I have written a series of posts suggesting that AI protective orders are becoming the standard of care. See A.I. Protective Order by Consent in Google Case (Sep. 13, 2026).
The jointly requested A.I. protective order in Hoffman v. Univ. of Nebraska Medical Ctr., 2026 WL 2969621 (D. Neb. Oct. 2, 2026), states:
Artificial Intelligence. Qualified Recipients shall not, without the Producing Party’s express written consent, upload, submit, or otherwise provide Confidential Discovery Material (or any information extracted therefrom) or any deposition testimony taken in this matter to any open-source artificial intelligence platform or service including, but not limited to, platforms or services that use or assemble uploaded information to train or improve machine-learning models. This prohibition applies regardless of whether the artificial intelligence platform or service represents it will maintain the confidentiality of information submitted by the user. The parties and their counsel are not prohibited from uploading, submitting, or otherwise providing Confidential Discovery Material (or information extracted therefrom) or any deposition testimony taken in this matter to a closed-source artificial intelligence platform or service, including Harvey, Westlaw, LexisNexis, Servient’s AI Canvas, or any other closed-source artificial intelligence platform or service agreed to by the parties.
In ANR Pipeline Co., LLC v. B&B Metal Processing Co., Inc., 2026 WL 2970050 (E.D. Wisc. Oct. 2, 2026), the court wrote:
On September 22, 2026, the parties filed a joint motion for the entry of a protective order, with a stipulated proposed order…. The parties request that the Court enter such an order to “prevent public disclosure of nonpublic confidential technical, commercial, or business information that may be exchanged in discovery.” … Federal Rule of Civil Procedure Rule 26(c) allows for an order “to protect a party or person from annoyance, embarrassment, oppression, or undue burden or expense” including “requiring that a trade secret or other confidential research, development, or commercial information … be revealed only in a specified way.” Fed. R. Civ. P. 26(c)(1)(G); see also Civ. L.R. 26(e).
Protective orders are an exception to the general rule that pretrial discovery must occur in the public eye…. Litigation must be conducted in public to the maximum extent consistent with respecting trade secrets … and other facts that should be held in confidence….
Nonetheless, the Court can enter a protective order if the parties have shown good cause and that the order is narrowly tailored to serve that cause…. The Court can find that even broad, blanket orders are narrowly tailored and permissible when it finds that two factors are satisfied: (1) that the parties will act in good faith in designating the portions of the record that should be subject to the protective order; and (2) that the order explicitly allows the parties to the case and other interested members of the public to challenge the sealing of documents….
The Court finds that the parties have requested the protective order in this action in good faith. The parties report that this case will entail the disclosure of confidential technical information about the parties…. Thus, the Court is satisfied that there exists a sufficient basis for the requested protective order. [cleaned up].
However, the court modified the parties’ request to establish parameters for the use of A.I. as it pertains to confidential documents. Id. at *1. The order states:
A receiving party may use AI tools in connection with discovery materials produced in this action only if the AI tool is operated in a secure environment and is subject to enforceable contractual terms that (a) prohibit the provider from retaining, using, disclosing, selling, or using the materials to train, improve, or develop any AI system; (b) prohibit the materials from being made publicly available or accessible to any other customer or third party; and (c) require commercially reasonable administrative, technical, and physical safeguards to protect the confidentiality of the materials. Discovery materials, whether designated CONFIDENTIAL or ATTORNEYS’ EYES ONLY, shall not be entered into any publicly available or consumer-based AI platform. Any use of AI tools must remain consistent with this Order and with the requirement that discovery materials be used solely for purposes of this litigation.
Id. at *5.
A protective order was also entered by consent in U.S.A. v. Amanuel, 2026 WL 2964210 (S.D.N.Y. Oct. 1, 2026):
Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.
a. “AI tool” means any automated system that uses machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.
b. The defense team will not submit Disclosure Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The defense team will not submit Disclosure Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data. Publicly accessible AI tools pose unique risks to the security and integrity of Disclosure Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.
c. The defense may submit Disclosure Materials to an AI tool (i) that maintains the confidentiality of Disclosure Materials; (ii) that will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.
Some prior posts are:
This blog was initially posted on Electronic Discovery Reference Model.
UPDATE:
White v. Chime Financial, Inc., 2026 WL 3000904 (W.D. Wash. Oct. 6, 2026)(stipulated):
USE OF ARTIFICIAL INTELLIGENCE
Should a Party elect to utilize artificial intelligence (“AI”) to assist in reviewing, analyzing, or summarizing discovery material produced or exchanged in this litigation, the Party shall take all necessary steps to ensure that the application, service, or analytical software is fully containerized. “Fully containerized,” as used in this Order, means an AI tool that does not retain the substance of a prompt or documents reviewed, share the substance of a prompt or documents reviewed for training of large language models, or use the substance of a prompt or documents reviewed in any other matter or inquiry other than this litigation. For the avoidance of doubt, this restriction expressly applies to the use of non-containerized advanced large language models (such as publicly available large language models), generative AI tools, and other advanced AI systems, including, but not limited to, OpenAI, Gemini, LLAMA, MidJourney, and Stable Diffusion, but this provision does not limit the use of services leveraging the technology underlying these generative AI tools in a fully containerized environment, including, but not limited to, Copilot Harvey, Relativity aiR, DISCO Cecelia, Everlaw AI, Syllo, Alchemy, Lexis+ AI, Epiq AIDA, Lighthouse AI, Westlaw AI, ChatGPT Enterprise, Microsoft 365 Copilot Enterprise, Claude Enterprise, NotebookLM Pro and Ultra, and Gemini Pro and Ultra. Before submitting any Protected Material to a fully containerized AI tool, a receiving party shall ensure that it (or its vendor) can delete all such Protected Material from the AI tool at the conclusion of this matter, including any derivative information stored within the tool. The obligations and restrictions of this paragraph apply even where the Protected Material has been anonymized.
U.S.A. v. Lockhart, 2026 WL 3003727 (S.D.N.Y. Oct. 6, 2026)(by consent):
Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.
a. “AI tool” means any automated system that uses machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.
b. The defense team will not submit Disclosure Materials to a publicly accessible version of an AI tool (e.g., ChatGPT, Claude, Grok, Gemini, Copilot, Perplexity, Midjourney, Canva). The defense team will not submit Disclosure Materials to an AI tool for which the AI tool provider or vendor (e.g., OpenAI, Anthropic, Microsoft, Google) uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data. Publicly accessible AI tools pose unique risks to the security and integrity of Disclosure Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.
*2 c. The defense may submit Disclosure Materials to an AI tool (i) that maintains the confidentiality of Disclosure Materials; (ii) that will not expose any Disclosure Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Disclosure Materials for model training; and (iv) all Disclosure Materials will be removed from the AI tool(s) at the conclusion of this case.
d. The Government will not submit any materials disclosed by the defense pursuant to Federal Rules of Criminal Procedure 26.2, 32.1 or other defense disclosure obligations (“Defense Materials”) to a publicly accessible version of an AI tool. The Government will not submit Defense Materials to an AI tool for which the AI tool provider or vendor uses submitted data for its own model training, allows submitted data to be publicly accessed, discloses submitted data to third parties, or, except as specified below, retains submitted data.
e. The Government may submit Defense Materials to an AI tool (i) that maintains the confidentiality of Defense Materials; (ii) that will not expose any Defense Materials to third parties not authorized under this Protective Order to receive such materials; (iii) that will not retain or use any Defense Sealed Materials for model training; and (iv) all Defense Materials will be removed from the AI tool(s) at the conclusion of this case.
U.S.A. v. Santos, 2026 WL 3003653 (Oct. 6, 2026)(same, by consent); U.S.A. v. Robinson, 2026 WL 3003677 (Oct. 6, 2026)(same).
U.S.A. v. Peplow, 2026 WL 3026474 (E.D. Cal. Oct. 8, 2026)(stipulation):
Artificial Intelligence Tools
15. No person or entity authorized to have access to protected material under the terms of the requested order shall input, transmit, upload, submit, quote, feed, process, generate output from, or otherwise expose any protected material received pursuant to the requested order to any artificial intelligence (“AI”) tool absent the prior written consent of the government or an order of the Court following a properly noticed motion to which the government has an opportunity to respond, unless that AI tool—a) is an enterprise-grade platform that counsel for the defendant has licensed;
b) is subject to a binding written agreement that (i) requires the provider to keep all user-supplied data strictly confidential, and (ii) expressly prohibits the provider from using such data for training, fine-tuning, product improvement, or any purpose other than providing the contracted-for services; and
c) employs technical and organizational security measures reasonably designed to prevent any unauthorized access, disclosure, or use of protected material.16. The obligations and restrictions of this section apply even where the data or the protected material has been anonymized. “AI tool” means any automated system that uses statistical modeling, machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.
17. By participating in this agreement, counsel for the defendant certifies: (i) they have implemented reasonable measures to ensure, if using any AI tool, it will maintain the protected discovery’s confidentiality as required by this Agreement and (ii) they will ensure all protected discovery is deleted from the tool once this case concludes.
18. Under no circumstances will any member of the defense team submit protected material to a publicly accessible AI system that retains and uses submitted data to train models. Such AI tools pose unique risks to the security and integrity of protected material, given the practical inability to claw back or delete data once it has been incorporated into a model.
U.S.A. v. Sarris, 2026 WL 2937892, at *2 (S.D.N.Y. Sep 30, 2026)(by consent).