Generative AI can help legal teams understand a document production more quickly. Reviewers may use AI tools to summarise lengthy reports, identify names and dates, compare documents, build chronologies or locate material relevant to a particular allegation. But what happens when those documents were received from another party through discovery?
A series of United States federal court decisions issued during the first quarter of 2026, and examined together in a late-May legal analysis, show that the answer may depend on the protective order, the AI platform and the contractual controls governing how that platform handles data. The practical lesson is straightforward: receiving documents through discovery does not necessarily give a legal team permission to upload them into any AI tool it chooses.
Courts Are Beginning to Restrict AI Use
In March 2026, two US federal courts amended protective orders to address the use of generative AI.
In Morgan v V2X, Inc, the Colorado court restricted parties from entering information designated confidential into an AI platform unless the provider was subject to specific contractual safeguards. The provider had to be contractually prohibited from storing the inputs or using them to train or improve its model. Disclosure to third parties was permitted only where necessary to deliver the service and where those parties were subject to equally protective obligations. The user also needed the ability to remove or delete the confidential information and was required to retain written evidence of the contractual protections. The plaintiff was ordered to disclose the name of any AI platform used to process confidential information.
A few days earlier, the court in Jeffries v Harcros Chemicals Inc approved a broader restriction. It prevented the parties from uploading any documents produced in discovery into public or open AI tools, including documents that had not been designated confidential. Closed or secure AI systems could still be used. The decision was specific to that litigation and the risks demonstrated by the defendants. These included concerns involving critical infrastructure, personal information, European privacy obligations and the difficulty of recovering information once it had been entered into an open AI system.
It should not be treated as a general prohibition applying across all US federal proceedings.
Public and Enterprise AI Are Not the Same
The decisions do not mean that all AI-assisted document review is prohibited. They highlight an important distinction between public AI services and controlled enterprise or closed systems. Depending on the platform, contract and settings, a public tool may retain prompts and uploaded documents, use them to improve its services or allow access by provider personnel and subprocessors.
An enterprise platform may offer stronger protections, including:
- preventing customer information from being used for model training;
- restricting access to authorised users;
- defined storage locations and retention periods;
- encryption and audit logging;
- deletion rights; and
- contractual confidentiality commitments.
However, calling a system “enterprise” or “closed” does not answer every question. Legal teams still need to examine the actual contract, technical settings and data-handling arrangements. The label applied to the product is less important than what the provider is permitted to do with the information.
Work Product Does Not Resolve the Data Risk
Another decision, Warner v Gilbarco, Inc, considered whether using ChatGPT affected work-product protection. The court held that the self-represented plaintiff could claim work-product protection over the internal litigation material sought by the defendants. It also rejected the argument that using ChatGPT automatically waived that protection. The decision should not be read as protecting every AI prompt or output. It also did not resolve separate questions involving attorney-client privilege. More importantly, work-product protection addresses a different issue from whether discovery material may be placed into a particular AI platform.
A document or AI-generated analysis may qualify as work product while the user still breaches a protective order, confidentiality obligation or restriction on the use of discovered documents.
Legal teams should therefore assess separately:
- compliance with the protective order;
- the permitted use of discovery material;
- confidentiality and privacy obligations;
- privilege and work-product protection;
- the provider’s retention and training practices; and
- the security of the review environment.

What Legal Teams Should Check
Before using generative AI on material obtained through discovery, legal teams should consider several practical questions.
Review the protective order
Check whether it regulates AI tools, cloud services, external processors or the handling of confidential information. Do not assume that restrictions apply only to documents formally marked confidential. In some matters, the order may cover all material produced through discovery.
Confirm the permitted purpose
Documents produced through discovery are usually provided for use in the proceeding. Using them to train, test or improve an external system may fall outside that permitted purpose, even where the legal team intends to use the resulting output in the case.
Assess the platform
Confirm whether uploaded documents and prompts are retained, used for model training, shared with subprocessors or accessible to provider personnel. The team should also understand whether the information can be permanently deleted and whether the provider will supply written contractual commitments covering its use.
Separate public and approved tools
Staff should understand that having access to a public chatbot does not make it an approved document-review platform. Organisations should clearly identify which systems may be used for confidential or discovery material.
Keep an audit record
Record:
- the platform used;
- the documents submitted;
- the purpose of the analysis;
- the relevant security and retention settings;
- the people authorised to access the results; and
- any contractual protections relied upon.
Agree the position early
Where AI-assisted review is contemplated, the parties should consider addressing it in the discovery protocol or protective order before documents are exchanged. Agreeing the position early may reduce uncertainty and avoid later disputes about how produced material has been handled.
Why This Matters in New Zealand
The US decisions do not bind New Zealand courts, but the underlying issue applies equally to New Zealand litigation.
High Court Rule 8.30 generally limits the use of documents obtained through disclosure to the purposes of the proceeding, subject to specified exceptions or permission from the Court. Confidential or commercially sensitive material may also be governed by court orders, undertakings, privacy obligations or contractual restrictions.
New Zealand legal teams should not assume that discovery material may be uploaded into a public or uncontrolled AI service merely because the service provides a convenient way to summarise a production.
The safer approach is to use a controlled review environment where the data-handling arrangements are understood, documented and consistent with the obligations applying to the matter.
The Takeaway
Generative AI can provide real value during document review, but the platform matters as much as the prompt.
Before uploading discovery material, legal teams should confirm what the protective order permits, where the information will be stored, whether it will be retained or reused, who may access it and whether it can be permanently deleted.
AI-assisted review should take place within a secure and defensible workflow, not through an informal upload to whichever tool is most convenient.
How We Can Help
We assist legal teams with secure eDiscovery hosting, document review and AI-assisted analysis.
This includes controlled review environments, evidence processing, Technology-Assisted Review, Continuous Active Learning, access controls, confidentiality workflows, audit records and defensible productions for litigation, investigations and regulatory matters.
Sources
United States District Court for the District of Colorado, Morgan v V2X, Inc, Document 65
