Tags

, , , , ,

I’ve spent forty-odd years watching the discovery process get weaponized—not always to protect legitimate interests, but often to price opponents out of the fight. I’ve seen it with discovery, privacy and security protocols, with TAR disputes and with forensic examination demands that cost more than the case is worth. Every new technology becomes a vector for cost-shifting dressed up as diligence. AI protective orders are the latest iteration, using the same playbook.

Consider two rulings handed down the same day this June in the Southern District of New York. Orechovesky v. BNY Administrative Services, LLC, No. 1:25-cv-08517, 2026 WL 1725149 (S.D.N.Y. June 15, 2026), requires a party receiving protected material to certify that any AI tool used to process it will maintain confidentiality, won’t expose materials to unauthorized third parties, won’t train on inputs, and will allow deletion at the conclusion of the case. Sensible requirements. I don’t quarrel with them. The Court also requires the LLM to operate “within a closed, private, limited, secure universe”—whatever that means—and lists Relativity’s aiR Platform, Westlaw’s CoCounsel, and Gemini for Google Workspace (Enterprise or Business editions) as acceptable, without saying whether those tools exemplify the standard or are simply agreed-upon exceptions to it.

The other, Pujas v. BDO USA, P.C., 2026 WL 1724307 (S.D.N.Y. June 15, 2026), goes further: it bars uploading confidential material to any AI tool unless the platform is “enterprise-grade,” backed by a binding agreement against training or product improvement.

Enterprise-grade?!? Nobody’s defined it, and it’s not settled law—but the notion is gaining traction in CLE panels and proposed orders: that only expensive, purpose-built legal AI platforms can satisfy requirements every major consumer AI platform already satisfies. That’s wrong on the technology, the contracts, and the policy—and courts are already proving my point. In Morgan v. V2X, Inc., No. 25-cv-01991-SKC-MDB (D. Colo. Mar. 30, 2026), the District of Colorado adopted a similar standard, then candidly admitted it will “bar the parties from using most, if not all, mainstream low-to-no cost AI.” If other courts follow uncritically, it will do what every prior technology-gatekeeping effort has done: widen the gap between well-funded litigants and everyone else, with no meaningful gain in security. My hope is that this post helps close that gap, not widen it.

Same Engine, Different Price Tag

Here’s what the legal AI industry doesn’t advertise: legal AI products run on the same handful of foundation models—OpenAI’s GPT series, Anthropic’s Claude, Google’s Gemini—hosted on the same cloud infrastructure. Whether you access a model through a $150,000-a-year legal platform or a $20-a-month ChatGPT Plus or Claude Pro subscription, your data hits the same servers, the same chips, the same security posture at the infrastructure layer.

Legal AI vendors add real value—workflow design, legal-specific prompting, citation checking—but not a different security architecture. The model doesn’t know whether it’s being called by a BigLaw platform or by little ol’ me.

One caveat: default settings aren’t identical across vendors. Anthropic’s consumer plans—Free, Pro, and Max—don’t train on your conversations unless you opt in. OpenAI’s ChatGPT does the opposite, training by default unless you opt out under Data Controls. Both are one click away from where you need them. But “fixable” isn’t “fixed”—a lawyer who assumes parity without checking that box hands opposing counsel the argument this post is written to rebut. If you’re relying on a consumer subscription to satisfy a protective order, flipping that setting is the whole ballgame. One level deeper, at the raw API the legal platforms are built on, both providers have defaulted to no training for years, enterprise contract or not.

When a vendor cites its SOC 2 attestation, contractual commitments, and zero-data-retention processing, it’s describing protections that flow from the foundation model provider’s own policies—which I get too, once I’ve checked the box. The DPA doesn’t cause OpenAI or Anthropic to skip training on your data. It documents a practice they already follow for every API customer, because Fortune 500 clients demanded it and because training on customer data creates liability nobody wants.

The security isn’t in the markup. It’s in the infrastructure. And the base infrastructure is shared.

What the Contracts Actually Say

Compare the enterprise DPAs and the consumer terms of service and you’ll find the same operative commitments: no training, no third-party sharing, deletion on request. The DPA says it in forty pages of indemnification clauses and liability caps; the terms of service say it in four paragraphs. The words that matter are substantively identical.

The DPA adds audit rights, breach notification timelines, and deletion SLAs. Sounds important—until you look closer.

Audit rights exist to be cited in a certification, not exercised. No law firm audits OpenAI’s or Microsoft’s data centers. Real verification comes from the provider’s public SOC 2 report, which I can read as easily as any CISO.

Breach notification would happen regardless of contract—the reputational cost of silence outweighs the cost of disclosure, and the law often requires it anyway. The clause is belt-and-suspenders for something self-interest already guarantees.

Deletion SLAs are genuinely useful, but consumer platforms let you delete a chat, a project, or the whole account. The enterprise customer gets a written confirmation; I get a confirmation screen. Same operation, different paperwork.

I’m not saying the DPA is worthless—I’m saying it’s a contractual enhancement, not a technical one. A protective order that requires a negotiated DPA as a precondition to AI use is asking a solo or small-firm lawyer without existing DPA paper to spend what I’ve seen run $10,000 to $30,000 to produce a document that adds zero technical protection. That’s not proportionality. That’s a tax.

The Backup Hypocrisy

Let’s talk about “removal at conclusion,” where the double standard gets embarrassing.

Look at the return/destroy provision in any standard protective order and you won’t find much about backup media, disaster recovery replicas, or archived email. Courts never carved out exceptions for those things—they never had to.

Here’s what actually happens when a firm must return or destroy discovery materials: someone decommissions the Relativity workspace, but the other data lingers on in nightly backups for 30 to 90 days, in disaster recovery replicas, in email attachments forwarded to associates who’ve since left, in litigation-hold snapshots for unrelated matters. Eventually it evaporates through ordinary retention schedules. Nobody has ever been made to forensically purge that tail, because it doesn’t create the risks protective orders target—it can’t be searched, exploited, or weaponized. Ghosts in the machine, fading on schedule.

A consumer AI platform’s 30-day compliance retention window is akin to backup media: transient, inaccessible, serving a narrow compliance function, expiring on schedule. When I create a dedicated project per matter and delete it at the conclusion of the case, I’ve done exactly what BigLaw does when it decommissions a workspace—only my 30-day tail is shorter and more predictable than their 90-day cycle. If that kind of retention never violated a protective order on an Iron Mountain tape, it doesn’t violate one on an Azure server. Unless the standard is simply that the familiar gets a pass and the novel doesn’t.

The Solo Practitioner’s Structural Advantage

Here’s an irony nobody acknowledges: my solo practice configuration is arguably more secure against unauthorized access than a typical firm’s. Not less.

I don’t share credentials. No paralegal, associate, or contract attorney logs in under my ID. The only person who touches matter-specific data is me, bound by every ethical obligation the profession imposes. A 200-lawyer firm, by contrast, must manage dozens of credentialed users, role-based access controls, the risk that an associate on one case queries another’s materials, laterals who retain cached access, and the grind of deprovisioning departing attorneys. All of that machinery adds complexity—and complexity is where security fails.

I don’t have that problem. My isolation isn’t a workaround. It’s a happy accident, and—no thanks to me—it turns out to be superior to a multi-user deployment.

What Courts Should Reject

Not because security doesn’t matter, but because these provisions don’t deliver it—they deliver cost, and cost without protection isn’t diligence. It’s a barrier to entry.

Mandated “enterprise-grade” platforms. Requiring the same model on the same infrastructure through a pricier wrapper. Ask: what technical characteristic does the mandated tool have that the alternative lacks? If the answer is “a negotiated DPA,” that’s contractual, not technical.

Negotiated DPA requirements. A binding terms-of-service is an enforceable contract of adhesion. No court has ever required parties to negotiate bespoke terms with, say, Relativity before loading discovery materials.

Audit rights as a precondition. Nobody exercises them. The solo practitioner and the BigLaw CISO both rely on the same SOC 2 attestation. Requiring an audit right nobody will use is a line item, not a control.

Blanket cloud-based prohibitions. If third-party infrastructure disqualifies AI, it disqualifies every cloud-hosted review platform and SaaS tool in the litigation stack too. We settled that question years ago; inference doesn’t change it.

Absolute-guarantee certifications. No technology is breach-proof, and we don’t require that certification of Relativity or a court reporter’s laptop. We certify reasonable precautions—the Rule 11 standard should apply here too.

Asymmetric restrictions. If AI is too dangerous for me to use with your client’s documents, it’s too dangerous for you to use with mine. Any restriction should run both ways or not at all.

What Courts Should Require

I’m arguing for proportionality—the same principle Rule 26(b)(1) already applies to every other discovery burden, weighing “the parties’ resources” against “whether the burden or expense… outweighs its likely benefit.” A properly scoped AI provision needs five things:

No training—a binary setting on every platform at every price tier. Know whether yours defaults on or off, and check it.

No public accessibility—authentication required, no cross-session exposure. Every paid tool satisfies this by default.

Matter isolation—materials processed in a defined, deletable container: a project, workspace, or thread.  All users with access must be bound by the protective order.

Deletion at conclusion—the practitioner deletes and certifies. Transient compliance retention gets the same grace we’ve always extended to backup tape.

Documentation—counsel identifies the tool, configuration, and contractual terms. Not a forty-page DPA. Just reasonable proof.

Five requirements, achievable at any budget, protecting against the actual risks—unauthorized use, competitive exploitation, ongoing exposure. Anything more isn’t protecting data. It’s protecting market position.

The Stakes

Our profession’s comfort with any technology follows the same curve: fear, restriction, grudging acceptance, ubiquity. We saw it with email, cloud computing, predictive coding, BYOD—and each time, restrictions born of unfamiliarity fell hardest on practitioners who couldn’t buy their way past the gatekeepers.

AI is the most powerful leveling tool this profession has seen in my career. A solo practitioner with a well-configured tool can now do work that once required a team. That’s not a threat to justice; it’s the promise of it. The small-firm lawyer on a contingency civil rights case, the public defender drowning in discovery, the solo taking on a corporate defendant with unlimited resources—these are the people AI helps most, and the people locked out first when courts set compliance floors calibrated to BigLaw budgets, exactly as the Morgan court admitted its own standard might do.

We must not let that happen—not because security doesn’t matter, but because we can protect discovery materials without building a toll booth only the well-heeled can pass through. The technology is the same. The commitments are the same. The security is the same. Only the price differs, and price has never been—and should never become—a proxy for diligence.

Hat tip to my friend Michael Berman, whose excellent series of posts on AI and discovery law got me thinking about this today.