The following Stipulated Protective Order was entered in Rapacon v. Abbott Laboratories, 2026 WL 2722543 (N.D. Cal. Sep. 15, 2026):
USE OF GENERATIVE AI TOOLS
“CONFIDENTIAL” Information or Items shall not be submitted to any Open Generative AI tool (e.g., Chat GPT) or any substantially similar tool that is available to the public. Providing “CONFIDENTIAL” Information or Items to an Open Generative AI tool is considered disclosure to a third party. For purposes of this Protective Order, “Open Generative AI tool” means an artificial intelligence system that may be accessed by the public, or that allows for the underlying code and materials to be accessed by the public.
The Parties may only submit “CONFIDENTIAL” Information or Items to a Permitted Generative AI Tool. For purposes of this Protective Order, a “Permitted Generative AI Tool” includes the use of enterprise AI tools that: (i) restrict access to authorized users; (ii) do not use customer data to train, refine, fine-tune, or improve publicly available models; (iii) provide reasonable retention and deletion controls; and (iv) maintain commercially reasonable security and confidentiality protections. For the avoidance of doubt, enterprise legal and productivity platforms that satisfy the foregoing requirements, including Thomson Reuters CoCounsel, Microsoft 365 Copilot, and similar enterprise tools, are permitted.
For more information on A.I. Protective Orders, please visit:
UPDATE: ZL Technologies, Inc. v. KLDiscovery Ontrack, LLC, 2026 WL 2731631, at *9 (S.D.N.Y. Sep. 16, 2026):
Use of Artificial Intelligence Tools
(a) Scope: To protect the confidentiality and security of all information disclosed or produced in this proceeding (“Discovery Information”), any Party receiving Discovery Information from another Party (“Receiving Party”) shall comply with the following requirements governing the use of artificial intelligence (“AI”) tools with such information.
(b) Permitted AI Use: A Receiving Party may use AI tools to process Discovery Information solely for purposes of this proceeding, provided that the AI tool and its use collectively satisfy all of the following requirements:
i. Restricted, Enterprise Environment: The AI tool is used pursuant to a written enterprise or professional agreement and is deployed within a secure, access-controlled environment.
ii. No Model Training or External Use: Discovery Information is not used to train, fine-tune, improve, develop, benchmark, or otherwise contribute to any AI model or service accessible outside the Receiving Party’s environment, except to the limited extent necessary to provide the requested functionality for this proceeding.
iii. Data Retention and Deletion: Within 30 days after final disposition of this action, Discovery Information retained by the AI tool shall be destroyed or caused to be destroyed to the extent reasonably possible.
iv. Security Safeguards: The AI tool is subject to technical and contractual safeguards reasonably designed to protect Discovery Information against unauthorized access, use, or disclosure, including encryption in transit and at rest and appropriate access controls.
(c) No Backdoor Access: Nothing in Section 23 permits a Party, Agent, Expert, or other person that is not able to access Confidential Discovery Information or Highly Confidential – Attorneys’ Eyes Only Information under this Order to use AI tools to query, analyze, search or otherwise process such information.
(d) Responsibility and Attribution: Each Receiving Party is responsible for compliance with this Order by its counsel, experts, consultants, vendors, or other agents using AI tools on its behalf.
(e) Attorney Work Product: Use of an AI tool shall not waive or diminish any applicable privilege or work-product protection, and prompts, instructions, workflows, chat histories, and outputs shall be treated the same as analogous attorney work product created without the use of AI tools.
UPDATE: U.S. v. Perez-Feliz, 2026 WL 2754823 (S.D.N.Y. Sep. 17, 2026)(consent order):
Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.
a. “AI tool” means any automated system that uses machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.
b. The defense team will not submit Disclosure Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The defense team will not submit Disclosure Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data.
c. The defense may submit Disclosure Materials to an AI tool (i) that maintains the confidentiality of Disclosure Materials; (ii) that will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.
UPDATE: U.S. v. Montes, 2026 WL 2824059, at *1 (S.D.N.Y. Sep. 21, 2026)(by consent); U.S. v. Hawkins 2026 WL 2825014, at *2 (S.D.N.Y. Sep. 21, 20260(same).
a. “AI tool” means any automated system that uses machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.
b. The defense team will not submit Disclosure Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The defense team will not submit Disclosure Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data. Publicly accessible AI tools pose unique risks to the security and integrity of Disclosure Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.
c. The defense may submit Disclosure Materials to an AI tool (i) that maintains the confidentiality of Disclosure Materials; (ii) that will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.
d. No person or entity authorized to have access to Disclosure Materials under the terms of this Order shall input, transmit, upload, process, generate output from, or otherwise expose any Disclosure Materials received pursuant to this Protective Order to any AI tool without prior written notice to, and corresponding receipt of acknowledgement from, the Government.
UPDATE: U.S.A. v Amanuel, 2026 WL 2972618 (S.D.N.Y. Oct. 2, 2026)(by consent).
Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.
a. “AI tool” means any automated system that uses machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.
b. The defense team will not submit Disclosure Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The defense team will not submit Disclosure Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data. Publicly accessible AI tools pose unique risks to the security and integrity of Disclosure Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.
c. The defense may submit Disclosure Materials to an AI tool (i) that maintains the confidentiality of Disclosure Materials; (ii) that will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.
d. The Government will not submit Defense Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The Government will not submit Defense Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data.
e. The Government may submit Defense Materials to an AI tool (i) that maintains the confidentiality of Defense Materials; (ii) that will not expose any Defense Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Defense Sealed Materials for model training; and (iv) all Defense Materials will be removed from the AI tool(s) at the conclusion of this case.