Protective Order Limited Uploading Discovery Responses to Open A.I.

Does Disclosure of Litigation Hold Directive to Preserve “Texts” Waive Privilege?
March 26, 2026
A.I. Limerick
March 28, 2026

In a putative class action brought by plaintiffs who live within a three-mile radius of a chemical facility, the court addressed restrictions on the use of open artificial intelligence tools to review any of the materials produced by an opponent in discovery, even if they are not confidential. Jeffries v. Harcros Chemicals, Inc., 2026 WL 820218 (D. Kans. Mar. 25, 2026).

“ROUND 1”: LIMITATION ON UPLOADING CONFIDENTIAL INFORMATION

The original protective order “resolved the parties’ first round of disputes over restrictions for using AI Tools in relation to Confidential Information” that was produced to that party by an opponent in discovery.

That order provided that, if a receiving party intended to use an “AI Tool,” then it “must provide other parties with notice and an opportunity to object; ensure that the AI Tool is used in a secure environment and that Confidential Information is not used to train or improve any AI Tool except one used exclusively in this action; to the extent that an AI Tool is trained or improved using Confidential Information, that information is destroyed at the conclusion of this litigation and is not made accessible to anyone not authorized to have access to Confidential Information; and ensure that all Confidential Information is deleted at the conclusion of this action.”

The Jeffries court explained that: “As a practical matter, these provisions effectively require parties to use only closed or secure AI Tools (‘closed AI Tools’) for Confidential Information.”

At that time, the court wrote that “the parties foreshadowed a broader dispute over the use of AI Tools in connection with all information produced in discovery in this case, not just Confidential Information.” [emphasis in original].

“ROUND 2”: EXPANSION TO ALL “DISCOVERY MATRIALS”

Defendants moved to expand the order to encompass all “Discovery Materials,” defined as “all documents and information produced in discovery.”  The Jeffries court wrote:

Highly summarized, Defendants seek to prevent parties from uploading even non-confidential documents into public or “open loop” generative artificial intelligence tools (collectively, “open AI Tools”).

The court found good cause to do so. First, it cited Fed.R.Civ.P. 26(c), the protective order rule.  It stated that the Rule is highly flexible.

The Jeffries court wrote in part:

Defendants assert that good cause exists for their proposed amendment governing the disclosure of non-confidential materials because the availability and use of AI Tools in litigation “represents a paradigm shift of yet-to-be defined proportions, but what is clear is that the way AI Tools function poses a potential threat to the integrity and security of data produced in litigation.” … Defendants explain that AI Tools rely on sophisticated machine learning models that work by identifying and encoding patterns and relationships in massive amounts of data and then using that information to understand users’ natural language requests or questions and respond with relevant new content. But, unlike closed AI Tools, the use of open AI Tools “risks disclosure, loss of control, and uncertainty concerning the security, storage, and other data-handling of that information.” … Defendants point out that, because an open AI Tool uses the data submitted to it to continually develop and improve the tool, it is “practically impossible” to claw back data later determined to be privileged, or delete data from the open AI Tool at the conclusion of the action (as required by the deletion clause in the Protective Order) because the information was used to train the AI Tool…. Defendants further explain the harm that might result if information cannot be clawed back or deleted—e.g., waiving confidentiality or privilege of information that was inadvertently disclosed without a “confidential” designation; revealing sensitive data or personal information from the AI Tool’s training datasets; and potentially violating counsel’s professional duty to safeguard information relating to representation of a client….  Defendants also point out that wholesale submission of discovery materials to an open AI Tool may violate U.S. data privacy laws and the strict disclosure rules under the European General Data Protection Regulation (“GDPR”), to which defendants Elementis and Philips are subject…. Lastly, Defendants contend that their proposed amendment is necessary to protect against exposure of critical infrastructure and data breach, given that Defendants are part of the chemical sector designated as Critical Infrastructure and vital to national security…. Defendants contend that all of these concerns constitute good cause to amend the protective order.

Plaintiffs responded that defendants were seeking a disfavored “umbrella” protective order, and that it would drive up costs by denying them access to open AI Tools.  They characterized the remaining concerns as speculative, pointing to a failure to provide expert testimony. They also claimed interference with free speech.

The court rejected the “umbrella” argument, writing: “Umbrella protective orders preemptively designate all discovery as protected without any review by either the court or the parties.”  Here, while all discovery materials were covered, parties were pre-screening them for confidentiality.  Therefore, the court held it was not an “umbrella” order.

As to increased costs, the court wrote that plaintiffs offered no support for an increased burden.  Thus, the court could not find an “undue” burden. It continued:

Next, the court turns to Plaintiffs’ contention that Defendants’ proposed amended protective order deprives Plaintiffs of their First Amendment right to use and disseminate nonconfidential discovery materials. Not so. A protective order does not offend the First Amendment when it is entered based on a showing of good cause, is limited to the context of pretrial civil discovery, and does not restrict the dissemination of the information if gained from other sources. Seattle Times Co. v. Rhinehart, 467 U.S. 20, 37 (1984). Here, Defendants’ proposed amended protective order does not prohibit the parties from disseminating non-confidential documents to the public.

Finally, “Plaintiffs point out that Defendants did not submit an affidavit from a cybersecurity expert to back up their claims of risk or to analyze the regulatory framework of the GDPR or provide specific examples….”  Defendants replied that this was an issue of first impression and pointed to documents and policies cited in their motion.  The court concluded:

On balance, Defendants have the better arguments. Plaintiffs never directly address Defendants’ argument that clawing back or deleting data submitted to an open AI Tool is impossible as a practical matter because such data is used to continually develop and improve the tool. Nor do they address Defendants’ argument that the use of an open AI Tool may expose Defendants’ critical infrastructure information to cyber criminals and risk data breach. Instead, they just call the arguments “speculative” and insist that any resulting harm from the information’s disclosure is no greater than if Plaintiffs publicly posted the nonconfidential information on a website, which the current version of the protective order would not prohibit…. But this analogy is not persuasive. The use of widely available AI Tools presents the opportunity for a centralized repository that makes information available to the public at a scale that was not historically available and ignores the very real security risks of public AI Tools, including the inability to effectively claw back information from the AI Tool.

The Jeffries court agreed that the use of AI can provide benefits in ediscovery.  However, it wrote: “But Defendants’ proposal does not foreclose a party from using any AI Tools; it only prohibits using open AI Tools while allowing the use of closed AI Tools—for good reason. The wholesale submission of discovery materials to an open AI Tool for these eDiscovery tasks could expose massive amounts of data. These actions may violate U.S. data privacy laws and the stricter GDPR disclosure rules, which set a high standard for protecting individuals’ information and requires documented consent to be ‘freely given, specific, informed and unambiguous.’ (GDPR Article 4(11).) As Defendants point out, Defendants’ employees, contractors, and correspondents have not consented. Thus, Plaintiffs’ proposal, which proposes only redaction of certain personally identifiable information, does not appear to comply with the strict requirements of the GDPR, including the consent requirement.”

Finally, the court reasoned:

If the court were to allow a party to upload all non-confidential documents and materials produced by another party to an open AI Tool, thereby making all such data amenable to public consumption, parties may err on the side of under-producing potentially responsive documents or seek to make extensive redactions of irrelevant or non-responsive information. Defendants’ proposed amendment allowing the use of closed AI Tools, as opposed to open AI Tools, will facilitate discovery by incentivizing more fulsome document productions.

For more information, please visit Order Prohibiting Upload of Confidential Discovery Documents to Artificial Intelligence (“AI”) (Nov. 3, 2025).

 

Share