AI Security in eDiscovery: Protecting Confidential Information while Managing Client Budget Expectations
Artificial intelligence is rapidly becoming part of modern litigation. AI can accelerate document analysis, identify relevant themes, summarize large document collections, and assist attorneys in understanding complex evidence. Like every technology before it—from email review to predictive coding—AI also raises legitimate questions about protecting confidential information during discovery.
The purpose of a protective order has never changed: preserve confidentiality while allowing the parties to efficiently exchange electronically stored information (ESI). As courts begin addressing the use of AI in litigation, the challenge is ensuring that protective orders remain focused on measurable security safeguards rather than prescribing expensive technologies that may provide little additional protection.
At Digital WarRoom, we believe AI should improve the efficiency and affordability of litigation while maintaining defensible, attorney-controlled workflows that satisfy both ethical obligations and the Federal Rules of Civil Procedure.
Courts Are Beginning to Define AI Security Standards
Recent federal decisions, including Orechovesky v. BNY Administrative Services, LLC and Pujas v. BDO USA, P.C., demonstrate that courts are actively considering how confidential discovery materials may be processed using generative AI.
These decisions generally require parties to ensure that AI platforms:
- Maintain the confidentiality of protected information.
- Prevent confidential data from being used to train AI models.
- Restrict access by unauthorized users.
- Allow confidential information to be deleted when litigation concludes.
- Is confidential information isolated from other matters?
- Is AI model training disabled?
- Is authenticated access required?
- Can project-specific information be permanently deleted?
- Are audit logs maintained?
- Is attorney review built into the workflow?
- topic clustering;
- document summarization;
- communication timeline generation;
- suggested issue coding;
- language translation;
- identifying potentially responsive documents.
- the importance of the issues;
- the amount in controversy;
- the parties’ resources; and
- whether the burden or expense outweighs the likely benefit.
- understanding hallucination risks;
- protecting confidential client information;
- supervising AI-generated work;
- independently verifying legal research;
- determining when client disclosure or consent is appropriate.
- litigation strategy;
- legal theories;
- attorney mental impressions;
- issue prioritization;
- witness evaluations.
- organizing evidence;
- identifying themes;
- recommending issue codes;
- generating timelines;
- accelerating document review.
- disabling AI model training using confidential case materials;
- authenticating all users and maintaining access logs;
- segregating each litigation matter into separate workspaces;
- deleting AI projects when matters conclude;
- documenting AI configurations and workflows;
- maintaining attorney supervision throughout the review process;
- complying fully with confidentiality obligations contained in the protective order.
These objectives are both reasonable and necessary. Confidential information deserves the same protection whether it is reviewed manually or analyzed with AI.
The more difficult question is whether protective orders should require specific AI vendors, undefined “enterprise-grade” platforms, or specialized contractual arrangements that significantly increase litigation costs without clearly improving technical security.
Security Depends on Implementation, Not Marketing Labels
Many legal AI products ultimately rely on the same underlying large language models developed by providers such as OpenAI, Anthropic, or Google. While legal technology vendors differentiate themselves through specialized workflows, integrations, and user interfaces, the underlying AI engines are often shared.
From an eDiscovery perspective, the more meaningful questions are operational:
These technical and procedural safeguards provide measurable protection regardless of whether the software is marketed as “enterprise” or “professional.”
Digital WarRoom believes courts should evaluate AI implementations based on demonstrable security controls rather than subscription pricing or marketing terminology.
Task-Specific AI Creates More Defensible Workflows
General-purpose AI systems excel at answering broad questions, but litigation requires something much more disciplined.
Digital WarRoom applies AI to narrowly defined eDiscovery tasks rather than allowing unrestricted interaction with confidential evidence. Examples include:
Each AI function serves a specific purpose within a documented workflow.
Rather than relying upon AI-generated legal conclusions, Digital WarRoom converts AI-assisted analysis into traditional, auditable litigation work product such as Boolean search strategies, issue coding recommendations, privilege review support, and attorney-reviewed timelines.
This approach preserves attorney judgment while providing complete transparency into how AI-assisted results were generated.
Simply put, customize the AI workflow for each litigation task—not the legal conclusions.
Proportionality Still Governs Discovery
The Federal Rules of Civil Procedure already provide the framework for evaluating discovery obligations.
Rule 26(b)(1) requires courts to consider:
These principles should continue to govern AI-assisted discovery.
If a properly configured AI workflow satisfies confidentiality requirements, requiring every litigant to purchase costly contractual infrastructure or premium software may increase litigation expense without providing meaningful additional protection.
Technology should reduce discovery costs—not become another barrier to accessing justice.
AI Assists Attorneys—It Does Not Replace Them
Federal courts have consistently emphasized that attorneys remain responsible for every filing submitted to the court.
The sanctions imposed in Mata v. Avianca, Inc. serve as a reminder that lawyers cannot delegate professional judgment to artificial intelligence. AI-generated legal authorities, factual summaries, and research must always be independently verified before they are relied upon in litigation.
Digital WarRoom’s philosophy reflects this same principle.
AI assists attorneys.
It does not replace attorneys.
Every important litigation decision—including responsiveness, privilege, relevance, production, and legal strategy—remains under attorney supervision.
Competence Includes Understanding AI
The American Bar Association’s Formal Opinion 512 (2024) recognizes that lawyers may ethically use generative AI provided they understand both its strengths and its limitations.
Competent AI use includes:
These responsibilities reinforce existing professional obligations under ABA Model Rules 1.1, 1.6, and 5.3, together with Rule 11 of the Federal Rules of Civil Procedure.
AI should enhance attorney competence—not substitute for it.
Are AI Prompts Discoverable?
Another evolving issue is whether AI prompts, instructions, and outputs themselves become discoverable electronically stored information.
Depending upon how AI is used, prompts may reveal:
Those questions will undoubtedly receive increasing judicial attention.
Digital WarRoom addresses this concern by limiting AI to supporting documented analytical processes rather than generating undisclosed legal conclusions.
AI may assist with:
The final work product, however, remains fully auditable and reviewable by attorneys through traditional eDiscovery tools, including Boolean searches, issue coding, and documented review decisions.
This preserves transparency while reducing the risk that undisclosed AI reasoning becomes an issue during later discovery disputes.
Best Practices for AI Protective Orders
Rather than prescribing particular software products, Digital WarRoom believes protective orders should focus on objective security requirements.
Reasonable safeguards include:
These safeguards directly address the risks courts seek to manage while allowing organizations to select technology appropriate for the size and complexity of each case.
Looking Forward
Every major technological advance in litigation has faced initial skepticism.
- Email.
- Cloud computing.
- Technology-assisted review.
- Predictive coding.
- Cloud-hosted eDiscovery platforms.
Each ultimately became accepted because the legal profession developed defensible workflows that balanced efficiency with reliability.
Generative AI is following the same path.
The objective should not be to prohibit AI or require the most expensive technology available. Instead, courts and litigants should encourage secure, transparent, attorney-supervised AI implementations that improve efficiency while preserving confidentiality and procedural fairness.
Digital WarRoom believes the future of AI-assisted eDiscovery lies in auditable workflows, measurable security controls, documented attorney oversight, and proportional implementation. When AI is deployed responsibly, it can significantly reduce litigation costs, improve document analysis, and make sophisticated eDiscovery capabilities available to organizations of every size.
Ultimately, the question should never be, “How expensive is the AI platform?”
The better question is, “Can this workflow demonstrate that confidential information remained protected, attorney judgment remained in control, and the resulting review process is fully defensible?”
That is the standard that will best serve litigants, courts, and the future of eDiscovery.



Comment On This Article