Home › Insights › Protective Orders Will Need a Vector-Index Destruction Clause by 2027

Protective Orders Will Need a Vector-Index Destruction Clause by 2027

Attorney

Quick Answer

Treat AI embeddings, chunk text and retrieval logs as copies: delete them when a protective order ends, and keep an itemized deletion log, because a certificate alone cannot prove vectors are gone.

Standard return-or-destroy language was written before AI review. It speaks of copies and names none of the stores a review tool builds. I expect orders to start naming them. Until they do, the cheaper review that AI makes possible is only as safe as the record showing what the tool kept, and when it let go.

Did this answer your question?

Key Points

  • Treat embeddings, chunk text and retrieval logs as copies when a protective order ends, and keep an index-level deletion record, because a certificate alone cannot prove vectors are gone.
  • In Morgan v. V2X (March 30, 2026), the District of Colorado kept Confidential material out of AI platforms unless the provider is contractually forbidden to train on or share it.
  • King & Spalding counted at least five federal district courts that issued or analyzed generative AI restrictions in protective orders between 2025 and early 2026.
Three things litigators believe about AI deletion. Myth or fact?
Call each one, then see how other readers called it.
1 A standard return-or-destroy certificate already accounts for everything an AI tool stored.
2 Some orders already require deletion from the AI tool itself when the case ends.
3 A firm-wide AI policy is enough to satisfy a destruction clause.
Attorney's desk at matter close with an unsigned certificate, a closed laptop and a box of returned exhibits, a server rack visible through the glass behind

The paper copies go back in the box. The derived copies stay on the server until someone can show they are gone.

Move first-pass review to AI, then plan for disposal before the first upload. The savings hold only if the firm can later show where the data went and that it is gone.

Most buyers ask the cost question first. They compare Relativity with other platforms, ask which eDiscovery companies suit a law firm their size, and price a review per matter. Rarely does anyone ask the vendor what the tool will be able to prove when the case ends, which seems to me the question on which the savings quietly depend.

The courts have started asking it for them. In 2025, two federal criminal cases in the Western District of Washington, United States v. Jackson and United States v. Navarro Hernandez, barred loading Protected Material into any AI tool, "generative or not," where a party not bound by the order keeps data rights. Fiorito v. Metropolitan Council, in the District of Minnesota, went further and banned uploading Confidential Data to any generative AI platform. A 2026 law-firm alert surveying these orders concluded that AI-specific provisions are no longer optional.

None of this makes AI review a bad bargain. It changes what the bargain includes. The same AI for Lawyers series that asked how data is disposed of placed a data inventory audit and data flow mapping among its steps, ahead of any tool being switched on. A firm that has mapped where the chunks, embeddings and logs will live can answer a destruction clause; a firm that has not is signing on faith.

What follows is the clause I would ask for, and the record that would let someone sign it honestly.

A matter ends, and someone at the firm signs a certificate saying every copy of the other side's documents has been returned or destroyed. The signature takes a second. If an AI review tool touched those documents, the safer reading is that its embeddings must go too, though none of the orders discussed here uses the word. An embedding is a list of numbers standing in for the meaning of a passage. The tool keeps one for every chunk it cut from an exhibit, filed beside metadata naming the source, page number and document type.

My forecast is narrower. By the end of 2027, AI protective orders will routinely name embeddings and retrieval logs in their return-or-destroy clauses, because no one can check a certificate against vectors that cannot be read. Only an index-level deletion log gives the signature something to rest on.

The worry predates the orders. In February 2025, Amy Swaner, writing on the AI for Lawyers Substack, set out "six critical steps" for a firm to take before deploying generative AI, and the first asked, among other baseline questions, "How is data monitored and disposed of?" She framed it as governance, a firm's private housekeeping. In 2026 the Sixth Circuit, in United States v. Farris, took up attorneys' ethical obligations when using AI, and the housekeeping began to look like duty.

One thing the record does not settle is time. None of the sources gathered here says how long it takes to purge a matter's index and its backups, and I would rather leave that blank than guess.

So the place to start is Colorado, where a court wrote its own AI clause after rejecting both sides' drafts.

What Does the Morgan Clause Require of an AI Tool?

Morgan v. V2X bars Confidential material from any AI platform unless the provider is contractually forbidden to train on it or share it, and must delete it on request.

Before a produced document goes into an AI tool under an order shaped like this one, I would want three things confirmed in writing:

  1. The provider is contractually barred from storing or using your inputs to train or improve its model.
  2. Disclosure to third parties happens only where essential to deliver the service, and any such third party is bound by obligations just as protective.
  3. The contract lets you remove or delete all Confidential information on request, and you keep written documentation of every one of these protections.

On March 30, 2026, a magistrate judge in the District of Colorado faced a situation that had arrived quietly, the way most AI disputes still do. A self-represented plaintiff had used AI to help prepare filings, working from material the plaintiff's former employer had designated Confidential. Both sides proposed language. Magistrate Judge Maritza Dominguez Braswell rejected both and wrote the court's own.

The provision that emerged reads less like a ban than like a procurement checklist. Confidential information may not enter an AI platform unless the provider is contractually prohibited from training on inputs and from disclosing them to third parties, except where disclosure is essential to the service. Then comes the condition that matters most here: the provider must contractually allow removal or deletion of all Confidential information on request. The court also ordered the plaintiff to disclose any AI platform already used with confidential materials.

An analysis published by the AAA-ICDR in September 2026 records the court's own forecast of the cost. The provision "will (at least for now) bar the parties from using most, if not all, mainstream low-to-no-cost AI to process Confidential Information." The court seemed to accept that outcome rather than resolve it.

The common assumption is that AI clauses in protective orders exist to stop model training. Morgan's text complicates that. Training is the first condition; deletion is the last, and the only one tested after the case ends.

Morgan was not alone. King & Spalding counted at least five federal district courts that issued or analyzed protective order provisions restricting generative AI between 2025 and early 2026. In Jeffries v. Harcros Chemicals, the District of Kansas's original order required deletion of all confidential information at the conclusion of the action. United States v. Allen requires deletion from any AI tool when the case ends. About three weeks after Morgan, the ByHeart infant formula MDL barred Protected Material from generative AI tools unless three specified conditions were met.

Set side by side, a comparison of 5 sources shows the same drift, away from general prohibitions and toward operational requirements a vendor either meets or does not. Relevant e-Discovery was built around those requirements: processing runs single-tenant, or inside the client's own AWS account under the client's own keys, with no vendor retention and no model training. The earlier wave of protective orders restricting AI training on produced data asked what a tool would learn. The newer orders ask what it will keep.

Deletion on request sounds simple enough. The harder question, the one none of these orders quite reaches, is what the provider would be deleting, and how anyone would know.

How Many Copies Does an AI Tool Make of One Exhibit?

Several kinds, and a standard destruction certificate names none of them: overlapping text chunks, one embedding per chunk, metadata tying chunks to pages, and records of retrieval.

Consider a single exhibit, an email chain stamped Confidential, as it enters an AI review tool built on retrieval-augmented generation. RAG, as the design is usually called, means the system first searches your documents and then answers from what it found. Robi Kumar Tomar, writing in November 2025, lays out the ingestion pipeline in six steps:

  1. Load PDFs, DOCX files, emails, HTML and manuals.
  2. Clean the text.
  3. Split it into chunks, recommended at 200 to 400 tokens with 30 to 50 tokens of overlap.
  4. Generate an embedding for each chunk.
  5. Add metadata: source, page number and document type.
  6. Store the result in a vector database.

An embedding is a list of numbers standing in for a passage's meaning. A vector database is the store that holds those lists and finds the ones nearest a question. OpenAI's smaller current embedding model produces vectors of 1,536 dimensions; its larger model supports up to 3,072. Other accounts of conventional pipelines describe chunks of 300 to 500 words, held in stores such as Pinecone, Weaviate or pgvector.

What strikes me is how ordinary each step is. Nothing here is exotic, and nothing here was designed with a protective order in mind. Because neighboring chunks share text, a sentence from the email can sit in the chunk store more than once before a single vector is computed. Each of those chunks then receives its own embedding and its own metadata row, the row that quietly records which document and which page it came from.

Then a reviewer asks a question. The tool retrieves the 3 to 5 most relevant chunks and passes them to the model along with the question. If the system keeps a record of what it retrieved, that record holds the email's words again, now paired with the reviewer's line of inquiry.

Count it out. One exhibit may persist as a native file, as extracted text, as several overlapping chunks, as an equal number of embeddings, as a metadata row per chunk, and as fragments inside retrieval records, before anyone has asked about backups.

A return-or-destroy certificate was written for things a person can count: boxes, drives, folders. A commenter on the r/legaltech forum, discussing whether to share a legal vector database, observed that such a database is "only usable with the same embedding model you used to create it." The same commenter argued that the underlying corpus and the chunking strategy were the assets worth sharing, not the vectors themselves.

The remark was offered as a reason not to bother sharing an index. Read from inside a protective order, it describes a verification problem. No one can open a vector store and see whether a given email is still there. Absence cannot be inspected. It can only be reported by the system that did the deleting.

The training question, whether your e-discovery AI trains on your case data, concerns what a model learns. This question concerns what a system keeps, and it leaves the receiving party, at the end of a case, signing a sentence about copies it has no way to see.

Photorealistic close view inside a dim server room: a technician's gloved hand slides a backup tape cartridge out of a tape library slot, while a coiled blue patch cable and a small flashlight rest on the rack shelf
Derived copies sit in more places than the review screen: the vector database, the metadata stored with each chunk, and the backups taken of both.

Outlook - next 12-24 months

How protective orders will handle AI-derived copies

Where courts, litigants and eDiscovery vendors are heading on embeddings, chunk stores and logs built from produced documents through 2028.

11 sources analyzed7 web sources3 blog posts1 community discussion
A

What courts, vendors and litigants do next

Use each forecast to decide which deletion terms and vendor commitments to request when you negotiate your next protective order.

75/100
Medium confidence 12-24 months

For AI-assisted matters, return-or-destroy certifications will start listing chunk stores, embedding indexes and their metadata separately from native files. Each chunk is embedded and stored with its source and page number, so it can be traced back to the produced document.

62/100
Medium confidence 12-24 months

Through 2027 and into 2028, more magistrate judges will draft AI provisions themselves when parties cannot agree, using Morgan v. V2X as the reference point. Later orders will extend its training and third-party disclosure conditions to the embeddings and indexes built from produced documents.

62/100
Medium confidence 12-24 months

AI-use restrictions will increasingly cover all produced discovery, not only material designated Confidential. Any production loaded into an AI review tool will then need a plan for disposing of its derived data when the matter closes.

62/100
Medium confidence 12-24 months

Parties will keep a log of which AI tool processed which produced documents, and under whose direction. Work product protection for AI use depends on counsel's direction, and it does not extend to the identity of the tool.

Minority view
61/100
Medium confidence 12-24 months

Destruction clauses that name only vector indexes will fall behind as vectorless retrieval spreads. Tools such as PageIndex store LLM-generated section summaries instead of embeddings, so orders will move toward defining derived data by what it reveals about produced documents.

Faint signals worth tracking: On March 30, 2026, the District of Colorado rejected both parties' proposed terms in Morgan v. V2X and wrote the court's own AI provision, which Kirkland calls one of the first detailed AI-specific protective order provisions. The Morgan v. V2X provision bars putting Confidential information into any AI platform unless the provider is contractually prohibited from storing or training on inputs. In United States v. Heppner, a privacy policy that disclosed training use defeated confidentiality. A Paul, Weiss memo dated April 14, 2026 reported a court applying a protective order's AI-use limits to all discovery. Between 2025 and early 2026, at least five federal district courts issued or analyzed AI restrictions on protected materials. Standard RAG ingestion splits documents into 300 to 500-word chunks and embeds each one. It stores each chunk with source, page number and document type metadata in a vector database such as Pinecone, Weaviate or pgvector. Morgan v. V2X held that a pro se litigant's AI use was protected work product, but the identity of the AI tool was not. Heppner denied protection to AI-generated materials created outside counsel's direction. PageIndex, an open-source library, implements vectorless RAG in about 50 lines of Python. A commenter in a legal tech forum argues that the underlying corpus and chunking strategy, not the vector database, are the assets worth sharing.

B

Rulings and technical sources behind each call

Each public ruling summary or technical source below is paired with the line that supports a forecast on AI terms in protective orders.

Source What it states Forecasts it backs
A Federal Court Charts a Path on AI, Protective Orders and Work [Web source] The adopted provision bars inputting CONFIDENTIAL information into any AI platform unless the provider is contractually prohibited from:. “In Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026), Magistrate Judge Maritza Dominguez Braswell approved protective order language permitting AI…”
Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026): Magistrate Judge Maritza Dominguez Braswell approved protective order language allowing AI use if certain confidentiality measures are met.
The court held that a pro se litigant's use of AI in preparing for litigation is protected work product under Federal Rule of Civil Procedure 26(b)(3). The protection does not cover the identity of the AI tool used.
Vendor contracts become the gate
Judges write AI terms themselves
Tool identity becomes part of the record
Federal Courts Issue Diverging Rulings on the Use of Generative AI [Web source] Users had no reasonable expectation of confidentiality because the platform's privacy policy disclosed that inputs and outputs are used for training, and it reserved the right to share data with third parties. “The court agreed with the defendants that because data submitted to a public AI tool is used to train and improve the system, it is “practically impossible” to…” Vendor contracts become the gate
Will Courts Enforce Protective Order Restrictions Affecting AI Use? [Web source] AI-use provisions in protective orders aim to keep confidential, proprietary or sensitive information from being "ingested into AI applications for training or improving AI models.". “Protective order practices have been upended by artificial intelligence (AI).” Vendor contracts become the gate
Vectorless RAG: Your RAG Pipeline Doesn’t Need a Vector Database [Blog] In traditional RAG, documents are split into "300 to 500-word chunks." Each chunk is converted to an embedding and stored in a vector database such as Pinecone, Weaviate or pgvector. “This is not a model problem. It is a retrieval problem.”
PageIndex (github.com/VectifyAI/PageIndex) is described as an open-source library that implements vectorless RAG "in about 50 lines of Python.".
Destruction records itemize derived stores
Vector-only wording will age fast
How RAG Actually Works: Embeddings, Vector Databases, Indexing & Retrieval Explained [Blog] The RAG ingestion pipeline described has six steps: load PDFs, DOCX, emails, HTML and manuals; clean text; chunk; generate embeddings; add metadata (source, page number, document type); and store in a vector database. “RAG = LLM (brain) + Search System (memory)” Destruction records itemize derived stores
Vector Databases: Searching by Meaning - The Essential Engine of the LLM Era [Blog] Embedding models such as OpenAI's text-embedding-ada-002 and the open-source all-MiniLM-L6-v2 (Sentence Transformers) convert unstructured data into fixed-length vectors, for example 384, 768, or 1536 dimensions. “LLMs are powerful, but they have critical limitations: they hallucinate, their training data has a knowledge cutoff, and they lack access to proprietary…” Destruction records itemize derived stores
AI Is Not a Special Case: A Default Standard for AI Use Under [Web source] On March 30, 2026, a magistrate judge in the District of Colorado amended a protective order covering a self-represented plaintiff's use of material his former employer designated Confidential. Judges write AI terms themselves
[PDF] Court Extends Protective Order's AI Restrictions to All Discovery [Web source] As of April 2026, at least one court was willing to apply a protective order's AI-use limits to all discovery. AI limits stretch past the confidential tier
Protective Orders in the Age of Generative AI: Best Practices for [Web source] Between 2025 and early 2026, at least five federal district courts issued or analyzed protective order provisions restricting generative AI use with protected materials. A federal appellate court, the Sixth Circuit in United States v. “These decisions establish that proactive AI-specific provisions are no longer optional - they must be standard practice.” AI limits stretch past the confidential tier
Generative AI in Discovery: Protective Orders as an Emerging Point [Web source] Heppner: the court declined to extend privilege or work product protection to AI-generated materials created outside the direction of counsel and not for the purpose of obtaining legal advice. “It concluded that the use of such publicly accessible AI tools presents unique risks, including the practical inability to claw back or delete data once it has…” Tool identity becomes part of the record
Who else has a vector database of their jurisdiction's laws and cases [Community / Forum] The same commenter argues that the underlying corpus and the chunking strategy are the assets worth sharing, not the vector DB itself. “Hey there ! I have a vector database of French law that is always up to date for my legaltech.” Vector-only wording will age fast
Each public source behind these forecasts, the line from it that each forecast rests on, and the forecasts it backs.
C

What would slow the push for deletion terms

Shifts in sanctions practice, privilege rulings or retrieval technology that would weaken or reverse the forecasts above.

On confidence and limits

A score measures how much current evidence backs a call, and that evidence keeps moving. “Vendor contracts become the gate” has the firmest support here, while “Vector-only wording will age fast” is the call most likely to shift.

  • Courts could keep treating AI use purely as a contract-and-training question and never sanction a party for AI ingestion.
  • As of September 23, 2026, courts had not directly addressed sanctions.
  • Gilbarco, where public AI use alone was not waiver, could become the dominant approach.
Methodology Each forecast is scored 0-100 from the public sources shown for it: how many there are and how authoritative they are.

What Will Matter Most for AI Protective Orders in the Next 12 to 24 Months?

Proof of deletion will matter more than permission to use AI. Courts are settling which tools may touch discovery; the harder question is showing the derived copies are gone.

I see three movements, each already visible in a 2026 ruling.

PredictionWeak signalWhy it mattersPublic source
More magistrate judges will write AI terms themselves when parties deadlock, and later drafts will add deletion records to the training and disclosure limits.The Morgan court found the defendant's draft too protective, rejected the plaintiff's as well, and wrote its own clause.A party that arrives without deletion terms can be bound by language it never negotiated.Morgan v. V2X, Inc., No. 25-cv-01991 (D. Colo. Mar. 30, 2026)
AI limits will cover all produced discovery, not only the Confidential tier.Jeffries extended its bar on open AI tools to non-confidential documents, and by April 2026 at least one court was applying AI-use limits to all discovery.Deletion duties then attach to the whole review index rather than a designated subset.Jeffries v. Harcros Chemicals Inc., 2026 WL 820218 (D. Kan.)
Parties will log which AI tool processed which documents, and under whose direction.Heppner denied protection to AI material made outside counsel's direction; the Morgan court called a request for the tool's identity "legitimate and reasonable."A discoverable tool invites the next question, which is what it kept. A deletion record naming the tool and its stores answers it.United States v. Heppner, 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026)

The forecast could fail in a quieter way. The AAA-ICDR analysis quoted earlier argues that a provider contract should not be the categorical default, and proposes a functional standard instead: no training on inputs or outputs, a provider post-deletion retention window of no more than thirty days, and a dated record of the configuration and published terms. If courts adopt something like it, orders may name a retention window rather than an index. Its author also notes that many current AI restrictions "began as form paragraphs and orders issued without adversarial testing," which suggests the wording is less settled than it looks.

Even then, I expect the log to survive. A retention window still has to be shown, and a dated configuration record is a deletion log by another name, kept one level up. "A judicial signature gives a term legal force," the same analysis observes. "It does not create a factual record that the parties never presented."

None of the sources gathered here describes a court ordering an index-level deletion log. That is the distance the prediction has to travel. The first order to cross it will probably come from a magistrate judge holding two drafts that both miss the index, and a pen.

What Should a Vector-Index Destruction Clause Say?

Name every derived store, set a deletion deadline, and require an itemized, append-only deletion log tied to content hashes, so the certificate rests on a record rather than a promise.

The fix is drafting, not technology. A clause that reaches derived data needs three elements, and I would propose all three before the first production is loaded:

  1. A functional definition of Derived AI Data. Describe what the data does rather than which product holds it: extracted and chunked text, embeddings, vector indexes and their metadata, generated summaries, caches, retrieval and prompt logs, and any backup or snapshot containing them.
  2. A trigger and a deadline. Deletion at final disposition, or sooner on the designating party's written request, within a fixed number of days the parties agree.
  3. An itemized record. Certification store by store, backed by an index-level deletion log, rather than one sentence covering everything.

Here is the difference in practice.

Before: At the conclusion of this action, the Receiving Party shall return or destroy all Protected Material and certify that no copies remain.

After: Within [number] days after final disposition, or sooner on the Designating Party's written request, the Receiving Party shall delete all Protected Material and all Derived AI Data from every system that processed it, deliver an index-level deletion record identifying each system and store, and certify deletion separately for each store listed.

The first version is true or false only in aggregate. The second can be checked line by line, and that is the whole of its value.

The record itself should carry, at minimum, the fields below.

Record fieldWhat it shows
Matter and production identifiersWhich produced volumes the deletion covers
AI system and tool identityEvery tool that processed Protected Material, and under whose direction
Stores purgedChunk store, vector index and metadata, caches, retrieval and prompt logs, each listed separately
Counts before and afterDocuments, chunks and embeddings present before deletion, and none after
Source hashesContent hashes tying each deleted entry to a specific produced document
Backups and snapshotsWhich backups held the data, and the date each was purged or expires
Timestamps and signerWhen each step ran and who attests to it

At Relevant e-Discovery, originals are immutable and content-hashed, audit trails are append-only, and chain of custody is documented. An append-only trail is the natural home for a deletion event, because an entry written there cannot be quietly revised afterward. Our tool's answers already link back to the exact exhibit they came from, and that same source linkage is what lets a deletion log name documents rather than gesture toward them. Where the index runs inside the firm's own cloud account, the log becomes the firm's own record instead of a vendor's letter.

Two figures belong in any vendor's answer: the exact format of the index-level deletion log for a single-tenant or own-account deployment, and the elapsed time to purge a matter's index and its backups at close. Neither figure appears here. Ask for both in writing before the first production loads; once supplied, they show precisely what the certificate will rest on.

Defensibility has always rested on records, the same reason predictive coding isn't the only defensible AI review. We invite buyers to bring a messy collection and a hard question and watch the tool read, code and cite their own evidence. I would add one request at the end of that session: delete the matter, and show me the record.

A firm that asks for this record now will already hold one on the day a court first asks to see it.

Can your review tool show you what it deleted?

AI-assisted review runs cents per document, against dollars per document and roughly $19K/GB for manual review. Relevant e-Discovery pairs that RAG intelligence with the defensible spine of Bates numbering, privilege and chain of custody, in one tool built for a small firm on a single messy matter.

Bring the matter. Then ask for the deletion record before anyone signs a certificate.

Will Deletion Logs Become Standard in AI Protective Orders?

Most likely by the end of 2027. Orders already require deletion from AI tools, and the next demand will be a record proving the deletion happened, index by index.

The enforcement record is thin. A September 2026 analysis published on JD Supra reports that courts "have not directly addressed" whether they will sanction a party for uploading confidential discovery into an unauthorized AI application. In Campbell v. TidalHealth, the magistrate judge deferred. Where courts have punished misuse of protected material, the sums stayed modest: in the Uber MDL, $30,000 against the $168,572 Uber sought. The same author warns that such sanctions "may not adequately remediate harm" from AI disclosures, depending on what was exposed.

I read that thinness less as comfort than as a window. When the law is unsettled and the penalties small, the argument tends to turn on who kept records, and a party holding an itemized deletion log is the only one able to answer, without pausing, the question a court will eventually put to both sides.

Ask your vendor for a sample deletion record now, before the matter that needs one arrives. If what comes back is a single signed line, you have learned something about the index.

Summarize This Article With AI

Open this article in your preferred AI engine for an instant summary.

Frequently Asked Questions

What Else Do Litigators Ask About AI Data After a Protective Order Ends?

Mostly whether public tools are allowed, whether privilege survives, and whether the tool's name is discoverable. Courts split on several of these in 2026, so the order's own text governs.

Do I have to delete AI embeddings when a protective order ends?

No order discussed here names them yet, though I would treat them as copies. An embedding is a string of numbers a tool generates to stand in for a passage's meaning, and it exists only because the produced document did. Akin Gump advises clients to ensure "the ability to permanently delete or 'claw back' sensitive discovery materials at the conclusion of a matter."

Can I upload produced documents to ChatGPT or another public AI tool?

Often not. In Jeffries v. Harcros Chemicals, decided March 25, 2026, the District of Kansas banned public or "open" generative AI tools for all discovery materials, designated or not. The court accepted that data submitted to a public tool is "practically impossible" to claw back or delete once processed.

Does using a public AI tool waive privilege or work product?

It can. In United States v. Heppner, a criminal defendant's exchanges with a public platform received neither protection, partly because the platform's privacy policy disclosed that inputs and outputs were used for training. Warner v. Gilbarco and Morgan v. V2X found no waiver for pro se civil plaintiffs. Reviewing four significant decisions from Q1 2026, Akin Gump still calls avoiding public AI "the safer approach."

Can the other side learn which AI tool I used?

In at least one case, yes. The Morgan court protected the plaintiff's work product but compelled disclosure of the tool's name, because Confidential Information appeared to have already gone into it. Once a tool is named, what it retained becomes a fair question.

What is a closed enterprise AI system?

A closed enterprise AI system is one whose contract and terms of service bar retaining inputs for training or sharing them with third parties. One court has already mandated closed systems for all discovery materials. Read the retention terms before the first upload, not after.

Does the archival-copy exception cover an AI index?

The orders do not say. Jeffries prohibits residual Discovery Materials in an AI tool, then permits counsel to keep an archival copy seven paragraphs later. I would ask for the index to be named outside the archival exception, in writing.

Written by

Michael

Kansky

Michael Kansky is a serial software entrepreneur who has spent more than two decades building and bootstrapping profitable SaaS and services companies.

Connect on LinkedIn

Read next

Close-up editorial photo of a litigation reviewerEdiscovery

Reviewers Who See the AI's Tag First Rarely Overrule It

Yes. A reviewer who sees the AI's code first can anchor on it, so tag-first QC mostly measures agreement. Only a random sample coded blind measures the AI's real error rate.October 2, 202625 min read
Stack of produced discovery documents under a desk lamp at night, one page showing faint hidden marks beside a laptop running AI document reviewEdiscovery

Can a Planted Document Fool Your AI Review Tool?

Yes. A planted document refers to a produced file carrying hidden text, white on white or tiny type, that the attorney never sees but the AI reviewer reads and may obey.September 30, 202630 min read
Laptop showing a long workplace chat thread beside a tall stack of printed pages with only a few flagged for reviewEdiscovery

What Share of a Chat Collection Is Actually Relevant?

Nobody has published a measured figure. A chat collection's responsive share refers to the fraction of gathered messages that a request for production actually calls for, and the only defensible number is one measured on your own matter.September 28, 202627 min read

See it on your matter

Bring us a messy collection - mailboxes, scans, phones, recordings - and watch it become one searchable, defensible record.