Skip to main content
Five Protective Order Mistakes That Expose Client Data to AI TrainingeDiscovery & Legal Holds
5 min readFor Legal Operations Professionals

Five Protective Order Mistakes That Expose Client Data to AI Training

Your opposing counsel just agreed to a standard protective order. You're using a closed AI system for document review. Everything's fine, right?

Not if you've made any of the five mistakes below. The gap between "we have a protective order" and "our protective order actually prevents AI training on produced materials" is wider than most legal operations teams realize. Here's why these mistakes keep happening and how to fix them before your next production.

Why These Mistakes Keep Happening

The issue isn't that teams ignore AI risks. It's that protective order templates were written before generative AI existed. Your standard confidentiality language from 2019 says nothing about model training, algorithm improvement, or unauthorized access through AI interfaces. Meanwhile, the AI systems you're evaluating change their data handling practices every quarter.

Most legal ops professionals inherited a protective order playbook that treats technology as a black box. The old approach worked when "technology-assisted review" meant keyword search. It fails when AI systems can extract, learn from, and potentially expose the patterns in your client's most sensitive documents.

Mistake 1: Treating All AI Systems the Same

Your team negotiates a protective order that says "no AI training on produced documents." Then your vendor deploys three different AI tools: a closed document review platform, a public chatbot for legal research, and a hybrid summarization service. Which ones comply with the order?

Why it happens: Legal teams think "AI" is a single category, like "email" or "databases." In reality, closed AI systems that operate within secure environments and are subject to contractual, technical, and administrative safeguards function completely differently from open systems that feed user inputs back into public model training.

The consequence: Your associate pastes a protected document into a public AI interface to generate a summary. That content now trains a model accessible to anyone, including opposing parties in future litigation. Your protective order didn't specify which AI architectures are permissible, so there's no clear violation to enforce.

The fix: Draft protective orders that distinguish between closed and open AI systems by their data handling characteristics, not their brand names. Specify that closed systems must provide contractual guarantees that produced materials will not train models, improve algorithms, or become accessible to unauthorized users. Require counsel to verify these safeguards before processing protected information through any AI tool.

Mistake 2: Ignoring the Supervision Obligation

You've restricted AI training. But who's checking that the AI's output doesn't leak confidential details into work product that gets filed publicly?

Why it happens: Teams focus on input restrictions (what goes into the AI) and ignore output risks (what comes out). Ethical obligations require counsel to supervise technology-assisted work, but most protective orders say nothing about AI output review procedures.

The consequence: Your AI summarizes 50,000 documents and flags key themes. An associate incorporates those themes into a brief without verifying the underlying sources. The brief cites a confidential settlement amount that should have been redacted. You've violated the protective order not through training, but through unsupervised disclosure.

The fix: Add protective order language that explicitly subjects AI usage to applicable procedural rules and the ethical obligations of counsel. Require that any AI-generated work product derived from protected materials undergo human review before filing or sharing. Make it clear that "AI did it" isn't a defense to disclosure violations.

Mistake 3: Negotiating AI Terms After Production

Your team produces 100GB of documents under a standard protective order. Three weeks later, opposing counsel emails: "We're using an AI review platform. Here's proposed AI language for the protective order."

Why it happens: Legal teams treat AI restrictions as an afterthought, something to negotiate once the case is underway. By then, the other side has already loaded your production into their review system.

The consequence: You're negotiating from weakness. The other side has already committed to a vendor and workflow. They'll resist restrictions that require changing platforms or review procedures. Even if you get strong AI language now, you can't verify what happened to your data before the amendment.

The fix: Make AI restrictions a first-day issue. Include AI-specific language in your initial protective order proposal, before any discovery changes hands. Address both permissible and impermissible uses upfront. If you're responding to the other side's proposal, insist on AI terms before consenting to production deadlines.

Mistake 4: Copying Boilerplate Without Verification

You find a protective order from a major case that includes AI restrictions. You copy the language into your template. Done.

Why it happens: Legal ops teams are understaffed and overworked. Copying tested language from a published order feels safer than drafting from scratch. The problem is that AI protective order language is evolving rapidly, and what worked in one case may not fit your facts.

The consequence: Your copied language prohibits "use of AI for any purpose related to protected materials." Sounds strong. But it's unenforceable because it would ban legitimate uses like document review and summarization. Opposing counsel ignores it, knowing you can't realistically enforce a blanket prohibition.

The fix: Adapt, don't copy. Use published protective orders as models, but customize the language to distinguish between permissible uses (document review, organization, summarization with closed systems) and impermissible uses (model training, algorithm improvement, public AI interfaces). Make sure your restrictions are specific enough to enforce and reasonable enough that opposing counsel will actually comply.

Mistake 5: Failing to Audit Vendor Contracts

Your protective order prohibits AI training. Your vendor's master services agreement says they can use client data to "improve services and develop new features." Which one controls?

Why it happens: Legal teams negotiate protective orders without reviewing the underlying vendor contracts that govern data handling. They assume the protective order flows down to all service providers automatically.

The consequence: Your vendor is contractually permitted to use your production data for model training, even though your protective order with opposing counsel prohibits it. When you discover the conflict, the vendor claims they're bound by their MSA, not your case-specific protective order. You have no enforcement mechanism.

The fix: Before agreeing to AI restrictions in a protective order, audit your vendor contracts to confirm they can comply. If your current vendors can't meet the protective order requirements, you need to know that before you commit to those terms. Add protective order compliance as a mandatory term in all vendor agreements for litigation support services.

Prevention Checklist

Before your next production, verify:

  • Protective order distinguishes between closed and open AI systems by data handling characteristics
  • Language specifies that closed systems must contractually guarantee no training, algorithm improvement, or unauthorized access
  • Order explicitly subjects AI usage to procedural rules and ethical supervision obligations
  • AI restrictions are negotiated before any discovery changes hands
  • Permissible uses (review, organization, summarization) are clearly defined alongside prohibitions
  • Vendor contracts align with protective order AI restrictions
  • Team has a process for verifying AI system safeguards before processing protected materials
  • Output review procedures are documented for AI-generated work product

The goal isn't to ban AI. It's to make sure your protective orders actually protect what they claim to protect, in a world where "confidential" data can train models accessible to anyone with an internet connection.

You Might Also Like