/ 3 min read

Whose Data Is It? A Colorado Magistrate Draws the Line on AI in Protective Orders

A magistrate judge in the District of Colorado recently weighed in on how AI fits into discovery, and it's a useful order for anyone writing about protective orders right now. 

In Dunn v. LexisNexis Risk Solutions, Inc., No. 26-cv-01249-GPG-MDB, 2026 U.S. Dist. LEXIS 196677 (D. Colo. Aug. 31, 2026), the parties had actually agreed on almost everything about how AI could be used with confidential discovery material.  Their agreed provision said you can't dump confidential info into just any AI platform, but you can use secure ones that don't train on your data, don't disclose it, and let you delete it, and they even named the specific tools they planned to use.  The one thing they couldn't agree on was a single extra sentence, which the court called the "Additional Disputed Language."

Here's what that sentence would have done: every time a party wanted to use a new AI tool, it would have to disclose the tool, get the other side's consent, and formally amend the protective order.  The judge wasn't buying it as a mere "transparency" measure, and instead saw it as a consent-and-amend process that would drag everyone back into motion practice every time someone tried a new tool.  Since the agreed language already set clear, tool-agnostic rules that competent lawyers could apply themselves, the court found the extra sentence unnecessary and struck it, granting the motion but entering the order without it. 

The plaintiff tried to argue that AI risks "are identical to those inherent in using any cloud storage service," and the court pushed back.  It acknowledged that in its own earlier Morgan v. V2X decision, No. 25-cv-01991-SKC-MDB, 2026 U.S. Dist. LEXIS 67939 (D. Colo. Mar. 30, 2026), it had noted real similarities (running data through an AI tool is a bit like running it through email, and you don't automatically give up your privacy either way), but it stressed that similar is not the same, because AI systems are newer, more opaque, and still evolving, which makes them riskier when someone else's data is on the line. 

This is really why the court distinguishes Morgan: it comes down to whose data is at stake. The court read Morgan as answering two separate questions, one about whether a litigant's own use of AI waived work-product protection, and a separate one about protective-order terms governing an opponent's information.  The logic is intuitive once you see it: when you upload your own stuff, you knowingly accept whatever small risk comes with it, but when you hand confidential material to your adversary, you can't manage that risk yourself without an agreement or a court order, and that shifts the whole calculus toward keeping opponents' data out of consumer-grade AI. 

Key Takeaway

Courts drawing up AI provisions seem to prefer real, substance-based guardrails – no training, no disclosure, deletion rights – over procedural gatekeeping that forces the parties back into court for every new tool.  And the reason Dunn distinguishes Morgan is because Morgan's privacy-friendly reasoning was about a party's own data, while Dunn is about protecting the other side's data, and that "whose data is it" distinction is the whole ballgame.