A.I. Protective Order by Consent in Google Case

Indicia of Misuse of A.I. – Courts Need Not “Fish a Gold Coin From a Bucket of Mud”
September 12, 2026
A Request to Serve a Categorical Privilege Log for 8,000 Documents Was Denied
September 14, 2026

The following AI Protective Order was stipulated in Skaf v. Google LLC, 2026 WL 2620563, at *10-11 (S.D.N.Y. Sep. 4, 2026):

Use of Generative Artificial Intelligence Tools and Large Language Models. Protected Material, and all information derived therefrom, shall not be inputted, uploaded, or submitted to any open, publicly accessible or freely available consumer-grade Large Language Model (“LLM”) or Artificial Intelligence (“AI”) tool (collectively, “AI Tools”). Protected Material may only be inputted, uploaded, or submitted to an AI Tool that is enterprise-grade and maintains confidential information using industry standard data security safeguards (“Confidential AI Tool”) after the Receiving Party first ensures that its contract with the AI Provider of the Confidential AI Tool:

(1) Prohibits the AI Provider from storing or using inputs to train, refine, or improve its model;

(2) Prohibits the AI Provider from disclosing inputs, metadata, and any information generated by the Confidential AI Tool to any third party, including integrated third party tools, except where such disclosure is essential to facilitating delivery of the service, in which case that third party shall be bound by obligations no less protective than those required by this Order; and

(3) Permits the Receiving Party to remove or delete the Protected Material, and any information generated by the Confidential AI Tool upon request.

A Receiving Party intending to use a Confidential AI Tool that it contends meets these requirements must retain written documentation of these contractual protections. In addition, the Protected Material, and any information generated by the Confidential AI Tool, including residual information stored in the Confidential AI Tool as a result of the submission of the Protected Material, must be deleted from the Confidential AI Tool at the close of the litigation, and in accordance with the Final Disposition section below. Any inputs, outputs, models, or other artifacts (e.g., embeddings, indexes, or logs) used in or created by a Confidential AI Tool that are derived from or contain Protected Material shall be subject to Section 7.1 and shall not be used for any purpose other than prosecuting or defending this litigation.

For the avoidance of doubt, submitting Protected Material, or excerpts therefrom, to any AI Tool that does not meet the requirements of this section is considered unauthorized disclosure to a third party under Section 10 of this Order. Nothing in this provision shall alter the obligations set forth in Section 1 (“Purposes and Limitations”) and Section 12.9 (“Data Security”) of this Order.

For more information on A.I. Protective Orders, please visit:

UPDATE: “Use of Large Language Model or Generative AI. A Party must not load, upload, input, import, submit, or otherwise transfer Confidential Information, Highly Confidential Information, or Restricted Highly Confidential Information to a publicly accessible Large Language Model (“LLM”) or generative artificial intelligence (“GenAI”) platform. Before using Confidential Information, Highly Confidential Information, or Restricted Highly Confidential Information in any non-publicly accessible LLM or GenAI platform, a Party must ensure that the LLM or GenAI platform cannot and will not utilize Confidential Information, Highly Confidential Information, or Restricted Highly Confidential Information to train public models or otherwise disclose Confidential Information, Highly Confidential Information, or Restricted Highly Confidential Information to other users of the LLM or GenAI platform not authorized to receive such materials.”  U.S.A. v. The New York and Presbyterian Hosp., 2026 WL 2547094, at *5 (S.D.N.Y. Aug. 28, 2026)(Amended Protective Order).

UPDATE: U.S.A. v. Jones, 2026 WL 2607719, at *2 (S.D.N.Y. Sep. 3, 2026).

UPDATE: Doe v. Google LLC, 2026 WL 2584519 (N.D. Cal. Sep. 1, 2026):

Any person in possession of Protected Material will maintain appropriate administrative, technical, and organizational safeguards (“Safeguards”) that protect the security and privacy of Protected Material, including restrictions regarding the disclosure or use of Protected Material in any large language models or any artificial intelligence services. The Safeguards will meet relevant industry standards and limit the collection, storage, disclosure, use of, or access to Protected Material solely to personnel and purposes authorized by this Order. As part of these Safeguards, each person will use a secure transfer method for all transfers or communication of Protected Material, and take reasonable measures to password protect and encrypt Protected Material. Each person will ensure that anyone acting on that person’s behalf is subject to the Safeguards or otherwise provides equivalent or greater protections for the security and privacy of Protected Material. [emphasis added].

“Such restrictions shall, at a minimum, prohibit the disclosure or use of Protected Material in any large language models or artificial intelligence services that are accessible to the public or will capture entered data in order to train what is accessible by the public.”

 

 

Share