Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials

Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials, by Michael D. Berman, E-Discovery LLC.
Image: EDRM.

[EDRM Editor’s Note: The opinions and positions are those of Michael D. Berman.]


In continuing use of protective orders limiting an opponent’s use of discovery materials  in the opponent’s AI system, a consent order was entered by consent in a criminal case as follows:

Restrictions on Use of Artificial Intelligence Tools to Process Disclosure Materials.

 a. “AI tool” means any automated system that uses statistical modeling, machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including but not limited to large language models, generative AI services, or AI-assisted software tools, whether cloud-based or otherwise.

 b. Under no circumstances will any member of the defense team submit Disclosure Material to a publicly accessible AI tool, or any AI tool, that retains and uses submitted data to train models. Such AI tools pose unique risks to the security and integrity of Disclosure Material, given the practical inability to claw back or delete data once it has been incorporated into a model.

 c. With respect to any AI tool used by the defendant, defense counsel must be able to certify that (i) the AI tool will maintain the confidentiality of any Disclosure Material; (ii) the AI tool will not expose any Disclosure Material to third parties not authorized under this Protective Order to receive such materials; (iii) the AI tool will not retain or use any Disclosure Material for model training; and (iv) all Disclosure Material will be removed from the AI tool at the conclusion of this case.

U.S.A. v. Mora, 2026 WL 2058416 (S.D.N.Y. Jul. 16, 2026).

This is no longer front page news. It is becoming standard practice.

One provision appears problematical to me—”the AI tool will not expose any Disclosure Material to third parties not authorized under this Protective Order to receive such materials.”  Given most A.I. privacy policies, that seems an excessively high standard.

Assume that the following day, A exercises its “clawback” rights. How does B return, sequester, or destroy the document on A.I.?

Michael D. Berman, Owner, E-Discovery LLC.

One hypothetical discussed in some of the following blogs and reflected in this order, is the problem of exercising “clawback” rights if material has been uploaded to A.I. 

Assume that A and B have a Fed.R.Evid. 502 non-waiver order and a Fed.R.Civ.P. 26 “clawback” agreement. Assume further that A produces a privileged document to B in discovery.  The next day, B uploads it to consumer-grade AI.  Assume that the following day, A exercises its “clawback” rights. How does B return, sequester, or destroy the document on A.I.?


Assisted by GAI and LLM Technologies per EDRM’s GAI and LLM Policy.

Author

  • Michael Berman

    Michael Berman is a practicing lawyer and an adjunct faculty member at the University of Baltimore School of Law.  He has published extensively, including as the editor-in-chief and a contributing author in “Electronically Stored Information in Maryland Courts” (Maryland State Bar Ass’n. 2020), co-editing two American Bar Association books on electronic discovery, as well as co-authoring law review and other articles regarding electronically stored information (“ESI”).  He has presented widely in venues ranging from local to National events and served as a Court Appointed ESI Discovery Supervisor for ESI Protocol.

    View all posts Owner, E-Discovery LLC