protocol (MCP) servers became the standard gateway for agent tool access in 2025, yet only 23.7% of organizations had adapted their authentication systems to control access to MCP and other agentic infrastructure, Gravitee noted.

Agents often share an original employee’s passwords with several other agents they invoke while completing tasks, Gravitee chief product officer Linus Håkansson told the Cybersecurity Law Report. “For agent-to-agent interactions, teams rely heavily on insecure or shared methods for authentication,” like API keys (45.6%) and “generic tokens” (44.4%), Gravitee warned in its report. Only 17.8% use “secure standards like mTLS,” a protocol using digital certificates, it added.

Agents’ password handoffs are becoming too complex for some authentication methods. “The secondary agents might invoke multiple different MCP tools, which themselves might invoke APIs, databases, etc. This delegating of permissions makes generic tokens and API keys obsolete and a security risk,” Håkansson said.

While approvals of human employees' credentials typically require multiple managers or executives, SailPoint learned that companies’ IT departments often are the only decision-maker for AI agent access (as reported by 35% of respondents), and companies commonly approve agents’ access in fewer steps than they approve access for humans (as reported by 34% of respondents). “IT may lack full awareness of the specific types of data being accessed – such as customer information, intellectual property, or employee records – by the agent, making it difficult to apply appropriate compliance or sensitivity controls,” its report states.

See “Gauging Uptake of AI in Cybersecurity” (Nov. 12, 2025).

Data Loss Prevention Software

Another key structural safeguard is data protection software. A majority of SailPoint respondents expressed concern about agents sharing privileged or inappropriate data, with 52% claiming that their company can track and audit all data that AI agents use and share.

NeuralTrust found that 31% of companies use data loss protection software to try to thwart any sensitive data leaking, but cautioned that such software often lacks automated enforcement mechanisms to keep up with agents’ quick movement.

Effective governance of AI agents begins with understanding the data that they may access, SailPoint observed, warning its survey revealed that compliance (47%) and legal (39%) often are uninformed about agent data access.

Other Safeguards

Prompt injection filtering (27%) and red teaming (19%) “remain niche,” NeuralTrust found. “Few organizations simulate or anticipate adversarial behavior.” AI supply chain protection (16%) is emerging, “but verifying third-party models, tools, and APIs is still largely manual,” the NeuralTrust Report states.

None of the three reports revealed companies’ practices around implementing human oversight, like the use of stop points to wait for human approval of agent decisions.

Best Practices for Agent Safeguards

NeuralTrust estimated only 10% of its respondents had implemented comprehensive, predictive and autonomous governance for agent security. Businesses in the financial industry led healthcare and telecom companies in establishing structured oversight of agents because of “heavy compliance mandates (Basel III, DORA, NIS2)” in Europe, it noted.

To achieve comprehensive, predictive and autonomous agent security governance, a company should:

  • automate monitoring of agent behavior and data interactions;
  • conduct adversarial simulation and automatic containment;
  • align proactively with emerging AI regulations; and
  • aim to create automated “self-learning governance” that constantly refines security controls.

Companies also should prioritize an inventory of all AI agents, given the dispersed rollout of agents across departments without central oversight, Pignati advised.

AI agents are largely invisible to traditional asset management, Gravitee reported. One-quarter of companies rely on manual spreadsheets, and 22.5% have no formal catalog of their agents, it found.

Longstanding security controls built to stop human intruders or malicious software frequently allow AI agents to slip through, according to the NeuralTrust Report. “As AI autonomy expands, traditional defenses, built for human-triggered systems, fail to catch unintended actions, data leaks and adversarial manipulations,” NeuralTrust warned. “AI agents don’t just malfunction, they act. The incidents are less about hacking and more about oversight and control gaps,” it concluded.

Judicial Decisions

Tool or Third Party? Courts Differ on AI’s Role in Privilege and Work-Product Protections


In February 2026, two federal judges assessing whether interactions with generative AI platforms are protected by attorney-client privilege and work-product doctrine reached significantly different conclusions. In United States v. Heppner, Southern District of New York (SDNY) Judge Jed Rakoff ruled that a criminal defendant’s exchanges with Claude were not protected. Yet, in the Eastern District of Michigan (EDMI), in Warner v. Gilbarco, Inc., Magistrate Judge Anthony Patti held that documents and information regarding a pro se plaintiff’s use of ChatGPT were shielded from discovery.

The divergent outcomes show how courts have begun to contemplate whether AI platforms are simply tools for drafting and research or if they should be considered third parties that can destroy reasonable expectations of confidentiality.

With insights from BakerHostetler, Hunton Andrews Kurth and Morrison Foerster partners, this article parses the courts’ analyses, examines the implications of this developing body of case law and offers practical takeaways regarding protections of AI inputs and outputs.

See our two-part series “Gen AI Chats Becoming Evidence”: Law Enforcement Warrants and Subpoenas (Dec. 3, 2025), and How Businesses Can Prepare for Requests (Dec. 10, 2025).

Why the SDNY Allowed Discovery of AI Communications in Heppner

In a much-publicized February 10, 2026, ruling that was memorialized in a memorandum filed on February 17, 2026, Judge Rakoff determined that a user’s communications with a publicly available AI platform made in connection with a pending criminal investigation were not protected by attorney-client privilege or work product doctrine.

Defendant Bradley Heppner, a former executive at GWG Holdings, Inc. had been accused of defrauding investors in the publicly traded company out of more than $150 million by making false representations and causing GWG to enter into “undisclosed self-serving transactions” with two privately held companies that Heppner controlled. After Heppner’s 2025 arrest, the FBI, acting pursuant to a search warrant, seized documents and devices, some of which reflected communications Heppner had with AI platform Claude (AI documents). The communications with Claude occurred after Heppner had received a grand jury subpoena.

Heppner claimed that the AI documents were privileged, and his counsel listed them on his privilege log.

In evaluating attorney-client privilege, Judge Rakoff emphasized “two core requirements: (1) the participation of an attorney in the communication; and (2) the preservation of confidentiality, which the court links to avoiding the use of publicly accessible generative AI tools that may expose communications to third‑party access,” Meghan Podolny, a partner at Hunton Andrews Kurth, said. “Attorney participation and continued confidentiality are two elements of the test for attorney-client privilege,” she added.

Ultimately, the Heppner decision is one “driven by its facts – particularly by the fact that the defendant used a publicly available AI tool of his own volition,” James Koukios, a partner at Morrison Foerster, told the Cybersecurity Law Report.

See “Lessons From SDNY Ruling on How to Preserve Privileged Communications With Attorney Consultants” (Aug. 7, 2019).

Privacy Policy Language Dispelled Expectation of Confidentiality

Judge Rakoff noted that the privacy policy for Claude users stated that Anthropic collects data on users’ inputs and Claude’s outputs and uses that data to train Claude, BakerHostetler partner James Sherer highlighted. The policy also mentioned that Anthropic reserves the right to disclose data to third parties, including governmental authorities.

Thus, one of the reasons the court found that the AI documents were not confidential was because of “the publicly available AI platform’s terms of use,” Koukios said.

Absence of Attorney Direction or Relationship Undermined Privilege and Work Product Claims

The court treated the AI interactions not as communications between an attorney and client but rather as communications between a defendant and a third-party platform. “The court concluded the AI documents could not satisfy the traditional elements of an attorney-client privilege claim because they were not communications with counsel, and the use of the AI tool was neither directed by an attorney nor made for the purpose of obtaining legal advice from an attorney,” Koukios explained.

Specifically, the court determined that Heppner had not used Claude to obtain legal advice because “the defendant was not told to communicate with the AI tool by counsel, and the AI tool told users (ostensibly including defendant), ‘I’m not a lawyer and can’t provide formal legal advice or recommendations,’” Sherer pointed out. Importantly, he added, “Judge Rakoff noted that privilege requires ‘a trusting human relationship’ with a ‘licensed professional who owes fiduciary duties and is subject to discipline,’ citing the Against an AI Privilege article in support.”

It is significant that the court ordered the production of the AI-generated documents notwithstanding the fact that the defendant used prompts that incorporated information obtained from counsel and later shared the AI outputs with his attorneys. “The court declined to treat the defendant – who had retained counsel and shared his generative‑AI materials with counsel in furtherance of his criminal defense – as having acted as an agent of counsel,” Podolny noted. Instead, the court “required evidence of specific direction from counsel to the defendant as a predicate for finding that the materials were prepared at an attorney’s behest and concluded that such direction was absent on the record before it,” she added.

Other courts “might reasonably have viewed these circumstances differently and, even if reaching the same conclusion with respect to attorney‑client privilege, could have found that the materials satisfied the requirements for protection under the work‑product doctrine,” Podolny posited.

Procedural Posture Impact

Because the government had already seized the materials at issue, the “privilege dispute concerned information already in the government’s possession,” noted Podolny. “That procedural posture may have influenced the court’s analysis, and a different result might reasonably have followed had the AI‑generated content not yet been obtained by the party seeking its production,” she suggested.

Criminal Context

The outcome in Heppner might not have been different if the underlying matter had been a civil one rather than a criminal one. “The underlying privilege and work product analysis are the same in both civil and criminal cases, but the relevance and proportionality requirements in Federal Rule of Civil Procedure 26(b)(1) likely provide civil litigants more arguments to resist the production of AI-generated materials than would be available in the face of a search warrant or grand jury subpoena,” Koukios explained.

Competing Work-Product Doctrine Case Law Not Addressed

The Heppner decision does not address “competing case law recognizing that a party – not only an attorney – may generate materials in anticipation of litigation that qualify for protection under the work product doctrine,” observed Podolny. He cited, as an example, Wultz v. Bank of China Ltd., where “the court held that Federal Rule of Civil Procedure 26(b)(3)(A) extends protection to materials prepared ‘by or for [a] party or its representative,’ not merely to work performed by or for counsel.”

In its holding, the Wultz court “relied on extensive authority and advisory committee notes confirming that the work‑product doctrine was intended to protect materials prepared by non‑attorneys in anticipation of litigation,” Podolny continued. Other decisions, she added, such as United States v. Stewart, “have recognized that a criminal defendant’s own documented recollection of events, absent any reflection of attorney strategy or thought process, may constitute protected work product, particularly in the criminal context.”

Why AI-Assisted Litigation Work Was Protected in Warner

Just a week before the Heppner memorandum was filed but on the same day the ruling was issued, in a February 10, 2026, order, Magistrate Judge Patti reached an opposite conclusion in Warner. Denying a motion to compel discovery of a pro se plaintiff’s use of AI tools such as ChatGPT, the court held that such materials are protected under the work-product doctrine despite the third-party operator potentially having access.

The underlying case in Warner involved employment-related claims. During discovery, the defendants sought extensive information about the plaintiff's use of third-party AI tools in connection with the lawsuit. They further asked the court to overrule the plaintiff’s attorney-client privilege and work-product objections to the AI materials or, alternatively, require a privilege log covering such items.

Work-Product Doctrine Applies to AI-Assisted Materials

“The court emphasized that, even if the AI-generated materials of a pro se plaintiff were otherwise discoverable, they were protected under the work product doctrine,” Podolny observed.

The court noted that the work-product doctrine expressly protects “documents and tangible things that are prepared in anticipation of litigation or for trial by another party or its representative.” Because the plaintiff was a pro se litigant, she had the right to assert work-product protection over such material.

No Work Product Waiver by Using ChatGPT

In considering the waiver of the work-product doctrine, the judge held that the disclosure must be “to an adversary or in a way likely to get in an adversary’s hand,” and not merely to a software tool. The plaintiff had used ChatGPT, which is a tool rather than a person, even if ChatGPT and other generative AI programs “have administrators somewhere in the background,” the court reasoned. Thus, the use of AI tools to assist in case preparation did not constitute a waiver of work product protection.

The court made the distinction that, “‘while the mere showing of a voluntary disclosure to a third person will generally suffice to show waiver of the attorney-client privilege, it should not suffice in itself for waiver of the work product privilege,’” Sherer noted.

Going a step further, the court rebuked the defendants’ focus on the plaintiff’s use of ChatGPT as excessive. “A footnote referenced previous court confirmation that this was not the first time AI use was at issue, including the admonition that ‘Defendants’ preoccupation with Plaintiff’s use of AI needs to abate,’” Sherer pointed out. The judge also scolded “that the request was a distraction from the case, and that defendants’ theory was ‘supported by no case law but only a Law360 article posing rhetorical questions,’” he added.

See “Understanding the Fiduciary Exception to Attorney-Client Privilege” (Oct. 4, 2023).

Reconcilable Differences?

Although Heppner denies privilege and work-product protection to generative AI inputs and outputs while Warner affords it, the cases are “largely reconcilable because they arose in different postures and on different ‘disclosure’ facts,” Koukios opined.

Direction From Counsel Theme

The Warner court, Koukios elaborated, “rejected a civil discovery effort to probe a party’s AI-assisted drafting process and treated the requested AI materials as not discoverable and as protected work product that was not disclosed to an adversary.” In contrast, Heppner addressed “written exchanges between an individual and a publicly available AI platform whose terms defeated confidentiality and that were not counsel-directed, leading the court to deny privilege and work-product protection,” he continued. Significantly, the “presence or absence of direction from counsel seemed central to both decisions,” he stressed.

See our two-part series on preserving the privilege for in-house counsel: “Communications and Common Issues” (Feb. 24, 2021), “Internal Investigations and Depositions” (Mar. 2, 2021).

Third Parties vs. Tools

Heppner and Warner also “reflect a potential philosophical divide between judges who view AI programs as ‘third parties’ and judges who view them as mere ‘tools,’ which could lead to different results based on similar facts,” Koukios suggested. “Not everyone would expect or agree that an AI tool should be treated as a ‘third party’ for privilege purposes,” he observed. As Warner shows, and “as Judge Rakoff took on in Heppner, some people would instead view AI tools as more akin to other software or cloud-based applications,” he added.

Potentially Strong Precedent and Useful Counterpoint

The Heppner decision has been widely reported and might be granted some deference. “Judge Rakoff’s reputation, combined with the fact that Heppner appears to be one of the first cases, and potentially the first case, confronting the application of privilege and work product protections in the AI context, leaves little doubt that Heppner will be widely read and applied,” Koukios predicted.

Ultimately, Heppner is “strong precedent that sharing privileged attorney advice with a publicly available AI tool under terms permitting broad use of inputs and outputs could result in a waiver,” Koukios said. Warner is a “useful counterpoint on work product: it emphasized waiver generally requires disclosure to an adversary, or in a way likely to reach an adversary, and refused to treat AI-assisted drafting, standing alone, as discoverable,” he explained.

There are likely to be more decisions addressing protections around AI use. “At this stage, courts appear to be in a period of doctrinal flux, with decisions likely to emerge that both support and contradict Heppner,” Podolny predicted. Privilege determinations “remain highly fact‑dependent and are likely to continue to vary by jurisdiction,” she said.

At the same time, there may be limited precedential value in the decisions so far. Heppner and Warner are “district court decisions made by a Federal Article III and Federal Article I magistrate judge, respectively,” Sherer pointed out. Assuming Warner is “not overturned by the Article III judge assigned to the case, then both decisions will be law of the given cases, but may have limited effect outside of those cases,” he noted.

Practical Takeaways

Despite the small body of case law addressing attorney-client privilege and work-product protection as it relates to AI use, some practical lessons already can be drawn from the Heppner and Warner decisions.

For prosecutors seeking discovery of technology-assisted materials, Heppner provides a framework for prosecutors to “defeat privilege and work product claims raised by defendants who have, on their own and not at the direction of counsel, used publicly available AI tools for various purposes,” Koukios said. “This will likely encourage prosecutors to include AI-related provisions in search warrant applications and grand jury subpoenas,” he predicted.

See our two-part series on the FirstEnergy decision: “Reaffirming Upjohn’s Approach to Privilege in Internal Investigations” (Jan. 14, 2026), and “Best Practices for Preserving Privilege in Internal Investigations” (Jan. 21, 2026).

Prepare for More Discovery

In the immediate future, litigators can expect more discovery requests concerning AI use. Such requests for AI prompts and results “are becoming much more common, especially as discussion points in depositions,” Sherer observed. Whether AI use is queried in a deposition or not, “practitioners should absolutely be asking their clients about the uses of these platforms as part of prospective fact development,” he advised.

Even as discovery requests seeking AI prompts and outputs are more frequent, they “are often made without meaningful conferral regarding whether a party’s use of AI is actually relevant or necessary to the core facts or evidence at issue in the case,” Podolny noted. “Just because information exists does not mean that it is significantly relevant to the dispute or reasonably accessible to obtain,” she said.

Caution Clients

For defense counsel advising clients under investigation, Heppner “heightens the need to warn clients not to use publicly available AI tools for case strategy or ‘legal research’ absent counsel’s direction, and to create a record if a client’s AI use is at counsel’s direction,” Koukios suggested. “Clients should be told that using publicly available AI chatbots to draft narratives, test defenses or explore legal arguments can create discoverable records and may waive privilege if it involves attorney communications or litigation strategy,” he said.

For individual and corporate defendants that independently use AI platforms, “the practical risk is that independent use of publicly available AI tools can generate discoverable electronic evidence and, if that use includes attorney advice or legal theories, it may waive privilege and work product protections.” Koukios cautioned.

Defense, corporate and regulatory counsel “need to be aware of what their clients are doing with [generative AI],” Sherer advised. Counsel “needs to ask the questions, and . . . client organizations should have an answer,” he added, acknowledging that can be a challenge with how freely available AI technologies are.

See “AI Governance: Striking the Balance Between Innovation, Ethics and Accountability” (Feb. 12, 2025).

Understand Policies

“Understanding the privacy policies governing the AI tools in use is critical,” Podolny said. “For this reason, companies and law firms evaluating the adoption of new technologies are devoting significant attention to the precise terms of applicable contracts, particularly as they relate to the confidentiality, security and potential downstream use of information uploaded to or generated by these tools,” she observed.

Heppner follows “guidance commonly given to corporations, which is to use caution when using unlicensed platforms or those that do not have confirmation that information submitted to the platforms will be protected and not used for other purposes,” Sherer said. 

See “Contracting With Vendors to Mitigate Third-Party AI Risk” (Feb. 18, 2026).

Assess Reasonable Expectation of Confidentiality

After Heppner and Warner, whether users of publicly accessible AI platforms retain any reasonable expectation of confidentiality in their prompts or outputs remains to be seen. Heppner “suggests that they do not if the terms of use allow broad use and disclosure of a user’s inputs and the tool’s outputs,” Koukios cautioned. “Narrower terms of use could lead to more reasonable expectations of confidentiality,” he said.

Because there is unlikely to be a reasonable expectation of confidentiality with the use of a publicly accessible AI platform, Podolny predicted that “individuals – particularly those with limited resources – may face meaningful access‑to‑justice challenges when the use of widely available AI tools effectively forecloses otherwise legitimate claims of privilege or protection.”

There is also a risk that denials of privilege and work-product protection could extend beyond AI. “I wonder if some of Judge Rakoff’s reasoning in Heppner could be extended to simple search engine use, or even AI tools embedded in search engines, where litigants might expect their searches to be protected,” Sherer queried. It is possible that Heppner is “a logical extension of that, where self-help might not constitute protected legal assistance,” he said.

See “A Baker’s Dozen AI Governance Resolutions for 2026” (Jan. 7, 2026).

SEC Enforcement

What “Back to Basics” Under Chair Atkins Means for SEC’s Division of Enforcement


Although every new administration brings a degree of change, developments at the SEC have been swift and significant following the end of Chair Gary Gensler’s tenure. Chair Paul S. Atkins has indicated that he intends to move away from “ad hoc enforcement” and toward a steadier, more principles-based approach that focuses on the SEC’s core mission. Ultimately, the new SEC will focus on what Atkins refers to as “back to basics” enforcement.

To explore how leadership changes and new policy directions are reshaping the efforts of the SEC’s Division of Enforcement (Enforcement), as well as the implications for those navigating the evolving regulatory environment, Gibson Dunn hosted a webinar, entitled “The New SEC: New Director and Enforcement.” The panel was moderated by Gibson Dunn partner David Woodcock and featured his partners Jina L. Choi, Osman Nawaz, Tina Samanta and Mark K. Schonfeld. This article offers relevant takeaways from the program.

See “What to Know About the Sleeping Giant That Is the SEC’s Amended Reg S‑P” (Dec. 10, 2025).

Overview

It is a time of a major transition at the SEC, and the Commission has signaled a reset, Woodcock remarked. Atkins has indicated that he intends to hold accountable those who lie, cheat and steal via a renewed focus on fraud and manipulation, with less attention to expansive theories of disclosure, control violations and simple negligence, he summarized.

“Chairman Atkins has emphasized that there is a new day at the SEC, and the new SEC will focus on its core mission – protecting investors, ensuring fair markets and fostering capital formation – while bringing what he describes as greater consistency, transparency and due process to Enforcement,” Woodcock said. The stated themes are a stark contrast from the last few years, and the SEC is expected to take a step back from enforcement in areas such as environmental, social and governance (ESG), cybersecurity disclosures and crypto.

“It’s a new leadership team, a recalibrated mission and a different tone at the top,” Woodcock summarized.

Leadership Changes

SEC Chair Paul S. Atkins

Atkins was sworn into office on April 21, 2025. Although significant changes were made to SEC practices and positions on substantive issues under Acting Chairman Mark T. Uyeda, a clearer picture of Atkins’ priorities and views on enforcement are emerging now that he has taken office, Schonfeld observed.

Atkins has stated that he wants to ensure the SEC fulfills its mission in a way that is grounded in its statutory authority from Congress, which contrasts with past Commissions that have pushed the interpretation of statutes and engaged in “regulation by enforcement,” Schonfeld noted. As a result, Enforcement is expected to focus on concrete instances of fraud, where there are demonstrable misrepresentations or fraudulent disclosures and conduct that results in harm to victims, he explained. Atkins has also signaled the SEC’s greater receptivity to the crypto industry, and the issuance of regulations to encourage the industry’s development in the U.S.

Director of Enforcement Judge Margaret Ryan

Judge Margaret Ryan was appointed director of Enforcement on September 2, 2025. Notably, when announcing her appointment, Atkins commented that Ryan’s leadership of Enforcement would be guided by Congress’ original intent in enforcing the securities laws, particularly as they relate to fraud and manipulation, Schonfeld said.

It is still early in Ryan’s tenure, and she has not made any public statements that elucidate her visions for Enforcement, Schonfeld continued. Anecdotally, from meetings with defense counsel, Ryan’s process has been described as “judicial” in that she is focused on understanding the factual record and legal issues, whether the SEC can prove a violation and, if so, what remedies are appropriate. That is positive for defense counsel and their clients, who were sometimes frustrated when engaging with prior Commissions that did not necessarily feel constrained by what could be proved so much as motivated by what might be achieved through a settlement, he opined.

“It is a refreshing change,” Schonfeld emphasized. “I think what remains to be seen is how those messages and agendas from the chairman and the director filter down through the many layers of staff to get to the line-level attorneys that fund managers deal with day in and day out in investigations.”

Organizational Structure

Reorganization to Consolidate Direct Reports

Prior to Atkins’ arrival, Uyeda reorganized Enforcement’s leadership structure to improve efficiency, management and oversight, Choi said. In the announcing memorandum that was reportedly issued to staff in early April 2025, Uyeda said that the sheer number of senior officers reporting to the director of Enforcement had created management challenges. The number of direct reports to the director has been consolidated to six:

  • deputy directors for:
    • northeast;
    • southeast;
    • west; and
    • specialized units;
  • chief counsel; and
  • chief litigation counsel.

The new structure is unlikely to affect how investigations are conducted or who conducts them, Choi continued. Staff and their immediate supervisors will still issue document requests and subpoenas for documents and testimony. Staff remain the point of contact for defense counsel on a day-to-day basis, and there will still be an opportunity to escalate.

It is too soon to gauge whether Ryan will retain the new leadership structure, Choi cautioned. There has been a significant change of personnel at the SEC and the federal government generally. There was the “fork in the road” email and VERA – Voluntary Early Retirement Authority - incentives for personnel, especially senior personnel, to move on from the Commission. “Those changes may continue and Ryan may want to get a sense of things before making more changes,” she opined.

Specialized Enforcement Units

Enforcement’s specialized units were announced in 2010 as part of the last major reorganization of the division, Choi noted. Currently, the specialized units include:

  • Cyber and Emerging Technologies Unit, which was renamed from Crypto Assets and Cyber Unit;
  • Complex Financial Instruments Unit;
  • Market Abuse Unit;
  • Public Finance Abuse Unit; and
  • Asset Management Unit.

An executive order issued at the beginning of the second Trump administration paused investigation and enforcement of the Foreign Corrupt Practices Act (FCPA) by the U.S. Department of Justice, and certain FCPA prosecutions have been dismissed, Choi said. The SEC’s longstanding FCPA chief and deputy chief have retired, and it appears the FCPA Unit no longer exists, as it does not appear on the SEC’s website and no new chiefs have been named, she added.

See “SEC Commissioners Urge Balance of Crypto Innovation and Privacy” (Jan. 21, 2026).

Shifting Enforcement Priorities

ESG and Digital Assets

The ESG Task Force was disbanded in the summer of 2024, Samanta noted. Over the three years it operated, the ESG Task Force brought two main types of ESG enforcement cases: (1) against public companies alleging misstatements; and (2) against investment advisers as to their investing processes for ESG funds. As ESG investing and ESG funds themselves decline, there will be a natural decrease in related enforcement, she observed.

A sea change is also expected from the new administration’s approach to digital assets and crypto, Samanta said. Atkins has stated that most crypto assets are not securities and has indicated that the SEC will draw clear lines rather than rely on the Howey test - which was articulated in 1946 – as the framework for digital assets. “To that end, Chairman Atkins recently unveiled Project Crypto as a Commission-wide initiative, with the focus on bringing crypto business and innovation back to the U.S.,” she stated.

“Back to Basics” Enforcement

“Back to basics” covers the broader regulatory approach of the SEC, not just Enforcement, Nawaz noted. As Commissioner Hester M. Peirce said in remarks delivered in 2018, “the SEC is not an enforcement agency, but enforcement is an important tool for the SEC.” In more recent speeches, Peirce said that an enforcement philosophy pursuing minor violations with the same vigor as major violations can cause problems, for example, by diverting resources from high-priority areas. The efficient use of resources is relevant now more than ever given the reduction in staff, he added.

Enforcement priorities under Atkins – which have been supported by the types of cases brought thus far during his tenure – have been identified as:

  • insider trading;
  • offering fraud;
  • market manipulation;
  • accounting fraud;
  • protection of retail investors; and
  • matters involving genuine harm and bad acts.

The “back to basics” approach will require Enforcement staff to answer key questions, including whether there is any investor harm, and to clearly show the legal elements of a claim and how the SEC will prove them, Nawaz commented. If the staff find they must conduct a detailed analysis or there is some risk around proving any of the straightforward questions, it is likely the case will not fit within a “back to basics” approach. “The catchall is matters that involve genuine harm and bad acts – that really illustrates where the SEC will want to be spending their enforcement resources,” he added.

Cross‑Border Task Force

In early September 2025, the SEC announced the formation of the Cross-Border Task Force within Enforcement to strengthen enforcement efforts against fraud involving foreign-based companies accessing the U.S. capital markets, with a focus on China, Choi said. It is the first and only task force announced during the new administration and reflects where the Commission wants to direct its resources. “It may be an answer to calls from Congress and other stakeholders to scrutinize Chinese companies that are seen as taking advantage of the U.S. capital markets and those gatekeepers who help them,” she observed.

Enforcement has deep and expansive experience investigating cross-border and international cases, including those involving Chinese issuers, advisers and traders, as well as the brokers and auditors who help them, Choi continued. Interestingly, the Commission has been quite active in ordering trading suspensions, generally for offshore issuers whose stocks are believed to be involved in market manipulation. The orders state that suspension is necessary for the public interest and for the protection of investors. Nine trading suspensions were ordered in a six-week period at the end of 2025, which is more than the total ordered in the last three years, she noted.

Voluntary Dismissal of Prior Litigation

Even before Atkins took office, multiple crypto lawsuits were dismissed to facilitate the Commission’s ongoing efforts to reform and renew its regulatory approach to the crypto industry, Nawaz said. There have also been dismissals in other areas, including a dealer case; a liquidity rule case; and a policy and procedure case based on “the specific facts and circumstances of the case.” On balance, the dismissals help pave the way for Atkins’ “new day” and action has been swift, especially in relation to crypto, he added.

See “SEC Stresses Cybersecurity, AI and Crypto in Its 2025 Exam Priorities” (Dec. 18, 2024).

Greater Transparency

Wells Process

The Wells process is a procedure where, at the end of an investigation, if the staff has determined that they believe a violation has taken place, the subject of the investigation is given the opportunity to make a written Wells submission (and often attend a meeting) to persuade the staff that an enforcement action should not be pursued, Schonfeld explained. The effectiveness of the Wells process depends on the subject’s understanding of what the staff has gathered as part of the investigative record, and the evidence on which the enforcement action would be based, he noted.

Historically, the level of access to an investigative record that a subject and their counsel is given varies between different SEC offices, and even within an office, Schonfeld continued. Atkins has indicated that, in the absence of exigent reasons (e.g., a parallel criminal investigation), the Wells process should be transparent, and staff should provide access to the record so that the subject can provide meaningful submissions and engage in a useful dialogue about the evidence and merits. In a recent Wells process, the staff were open and provided access to what appeared to be all the transcripts and exhibits, Schonfeld mentioned.

Greater transparency results in a more productive process, Schonfeld continued. The Wells process is particularly valuable for trial counsel at the SEC, who have an important role in helping staff decide on an appropriate outcome and may not have time to examine the record as defense counsel would. Based on Atkins’ pronouncement, defense counsel may now argue that access is the default position and can more easily escalate the issue up the chain, he said.

Along that vein, Atkins has also said that subjects should be given at least four weeks to provide a Wells submission, which is a very welcome development, Samanta added. The staff have still specified the standard two weeks in letters but have accommodated extensions, Schonfeld noted.

Consideration of Settlements and Collateral Waivers

One consequence that can flow from settlements or judgments against a party for a violation of the securities laws is the loss of certain exemptions or safe harbors that might otherwise apply, Schonfeld explained. For example, companies with well-known seasoned issuer status can take advantage of a safe harbor for forward-looking statements, but that entitlement may be forfeited if the company is the subject of an enforcement action that results in a finding that the company violated anti-fraud provisions. The Commission can grant exemptions from such disqualifications, but it has historically decided whether to accept a settlement offer and a request for waiver at the same time. As a result, there was a risk that the SEC would accept an offer of settlement that bound the company to a fraud violation settlement without granting a waiver, he said.

The SEC changed the process for a period during the prior Trump administration, and Atkins has returned to that process, Schonfeld commented. Specifically, if a company wants to offer to settle an anti-fraud violation that would trigger a disqualification, the company can request a waiver and the Commission will consider both the settlement offer and waiver request. If the Commission decides to accept settlement but refuses to grant a waiver, the company will be given an opportunity to withdraw the settlement offer. “That is good news for parties that are confronted with settlement decisions, as it will give them greater transparency and predictability about the consequences of a settlement,” he added.

SEC Enforcement Actions

Large Scale Fraud

The SEC’s focus on large scale fraud actions, especially offering frauds, is illustrated by two recent actions that, according to Nawaz, are likely to be emphasized by Enforcement going forward:

  1. Raising Money Through Misrepresentations: The SEC filed fraud charges against a New York-based commercial real estate firm and its owner for allegedly using an internet funding platform to obtain more than $52 million from over 700 investors by falsely claiming the funds would be used to purchase or recapitalize two specific deals, but instead using the funds for unrelated projects and other purposes.
  2. Misusing Investor Funds: The SEC filed charges against the founder and former CEO of a privately held technology startup for allegedly raising more than $42 million through sales of company stock by making false and misleading statements about the company’s use of artificial intelligence.

The above cases were in Enforcement’s pipeline for some time, but there are likely to be shifts in staff resourcing and more time spent looking for similar large scale fraud actions, Nawaz opined.

Investment Adviser Focus

The SEC’s “back to basics” approach under Atkins is reflected in cases involving investment advisers, with an uptick in disclosure-based fraud and other misconduct cases, Samanta noted. There is also a focus on traditional areas (e.g., conflicts of interest and expense allocations), in addition to allegations of fraud. The cases are consistent with the stated focus on retail investors and individual accountability, with the SEC charging individual representatives, she added.

It is difficult to predict whether the number of investment adviser exams will decrease, but it seems likely they will become more risk-based, Samanta reasoned. “For registered entities such as investment advisers and broker dealers, we think the exam process is likely to present an opportunity to show potential remediation in connection with issues uncovered during an exam, and potentially to avoid an escalation to Enforcement.”

It will be interesting to see if the new administration undertakes any initiatives similar to the prior Trump administration, such as the Retail Task Force or the Share Class Disclosure Initiative, which resulted in charges against 79 investment advisers through a self-reporting process, Samanta said.

Opportunities and Strategies in Navigating an Investigation

There is an opportunity for earlier engagement with SEC staff on the merits of a matter, including from the start of an investigation as the factual record develops and potential legal theories are being considered, Woodcock said. Defense counsel should also look for opportunities for earlier escalation to senior staff, before the Wells process, understanding that there is likely to be only one opportunity to engage with the director, if at all. “Do not wait until the Wells process to engage, because staff are more likely to have firm views by that stage and to feel strongly about their case,” he asserted.

The defense team may also consider being more transparent with the SEC, depending on the facts of the particular investigation, Woodcock continued. Greater transparency from the defense may ameliorate the risk of whistleblowers coming forward in the future and could result in greater cooperation credit from the SEC, he added.

From a strategy perspective, arguments should be grounded in the Commission’s priorities (e.g., emphasizing the absence of fraud or investor harm), Woodcock suggested. Although it may be possible to challenge investigations that are inconsistent with the SEC’s stated priorities, that may be risky as staff can easily counter that they are aware of their priorities, he cautioned. “On all these points, don’t expect the staff to necessarily agree with you, but I think making these arguments early and often is probably a good idea.”

In a Wells process, it is reasonable to expect access to the investigative record and more consistency across offices, Woodcock commented. Counsel should request information if they do not have what they need and then be ready to dive in quickly because the investigative record may be voluminous. Four weeks is not a lot of time for a review, he cautioned.

Although the SEC’s current approach seems to be less aggressive than the prior administration, priorities will inevitably shift again, Schonfeld said. “An aggressive Enforcement staff can be somewhat empowering for in-house counsel and the compliance team at an SEC registrant. When the government taps the brakes, however, it can create a mistaken impression that registrants don’t have to worry as much about regulatory oversight.”

It is important to remember that another wave of investigations will eventually come when there is a market correction or change in administration, and those investigations will be focused on what people are doing now, Schonfeld cautioned. The seeds for the next wave of investigations are being sown now and over the next three or so years. Counsel can assist clients by providing support, authority and reasons to maintain the same level of vigilance that was developed over the preceding years, he offered.

“The statute of limitations for violations is very long – at least five years – and so anything that anybody is doing now will be the subject of investigations in the next administration at the latest, let alone what can happen if there’s a major market correction,” Schonfeld emphasized. “There are still things to be concerned about, and still reasons to keep your eyes focused on the target.”

See “Present and Former SEC Officials Discuss Strategy, Testimony, Proffers and Negotiations” (Mar. 19, 2025).

People Moves

Mason Hayes & Curran Welcomes Former Data Protection Commissioner As Global Digital Regulatory Consultant


Former Irish Data Protection Commissioner Helen Dixon has joined Mason Hayes & Curran as a global digital regulatory consultant within its data & technology team. Dixon will further enhance the firm’s capabilities in data and technology regulation and platform governance.

Dixon helps clients to develop practical strategies that enable them to operate confidently while meeting regulatory and societal expectations in an increasingly complex regulatory environment shaped by emerging E.U. and global rules regulating data, technology, AI and content.

Dixon brings deep regulatory insight to her new role, having previously served as a commissioner at both the Data Protection Commission and the Commission for Communications Regulation.

For commentary from Dixon, see “Irish Data Protection Commissioner Helen Dixon on Breach Notification, the Role of the DPO and a U.S. Privacy Law” (Jun. 5, 2019).