Confidential Does Not Mean AI-Proof: Updating Protective Orders for AI

Confidential Does Not Mean AI-Proof: Updating Protective Orders for AI

Artificial intelligence (“AI”) is now a part of routine litigation practice. Lawyers use AI to review productions, summarize medical records, prepare deposition outlines, analyze discovery responses, and organize evidence. The question is no longer whether attorneys will use AI. It is what information will they place into those systems? The next question is what later happens to that information?

These issues matter when discovery includes medical records, personally identifiable information, trade secrets, proprietary business information, financial records, employee data, or large collections of otherwise ordinary documents. The practical risk depends on the AI system’s terms, configuration, retention practices, access controls, and whether the provider can use submitted information for training or other purposes.

The Los Angeles Superior Court’s Stipulation and Protective Order – Confidential Designation Only model protective order, created by the Court in 2011, provides a familiar framework for designating confidential information, limiting recipients, restricting use to the litigation, and returning or destroying protected material. They do not expressly answer a newer question: What AI systems may process discovery, and what may those systems do with the data?[1]

California’s ethical guidance points in the same direction. The State Bar advises lawyers to understand how an AI product collects, uses, stores, and discloses information; to look beyond generalized marketing assurances; and to evaluate security, confidentiality, and data-retention protocols before placing confidential client information into an AI system. A protective order can add a mutually enforceable litigation rule to those existing duties.[2]

 

The Gap Jeffries Exposed

In Jeffries v. Harcros Chemicals Inc. (a 2026 Kansas Federal Court case), an original protective order restricted AI use for information designated as confidential. The defendants later sought to extend those restrictions to all discovery materials, including material not designated as confidential. The Court found good cause to bar the parties from uploading discovery produced by another party into public or ‘open loop’ AI systems, while continuing to permit appropriately secured, closed systems.[3]

Although Jeffries is a Kansas federal case, it highlights an important distinction significant to all courts. A confidentiality designation generally turns on the nature of the information itself. An AI-use restriction can instead turn on how information will be processed, retained, aggregated, reused, or disclosed. A document may not independently qualify as confidential and can still create risk when placed into a system that retains data, uses inputs to improve a model, allows provider access, or makes deletion practically impossible.

Jeffries also exposes a weakness in ordinary clawback provisions. If privileged or sensitive material is inadvertently produced, return or destruction is less meaningful if the receiving party has already submitted the information to a system from which it cannot effectively be retrieved or deleted. The Court also recognized the different scale created by a centralized AI repository, while rejecting the argument that extending AI restrictions to all discovery automatically makes all discovery confidential.[4]

The solution is not to ban AI. Confidential material may be processed within a system that provides appropriate contractual, technical, and organizational safeguards. The distinction is controlled versus uncontrolled processing.

 

Aggregation Changes the Risk

The aggregation problem is amplified by increasingly capable AI tools. Courts, however, do not need to start from scratch. The federal classification system presents a useful analogy: Executive Order 13,526 acknowledges a compilation of individually unclassified items may warrant protection when the information, viewed together, reveals an additional association or relationship independently satisfying classification standards not otherwise apparent from the individual items.[5]

Separate documents identifying employee roles, vendor relationships, facility locations, pricing decisions, customer contacts, or product complaints may appear unremarkable on their own. However, AI can compare those records, identify patterns, reconstruct relationships, and infer business processes or vulnerabilities not stated in any single document. The potential harm may therefore arise from the production as a whole, not merely from each individual page.

 

Building an AI-Inclusive Protective Order

For many cases, the most practical approach may require a hybrid structure: Keep the ordinary confidentiality designations, but add a baseline AI rule applicable to all discovery produced by another party. The order can prohibit submission to open or public systems while permitting systems that satisfy defined safeguards. Particularly sensitive material can remain subject to additional notice, consent, or court-approval procedures.

The proposed order should focus on what a system does rather than on brand names. Subscription tiers, configurations, and vendor terms change. At a minimum, an AI provision should address:

  1. Training and secondary use. Produced material and derived output should not be used to train a generally available model or for advertising, profiling, sale, or unrelated purposes.
  2. Access and security. The system should employ reasonable security and access controls, restrict provider personnel access, and impose equivalent obligations on subprocessors.
  3. Retention and deletion. The order should identify permissible retention periods and require deletion of submitted material and derived output to the extent technically and contractually possible.
  4. Derived information. Summaries, chronologies, extracted data, embeddings, indices, prompts, and other output that reproduce or reveal protected information should remain subject to the order.
  5. Other users. Experts, consultants, investigators, vendors, and other authorized recipients must be subject to the same AI restrictions placed upon counsel.

Redaction can reduce risk, but it should not become an automatic safe harbor. Removing names and account numbers does not necessarily remove confidential substance, proprietary relationships, metadata, or information that becomes identifiable when combined with other records.

 

Takeaway

In our new AI-included world protective orders must address more than who may receive confidential information. They must also address what systems may process discovery, how those systems may use and retain the data, and whether the information can be retrieved or deleted.

The Los Angeles Superior Court model remains a useful foundation. But in cases involving significant personal information, trade secrets, proprietary data, medical records, or large document productions, counsel should consider adding an AI data-handling component to the agreement before the first production. If the restriction applies only to confidential material, say so. If it extends to all discovery, identify the separate good cause supporting a broader protection. In either event, preserve responsible use of AI systems that satisfy defined safeguards.

Once protected information has been submitted to the wrong system, a confidentiality designation may do little to get it back. The time to address such a risk is before the data leaves counsel’s control.

 

 

 

Keep Reading

More by this author

Sources


 

[1] Superior Court of California, County of Los Angeles, Model Stipulation and Protective Order – Confidential Designation Only, https://www.lacourt.org/division/civil/pdf/FormProtectiveOrder1Confidential_1.docx (last visited Aug. 12, 2026).

[2]State Bar of California, Standing Committee on Professional Responsibility and Conduct, Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law 5-6 (2026), https://www.calbar.ca.gov/Portals/0/documents/ethics/Generative-AI-Practical-Guidance.pdf.

[3] Jeffries v. Harcros Chemicals Inc., No. 25-2352-KHV-ADM, 2026 WL 820218, at *1-*2, *4 (D. Kan. Mar. 25, 2026).

[4] Jeffries, 2026 WL 820218, at *2-*4.

[5] Exec. Order No. 13,526, 75 Fed. Reg. 707 (Dec. 29, 2009).