On March 30, 2026, a magistrate judge in the District of Colorado amended a protective order governing a self-represented plaintiff’s use of material designated Confidential by his former employer. The plaintiff had used artificial intelligence to help prepare his filings. The defendant and the plaintiff proposed different terms. The court rejected both proposals and wrote its own provision:
No party or authorized recipient may input, upload, or submit CONFIDENTIAL Information into any modern artificial intelligence platform, including any generative, analytical, or large language model-based tool (“AI”), unless the AI provider is contractually prohibited from: (1) storing or using inputs to train or improve its model; and (2) disclosing inputs to any third party except where such disclosure is essential to facilitating delivery of the service. Where disclosure to a third party is essential to service delivery, any such third party shall be bound by obligations no less protective than those required by this Order. In addition, the AI provider must contractually afford the party or authorized recipient the ability to remove or delete all CONFIDENTIAL information upon request. A party intending to use AI that it contends meets these requirements must retain written documentation of these contractual protections.[2]
The court identified the practical effect. It observed that the provision “will (at least for now) bar the parties from using most, if not all, mainstream low-to-no-cost AI to process Confidential Information,” because qualifying accounts “may be available only through organizational procurement processes.” A footnote asked the question directly: “how will a pro se litigant or a litigant who cannot afford big-ticket legal services and better AI keep up?”[3]
Three weeks later, a court entered a protective order in the ByHeart infant formula MDL, permitting disclosure of Protected Material to “any mediator who is assigned to hear this action, and his or her staff,” on acknowledgment of the order, and separately forbidding covered persons from putting Protected Material into a generative AI tool unless the tool satisfies three specified conditions.[4] The mediator is therefore an authorized recipient under a court-enforceable order that he or she did not negotiate.
Arbitration presents a related setting with a different enforcement architecture. Counsel commonly craft the confidentiality regime and the tribunal enters it, so the terms arrive by agreement rather than through motion practice, and they are enforced through procedural authority, adverse inference, and cost allocation. A tribunal has no docket of prior orders to consult when a term proves unworkable, and no appellate correction if it does. The AAA-ICDR’s AAAi Standards place privacy and security duties on neutrals, advocates, and administrators, which supply the vocabulary for a functional standard without a vendor contract requirement.[5]
Protective orders have governed the custody of confidential material in third-party hands for as long as parties have hired court reporters. The Northern District of California’s widely copied Model Order (“Northern District Model Order”) requires that Protected Material be stored “in a secure manner that ensures that access is limited to the persons authorized under this Order.” It permits disclosure to Professional Vendors, defined to include entities providing services for “organizing, storing, or retrieving data in any form or medium,” on the condition that they sign an acknowledgment agreeing to be bound and submitting to the court’s jurisdiction. At the end of the case, the Model Order requires return or destruction and a certification that nothing has been retained, but it expressly preserves counsel’s archival copies.[6]
Counsel and their agents regularly send confidential material through commercial email, store it on cloud servers, and run it through hosted review platforms to process it. Some orders require a vendor acknowledgment; others rely on counsel to select and manage authorized vendors. In both forms, the order authorizes custody, requires secure handling, and binds the people subject to it.
The Morgan clause uses a different test. It conditions what the litigant may do on the terms of an agreement with a company that is not before the court and may not make a separately negotiated agreement available to an individual litigant.
This article argues that a provider contract should not be the categorical default and proposes a functional standard in its place. The AI account should bar model training on inputs and outputs; the provider’s ordinary post-deletion retention window should not exceed thirty days; reasonable access and security controls should apply; and the user should delete protected content from the tool when the task is complete, subject to preservation and disclosure obligations. The user should document the configuration and published terms in a dated record. A provider agreement should be required only after a particularized showing and only for material that warrants it.
The argument rests on two findings. First, the proposed standard addresses risks that a protective order can control. It does not use the product tier as a proxy for security. Second, many current AI restrictions began as form paragraphs and orders issued without adversarial testing. A judicial signature gives a term legal force. It does not create a factual record that the parties never presented.
What Protective Orders Have Always Required
A protective order has a defined purpose. In Seattle Times Co. v. Rhinehart, the Supreme Court upheld one against a First Amendment challenge because it rested on good cause, was limited to information gained through discovery, and did not restrict dissemination of the same information obtained elsewhere.[7] A protective order controls material that the court’s process compels into a party’s custody. Fed. R. Civ. P. 26(c) is “highly flexible, having been designed to accommodate all relevant interests as they arise.”[8]
Third-party custody is handled by authorizing the custodian and imposing enforceable safeguards. Under the Northern District Model Order, a litigation support vendor can receive Protected Material only after signing an acknowledgment, agreeing to be bound, and submitting to the court’s jurisdiction, including after the action terminates.[9] Other form orders rely more heavily on counsel’s responsibility for vendors.
Protective orders routinely permit residual retention. The final disposition paragraph of the Model Order requires return or destruction within sixty days and a certification that no copies remain. Then it carves out an archive. Counsel may retain specific case materials “even if such materials contain Protected Material,” subject to the order’s continuing duration.[10] Those copies can remain on the firm’s systems indefinitely, but they remain protected.
Two recent AI orders show the comparison in one instrument. The amended order in Jeffries v. Harcros Chemicals prohibits residual Discovery Materials in an AI tool and, seven paragraphs later, permits counsel to keep an archival copy for record-keeping, appellate rights, professional responsibility compliance, malpractice defense, and regulatory reporting. The protective order in United States v. Allen requires deletion from any AI tool at the conclusion of the case and permits defense counsel to retain the same materials in the case file indefinitely.[11]
Over-designation is already sanctionable. The Northern District Model Order prohibits “[m]ass, indiscriminate, or routinized designations” and exposes the designating party to sanctions for designations made to impose “unnecessary expenses and burdens on other parties.” The burden in a designation challenge rests on the designating party, and the Jeffries and ByHeart orders state the same rule.[12]
Together, these provisions create a coherent scheme. The order authorizes defined recipients, regulates people it can reach, tolerates protected archival copies, and places the burden of justifying additional restriction on the party seeking it.
Now measure the Morgan clause against that system. It conditions use on a nonparty AI provider’s agreement, tolerates no residual copies at all on any timeline, and applies to everything a party designates without a separate showing that the designated material warrants the restriction.
The Line of Orders
The privilege waiver question
On February 10, 2026, two federal judges took up the waiver question and gave opposite answers. Neither seems to have known about the other.
In Warner v. Gilbarco, Inc., Magistrate Judge Patti of the Eastern District of Michigan held that a self-represented plaintiff had not waived work product protection. The plaintiff had used generative AI to process litigation material. The court explained that waiver “has to be a waiver to an adversary or in a way likely to get in an adversary’s hand,” and then described the relevant tools. It described the programs as “tools, not persons, even if they may have administrators somewhere in the background.”[13] The court denied the underlying motion to compel as untimely except in specified respects, and denied the request for the AI materials on the alternative ground that the information sought was not discoverable. Work product was a further ground.
On the same day, in the Southern District of New York, Judge Rakoff ruled from the bench in United States v. Heppner that a criminal defendant’s exchanges with a commercial AI assistant were not attorney-client privileged or protected work product. He issued a written memorandum one week later. The exchanges were communications with a machine not an attorney, and the defendant had created them independently, not at counsel’s direction or through an agent of counsel. The platform’s published privacy policy at the time of the uploads also undermined the asserted confidentiality.[14]
Morgan followed Warner seven weeks later. It distinguished Heppner on two grounds. First, Heppner was a criminal matter. Rule 26(b)(3), by contrast, protects a party’s work product and not only counsel’s work product. Second, Heppner involved a gap between the defendant and his lawyers. That gap has no analogue when the litigant is both the party and the advocate.
In June 2026, a New York justice quashed subpoenas to OpenAI seeking a self-represented defendant’s prompts, inputs, uploads, and outputs used to generate his filings in the action, along with any that referenced the plaintiffs, the entity at issue, the claims and defenses, or filings made for use in the case. The Texas Business Court then followed Warner and Morgan on work product waiver while separately requiring disclosure of discovery materials supplied to ChatGPT and reserving possible protective order violations.[15]
These civil decisions point in one direction. Use of a public AI tool does not by itself waive work product protection. This conclusion does not determine whether the material was work product in the first place, whether attorney-client privilege applies, or whether the upload violated a protective order.
Where the handling restrictions came from
The custodial question has generated more paper than the waiver question. Little of that attention contains judicial reasoning. The same sentences appear in orders from districts that do not cite each other. A small number of form paragraphs have circulated through proposed and stipulated orders, acquiring legal force when courts enter them. The following account traces certain identified clauses. It is not an exhaustive catalog of every AI provision entered by August 2026.
Start with the paragraph that reads sensibly. On September 18, 2025, in Moher v. Zip Co US Inc., Judge Subramanian entered a stipulated protective order in an employment case in the Southern District of New York. Paragraph 16 provides:
The receiving party shall not upload, input, or otherwise provide any documents, data, or information produced in this litigation to any publicly available generative artificial intelligence tool or platform (including, but not limited to, ChatGPT, Bard, Claude, or similar services) unless those tools or platforms can be configured so that the producing party’s information will not train on, learn from, or otherwise incorporate the producing party’s data into its underlying models. Any use of generative artificial intelligence for litigation support must be limited to secure, private tools that do not use the producing party’s information to retrain or improve their systems.[16]
Seven months later a magistrate judge in Stansfield v. Int’l Bus. Machs. Corp. entered a virtually identical provision. Two product names were dropped, one noun was capitalized, and the opening subject was rephrased. From the operative verb onward, nothing changed.[17] Its first sentence states a no-training configuration test. Its second requires that any use “be limited to secure, private tools,” a separate standard the paragraph does not define or reconcile with the first. Repetition carried that internal ambiguity into a second order without adversarial testing.
Defense counsel in Moher was Ogletree Deakins.[18] The same firm represented the defendants in Warner, where on October 30, 2025 Magistrate Judge Patti modified the court’s Rule 26(c) protective order to prohibit any document marked confidential from being uploaded onto any AI platform.[19] The producing party there withheld personnel, investigation, and termination records out of concern about what the self-represented plaintiff would do with them. The flat ban became a condition of production.
The same firm appeared in both matters, but the clauses differ. I do not suggest coordination. The comparison shows that AI handling restrictions had become a defense request in employment cases by autumn 2025. The form of the request depended on the dispute in each case.
A second group of orders imposes more demanding conditions. Two Southern District of New York orders were entered on the same day in June 2026. Both condition AI use on the producing party’s agreement.
Orechovesky v. BNY Administrative Services, LLC prohibits transfer of Discovery Material to an AI platform “without agreement of the Parties.” If the parties agree, the platform must satisfy seven conditions. The phrase “within a closed, private, limited, secure universe including enterprise versions of web-based systems” defines the required environment. The conditions also include certifications such as SOC 2 and ISO/IEC 27001. The order then approves three products by name.
Pujals v. BDO USA, P.C. prohibits upload absent the producing party’s prior written consent or an order of the court. The phrase “an enterprise-grade platform that the receiving Party (or its counsel) has licensed” describes the tool in the exception. The provider must also be subject to a binding agreement that prohibits training use. The clause applies “even where the data or the Confidential Material has been anonymized.” Both orders are stipulated.[20] The same “closed, private, limited, secure universe” phrase appears in one other filing in the district and, two weeks later, in a joint motion in the Northern District of Georgia.[21]
A third family appears across the criminal dockets. Its core paragraph requires prior notice to the government and receipt of the government’s acknowledgment before any AI use, identification of the tool, and certification by defense counsel as to training, third-party exposure, confidentiality measures, and deletion at the conclusion of the case. It closes with a sentence that governs everything before it: “Under no circumstances will any member of the defense team submit Materials to a publicly accessible AI system that retains and uses submitted data to train models.” Then it explains itself, describing such systems as posing “unique risks to the security and integrity of Materials, given the practical inability to claw back or delete data once it has been incorporated into a model.”[22]
That justification sentence appears verbatim across federal criminal dockets in several districts.[23] Each of the located documents entered on the government’s motion or by agreement.
On June 16, 2026 the Northern District of West Virginia adopted the template as a standing order applying to every criminal action filed in the district. It recites the factual premise as a judicial finding, and escalates notice and acknowledgment into a requirement of “prior written consent from the government.”[24]
In re ByHeart is the one instance where the docket records what ordinarily happens off it. On April 16, 2026 the court directed the parties to submit a proposed protective order. On April 22, plaintiffs’ counsel wrote that plaintiffs preferred the court’s own model order and that the defendants had developed their own version, “which Plaintiffs do not agree to.” The defendants filed their competing version the same day, identifying the AI provision as one of three substantive modifications. On April 23, the court entered the defendants’ order:
The Court has received letters from both plaintiffs and defendant ByHeart with dueling protective orders. It isn’t clear that anyone made an effort to meet and confer to reach a resolution, nor does it really seem like there’s a real dispute. Next time, meet and confer and try to work things out. For present purposes, the Court will adopt ByHeart’s proposed order.[25]
The words “The parties agree that individuals or entities with access to Protected Materials are prohibited from inputting” begin paragraph 20. The sentence then prohibits input of Protected Material without three specified protections.[26] But plaintiffs had told the court one day earlier that they did not agree to defendants’ proposed order.
The judge was managing a new MDL and an attorneys’ eyes only dispute. He perceived no material dispute about the proposed orders. For that reason, the recital of agreement remained in the order. This is not a criticism of the judge. It shows how a recital can enter an order without a developed record on the provision.
Two observations follow:
First, a stipulation relocates the problem rather than resolving it. It binds later-added parties, successor counsel, and a litigant who becomes self-represented after counsel withdraws. The records reveal no adversarial testing or express AI-specific good cause findings, yet the resulting term is enforceable in the same manner as one that survived argument.
Second, a party will usually propose a handling standard that it already satisfies. Morgan recognized this dynamic. It found that defendant’s language “appears crafted to fit the precise bounds of Defendant’s contractual engagement with AI providers, resulting in an over-engineered provision that feels vague to Plaintiff.”[27] Orechovesky shows the same dynamic. It approves “Gemini for Google Workspace (Enterprise or Business editions), as integrated within Plaintiff’s counsel’s email and firm communication environment.” The resulting standard can reflect the drafter’s procurement system instead of a neutral risk assessment.
Copying can carry defects forward. The phrase “any modern artificial intelligence platform, including any generative, analytical, or large language model-based tool” defines the scope of one provision. That language reaches Westlaw, Lexis, Microsoft 365, and most current PDF software. A practitioner might violate the text or rely on the order not meaning what it says. Neither result is acceptable in an instrument enforced through contempt.
Another clause prohibits a provider from “storing or using inputs to train or improve its model,” which combines two different functions. The word “storing” by itself nominally requires zero data retention (ZDR). It can also conflict with disclosed legal or safety exceptions. A party facing a contempt motion should not have to guess.
Where somebody argued
Three identified protective order decisions rest on a contested record, and they are among the most measured in the group.
Litton v. Roblox Corp. is the identified refusal. Defendants proposed AI-related edits to the Northern District Model Order. Magistrate Judge Kang declined the edits because the court’s standing order already addressed AI tools. Defendants “did not demonstrate sufficient cause to overcome the presumption of reasonableness and to warrant editing the Model Protective Order to address those same issues.” The ruling permits renewal after a good cause showing at a later discovery phase.[28]
Jeffries v. Harcros Chemicals went the other way on a record the plaintiffs did not build. They opposed on four grounds: that this was a disfavored umbrella protective order, that the restriction would increase their costs, that it burdened their First Amendment right to disseminate non-confidential material, and that the defendants had submitted no cybersecurity expert declaration. What they never did was answer the claw-back premise. They “never directly address” the defendants’ argument that data submitted to an open AI tool cannot practically be retrieved or deleted. They lost the burden argument on the same footing, having “not presented any support for the increased burden, such as by attempting to quantify the extent of any such increased cost.”[29] In March 2026, the magistrate judge extended the restriction from Confidential Information to all Discovery Materials, meaning everything produced in the case whether designated or not.[30]
The lesson is a practice lesson. A party resisting an enterprise-grade requirement must put the vendor terms, the tier availability, and the mechanics of the training election into the record. The plaintiffs in Jeffries did not, and the order that resulted now reaches every document produced.
Morgan is the case where a court chose between competing proposals over objection. It rejected both, wrote its own clause, and then said out loud what the clause would cost. The provision would bar the parties from most mainstream low-to-no-cost AI. Qualifying accounts might be available only through organizational procurement or at a price a self-represented litigant is unlikely to pay. The restriction “disadvantages pro se litigants.” The footnotes quoted at the outset of this article ask how such a litigant is meant to keep up as large firms pour money into enterprise-grade tools, and caution the parties against over-designation.[31]
The docket shows what followed. On April 10, 2026 the defendant filed a notice regarding the plaintiff’s use of AI tools, with three exhibits, which is the filing the order contemplated. On May 14 and 18, the court stayed discovery and appointed counsel to represent the plaintiff on a limited basis for a settlement conference.[32]
Which leaves the question of why Morgan, having looked squarely at the cost, still selected a contractual test. The answer is in the opinion’s own structure. The court held that AI systems collecting user data for training “does not eliminate all expectations of privacy or automatically waive protections.”[33] Six pages later, however, persistent collection reappears as the ground for a categorical restriction: the court “cannot ignore the real risks associated with mainstream tools that persistently collect and store data.”[34] The characteristic the waiver analysis had found insufficient becomes the characteristic that drives the handling term, with no intervening account of how large the risk is or what a contractual prohibition removes from it.
What a Protective Order Can Actually Close
The controllable channels
A handling term reduces the probability that designated material reaches an adversary or the public. The controllable channels are limited, and no single configuration eliminates every route of access or disclosure.
Training and memorization are the risks most distinctive to generative AI, and they are central to many concerns about AI in litigation. A no-training configuration addresses the first of these directly, by preventing the provider’s use of new inputs and outputs for model training or improvement. It does not alter what a model has already learned, and it does not reach stored content, retrieval features, human review, legal process, or a security incident. Anthropic states that deleted consumer conversations ordinarily purge within thirty days. Content already placed in a de-identified training pipeline under a model improvement election may be retained for up to five years.[35]
Retention of live content is addressed by user deletion. For the ChatGPT and Claude products, deleted conversations ordinarily purge from provider systems within thirty days, subject to identified legal, safety, security, and product-specific exceptions.[36]
Persistent memory, project storage, and saved files present additional risks in products that offer those features. Depending on the product and configuration, a stored memory or separately saved file may persist after deletion of the conversation that created or used it.[37]
Those are the channels a protective order can close. The rest it cannot.
Human review for trust and safety can create longer retention. Anthropic states that flagged inputs and outputs may be retained for up to two years and safety classification scores for up to seven, including under specified commercial arrangements. Its ZDR terms preserve limited safety and legal exceptions. Google states that conversations selected for human review may be held for up to three years and are not deleted when the user deletes activity.[38] These exceptions are not unique to AI, but they mean that a thirty-day ordinary deletion window is not an absolute maximum retention limit. Classifiers usually select content based on abuse categories, not commercial sensitivity. Ordinary discovery material may be an unlikely trigger, but the probability is not zero.
Legal process is visible and contestable, and it reaches every custodian. A contractual term does not close it. From May to September 2025, a preservation order in copyright litigation against OpenAI required retention of consumer ChatGPT and API content, including conversations users had deleted and content belonging to users who had opted out of training.[39] Two categories fell outside it. OpenAI has reported that the magistrate judge clarified at a May 27, 2025 hearing that ChatGPT Enterprise was excluded, and that customers using the ZDR API were unaffected because the provider held nothing to preserve. Neither exclusion shows that a contract can bar a court. The first turns on who administers the workspace and the second turns on the absence of a copy.[40]
The baseline the order already accepts
Deleted Gmail sits in Trash for thirty days. In Google Workspace, an administrator can restore the message for a further twenty-five days, after which it is purged unless a retention rule or litigation hold overrides deletion.[41] The comparison shows that ordinary cloud systems also retain deleted content temporarily. It does not make email and generative AI identical: their access controls, provider roles, product features, and contractual protections may differ.
The comparison nevertheless supports a modest proposition. A defined ordinary purge period, combined with no-training, access controls, and user deletion, can reduce residual provider custody to a familiar and manageable risk.
The faulty premise
One factual proposition recurs across orders, and it is false as stated.
In Jeffries, the defendants argued that clawing back or deleting data submitted to an open AI tool “is impossible as a practical matter because such data is used to continually develop and improve the tool.” The court accepted the argument and closed its analysis by finding that the plaintiffs had ignored “the very real security risks of public AI Tools, including the inability to effectively claw back information from the AI Tool.”[42] The criminal template described in Part II carries the same proposition in its own justification sentence, where publicly accessible AI systems are said to pose unique risks “given the practical inability to claw back or delete data once it has been incorporated into a model.”[43]
The premise holds only where the material is in fact used for training or model improvement. Under providers’ no-training configurations, published terms state that inputs and outputs are not used for that purpose, so the model weight concern does not arise in the form asserted. Stored conversation records remain subject to the provider’s retention schedule and disclosed exceptions. A description of one configuration has circulated as a description of the full technology.
The Default Standard
The elements
A default AI provision should impose three conditions on the service and one duty on the user. The account must be configured so the provider does not train on inputs or outputs. The provider’s ordinary post-deletion retention window must not exceed thirty days, subject to disclosed legal and safety exceptions. Reasonable access and security controls must apply. The user must delete protected content from the tool when the task is complete, subject to applicable preservation and disclosure obligations.
Each element addresses the reasonable concerns. No-training addresses model improvement. The thirty-day ordinary window limits residual provider custody. Security controls address unauthorized access and external transmission. User deletion reaches live content, saved files, and stored memories while preserving material that litigation rules require the user to retain elsewhere.
Evidence of each is something a litigant can ordinarily produce without provider cooperation: a dated record of a settings page, the published terms then in force, and a signed certification based on reasonable inquiry. A provider contract can add protections, but it should not be the categorical gateway absent a particularized showing.
The provision
The following language can be adopted or adapted. It is drafted to be entered by stipulation, on motion, or in a procedural order in arbitration. The language is designed to be clear to a litigant without counsel.
AI Tools. For purposes of this Order, “AI Tool” means any hosted service or embedded function that transmits Protected Material outside the Receiving Party’s authorized environment for processing by a machine learning model to generate responsive text, analysis, or other output. The term does not include functionality that processes Protected Material entirely within that authorized environment without transmission to an external model provider. For purposes of this paragraph, the Receiving Party’s “authorized environment” means the devices, networks, and workspaces that the Receiving Party or its counsel owns or administers, together with any vendor or service provider authorized to receive Protected Material under this Order.
Processing of Protected Materials under this paragraph is authorized if the conditions below are satisfied during use:
(a) The Receiving Party must use an account or workspace that prevents provider training and model improvement. The provider must not use inputs or outputs to train, fine-tune, or otherwise improve a model. The provider’s published terms must state these restrictions.
(b) The provider’s published terms must state how long the provider retains content after the user deletes it. That period must not exceed thirty (30) days. The terms must identify any longer retention and the reasons for which such content is retained.
(c) The Receiving Party must use an account or workspace with reasonable technical and organizational safeguards. The safeguards must include, at a minimum, access restriction and authentication. The Receiving Party must disable public sharing and external actions, connectors, or plug-ins. These functions must not transmit Protected Material to an unauthorized recipient.
(d) The Receiving Party must promptly delete each conversation, file, saved artifact, project, and stored memory that contains Protected Material once it completes the related task. If preservation or disclosure duties require retention, the Receiving Party must first export the material to an authorized case repository.
Before first use, the Receiving Party must review the material configuration and published terms. During continuing use, it must repeat the review at least every ninety (90) days.
The Receiving Party must provide a written certification on request of the Producing Party or order of the Court. It must identify any minimum retention period that the Receiving Party’s deletion does not shorten. The certification must be based on reasonable inquiry. It must state that the configured AI Tool satisfied subparagraphs (a) through (d). It must identify the tool, account tier, review date, and published terms. This paragraph does not require a separate provider agreement unless the Court orders heightened protection after a showing of good cause.
If a configuration or published term ceases to satisfy subparagraph (a), (b), or (c), the Receiving Party must stop use. It must not use the AI Tool for Protected Material. It must notify the Producing Party within seven (7) days.
This paragraph applies equally to each Party and each person authorized to receive Protected Material under this Order.
A Party can seek requirements that provide more protection for particular material. The Party must show good cause for the additional requirements. A Party may also seek leave to use an AI Tool that does not satisfy subparagraph (b), on a showing that the material does not warrant exclusion. A Party can also seek relief for a violation of this Order.
What the clause does
The test is functional rather than tiered. Subparagraphs (a) through (d) do not ask what a party paid. A lower-cost account can qualify only if it satisfies every condition. An “enterprise” label does not excuse a noncompliant configuration. That rejects the assumption that tier alone is a reliable proxy for risk.
The definition is also functional. A provision reaching “any modern artificial intelligence platform” can reach a research database, word processor, and PDF reader. Product labels are therefore poor boundaries. The revised definition asks whether the function transmits Protected Material outside the authorized environment, including through an embedded feature. The definition also fixes the boundary by reference to administration rather than ownership.
Subparagraph (d) makes explicit what most entered clauses leave ambiguous. Separate memories, files, artifacts, and project workspaces can persist after conversation deletion, depending on the product and configuration. The preservation qualification is equally important. Prompts and outputs may themselves be discoverable, especially when they form part of an expert’s methodology, so the order should require removal from the provider without directing destruction of material the litigation requires the user to preserve.[44]
Thirty days is not arbitrary. It is a common ordinary post-deletion window in providers’ published terms, the minimum period in Anthropic’s configurable enterprise controls, and the floor that applies to its designated Covered Models.[45] The clause does not describe it as an absolute outside limit, because legal, security, and trust and safety exceptions can last longer. It instead requires those exceptions to be disclosed and confined to their stated purposes.
The certification is based on reasonable inquiry and identifies what must be reviewed. It does the work a protective order is actually able to do, which is to authorize the custody and impose an enforceable obligation on a person before the court. For the default case, a dated configuration record and the published terms can provide the required proof. A contract remains available when particular material warrants additional protection.
The review and notice provisions address a risk a static test cannot address. A provider’s terms can change after material is uploaded, and Heppner shows the importance of the policy in force at the time of use. Periodic review makes the obligation operational, and a duty to notify without a duty to recheck would not.
Reciprocity is necessary because most AI provisions bind only the receiving party. If configured AI processing creates a prohibited risk, the same risk exists regardless of which party uses the tool. The producing party also usually holds more of its own confidential material. Jeffries supports reciprocity. The court relied on the symmetry of the proposed restriction when it found no undue burden.[46] The simplest test of whether a proposed AI restriction is calibrated to risk is to ask the proposing party whether it will accept the same restriction on its own handling of the same documents.
The final sentence preserves the particularized route, because a default that foreclosed heightened protection in a case that warranted it would deserve the resistance it would get.
None of this is far from what some courts are already entering. The closest is In re ByHeart, which asks for confirmation that the tool will not train on Protected Materials or incorporate them into model weights, for administrative controls allowing deletion and preventing unauthorized access, and for adherence to cybersecurity best practices.[47] The proposed provision supplies a retention standard, identifies minimum security functions, and preserves evidence outside the tool when litigation obligations require it.
Why the contractual test should not be the default
One objection might be that a contractual requirement gives more protection. It can. Enterprise agreements may add confidentiality commitments, security standards, subprocessor controls, breach obligations, audit rights, and enforceability. The question is whether that additional paper should be the categorical default for every designation.
Providers commonly publish a thirty-day ordinary deletion period, but the details vary by product. OpenAI separately describes abuse-monitoring logs, application state, and zero or modified retention controls. Anthropic distinguishes consumer chat, commercial chat, API use, files, custom enterprise retention, and safety exceptions.[48] Those differences counsel against treating either a consumer toggle or an enterprise label as conclusive.
A contractual test can exclude litigants without access to organizational procurement, including solo practitioners, small firms, and people proceeding without counsel. Where the asserted risk is training or routine post-deletion retention, a functional test may address it without that exclusion. Where the material requires contractual confidentiality, audit, breach, or subprocessor commitments, a heightened route remains available.
When More Is Warranted
A default is a default. Trade secret and competitively sensitive technical information whose disclosure would be difficult to remedy in damages justifies departure. So does source code, which is conventionally handled under separate and more restrictive terms in any event. So does material subject to independent statutory handling obligations, and the chemical sector infrastructure data at issue in Jeffries is a good illustration, because the showing there was about the material rather than about the tool.[49]
For those categories the response should track the risk rather than the tier. A court or tribunal might require a ZDR arrangement, which ordinarily eliminates provider content storage subject to disclosed safety and legal exceptions. Eligibility for that arrangement depends on the product, endpoint, and model, and at least one provider (Anthropic) now excludes its most capable models from it, so the requirement should be written against the actual feature path rather than the label.
It might require that the material be processed only by software executing on a device the party controls, which is the traditional answer for source code. Or it might require a negotiated agreement containing confidentiality, security, deletion, subprocessor, and breach terms, which is what the Orechovesky and Pujals orders demand of every designation.[50] That is the contractual test in its proper place, applied to material that warrants it.
Two procedural points make the exception workable, and the Northern District Model Order already contains both.[51] The party seeking the heightened requirement bears the burden of showing why the material warrants it, which is the ordinary allocation and which blanket application reverses. The requirement then attaches to a defined subset rather than to everything a party designates.[52]
Conclusion
The civil decisions are converging on work product waiver. Use of a commercial AI platform does not by itself disclose protected work product to an opponent. This conclusion does not decide whether the material was work product when created. It also does not decide privilege or compliance with a protective order.
The custody issue is newer and less settled. Its history did not start with a judicial decision. The earliest clause located here is a paragraph in a stipulated employment order entered in September 2025, and it spread by copying. Provider terms had become the operative metric in these orders months before any court examined a privacy policy in a privilege dispute. The two lines converged on the same measure. In each, the provider’s published terms were the documented source the parties put before the court.
Among the orders identified here, the most burdensome terms usually lack an adversarial record, and the three decisions that rested on a contested record produced the most measured results.[53]
A form clause based on an overbroad premise spread through the located criminal filings. One district then adopted it as a standing order.[54] This pattern should concern anyone who treats Rule 26(c) good cause as a real limit.
The protective order already provides the framework for this issue. It authorizes defined custody. It binds the persons before the court or tribunal. It requires secure handling. It permits additional protection when particular material needs it.
For AI tools, the default should prohibit training and define an ordinary deletion period. It should require reasonable security controls and deletion from the provider, subject to preservation duties. A provider contract remains available when it materially reduces a demonstrated risk. AI is not categorically special. Its risks are functional, and the order should address those functions.
About the Author
[2] Morgan v. V2X, Inc., No. 1:25-cv-01991-SKC-MDB, ECF No. 65, at 14-15 (D. Colo. Mar. 30, 2026) (Dominguez Braswell, M.J.), reported at 2026 WL 864223. The amended protective order was entered the same day.
[3] Id. at 15 & nn.4-5.
[4] In re ByHeart, Inc., Infant Formula Mktg., Sales Pracs., & Prods. Liab. Litig., No. 1:26-md-03178 (AS), ECF No. 45, 7(g), 20 (S.D.N.Y. Apr. 23, 2026) (Subramanian, J.).
[5] AAA-ICDR, AAAi Standards for Use of AI in Alternative Dispute Resolution (May 9, 2025).
[6] N.D. Cal. Model Stipulated Protective Order for Standard Litigation §§ 2.12, 5.1, 7.1, 7.2(e), 13, Ex. A (Feb. 2022).
[7] Seattle Times Co. v. Rhinehart, 467 U.S. 20, 37 (1984).
[8] United States v. Microsoft Corp., 165 F.3d 952, 959 (D.C. Cir. 1999), quoted in Rohrbough v. Harris, 549 F.3d 1313, 1321 (10th Cir. 2008), and in Jeffries v. Harcros Chems., Inc., No. 2:25-cv-02352-KHV-ADM, ECF No. 152, at 3 (D. Kan. Mar. 25, 2026) (Mitchell, M.J.). The Jeffries action is consolidated with Tucker v. Harcros Chemicals, Inc., No. 2:25-cv-02569-KHV-ADM.
[9] N.D. Cal. Model Protective Order §§ 2.12, 7.2(e), Ex. A.
[10] Id. § 13. The Western District of Washington’s model order preserves the same archival right in substantially the same terms, entitling counsel to retain “one archival copy” of court filings, transcripts, correspondence, exhibits, expert reports, and work product “even if such materials contain confidential material.” W.D. Wash. Model Stipulated Protective Order § 10.
[11] Jeffries, ECF No. 153, 8(b), 15 (amended protective order); United States v. Allen, No. 1:24-cr-00454, ECF No. 90, 6, 11 (N.D. Ill. May 28, 2026) (Rowland, J.) (amended protective order entered as to defendant Tyana Hoskins).
[12] N.D. Cal. Model Protective Order § 5.1; Jeffries, ECF No. 153, 10 (“The burden of proving the necessity of a confidentiality designation remains with the party asserting confidentiality.”); ByHeart, ECF No. 45, 21.
[13] Warner v. Gilbarco, Inc., No. 2:24-cv-12333-GAD-APP, ECF No. 94, at 11 (E.D. Mich. Feb. 10, 2026) (Patti, M.J.), reported at 2026 WL 373043. On the substantive standard, the court quoted United States v. Am. Tel. & Tel. Co., 642 F.2d 1285, 1299 (D.C. Cir. 1980) (“while the mere showing of a voluntary disclosure to a third person will generally suffice to show waiver of the attorney-client privilege, it should not suffice in itself for waiver of the work product privilege”), and cited In re Columbia/HCA Healthcare Corp. Billing Pracs. Litig., 293 F.3d 289, 306 n.28 (6th Cir. 2002).
[14] United States v. Heppner, No. 1:25-cr-00503, ECF No. 27 (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.), reported at 2026 WL 436479. The court left a door open, observing that had counsel directed the defendant to use the tool, it “might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege,” citing United States v. Adlman, 68 F.3d 1495, 1498-99 (2d Cir. 1995), and United States v. Kovel, 296 F.2d 918 (2d Cir. 1961).
[15] Morgan, ECF No. 65, at 7-8; Assini v. Hayward, 2026 NY Slip Op 26086 (Sup. Ct., Nassau Cnty. June 4, 2026) (Fischer, J.); Tate Grp. Auto., LLC v. Legacy Auto. Cap., LLC, Cause No. 25-BC11B-0020, minute entry (Tex. Bus. Ct., 11th Div., June 3, 2026) (Dorfman, J.).
[16] Moher v. Zip Co US Inc., No. 1:25-cv-04576-AS, ECF No. 21, 16 (S.D.N.Y. Sept. 18, 2025) (Subramanian, J.) (stipulation and protective order).
[17] Stansfield v. Int’l Bus. Machs. Corp., No. 2:26-cv-00088, ECF No. 16, at 4 (D. Nev. Apr. 16, 2026) (Albregts, M.J.) (stipulated protective order entered subject to the court’s amendments). The Nevada version omits “Bard, Claude” from the parenthetical list, capitalizes “Party,” and replaces “The receiving party” with “Persons receiving Confidential information under this Stipulated Protective Order.” From “shall not upload” onward it is identical to the language quoted in note 16.
[18] Moher, ECF No. 21, at 6 (signature block of Ogletree, Deakins, Nash, Smoak & Stewart, P.C., for defendant).
[19] Warner, ECF No. 66 (E.D. Mich. Oct. 30, 2025) (Patti, M.J.) (order granting in part and denying in part plaintiff’s motion to compel and motion for protective order, and modifying the court’s March 18, 2025 protective order, ECF No. 21). Plaintiff filed a limited objection under Fed. R. Civ. P. 72(a). Warner, ECF No. 70 (Nov. 13, 2025). Counsel of record for the defendants were Richard W. Warren and Lauren Harrington of Ogletree, Deakins, Nash, Smoak & Stewart, PLLC.
[20] Orechovesky v. BNY Admin. Servs., LLC, No. 1:25-cv-08517, ECF No. 18, 15-18 (S.D.N.Y. June 15, 2026) (Garnett, J.); Pujals v. BDO USA, P.C., No. 1:25-cv-01757, ECF No. 85, 10 (S.D.N.Y. June 15, 2026) (Rochon, J.).
[21] Rudasill v. Swiss Re Am. Holding Corp., No. 1:25-cv-01403, ECF No. 102 (S.D.N.Y. May 13, 2026) (Figueredo, M.J.) (confidentiality stipulation and protective order); Baker v. Aspen Specialty Ins. Co., No. 1:26-cv-00163, ECF No. 16 (N.D. Ga. June 1, 2026) (joint motion for protective order), granted, ECF No. 19 (June 2, 2026).
[22] Allen, ECF No. 90, 6. The order was entered “[u]pon the agreed motion of the government, pursuant to Fed. R. Crim. P. 16(d) and 18 U.S.C. § 3771(a)(1) and (8).”
[23] See, e.g., United States v. Brown, No. 1:26-cr-00117, ECF No. 86 (N.D. Ill. May 11, 2026) (Johnston, J.); United States v. Weaver, No. 5:26-cr-00061, ECF No. 25 (E.D. Ky. June 5, 2026) (Stinnett, M.J.); United States v. Govan, No. 2:26-cr-20260, ECF No. 28 (W.D. Tenn. July 6, 2026) (Norris, J.); United States v. Southern Poverty Law Center, Inc., No. 2:26-cr-00139-ECM-KFP, ECF No. 26-1 (M.D. Ala. May 1, 2026) (proposed order filed by the United States).
[24] In re Use of Artificial Intelligence Tools to Review Criminal Discovery, No. 1:26-mc-00038-TSK (N.D.W. Va. June 16, 2026) (Kleeh, C.J.) (standing order).
[25] ByHeart, ECF No. 44 (order granting ECF No. 39, Apr. 23, 2026). The plaintiffs’ letter is at ECF No. 36 and the defendants’ competing submission at ECF No. 39.
[26] ByHeart, ECF No. 45, 20. The three protections are confirmation that the tool will not train the model or incorporate Protected Materials into model weights, administrative controls allowing deletion by the user and preventing unauthorized access, and adherence to cybersecurity best practices.
[27] Morgan, ECF No. 65, at 14; Orechovesky, supra note 20, 17.
[28] Litton v. Roblox Corp., No. 4:25-cv-03088-AMO, Discovery Management Order No. 2, ECF No. 167, at 6-7 (N.D. Cal. May 27, 2026) (Kang, M.J.), citing Wade v. City & Cnty. of San Francisco, No. 25-cv-09623-PHK, 2026 WL 1002049, at *2 (N.D. Cal. Apr. 14, 2026).
[29] Jeffries, ECF No. 152, at 5, 7.
[30] Id. at 1-2, 8; Jeffries, ECF No. 153. The court also found that the proposal was not a disfavored umbrella order because the parties would still screen materials for confidentiality designation, ECF No. 152, at 4-5, a rationale in some tension with the extension of the restriction to all Discovery Materials.
[31] Morgan, ECF No. 65, at 15 & nn.4-5.
[32] Morgan, ECF No. 69 (D. Colo. Apr. 10, 2026) (notice regarding plaintiff’s use of AI tools, with exhibits; the document is not available in the public RECAP archive as of Aug. 13, 2026); id., ECF Nos. 77, 79 (May 14 and 18, 2026) (staying discovery and appointing counsel for limited representation); id., ECF No. 80 (June 12, 2026) (entry of limited appearance).
[33] Morgan, ECF No. 65, at 8-9. The court cited United States v. Warshak, 631 F.3d 266, 268, 285-86 (6th Cir. 2010), United States v. Ackerman, 831 F.3d 1292, 1308 (10th Cir. 2016), and Carpenter v. United States, 585 U.S. 296, 310-16 (2018), while noting that the Fourth Amendment “offers a wholly different legal framework” and that the principle it reflects is informative rather than controlling.
[34] Id. at 15.
[35] Anthropic, How Long Do You Store My Data?, Privacy Center (consumer products, updated July 1, 2026; verified Aug. 3, 2026).
[36] OpenAI, Data Controls FAQ and Chat and File Retention Policies in ChatGPT (Aug. 3, 2026); Anthropic, supra note 35; Anthropic, How Long Do You Store My Organization’s Data?, Privacy Center (Aug. 3, 2026).
[37] OpenAI, supra note 36. Persistence varies by product, feature, and configuration; the statement in text is not intended to describe every account tier or product surface.
[38] Anthropic, supra notes 35-36; Anthropic, I Have a Zero Data Retention Agreement with Anthropic. What Products Does It Apply To?, Privacy Center; Google, Gemini Apps Privacy Hub (Aug. 3, 2026). With Gemini Apps Activity switched off, conversations ordinarily persist for seventy-two hours.
[39] In re OpenAI, Inc., Copyright Infringement Litig., No. 1:25-md-03143 (SHS) (OTW) (S.D.N.Y.) (preservation order entered May 13, 2025 (Wang, M.J.); preservation obligation terminated effective Sept. 26, 2025 by order entered Oct. 9, 2025). The preservation obligation covered ChatGPT Free, Plus, Pro, and Team accounts and API customers without a zero data retention agreement. OpenAI has stated that the magistrate judge clarified at the May 27, 2025 hearing that ChatGPT Enterprise is excluded from preservation, and that business customers using ZDR API were not impacted because the provider retains neither the prompts sent nor the answers returned. See OpenAI, How We’re Responding to The New York Times’ Data Demands in Order to Protect User Privacy.
[40] In re OpenAI, supra note 39, Dkt. Nos. 734 (Nov. 7, 2025) and 910 (Dec. 5, 2025) (Wang, M.J.), objections overruled, Dkt. No. 1021 (Stein, J.). The exclusions described in note 39 did not carry over to the ordered sample.
[41] Google Workspace Admin Help, Delete or Restore a User’s Gmail Message (Aug. 3, 2026). The additional twenty-five day restoration period is a Google Workspace administrator control and does not describe consumer Gmail.
[42] Jeffries, ECF No. 152, at 6-7.
[43] Allen, supra note 11, 6; In re Use of Artificial Intelligence Tools to Review Criminal Discovery, supra note 24.
[44] Conservation Law Found., Inc. v. Shell Oil Co., No. 3:21-cv-00933-VDO, ECF No. 970 (D. Conn. May 18, 2026) (Farrish, M.J.) (ordering production of the prompts used in an expert’s AI-assisted document review; order stayed pending resolution of the objection under Fed. R. Civ. P. 72(a)).
[45] OpenAI, supra note 36; Anthropic, supra notes 35-36; Anthropic, Configure Custom Data Retention Controls for Enterprise Plans (Aug. 3, 2026).
[46] Jeffries, ECF No. 152, at 5 (noting the defendants’ point that the restriction “applies equally to all parties and allows all parties to use Closed AI Tools that meet basic security requirements”).
[47] ByHeart, ECF No. 45, 20.
[48] OpenAI, Data Controls in the OpenAI Platform (describing endpoint-specific abuse-monitoring and application-state retention, zero data retention, and modified abuse monitoring); OpenAI, supra note 36; Anthropic, supra notes 35-36; Anthropic, Data Retention and Deletion, API documentation (Aug. 3, 2026).
[49] Jeffries, ECF No. 152, at 8 (finding the AI-specific risks established “in this particular case” where the documents “come from entities in a critical infrastructure industry and disclosure may violate data privacy laws”).
[50] Orechovesky, supra note 20, 15; Pujals, supra note 20, 10.
[51] N.D. Cal. Model Protective Order §§ 5.1, 6.3.
[52] Morgan, ECF No. 65, at 15 n.4 (cautioning the parties against over-designation).
[53] Litton, supra note 28, at 6-7; Morgan, ECF No. 65, at 14-15. Jeffries is the counterexample, and there the restriction was contested but the record was one-sided. See supra notes 29-30.
[54] In re Use of Artificial Intelligence Tools to Review Criminal Discovery, supra note 24.