Skip to main content
Can We Use AI on Discovery? Eight Questions Legal Teams AskeDiscovery & Legal Holds
5 min readFor Legal Operations Professionals

Can We Use AI on Discovery? Eight Questions Legal Teams Ask

These questions are likely echoing in your team meetings right now. Since protective orders began including AI-specific language in early 2026, legal operations teams have struggled with what feels like a moving target. The U.S. v. Thomas case in the Southern District of New York highlighted this confusion: defense counsel couldn't get discovery released because they couldn't agree on AI language in the protective order, and the court essentially told both sides to keep negotiating. Many teams find themselves in this position, wanting to use AI tools but unsure of the restrictions they'll face.

Do My Existing Ethical Obligations Already Cover AI Use in Discovery?

Yes, but that doesn't solve the practical problem.

Defense counsel in Thomas argued: "I am well aware of my ethical obligations on the use of AI in handling my client's documents whether those documents are discovery or something other. The Government does not have a role in policing or overseeing or even dictating with my ethical obligations."

The court didn't accept this as a reason to skip negotiating the protective order. Your ethical duties around confidentiality, competence, and supervision apply regardless of the tools you use. However, opposing counsel and courts now want explicit agreement on what "using AI" means in practice. Does uploading to a third-party platform for analysis violate confidentiality restrictions? Does using a vendor's hosted AI tool constitute "further disclosure"? Your ethics rules don't answer these questions with the specificity that protective orders now demand.

What Exactly Are Courts Restricting in These AI Provisions?

The most common restriction is uploading protected materials to AI platforms that might use the data for training or expose it to other users.

In Thomas, the government's proposed order subjected all discovery materials to "restrictions on, inter alia, further disclosure and use other than for purposes of the defense of the charges, as well as the AI-specific restrictions." This language is becoming standard. Courts want to prevent scenarios where confidential discovery ends up in a large language model's training corpus or gets exposed through prompt injection attacks.

You'll see provisions that prohibit uploading to "open AI" platforms, require use of isolated or air-gapped AI tools, or mandate that any AI processing happens on counsel's own infrastructure. Some orders require disclosure of which specific AI tools you plan to use before you deploy them.

Can I Just Avoid the Whole Issue by Not Using AI?

Not really, because opposing counsel may assume you will use it.

The Thomas court noted that the government characterized all discovery as "disclosure materials" subject to AI restrictions, even materials that weren't designated as sensitive. This is the new default posture. Parties are writing protective orders that assume AI will be used somewhere in the workflow, so they're restricting it preemptively.

If you genuinely won't use AI tools, you can negotiate that into the order. But you'll need to define what counts as "AI" (does advanced search in your review platform qualify?) and commit to notifying opposing counsel if your approach changes mid-case.

What Happens If We Can't Agree on AI Language?

You don't get discovery, and the court won't force the issue.

Thomas is instructive here. Defense counsel asked the court to compel production of at least the non-sensitive materials while the parties continued negotiating. The court denied the request, finding that under the government's broad definition, there wasn't any discovery that would be produced without restrictions. The court encouraged the parties to "continue to meet and confer" but didn't impose a solution.

This puts pressure on both sides to compromise. The producing party can't withhold discovery indefinitely, but the receiving party can't access critical materials until they agree to terms. Most teams find that negotiation is faster than motion practice.

Should Our Coordinating Discovery Attorney Be Involved in These Negotiations?

Absolutely, and courts are starting to expect it.

In Thomas, the court noted that Emma Greenwood, the appointed Coordinating Discovery Attorney, had participated in discussions between the government and defense counsel. When you're managing multi-party cases or complex discovery, your CDA should be part of AI provision negotiations from the start. They can identify workflow implications that individual counsel might miss and help standardize approaches across defendants or parties.

What Should We Be Clarifying About Our Own Ethical Obligations Before We Negotiate?

Start by mapping which AI tools in your current workflow involve third-party data processing.

The Thomas court asked defense counsel to "clarify the defense's position as to whether it believes its ethical obligations already preclude its use of AI tools that would subject the discovery material to disclosure and/or use that is incompatible with the general restrictive principles." That's the right question for your team, too.

Document which tools send data outside your environment, which vendors claim they don't train on customer data, and which tools run entirely on your infrastructure. Know whether your contract with your review platform allows AI features to be disabled at the document-set level. This audit gives you a starting position for negotiations.

Are There Any Discovery Materials We Can Get Without Agreeing to AI Restrictions?

Probably not, based on current trends.

The government in Thomas took the position that all discovery, even non-sensitive Rule 16 materials, fell under the protective order's AI restrictions. This approach is spreading. Parties are treating AI provisions as baseline terms that apply to everything produced, not just designated confidential materials.

You might negotiate different tiers: perhaps non-confidential materials can be processed with vendor-hosted AI tools, while "attorneys eyes only" materials require on-premises processing. But expect some level of restriction across the board.

What's the Practical Impact on Our Review Timeline?

Plan for at least two to four weeks of additional negotiation time before you can start substantive review.

In Thomas, the parties spent over a month negotiating AI language, with proposals going back and forth. That's becoming typical. Budget time for your vendors to provide technical documentation about their AI implementations, for your IT team to assess infrastructure options, and for multiple rounds of redlines on the protective order language.

If you're responding to discovery requests, start the AI conversation in your initial meet-and-confer. If you're requesting discovery, include proposed AI language in your draft protective order from day one.

Where to Go for More

Track protective order language in cases within your jurisdiction. The Southern District of New York has seen multiple AI-specific orders entered by consent in criminal cases throughout 2026, and civil cases are following the same pattern. Your litigation support team should be collecting these orders and identifying common language you can adapt.

Work with your vendors to understand their roadmap for AI features that comply with restrictive protective orders. The market is responding, you'll see more options for on-premises AI deployment and contractual commitments around data isolation.

Expect this landscape to keep shifting. Courts are learning alongside practitioners, and the provisions that feel onerous today may become standard workflow considerations tomorrow.

You Might Also Like