, , , , ,

Magistrate Judge’s opinion finding OpenAI waived attorney-client privilege ignores Supreme Court, 2d Circuit precedent

This article is the third in a series reviewing Magistrate Judge Wang’s controversial opinion finding that OpenAI waived its attorney-client privilege regarding the reasons OpenAI deleted Books 1, 2 datasets in 2022. For the first 2 reviews, click below. Today’s article will look more closely at the key Supreme Court precedents and Second Circuit precedents Judge Wang’s opinion ignores.

Magistrate Judge’s Opinion Ignores Halo and Andy Warhol Foundation v. Goldsmith

Magistrate Judge Wang’s opinion finds waiver of privilege due to the alleged willfulness of OpenAI’s infringement being “at issue” in the case.* But the Judge’s opinion commits legal error in failing to apply the Supreme Court’s teachings in (1) Halo Elecs. Inc. v. Pulse Elecs., Inc., 579 U.S. 93 (2016) on willfulness and (2) Andy Warhol Foundation for the Visual Arts, v. Goldsmith, 598 U.S. 508 (2023) on use-by-use analysis of fair use for analyzing each separate alleged infringement. (*The opinion’s analysis of selective voluntary disclosure is not reviewed by this article.)

First, consider Halo. It dealt with alleged willful infringement of a patent, but its teaching is broadly worded and based on general tort principles that should apply as well to willful copyright infringement. Writing for the Supreme Court, Chief Justice Roberts explained:

“[C]ulpability is generally measured against the knowledge of the actor at the time of the challenged conduct. See generally Restatement (Second) of Torts § 8A (1965) (“intent” denotes state of mind in which “the actor desires to cause consequences of his act” or “believes” them to be “substantially certain to result from it”); W. Keeton, D. Dobbs, R. Keeton, & D. Owen, Prosser and Keeton on Law of Torts § 34, p. 212 (5th ed. 1984) (describing willful, wanton, and reckless as “look[ing] to the actor’s real or supposed state of mind”); see also Kolstad v. American Dental Assn., 527 U.S. 526, 538, 119 S.Ct. 2118, 144 L.Ed.2d 494 (1999) (“Most often … eligibility for punitive awards *106 is characterized in terms of a defendant’s motive or intent”).” (emphasis added).

Thus, under Halo, courts must examine willfulness or knowledge of the defendant at the time of the alleged infringement. As I explained in a prior post, this examination of the defendant’s state of the mind at the time of the alleged offense (contemporaneous state of mind) is used generally in many areas of law from torts to criminal law to infringement when the defendant’s state of mind is at issue. Copyright law is no different.

Second, add the important teaching of Andy Warhol Foundation. The case involved the examination of Factor 1 of fair use in a case in which the artist Andy Warhol and later the Andy Warhol Foundation made numerous uses of a portrait photograph taken by Lynne Goldsmith. But to determine whether the uses were fair or infringement, courts must examine each respective use or alleged infringement separately. Writing for the majority, Justice Sotomayor explained:

“The fair use provision, and the first factor in particular, requires an analysis of the specific ‘use’ of a copyrighted work that is alleged to be ‘an infringement.‘” § 107. The same copying may be fair when used for one purpose but not another. See Campbell, 510 U.S. at 585, 114 S.Ct. 1164 (contrasting the use of a copyrighted work ‘to advertise a product, even in a parody,’ with ‘the sale of a parody for its own sake, let alone one performed a single time by students in school’); Sony Corp. of America v. Universal City Studios, Inc., 464 U.S. 417, 449–451, 104 S.Ct. 774, 78 L.Ed.2d 574 (1984) (contrasting the recording of TV ‘for a commercial or profit-making purpose’ with ‘private home use’).

Here, Goldsmith’s copyrighted photograph has been used in multiple ways: After Goldsmith licensed the photograph to Vanity Fair to serve as an artist reference, Warhol used the photograph to create the Vanity Fair illustration and the other Prince Series works. Vanity Fair then used the photograph, pursuant to the license, when it published Warhol’s illustration in 1984. Finally, AWF used the photograph when it licensed an image of Warhol’s Orange Prince to Condé Nast in 2016. Only that last use, however, AWF’s commercial licensing of Orange Prince to Condé Nast, is alleged to be infringing. We limit our analysis accordingly. In particular, the Court expresses no opinion as to the creation, display, or sale of any of the original Prince Series works.”

The Warhol case provides an excellent example of why examining the state of mind of the alleged infringer at the time of the specific offense is required. Imagine that, in 2016, the Andy Warhol Foundation, acting on legal advice, licensed the Orange Prince created by Andy Warhol to use on the cover of a special magazine of Vanity Fair. Such 2016 legal advice is completely irrelevant to the state of mind of Andy Warhol in 1984 when he created the Prince series. Of course, the 2016 legal advice would be relevant to the Foundation’s own conduct in 2016. But it would not — and could not — be relevant to Andy Warhol’s conduct in originally creating the works in 1984.

The Supreme Court’s use-by-use analysis of fair use requires a use-by-use analysis of each alleged infringement. See Timothy J. McFarlin, Infringing Use, Not Works, 76 S. Car. L. Rev. 103, 105, 112-13 (2024). As Justice Gorsuch explained in concurrence, “Under the law Congress has given us, each challenged use must be assessed on its own terms.” Warhol, 598 U.S. at 558 (Gorsuch, J., concurrence). Under Warhol, the use-by-use analysis is especially warranted where, as here, OpenAI has asserted a fair use defense. The two district courts that have considered fair use in the context of LLMs both applied use-by-use analysis of Warhol. See Bartz v. Anthropic, 787 F. Supp. 3d 1007, 1020-29 (N.D. Cal. 2025) (examining, under Warhol, the respective uses of Anthropic in downloading copies to create a permanent library versus training uses); Kadrey v. Meta Platforms, Inc., 788 F. Supp. 3d 1026, 1043 n.18, 1047-48 (N.D. Cal. 2025) (considering the uses of Meta in downloading copies for the purpose to train, but differentiated from the use in the potential distribution claim in torrenting the copies).

The teachings of Halo and Warhol require courts to examine the state of mind of the defendant alleged willful infringement at the time of each alleged infringement by the defendant.

But Magistrate Judge Wang’s opinion fails to do so. On p. 19, Judge Wang’s opinion simply lumps everything into an undifferentiated, generic “willful infringement” that OpenAI allegedly “willfully infringed their copyrighted works.” The opinion specifies no time, conduct, or OpenAI employees who engaged in this generic “willful infringement,” much less allege that the OpenAI employees actually or ever relied on any in-house attorney’s legal advice when engaging in alleged willful infringement. Magistrate Judge Wang’s opinion’s failure to identify the times of alleged willful infringement is quite noticeable when compared the opinion’s quite detailed timeline of the chronology of OpenAI’s lawyer’s assertions in 2024 and 2025 regarding its deletion of Books 1 and 2. Op. pp. 2-10. No such timeline is provided for the alleged willful infringement at issue. The opinion instead merely cites to the Plaintiffs’ Consolidated Complaint (See, e.g., ECF 183 ¶¶ 121, 175, 189, 200, 211, 221, 226, 233, 242, 247, 253, 266, 276, 286, 301(d), 312.)

But these allegations in the Complaint are also bare, lacking allegations of times or the people involved in OpenAI’s downloading of Library Genesis or any allegation those OpenAI employees actually relied on the advice of counsel of OpenAI. But the Complaint involves multiple alleged infringements apparently that occurred at different times, including (1) downloading from shadow libraries and (2) use of copies in AI training.

If we construct a timeline of alleged infringement related to the Books 1 and 2 datasets at issue from Magistrate Judge Wang’s own opinion as well as public information, we can identify different time periods when the different alleged infringements occurred:

Timeline of Alleged Infringements by OpenAI and Key Events

I have labeled the 2018 downloading “Alleged Willful Infringement 1” and the circa 2020 training “Alleged Willful Infringement 2” for clarity. The training with Books 1 and 2 may have spanned the period from 2018 – late 2021.

Applying Halo and Warhol requires the court to examine the alleged willfulness of OpenAI based on its state of mind at each alleged infringement:

  1. OpenAI’s state of mind in 2018 during its downloading from shadow libraries
  2. OpenAI’s state of mind in later using Books 1 and 2 to train its earlier model at least by May 2020, though the period may span from 2018 to late 2021. For ease of reference, I will refer to the training period with Books 1 and 2 as “circa 2020.”

Distinguishing the respective times of alleged infringement is especially warranted here, given the startup OpenAI was just a non-profit research entity before it added a for-profit arm in 2019. Given the relevance of both research and non-profit to the fair use analysis, the proper inquiry to analyze willfulness of the initial downloading must focus on OpenAI’s researchers’ state of mind in 2018 when they downloaded from shadow libraries, under the Supreme Court’s teaching in Halo, 579 U.S. at 106. And, to analyze the willfulness of OpenAI’s later use of Books 1 and 2 to train its model, the court must focus on the time of the training, which may have spanned 2018 to 2021.

Indeed, even the lawyer for the New York Times, which is also suing OpenAI, recognized the need to consider OpenAI’s earlier status as a non-profit research entity. Although the lawyer was refuting the statute of limitations for OpenAI’s earlier conduct, the lawyer’s insight has equal application when understanding the fair use defense — or OpenAI researchers’ understanding of it in 2018 or 2020. At a hearing in the case, the New York Times lawyer suggested “training models for research purposes or training models in a university,” such as when OpenAI “present[ed] itself as being this nonprofit benefit entity developing artificial intelligence for the benefit of humanity” might weigh differently under Factor 1 than a commercial use. See Transcript for Oral Argument on Motion to Dismiss, at 41–42, New York Times Co. v. Microsoft Corp., 777 F. Supp. 3d 283 (S.D.N.Y. 2025) (No. 23 Civ. 11195 (SHS)).

Under Halo and Warhol, Magistrate Judge Wang’s opinion is legal error. The opinion failed to identify, much less examine, the specific times for each alleged willful infringement by OpenAI in torrenting in 2018 and in training by 2020. And it failed to examine the mental state or willfulness of OpenAI “against the knowledge of the actor at the time of the challenged conduct.Halo. What Benjamin Mann and other early OpenAI researchers/employees knew in 2018 or 2020 is the relevant inquiry. What OpenAI in-house lawyers hired afterwards thought and said subsequently in 2022 is irrelevant to what Benjamin Mann and other OpenAI researchers/employees thought in 2018 or 2020 in engaging in the alleged willful infringement. OpenAI’s in-house counsel’s communication in 2022 cannot have retroactively entered the minds of Benjamin Mann and other OpenAI researchers back in 2018 or circa 2020.

2d Circuit Precedent

Magistrate Judge Wang’s opinion is also legal error under Second Circuit precedent. As the analysis and timeline above show, OpenAI researchers who torrented LibGen in 2018 and trained AI model(s) using Books 1 and 2 that was discussed in OpenAI’s research paper in 2020 could not have relied on the 2022 advice of OpenAI’s in-house counsel regarding deletion of Books 1 and 2.

As the Second Circuit held in In re County of Erie, for waiver an “essential element” is “reliance on privileged advice in the assertion of the … defense to effect a waiver.” 546 F.3d 222, 229 (2d Cir. 2008); see also U.S. v. Bilzerian, 926 F.2d 1285, 1292 (2d Cir. 1991) (“This waiver principle is applicable here for Bilzerian’s testimony that he thought his actions were legal would have put his knowledge of the law and the basis for his understanding of what the law required in issue. His conversations with counsel regarding the legality of his schemes would have been directly relevant in determining the extent of his knowledge and, as a result, his intent.).

Indeed, the district court opinion Magistrate Judge Wang relied on, Arista Records LLC v. Lime Group LLC, 06-CV-5936 (KMW), 2011 WL 1642434, at *2 (S.D.N.Y. Apr. 20, 2011), recognizes this essential element: “the advice given by counsel where that advice played a substantial and significant role in formulating actions taken by the defendant.” In Arista Records, Judge Wood correctly trained the inquiry of waiver of attorney-client privilege on whether “a party … assert[ed] it believed its conduct was lawful, and simultaneously claim[ed] privilege to block inquiry into the basis for the party’s state of mind of belief.” Id. (emphasis added).

Here, the alleged willful infringements by OpenAI include (1) 2018 torrenting from shadow libraries and (2) circa 2020 training by OpenAI researchers using Books 1 and 2. It is simply impossible for OpenAI researchers in 2018 or 2020 to have relied on OpenAI attorneys’ advice (on deletion of datasets) that was not given until 2022 — by OpenAI attorneys who were not even working at the company in 2018 or 2020. Whatever “the basis for the party’s [OpenAI’s] state of mind of belief” in 2018 and 2020, it was not OpenAI’s in-house counsel’s communications in 2022.

Deletion Is Not Infringement

And, even if OpenAI employees relied on in-house attorneys’ advice in deleting Books 1 and 2 in 2022, such deletion of copies is not copyright infringement, much less willful infringement. Deletion is the antithesis of reproduction. Indeed, destruction is often a remedy sought for infringing reproductions. Cf. 17 U.S.C. s. 503(b) (“As part of a final judgment or decree, the court may order the destruction or other reasonable disposition of all copies or phonorecords found to have been made or used in violation of the copyright owner’s exclusive rights, and of all plates, molds, matrices, masters, tapes, film negatives, or other articles by means of which such copies or phonorecords may be reproduced.”).

For example, in the class settlement in Bartz v. Anthropic, Class Counsel touted as a victory for the class that Anthropic agreed to destroy datasets from shadow libraries: “Class Counsel also secured valuable non-monetary relief. The Settlement requires Anthropic to ‘destroy all the original files of works torrented/downloaded from Library Genesis or Pirate Library Mirror, and any copies that originate from the torrented copies,” subject to certain legal preservation obligations. Dkt. 363-3 ¶2.2. This destruction is an enormous victory for victims of Anthropic’s piracy, given Anthropic’s intent to retain the pirated works “forever.” Dkt. 244 at 3. Another important benefit is Anthropic’s certification that “neither the LibGen or PiLiMi datasets, nor any portions of those datasets, were in the training corpus of any of its commercially released” LLMs. Dkt. 363-3 ¶3.1.” Plaintiffs’ Notice of Motion and Motion for Attorneys’ Fees, Bartz v. Anthropic (filed Dec. 3, 2025), at p. 12.

If anything, the deletion of datasets helps an AI company avoid infringement that may arise from building a permanent library of copies, whether used for training or not. See Bartz v. Anthropic, 787 F. Supp. 3d 1007, 1026 (N.D. Cal. 2025) (holding that “[p]irating copies to build a research library without paying for it, and to retain copies should they prove useful for one thing or another, was its own use — and not a transformative one“) (emphasis added); see also my analysis.

Ignoring Halo and Warhol Eviscerates Attorney-Client Privilege

By not following the Supreme Court’s teachings in Halo and Warhol, Magistrate Judge Wang’s opinion sets a dangerous precedent. Whenever a plaintiff alleges willful infringement (which is just about every complaint for copyright infringement seeking statutory damages), Judge Wang’s opinion gives defendants a Hobson’s choice: Concede willfulness or waive attorney-client privilege. See Op. p. 19 (“Because OpenAI continues to make factual assertions that its conduct was not willful, and in the absence of any clear representations that OpenAI intends to waive this affirmative defense or will not advance factual arguments opposing Class Plaintiffs’ claims of willfulness, OpenAI has put its alleged good faith and state of mind at issue.”).

But this overbroad approach is not the law. Under Halo, willfulness and state of mind must be examined at the time of the alleged infringement. Under Warhol, each infringement must be analyzed separately especially when a fair use defense is raised. The same use might be fair for one purpose but not another. And, under Second Circuit and Southern District of New York precedent, waiver requires a showing that the people who engaged in the infringement actually relied on legal advice in doing so, meaning the “advice played a substantial and significant role in formulating actions taken by the defendant.”

Advice by OpenAI’s in-house counsel on deletion in 2022 cannot have informed the early OpenAI researchers in their torrenting Library Genesis in 2018 or their AI training activities circa 2020. (Benjamin Mann testified in Bartz v. Anthropic that he believed, based on his own research, it was fair use to torrent Library Genesis when he worked at OpenAI and it was fair use to train the AI model in 2019.) The alleged willfulness of the 2018 torrenting and 2020 training hinge on, under Halo, “the knowledge of the actor at the time of the challenged conduct.

Magistrate Judge Wang’s opinion already ruled out that the crime-fraud exception applied to the 2022 communications because they took place after the alleged willful criminal infringement in torrenting Library Genesis in 2018. Op. p. 26. And Judge Wang’s opinion already ruled out even “probable cause to believe that that the [2022] communications at issue were in furtherance of the types of misconduct that are recognized by Second Circuit precedent and/or that such communications were intended to facilitate or conceal such activities.” Op. p. 27. Both rulings show the need both to examine the times of the alleged infringements and to ensure any waiver of attorney-client privilege involves attorney communications that actually “played a substantial and significant role” in those infringements. Magistrate Judge Wang’s opinion fails to do so.

Waiver does not occur in the air or en masse. Waiver occurs when the legal advice was actually at issue because the advice was a basis for the actor’s state of mind in committing specific acts of infringement at the time they were committed.

Leave a Reply


Discover more from Chat GPT Is Eating the World

Subscribe now to keep reading and get access to the full archive.

Continue reading