Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials

Example of Stipulated Search Methodology
July 26, 2026
“Ten depositions are too few for this case…. But twenty-seven depositions is too many….”
July 28, 2026

In continuing use of protective orders limiting an opponent’s use of discovery materials  in the opponent’s AI system, a consent order was entered by consent in a criminal case as follows:

Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.

a.  “AI tool” means any automated system that uses statistical modeling, machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.

b.  Under no circumstances will any member of the defense team submit Disclosure Material to a publicly accessible AI tool, or any AI tool, that retains and uses submitted data to train models. Such AI tools pose unique risks to the security and integrity of Disclosure Material, given the practical inability to claw back or delete data once it has been incorporated into a model.

c.  With respect to any AI tool used by the defendant, defense counsel must be able to certify that (i) the AI tool will maintain the confidentiality of any Disclosure Material; (ii) the AI tool will not expose any Disclosure Material to third parties not authorized under this Protective Order to receive such materials; (iii) the AI tool will not retain or use any Disclosure Material for model training; and (iv) all Disclosure Material will be removed from the AI tool at the conclusion of this case.

U.S.A. v. Mora, 2026 WL 2058416 (S.D.N.Y. Jul. 16, 2026).

This is no longer front page news. It is becoming standard practice.

One provision appears problematical to me—”the AI tool will not expose any Disclosure Material to third parties not authorized under this Protective Order to receive such materials.”  Given most A.I. privacy policies, that seems an excessively high standard.

One hypothetical discussed in some of the following blogs and reflected in this order, is the problem of exercising “clawback” rights if material has been uploaded to A.I.

Assume that A and B have a Fed.R.Evid. 502 non-waiver order and a Fed.R.Civ.P. 26 “clawback” agreement. Assume further that A produces a privileged document to B in discovery.  The next day, B uploads it to consumer-grade AI.  Assume that the following day, A exercises its “clawback” rights. How does B return, sequester, or destroy the document on A.I.?

For more information on related orders, please see:

This blog was initially posted on  Electronic Discovery Reference Model.

Share