Site icon eDiscovery Today by Doug Austin

Is There a Double Standard with AI Protective Orders?: eDiscovery Trends

Double Standard

Is there a double standard with AI protective orders? Craig Ball says there is, and he sets out to shed light on the extent of it.

In Craig’s latest post titled (wait for it!) The AI Protective Order Double Standard (available here) he discusses three recent case law rulings – two of them in the same day:

Orechovesky v. BNY Administrative Services, LLC, No. 1:25-cv-08517, 2026 WL 1725149 (S.D.N.Y. June 15, 2026), requires a party receiving protected material to certify that any AI tool used to process it will maintain confidentiality, won’t expose materials to unauthorized third parties, won’t train on inputs, and will allow deletion at the conclusion of the case.

Advertisement

As Craig states: “Sensible requirements. I don’t quarrel with them.” But he adds: “The Court also requires the LLM to operate “within a closed, private, limited, secure universe”—whatever that means—and lists Relativity’s aiR Platform, Westlaw’s CoCounsel, and Gemini for Google Workspace (Enterprise or Business editions) as acceptable, without saying whether those tools exemplify the standard or are simply agreed-upon exceptions to it.”

The second case, Pujas v. BDO USA, P.C., 2026 WL 1724307 (S.D.N.Y. June 15, 2026), goes further: it bars uploading confidential material to any AI tool unless the platform is “enterprise-grade,” backed by a binding agreement prohibiting the provider from using the data for training or product improvement, a so-called DPA, for Data Processing Agreement.

Craig notes: “Enterprise-grade?!? It’s not clear what that means nor is it settled in law; but the notion is gaining traction in CLE panels and proposed orders: the assumption that only expensive, purpose-built legal AI platforms can satisfy requirements that every major consumer AI platform already satisfies. That assumption is wrong on the technology, wrong on the contracts, and wrong on the policy.”

In Morgan v. V2X, Inc., No. 25-cv-01991-SKC-MDB (D. Colo. Mar. 30, 2026), the District of Colorado adopted a similar standard and then candidly recognized, “that practically speaking, and in light of the current state of AI, this provision will (at least for now) bar the parties from using most, if not all, mainstream low-to-no cost AI to process Confidential Information.”

Advertisement

The reason for Craig’s post is this: “If other courts follow uncritically, it will do what every prior technology-gatekeeping effort has done: widen the gap between well-funded litigants and everyone else, while delivering no meaningful improvement in data security.  My hope is that this post will shed light on a distinction without a difference so as to not hinder the use of properly configured, ‘consumer grade’ AI for processing sensitive data.”

Without stealing too much of his thunder, here are a couple of the points he stresses:

Craig also discusses the “Solo Practitioner’s Structural Advantage”, identifies the provisions that courts should refuse to adopt, and the five things that a properly scoped AI provision needs.

When it comes to Craig’s statement of the double standard with AI protective orders, he concludes with this:

“We must not let that happen. Not because security doesn’t matter—it does—but because we can protect discovery materials without building a toll booth that only the well-heeled can pass through. In the ways that matter, the technology is the same. The commitments are the same. The security is the same. The only thing that differs is the price; and price has never been, and should never become, a proxy for diligence.”

Check out his post here for the stuff that I didn’t mention here (which is a lot).

So, what do you think? Do you agree with Craig that there’s a double standard with AI protective orders? Please share any comments you might have or if you’d like to know more about a particular topic.

Image created using DALL-E-3, using the term “well dressed robot lawyer inside a courtroom and a poorly dressed robot lawyer at the door of the courtroom”.

Disclaimer: The views represented herein are exclusively the views of the author, and do not necessarily represent the views held by my employer, my partners or my clients. eDiscovery Today is made available solely for educational purposes to provide general information about general eDiscovery principles and not to provide specific legal advice applicable to any particular circumstance. eDiscovery Today should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.

Exit mobile version