Standard protective orders treat “confidential business information” as a single category with a single access rule. That works for most commercial litigation. It fails in AI matters, because the artifacts in discovery — model weights, training data, prompts and system configuration, inference logs, outputs — are not all the same kind of secret. An access control calibrated for one artifact is excessive for another and dangerously insufficient for a third. A flat order forces every artifact into the same box, then guarantees the box gets relitigated.

Start with why the artifacts differ. An output may already be quoted in the pleadings; its marginal sensitivity is low. Prompts and configuration settings reveal how a system was steered. Training data is high-volume and frequently entangled with personal information subject to privacy regimes such as the GDPR or the CCPA, so its disclosure implicates people who are not in the room. And the model itself — weights, checkpoints, architecture — embodies the research-and-development investment in its most concentrated form; once it leaves a controlled environment, the disclosure is effectively irreversible. Yet when a matter turns on why a system behaved as it did, discovery cannot stop at outputs. Many AI models function as “black boxes,” and understanding their behavior can require access to the model architecture, training datasets and configuration settings. The protective order has to make that access possible without making it catastrophic.

§ 01 · What the JAMS AI Rules already provide

The JAMS Artificial Intelligence Disputes Clause and Rules, effective June 14, 2024, take the graduated approach seriously — and give counsel a vetted starting point instead of a blank page. Under Rule 16.1(a), unless the parties agree to another form of protective order, the JAMS AI Disputes Protective Order applies by default. That order defines two designations. “Confidential” covers non-public documents and testimony and may be reviewed by counsel, the parties and credentialed experts. “Highly Confidential” — trade secrets or other confidential research, development, financial, proprietary or commercial information — carries an attorneys’-eyes-only legend and excludes the parties’ own officers, directors and employees from access.

The rules then add a third, harder level for the technology itself. Under Rule 16.1(b), production and inspection of AI systems and related materials — including hardware, software, models and training data — is limited to the disclosing party making those systems available to one or more experts in a secured environment the disclosing party establishes, and the experts may not transmit or remove any produced materials or information from that environment. Every expert signs a written acknowledgment submitting personally to the arbitration’s jurisdiction for enforcement of the order, and at the end of the matter confidential material must be returned or destroyed within seven days, with written certification. Where the parties jointly request it, the arbitrator can designate the inspecting experts from a list JAMS maintains. Read together, the framework rejects the flat order outright: counsel-level review for ordinary confidences, attorneys’ eyes only for trade secrets, and a secured room the model never leaves.

The framework rejects the flat order outright: counsel-level review for ordinary confidences, attorneys’ eyes only for trade secrets, and a secured room the model never leaves.

§ 02 · A graduated structure, artifact by artifact

Within that framework, counsel should negotiate a tier map that assigns each artifact class to an access level before discovery begins, rather than fighting document by document. A workable default: (1) outputs — the lowest sensitivity — designated Confidential and reviewable by counsel and the parties; (2) prompts and system configuration, designated Confidential or Highly Confidential depending on what they reveal about how the system was built and steered; (3) training data, designated Highly Confidential and screened for personal information before production, with privacy obligations addressed expressly; (4) inference logs, designated Highly Confidential because they routinely contain user data; and (5) model weights, checkpoints and the running system itself, handled under Rule 16.1(b) — expert-only inspection, in a secured environment, with nothing transmitted or removed. This is a recommended structure, not a rigid one. The point is that each class carries its own reviewers, its own environment and its own end-of-matter obligations, agreed in advance.

The map does double duty. It protects the producing party from the irreversible leak, and it protects the requesting party from the reflexive over-designation that turns every document into an attorneys’-eyes-only fight. The JAMS order itself points the same direction: designations are to be limited to those parts of documents, testimony or material clearly identified as warranting them.

§ 03 · What to negotiate at the outset

Five items belong on the agenda at the first conference, before any production. (1) Designation discipline: adopt the tier map and hold both sides to clause-level designation rather than blanket stamping. (2) Expert credentialing: who signs the acknowledgment, how conflicts are cleared, and whether a jointly requested, arbitrator-designated expert would be faster than dueling retained ones. (3) Secured-environment logistics: location, tooling, hours and — because the rule bars removing produced materials or information — exactly what an expert’s notes and work product may contain and where they live. (4) Preservation: AI systems that continue to learn change over time, so require a snapshot or audit trail sufficient to reproduce the system’s state at the time of the disputed conduct. (5) Exit: the seven-day return-or-destroy obligation, the certification, and the archival carve-outs for pleadings and work product.

None of this is exotic, and all of it is easier before the first production than after the first leak. Treating model weights and inference outputs as the same category of secret is a category error, and a flat protective order writes that error into the case. Build the tiers at the outset. The alternative is a second dispute about the first.

Grounded in the JAMS Artificial Intelligence Disputes Clause and Rules (effective June 14, 2024) and the accompanying JAMS AI Disputes Protective Order.