Another A.I. Protective Order – Part 10

Maryland’s Digital Media Rules
August 20, 2026

I have been posting about A.I. protective orders since last year.  This is the 10th post.  A.I. protective orders, in one form or another, are becoming the standard of care.

Basically, these orders limit use of artificial intelligence by the recipient of discovery materials.  But, they are not always fair.

Craig Ball has explained that these orders can create a double standard.  He quoted a District of Colorado decision stating “that practically speaking, and in light of the current state of AI, this provision will (at least for now) bar the parties from using most, if not all, mainstream low-to-no cost AI to process Confidential Information.”  Craig added:

If other courts follow uncritically, it will do what every prior technology-gatekeeping effort has done: widen the gap between well-funded litigants and everyone else, while delivering no meaningful improvement in data security.  My hope is that this post will shed light on a distinction without a difference so as to not hinder the use of properly configured, ‘consumer grade’ AI for processing sensitive data.

U.S. v. Dygdon, 2026 WL 2225226 (S.D.N.Y. Aug. 3, 2026), provides another example of an AI  protective order entered by consent in a criminal case.  The materials disclosed in discovery  would affect “the privacy, confidentiality and business interests of individuals and entities,” and “would risk prejudicial pretrial publicity if publicly disseminated….” The consent order states:

  1. Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.

    a.  “AI tool” means any automated system that uses statistical modeling, machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.

    b.  Under no circumstances will any member of the defense team submit Disclosure Materials to a publicly accessible AI tool, or any AI tool, that retains and uses submitted data to train models. Such AI tools pose unique risks to the security and integrity of Disclosure Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.

    c.  With respect to any AI tool used by the defendant, defense counsel must be able to certify that (i) the AI tool(s) will maintain the confidentiality of any Disclosure Materials; (ii) the AI tool(s) will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) the AI tool(s) will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.

I suggest that there is general agreement that a degree of protection of materials produced in discovery is reasonable.  Craig has some excellent suggestions, writing: “I’m not arguing for anarchy or carelessness. I’m arguing for proportionality….”

Craig lists five provisions for a “properly scoped Ai provision….” They are: 1) no training; 2) no public accessibility; 3) matter isolation; 4) deletion at conclusion; and, 5) documentation.  He adds: “Five requirements, all achievable at any budget. All providing genuine protection against the actual risks that protective orders target: unauthorized use, competitive exploitation, and ongoing exposure. Anything beyond this isn’t really protecting data. It’s protecting market position.”

I suggest that AI protective orders are now the standard of care. I agree with Craig’s well-written suggestion that “we can protect discovery materials without building a toll booth that only the well-heeled can pass through.”

I also very much appreciate Craig’s endnote: “Hat tip to my friend Michael Berman, whose frequent and excellent series of posts about AI and discovery law got me thinking about this today.”

For more on this topic, please visit:

This blog was initially posted on  Electronic Discovery Reference Model.

UPDATE:

After the first posting of this blog, an AI protective order was entered by consent in U.S.A. v. Marrow, 2026 WL 2389395 (S.D.N.Y. Aug. 17, 2026).

7. Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.

a. “AI tool” means any automated system that uses machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.

b. The defense team will not submit Disclosure Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The defense team will not submit Disclosure Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data.

c. The defense may submit Disclosure Materials to an AI tool (i) that maintains the confidentiality of Disclosure Materials; (ii) that will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.

Additional consent cases are U.S.A. v. Spatola, 2026 WL 2351459 (S.D.N.Y. Aug. 13, 2026), U.S.A. v. Davis, 2026 WL 1333520 (S.D.N.Y. Aug. 12, 2026).  The protective order in Spatola is the same as Marrow.  The order in Davis states:

Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.

a.  “AI tool” means any automated system that uses statistical modeling, machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.

b. Under no circumstances will any member of the defense team submit Disclosure Materials to a publicly accessible AI tool, or any AI tool, that retains and uses submitted data to train models. Such AI tools pose unique risks to the security and integrity of Disclosure Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.

Share