I’ve spent forty-odd years watching the discovery process get weaponized, not always to protect legitimate interests, but often to price opponents out of the fight. I’ve seen it with discovery, privacy and security protocols, with TAR disputes and with forensic examination demands that cost more than the case is worth. Every new technology becomes a vector for cost-shifting dressed up as diligence. AI protective orders are the latest iteration, using the same playbook.
Consider two rulings handed down the same day this June in the Southern District of New York. Orechovesky v. BNY Administrative Services, LLC, No. 1:25-cv-08517, 2026 WL 1725149 (S.D.N.Y. June 15, 2026), requires a party receiving protected material to certify that any AI tool used to process it will maintain confidentiality, won’t expose materials to unauthorized third parties, won’t train on inputs, and will allow deletion at the conclusion of the case. Sensible requirements. I don’t quarrel with them. The Court also requires the LLM to operate “within a closed, private, limited, secure universe”—whatever that means—and lists Relativity’s aiR Platform, Westlaw’s CoCounsel, and Gemini for Google Workspace (Enterprise or Business editions) as acceptable, without saying whether those tools exemplify the standard or are simply agreed-upon exceptions to it.
The second case, Pujas v. BDO USA, P.C., 2026 WL 1724307 (S.D.N.Y. June 15, 2026), goes further: it bars uploading confidential material to any AI tool unless the platform is “enterprise-grade,” backed by a binding agreement prohibiting the provider from using the data for training or product improvement, a so-called DPA (for Data Processing Agreement).
Enterprise-grade?!? It’s not clear what that means nor is it settled in law; but the notion is gaining traction in CLE panels and proposed orders: the assumption that only expensive, purpose-built legal AI platforms can satisfy requirements that every major consumer AI platform already satisfies. That assumption is wrong on the technology, wrong on the contracts, and wrong on the policy.
Courts are already proving my point. In Morgan v. V2X, Inc., No. 25-cv-01991-SKC-MDB (D. Colo. Mar. 30, 2026), the District of Colorado adopted a similar standard and then candidly recognized, “that practically speaking, and in light of the current state of AI, this provision will (at least for now) bar the parties from using most, if not all, mainstream low-to-no cost AI to process Confidential Information.” If other courts follow uncritically, it will do what every prior technology-gatekeeping effort has done: widen the gap between well-funded litigants and everyone else, while delivering no meaningful improvement in data security. My hope is that this post will shed light on a distinction without a difference so as to not hinder the use of properly configured, ‘consumer grade’ AI for processing sensitive data.
Same Engine, Different Price Tag
The legal AI industry doesn’t advertise it, but all the legal AI products on the market run on the same small handful of foundation models including OpenAI’s GPT series, Anthropic’s Claude, Google’s Gemini and are hosted on the same cloud infrastructure, like Azure, AWS or Google Cloud. Whether you access that model through a $150,000-per-year legal AI platform or a $20-a-month ChatGPT Plus or Claude Pro subscription, your data hits the same servers, gets processed by the same chips and is governed by the same operational security posture at the infrastructure layer (the actual servers and networks where data is processed).
The legal AI vendors do add value through workflow design, legal-specific prompting, citation checking, integration with document review tools and such; but what the vendors don’t add is a fundamentally different security architecture at the AI. The model doesn’t know whether it’s being called by a BigLaw firm’s bespoke platform or by little ol’ me. The bytes don’t care about the price tag on the Application Programming Interface (API) wrapper.
Certainly, the default security settings aren’t identical across vendors. Anthropic’s consumer plans—Free, Pro, and Max—don’t train on your conversations unless you affirmatively opt in. OpenAI’s consumer ChatGPT does the opposite: it trains on your conversations by default, unless you affirmatively opt out under Data Controls in Settings.
If you’re relying on a consumer subscription to satisfy a protective order, choosing the correct setting isn’t optional housekeeping; it’s the ballgame. For tools accessing the raw API, training the model on client data is not a concern; both Open AI and Anthropic have defaulted to “no training” for years.
When the ‘enterprise grade’ vendor tells you that your data is protected by their SOC 2 Type II attestation (an independent audit confirming security controls are in place and working), contractual commitments, and zero-data-retention processing (meaning your inputs aren’t stored after the response is generated), they’re describing protections that flow from the foundation model provider’s policies. The ‘consumer grade’ user benefits from the same no-training setting and the same underlying infrastructure security — though not from a zero-data-retention agreement, which is a negotiated feature, not a default at any price tier. What a consumer account gets instead is a short, fixed retention window, which I’ll come back to. The vendor’s DPA doesn’t cause OpenAI or Anthropic to not train on inputs. It merely documents a practice those providers already follow for every API customer, because their Fortune 500 clients demand it and because training on customer data creates legal liability they don’t want.
The security isn’t in the markup. It’s in the infrastructure. And the infrastructure is shared.
What the Contracts Actually Say
Compare the enterprise DPAs and the consumer terms of service, and you’ll find the operative commitments converge: no sharing with third parties, deletion on request, and—for the training question, once you’ve checked the box covered above—no training on inputs either. “The DPA says it in forty pages, dressed up with indemnification clauses and liability caps. The terms of service say it in four paragraphs; but the words that matter are substantively identical.
The DPA adds audit rights, breach notification timelines, and deletion SLAs (service-level agreements specifying timelines for action). These sound important, but what do they mean in practice?
Audit rights. No law firm audits OpenAI. No law firm sends a forensic examiner in to audit Microsoft’s data centers. The “audit right” exists to be pointed to in a certification, not to be exercised. It’s a clause that lets a general counsel tell a managing partner that the box is checked. Actual security verification comes from the provider’s SOC 2 report—which is public, and which I can read as easily as any Chief Information Security Officer.
Breach notification. The major providers must notify affected customers of a material breach regardless of contractual obligation, because many laws require it and the reputational cost of silence vastly exceeds the cost of disclosure. The contractual provision is belt-and-suspenders for something the provider’s self-interest already guarantees.
Deletion Service Level Agreements (SLA). Useful, genuinely. But consumer platforms also provide mechanisms to delete a chat or a project, even delete the account, if you open an account dedicated to a matter. The difference is that the enterprise customer gets a written confirmation within a defined timeframe. I get a confirmation screen. Both result in the same outcome at the infrastructure level.
I’m not saying the DPA is worthless. I’m saying it’s a contractual enhancement, not a technical one. And a protective order that requires a negotiated DPA as a precondition to AI use is requiring me to spend what I’ve seen run $10,000 to $30,000 for a solo or small-firm lawyer without existing DPA paper on file to produce a document that adds zero technical protection to discovery materials. That’s not proportionality. That’s a tax.
The Backup Hypocrisy
Let’s talk about “removal at conclusion,” because this is where the double standard gets embarrassing.
Go look at the return/destroy provision in standard protective orders and you won’t find much about backup media, disaster recovery replicas, or archived email. Courts didn’t carve out exceptions for such things because they never had to.
Here’s what happens at a large firm when a protective order requires return or destruction of discovery materials: someone decommissions the Relativity workspace. For old-school networks, the data persists on nightly backups for perhaps 30 to 90 days. It lingers in disaster recovery replicas (duplicate systems kept in case the primary goes down). It sits in email attachments that partners forwarded to associates who have since left the firm. It exists in litigation hold snapshots frozen for unrelated matters. Eventually—weeks or months later—the backup media cycles out, the replicas get overwritten and the data evaporates through the ordinary operation of retention schedules.
Courts didn’t require firms to forensically purge backup media simultaneously with the return/destroy deadline. The profession has long accepted this evaporating ‘digital tail,’ the unspoken understanding that transient, non-accessible, automatically expiring copies that no one will retrieve in the ordinary course will not be purged. Why? Because those copies don’t create the risks that protective orders target. They can’t be readily searched, can’t be exploited competitively, and can’t be weaponized in other litigation. They’re ghosts in the machine, fading away in time.
A consumer AI platform’s 30-day compliance retention window is like that old backup media. The data exists, transiently, in a medium that isn’t accessible to me or anyone else, can’t be queried or searched, serves a narrow compliance function and expires automatically on a defined schedule. When I create a dedicated project for each matter—the AI equivalent of a separate Relativity workspace—and delete that project at the conclusion of the case when a protective order requires that I do so, I’ve done what BigLaw does when it decommissions a workspace. My 30-day tail is shorter and more predictable than their 90-day backup cycle.
If transient, non-accessible, automatically expiring retention didn’t violate a protective order when it lived on an Iron Mountain tape or, now, in a cloud backup, it doesn’t violate one when it lives on an Azure compliance server. Unless the standard is simply: the familiar gets a pass and the novel doesn’t.
The Solo Practitioner’s Structural Advantage
Here’s an irony that never gets acknowledged: my configuration is arguably more secure against unauthorized access than a typical firm deployment. Not less.
I don’t share my credentials. No one else has access to my account. No paralegal, no associate, no contract attorney logs in under my user ID or uses my workspace. When I process protected materials through a matter-specific project, the only human being who touches that data is me, bound by every ethical obligation the profession imposes. There’s a smaller attack surface to manage because there’s no team to manage.
A 200-lawyer firm deploying an enterprise AI platform across its litigation department must contend with dozens of credentialed users, role-based access controls (systems that limit what each user can see based on their assigned role), the ever-present risk that an associate working one case inadvertently queries materials from another, the chance that a lateral hire retains cached access after changing groups, and the unrelenting challenge of deprovisioning departing attorneys. Enterprise platforms address these problems with access control matrices, ethical walls and matter-segregation protocols, all of which add complexity. Complexity is where security fails.
I don’t have that problem. My isolation isn’t a workaround. It’s a happy accident of being solo, and it turns out to be superior to a multi-user deployment.
What Courts Should Reject
With that foundation laid, let me identify the provisions that courts should refuse to adopt—not because security doesn’t matter, but because these provisions don’t deliver real security, just excess cost. And cost without corresponding protection isn’t diligence. It’s a barrier to entry.
Mandated “enterprise-grade” platforms. If a court requires that AI tools be “enterprise-grade” or “specifically designed for legal use,” it’s requiring the same model on the same infrastructure, accessed through a more expensive wrapper. Courts should ask: what specific, technical security characteristic does the mandated tool possess that the alternative lacks? If the answer is “a negotiated DPA,” that’s a contractual characteristic, not a technical one.
Negotiated DPA requirements. A binding terms-of-service is an enforceable contract. It’s a contract of adhesion, sure, but so is every engagement letter a client signs with a litigation support vendor, and I’ve never seen a court require parties to negotiate bespoke terms with Microsoft or Relativity before loading discovery materials. If the operative terms address the substantive requirements of the protective order, the form of the contract shouldn’t matter.
Audit rights as a precondition. No one exercises audit rights over AI infrastructure. The solo practitioner and the BigLaw CISO rely on the same thing: the provider’s SOC 2 attestation and published security architecture. Requiring audit rights that will never be exercised is requiring a line item in a contract, not a security control. It’s meaningless.
Blanket cloud-based prohibitions. If “processed on third-party infrastructure” is disqualifying for AI, it’s equally disqualifying for cloud-hosted document review, cloud-based legal research and every SaaS tool in the modern litigation stack. We decided years ago that cloud infrastructure with proper access controls provides adequate security for confidential materials. That conclusion doesn’t evaporate because the application performs inference rather than keyword search.
Absolute-guarantee certifications. No technology is breach-proof. No one certifies that Relativity will never be hacked, that a court reporter’s laptop is invulnerable, or that a lawyer won’t lose a laptop. We certify that reasonable precautions have been taken. The same standard should apply to AI tools. The formulation should track Rule 11: counsel certifies that, based on reasonable inquiry, the tool as configured satisfies each substantive requirement of the order.
Asymmetric restrictions. If AI is too dangerous for me to use with your client’s documents, it’s too dangerous for you to use with mine. Any AI restriction should apply reciprocally or not at all. Asymmetric technology limitations aren’t protective orders; they’re tactical weapons with a compliance veneer.
What Courts Should Require
I’m not arguing for anarchy or carelessness. I’m arguing for proportionality: the same principle that Federal Rule of Civil Procedure 26(b)(1) already applies to every other discovery burden, considering “the parties’ resources” and “whether the burden or expense of the proposed discovery outweighs its likely benefit.” If proportionality governs what a party must produce, it should equally govern what compliance infrastructure a party must procure to handle what it receives.
A properly scoped AI provision needs five things:
No training. The tool must not use inputs to improve its models. This is a binary setting available on every major platform at every subscription price tier (though as I noted above, on some platforms you switch it on, and on others you switch it off). Know which one you’re using, and check it.
No public accessibility. The tool must require authentication and must not expose one user’s inputs to another’s session. Every paid AI tool satisfies this by default.
Matter isolation. Discovery materials should be processed within a defined container—a project, workspace, or thread—that can be identified and deleted as a unit. This is how competent practitioners work regardless of what the protective order says.
Deletion at conclusion. The practitioner deletes the container and certifies deletion. Transient compliance retention gets the same grace we’ve always extended to backup media because it presents the same negligible risk profile.
Documentation. Counsel should be prepared to identify the tool, the configuration, and the contractual terms that address each requirement. Not a 40-page DPA. Just reasonable proof.
Five requirements, all achievable at any budget. All providing genuine protection against the actual risks that protective orders target: unauthorized use, competitive exploitation, and ongoing exposure. Anything beyond this isn’t really protecting data. It’s protecting market position.
The Stakes
I’ve been doing this long enough to know that our profession’s comfort with any technology follows a predictable curve: fear, restriction, grudging acceptance, ubiquity. We went through it with email, with cloud computing, with predictive coding. Each time, the early restrictions were driven by unfamiliarity rather than genuine risk. Each time, those restrictions disproportionately burdened smaller practitioners who couldn’t afford to buy their way past the gatekeepers.
AI is the most powerful leveling tool the legal profession has seen in my career. A solo practitioner with a well-configured AI tool can now perform work that previously required teams, like document analysis, deposition preparation and legal research at scale. That’s not a threat to justice; that’s the promise of justice. The small-firm lawyer handling a civil rights case on contingency, the public defender drowning in discovery, the solo practitioner taking on a corporate defendant with unlimited resources—these are the people AI helps most. And they’re the people who get locked out first when courts set compliance floors calibrated to BigLaw budgets, exactly as the Morgan court itself admitted its own standard might do.
We must not let that happen. Not because security doesn’t matter—it does—but because we can protect discovery materials without building a toll booth that only the well-heeled can pass through. In the ways that matter, the technology is the same. The commitments are the same. The security is the same. The only thing that differs is the price; and price has never been, and should never become, a proxy for diligence.
Hat tip to my friend Michael Berman, whose frequent and excellent series of posts about AI and discovery law got me thinking about this today.









