Stepping Up to the Plate: Protective Orders to Restrict AI Training on Produced Data

September 09, 2026

In our previous post in this series, we discussed why using public LLMs to analyze opponents’ document productions is an issue, how the risk for public LLMs differs from other technology platforms, and the balance between the risk of inadvertent disclosure against the potential access to justice benefits of using lower cost AI solutions.

Protective orders are commonly used in litigation to establish clear rules governing the handling, disclosure, and use of confidential or sensitive information exchanged during discovery. By limiting access to authorized individuals and specifying how protected materials must be stored, shared, and ultimately disposed of, protective orders help reduce the risk of unauthorized disclosure while encouraging the exchange of information necessary to resolve the case.

In this post, we’ll discuss entering into protective orders to limit the use of public LLMs on opponents’ sensitive and confidential documents, three recent relevant case law rulings, and two examples of protective order language on which to model your own request.

Restrictions To Be Addressed by An AI Protective Order

Rather than imposing a blanket prohibition on AI, a well-drafted protective order should distinguish between permissible and impermissible uses, recognizing that AI can provide significant efficiencies for tasks such as document review, summarization, organization, and drafting when used responsibly. Any use of AI should remain subject to applicable procedural rules, court orders, and the ethical obligations of counsel, including the duty to supervise technology-assisted work and protect confidential client information.

Closed AI vs. Open AI

A key consideration for protective orders is the distinction between closed AI systems and open AI systems. Closed AI systems that operate within secure environments and are subject to contractual, technical, and administrative safeguards. These protections make them typically appropriate for processing protected information, provided there’s a reasonable basis to conclude that confidential materials will not be used to train models, improve algorithms, or become accessible to unauthorized users.

However, as we discussed in the previous post, the use of public LLMs as open AI systems presents substantially greater risks because information submitted to those platforms may be retained, incorporated into future model development, or otherwise exposed beyond the control of the producing parties. Protective orders should prohibit the disclosure of protected information to any AI platform that cannot provide adequate assurances regarding confidentiality, data segregation, and restrictions on the use of submitted materials for model training.

Responsibilities for Counsel

Protective orders should also establish clear responsibilities for counsel when using AI. Attorneys should remain accountable for verifying the accuracy of AI-generated work product, ensuring that confidential information is handled consistently with the terms of the protective order, and confirming that any AI platform used complies with applicable security and privacy requirements. The use of AI should never diminish an attorney’s obligations under the Federal Rules of Civil Procedure, applicable ethical rules, or court orders governing confidentiality and discovery.

Evolution of AI

Protective orders should also recognize that AI technology continues to evolve rapidly. Instead of referencing specific products or vendors, the order should focus on objective requirements such as security controls, restrictions on model training, access limitations, auditability, and contractual commitments regarding the handling of protected information. By establishing technology-neutral standards, courts can provide flexibility for parties to benefit from future AI innovations while maintaining the confidentiality protections that are essential to the discovery process.

Three Case Law Rulings Involving Protective Orders and AI

We’re seeing an influx of case law rulings that address protective orders for AI use. Here are three notable cases regarding the use of protective orders for their opponent’s use of public AI:

Jeffries v. Harcros Chems. Inc., (D. Kan. Mar. 25, 2026): In this case, Kansas Magistrate Judge Angel Mitchell granted Defendant’s proposal for protective order modifications to extend protection against uploading confidential documents into open generative AI tools to protect against loading any documents and information produced in discovery, rejecting Plaintiffs contention that Defendants’ proposal would drive up Plaintiffs’ costs by denying them access to open AI Tools to analyze “otherwise unprotected discovery materials”.

Litton v. Roblox Corp., (N.D. Cal. May 27, 2026): Here, California Magistrate Judge Peter Kang rejected Defendants proposed changes from the court’s Model Protective Order primarily addressing the use of Confidential/Highly Confidential Information with an AI tool, finding there was a set of provisions addressing AI tools in that Standing Order.

Morgan v. V2X, Inc., (D. Colo. Mar. 30, 2026): Here, both parties proposed competing language as to what extent the protective order should restrict the use of AI, with the defendant advocating for strict limitations and the plaintiff proposing a more flexible, security-focused approach. Colorado Magistrate Judge Maritza Dominguez Braswell rejected both proposals and wrote a balanced provision that restricted uploading confidential documents only. She also ruled that Plaintiff must disclose the name of any AI tool he had already used in connection with Confidential Information.

Notably, all three cases had different outcomes. Still, most cases we’ve seen so far follow the model of the Morgan ruling in terms of limiting the ability to upload confidential documents into a public AI tool.

Two Examples of Model AI Protective Order Language

With more cases involving protective orders for AI usage, there are many examples to choose from. Here are two examples of AI protective order language to consider when modeling your own AI protective orders:

Morgan v. V2X, Inc.

As mentioned above, Judge Braswell wrote a balanced provision that restricted uploading confidential documents to a public AI solution, as follows:

No party or authorized recipient may input, upload, or submit CONFIDENTIAL Information into any modern artificial intelligence platform, including any generative, analytical, or large language model-based tool (“AI”), unless the AI provider is contractually prohibited from: (1) storing or using inputs to train or improve its model; and (2) disclosing inputs to any third party except where such disclosure is essential to facilitating delivery of the service. Where disclosure to a third party is essential to service delivery, any such third party shall be bound by obligations no less protective than those required by this Order. In addition, the AI provider must contractually afford the party or authorized recipient the ability to remove or delete all CONFIDENTIAL information upon request. A party intending to use AI that it contends meets these requirements must retain written documentation of these contractual protections.

RMME LLC v. Majestic Steel USA, Inc.

As noted by Michael Berman in his blog for his site E-Discovery LLC, “Protective orders addressing the use of A.I. to review materials produced to an opponent in discovery are becoming routine.” Here’s an example from the stipulated protective order in the case RMME LLC v. Majestic Steel USA, Inc.:

USE OF ARTIFICIAL INTELLIGENCE

Counsel and the Parties may use artificial intelligence (“AI”) systems—including both closed AI systems and open AI systems—to assist with tasks in this action, such as drafting documents, processing discovery, summarizing materials, organizing information, and conducting document review, provided that all such use complies with Fed. R. Civ. P. 11, the Court’s Standing Order, this Order, and all applicable legal and ethical obligations.

Protected Material may be used with a closed AI system only where the user has a good-faith basis to believe that (i) the system does not use submitted materials to train publicly accessible models, and (ii) access to such materials is restricted in a manner consistent with this Order.

Open AI systems may be used only if such use does not result in the disclosure of Protected Material in violation of this Order and does not violate Section III(4) of Judge Couvillier’s Standing Order, including its prohibition on uploading to any open AI system any document filed under seal or containing personal-data identifiers identified in LR IC 6-1(a)(1)–(6).

For purposes of this section, an “open AI system” means an AI system for which the source code, training data, or underlying models are publicly accessible. A “closed AI system” means any AI system that is not an open AI system and that is subject to contractual, technical, or administrative safeguards reasonably designed to prevent unauthorized access, disclosure, or use of submitted materials, and that does not use Protected Material to train, improve, or refine its models or algorithms or otherwise incorporate Protected Material into outputs generated for other users or matters. [emphasis added].

Conclusion

Given the risks associated with public AI platforms, protective orders that limit the ability of opposing parties to upload sensitive and confidential produced documents into a public AI tool are essential today. But the considerations associated with AI are changing rapidly. It’s important to keep that in mind when drafting your own protective order to protect your organization’s sensitive and confidential data.

Next time, we’ll discuss why meaningful attorney oversight remains central to defensible AI usage and what that entails.

For more regarding Cimplifi specialized expertise regarding AI & machine learning, click here.