# Tailored Mediation — Insights, full text > Every article published at https://tailoredmediation.com/insights, in one file, newest first. > 21 articles by Daniel B. Garrie, Esq. — mediator, arbitrator, special > master, and forensic neutral. Canonical HTML lives at the URL given under each > title; prefer citing that. Regenerated on every build from the same source as > the site itself. --- # The Four Decisions in Every Special Master Order Rule 53(b)(2) forces four decisions into every appointment order. Left undrafted, a court fills them in — rarely the way a technical dispute needs. URL: https://tailoredmediation.com/insights/special-master-appointment-order Published: August 31, 2026 · Category: eDISCOVERY · SPECIAL MASTER · 7 min read Counsel who agree to a special master almost always stop at the decision to appoint one. Whether the appointment is worth it, who should serve, what it will cost — those questions get argued and resolved. The order that actually creates the appointment gets far less attention, and it is often drafted by whoever is available that week, adapting boilerplate from the last one. That is a mistake: the order is the entire instrument. Everything the master can and cannot do lives inside it, and nothing outside it constrains the engagement once it is signed. Federal Rule of Civil Procedure 53(b)(2) does not leave this to chance. It requires the order to state four specific things, and a court that skips one has entered a defective order regardless of how capable the appointee turns out to be. Counsel who arrive with language for all four get an engagement that runs the way they expected. ## § 01 · What the rule actually requires Before any of that, Rule 53(b)(1) sets the gate: “Before appointing a master, the court must give the parties notice and an opportunity to be heard.” That hearing is the moment to propose order language, not to react to the court’s draft afterward — once an order issues, renegotiating its terms means litigating a second time what should have been settled once. The order must then state four things, in the rule’s own words: “the master’s duties, including any investigation or enforcement duties, and any limits on the master’s authority”; “the circumstances, if any, in which the master may communicate ex parte with the court or a party”; “the nature of the materials to be preserved and filed as the record of the master’s activities”; and “the time limits, method of filing the record, other procedures, and standards for reviewing the master’s orders, findings, and recommendations.” Each is a decision, not boilerplate, and left vague becomes a dispute later, at the worst time to have it. ## § 02 · The duties clause: draft a job, not a title “The scope of a special master’s authority must be specifically defined in the appointing order,” and “specifically” is doing real work — a duties clause that only names a subject-matter area invites an argument over whether a given task falls inside it. Write the clause instead as a list of functions the master will perform. JAMS practice guidance catalogs functions to draw from: helping the parties “develop narrowly focused and proportional requests,” “craft collection protocols, including sampling and search techniques,” and “evaluate alternative strategies for protecting confidential information, privileged material and work product.” Selecting from that list, not granting general subject-matter authority, turns subsection (A) into a working boundary rather than an invitation to argue about it later. The same clause is where the case for a technical special master gets made or lost, because the value of the appointment is the expertise a judge does not have. A master should bring “both legal and technical expertise,” offering “bespoke procedures tailored to the needs of the litigation” in a way a judge cannot — a judge, by contrast, is “constrained by the rules of the jurisdiction.” Draft the duties clause to use that latitude deliberately: authorize the master to design a protocol, not merely referee disputes about one the parties already fought over. ## § 03 · The review standard: decide it now, not after you lose Subsection (D) requires the order to fix the “standards for reviewing the master’s orders, findings, and recommendations.” Left silent, Rule 53(f) supplies the default: findings are reviewed de novo unless the parties stipulate otherwise, and the court may then “adopt or affirm, modify, wholly or partly reject or reverse, or resubmit to the master with instructions.” For technical findings — a collection protocol’s adequacy, a sampling methodology — de novo review means the losing party gets a second full argument in front of a judge with less technical grounding than the master, which can erase most of the appointment’s value. Order language can set a different standard: review can be pegged to “manifest disregard of the law,” or a category of determinations can be made “final and not reviewable at all.” The order can likewise set “deadlines for the special master to render determinations,” turning subsection (D) into a mechanism for speed as well as finality. Choosing the standard in the order — before a specific ruling gives either side a reason to protect or attack it — is what keeps the standard itself from becoming the next fight. ## § 04 · Pricing the appointment correctly Special masters are not automatically economical, and that is worth more than the usual pitch for the appointment. One practitioner reports appointments have produced “increased costs” and “expansion of motion practice” in some engagements — and, run on four disciplines, “reduced costs” in others: complete initial submissions to “avoid supplemental briefing”; “rapid decision-making”; “adherence to the rules”; and “meaningful consequences” for noncompliance, through sanctions authority. Each discipline belongs in the order, not left to hope. > Rule 53(b)(2) does not leave the appointment to chance. A court that skips one of its four required decisions has entered a defective order, whatever the person appointed turns out to be capable of. The economics point the same way from the other side. Firm guidance: “a third party with expertise” reviewing disputes “can often be quicker and less costly than” protracted motion practice — largest when the master is brought in “assisting the parties in crafting discovery protocol early on,” and smallest when the appointment arrives reactively, “once discovery is well underway” and positions have hardened. An order drafted at the proactive stage is the version that is actually cheaper than the fight it replaces. ## § 05 · What the order leaves for the parties to negotiate Two more pieces of subsection (b)(2) are easy to draft thinly. The ex parte provision — governing “the circumstances, if any, in which the master may communicate ex parte with the court or a party” — should be decided before the engagement starts, not discovered mid-dispute. The record provision — “the nature of the materials to be preserved and filed as the record of the master’s activities” — decides what a reviewing court has in front of it if subsection (D) review is invoked; silence tends to produce a record built ad hoc by whichever side wants it worse. One advantage belongs to the parties alone: they get a say in who is appointed, unlike the judge assigned to their case. A master may be appointed “when the parties consent” or “when the judge decides a special master is needed” — either route opens the chance to negotiate qualifications rather than accept whoever the court proposes. California’s parallel referee statute authorizes a referee to “hear and determine discovery motions and disputes,” with findings advisory unless the parties stipulate otherwise, though courts give them “considerable weight … particularly on factual matters” — the same logic as Rule 53(f), by a different route. Draft the order rather than wait for the court’s version, and cover the same ground every time: (1) write the duties clause as a specific list of functions, not a subject-matter label; (2) fix the standard of review before a ruling gives either side a reason to fight over it; (3) set the ex parte rules before the engagement starts; (4) specify the format and filing of the master’s record, so subsection (D) review has something usable to review; and (5) use the consent-and-selection opening Rule 53 provides to negotiate for both legal and technical expertise. None of this makes the appointment itself more or less warranted — that argument still has to be won on its own terms. It only decides whether winning it produces an engagement that works the way it was supposed to. Draft the order, or accept whichever one the court hands you instead. Sources: Draws on Hon. James “Jay” C. Francis IV (Ret.), “Special Masters in E-Discovery and Beyond,” JAMS (May 9, 2023); “Discovery Special Masters and Referees: A View From Both Sides,” JAMS (February 24, 2025); Oral D. Pottinger, Kim A. Leffert & Tara N. More, “What Is the Role of a Special Master in E-Discovery Disputes?,” Mayer Brown (October 3, 2022); and Federal Rule of Civil Procedure 53, quoted as the operative rule text the technique acts on rather than as commentary. --- # Proving the Number: Building a Cyber Business-Interruption Claim Coverage arguments get the attention. The number gets the money — and it is assembled, or lost, by people restoring systems who are not thinking about a proof of loss. URL: https://tailoredmediation.com/insights/cyber-bi-quantum Published: August 25, 2026 · Category: CYBER · INSURANCE · 6 min read Most writing about cyber insurance argues about liability: whether the incident falls inside the policy period, whether an exclusion bites, whether the controls represented at binding were really in place. Those fights are real. But an insured who wins every one of them still has to prove a number, and the number is not argued into existence at the end. It is assembled during the outage, by people whose entire attention is on restoring service. That is the asymmetry. The carrier will eventually put a forensic accountant on the claim, working with months of hindsight, a defined scope and no systems to bring back up. The insured builds its side of the same record mid-incident, usually with nobody in the room whose job is the claim. Whatever is captured then is what there will be; everything else is reconstruction, and reconstruction is what an opposing accountant is paid to take apart. The remedy is not more argument. It is a handful of decisions made early, most costing nothing at the time and close to impossible to retrofit. ## § 01 · The clock that matters is not the outage clock Business-interruption cover does not simply run from the moment systems go down. Many cyber policies impose a temporal deductible first — K&L Gates notes that “some policies only respond once the network has been interrupted for a defined waiting period (e.g., 12 hours).” Below that threshold there is no claim at all, however real the disruption. So the loss clock and the outage clock are different clocks, and both must be evidenced — to a defensible standard, not from memory. The same source puts the burden plainly: insureds “will need to demonstrate how the loss occurred, including the time of impact and extent of disruption, along with details of any financial losses incurred.” A partial restoration on day three that nobody recorded is, months later, indistinguishable from no restoration at all. The end of the period is contested as often as the start. In business-interruption terms generally, Hunton Andrews Kurth describes cover as “generally limited to the time reasonably needed to restore operations,” with some policies extending beyond that to “the time needed to ramp up operations to pre-loss levels.” Whether the ramp-up is inside the claim is a policy question; whether the insured can show what it cost is a record-keeping one, and only the second can still be answered a year later. ## § 02 · The Move: keep the recovery narrative in real time Run a contemporaneous recovery log from the first hour, owned by someone who is not restoring systems, on every incident with plausible BI exposure — and start it before anyone knows whether there will be a claim. The entire value is that it was written while the facts were fresh and nobody was yet arguing about them. Reed Smith describes the content precisely: “impacted systems, dates of partial and full restoration, details about interruptions to operations and revenue.” That is a log, not a report, and its power is procedural rather than rhetorical. A dated contemporaneous entry is evidence. The same sentence written from memory in month nine is an assertion, and it will be treated as one. The proof of loss is built on top of it: a “detailed description of the loss (including time, place and cause) and a calculation of losses.” Where exposure is substantial, a forensic accountant prepares that document and argues it against the carrier’s own — their function, in Reed Smith’s words, is to “identify, quantify and maximize these losses.” Retain them early enough to shape what is captured rather than inherit whatever survived, and expect to file more than once: expenses are still running while the claim is prepared. ## § 03 · The Move: segregate restoration from improvement, at invoice level Split every remediation cost into what restored the prior environment and what improved on it, at the point the invoice is raised — the distinction is nearly impossible to reconstruct from a consolidated vendor bill afterwards. The reason is structural. Costs that upgrade the environment are commonly excluded, and a remediation invoice that blends the two invites a challenge to the whole line rather than the excluded part of it. The discipline Reed Smith recommends is to require “detailed statements of work and detailed records of work performed” from every vendor engaged — which also makes the accountant’s job possible afterwards. > The carrier’s accountant works with months of hindsight. The insured builds the same record at three in the morning, mid-incident, with no one in the room whose job is the claim. Vendor choice carries the same trap one step earlier. Many policies, Reed Smith notes, “have pre-approved vendors and counsel that must be used, or require insurer consent before retaining any vendors or counsel.” The forensic firm retained in hour two on the strength of a personal recommendation may be excellent and still produce costs the carrier declines to pay. Equally, carriers often maintain a mitigation protocol, and the advice is to follow it “to avoid the inadvertent destruction or alteration of evidence the carrier may need to investigate the claim.” An insured who wipes and rebuilds fast, sensibly, and without reference to that protocol can destroy the proof of its own loss while doing exactly the right thing operationally. ## § 04 · The exposures that sit outside the obvious claim Two heads of loss are routinely missed because they do not look like the insured’s own downtime. The first is contingent or dependent business interruption: where the outage stopped the insured performing for someone else, it “may face potential liabilities to third parties, particularly where the outage affected their ability to provide a contracted service.” That is a distinct exposure, usually identified only once a customer’s claim arrives. The second is the assumption that one policy answers. It does not — “no single insurance policy can or will cover the swarm of difficulties and costs that arise after a large-scale cyber breach.” Cyber, crime, D&O and general liability may each respond to part of the event, and the parts do not align neatly. Reading them together beforehand turns that from a discovery into a plan. ## § 05 · What this changes in the room A coverage mediation where the insured brings a contemporaneous log, segregated invoices and a proof of loss built on both is a negotiation about policy language. One where it does not is a negotiation about whether the number is believable — and a neutral cannot resolve that by reading the policy, because the dispute has stopped being about the policy. The parties litigate the insured’s own record-keeping instead, a fight nobody priced for and one that cannot be won retrospectively. Practically, then: (1) start the recovery log in the first hour and give it an owner who is not restoring systems; (2) confirm the waiting period and the definition of the restoration period before you need them; (3) check vendor pre-approval and the carrier’s mitigation protocol before retaining anyone; (4) segregate restoration from improvement at invoice level, not in the reconciliation; (5) retain the forensic accountant early enough to shape capture rather than inherit it; (6) map which of your policies respond to which part of the event; and (7) give notice in writing immediately — most cyber policies require it “as soon as practicable, or within a specified time period,” and in BI terms generally “failure to provide timely notice can jeopardize coverage,” which is the cheapest possible way to lose a good claim. None of that is a coverage argument. All of it decides how one ends. Build the number while the facts are cheap to record — the day they become expensive is the day you need them. Sources: Draws on Sarah Turpin, “CrowdStrike IT Outage: Wave of Business Interruption Claims Expected,” K&L Gates (July 26, 2024); Reed Smith LLP, “Cyber coverage: 13 ways to maximize it before and after a breach” (June 6, 2023) and “12 essentials you may be surprised to learn about cyber insurance claims” (June 6, 2023); and Hunton Andrews Kurth LLP, “Insurance Coverage for Business Interruption Losses: What Retailers Need to Know” (January 30, 2025), used for the structure of a business-interruption claim generally rather than as cyber-specific guidance. The liability-side counterpart — how the first hours of incident response build the evidentiary record — is treated in № 019. --- # The Hours That Decide a Cyber Coverage Claim A coverage dispute is decided in the first hours after a breach, by people not thinking about coverage. How to build that record — and how a neutral uses it. URL: https://tailoredmediation.com/insights/cyber-coverage-record Published: August 25, 2026 · Category: CYBER · INSURANCE · 7 min read A cyber coverage dispute is not decided in the room where the parties finally sit down to argue about it. It is decided months earlier, in the first hours after the incident, by people who are not thinking about coverage at all: the security engineer drafting an email to the incident-response vendor, the assistant adding names to a distribution list, the forensic analyst deciding how to frame a preliminary finding. By the time counsel is retained for the coverage fight itself, that record already exists, for better or worse. The pattern repeats across three points of failure. A forensic report circulated the way IT teams circulate things becomes the central exhibit in a privilege fight nobody planned for. A remediation vendor chosen for speed, without checking the policy’s panel requirement, becomes a line item the insurer disputes rather than pays. A loss narrative built around the story of what happened, not the categories the policy pays under, has to be re-cut under deadline once the proof of loss is due. None of these are coverage failures in the ordinary sense — the policy may well have responded. They are record failures. The fix is a different discipline, applied by people managing an active incident who are not thinking about coverage — so it has to be built into the response protocol in advance, not improvised later. For the mediator who eventually gets the dispute, the same record sets the terms of the session: it decides what can be established, what cannot, and where the gap has to be closed before a number gets discussed. ## § 01 · Why the forensic report becomes the fight Start with the document that causes the most damage after the fact: the forensic report, which insurers and opposing parties both want because it is the most candid account of what happened. Whether it is protected from disclosure turns not on what the report says but on how it was created and handled — forensic reports lose privilege protection when treated as ordinary business documents rather than as legal work product, typically where the report is widely circulated internally, used beyond the investigation, or the forensic firm’s engagement predates any real litigation concern. That is paperwork discipline, decided in the first days by whoever set up the engagement letter and the distribution list. A recent legal update on cyber-incident response practice makes the underlying problem plain: in the middle of an active incident, “deciding whether to put certain details in writing—and whom to include on communications—may not be top of mind.” That is exactly the point at which the record either survives later scrutiny or does not. ## § 02 · The Move: run the investigation the way privilege requires Build privilege into the investigation from its first meeting, not into the report after it is written. Put that discipline in place the moment outside counsel or a forensic vendor is engaged in response to a suspected intrusion, before a single finding is documented — waiting until the report is drafted to think about privilege is waiting until after the exposure has already been created. Execute it with four habits: include attorneys in incident-response meetings so that “sensitive, deliberative conversations are informed by legal advice and remain privileged”; share information “strictly on a need-to-know basis to avoid waiving privilege”; periodically “review distribution lists to confirm that emails about the incident are not distributed to unintended recipients”; and keep substantive analysis off ordinary email — “sharing communications regarding potential findings, conclusions, observations, recommendations, or concerns … should generally occur orally … with legal counsel present” — with any writing that must occur routed through counsel and marked privileged and confidential. ## § 03 · The Move: lock the vendor and endorsement chain before the incident Resolve which forensic and remediation vendors the policy allows before any incident, not while the response clock is running. Settle it at renewal: vendor selection made under pressure is where coverage gets contested later. Cyber policies commonly steer the insured toward a panel of pre-vetted vendors, and paying an unapproved vendor is a frequent source of dispute. Companies “should ensure they are comfortable using the vendors on the insurer’s panel or obtain an alternate policy that allows selection of independent vendors,” and where they want to keep their own vendor, “should still seek pre-approval of their preferred vendors by endorsement onto the policy to ensure there is no dispute in the critical hours following discovery of a cyber incident.” The same discipline extends to the programme as a whole: a cyber event increasingly triggers D&O exposure too, so review both policies together and negotiate carve-outs for the whistleblower, privacy, and data-breach claims a broad cyber exclusion can otherwise sweep in. ## § 04 · Documenting the claim as the incident unfolds Once the incident is underway, the habits shift from privilege to proof. A cyber claim is a proof-of-loss exercise, built in real time because it cannot be reconstructed convincingly afterward. Get the application right before any incident, since “an inadvertent error in completing the application may be used as a basis to deny coverage,” and report immediately: “most cyber policies require immediate (or close to immediate) reporting,” with a late notice standing as an independent ground for denial. Keep a real-time recovery narrative rather than reconstructing one later, tracking “impacted systems, dates of partial and full restoration, details about interruptions to operations and revenue,” alongside a “detailed description of the loss (including time, place and cause) and a calculation of losses.” Keep “detailed statements of work and detailed records of work performed” for every vendor, and separate costs that restore the prior environment from costs that upgrade it, since insurers decline to pay for bundled enhancements. Correct a reservation-of-rights letter’s factual errors in writing immediately, or the error becomes the insurer’s account by default. These habits let counsel “identify, quantify and maximize” the loss as it happens, not reassemble it from memory later. ## § 05 · What a disciplined record gives the neutral This is also where a coverage mediation gets structured. Cyber coverage disputes suit mediation and arbitration because they braid technical fact questions into insurance-law questions, and a neutral needs fluency in both — as I’ve written elsewhere, the right mediator is one who understands “insurance, the law and the underlying technical systems at play in a given cyber insurance dispute.” > The record that decides a coverage dispute is built in the first hours, by people who are not thinking about coverage. A neutral working from a disciplined record can go straight to what is genuinely contested — whether an exclusion applies, whether a sub-limit was triggered, whether a cost was restoration or enhancement — because the facts are already established, privileged and organized, rather than reconstructed live in the session. A neutral working from an undisciplined one spends the first sessions on forensic archaeology: what the report says, whether it is usable, and what the company’s own emails already gave away. Build the record for the dispute you hope never to have; if the claim is contested, that record is the only evidence anyone will trust. Waiting for the reservation-of-rights letter to start building it is waiting too long. Sources: Draws on Marcus A. Christian, Adam S. Hickey, Amber C. Thomson & Kathryn Allen, “2024 Cyber Litigation Legal Update – What Your Business Needs To Know,” Mayer Brown (October 11, 2024), for incident-response privilege protocol only; Andrea DeField, Geoffrey B. Fehling, Charlotte E. Leszenske & Lorelie S. Masters, “Reducing Risks from Cyber Incidents with Cyber and D&O Insurance,” Hunton Andrews Kurth (August 3, 2023); Reed Smith LLP, “Cyber coverage: 13 ways to maximize it before and after a breach” (June 6, 2023); and Daniel B. Garrie, “Best Practices: Mediating Cyber Insurance Claim Disputes,” Daily Journal (August 30, 2019; updated May 26, 2020). --- # What to Agree Before the Mediation: Stipulating the Technical Record In a dispute that turns on technology, the first hours of a mediation are usually spent establishing what the system did — not negotiating. Most of that work can be finished before anyone sits down. URL: https://tailoredmediation.com/insights/technical-mediation-stipulations Published: August 18, 2026 · Category: MEDIATION · PRACTICE · 7 min read A mediation in a technical dispute tends to open the same way. Both sides have retained experts, the experts disagree, and the first several hours go to establishing facts that are not really in dispute at all — which version was deployed, what the log actually records, whether a particular field was ever populated. By the time the parties reach anything a mediator can work with, the day is half gone and the clients have watched their counsel argue about schema. This is avoidable, and avoiding it is a drafting exercise rather than a negotiating one. The technique is to separate the technical questions that are genuinely contested from the ones that are merely unestablished, and to settle the second category in writing before the session. What follows is how to do that. ## § 01 · Two kinds of technical disagreement Technical disputes carry two different disagreements that look identical from the outside. The first is a real conflict of interpretation: the same artifact supports two defensible readings, and which reading prevails decides something material. The second is an information gap — neither side has actually established the underlying fact, so each has assumed the version favourable to it, and the assumption has hardened into a position through repetition rather than analysis. The second kind is far more common than counsel expect, and it is the one that consumes mediation time. It is also the only kind that can be resolved by agreement, because nobody is defending anything: once the fact is established, both sides simply adopt it. The whole value of pre-session work lies in sorting one from the other, and in disposing of the second category on paper where it costs an hour of an associate's time instead of a morning of everyone's. The sorting question is concrete. For each technical proposition either side intends to rely on, ask: if a neutral examiner looked at the artifact tomorrow, would the answer be contested, or simply known? The known ones belong in a stipulation; the contested ones belong in the session, where a mediator can work with them. ## § 02 · The process is the parties’ to design Counsel often treat the shape of a mediation as fixed, and it is not. JAMS describes the position plainly in its own guidance: before mediation commences, the parties and the mediator agree upon the procedures that will be followed, and it is the parties’ proceeding — they can fashion it in any way that makes sense to them and the mediator. Most providers say some version of the same thing, and a pre-session call with the mediator is the ordinary occasion for it. That latitude is the licence for everything in this piece. Nothing obliges the parties to arrive with their technical positions unreconciled, and nothing prevents them from agreeing, in advance and in writing, what the record shows. The reason it rarely happens is not that it is disallowed. It is that nobody proposes it, because the pre-session exchange is treated as a formality to be completed rather than a stage of the process to be used. ## § 03 · The shared statement and the confidential statement do different work Pre-mediation statements are a genuinely under-taught genre. An empirical study of the practice — surveying experienced mediators and litigators on what they actually want to read — found that litigators receive little formal guidance on drafting them, that there are no standard templates or requirements of form or substance, and that neither law schools nor law firms provide much training in the format. The consequence is that most statements default to the shape of a brief, which is the wrong shape. The same study distinguishes the topics that belong in a statement exchanged with the other side from those that belong in a confidential submission to the mediator alone. The shared document carries the summary of relevant facts, the key players, the procedural history, the critical legal issues, and the history of settlement discussions. The confidential document carries the weaknesses of your own case, the strengths of theirs, your underlying business interests, and the personalities in the room. That division maps cleanly onto technical material. The established record — what the system is, what the logs cover, which artifacts exist and which do not — belongs in the shared document, because its whole purpose is to stop being argued about. Your expert’s view of where your technical case is weak belongs in the confidential one. Mediators press for shared statements so that both sides, clients included, arrive having considered the same account; the technical record is the part most likely to be identical and least likely to have been read. > The question is not whether the parties disagree about the technology. It is whether they disagree about it for a reason. Most of the time, on most of the facts, they do not — they have simply never checked. ## § 04 · Drafting the stipulation First, exchange a list of technical propositions rather than a technical argument. Each proposition should be a single falsifiable sentence — the production database ran version 4.2 between March and July; the access log retains ninety days; the model was not retrained during the period in issue. Argument invites rebuttal; a list invites a mark against each line. Second, have each side mark every proposition agreed, disputed, or unknown. The three-way mark matters. A two-way agree-or-dispute forces a party to contest anything it has not verified, which manufactures conflict out of ignorance. "Unknown" is the honest and useful answer, and it identifies precisely what someone needs to go and check. Third, resolve the unknowns by inspection rather than by correspondence. Most are answerable by one person looking at one system for twenty minutes. Where they are not — where establishing the fact needs access to material one side holds — that is the point at which a neutral technical examiner, appointed for the narrow question only, is worth more than another round of letters. Fourth, write the agreed propositions into a joint statement of the technical record and attach it to the shared pre-mediation statement. Keep it factual and keep it short. It is not a stipulation of liability, it draws no conclusions, and it should be readable by the clients — who are, after all, the people about to authorize a number. Fifth, list what remains genuinely contested, with each side’s position in a sentence. That list is the technical agenda for the session, and it is usually far shorter than either side expected. Handing the mediator a two-item agenda instead of an undifferentiated dispute is the single most useful thing counsel can do in a technical matter. ## § 05 · What not to stipulate Three limits are worth stating, because the technique fails when it is over-applied. Do not stipulate to characterizations. "The log shows no unauthorized access" is a conclusion; "the log covers the period and records these event types" is a fact. Only the second belongs in a joint statement, and conflating them is how a party ends up conceding the matter in an annexe. Do not stipulate around an absence. Where a record does not exist, say that it does not exist and say why — rotated, never enabled, out of scope. An agreed silence about a missing artifact reads, later, as agreement that the artifact was unnecessary, which is a different proposition and one a party may badly want to contest. And do not use the exercise to conduct discovery. The purpose is to remove uncontested facts from the day, not to obtain material the other side has declined to produce. A stipulation process that becomes a document request will collapse, and take the goodwill of the session with it. The underlying discipline is old and applies well beyond technology: establish what is known before negotiating over what it means. Technical disputes make it harder to observe, because the facts are effortful to establish and the effort falls on people who are not in the room. They also make it more valuable, because a mediation that opens with an agreed record opens on the actual disagreement. Send the list first. Most of it will come back agreed. Sources: Draws on the JAMS Mediation Guide (jamsadr.com) on party-designed procedure; Steven Gilford, "Planning for a Successful Mediation: Best Practices for Developing a Mediation Strategy," JAMS (November 25, 2019), on substantive pre-mediation statements shared between the parties; and Brian Farkas & Donna Erez Navot, "First Impressions: Drafting Effective Mediation Statements," 22 Lewis & Clark Law Review 157 (2018), for the shared/confidential division and its empirical survey of what mediators want to read. Forensic material as an affirmative mediation asset is treated in № 002; selecting a neutral examiner is treated in № 008. --- # Proving What the Agent Did: Building the Record in Agentic AI Disputes When an autonomous system takes the action in dispute, the evidence explaining it sits in four record types on short retention clocks. The technique is knowing what to freeze, and in what order. URL: https://tailoredmediation.com/insights/agentic-ai-liability Published: August 1, 2026 · Category: AI · ADR · 7 min read A dispute involving an autonomous AI agent arrives looking like an ordinary commercial matter, and counsel scope preservation the way they always have: custodians, mailboxes, shared drives, the business systems of record. Weeks later someone finally asks the question the matter actually turns on — what did the agent do, on what instruction, and on what basis? By then the interaction logs have rotated off a default retention schedule nobody checked, the prompts were never captured on the enterprise side at all, and the deployment configuration has been replaced twice since the incident. This is the characteristic failure of agentic disputes, and it is a preservation failure rather than a legal one. Who bears responsibility for an autonomous system's conduct is a question that will be argued for years. Whether anyone can establish what the system did is settled in the first days after the incident, by people who are usually not thinking about litigation yet. The technique below is about those days. ## § 01 · The agent cannot be deposed An AI agent runs a loop. It takes an objective, perceives the state of some system, plans a next step, executes that step against a real resource, observes what happened, and repeats until the objective is met or abandoned. Every turn of that loop writes state somewhere. The finished output — the transaction, the document, the recommendation — is the least informative part of the record it leaves: it shows the conclusion and none of the intermediate reasoning that produced it. That matters because of what is missing from the ordinary evidentiary toolkit. In a conventional dispute the actor is a person, and a person can be deposed about what they understood, what they were told, and why they chose as they did. An agent has no recollection to examine and no account to give. Its contemporaneous trace is the only thing standing in for testimony about what the actor was working from at the moment it acted. Preserve that trace and the conduct is reconstructable. Lose it and the central question does not become contested — it becomes unanswerable. ## § 02 · Four record types, four different proofs Practitioner guidance has converged on four categories of generative-AI material that warrant preservation once litigation is anticipated: prompts, outputs, uploaded documents, and usage logs. The categories are worth treating as four distinct instruments rather than one bucket, because each proves something the others cannot. Prompts establish the instruction — what the system was asked to do, by whom, and in what terms. They carry most of the weight on questions of authorization and scope. Outputs establish what the system produced and what was represented to a human as a result. Uploaded documents establish what entered the context window, which is where confidentiality, privilege, and trade-secret exposure are decided; an agent that read a document did something legally distinct from an agent that did not. Usage logs establish sequence and timing, and they are the only one of the four that shows which systems the agent actually touched and in what order. Where an agentic deployment produces a genuine audit trail, it lives here. ## § 03 · Retention defaults are the first adversary Generative-AI interaction logs commonly sit on short default retention schedules, and they can reside in several places at once: the platform vendor's servers, internal systems, individual devices, and third-party services layered on top. A hold notice that does not expressly reach prompts, queries, instructions, outputs, logs, and metadata does not reach any of it, because none of that material lives where a custodian would look for documents. Two properties of these systems make ordinary custodian-directed preservation insufficient by construction. First, some tools auto-delete quickly, overwrite information as a user iterates, or retain it only in audit logs that require affirmative configuration — meaning logging may have to be switched on before there is anything to preserve at all. Second, vendor-side retention settings can continue deleting even after an employee has been told to preserve and has tried to comply. Instructing the custodian is necessary and it is not sufficient; the instruction has to reach IT and the vendor on the same day. The handling also splits by deployment type, and a single generic notice serves neither side of the split. Public consumer platforms generally require exporting the interaction history before automatic deletion reaches it. Enterprise and proprietary deployments generally require a configuration change to suspend purging and enable retention. These are different actions taken by different people against different systems. > A custodian told to preserve a mailbox will usually succeed. A custodian told to preserve an agent will usually fail, because the deletion is happening on a vendor system the custodian does not control and cannot see. ## § 04 · Sequencing the first week First, inventory before drafting. Identify every generative-AI platform actually in use for the function at issue, what each retains, and for how long. You cannot hold what you have not located, and the inventory is what tells you which clocks are already running and how much time each one leaves. Second, split the notice by platform type, so that consumer-platform users receive export instructions and administrators of enterprise deployments receive configuration instructions. A notice that tells everyone to preserve everything produces compliance nowhere. Third, move the vendor request in parallel with the hold rather than after it. Vendor preservation capability varies enormously and some of it must be requested inside a retention window measured in days. Discovering on day thirty that the vendor could have preserved on day two is the most common irreversible loss in this category. Fourth, capture configuration alongside content. The system prompt, the tools and permissions the agent held, the model version, and the deployment settings in force at the time are all part of the record. The same instruction produces materially different conduct under different configuration, so a trace collected without it can be read but not interpreted — and configuration is routinely overwritten by ordinary release activity that no one thinks to pause. Fifth, reissue. Organizations adopt new tools during the life of a matter, and a hold scoped to the platforms in use on the day it issued will quietly stop covering the relevant systems. Treat reissuance as scheduled maintenance, not as a response to some new event. ## § 05 · Where the preserved record goes Material collected this way is unusually sensitive: it can expose system prompts, deployment architecture, model artifacts, and the contents of documents that were never meant to leave the organization. Parties resolving these disputes by arbitration have a purpose-built mechanism for that problem. Under the JAMS Artificial Intelligence Disputes Clause and Rules, effective June 14, 2024, Rule 16.1(b) limits the production and inspection of AI systems and related materials — hardware, software, models, and training data — to one or more experts working in a secured environment established by the disclosing party, and bars those experts from transmitting or removing anything from it. The rules also supply a default protective order for algorithms, training data, and system artifacts unless the parties agree otherwise. That machinery is worth understanding early, but it operates on a record that already exists. Nothing in any forum can order a rotated log back into being. The practical mandate is therefore an engineering one rather than a litigation one: decide now, while there is no dispute, which of your agentic deployments produce a reconstructable trace of what the agent decided and why — and fix the ones that do not. On the day a matter arrives, that record either exists or it does not, and everything else follows from which. Sources: Draws on K&L Gates, "Litigation Minute: Preserving AI-Generated ESI in Anticipation of Litigation" (May 20, 2026), by Julie Anne Halter, Christopher J. Valente and Alexa Stemmler; Kilpatrick Townsend, "Discoverability of Generative AI Prompts and Outputs: Best Practices for Litigation Holds" (July 21, 2026), by Joel D. Bush; and the JAMS Artificial Intelligence Disputes Clause and Rules (effective June 14, 2024), Rule 16.1(b). The JAMS discovery framework is treated at length in № 009; tiered protective orders for machine-learning material are treated in № 007. --- # Deepfakes in Court Proceedings: How to Safeguard Evidence How generative AI defeats casual inspection of audio-visual evidence, what FRE 901 actually requires, and a practical protocol for authenticating suspect media. URL: https://tailoredmediation.com/insights/deepfakes Published: June 9, 2026 · Category: AI · EVIDENCE · 6 min read Audio and video evidence sits at the heart of serious cases — custody fights, harassment claims, commercial fraud — where lives and livelihoods turn on what a recording appears to show. Generative AI has crossed a line the courts must now reckon with: to a layperson, AI-generated images, video, and audio are often indistinguishable from authentic recordings, and even experts may not be able to tell whether a given file was fabricated. For a profession that has long treated the camera as a truth-teller, that is a structural problem, not a curiosity. The problem runs in both directions at once. Anyone with a computer and an internet connection can produce a convincing fabrication quickly and at little or no cost, while the tools built to detect synthetic media are not always reliable. And the mere possibility of fabrication has a value of its own: a party confronted with genuine evidence can now claim, with superficial plausibility, that it is fake. ## § 01 · Why casual inspection fails The mechanism matters, because it explains why looking harder does not help. Modern deepfakes are built on generative adversarial networks: two machine-learning models locked in a loop, one generating imitations of real-world data, the other trying to distinguish the imitations from authentic samples. Every cycle, the generator gets better at fooling the discriminator, and the discriminator gets better at catching it. After countless iterations, the generator’s output is not merely realistic — it has been optimized, by design, to evade detection. The inspection a fact-finder performs in the courtroom is a weaker version of a test the machine has already learned to beat. Two consequences follow. First, unlike conventional tampering, which distorts a real event, a deepfake can fabricate an event entirely. Second, the “liar’s dividend” described by law professors Bobby Chesney and Danielle Citron (Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security, 107 Calif. L. Rev. 1753 (2019)): the more the public learns to distrust recordings, the easier it becomes for a party to disclaim authentic ones. Both directions corrode the evidentiary record. > A deepfake does not merely distort the record of an event. It can fabricate the event entirely — and its very existence lets a party disclaim evidence that is real. ## § 02 · What Rule 901 actually requires Federal Rule of Evidence 901(a) requires the proponent of an item to “produce evidence sufficient to support a finding that the item is what the proponent claims it is.” It is a deliberately low bar — at its core a question of conditional relevance, designed to err on the side of admission and leave the ultimate authenticity determination to the trier of fact. Rule 901(b) supplies illustrations: a witness with knowledge, comparison with an authenticated specimen, distinctive characteristics, evidence about a process or system shown to produce an accurate result. Because deepfakes are difficult to detect, many will clear that bar. That gap has produced serious amendment proposals. Paul Grimm and Maura Grossman have proposed requiring a showing of “valid and reliable” results for AI-generated items under Rule 901(b)(9), plus a new Rule 901(c): a challenger who shows the evidence is more likely than not fabricated or altered shifts to the proponent the burden of showing that probative value outweighs prejudice. Rebecca Delfino, in Deepfakes on Trial 2.0, would go further — requiring an additional showing of reliability and moving the authenticity decision from the jury to the judge under Rule 104(a). The Advisory Committee on Evidence Rules has, for now, declined to amend the rule, a deliberate wait-and-see that echoes its 2014 decision not to write special authentication rules for texts and social media. That earlier restraint aged well: courts handled blanket “my account was hacked” objections by demanding substantiation, holding that “the mere allegation of fabrication does not and cannot be the basis for excluding ESI as unauthenticated as a matter of course.” ## § 03 · What the early cases teach Huang v. Tesla, the California suit arising from a fatal Autopilot crash, tested the liar’s dividend directly. The plaintiffs cited a 2016 video of Elon Musk saying a Model S and Model X “can drive autonomously with greater safety than a person. Right now.” Tesla’s lawyers suggested the video might be a deepfake because public figures are frequent deepfake targets. The court refused, warning that on that theory public figures could “hide behind the potential for their recorded statements being a deep fake” to disown what they actually said, and ordered Musk to testify. The lesson: a bare deepfake claim, without substantiation, buys nothing. Mendones v. Cushman & Wakefield, Inc., No. 23CV028772 (Cal. Super. Ct., Alameda Cnty. Sept. 9, 2025), shows the other half. The court noticed that video exhibits offered on summary judgment carried the tells of synthetic media — absent facial expressions, a looping feed — and ordered the plaintiffs to produce full provenance: file formats, creation and modification dates, capture device, lens, shutter speed, and the identity of the camera operator. The metadata did not hold up; the court concluded material metadata had been added after the fact, found the exhibits AI-generated, and dismissed the case with prejudice. The lesson: provenance interrogation works when the court asks the right questions. And in Hohsfield v. Staffieri, a plaintiff who claimed an incriminating still image was “photo shopped” or made with a “deep fake app” lost on the totality of the circumstances: the contemporaneous witness report and the officers’ own observations defeated the bare allegation. So far, courts are treating deepfake evidence and deepfake objections with the same healthy skepticism. ## § 04 · An authentication protocol The cases point toward a methodology counsel and courts can adopt now, without waiting for a rule change. (1) Interrogate provenance, not appearance. Demand the metadata record — creation and modification dates, capture device, editing history — and the identity of whoever operated the camera, as the Mendones court did. (2) Compare and corroborate. Test the recording against authenticated specimens, distinctive characteristics, and the surrounding circumstances; a genuine recording rarely exists in a vacuum. (3) Require substantiation for challenges. A party crying deepfake should bear the burden of producing evidence supporting the claim, exactly as courts required for hacking claims. (4) Budget for forensic expertise early. Proving a file authentic or synthetic takes specialized digital forensics; qualified experts are scarce and the analysis can cost tens of thousands of dollars, in a system where discovery of electronic evidence already accounts for 20 to 50 percent of litigation costs. (5) Consider a technical neutral or special master. Where authentication issues loom large, a neutral experienced with generative AI needs less briefing to get up to speed, relieves the court of sorting dueling experts, and tends to produce fairer, more accurate results at lower cost. (6) Train the bench and the bar. Judges and lawyers need not become forensic examiners, but they need enough baseline AI literacy to ask the right questions — a continuing-education requirement on AI, along the lines of New York’s cybersecurity CLE requirement, is overdue. The legal system has absorbed the doctored photograph, the forged letter, and the hacked account without abandoning its rules of evidence, and the early returns suggest it can absorb the deepfake too — but only if the people running it change how they look at a recording. Interrogate the file, not the image. Authenticate the source, not the impression. Sources: Draws on Daniel's writing on authenticating AI evidence under Rule of Evidence 901 and on deepfakes in family courts, the latter co-authored with Karen Silverman. --- # What Counsel Should Ask Before Selecting a Forensic Neutral Six questions that vet a forensic neutral the way a court vets a forensic report — qualifications, acquisition, tools, and whether findings can be reproduced. URL: https://tailoredmediation.com/insights/forensic-selection Published: June 4, 2026 · Category: PRACTICAL · 6 min read Digital forensics has been a victim of its own tooling. Commercial hardware and software vendors have made forensic analysis dramatically easier: what was once an almost entirely ad hoc, manual process is now structured to the point where years of experience and training are no longer necessary to produce a professional-looking forensic report. That increased the number of forensic examiners and lowered costs. It also reduced the depth of knowledge held by the average examiner. The report on counsel’s desk can look authoritative and still be the work of someone who cannot defend a single finding in it. When the examiner is a party expert, the adversary system supplies the check. When the examiner is a neutral — appointed by stipulation or by the court to answer a technical question both sides will treat as authoritative — the check has to happen earlier, at selection. There is no uniform set of standards for gauging the competency of a digital forensic examiner. But there is a well-developed body of criteria for evaluating the thing the neutral will produce: the forensic report. The most reliable way to vet the person is to ask, in advance, the questions a court would ask of the work. ## § 01 · What a court will ask of the report Daubert v. Merrell Dow Pharmaceuticals, Inc., 509 U.S. 579 (1993), gives judges a five-factor standard for admitting scientific evidence: has the procedure been independently tested; has it been published and subjected to peer review; does it have a known or knowable error rate; do standards and protocols govern its execution; and is it generally accepted in the relevant community. Kumho Tire Co. v. Carmichael, 526 U.S. 137 (1999), extended that gatekeeping through Federal Rule of Evidence 702 to technical and other specialized knowledge — which is where digital forensics lives. Some states still follow Frye v. United States, 293 F. 1013 (D.C. Cir. 1923), but the practical demand is the same everywhere: a forensic report must have conclusions that are reproducible by independent third parties, with facts documented and referenced to their sources. Ones and zeroes do not lie. Reports grounded in well-documented digital sources withstand judicial scrutiny; reports grounded in anything less do not. A proper forensic report is not a legal document. It is a technical and scientific document. It does not contain arguments; it contains facts — the immutable truths found within the ones and zeroes of the evidence. Every question below is a way of testing, before appointment, whether a candidate can produce that document. > A proper forensic report is not a legal document. It does not contain arguments; it contains facts — the immutable truths found within the ones and zeroes. ## § 02 · The six questions First: what combination of certification, education, and field experience qualifies you for this evidence? No single credential settles the question. Vendor certifications have value, but the certification marketplace partly exists to monetize products, and a credential should be read only as an indication of additional expertise with a particular tool or domain. The true measure is actual field experience in real-world situations, weighed against the specific devices and data types in your matter. Second: how will you acquire the evidence, and what chain of custody will you maintain? A sound engagement begins with careful documentation of every data source the parties provide and a detailed chain of custody, followed by a verified, validated duplicate of each repository so the original data is never lost or modified. Ask whether the candidate intends a bit-by-bit forensic image or a live acquisition — circumstances dictate the choice, but a bit-by-bit image is generally more reliable because it has fewer moving parts and fewer opportunities for error. Third: what tools will you use, and what are their limitations and assumptions? The tools should be explicitly stated in the report, along with their purpose and underlying assumptions, because tools built for different purposes can produce superficially similar output — a system log written for debugging is not a forensic instrument, even when it records the same events a purpose-built forensic tool would. A candidate who cannot discuss tool limitations fluently will not be able to qualify findings honestly. Fourth: could an independent examiner replicate your findings? This is the heart of it. A report should document its steps in sufficient detail that a third party, given the same forensic images and similar analysis software, reaches the same conclusions — and the images should be available for copying so someone can actually try. Courts reward this discipline. In Nucor Corp. v. Bell, 251 F.R.D. 191 (D.S.C. 2008), an expert opined that a departing employee had used a non-traceable wiping program on a laptop; the testimony survived a motion to exclude because the expert had tested a hypothesis about how blocks of zeroes appeared on the drive, replicated the pattern, and thoroughly documented each step of a repeatable test. Fifth: what will your report look like? The structure is fairly standard: a summary of the matter; the tools used, with their purposes and assumptions; then, evidence item by evidence item, a summary and analysis of each repository; and recommendations for counsel on whether to continue or cease the investigation. A report that substantially departs from that shape is a red flag worth investigating. So is padding — a report inflated with hundreds of images or documents that distract from the conclusions usually signals there was little of substance to report. And a good report qualifies itself: it states the limitations of the tools, the methodology and search criteria used, the scope of the investigation, and the areas of potential concern, with their implications for counsel and the court. Sixth: have you testified, and how does the work hold up under cross-examination? Technical expertise is the baseline; the ability to calmly and confidently relay findings while undergoing rigorous cross-examination is what makes the work durable. A written report is mandatory in federal and most state courts unless otherwise stipulated or ordered, and a report done properly can practically negate the need for testimony — but retain the candidate who can survive the stand, because the appointment is insurance against the day the findings are challenged. ## § 03 · The disqualifiers Two behaviors should end a candidacy outright. The first is any willingness to shade findings toward the engaging party’s theory. Examiners must resist overtures, however well-intended, to overstate, understate, or omit findings; findings must be concise and carefully circumscribed, because a report tailored to support a particular outcome is not merely weak — a material omission may constitute fraud. The second is resistance to replication: conclusions that cannot be reproduced from the forensic images should be granted little credence absent exceptional circumstances, and a candidate who hesitates to make replication possible is telling you something. The selection conversation, done this way, takes an hour. It is the cheapest hour in the engagement. Vet the neutral the way the court will vet the report — because eventually, it will. Sources: Draws on “Digital Forensic Evidence in the Courtroom: Understanding Content and Quality,” 12 Nw. J. Tech. & Intell. Prop. 121 (2014), co-authored with J. David Morrissy, and Daniel's forensic-report evaluation articles (2014–2016). --- # Arbitrating Smart Contract Disputes: A Comprehensive Approach A smart contract executes exactly as written, right or wrong. Resolving what happens next takes arbitration rules built for code and a neutral who can read it. URL: https://tailoredmediation.com/insights/smart-contracts Published: May 28, 2026 · Category: BLOCKCHAIN · ADR · 5 min read A smart contract executes exactly as written — including when what is written is wrong. The features that make smart contracts attractive are self-execution, immutability and transparency: once deployed, the code runs without human involvement, and once a transaction is recorded on the blockchain, no court, clerk or ledger keeper has control over the underlying data. Those same features are what make smart-contract failures hard to unwind. When a coding error misdirects a payment, or a condition fires that the parties never intended, there is no back office to call and no entry to reverse. Consider an example I have written about before. In one situation, a mistyped variable caused a payment to be sent to the wrong vendor. A week passed before anyone noticed, by which point several million dollars sat with a third party. That recipient had not spent the money and did the honorable thing, refunding the payment. The situation could easily have taken a different course — with the parties spending millions of dollars in legal fees to remedy a typo. ## § 01 · What a smart contract actually is The term comes from Nick Szabo, the computer scientist and lawyer who described a smart contract as “a set of promises, specified in digital form, including protocols within which the parties perform on these promises.” The simplest way to think about one is as an if-then statement: if condition X is met, then Y occurs. The parties reduce the basic terms of their agreement to computer code; the code typically references an external data source — an “oracle” — to verify that a triggering event has occurred; and when it has, the contract self-executes and the transfer is recorded on the blockchain. JAMS defines the artifact the same way in its smart-contract rules: “a computer protocol intended to digitally facilitate, verify or enforce the negotiation or performance of a self-executing contract,” with the terms written directly into code on a decentralized blockchain network. To see the difference in kind, take a simple transaction between a buyer and a seller for one hundred blue widgets. Traditionally the parties would execute a paper agreement reading, in part, “Seller shall deliver to Buyer one hundred (100) blue widgets.” The smart-contract version of the same deal is a transfer function written in Solidity, the language of the Ethereum blockchain — a few lines of code that check an allowance and move the asset when the condition is met. In either case the seller packs and ships widgets. But when a dispute arises, the first step in resolving a conventional contract fight — apply the plain language of the agreement as written — points somewhere new. With a smart contract, the plain language is computer code. Code has usurped the role plain language has always played. > With a smart contract, the plain language of the agreement is computer code. A neutral who cannot read the code cannot apply the contract as written. ## § 02 · Where the disputes come from The common sources of smart-contract disputes are by now familiar: coding errors; ambiguous or incomplete contract terms; external factors such as changes in regulation or market conditions; and problems in the underlying blockchain network itself, from congestion to security vulnerabilities. There is also a second-order category — claims against the person hired to “draft,” meaning code, the contract — and an insurance-coverage layer that often rides on top of all of it. Immutability sharpens every one of these: once recorded, a smart contract is nearly impossible to unilaterally modify, even when circumstances change, forbearance is warranted or a programming error is found. Litigation handles this badly. A judge confronting even a run-of-the-mill contract dispute built on a smart contract must understand and interpret the underlying computer code and the effect of its self-executing nature before reaching the questions lawyers normally argue. The decentralized character of blockchain networks adds jurisdictional conflict to the technical baggage. Traditional legal frameworks were not built for disputes with this level of requisite technological knowledge — which is why arbitration, with the right rules and the right neutral, fits these matters better. ## § 03 · What the JAMS smart-contract rules provide JAMS publishes Rules Governing Disputes Arising out of Smart Contracts, together with a model dispute resolution clause that parties can incorporate by reference — including directly into the smart contract’s own code. The rules make a set of design choices worth understanding before you adopt them. Appointment is fast: the parties appoint an arbitrator within 72 hours after the arbitration statement is filed and served (Rule 5(b)). The record is deliberately narrow: discovery is limited to the deposition of one competent individual expert witness on the meaning of the smart-contract coding, and the only documentation the arbitrator reviews is the written contract, the computer code and that witness’s testimony (Rule 12(b)). The award issues quickly — no later than 30 calendar days after the arbitrator’s appointment (Rule 13(a)) — and the proceeding and award are confidential (Rule 15(a)). The compressed record reflects a bet: that most smart-contract disputes reduce to what the code says measured against what the parties agreed it should say. For most matters that bet is sound, and the payoff is speed, privacy for proprietary technology, and an award that travels — the New York Convention, ratified by 172 countries as of 2024, gives arbitral awards a cross-border reach that court judgments rarely match in blockchain disputes. ## § 04 · A protocol for counsel Four steps, all of them before the code is deployed. (1) Put dispute resolution into the transaction at the drafting stage — the smart contract’s code can itself specify the arbitration institution, the applicable rules and the procedures for initiating a proceeding. (2) Keep the paper and the code consistent. Under a limited-record framework like Rule 12(b), the written contract and the deployed code are essentially the whole case; a divergence between them is the dispute. (3) Select a neutral who is bilingual — fluent in both English (the law) and computer code (the technology). A superficial comprehension of blockchain is not enough; parties expect the neutral to understand the issues at least as well as they do. (4) Preserve the artifacts the tribunal will actually review: the agreement, the deployed code and the inputs the parties supplied to it. Blockchain will keep spreading through business and consumer transactions, and it is a matter of when, not if, these disputes populate the ADR dockets. The code will execute either way. The parties’ only real choice is whether they decided, before deployment, who reads it when it executes wrong. Sources: Adapted from “Arbitrating Smart Contract Disputes: A Comprehensive Approach” (2024), co-authored with Hon. Gail A. Andler (Ret.), and “Neutrals Need to ‘Speak Tech’ to Resolve Disputes Involving Smart Contracts,” New York Law Journal (2019). --- # How the JAMS AI Rules Can Streamline Discovery in AI Disputes Why conventional e-discovery breaks down when the evidence is an evolving AI system, and how the JAMS AI Rules restore proportionality and technical competence. URL: https://tailoredmediation.com/insights/jams-ai-rules Published: May 17, 2026 · Category: AI · ADR · 5 min read The emergence of AI technologies has introduced significant challenges to the process of e-discovery. Even without factoring in AI, the identification, collection, and analysis of electronically stored information has exploded in scope and complexity in recent years. As AI systems become increasingly embedded in both personal and corporate environments, legal professionals must confront a range of new challenges that the conventional discovery toolkit was never designed to handle. ## § 01 · Why AI breaks conventional discovery The foremost issue is the volume and variety of data AI systems generate. Unlike traditional software that stores data in structured formats, AI applications often produce unstructured output — chat logs, sensor data, machine-learning model outputs — that is difficult to categorize or analyze. Worse, the models themselves may evolve over time, learning from new data and altering their outputs, which makes it harder to reproduce or trace a decision-making process for legal review. A second challenge is interpretability. Many AI models, particularly those built on deep learning, function as black boxes. When a legal matter hinges on understanding why an AI system behaved a particular way — as in discrimination or liability cases — discovery may require access not just to the data but to the model architecture, the training datasets, and the configuration settings. That level of complexity sits outside the expertise of most legal teams and requires technical experts to decode. Layered on top are data ownership and privacy concerns. AI systems often process data from multiple sources, some proprietary and some containing personal information subject to privacy laws such as the GDPR or the CCPA, and extraction and review must comply with all of them. And there are significant preservation and spoliation risks: a system that continuously learns and updates threatens evidence preservation, because the underlying data and model parameters change over time. Without a clear snapshot or audit trail, it can be nearly impossible to recover the state of an AI system at the moment of the disputed event. ## § 02 · What the JAMS AI Rules actually do JAMS introduced its AI Disputes Rules to address precisely these challenges, and one of their most significant benefits is the ability to streamline e-discovery — historically the most burdensome and costly phase of a proceeding. Traditional legal frameworks are ill-equipped to efficiently manage the vast amounts of unstructured, dynamic data at issue in AI-related disputes. The rules address this by allowing the parties to work with a technically savvy arbitrator or discovery referee to tailor discovery protocols to the realities of the AI technology at issue. Arbitrators under the rules are empowered to limit overly broad or irrelevant requests, reducing time and expense while keeping the focus on truly material evidence. A key innovation in the framework is its focus on early identification of technical issues, including data provenance and model explainability. The rules allow for the appointment of neutral experts who understand both the legal and the technical nuances of AI, which helps expedite the review of complex digital evidence where appropriate and minimizes the risk of misunderstandings. The rules also promote proportionality in discovery — balancing each request against the burden and relevance of the data sought, an essential safeguard when the system in question is opaque or evolving — and support confidentiality measures to protect sensitive proprietary information, a recurring concern in AI-related cases. > Traditional frameworks are ill-equipped for the unstructured, evolving data at the center of AI disputes. The rules let the parties tailor discovery to the technology itself. ## § 03 · The arbitrator-selection advantage Arbitration offers AI litigants one further advantage: the parties select the decision-maker. An arbitrator with technical and e-discovery knowledge that most judges do not have can resolve disputes over the scope of discovery, search terms, proportionality, and the AI systems themselves far more efficiently — a substantial cost and time saver. Technical fluency also matters on the merits. In a developing legal landscape where key issues may have little precedent, an arbitrator who understands AI systems is better positioned to produce fair and reasonable rulings. ## § 04 · Putting the rules to work For counsel drafting or managing AI-related agreements, the practical sequence is straightforward: (1) address dispute resolution before the dispute, by adopting the JAMS AI Rules in the contract's dispute-resolution clause; (2) raise the technical issues — data provenance, explainability, preservation of model state — at the earliest procedural conference, not after positions have hardened; (3) insist on an arbitrator or discovery referee with demonstrated AI and e-discovery fluency; and (4) build proportionality limits and confidentiality protections into the discovery protocol from the outset. In short, by providing structure, flexibility, and technical competence, the JAMS AI Rules offer a pragmatic solution to managing the e-discovery challenges of AI disputes — one that saves time, reduces cost, and promotes fair outcomes. The technology at issue will keep evolving. The discovery framework should be built, from day one, to evolve with it. Sources: Adapted from “How the JAMS AI Rules Can Streamline Discovery for AI-Related Disputes” (2025). Disclosure: the author co-developed the JAMS Artificial Intelligence Disputes Clause and Rules discussed here, with fellow JAMS neutral Ryan Abbott. --- # Mediating Cyber Insurance Coverage Disputes Cyber policy forms change faster than precedent can settle them. Why coverage disputes resolve better in mediation and arbitration, and how to draft the clause. URL: https://tailoredmediation.com/insights/cyber-insurance Published: May 6, 2026 · Category: CYBER · INSURANCE · 6 min read A cyber insurance policy is a young contract sold into an old dispute system. When Andrew Nadolna and I surveyed this market in 2016, gross written premiums had just set a record of $2.75 billion on annual increases of 25 to 50 percent — growth so rapid that not every exposure had been identified, turned into policy language, and priced. Terms and conditions were negotiable, and the forms were being revised constantly. A decade on, the market is far larger, but the underlying condition persists: this is a line of insurance whose language has never hardened into standard forms. That matters because unsettled language is where coverage disputes come from — and because it breaks the tool courts normally use to resolve them. A cyber policy is generally an amalgamated form of several older coverages — errors & omissions, network security, privacy — combined with protections for loss or corruption of data, business interruption, crisis management, and cyber terrorism. When a claim lands in the gap between what the insured believed it bought and what the form actually says, the parties reach for precedent. In cyber, there is very little worth reaching for. Court decisions construe wordings the market has already amended; the next dispute arrives on a form no court has ever read. ## § 01 · The lesson of P.F. Chang’s Consider the case that taught the market this. In P.F. Chang’s China Bistro, Inc. v. Federal Insurance Co., No. CV-15-01322, 2016 WL 3055111 (D. Ariz. May 31, 2016), the restaurant chain discovered a 2014 data breach involving 33 restaurants and the credit card data of roughly 60,000 customers. It reported the breach to its carrier immediately and sought coverage for its payments to the credit card companies arising from the resulting fraudulent charges. The policy covered “direct loss, legal liability, and consequential loss resulting from cyber security breaches” — and the court still held that the loss fell outside coverage. Relying on case law developed under commercial general liability policies, it reasoned that coverage is generally excluded for the assumption of another’s liability, and P.F. Chang’s was seeking coverage for exactly that. The lesson: the words were broad, the loss was real, and the coverage was not there. Most cyber forms were subsequently amended to cover the exposures at issue in the case — which is precisely the point. Every litigated wording becomes an amended wording. Litigation in this market does not build a stable body of interpretation; it documents, expensively and publicly, one generation of drafting mistakes at a time. ## § 02 · What mediation and arbitration actually buy Against that backdrop, the case for resolving cyber coverage disputes through mediation or arbitration is not ideological. It rests on three practical advantages. First, speed: depending on the dispute, ADR can save anywhere from a handful of months to several years, largely because the parties set their own discovery procedures — almost always faster, easier, and more direct than discovery in traditional litigation. Second, fluency: cyber coverage disputes braid complex technical questions into complex insurance questions, and a judge will often need significant time and resources to come up to speed on both. The parties, by contrast, can select a neutral who already has technical cyber experience, relevant insurance experience, or both. The technical questions in particular reward a neutral who can read the record directly. The technical elements of a dispute are not grounded in law, advocacy, and persuasion; they are grounded in the ones and zeroes of the relevant computer systems. A technically competent neutral can surface those truths efficiently, without the parties funding lengthy rounds of briefing and dueling expert opinions to establish facts that were never genuinely in dispute. > Every litigated wording becomes an amended wording. The next dispute arrives on a form no court has ever read. Third, confidentiality — and in cyber, this cuts deeper than reputation management. A coverage fight after a breach can require discovery into the policyholder’s cyber defenses and their weaknesses, its diligence in selecting systems, the adequacy of its security funding, and the quality of its internal decision-making. Breaches also tend to arrive with company: class actions and regulatory proceedings whose lawyers follow any public coverage litigation with interest, looking for material they could not obtain in their own discovery. Few policyholders want a published judicial ruling that their defenses were inadequate or misrepresented. Arbitration produces neither the public record nor the precedent. ## § 03 · Negotiate the clause before the breach None of this happens by accident; it happens by clause, and the clause must be drafted with care. A mandatory arbitration provision in an insurance policy is both unpopular and, in many places, unenforceable — nearly half the states forbid mandatory arbitration clauses in some or all insurance contracts, and the Washington Supreme Court has held them unenforceable even in the excess and surplus lines market. State of Washington Department of Transportation v. James River Insurance Co., 176 Wash. 2d 390 (2013). Parties have already litigated over the ADR clauses in cyber policies themselves — see Columbia Casualty Co. v. Cottage Health System, 2015 U.S. Dist. LEXIS 93456 (C.D. Cal. July 17, 2015) — and litigation over the dispute-resolution method defeats every purpose the method was meant to serve. The workable answer is an optional, negotiated clause rather than an imposed one. Policyholder counsel should treat the ADR provision as part of the placement negotiation and press on five points: (1) the trigger — mutual consent, or better for the insured, a one-way option letting the policyholder elect arbitration that the insurer cannot refuse; (2) the panel — qualification requirements ensuring at least one arbitrator fluent in both policy language and technical cyber issues; (3) choice of law and rules of interpretation, so that the common-law rule construing ambiguity in the policyholder’s favor is not quietly bargained away; (4) fees and remedies, including whether attorneys’ fees and bad-faith damages remain available, subject to caps if the insurer insists; and (5) the tower — pressing every carrier on the program toward a clause that permits consolidation of common issues, so coverage is not relitigated layer by layer. Consider the position of a company that has just been hacked. Regulators are on the way, a class action may be filed at any moment, the breach-response teams are on high alert — and then the reservation-of-rights letter arrives, with counsel advising that a declaratory judgment action in federal court may follow. If the policy has no dispute-resolution clause, would you want to try negotiating one at that moment? Better to have the option in place before the crisis. The worst time to design the forum is the moment you need it. Sources: Draws on Daniel's cyber-insurance and ADR writing co-authored with Andrew Nadolna and Michael Mann (Law360 and Law.com, 2016–2017). --- # Building a Tiered Protective Order for Machine-Learning Matters Model weights, training data, prompts and outputs are not the same kind of secret. How the JAMS AI Rules support graduated, artifact-by-artifact access. URL: https://tailoredmediation.com/insights/protective-order Published: April 24, 2026 · Category: AI · DISCOVERY · 5 min read Standard protective orders treat “confidential business information” as a single category with a single access rule. That works for most commercial litigation. It fails in AI matters, because the artifacts in discovery — model weights, training data, prompts and system configuration, inference logs, outputs — are not all the same kind of secret. An access control calibrated for one artifact is excessive for another and dangerously insufficient for a third. A flat order forces every artifact into the same box, then guarantees the box gets relitigated. Start with why the artifacts differ. An output may already be quoted in the pleadings; its marginal sensitivity is low. Prompts and configuration settings reveal how a system was steered. Training data is high-volume and frequently entangled with personal information subject to privacy regimes such as the GDPR or the CCPA, so its disclosure implicates people who are not in the room. And the model itself — weights, checkpoints, architecture — embodies the research-and-development investment in its most concentrated form; once it leaves a controlled environment, the disclosure is effectively irreversible. Yet when a matter turns on why a system behaved as it did, discovery cannot stop at outputs. Many AI models function as “black boxes,” and understanding their behavior can require access to the model architecture, training datasets and configuration settings. The protective order has to make that access possible without making it catastrophic. ## § 01 · What the JAMS AI Rules already provide The JAMS Artificial Intelligence Disputes Clause and Rules, effective June 14, 2024, take the graduated approach seriously — and give counsel a vetted starting point instead of a blank page. Under Rule 16.1(a), unless the parties agree to another form of protective order, the JAMS AI Disputes Protective Order applies by default. That order defines two designations. “Confidential” covers non-public documents and testimony and may be reviewed by counsel, the parties and credentialed experts. “Highly Confidential” — trade secrets or other confidential research, development, financial, proprietary or commercial information — carries an attorneys’-eyes-only legend and excludes the parties’ own officers, directors and employees from access. The rules then add a third, harder level for the technology itself. Under Rule 16.1(b), production and inspection of AI systems and related materials — including hardware, software, models and training data — is limited to the disclosing party making those systems available to one or more experts in a secured environment the disclosing party establishes, and the experts may not transmit or remove any produced materials or information from that environment. Every expert signs a written acknowledgment submitting personally to the arbitration’s jurisdiction for enforcement of the order, and at the end of the matter confidential material must be returned or destroyed within seven days, with written certification. Where the parties jointly request it, the arbitrator can designate the inspecting experts from a list JAMS maintains. Read together, the framework rejects the flat order outright: counsel-level review for ordinary confidences, attorneys’ eyes only for trade secrets, and a secured room the model never leaves. > The framework rejects the flat order outright: counsel-level review for ordinary confidences, attorneys’ eyes only for trade secrets, and a secured room the model never leaves. ## § 02 · A graduated structure, artifact by artifact Within that framework, counsel should negotiate a tier map that assigns each artifact class to an access level before discovery begins, rather than fighting document by document. A workable default: (1) outputs — the lowest sensitivity — designated Confidential and reviewable by counsel and the parties; (2) prompts and system configuration, designated Confidential or Highly Confidential depending on what they reveal about how the system was built and steered; (3) training data, designated Highly Confidential and screened for personal information before production, with privacy obligations addressed expressly; (4) inference logs, designated Highly Confidential because they routinely contain user data; and (5) model weights, checkpoints and the running system itself, handled under Rule 16.1(b) — expert-only inspection, in a secured environment, with nothing transmitted or removed. This is a recommended structure, not a rigid one. The point is that each class carries its own reviewers, its own environment and its own end-of-matter obligations, agreed in advance. The map does double duty. It protects the producing party from the irreversible leak, and it protects the requesting party from the reflexive over-designation that turns every document into an attorneys’-eyes-only fight. The JAMS order itself points the same direction: designations are to be limited to those parts of documents, testimony or material clearly identified as warranting them. ## § 03 · What to negotiate at the outset Five items belong on the agenda at the first conference, before any production. (1) Designation discipline: adopt the tier map and hold both sides to clause-level designation rather than blanket stamping. (2) Expert credentialing: who signs the acknowledgment, how conflicts are cleared, and whether a jointly requested, arbitrator-designated expert would be faster than dueling retained ones. (3) Secured-environment logistics: location, tooling, hours and — because the rule bars removing produced materials or information — exactly what an expert’s notes and work product may contain and where they live. (4) Preservation: AI systems that continue to learn change over time, so require a snapshot or audit trail sufficient to reproduce the system’s state at the time of the disputed conduct. (5) Exit: the seven-day return-or-destroy obligation, the certification, and the archival carve-outs for pleadings and work product. None of this is exotic, and all of it is easier before the first production than after the first leak. Treating model weights and inference outputs as the same category of secret is a category error, and a flat protective order writes that error into the case. Build the tiers at the outset. The alternative is a second dispute about the first. Sources: Grounded in the JAMS Artificial Intelligence Disputes Clause and Rules (effective June 14, 2024) and the accompanying JAMS AI Disputes Protective Order. Disclosure: the author co-developed those rules with fellow JAMS neutral Ryan Abbott. --- # When (and How) to Appoint a Special Master for TAR Validation Courts settled whether parties may use TAR years ago. The disputes now are over protocols and validation — and early special-master appointment avoids them. URL: https://tailoredmediation.com/insights/special-master-tar Published: April 9, 2026 · Category: eDISCOVERY · 5 min read In 2012, Da Silva Moore v. Publicis Groupe, 287 F.R.D. 182 (S.D.N.Y. 2012), became the first judicial opinion to approve technology-assisted review for document production in federal litigation. Three years later, Rio Tinto plc v. Vale S.A., 306 F.R.D. 125 (S.D.N.Y. 2015), observed that it had become “black letter law that where the producing party wants to utilize TAR for document review, courts will permit it.” Whether parties may use predictive coding is settled. How they use it is not. Predictive coding can save significant time and money in discovery, but parties routinely disagree on the methods and protocols for implementing it, and those disagreements — over seed sets, search terms, disclosure obligations, statistical benchmarks — can negate the savings the technology was adopted to capture. The fight has moved from the admissibility of the method to the defensibility of the execution. There is a structural answer, and it is not more motion practice. It is the appointment of an e-discovery special master with genuine technical expertise, made as early in the case’s life cycle as possible — before the predictive-coding protocol is drafted, not after it has failed. ## § 01 · How predictive coding actually works Predictive coding is, essentially, the use of keyword search, filtering, and sampling to teach a computer to identify responsive or privileged documents. A set of documents — the seed set — is pulled from the corpus under review. A subject-matter expert who knows the case codes that set for responsiveness and privilege. The software analyzes the expert’s coding, attempts to learn what makes a document responsive or privileged, and codes a new set of documents; the expert corrects the machine’s mistakes; and the cycle repeats until the model hits agreed statistical benchmarks. Only then is it turned loose on the full corpus. Two features of that process matter for dispute resolution. First, there is no single correct way to do predictive coding: seed-set composition, training cadence, culling criteria, and precision and recall standards all involve judgment calls. Second, every one of those judgment calls is a place where the parties can disagree — and most of them are invisible to a generalist bench until they surface as motion practice. ## § 02 · The lesson of Rio Tinto Rio Tinto is the cautionary tale. The parties stipulated to a Predictive Coding Protocol that was supposed to make the technology self-executing. Execution instead became a major point of contention. The parties sought judicial relief over which search terms would cull the document universe before predictive coding was applied; over whether Rio Tinto could challenge the adequacy of Vale’s training in the predictive-coding workflow after alleged delays in disclosing its seed set; and over whether Vale could compel Rio Tinto to update and correct its technical disclosures. The court resolved the issues, but the motion practice and hearings were time-consuming, expensive, and fueled by extensive argument between the parties’ technical experts. The court in Rio Tinto did eventually appoint a special master — but only after months of trudging through protocol issues, by which point the litigation had already been significantly disrupted. That sequencing is the lesson. A predictive-coding protocol drafted without technical fluency does not prevent disputes; it schedules them. > A predictive-coding protocol drafted without technical fluency does not prevent disputes. It schedules them. ## § 03 · What the special master actually does Appointed early, an e-discovery special master serves three functions. In drafting, the special master’s technical knowledge helps the parties write unambiguous protocol provisions — methods for selecting search terms and seed sets, precision and recall standards, disclosure obligations — that are mutually agreeable and that fit each side’s actual technical capabilities. In monitoring, the special master oversees compliance with the protocol and decides technical issues that may be beyond the court’s or the parties’ understanding, which eliminates the need for each side’s consultants to argue their positions before the bench. And as a neutral technical presence, the special master helps the parties find common ground on issues that would otherwise become contentious simply because the lawyers are inexperienced with the technology. Validation belongs in the protocol, not in a post-production brawl. A well-drafted protocol states in advance which statistical benchmarks the trained model must meet, how the results will be sampled — including the documents the model has coded non-responsive — and how recall will be measured against the agreed standard. The measuring stick is reasonableness, not perfection: “courts cannot and do not expect that any party can meet a standard of perfection” in producing ESI. Pension Committee of the University of Montreal Pension Plan v. Banc of America Securities, LLC, 685 F. Supp. 2d 456, 461 (S.D.N.Y. 2010). A protocol that defines defensible in numbers before review begins leaves very little to fight about after it ends. ## § 04 · When and how to seek appointment The practical protocol for counsel: (1) Move early — raise the appointment when predictive coding is first proposed, at the meet-and-confer stage, not after the first dispute has hardened positions. (2) Insist on genuine technical expertise; a special master who cannot interrogate a seed set cannot referee one. (3) Scope the appointment order to all three functions — protocol drafting, compliance monitoring, and resolution of technical disputes. (4) Fix the validation standards — benchmarks, sampling method, disclosure obligations — in the protocol itself. (5) Do the arithmetic honestly: special masters cost money, but the benefits they provide often produce a net gain from predictive coding that is never realized when the court and the parties are left to their own machinations. Predictive coding remains useful technology with real potential to save time and money. Rio Tinto teaches that those benefits are not self-executing, no matter what the protocol says on its face. Appoint the technical referee before the technical fight — not after. Sources: Adapted from Legal Executive Institute articles on predictive coding and e-discovery special masters (2016), co-authored with Michael Mann. --- # AI Hallucinations in Litigation and Arbitration Hallucinated authority is not a software glitch. It is a breach of the duty of competence that taxes every party in the room and endangers the award itself. URL: https://tailoredmediation.com/insights/hallucinations Published: March 14, 2026 · Category: AI · LITIGATION · 7 min read The promise of arbitration has always rested on a simple, seductive value proposition: it is faster, cheaper, and more final than the labyrinthine procedures of national courts. Parties are sold a streamlined dispute resolution mechanism — a private justice optimized for commercial efficiency. Yet as legal practice moves deeper into the age of generative artificial intelligence, a subset of the profession is actively sabotaging that value proposition, submitting briefs riddled with hallucinations: fabricated case law, phantom statutes, and invented evidentiary records generated by large language models. When caught, the defense is almost always the same: a plea of ignorance, a blaming of the “black box,” a claim that the technology misled them. These excuses are no longer tenable. In 2026, the submission of hallucinated legal authority is not a technological glitch; it is a fundamental breach of the ethical duty of competence. It is a self-inflicted wound that destroys the credibility of counsel and imposes a verification tax on the entire system, driving up the very costs arbitration was designed to curtail. ## § 01 · The death of the “black box” defense Start by dispensing with the myth that AI hallucinations are mysterious accidents. They are a feature, not a bug, of how large language models operate. These models are probabilistic engines, not truth machines. When a lawyer prompts an LLM to find a case where an arbitrator was removed for undisclosed conflicts in the energy sector, the model does not search a database of verified law. It predicts the most statistically likely sequence of words that looks like such a case. A lawyer who uses a general-purpose LLM for legal research without understanding this mechanism is akin to a pilot flying a plane without understanding the difference between an altimeter and a fuel gauge. The standard for technological competence is already set in stone. Model Rule of Professional Conduct 1.1 and its Comment 8 explicitly require lawyers to keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. This is a non-delegable duty. You cannot outsource your professional judgment to a summer associate, and you certainly cannot outsource it to a chatbot. ## § 02 · The verification tax The most pernicious effect of hallucinations in arbitration is economic. In a typical arbitration the tribunal is paid by the hour, and every hour spent chasing a citation that does not exist is an hour billed to the parties. Consider the procedural fallout of a single hallucinated citation. Opposing counsel spends hours attempting to locate the case, then must draft correspondence or applications to the tribunal pointing out the discrepancy. The arbitrator, bound by a duty to fully investigate the law, must personally verify the non-existence of the authority. The inevitable result is a show-cause order or a motion for sanctions — and the main dispute, the breach of contract or the intellectual property theft, is put on hold while the parties litigate the conduct of the lawyers. This is the verification tax: a surcharge levied on the process by the incompetence of one party. Recent federal cases illustrate the scale of the waste — in 2025, one court ordered sanctioned counsel to pay over $26,000 to reimburse the opposing party for legal fees incurred investigating fake citations. In arbitration, where the loser-pays principle is often the default, a party that submits hallucinations is effectively writing a blank check to its opponent for costs. The deeper damage is to trust, the primary efficiency driver of arbitration. An arbitrator who finds one fake case in a submission will instinctively distrust every other factual assertion and legal argument in that brief. The benefit of the doubt is lost; the tribunal is forced into a forensic, skeptical posture that slows the drafting of the award and increases the hours required to complete the mandate. And the stakes run past the fee. Under the New York Convention, an award must be enforceable. A tribunal that relies, even inadvertently, on a hallucinated legal principle renders its award vulnerable to set-aside proceedings — the losing party can argue the award is contrary to public policy, or that it was unable to present its case against fictitious law. Counsel who introduce hallucinations into the record are planting a poison pill in their own client's victory. ## § 03 · The case law of consequence Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), is the case that started it all. Plaintiff's counsel filed a brief citing at least six nonexistent cases, and when the court and opposing counsel could not find them, the lawyers doubled down — submitting “copies” of the fake opinions generated by the AI. The lesson: the court imposed a $5,000 sanction, but the reputational damage far exceeded it. The judge observed that there is nothing inherently improper about using a reliable artificial intelligence tool for assistance, but emphasized that existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings. Park v. Kim, 91 F.4th 610 (2d Cir. 2024), is more often described than read, and the description is usually wrong. The Second Circuit did affirm the dismissal of the plaintiff's action — but under Rules 37 and 41(b), for the plaintiff's own persistent and knowing violation of discovery orders, on a judgment entered long before the appeal was briefed. The court addressed counsel separately: her reply brief cited a state court decision that did not exist, which she admitted generating with ChatGPT and never read or confirmed. The lesson is in that separation. The fabricated citation did not lose the case; it earned counsel a referral to the court's Grievance Panel and an order to furnish the decision to her own client. The arbitral analogue is not dismissal but a tribunal that has quietly stopped extending the benefit of the doubt. United States v. Cohen (S.D.N.Y. 2023) showed that no one is immune. Michael Cohen, seeking an early end to his supervised release, submitted citations to three nonexistent cases generated by Google Bard. The lesson, in the presiding judge's words: it is not the court's job to wade through the record to determine which citations are real and which are hallucinations. In arbitration the sentiment is amplified. Arbitrators are paid service providers, and a party that forces them to traverse garbage is likely to receive an award that reflects their frustration. ## § 04 · The layer nobody checks: metadata The risk does not stop at the visible text. When AI generates a document, it may quietly populate the hidden metadata fields embedded in the file — author, company, creation date, version history — with fictitious or misleading information. Faced with uncertain or nonexistent data for the fields its training says a “complete” document should contain, the model fabricates them. A team can review every sentence and every citation, file the brief, and still hand the court a document whose properties name an author who does not exist or a creation date that predates the engagement. Metadata is not a technical curiosity; it is evidence. Courts and opposing counsel routinely rely on it to authenticate documents and establish chain of custody, and forensic tools report what a file contains, not whether it is truthful. Hallucinated metadata can pass undetected unless it is carefully cross-checked against other evidence. > In the final analysis, the “black box” is a mirror. When it produces garbage, and that garbage is filed, it reflects the competence of the filer. ## § 05 · A verification protocol The exposure is manageable with discipline. A workable internal protocol has three phases. (1) The sandbox restriction: general-purpose LLMs are prohibited for final legal research. They may assist with brainstorming, summarizing, or drafting non-legal text, but they never generate citations — only legal-grade, retrieval-grounded tools that link directly to primary law may do that. (2) The click-through requirement: no AI-generated citation goes into a brief until the drafting attorney has opened the primary source and verified that the case exists, that the pin-cite is accurate, and that the proposition of law is actually supported by the text of the opinion — with a source-verification log confirming every case has been checked. (3) The hallucination check: before filing, run the table of authorities through a traditional legal database, and halt the filing if any case fails to resolve until the source is manually retrieved. Given the metadata risk, inspect the document's file properties before it goes out the door as well. The integration of AI into legal practice is inevitable and, effectively managed, desirable. Retrieval-augmented tools grounded in verified databases are genuine force multipliers. But they multiply judgment; they do not replace it. The lawyer who files a hallucinated brief is not a victim of bad software — they have chosen the speed of the draft over the integrity of the submission. The mandate for the modern practitioner is clear. Trust, but verify. Anything less is malpractice. Sources: Adapted from “The Hallucination Tax: Why AI Negligence Is a Self-Inflicted Wound on Arbitral Efficiency,” co-authored with Hon. Leo M. Gordon, and from Daniel's work on AI metadata hallucination with Jennifer Deutsch and Morgan Ward. --- # Cross-Border Forensic Collection: The Legal Layer Comes First GDPR, Schrems II, and divergent disclosure regimes have turned cross-border forensic collection from a logistics exercise into a conflict-of-laws problem. URL: https://tailoredmediation.com/insights/cross-border Published: March 11, 2026 · Category: CROSS-BORDER · 4 min read American discovery is the broadest in the world. Under the Federal Rules of Civil Procedure, electronically stored information has been squarely discoverable since the 2006 amendments, and a party must produce ESI on any nonprivileged matter relevant to a claim or defense. Most of the rest of the world starts from a different premise: disclosure, privacy, and data-protection obligations are generally stricter outside the United States, and when the evidence sits abroad, that difference is not a nuance — it adds an entire layer of legal complexity to the collection itself. The producing party’s dilemma is structural. A US court can order production of data held overseas; the jurisdiction where the data lives may treat the transfer of personal data beyond its borders as a criminally and administratively punishable act. Counsel who treat cross-border forensic collection as a logistics exercise — send the examiner, image the device, ship the image — discover the conflict at the worst possible moment: after the collection has already happened. The discipline that works is the reverse. Map the legal layer first, and design the collection so it is lawful in every jurisdiction the data touches. ## § 01 · Why the regimes genuinely conflict Start with the disclosure rules themselves. The FRCP organizes discovery around relevance. England’s Civil Procedure Rules establish a far narrower scope: under CPR Part 31.6, a party discloses the documents on which it relies and those that adversely affect or support a party’s case — relevance is not the test. Continental civil-law systems narrow disclosure further still and channel international evidence requests through treaty machinery. Misunderstanding runs in both directions: US courts, lawyers, and parties routinely misread non-US law, and the reverse is equally true. For a company operating on both sides, guessing wrong in either direction means exposure to sanctions and fines. Now layer data protection on top. Under the EU General Data Protection Regulation (Regulation (EU) 2016/679), personal data may be transferred to a third country only through the mechanisms its Chapter V provides — an adequacy decision, appropriate safeguards, or narrow derogations. In Schrems II (Case C-311/18, Data Protection Commissioner v. Facebook Ireland Ltd. and Maximillian Schrems, CJEU July 16, 2020), the Court of Justice invalidated the EU–US Privacy Shield and demanded case-by-case scrutiny of transfers made under standard contractual clauses. And forensic collection is personal-data-intensive by nature: custodian mailboxes, laptops, and handheld devices carry not only the custodian’s personal data but third parties’ — which is exactly what these statutes protect. ## § 02 · The treaty layer and its limits The Hague Convention of 18 March 1970 on the Taking of Evidence Abroad in Civil or Commercial Matters is the treaty mechanism through which international discovery requests are channeled in much of continental Europe; it regulates the transfer of evidence located abroad through national legal proceedings. But the Convention does not dissolve the conflict for US litigants. In Société Nationale Industrielle Aérospatiale v. United States District Court, 482 U.S. 522 (1987), the Supreme Court held that the Convention is neither the exclusive nor necessarily the first resort: American courts may order discovery of foreign-held evidence directly under the Federal Rules, subject to a comity analysis. The lesson: a producing party can face a US production order on one side and a foreign data-protection or disclosure regime on the other, with no treaty automatically reconciling the two. The reconciliation has to be engineered into the discovery protocol. > The hard part of cross-border collection is not imaging the device. It is making the transfer lawful in every jurisdiction the data touches. ## § 03 · Designing the protocol The elements of a defensible cross-border protocol are knowable in advance. (1) Map the legal layer before the technical plan: for every data source, identify where the data resides, who the custodians are, which data-protection and disclosure regimes apply, and what mechanism will authorize the transfer. (2) Narrow before anything moves: agree on categories of ESI, date ranges, custodians, and search terms — the scoping discipline international arbitration protocols already demand — so the volume of personal data crossing a border is the minimum the dispute requires. (3) Write the data-privacy obligations into the discovery protocol and the protective order expressly, rather than assuming a US confidentiality order satisfies foreign law. (4) Where feasible, process and review in-country, so only responsive, filtered material is ever transferred. (5) Use the analytical frameworks that exist: The Sedona Conference’s Working Group 6 published its Framework for Analysis of Cross-Border Discovery Conflicts and its International Overview of Discovery, Data Privacy & Disclosure Requirements precisely to help practitioners navigate the competing currents of international data privacy and e-discovery. ## § 04 · What this means for selecting the neutral Counsel selecting a forensic neutral or special master for a cross-border matter should test the candidate on the legal-authorization layer, not just the laboratory. Can the candidate walk through a GDPR transfer analysis? Explain what changed after Schrems II? Say when the Hague Evidence Convention route is worth its delays, and when the Aérospatiale comity factors will carry the day? A neutral who is technically excellent but blind to that layer can put a matter sideways before the first device is imaged. Authorization first; collection second. A forensic image acquired in violation of the law of the place it came from is not evidence — it is a liability. Sources: Draws on Daniel's eDiscovery Dispute Resolution (2024) and his cross-border e-discovery writing. --- # Forensic Data as a Mediation Asset The forensic record is treated as trial ammunition. Produced by a neutral under an agreed protocol, it is also a settlement instrument that narrows the fight. URL: https://tailoredmediation.com/insights/forensic-data Published: February 22, 2026 · Category: FORENSICS · 5 min read Each year the cost of litigation increases, and the primary driver is discovery. The cause is no mystery: we produce data at a remarkable rate, and the data is growing not just in volume but in complexity. One of the fastest-growing categories is “invisible data” — data generated by computer systems to deal with other systems, rarely if ever touched by an end user. When a dispute turns on what those systems recorded, two parties can examine the same machines and hand the court incompatible accounts of what is in them. Underneath many discovery fights is a simpler problem: information inequity. Neither side trusts the other's account of its own systems, and inside litigation the only lever for testing that account is a discovery motion. So positions harden around competing narratives about the data rather than around the data itself, and the parties spend the case litigating the discovery instead of the issues. There is a better use for the forensic record. Produced by a qualified neutral, under an agreed protocol, it is not merely trial ammunition. It is a mediation asset — a body of verifiable fact that both sides have reason to accept, and that narrows what is left to fight about. ## § 01 · Facts against narratives The technical elements of a dispute are different in kind from the substantive claims. They are not grounded in law, advocacy, and persuasion, but in the ones and zeroes of the relevant computer systems. That immutability is what makes the forensic record useful in mediation: a neutral third party can establish those facts and present them in an efficient process, without the parties engaging in lengthy and costly rounds of briefing and dueling expert submissions. Digital evidence, properly understood, is any evidence found on a computer or digital device — including data that has been hidden, erased, or otherwise altered and requires forensic analysis to recover. It lives in the usual places and, increasingly, in unusual ones: cloud platforms, vehicle systems, wearable devices. The volume is enormous, and most of it is noise. A forensic neutral's first economic contribution is cutting through the surplus to the data that is most probative, and potentially dispositive, of the question actually in dispute. ## § 02 · Why a neutral, and not another expert Consider two rival technology companies. Key employees leave Company A for Company B; soon after, Company B announces products whose functionality mimics Company A's. Whether confidential information was misappropriated will not be answered by the products' functionality. It will be answered by the code, and by whether Company A's documents exist on Company B's systems. Yet Company B has a valid objection to giving a direct competitor — including its counsel — access to its code and systems, and Company A has no desire to expose its own proprietary information in discovery. A qualified forensic neutral with no ties to either party, given access to both parties' systems under an agreed protocol, resolves those concerns without forcing either side to trust the other. Federal Rule of Civil Procedure 53 gives courts express authority for such appointments, and parties can also stipulate to one. The neutral can draft the forensic protocol, determine the existence and authenticity of digital evidence, analyze deleted or corrupted data, validate court-ordered deletion, and audit compliance with a court order — and, unlike a party-retained expert's report, the neutral's findings do not arrive pre-discounted as advocacy. ## § 03 · What makes a report settlement-grade Not every forensic report can carry that weight, and counsel should know the difference. A proper forensic report is not a legal document; it is a technical and scientific document. It does not contain arguments — it contains facts, the immutable truths recorded in the ones and zeroes of the systems examined. The discipline shows in the method: the examiner documents every source of data and maintains a detailed chain of custody; works only from verified, validated duplicates so the original data is never altered; and writes up both process and findings so that another examiner, given the same repositories, could follow the report step by step and reach the same results. > A proper forensic report is not a legal document. It contains no arguments — only the facts recorded in the ones and zeroes of the systems examined. A good report also states its own limits: the tools used and their underlying assumptions, the methodology and search criteria, the scope of the investigation. No report is perfect, but a good one identifies its areas of potential concern and spells out their implications for counsel and the court. Padding is the tell in the other direction — a report beefed up with superfluous data usually signals there was little of use to find. In mediation, transparency of method is what lets an adversary accept the finding without conceding anything else. ## § 04 · Putting the record to work Counsel who want the forensic record to do settlement work should: (1) engage the neutral early — it is faster and cheaper to establish the technical facts before positions harden than to remediate a dispute afterward; (2) scope the engagement to the technical questions, not the merits — the neutral clarifies what the systems show and what preservation, collection, and production will actually cost, while the parties generate the solutions; (3) arrive with the inputs that make the work efficient: data maps, business use cases for the data at issue, an explanation of why each item of discovery is requested, and IT resources on call when technical questions arise; (4) insist on the report qualities above — chain of custody, reproducibility, stated limitations; and (5) memorialize the result in a written protocol, search terms, or scope agreement, which gives the parties both a record to present to the court and a roadmap for continued compliance. The facts of the dispute are already sitting in the parties' systems. The only question is whether counsel spend the case arguing about what those facts might be, or spend a fraction of that establishing what they are. Establish them — and litigate the issues, not the discovery. Sources: Draws on “Mediating E-Discovery Disputes Can Save Time and Money,” Law360 (2016), “Understanding a Digital Forensics Report” (2016), and “Deciphering Digital Dilemmas” (2025), co-authored with Hon. Charles Margines (Ret.). --- # The Economics of Appointing a Special Master Special masters cost money. The disputes they absorb — protocol fights, compliance, fee allocation — routinely cost more. Where the appointment pays for itself. URL: https://tailoredmediation.com/insights/special-master-economy Published: February 14, 2026 · Category: NEUTRAL · ECONOMY · 5 min read Counsel resist special-master appointments on cost grounds, and the instinct is understandable: another billing professional, another invoice, another layer between the parties and resolution. The instinct is also incomplete. Special masters cost money — but the question is not whether the appointment costs money. It is what the appointment displaces. What it displaces is the most expensive activity in modern litigation: fighting about process. Discovery is the primary driver of rising litigation cost, and the disputes it spawns — how to preserve, collect, search, and produce electronically stored information; whether a protocol was followed; how to allocate fees across dozens of firms — consume motion practice, dueling expert submissions, and court time that neither side recovers. ## § 01 · What the appointment actually buys Federal Rule of Civil Procedure 53 authorizes a court to appoint a master to perform duties the parties consent to; to address pretrial and posttrial matters that cannot be “effectively and timely addressed by an available district judge or magistrate judge of the district”; to hold non-jury trial proceedings where an exceptional condition warrants; and to perform accountings or resolve difficult damage computations. The rule’s own language is economic — effectively and timely — and so is its structure: the appointing order delineates duties, scope of authority, timelines, reporting obligations, and compensation. Unlike motion practice, the appointment is scoped, priced, and time-limited at the outset. The bench has said as much. Chief Justice John Roberts, in his 2015 Year-End Report on the Federal Judiciary, wrote that the discovery process “must provide parties with efficient access to what is needed to prove a claim or defense, but eliminate unnecessary or wasteful discovery,” and that the required assessment of actual need “may … require the involvement of a neutral arbiter … to guide decisions.” Courts reach for masters where a case involves a complex, technical, or specialized area of law; where discovery requires heightened and extensive oversight; or where fact-intensive non-jury determinations loom. ## § 02 · A case study in relocated costs Rio Tinto plc v. Vale S.A., 306 F.R.D. 125 (S.D.N.Y. 2015), is the canonical illustration. Judge Andrew Peck approved the parties’ stipulated predictive-coding protocol — a protocol designed to be self-executing. Execution promptly became a major point of contention. The parties returned to court over which search terms would cull the document universe before predictive coding began, whether one side could challenge the adequacy of the other’s training after alleged delays in disclosing its seed set, and whether technical disclosures had to be updated and corrected. The court resolved each issue, but the motion practice and hearings were time-consuming, expensive, and heavy with competing expert argument. The lesson: a technically ambiguous protocol does not eliminate the dispute; it relocates it. An e-discovery special master appointed early can draft unambiguous provisions before disputes arise, monitor compliance as the work proceeds, and decide technical issues that sit beyond the court’s or the parties’ expertise — eliminating rounds of consultant-versus-consultant briefing. The master costs money; the benefits often produce a net gain that is never realized when the court and parties are left to their own devices. > A technically ambiguous protocol does not eliminate the dispute; it relocates it. The appointment is scoped, priced, and time-limited at the outset — motion practice is none of these. ## § 03 · The mass-tort ledger The same economics govern at the largest scale. In mass tort litigation, courts appoint neutrals under Rule 53 to oversee the distribution of common benefit funds — the pools that compensate attorneys whose work benefited the entire group of plaintiffs. The appointed neutral verifies time and expense submissions, evaluates the value of each firm’s contribution, mediates allocation disputes among counsel, monitors compliance with judicial guidelines, and reports regularly to the court. Recent examples include In re Roundup Products Liability Litigation (N.D. Cal.), In re JUUL Labs, Inc., Marketing, Sales Practices, and Products Liability Litigation (N.D. Cal.), and In re 3M Combat Arms Earplug Products Liability Litigation (N.D. Fla.). Judges have repeatedly recognized why: unresolved fee disputes impede the progress of the litigation itself and can erode plaintiff recoveries. Early involvement by a court-appointed neutral prevents protracted fee fights, expedites resolution, and reduces the associated costs — while the neutral’s reporting obligations keep the process transparent and accountable to the court. ## § 04 · When the appointment pays The appointment tends to pay for itself when the answer to any of the following is yes: (1) Does the dispute center on preserving, collecting, or allegedly spoliating electronic data? (2) Does the data sit on proprietary or heavily customized systems? (3) Will a protocol need to be drafted — and compliance with it monitored — to govern the parties’ e-discovery obligations? (4) Are there large quantities of data to process, search, and review, with predictive coding or technology-assisted review in play? (5) Are fees or funds to be allocated across many firms with competing claims of contribution? Timing compounds the economics. It is faster and cheaper to bring in the neutral before issues arise than to remediate them afterward, and the Federal Rules leave little slack: Rule 16(b)(2) requires scheduling orders within 90 days after a defendant is served. A master in place before the first protocol fight is an investment; one appointed after the third is triage. The special master’s invoice is visible and easy to object to. The costs it displaces — briefing, hearings, dueling experts, stalled dockets, delayed recoveries — are diffuse and easy to ignore. Price the appointment against the disputes it retires, not against zero. Sources: Draws on “The Power of Neutrality” (2025), co-authored with Hon. Gail A. Andler (Ret.), and Legal Executive Institute articles on e-discovery special masters co-authored with Michael Mann. --- # The Evolution of the Technical Neutral How the technical neutral became a distinct role — from the 2006 e-discovery amendments and special masters to forensic appointments and the JAMS AI rules. URL: https://tailoredmediation.com/insights/evolution Published: January 09, 2026 · Category: NEUTRAL · PROFESSION · 6 min read The share of litigation cost consumed by electronic evidence has been climbing for two decades, and the questions at the center of commercial disputes have become machine questions: what a system did, where the data lives, whether the record of it can be trusted. The profession’s answer has been a role that barely existed at the turn of the century — the technical neutral. Its history is worth telling accurately, because the history explains what the role is for. ## § 01 · The eDiscovery wave The role begins with email. As electronically stored information swamped conventional discovery practice, The Sedona Conference spent the early 2000s building a shared vocabulary and principles for electronic discovery, and the 2006 amendments to the Federal Rules of Civil Procedure brought ESI formally within the discovery rules. Courts began confronting disputes — over preservation, formats, search, privilege — that neither judges nor generalist masters were equipped to referee, and the eDiscovery special master became a recognized appointment. The data kept growing faster than the process. Writing in 2016, I noted that 90 percent of the world’s data had been created in the preceding two years, arriving from automobile black boxes, cloud storage, and wearable trackers. The 2015 amendments answered by pushing responsibility onto the parties: Rule 1 was amended to direct the court “and the parties” to secure the just, speedy, and inexpensive determination of every action; Rule 26(b) codified proportionality; Rule 16(b)(2) cut the scheduling-order deadline from 120 days to 90. Chief Justice Roberts, in the 2015 Year-End Report on the Federal Judiciary, wrote that the careful assessment of actual discovery need “may … require the involvement of a neutral arbiter … to guide decisions.” Many attorneys took him at his word. The technical eDiscovery neutral’s work was procedural but real: developing processes to identify, extract, analyze, verify, and validate relevant data; drafting protocols to govern the parties’ discovery obligations; guiding keyword selection, predictive coding, and technology-assisted review — case-agnostic functions, useful in any matter with complex discovery. ## § 02 · From procedure to substance The second stage of the evolution was substantive, and the authority was already in place. Federal Rule of Civil Procedure 53(a)(1)(A) lets a judge appoint a master to perform duties the parties consent to; to address pretrial and post-trial matters that cannot be effectively and timely handled by an available district or magistrate judge; to make or recommend findings of fact in non-jury matters where an exceptional condition warrants it; and to perform accountings or difficult damages computations. What changed was what courts asked the appointee to do with that authority. A forensic neutral does both the legal work and the technical work: drafting forensic protocols and monitoring compliance with them; determining the existence and authenticity of digital evidence; performing or validating court-ordered purging of data from systems; analyzing deleted or corrupted data for evidence of wrongdoing; and auditing systems against a court order or regulatory mandate. The dual capability is the point. Consider two rival technology companies: key employees leave Company A for Company B, and Company B soon announces products that mimic Company A’s. Neither side can let the other — counsel included — into its source code or systems. A qualified forensic neutral with ties to neither party can examine both, answer the misappropriation question directly, and then make the remedy real by verifying that proprietary data is actually returned and deleted. The presence of a neutral technologist may be the most, if not the only, effective way of ensuring compliance with such an order. > The neutral does both the technical work and the legal work. That dual capability is what the role evolved to deliver — and why it keeps absorbing new classes of dispute. ## § 03 · The role broadens — mass torts and fund administration The same Rule 53 machinery now runs well beyond data disputes. In mass tort litigation, courts appoint neutrals to oversee the distribution of common benefit funds — verifying fee submissions, evaluating the value of each firm’s contribution, mediating allocation disputes among plaintiffs’ counsel, and reporting to the court. Court-appointed neutrals have played that role in recent years in In re Roundup Products Liability Litigation (N.D. Cal.), In re JUUL Labs, Inc., Marketing, Sales Practices, and Products Liability Litigation (N.D. Cal.), and In re 3M Combat Arms Earplug Products Liability Litigation (N.D. Fla.). An appointment that began as a way to referee load files now administers some of the largest fee allocations in American litigation. ## § 04 · The AI register The current stage is generative AI. Synthetic media has pushed authentication to the front of the evidence fight, and judges facing deepfake allegations must scrutinize exhibits as never before. As I have argued in the debate over amending Rule of Evidence 901, courts and parties should consider appointing technical neutrals or special masters where generative-AI authentication issues loom large: a neutral already fluent in the technology needs less briefing to get up to speed, relieves the court of sorting dueling experts, and tends to produce fairer and more accurate results at lower cost. The institutions have moved with the caseload — JAMS published rules purpose-built for disputes involving AI systems, a formal recognition that AI-centered disputes need procedures designed for them. ## § 05 · When to engage one The questions I proposed in 2016 for deciding whether to engage a technical neutral still hold, with the categories widened by a decade of technology: (1) Does the dispute center on preserving, collecting, or spoliating electronic data — or on what an automated system actually did? (2) Does it involve proprietary or heavily customized systems no outsider can casually read? (3) Will a protocol be needed to govern the parties’ compliance with their obligations? (4) Are there large volumes of data to be retrieved, processed, searched, and reviewed? If the answers run yes, engage early. It is far faster and cheaper to involve a neutral before the issues metastasize than to remediate afterward, and the compressed deadlines of the modern Federal Rules leave little room to improvise. The history has one throughline. Every time the technology outran the process — email, big data, forensic evidence, now generative AI — courts reached for the same instrument: a neutral who could read the machine and carry the law to it. Nothing about the direction of the technology suggests that will reverse. Treat the technical neutral not as an exotic appointment but as standard equipment for the technically contested case. Sources: Draws on Daniel's published work, including “Deciphering Digital Dilemmas” with Hon. Charles Margines (Ret.), “The Power of Neutrality” with Hon. Gail A. Andler (Ret.), and his Neutral Corner columns for Thomson Reuters. --- # eDiscovery and AI in ADR: A Practitioner's Guide How eDiscovery and AI reshape arbitration and mediation: TAR, predictive coding, data-privacy duties, and the ethics of disclosing AI use to a tribunal. URL: https://tailoredmediation.com/insights/ediscovery-ai-adr Published: February 17, 2025 · Category: AI · ADR · 5 min read There is a persistent assumption that alternative dispute resolution carries a lighter data burden than litigation. The instinct is understandable. Arbitration and mediation were built to be faster and less formal than the courtroom they were meant to relieve. But the instinct is wrong, and counsel who rely on it are increasingly caught flat-footed. The volume of electronically stored information at issue in a commercial dispute does not shrink because the parties chose a private forum. If anything, the expectation of transparency travels with the parties into the room. Knowing how to manage that information is no longer a specialty. It is a baseline obligation. Comment 8 to ABA Model Rule 1.1 is explicit: to maintain competence, a lawyer must keep abreast of the benefits and risks of relevant technology. eDiscovery and artificial intelligence are now squarely within that duty, and nowhere is the gap between obligation and practice more visible than in ADR. ## § 01 · eDiscovery does not stop at the courthouse door Electronic discovery is the process of identifying, collecting, and producing ESI, and ESI is everything now: email, chat, documents, databases, social posts, the metadata behind all of it. In litigation the rules force a discipline around this. In arbitration and mediation, the discipline is something the parties have to build for themselves, often under a procedural framework that gives them wide latitude. That latitude cuts both ways. In a complex intellectual-property or corporate matter, the production of a single decisive document can settle the dispute. The same flexibility that makes ADR attractive also breeds disagreement about the scope of discovery: what is relevant, what is proportionate, and how much one side can demand of the other before the burden becomes its own form of leverage. Counsel handling an arbitration should know the applicable provider rules on eDiscovery, including the JAMS rules, before the first exchange, not after a dispute over scope has already hardened. In practice, scope fights are rarely about the documents. They are about uncertainty. When neither side can see the shape of the other's data, every request looks like overreach and every objection looks like concealment. The work, early, is to give the room enough shared visibility that the parties can argue about substance rather than shadows. ## § 02 · What AI actually changes The honest version of the AI story in eDiscovery is narrower and more useful than the marketing version. Machine learning categorizes documents, surfaces themes, and flags likely-relevant material across volumes no review team could read in time. Technology-assisted review, or predictive coding, lets a model learn from human coding decisions and extend them across the larger set. The result is faster, cheaper review, which matters acutely in ADR, where parties chose the forum precisely to contain time and cost. AI's reach now extends past review into the resolution itself. Systems can mine historical case data to estimate likely outcomes, informing the settle-or-proceed calculus. They can compress sprawling records into summaries that help a mediator or arbitrator orient quickly. These are aids to judgment, and that qualifier is the whole point. > Predictive coding can inherit the bias in its training set. It can also expose a party to charges of under-inclusivity in what was searched. AI outputs are inputs to judgment, never substitutes for it. The failure modes are concrete. A skewed seed set teaches the model the wrong lesson and propagates it at scale. A poorly defended selection methodology opens a party to the argument that its production was under-inclusive by design. None of this is a reason to avoid the tools. It is a reason to keep a human accountable for the output and to be able to defend the methodology when an opponent, or the tribunal, asks how the set was built. ## § 03 · The duties that come with the tools Two obligations sit on top of the technical work. The first is data protection. Handling sensitive ESI means complying with the regimes that govern it, from GDPR in the EU to CCPA in California, and the obligation intensifies in cross-border ADR where regimes conflict. The platform a party chooses is part of this calculus; its security posture is the party's exposure. Mishandling data does not just threaten the matter. It threatens the client relationship and the practitioner's reputation. The second is candor. ADR runs on trust in a way litigation does not, because the parties consented to the process and to the neutral. When AI is used in a way that bears on the proceeding, the parties, and often the arbitrator specifically, should know. Disclosure is not a confession. It is the condition under which the technology strengthens the fairness of the process rather than quietly undermining it. This is the connective tissue across everything I write about AI in disputes: the tool is only as legitimate as the room's understanding of how it was used. ## § 04 · A working posture for practitioners For counsel building this competence, the practical advice is unglamorous and durable. Stay current; the field moves and CLE, provider resources, and serious industry writing are how you keep pace. Learn the tools you rely on well enough to state their limits, not just their features. Collaborate without ego, with forensic experts and eDiscovery consultants on the technical side and with opposing counsel on setting reasonable discovery parameters. Keep clients informed in plain terms about cost, benefit, and risk. And develop the negotiation instinct to land discovery scope at a point that is transparent enough to be fair and bounded enough to be efficient. That balance, transparency against efficiency, is the through-line. It is the same calculus whether the matter is headed for arbitration or whether it can be resolved in mediation, and it is the question I find parties most ready to answer once they can see their own data clearly. The technology will keep advancing. The discipline of using it carefully, disclosing it honestly, and keeping human judgment at the center is what will separate the practitioners who harness these tools from the ones who get caught out by them. Sources: Adapted from “Mastering eDiscovery and AI in ADR: A Guide for Legal Practitioners” (2025), co-authored with Bradford Newman. --- # Forensic Neutrals in Large-Scale Litigation How a forensic neutral resolves the data-driven disputes at the center of large commercial litigation, from FRCP 53 authority to ex parte seizure relief. URL: https://tailoredmediation.com/insights/forensic-neutrals-litigation Published: January 28, 2025 · Category: FORENSICS · 5 min read Large commercial litigation has changed shape. The disputes that once turned on contract language and witness credibility now turn on what a system did, when it did it, and whether the record of it can be trusted. Deciphering a digital trail, establishing the integrity of electronic evidence, understanding what a particular technology can and cannot do — these are no longer adjacent to the merits. They are the merits. And they are not questions a judge, a jury, or even most trial counsel are equipped to answer alone. This is the problem a forensic neutral exists to solve. I have written before about the forensic record as a mediation asset and about the long evolution of the technical neutral as a recognized role. Here I want to be more specific about the function in its hardest setting: the large, data-driven commercial dispute where the stakes are high, the technology is genuinely contested, and time is short. ## § 01 · What a forensic neutral is, and where the authority comes from A neutral is an auxiliary judicial officer appointed by the court to assist with specific aspects of a case. The role is not new — it has been part of the American legal system for decades — and it is not a substitute for the judge or the jury. Its purpose is to enhance the court's comprehension of issues that demand specialized knowledge. In federal court, the authority sits in Federal Rule of Civil Procedure 53(a)(1)(A). A judge may appoint a master to perform duties the parties consent to; to address pretrial and posttrial matters that cannot be effectively and timely handled by an available district or magistrate judge, even without consent; to conduct trials and make or recommend findings of fact in non-jury matters where some exceptional condition warrants it; and to perform accountings or difficult damages computations. In state court, the law may or may not require party consent, and an appellate decision may have already settled the question. Courts reach for a neutral when a case involves a complex or specialized area of law, when discovery requires heightened and extensive oversight, or when the matter calls for fact-intensive non-jury determinations. What distinguishes a forensic neutral from a special master generally is that the forensic neutral does both the legal and the technical work. A neutral qualified in data forensics has the credentials to understand a protective order's technical requirements, the standing to draft and monitor compliance with a forensic protocol, and the ability to perform the technical work itself. That dual capability is the entire point. It is what saves the time and money that dueling party experts otherwise consume. ## § 02 · The work in a large commercial dispute In large, data-driven matters, the forensic neutral's mandate tends to cluster around a recognizable set of tasks: drafting forensic protocols and confirming compliance with them; establishing the existence and authenticity of digital evidence; performing or validating the court-ordered or settlement-related purging of data from systems; analyzing deleted or corrupted data for evidence of wrongdoing; examining the actual limitations of the systems at issue to determine what can and cannot readily be done; and auditing systems against a court order or regulatory mandate. The value rises sharply where injunctive or ex parte seizure relief is in play. That relief frequently requires highly technical collection, transfer, and deletion of sensitive data under severe time pressure, in exactly the circumstances where experience is most scarce and most expensive. A qualified forensic neutral can deliver that relief equitably and efficiently because the same person who understands the order also understands the machine the order operates on. > The presence of a neutral technologist may be the most — if not the only — effective way of ensuring compliance with an order to return and delete proprietary data. ## § 03 · A familiar scenario Consider two rival technology companies. A handful of key employees leave Company A for Company B. Shortly after, Company B announces a product line whose functionality mimics, and perhaps exceeds, Company A's. Company A suspects its departed employees breached the confidentiality obligations that survived their departure. But the answer does not live in the new product's functionality, however suggestive that may be. It lives in the actual code behind the functionality, and in whether Company A's documents are sitting on Company B's systems. Even if Company B is entirely innocent, it has a legitimate objection to handing a direct competitor — counsel included — access to its source code and systems. Company A has no more desire to expose its proprietary information through discovery. A properly qualified forensic neutral with no ties to either side, granted access to both parties' systems and code, resolves the impasse that would otherwise be intractable. And if the neutral finds Company A's information on Company B's systems, the neutral can ensure Company B actually returns it and deletes it, rather than merely promising to. The neutral does not just find the fact. The neutral makes the remedy real. ## § 04 · Where this is heading Digital data is growing exponentially, and its relevance to commercial disputes is growing with it. The gap between technical intricacy and legal complexity is widening faster than most litigation teams can close it on their own. The forensic neutral bridges that gap — not to make the case easier, but to make it accurate. As courts and counsel grow more comfortable with the role, I expect the forensic neutral to move from an exceptional appointment to a default consideration in any large, technically contested matter. The work of a technical special master is increasingly indistinguishable from the work of getting these cases right. That is where it should be. Sources: Adapted from “Deciphering Digital Dilemmas: Forensic Neutrals in Large-Scale Litigation” (2025), co-authored with Hon. Charles Margines (Ret.). --- # Ransomware and Cyber Insurance: Exclusions, Endorsements, and the Risks of Paying What cyber coverage actually buys in a ransomware event — first-party vs. third-party coverage, the war exclusion after NotPetya, and the OFAC risks of paying. URL: https://tailoredmediation.com/insights/cyber-insurance-ransomware Published: January 22, 2025 · Category: CYBER · INSURANCE · 6 min read Ransomware is a type of malware that prevents users from accessing their systems or files absent payment of a ransom, and the attacks have long since stopped discriminating. When Peter Halprin and I examined this landscape in the Journal of Internet Law, 2020 had seen a seven-fold rise in ransomware attacks over the prior year, with reported strikes on school districts, hospitals, and even institutions working on COVID vaccines. For businesses, government entities, and other institutions facing such attacks, insurance may be available to help them through the event and recover income losses. But the coverage is only as good as the insured's understanding of its exceptions and exclusions — and in ransomware, the exclusions are where the disputes live. ## First-party, third-party, and the endorsement trap Start with the structure of the product. Insurance contracts generally divide into first-party coverage, which pertains to loss or damage sustained by the insured to its own property, and third-party coverage, where the insurer's duty to defend and pay runs to claims others bring against the insured. A ransomware event can implicate both at once — the insured's own locked systems and lost income on one side, and the customers, banks, and regulators affected by the breach on the other. Effective cyber insurance therefore has to cover three key types of risk: network security (first party), errors and omissions (third party), and privacy (third party). That is why many stand-alone cyber policies are a hybrid of first- and third-party coverage. The cheaper alternative — a cyber endorsement bolted onto an existing CGL, professional liability, or property policy — is where insureds most often discover a gap at the worst moment. Camp's Grocery, Inc. v. State Farm is the cautionary tale. After a data breach compromised customer card information, three credit unions sued the Alabama grocer, which turned to the cyber endorsements on its property and casualty policy for defense and indemnity. The federal court held that the endorsement's promise to pay for “accidental direct loss” unambiguously provided first-party coverage only — it imposed no duty to defend the credit unions' third-party claims. The lesson: an endorsement can be a reasonable, lower-cost approach for a company whose primary exposure really is first-party (breach notification, forensics, remediation), but a company that assumes an endorsement works like a stand-alone policy will most likely be left with significant gaps. Cyber insurance is never one size fits all, and with endorsements the devil is in the details. ## The war exclusion after NotPetya One might not expect the “war” exclusion in a property or cyber policy to have any bearing on a malware claim. The issue came into prominence in 2018, when Mondelez International sued Zurich American Insurance Company after suffering losses from the NotPetya malware — an attack whose goal, as reporting at the time put it, was purely destructive: it irreversibly encrypted machines' master boot records, and no key even existed to restore what any ransom payment might have bought. Zurich denied the claim based on an exclusion for “hostile or warlike action.” The case law counsels against stretching that language. In Universal Cable Productions, Inc. v. Atlantic Specialty Insurance Co., 929 F.3d 1143 (9th Cir. 2019), the Ninth Circuit — construing a war exclusion outside the cyber context — held that “war” in the insurance context is limited to hostilities between sovereigns or entities essentially like governments, and noted the leading treatises' warning that an insurer invoking war and sovereign-act exclusions faces steep factual, legal, and political hurdles. That definitional problem is compounded in cyberspace, where the line between cybercrime, espionage, terrorism, and warfare is genuinely blurry, and where attribution — the thing the exclusion turns on — is often non-existent. Policyholders, brokers, CFOs, in-house counsel, and risk managers should pay close attention to the wording of war exclusions before the claim, not after. > Paying a ransom does not guarantee the return of access to data, it emboldens the attackers — and if the payee is sanctioned, it can violate U.S. law on a strict-liability basis. ## The risks of paying However tempting, paying a ransom is not recommended, for three reasons. First, payment does not guarantee the return of access to data. Second, it emboldens and enables cybercriminals to continue launching attacks. Third, payment can itself be illegal. On October 1, 2020, the U.S. Treasury's Office of Foreign Assets Control issued its Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments. U.S. persons are generally prohibited from transacting with individuals or entities on OFAC's Specially Designated Nationals and Blocked Persons List or covered by country embargoes, under the International Emergency Economic Powers Act and the Trading with the Enemy Act — and facilitating a payment by someone else can be a violation too. The sharpest edge is strict liability: OFAC can impose civil penalties even where the payer did not know, and had no reason to know, that it was engaging in a prohibited transaction. The practical protocol follows directly. (1) Before any payment is considered, check whether the criminal entity appears on OFAC's lists. (2) Financial institutions and intermediaries should maintain risk-based sanctions-compliance programs that specifically account for ransomware payments touching an SDN or embargoed jurisdiction. (3) Practice caution and cooperate with law enforcement during and after the attack — cooperation is protective in any later enforcement posture. (4) Treat the decision as a cross-functional one: the risk can be mitigated when corporate finance, insurance, legal, operational, and technical professionals work together closely, rather than leaving the decision to whoever is holding the incident bridge line at 2 a.m. ## What this means for the coverage fight Every one of these pressure points — first-party versus third-party characterization, endorsement scope, the war exclusion, the propriety of a payment — is a technical question wrapped in policy language. The disputes turn on what the forensic record shows about what the malware did, who sent it, and what the insured's systems lost. Coverage fights of that shape are well suited to resolution by a neutral who can read both the policy and the record; the alternative is years of motion practice over facts that a technically fluent process could establish in weeks. Read the policy before the incident, question the exclusions before renewal, and check the sanctions lists before anyone pays anything. The time to discover what your cyber insurance actually covers is never the week of the attack. Sources: Adapted from “Placing Ransomware in Context and Avoiding Liability for Paying Ransomware Claims,” Journal of Internet Law (2021), co-authored with Peter A. Halprin, and “Cyber Endorsements: Proceed with Caution” (2017). --- # Attorney-Client Privilege for In-House Counsel Best practices for in-house counsel asserting attorney-client privilege over ESI: defining the client, legal vs. business advice, and avoiding waiver. URL: https://tailoredmediation.com/insights/privilege-in-house-counsel Published: January 7, 2025 · Category: eDISCOVERY · 5 min read The attorney-client privilege is a cornerstone of legal practice. It exists to foster open and honest communication between a client and its lawyers. For in-house counsel, that simple premise turns out to be deceptively hard to live by. In-house attorneys operate at the intersection of legal and business functions, and that position complicates almost every element of the privilege analysis. Recent decisions in matters such as Garner v. Amazon.com and Epic Games v. Apple illustrate just how often the assertion of privilege by in-house lawyers is challenged, and how often those challenges find traction. The privilege protects only a narrow class of communication: communications made in confidence, between privileged persons, for the purpose of obtaining or providing legal assistance. Each of those three requirements carries a trap for in-house counsel, and the volume of corporate ESI makes every trap larger. A single misjudgment about who the client is, or whether a given email rendered legal advice, can expose an entire thread to discovery. ## Who is the client? The first requirement is that an attorney-client relationship exists at all. In the corporate context, the client is the corporation, not any individual employee. But corporations act through people, which forces the question of which individuals can be treated as the client for privilege purposes. Courts answer with two main tests. Under the subject-matter test, the privilege applies where communications concern matters within the scope of the employee's corporate duties and the employee understands the discussion is occurring so the corporation can obtain legal advice. That phrasing comes from the Supreme Court's 1981 decision in Upjohn Co. v. United States. The point that often gets lost is that the test turns on the employee's understanding. It is in-house counsel's job to make sure employees actually know when counsel is giving legal advice to the corporation. The narrower control-group test, articulated in Consolidation Coal Co. v. Bucyrus-Erie Co., extends the privilege only to decision-makers and those who substantially influence corporate decisions, which in practice means controlling executives and key managers. ## Legal advice versus business advice Not every communication with a corporation's lawyers is privileged. To be protected, a communication must be made in furtherance of the rendition of professional legal services. When a lawyer supplies business advice rather than legal advice, the privilege does not attach. In-house counsel routinely serve a dual role as legal and business advisor, and that dual function is exactly what makes the determination difficult. When a communication serves both purposes, courts have split on how to evaluate it. In United States v. ChevronTexaco, the court applied the because-of test in the work-product context, asking whether the document was created because of anticipated litigation and would not have been created in substantially similar form but for that prospect. That test does not ask whether litigation was the primary or secondary motive. The competing primary-purpose test asks instead whether the communication's primary purpose was to give or receive legal advice. The Second, Fifth, Sixth, and Ninth Circuits follow the primary-purpose test, while the D.C. Circuit will recognize privilege where one significant purpose of the communication is legal. In 2023 the Supreme Court dismissed In re Grand Jury, which had asked the Court to clarify the standard for dual-purpose communications. The dismissal left the circuit split intact. For in-house counsel drafting and receiving thousands of mixed-purpose communications, that unresolved split means the protection of a given message can depend on the circuit in which it is later litigated. ## Confidentiality and the limits of cc The communication must also be intended to remain confidential. Even a communication between a lawyer acting as legal advisor and an individual inside the corporate client group loses protection if the parties do not behave as though they intended it to stay confidential. Courts have been explicit that a corporation cannot insulate its files from discovery by copying or cc-ing in-house counsel. > A corporation cannot insulate its files from discovery simply by copying in-house counsel. Labeling an email privileged does not make it so. The antitrust ruling in United States v. Google is the cautionary tale. Beyond the antitrust questions, the court addressed the plaintiff's request for sanctions over Google's systemic destruction of documents and its alleged misuse of privilege. The misuse charge grew out of Google's communicate-with-care initiative, under which employees were told to add in-house attorneys to certain antitrust-related emails and mark them as attorney-client privileged. Several initially withheld emails were predominantly non-privileged, distinguished only by a single line noting that an attorney had been cc'ed for legal advice. The court declined to sanction Google, but warned that the company had to take rigorous steps to ensure that documents labeled privileged were in fact substantively privileged. ## Practical steps to avoid forfeiting privilege A few disciplines go a long way. Keep legal and business communications in separate emails where feasible, and where they must mix, expressly identify the legal theories and conclusions and set them apart from the business discussion. Control the copying: train employees that cc-ing an attorney does not, by itself, confer privilege. Label documents accurately to reflect their confidential and privileged status, and make clear that counsel is acting in a legal capacity. And educate the business. Headers like Privileged and Confidential should be used judiciously, because overuse dilutes their meaning and gives an adversary an easy waiver argument. When there is any doubt, in-house counsel should remind an employee that counsel represents the corporation and not the individual, particularly once the individual begins disclosing something sensitive. These are not exotic measures. They are habits, and habits are what survive the scale of modern ESI. When a privilege dispute does land in front of a tribunal, the same discipline pays off again. A neutral asked to referee a privilege fight, whether sitting as a special master over a contested log or as a forensic neutral examining how documents were created and routed, can resolve far more quickly when the corporation's privilege practices were principled rather than reflexive. The cases above show what scrutiny looks like when they were not. For in-house counsel, the work of protecting privilege is done long before the dispute, in the ordinary discipline of how legal advice is sought, given, and recorded. Sources: Adapted from “Challenges for Asserting Attorney-Client Privilege for In-House Counsel and Best Practices” (2025).