← All writing
July 29, 202610 min read#ai#legal-tech#discovery#access-to-justice

AI protective orders are becoming a tax on smaller litigants

Courts should protect discovery with clear, reciprocal security controls, not vague enterprise labels, favored-vendor lists, or DPA requirements that price smaller litigants out of useful AI.

Courts have started writing special protective-order rules for artificial intelligence. Some are sensible. Others are turning ordinary data-security questions into a procurement test that only large firms can pass cheaply.

That is a policy mistake.

Craig Ball made the point well this week. He calls the emerging approach an "AI protective order double standard." I think he is right. A court should care whether discovery material is secure, whether the provider can train on it, who can access it, and whether it can be deleted. It should not care whether the product has the right marketing label or comes with forty pages of enterprise paper.

One boundary matters at the outset. These are discovery-management orders. They govern what parties may do with material produced in particular lawsuits. They do not decide whether a lawyer may use AI with the lawyer's own client information. They do not create a new ethics rule. They do not hold that AI use waives attorney-client privilege or work product.

I wrote about those separate questions in Lawyers, AI agents, and the three things we keep getting wrong. The short version is unchanged: ordinary ethics and waiver doctrine turn on reasonable safeguards, confidentiality, disclosure, and adversary access. A protective order can impose additional rules for protected discovery in one case. That is what a protective order does.

The New York orders

Craig starts with two stipulated protective orders entered on the same day in the Southern District of New York.

In Orechovesky v. BNY Administrative Services, LLC, No. 1:25-cv-08517, ECF No. 18 (S.D.N.Y. June 15, 2026), the parties agreed that a receiving party could not put discovery material into an AI platform without party agreement. An approved tool must avoid training on the produced data, isolate data across users and matters, maintain confidentiality, undergo security testing, encrypt data, meet listed security standards, track access, and purge uploaded data on a schedule or at final disposition.

The order then names Relativity aiR, Westlaw CoCounsel, and Gemini for Google Workspace Enterprise or Business as acceptable tools. Anyone who wants to use something else must disclose the product and verify compliance with part of the security list.

Some of those requirements are perfectly ordinary. Encryption, access controls, matter isolation, non-training, and deletion are real controls. The odd part is the verbal fog around them. The platform must operate in a "closed, private, limited, secure universe." That is not a technical standard. It is a string of reassuring adjectives.

The named-product safe harbor makes the problem worse. A court order should identify the control and let a party prove compliance. It should not create a favored-vendor list. Products change. Terms change. Settings change. A product that met the standard when the order was signed may not meet it six months later, while a cheaper product that does meet the stated controls may remain disfavored because nobody put its brand name into the order.

The second order, Pujals v. BDO USA, P.C., No. 1:25-cv-01757, ECF No. 85 (S.D.N.Y. June 15, 2026), goes further. It allows confidential material to be used only with an "enterprise-grade" licensed platform operating under a binding written agreement that requires confidentiality and bars training, fine-tuning, product improvement, and any use beyond the contracted service. The restriction applies even to anonymized material.

Here the court did not decide a contested technological record. Both are stipulated orders. The parties proposed the terms, and the judges entered them. That makes the language relevant as a sign of where discovery practice is heading, but it does not transform "enterprise-grade" into a judicially tested security category.

The DPA shibboleth

Craig's strongest point concerns data processing agreements.

A DPA can be useful. It may provide audit rights, breach-notification deadlines, deletion commitments, subprocessor terms, and a written promise that customer data will not be used to train or improve models. Those are contractual protections. They can matter.

But the existence of a document called a DPA does not change the chips, the servers, the model, or the network that processes the data. Many legal AI products use the same small group of foundation models and cloud providers used by lower-cost general AI products. The expensive legal wrapper may improve workflow, administration, citation checking, or support. It does not necessarily create a new technical security architecture.

Craig puts it bluntly: a DPA is a contractual enhancement, not a technical one. He says a negotiated DPA can cost a solo or small firm $10,000 to $30,000 when the firm does not already have one. Requiring that paper as the price of using AI can therefore add substantial cost without changing how the data is processed.

I would put the criticism this way: requiring a DPA because its terms supply a protection the order actually needs can be rational. Requiring a document bearing the label "DPA" is dumb. A binding set of standard terms may supply the same operative promises. A DPA with lovely headings may still fail to supply them. Courts should read the terms instead of grading the stationery.

The same problem infects "enterprise-grade." Enterprise is a sales category, not a security protocol. Sometimes it comes with materially better administration and contractual rights. Sometimes it is the same infrastructure with centralized billing and a nicer dashboard. If a court cannot identify the specific protection it means, the phrase does no useful work.

This is where Craig's argument and mine converge. Security should be measured by controls and outcomes. No training. No unauthorized disclosure. Authentication. Matter isolation. Reasonable retention. Deletion. Documented terms. Those are intelligible requirements. "Buy something expensive enough that opposing counsel feels comfortable" is not.

West Virginia shows how the imbalance happens

A new standing order from the Northern District of West Virginia shows the access problem in a sharper form.

The order applies to every criminal action in the district. It says no member of the defense team may use any AI tool with "Sensitive Materials" without prior written consent from the government. The definition of AI reaches systems using statistical modeling or machine learning, whether cloud-based "or otherwise." Defense counsel must identify and describe the tool, certify non-training and limits on third-party access, certify reasonable confidentiality measures, promise deletion at the end of the case, and take responsibility for destruction.

The protected categories include genuinely sensitive material: confidential sources, undercover agents, witness-security information, minors, medical records, tax information, private communications unrelated to the charged conduct, and information about ongoing investigations. Protecting that material is legitimate. The order also excludes material that is public, obtained outside discovery, or pertains solely and directly to the defendant. Those limits are sensible too.

The structure is still lopsided. The government produces the material, designates it sensitive, receives the defense's request, and decides in the first instance whether the defense may use AI to review it. The order imposes no corresponding requirement that the prosecution obtain defense consent before using AI. It does not ask whether the government's own tools satisfy the same controls. It makes one side's adversary the gatekeeper for that side's litigation technology.

That is especially hard to justify in criminal cases, where the government usually has the larger technology budget and the defense often has the greater need for a cheap way to work through a large production. A restriction that lands only on the defense does not preserve a level field. It tilts one that was already tilted.

The order is also broader than its stated threat model. Its opening concern is "data-retentive" or "consumer-tier" AI that allows public systems to retain submissions and train models. Fine. But its operative definition reaches local and otherwise non-cloud software too. A local model that sends nothing anywhere does not present the public-training risk the order invokes, yet defense counsel still needs government permission to use it.

Again, this standing order says nothing about privilege waiver or ordinary legal ethics. It is another protective order governing criminal discovery. Its importance here is policy. It shows how quickly a reasonable concern about public training can grow into a one-sided permission regime covering an entire class of software.

What courts should require

Courts do not need to choose between banning AI and letting lawyers paste discovery into a public chatbot with training enabled. That is a false choice.

A useful AI provision can be short and product-neutral:

  1. The tool may not use protected material to train or improve a model.
  2. The tool must require authentication and prevent access by unauthorized users.
  3. The tool must limit access to the people authorized to see the material. Matter-level isolation should be required only when the protective order, an ethical wall, or another actual confidentiality obligation calls for it.
  4. AI chats and working copies should follow the same retention and destruction rules as other discovery material. If the protective order requires deletion, delete the chats and stored copies, or use zero data retention so the provider stores none in the first place.
  5. Counsel must keep enough documentation to show that the configured tool satisfies the order.
  6. The same rule must apply to every party.
  7. A court must consider proportionality, party resources, and less burdensome alternatives before requiring a particular contract or product tier.

A DPA can prove some of those points. So can binding standard terms, product documentation, a SOC 2 report, a configuration record, or a declaration based on reasonable inquiry. The proof should match the risk. The title on the contract should not decide the issue.

The bytes don't care about the price tag on the API wrapper.

Craig Ball, The AI Protective Order Double Standard

That line gets to the policy failure. Courts are reacting to the novelty of AI rather than the mechanics of the risk. We do not require a solo lawyer to negotiate custom terms with Microsoft before using hosted email. We tolerate ordinary backup cycles when firms certify destruction of protected material. We accept published security attestations for the rest of the litigation stack. AI should not trigger a separate caste system built out of vendor labels.

The people hurt first will be the people who can least afford another compliance tax: solos, small firms, public defenders, civil-rights lawyers, and pro se parties. Those are also the people who stand to gain most from cheap document review, chronology building, deposition preparation, and large-record analysis.

The profession should be trying to make AI easier and safer to use. That means clear controls, reciprocal rules, honest documentation, and consequences for actual misuse. It does not mean a toll booth labeled "enterprise-grade."