AI protective orders are becoming court-ordered staffing restrictions
Restrictive AI orders can dictate a law firm's effective labor inputs. Courts should protect discovery with clear, reciprocal controls, not enterprise labels that kneecap smaller litigants.
Courts have started writing special protective-order rules for artificial intelligence. Some target real security risks. Others use vendor labels and contract forms as proxies for security, steering firms toward enterprise legal chat products and away from customizable agent systems. That choice limits the work a firm can automate, and smaller practices bear the cost first.
That is a policy mistake.
Craig Ball made the point well this week. He calls the emerging approach an "AI protective order double standard." I think he is right. A court should care whether discovery material is secure, whether the provider can train on it, who can access it, and whether it can be deleted. It should not care whether the product has the right marketing label or comes with forty pages of enterprise paper.
One boundary matters at the outset. These are discovery-management orders. They govern what parties may do with material produced in particular lawsuits. They do not decide whether a lawyer may use AI with the lawyer's own client information. They do not create a new ethics rule. They do not hold that AI use waives attorney-client privilege or work product.
I wrote about those separate questions in Lawyers, AI agents, and the three things we keep getting wrong. The ethics question concerns duties to protect client information and make reasonable choices about technology providers. Privilege waiver depends on disclosure, confidentiality, and the provider's role. Work-product waiver generally asks whether the use substantially increased the chance that an adversary would obtain the material. A protective order can impose additional rules for protected discovery in one case. That is what a protective order does.
The New York orders
Craig starts with two stipulated protective orders entered on the same day in the Southern District of New York.
In Orechovesky v. BNY Administrative Services, LLC, No. 1:25-cv-08517, ECF No. 18 (S.D.N.Y. June 15, 2026), the parties agreed that a receiving party could not put confidential discovery material into an AI platform without party agreement. An approved tool must avoid training on the produced data, isolate data across users and matters, maintain confidentiality, undergo security testing, encrypt data, meet listed security standards, track access, and purge uploaded data on a schedule or at final disposition.
The order then names Relativity aiR, Westlaw CoCounsel, and Gemini for Google Workspace Enterprise or Business as acceptable tools. Anyone who wants to use something else must disclose the product and verify compliance with part of the security list.
Some of those requirements are perfectly ordinary. Encryption, access controls, matter isolation, non-training, and deletion are real controls. The odd part is the verbal fog around them. The platform must operate in a "closed, private, limited, secure universe." That is not a technical standard. It is a string of reassuring adjectives.
The named-product safe harbor makes the problem worse. A court order should identify the control and let a party prove compliance. It should not create a favored-vendor list. Products change. Terms change. Settings change. A product that met the standard when the order was signed may not meet it six months later, while a cheaper product that does meet the stated controls may remain disfavored because nobody put its brand name into the order.
The second order, Pujals v. BDO USA, P.C., No. 1:25-cv-01757, ECF No. 85 (S.D.N.Y. June 15, 2026), goes further. Absent the producing party's written consent or a court order, it allows confidential material to be used only with an "enterprise-grade" licensed platform operating under a binding written agreement that requires confidentiality and bars training, fine-tuning, product improvement, and any use beyond the contracted service. The restriction applies even to anonymized material.
Neither judge resolved a contested record about AI security. The parties drafted both New York provisions and submitted them as stipulated orders. Their language shows where discovery practice may be heading, but it does not make "enterprise-grade" a judicially tested security category.
The DPA shibboleth
Craig's strongest point concerns data processing agreements.
A DPA can be useful. It may provide audit rights, breach-notification deadlines, deletion commitments, subprocessor terms, and a written promise that customer data will not be used to train or improve models. Those are contractual protections. They can matter.
But the existence of a document called a DPA does not change the chips, the servers, the model, or the network that processes the data. Many legal AI products use the same small group of foundation models and cloud providers used by lower-cost general AI products. The expensive legal wrapper may improve workflow, administration, citation checking, or support. It does not necessarily create a new technical security architecture.
Craig puts it bluntly: a DPA is a contractual enhancement, not a technical one. He says a negotiated DPA can cost a solo or small firm $10,000 to $30,000 when the firm does not already have one. Requiring that paper as the price of using AI can therefore add substantial cost without changing how the data is processed.
I would put the criticism this way: requiring a DPA because its terms supply a protection the order actually needs can be rational. Requiring a document bearing the label "DPA" is dumb. A binding set of standard terms may supply the same operative promises. A DPA with lovely headings may still fail to supply them. Courts should read the terms instead of grading the stationery.
The same problem infects "enterprise-grade." Craig's point should be the starting point: enterprise describes a sales product. The label makes no privacy or security commitment. Buying the enterprise tier buys whatever protections its terms, configuration, and architecture actually provide. Sometimes that includes materially better administration and contractual rights. Sometimes it is the same infrastructure with centralized billing and a nicer dashboard. If a court cannot identify the specific protection it means, the phrase does no useful work.
Craig's argument and mine converge on the same rule: define the required controls and let parties prove compliance. Vendor labels become more harmful when they determine which kind of AI a firm may use, because that choice affects the firm's capacity to perform the case.
A protective order can become a staffing order
There is a larger problem here. A restrictive AI provision regulates a law firm's labor inputs. Modern agents can review records, maintain chronologies, draft documents, monitor deadlines, and carry work across the separate systems where a firm operates. A rule that confines counsel to a few approved enterprise legal chat products limits which tasks the firm may automate, which systems its software may access, how deeply the software can be adapted to the firm's work, and who controls the stack. The economic effect resembles a staffing restriction even though the regulated input remains software.
In my view, most enterprise legal chat products are expensive wrappers around foundation models that firms can access elsewhere. They add legal templates, document retrieval, administrative controls, and reassuring contracts. Fine. They still lack the deep customization, persistent tool access, and reliable cross-platform action that make an agent useful as part of a law firm's operating system. A legal chatbot can answer questions about a document inside its product. An agent can work through the firm's systems and complete the job.
If the chatbot is the only permissible choice, smaller firms are locked out of a major refashioning of legal labor. A court or opposing party that rejects the firm's actual agent system may remove a substantial part of the capacity the firm expected to use on that case. We would regard that degree of control over a firm's human staffing as extraordinary. Calling the labor input software should not make the interference trivial.
The analogy has a limit. It helps explain the economic effect of the restriction, not the law of waiver. AI remains software even when it performs work once assigned to employees. Courts should not turn the staffing analogy into a claim that the model itself received a client confidence. For privilege, the relevant questions concern disclosure to the provider or other people, the confidentiality restrictions governing that disclosure, and the provider's role. Work-product analysis should ask whether the arrangement materially increased the likelihood of adversary access. The software may perform labor without becoming a legal person.
West Virginia shows how the imbalance happens
The New York examples were party-drafted civil orders. A standing order from the Northern District of West Virginia shows the access problem when a court imposes the rule across an entire category of criminal cases.
The order applies to every criminal action in the district. It says no member of the defense team may use any AI tool with "Sensitive Materials" without prior written consent from the government. The definition of AI reaches systems using statistical modeling or machine learning, whether cloud-based "or otherwise." Defense counsel must identify and describe the tool, certify non-training and limits on third-party access, certify reasonable confidentiality measures, promise deletion at the end of the case, and take responsibility for destruction.
The protected categories include genuinely sensitive material: confidential sources, undercover agents, witness-security information, minors, medical records, tax information, private communications unrelated to the charged conduct, and information about ongoing investigations. Protecting that material is legitimate. The order also excludes material that is public, obtained outside discovery, or pertains solely and directly to the defendant. Those limits are sensible too.
The structure is still lopsided. The government produces the material, designates it sensitive, receives the defense's request, and decides in the first instance whether the defense may use AI to review it. The order imposes no corresponding requirement that the prosecution obtain defense consent before using AI. It does not ask whether the government's own tools satisfy the same controls. It makes one side's adversary the gatekeeper for that side's litigation technology.
That is especially hard to justify in criminal cases, where the government usually has the larger technology budget and the defense often has the greater need for a cheap way to work through a large production. A restriction that lands only on the defense does not preserve a level field. It tilts one that was already tilted.
The order is also broader than its stated threat model. Its opening concern is "data-retentive" or "consumer-tier" AI that allows public systems to retain submissions and train models. Fine. But its operative definition reaches local and otherwise non-cloud software too. A local model that sends nothing anywhere does not present the public-training risk the order invokes, yet defense counsel still needs government permission to use it.
As a discovery-management rule, the standing order shows how quickly a reasonable concern about public training can grow into a one-sided permission regime covering local and other non-cloud software that presents a different risk.
What courts should require
Product-neutral safeguards can keep protected discovery out of training pipelines and unauthorized hands while preserving useful AI access. A workable provision can be short:
- The tool may not use protected material to train or improve a model.
- The tool must require authentication and prevent access by unauthorized users.
- The tool must restrict protected material to authorized users. The order should not demand a separate technical environment for each matter unless the sensitivity of the material or an ethical wall justifies it.
- AI chats and working copies should follow the same retention and destruction rules as other discovery material. If the protective order requires deletion, delete the chats and stored copies, or use zero data retention so the provider stores none in the first place.
- Counsel must keep enough documentation to show that the configured tool satisfies the order.
- The same rule must apply to every party.
- A court must consider proportionality, party resources, and less burdensome alternatives before requiring a particular contract or product tier.
Different evidence proves different controls: contract terms can establish training and retention obligations, configuration records can establish the settings in use, and a properly scoped SOC 2 report can document audited security controls. The required proof should match the claimed risk. The title on the contract should not decide the issue.
The bytes don't care about the price tag on the API wrapper.
That line gets to the policy failure. Courts are reacting to the novelty of AI rather than the mechanics of the risk. We do not require a solo lawyer to negotiate custom terms with Microsoft before using hosted email. We tolerate ordinary backup cycles when firms certify destruction of protected material. We accept published security attestations for the rest of the litigation stack. AI should not trigger a separate caste system built out of vendor labels.
The people hurt first will be the people who can least afford another compliance tax: solos, small firms, public defenders, civil-rights lawyers, and pro se parties. Those are also the people who stand to gain most from cheap document review, chronology building, deposition preparation, and large-record analysis.
The profession should be trying to make AI easier and safer to use. That means clear controls, reciprocal rules, honest documentation, and consequences for actual misuse. A protective order should protect discovery. Designing a law firm's workforce is beyond its proper job.