Purpose of the Template
You're drafting a protective order for a case involving sensitive discovery materials, and you need to address AI usage restrictions. This template provides language to protect confidential information without creating a two-tier justice system where only well-funded parties can afford compliance.
Many AI protective orders today ban "mainstream low-to-no cost AI" while leaving expensive enterprise solutions untouched. That's not proportionality; that's gatekeeping.
This template builds on a five-requirement framework that addresses real risks: unauthorized use, competitive exploitation, and ongoing exposure. You can copy these provisions into your stipulated protective order or motion, then customize based on your case's sensitivity level.
Prerequisites
Before using this template, confirm:
Identify what needs protection. Not all discovery materials warrant AI restrictions. If you're protecting trade secrets, personally identifiable information under specific regulations, or materials that could cause prejudicial pretrial publicity, document that basis.
Understand the difference between consumer AI and enterprise AI. The distinction isn't technical capability; it's contractual. Consumer tools (free ChatGPT, public Claude) train on your inputs. Enterprise versions with business associate agreements don't. Your order should target the behavior (training, retention, public access), not the price point.
Explain proportionality to the court. If opposing counsel objects that your restrictions are too narrow, articulate why broader bans impose undue burden without corresponding security benefit.
The Template
AI Usage Restrictions for Discovery Materials
Definitions
"AI Tool" means any automated system that uses statistical modeling, machine learning, or similar techniques to process inputs and generate outputs, recommendations, or predictions, including large language models, generative AI services, and AI-assisted software tools.
"Discovery Materials" means all documents, electronically stored information, and other materials produced or disclosed in this matter and designated as Confidential or Attorneys' Eyes Only under this Protective Order.
Mandatory Requirements
Any party using an AI Tool to process Discovery Materials must certify in writing that the AI Tool satisfies all five requirements below:
No Training on Discovery Materials. The AI Tool will not retain, use, or incorporate any Discovery Materials for model training, fine-tuning, or improvement of the AI system. This prohibition applies whether training occurs automatically or by manual selection.
No Public Accessibility. Discovery Materials will not be processed through publicly accessible AI interfaces where other users could potentially access, view, or receive outputs derived from those materials.
Matter Isolation. Discovery Materials from this case will be logically segregated from other matters. The AI Tool must maintain access controls preventing Discovery Materials from being used to generate outputs in unrelated matters or for parties not authorized under this Order.
Deletion at Conclusion. Within 30 days of final disposition of this matter (including appeals), all Discovery Materials will be permanently deleted from the AI Tool, and the deleting party will certify completion of deletion in writing to all parties.
Documentation. The party deploying the AI Tool will maintain records sufficient to demonstrate compliance with requirements 1-4, including the AI Tool's name, version, configuration settings related to data retention and training, and the identity of personnel who configured or accessed the tool for processing Discovery Materials.
Certification Process
At least 10 days before first use of an AI Tool to process Discovery Materials, the using party shall serve on all parties:
- The name and version of the AI Tool
- A copy of the vendor's terms of service or data processing agreement demonstrating compliance with requirements 1-3
- A description of the technical or contractual controls ensuring matter isolation
- The name and contact information for the person responsible for ensuring compliance
Any party may object within 7 days. Absent timely objection, use is permitted. If objection is filed, the using party may not deploy the tool until the court resolves the dispute or parties stipulate to modified terms.
Scope Limitation
This provision applies only to Discovery Materials designated as Confidential or Attorneys' Eyes Only. It does not restrict AI usage for:
- Publicly available information, even if also produced in discovery
- The producing party's own documents before production
- Work product created by counsel (though counsel remain responsible for work product confidentiality under applicable rules)
Customizing the Template
For higher sensitivity cases (trade secrets, national security, healthcare records under HIPAA), add:
- Require on-premises deployment or private cloud instances with dedicated infrastructure
- Mandate encryption at rest and in transit using specified standards (AES-256, TLS 1.3)
- Require third-party security audits (SOC 2 Type II, ISO 27001 certification)
- Shorten the deletion timeline to 7 or 14 days post-disposition
For lower sensitivity cases (routine commercial disputes, non-confidential discovery), consider:
- Eliminating the pre-use certification process; require only that parties maintain documentation
- Extending the objection period to allow reasonable evaluation
- Clarifying that the five requirements apply only to designated confidential materials, not all discovery
If you're the producing party seeking restrictions, frame your proposal around actual harms:
- "These materials contain customer lists and pricing data that, if used to train a public model, could become accessible to competitors through prompt engineering."
- "Disclosure of these medical records to a training dataset would violate our HIPAA business associate agreement and create regulatory liability."
If you're the receiving party resisting overbroad restrictions, your opposition should emphasize:
- "We propose to use [Tool X] with enterprise data processing agreement attached as Exhibit A, which contractually prohibits training and requires deletion. Producing party has not identified any security risk this configuration fails to address."
- "Producing party's proposed ban on 'cloud-based AI' would require us to purchase on-premises infrastructure at a cost of [amount if you have it; otherwise describe the burden], creating disproportionate expense without corresponding protection, given that our proposed enterprise solution provides equivalent data isolation."
Validation Steps
After your protective order is entered, validate compliance:
Before first use:
- Obtain and review the AI vendor's data processing agreement
- Verify that auto-training features are disabled (check settings, not just vendor claims)
- Test matter isolation by attempting to access discovery materials from a different user account or matter workspace
- Document your configuration in a compliance memo to the file
During the case:
- Audit access logs quarterly to confirm only authorized personnel are processing discovery materials
- If you change AI tools or vendors, repeat the certification process
- If the vendor updates terms of service, re-evaluate compliance with requirements 1-3
At case conclusion:
- Execute deletion according to the vendor's documented procedure (don't just delete your local copies; confirm deletion from vendor systems)
- Obtain deletion confirmation from the vendor if available
- Retain the deletion certification in your closed-matter file for the same period you retain other case materials
Red flags that your order isn't working:
- You can't determine whether the tool trains on inputs (vendor documentation is vague or contradictory)
- The tool requires you to accept consumer terms of service that disclaim confidentiality
- You're paying for "enterprise" features but can't identify what contractual protections distinguish them from the free version
- Your certification relies on vendor marketing claims rather than enforceable contract terms
If you encounter these issues, don't proceed. File a motion to modify the protective order or propose an alternative tool that you can actually certify meets the five requirements.
The goal isn't to ban AI. It's to ensure that using AI to process sensitive discovery doesn't create unauthorized disclosure, competitive harm, or permanent exposure. These five requirements accomplish that goal at any budget level.



