Double Standard

Is There a Double Standard with AI Protective Orders?: eDiscovery Trends

Is there a double standard with AI protective orders? Craig Ball says there is, and he sets out to shed light on the extent of it.

In Craig’s latest post titled (wait for it!) The AI Protective Order Double Standard (available here) he discusses three recent case law rulings – two of them in the same day:

Orechovesky v. BNY Administrative Services, LLC, No. 1:25-cv-08517, 2026 WL 1725149 (S.D.N.Y. June 15, 2026), requires a party receiving protected material to certify that any AI tool used to process it will maintain confidentiality, won’t expose materials to unauthorized third parties, won’t train on inputs, and will allow deletion at the conclusion of the case.

Advertisement
Veracity Forensics

As Craig states: “Sensible requirements. I don’t quarrel with them.” But he adds: “The Court also requires the LLM to operate “within a closed, private, limited, secure universe”—whatever that means—and lists Relativity’s aiR Platform, Westlaw’s CoCounsel, and Gemini for Google Workspace (Enterprise or Business editions) as acceptable, without saying whether those tools exemplify the standard or are simply agreed-upon exceptions to it.”

The second case, Pujas v. BDO USA, P.C., 2026 WL 1724307 (S.D.N.Y. June 15, 2026), goes further: it bars uploading confidential material to any AI tool unless the platform is “enterprise-grade,” backed by a binding agreement prohibiting the provider from using the data for training or product improvement, a so-called DPA, for Data Processing Agreement.

Craig notes: “Enterprise-grade?!? It’s not clear what that means nor is it settled in law; but the notion is gaining traction in CLE panels and proposed orders: the assumption that only expensive, purpose-built legal AI platforms can satisfy requirements that every major consumer AI platform already satisfies. That assumption is wrong on the technology, wrong on the contracts, and wrong on the policy.”

In Morgan v. V2X, Inc., No. 25-cv-01991-SKC-MDB (D. Colo. Mar. 30, 2026), the District of Colorado adopted a similar standard and then candidly recognized, “that practically speaking, and in light of the current state of AI, this provision will (at least for now) bar the parties from using most, if not all, mainstream low-to-no cost AI to process Confidential Information.”

Advertisement
Lexbe

The reason for Craig’s post is this: “If other courts follow uncritically, it will do what every prior technology-gatekeeping effort has done: widen the gap between well-funded litigants and everyone else, while delivering no meaningful improvement in data security.  My hope is that this post will shed light on a distinction without a difference so as to not hinder the use of properly configured, ‘consumer grade’ AI for processing sensitive data.”

Without stealing too much of his thunder, here are a couple of the points he stresses:

  • “The legal AI industry doesn’t advertise it, but all the legal AI products on the market run on the same small handful of foundation models including OpenAI’s GPT series, Anthropic’s Claude, Google’s Gemini and are hosted on the same cloud infrastructure, like Azure, AWS or Google Cloud. Whether you access that model through a $150,000-per-year legal AI platform or a $20-a-month ChatGPT Plus or Claude Pro subscription, your data hits the same servers, gets processed by the same chips and is governed by the same operational security posture at the infrastructure layer (the actual servers and networks where data is processed).”
  • “Compare the enterprise DPAs and the consumer terms of service, and you’ll find the operative commitments converge: no sharing with third parties, deletion on request, and—for the training question, once you’ve checked the box covered above—no training on inputs either. “The DPA says it in forty pages, dressed up with indemnification clauses and liability caps. The terms of service say it in four paragraphs; but the words that matter are substantively identical.”
  • He also says: “’removal at conclusion,’…is where the double standard gets embarrassing… you won’t find much about backup media, disaster recovery replicas, or archived email. Courts didn’t carve out exceptions for such things because they never had to.”

Craig also discusses the “Solo Practitioner’s Structural Advantage”, identifies the provisions that courts should refuse to adopt, and the five things that a properly scoped AI provision needs.

When it comes to Craig’s statement of the double standard with AI protective orders, he concludes with this:

“We must not let that happen. Not because security doesn’t matter—it does—but because we can protect discovery materials without building a toll booth that only the well-heeled can pass through. In the ways that matter, the technology is the same. The commitments are the same. The security is the same. The only thing that differs is the price; and price has never been, and should never become, a proxy for diligence.”

Check out his post here for the stuff that I didn’t mention here (which is a lot).

So, what do you think? Do you agree with Craig that there’s a double standard with AI protective orders? Please share any comments you might have or if you’d like to know more about a particular topic.

Image created using DALL-E-3, using the term “well dressed robot lawyer inside a courtroom and a poorly dressed robot lawyer at the door of the courtroom”.

Disclaimer: The views represented herein are exclusively the views of the author, and do not necessarily represent the views held by my employer, my partners or my clients. eDiscovery Today is made available solely for educational purposes to provide general information about general eDiscovery principles and not to provide specific legal advice applicable to any particular circumstance. eDiscovery Today should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.


Discover more from eDiscovery Today by Doug Austin

Subscribe to get the latest posts sent to your email.

Leave a Reply