Meet and Confer with Kelly Twigger

The First Stipulated ESI Protocol For Generative AI Review

Kelly Twigger

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 41:15

A new line just got crossed in e-discovery: a federal stipulated ESI protocol treats generative AI document review as its own governed process, and it requires disclosures many lawyers have spent years trying to protect. We walk through James v Cerebro Systems, where the parties agree to an AI-specific review appendix that demands documented workflows, human-confirmed privilege calls, audit trails, and prompt disclosure with rapid redline updates.

We unpack how the protocol is built and why that structure matters: search terms, TAR, and “AI responsiveness review” each get their own rulebook, plus explicit controls for layering methods that can silently compound missed responsive documents. Then we dig into the details that will change meet and confer conversations, including 95% confidence level sampling with a plus or minus 2% margin of error, reporting of recall and precision, an “illusion” rate trigger, and required quality checks for hallucination, oversummarization, and misclassification. The bottom line is clear: AI doesn’t reduce counsel’s Rule 26G duty, it raises the bar for defensibility.

We also connect the ESI protocol to the companion protective order, where AI use on protected material turns on contract terms in a data processing agreement, not hype about a brand name. We explain what it really means when an order references enterprise ChatGPT or Harvey, why consumer accounts typically fail the “no training” requirement, and how these rules can create new incentives to over-designate confidentiality.

Subscribe to Meet and Confer for more case-driven discovery strategy, and if you found this useful, share the episode with a colleague and leave a review with your biggest takeaway.

Thank you for tuning in to Meet and Confer with Kelly Twigger. If you found today’s discussion helpful, don’t forget to subscribe, rate, and leave a review wherever you get your podcasts. For more insights and resources on creating cost-effective discovery strategies leveraging ESI, visit Minerva26 and explore our practical tools, case law library, and on-demand education from the Academy.  

Unplugging And The AI Milestone

Kelly Twigger

Hi, and thanks for joining me this week. Last week I was on vacation, enjoying the incredible beauty of Yellowstone and Grand Tetons National Parks near Jackson, Wyoming. It was the first time in probably years that I have not touched my laptop for a week and it was blissful. So if you need a push to take a real unplugged vacation, I'm giving it to you right now. If it helps, you can do what I did and go somewhere where that has no internet coverage. So you don't have a choice. That works. All right, back to our topic de jour. For the last year on this show, I've been tracking how courts are working through artificial intelligence and discovery. The privilege fights over a litigance prompts, the judges starting to write AI terms into their protective orders, the slow realization that the rules we have are not built for any of this. Today we hit a genuine milestone in that arc. And I want to walk you through all the pieces carefully because it's going to shape how these protocols get written for the next several years. This case is called James versus Cerebro Systems. And what the parties did here is, as far as I have seen, created a first, a stipulated ESI protocol that governs the use of generative AI to review and produce documents as its own category with its own disclosure rules, its own validation math, and a requirement that the party using AI to decide what gets produced disclose the prompts it used to do it. And the parties agreed to all of it. Nobody fought. That, as much as any single provision, is really the story here. And I will tell you up front that when I read it, I thought I would never agree to any of this. So I'm not entirely sure why they did it. Welcome back to the Meet and Confer podcast. This is the case of the week series where I choose a recent decision or order on the discovery of ESI and turn it into practical advice for you to use. My name is Kelly Twigger. I'm the CEO and founder at Minerva 26 and the principal at ESI Attorneys. And I've been a discovery strategist and practicing attorney for just about 30 years. Let's talk about why orders like this one belong on your radar. There are more than 5,000 discovery decisions issued at the federal level every year, and that has held for the last four to five years. About 80% of those decisions on ESI come from magistrate judges. And less than 1% of civil cases go to trial, which means that these cases are won and lost on discovery. If you are not watching how sophisticated parties are handling AI in that process, you are already behind. And you may want to make the argument that your client doesn't have as much information. They're not as sophisticated, they don't have the budget. And here's my response to that: the less money you have, the more diligent you need to be about addressing these ESI issues. So if you've got clients that are dealing with smaller matters with lower budgets, you actually need to have more knowledge than your clients who have wiggle room for you to figure it out. Now, in this case, there are two orders, both entered by United States Magistrate Judge Robert M. Ilman on July 6, 2026. And you need to keep them straight because they do two different jobs. Document 74 in the case on the docket is the ESI protocol. It's the stipulation and order regarding

Why This Stipulated Protocol Matters

Kelly Twigger

the production of electronically stored information. Document 75 is a companion order. That's the stipulated protective order. Now I'll come back to how the two work hand in hand because it turns out to matter a great deal with how the party set them up here. Now, before we get into the provisions, I want you to remember something. Nothing in the federal rules required any of this. Rule 26 obligates a party to provide relevant proportional discovery. Rule 34 governs the form in which documents are produced. Neither rule says a word about disclosing your prompts, your validation methodology, or your allusion rate. Those obligations exist in this case for one reason and one reason only. The parties agree to them. Now, this was a stipulated order, negotiated and consented to, not an order that a court imposed after a fight, not the kind of scorched earth discovery battle that we watched in the open AI cases. So as I walk through how demanding this protocol is, keep thinking about this question. Why would sophisticated parties agree to expand their own obligations this far beyond what the rules would require? Now we've had this debate on case of the week about TAR and search terms. How much are parties really obligated to share in meeting their obligations under the rules? It's been left up to what the parties agree to or what individual courts order on motion. We've not seen this before where parties have just flat out agreed to it. Let's dive into what the facts are here. The case underneath these orders is a copyright class action. The plaintiffs are authors. The defendant, Cerebro Systems, is released a family of open source large language models called Cerebrous GPT. And the plaintiffs allege that these models were trained on a data set called the PICE, the Pile, excuse me, the PILE, which contains a subset known as Books 3, described in the complaint as derived from pirated books. Now, let me be precise about exactly what this case is because the AI chip company that is Cerebrus can mislead you. Cerebrus is best known as a hardware company that builds chips for AI. Think of it like an NVIDIA that you might be familiar with. But this claim is not about the chips, it is about Cerebrus GPT, the models, and the allegation that they were trained on pirated books. Cerebrus used its own chips to build a model to show off allegedly how much faster its chips are than other chips on the market. That makes this class, this case, materially identical to the author cases in actions against OpenAI, Anthropic, and Meta. Same theory, same kind of data set, just a different defendant. The only real wrinkle is that a company better known for selling the hardware is now on the receiving end of the same copyright claim as the model builders. Now, let's look at who is at counsel table because it really matters here. For the plaintiffs, Leif Cabrazer, Hyman and Bernstein, and McGuire Law, serious class action firms who know and understand Discovery. For Cerebrus, Kecker, Van Nest, and Peters. Kecker may not be a firm that you have heard of, but they are a very well-respected litigation boutique firm with very high-profile clients. Kecker is the same firm with some of the same lawyers, including Robert Van Nest, that serve as OpenAI's lead trial counsel in the AI copyright cases. So the lawyers who negotiated this meticulous AI-specific protocol are the same defense lawyers living through the discovery wars in the OpenAI litigation. That's not a coincidence, and I think it's a large part of why this order looks the way it does. One more piece of context specific to this courthouse. The Northern District of California has a model-stipulated ESI order on its books for litigants to adopt since 2015. It is, quite frankly, and I've discussed this before, pretty hopelessly out of date because it predates the discovery problems that we have dealt with since 2015, let alone generative AI. The ESI protocol says on its face in the opening recital that the party started from the court's model order, and the court's standing order required them to attach two things: a declaration explaining every modification they made, and a red line comparing their version to the model. They had to show their work. The fact that this judge let them modify a decade-old form this heavily, building entire TAR and AI appendices into it, is a good sign. It is also different from how a lot of judges treat their standing protocols, where deviation is discouraged and you're really nudged back toward the form. Magistrate Judge Ilman let the parties tailor the model to the technology. And that's a great instinct, and I hope

The Copyright Fight Behind The Order

Kelly Twigger

that more courts follow that path. All right, let's start with the shape of the entire protocol because the AI piece only makes sense once you see where it sits. The heart of this ESI protocol is section seven, titled Search and Review. And it does something that I want you to take in as a whole before we get to any one part. It expressly authorizes and governs three different ways to cull and review documents, and it addresses combining them or so-called layering. First, search terms, capped at 20 search terms per custodian per party with required HIT reports and a null set test on the documents that do not hit. Second, technology assisted review or TAR, the predictive coding process where you train a classifier to rank documents by likely responsiveness, which gets its own rulebook in appendix three in the protocol. Third, artificial intelligence, which gets its own separate rulebook in appendix four in the protocol. And section 7.6 governs what I refer to as layering, which is using more than one of those methods on the same set of documents. So the architecture is simple to state. You choose your method or methods, you disclose that choice. And if you're using tar, or you hand over, you hand over the matching appendix in either three or four, pursuant to the protocol. Everything else flows from that. Now, most of what this protocol requires goes well beyond rule 26. And a fair amount of it brushes right up against the material that is arguably privileged or work product, the prompts you wrote, how you trained your model, your validation results, your error rates. So my instinct as council is generally to protect all of that and not hand it over. Why consent here? What is the thought process behind the parties? And the most plausible read that I can see is the council who lived through the open AI discovery fights decided that a detailed, agreed-upon protocol up front is going to be cheaper and more predictable than litigating every AI question by motion one expensive fight at a time. It also draws the litigation out ears. OpenAI also lost most of those battles and had to disclose the information anyway. So this level of detail buys peace, but you buy that piece by expanding your own obligations and trading away protections you would have otherwise had. Now that's a real strategic decision and not an obvious one, but it goes to one of the themes that we're always talking about here on Case of the Week. You need to sit down early in your case, understand what the issues are going to be, understand who counsel is on the other side, and make strategic decisions that are appropriate for that case. Protection, hostility, those are things that ultimately cost money. You have to make great decisions for your clients. And perhaps that's what drove the decision of the protocol here. Now, with that frame, let's talk about the actual protocol itself. Now, section 7.8 of the protocol creates a distinct regime the order calls AI responsiveness review. And it defines it broadly as workflows using, quote, large language models, deep learning classifiers, embedding-based similarity analysis, semantic clustering, predictive redaction systems, or generative summation models to decide whether a document gets produced, withheld, or redacted. Six different technologies that make up AI, not one. Now that's a far wider net than TAR. If you use a large language model or any of those tools in that list to make responsiveness or privilege calls, you are in the regime of this protocol and you must disclose that election to the requesting party. And under section 7.9, you must provide an AI review protocol containing everything in Appendix 4. So let me tell you what Appendix 4 actually requires because the scope of it is what will blow your mind. From a workflow standpoint, if you use AI to decide what gets produced, then how the AI reach those decisions, every single one of the decisions must be documented. Your privilege calls must be human confirmed, and the entire process is disclosed to your opponent. The AI's decision making actually becomes part of the discovery. Specifically, Appendix 4 requires you to disclose at a minimum these things. The system itself, including the identity, version, and hosting environment of each AI model, whether it runs on-prem, in a private cloud, or in a vendor-secured environment, plus a statement that the system is, quote, generally accepted within the e-discovery industry as a reasonably reliable tool. Close quote. Now, we'll come back to that later, but if any of you use these AI tools on a regular basis, you'll always notice that in the lower left-hand corner, you often see a relaunch button almost every single day that you log into it. Meaning that every day that you use the system, you're using a different model. So one question that I have in reading this protocol is do I have to document every single time the model changes if I'm updating it? It sounds like yes. Next, the universe of data. The criteria that is used to select the documents the AI reviewed, including any culling done before the AI ran, whether that includes search terms, date ranges, custodians, deduplication, threading, or near deduplicates,

Search Terms TAR And AI Layering

Kelly Twigger

near duplicates suppression. Vacation brain is kicking in. And which document types were excluded from AI analysis and how those were reviewed instead. If that's manual, who reviewed them? It even asks for the credentials of the reviewers doing this work. Next, the training and the prompts, the methodology used to train or instruct the system, the sources of training and validation data, the identity and qualifications of the people who designed, trained, and validated it, any documents excluded from training, and disclosure of all prompts, templates, instruction sets, and parameter configurations with any change to a prompt served in red line within three business days. Now think about how often you iterate on your prompts. That's going to be a quite a feat to be able to provide within three business days. So there's going to have to be a very well-articulated process up front in order for this not to become a nightmare. Next, the protocol outlines the scoring, how the system generates scores, classifications, or decision boundaries, and the thresholds used, the distribution of scores from the initial run and how many documents were placed in each category, including responsive, non-responsive, privileged, uncertain, or requiring further review. Next, the protocol requires oversight. Who conducted oversight, privilege review and validation, the review workflow used, the number of documents manually reviewed, and the quality control procedures, which must include human confirmation of privilege determinations, checks for hallucination, oversummarization, and misclassification by the AI, as well as testing of prompt performance. Next, the iteration. How many times the model or the prompts were adjusted during the review and how that changed the results. Again, those red line prompts have to be provided every three business days. Next, the validation. The validation method that's used, a sample of the documents the AI excluded as non-responsive, sized at a 95% confidence level with a plus or minus 2% margin of error. The resulting richness, recall, precision, and illusion rates, and a duty to meet and confer and take corrective measures if illusion exceeds 3%. Next, the audit trail and security. All AI processing must occur inside the secure review environment holding the documents with no content exported to an outside model except by written agreement. The responding party must retain audit materials, including prompt iteration logs and configuration records, and any genuinely proprietary prompt may be withheld, but must be logged and made available for attorney's eyes inspection under the protective order. Now that is a remarkable amount of transparency to sign up for. Now let me pull out those pieces that matter most for us to consider. The prompts are the provision that people are going to focus on most. You are disclosing all of them and every change to them in red line on a three-day clock. And we've spent time this year on whether a litigant's own AI prompts are protected. Warner versus Gilbarko said yes, they are work product and gave us the line that an AI platform is a tool, not a person. Morgan versus V2X agreed for a pro se litigant. So there is law that prompts can be protected work product. And here the parties just agreed to hand them over. Now that is not a court overriding a work product objection. It is a sophisticated set of parties on both sides of the V trading away that protection by stipulation, which is exactly the kind of protection that I think would be hard to do. I think that that's something it would be very difficult for many lawyers to sit down and think about doing. I'm not saying it's a bad idea here because I think in the scope of what this litigation is and the potential to move it forward faster and get to the merits of the case, it probably has an incredible strategic angle to it. But it's going to be hard for a lot of folks to accept. The one escape patch is the first place that the two orders touch, the protocol and the protective order. A genuinely proprietary prompt can be withheld, but it has to be logged and shown to opposing counsel's eyes only under the protective order. So it's not a clear, this is privileged, you don't get to see it. It's we're saying it's privileged, but we'll show it to the lawyers, and the lawyers can determine whether or not they get to argue that it's privileged. So it's even giving up some of that on that level as well. It's it's it's gonna be hard to see how that gets implemented. I'm I'm interested to see how this plays out. The validation numbers also strike me as high, and I think that's really worth pointing out. A 95% confidence level is standard for this kind of sampling, but a plus or minus 2% margin of error is tight. A lot of TAR validation runs at a 5% margin, and tightening from 5% to 2% multiplies the number of documents you have to review in your validation sample by six times because the sample size grows with the square of the precision that you demand. And an illusion expectation of 3% or lower is also pretty aggressive. The case law that blessed Tar, going back to DeSilvamore and Rio Tento, focused on whether or not the process was reasonable and cooperative, not on hitting a hard number target. And

Appendix 4 Prompt Disclosure And Validation

Kelly Twigger

recall in the range of 70 to 80% has generally been treated as defensible. So what these parties agreed to sits at the very demanding end of anything the TAR world has required, and it's now being applied to AI. That's a lot to take on voluntarily, which is again my whole question about this order. I'm gonna guess, given the level of sophistication of these parties, that they've used these systems that they're engaging with, that they understand what they're taking on, but it's gonna create a huge burden. The next thing to consider is that the quality control requirement writes the failure modes of generative AI into a discovery protocol. Appendix 4 requires checks for hallucination, oversummarization, or misclassification. A federal court order, remember Rule 37B, sanctions for violation of a court order, now expects your document review to include a documented check against the AI making things up. And it comes with a backstop that I want every person on your team to hear. The order states that, quote, legal counsel remains responsible for ensuring the accuracy and completeness of all productions, close quote. The AI does not absorb the lawyer's duty under Rule 26G. You cannot point at the model when a production is wrong. These tools do not reduce the duty of care, they raise it. On security, all AI processing has to happen in. Inside the secure review environment with no document content exported to an outside model absent agreement. In plain terms, you cannot pipe the collection out to a public model. That one sentence tells you how firms and vendors can and cannot deploy these tools for this case under this protocol. If that's not how you want your case to work, don't copy the language of this protocol. Adjust it for the way that the technology works in your case. That is critical. And a little quieter point on this generally accepted standard that's in Appendix 4. That appendix makes you certify that the system is generally accepted in the e-discovery industry as reasonably reliable. It will not be a fight in this case because the parties agreed on that their systems met that standard. But notice what the phrase is asking because it will matter elsewhere. Who decides what is generally acceptable for a tool that may be six months old? We have decades of literature and case law validating tar. We have nothing like that consensus for large language models used to make responsiveness calls. And the tools are changing faster than anyone can evaluate them. We don't know yet what generally accepted means for this technology, and that undefined standard is going to get tested somewhere. Finally, layering, which is discussed in section 7.6 of the protocol, is the quiet provision that really matters here. Layering is using two culling methods on the same set of documents, say search terms and then tar or search terms and then AI. The document has to clear both filters. The problem is that each method independently misses some responsive documents, and stacking them compounds the loss. The keyword pass strips out responsive documents that do not contain your terms, and the tar system never sees them or the AI system. So the protocol makes you disclose the intent to layer before you do it, meet and confer, compare the hit counts with and without layering, and let the requesting party sample the excluded set. The risk is not the technology, it is the undisclosed, unvalidated combination of the two technologies. So transparency about process is what makes a review defensible, and this provision writes that down. We've not seen anything this comprehensive in addressing that layering concern in a protocol before. I think it's kind of genius. Now, let's talk about how the two orders work hand in hand, the ESI protocol and the stipulated protective order. The documents are designed to interlock, and if you read one without the other, frankly, you're going to misunderstand both of them. The difference that you can't lose sight of is the scope. The ESI protocol, which is document 74 from the docket, governs your entire review and production. Everything. Every document, whether or not it is ever designated under the protective order. The protective order, which is entry 75 on the docket, reaches only the material a party actually designates as protected using the categories in the protective order. Protocol applies to everything. The protective order applies to a subset. That distinction drives the next point. In section 13.4 of the protective order, which governs running protective material through generative AI tools, that section says that a party may use AI tools on that material only where the tool does not train on it and meets industry security and industry standard security, I should say. And then it names names, stating that quote, the party's enterprise chat GPT and Harvey accounts satisfy the foregoing requirements. Close quote. Now read this carefully because it is easy to get it wrong. It does not mean that ChatGPT, Enterprise Chat GPT, and Harvey are the only two tools you can use, and it does not bless them for everyone. It means that these parties review the data processing agreements called the DPA behind their own enterprise chat GPT and Harvey accounts, confirmed that those contracts prohibit training on the data and provide the required security, and put that finding in the order. This is a contract point, not a technology point. Plenty of other tools meet that same bar. The difference between a consumer account and an enterprise account is entirely a difference in the data terms. The enterprise DPA, data processing agreement, again, is what promises no training and delivers the security controls. And a consumer account does not do that. So if you adopt this language, the takeaway is not use ChatGPT Enterprise or Harvey. It is review your own tools DPA, confirm it meets this requirement, and get that verification into the record in your protocol if necessary. Now, this did not come from nowhere. This is the direct descendant of Morgan versus V2X, where Judge Brasswell wrote a new AI-specific language into a protective order requiring that any AI platform carry a contractual prohibition on training, flow that prohibition down to third parties, provide a right to delete the data and be documented in writing, which are functionally the terms of a DPA imposed from the bench. These parties took that same logic and stipulated it, stipulated to it in their protective order. They went one step further than Judge Brasswell required by verifying and naming their tools. That was not actually, I think it was mentioned in Morgan versus V2X that the parties were required to disclose their tools. And that has come up in other cases as well. But in Warner, in the Warner decision, the judge said that the parties did not have to disclose their tools. Now, here's the over-designation problem that I really raised for you when we first looked at the Morgan case. Because of the section 13.4 restriction in the protective order attaches only to protected material, its practical weight depends entirely on how much gets designated. And that creates a brand new incentive for parties to over-designate. If designating material controls what tools the other side can run it through, a producing party now has a reason to designate aggressively to keep its data out of opponents' unvetted tools. Now that is a different access from the over-breadth problem in Morgan. There in that case, the breadth was in the definition of the tool, where any modern artificial intelligence platform was broad enough to sweep in Westlaw, relativity, and Microsoft Copilot. Here, the breadth is in the scope of the designation. But it is the same issue, and guardrails are already in the order. Section 5.1 prohibits mass indiscriminate or routine designations and threatens sanctions. And section six gives the other side a challenge procedure. Those guardrails only work if the court enforces them and counsel actually challenges over designation. So designation here, based on the issue that we raised with Morgan, now carries AI usage consequences that it did not carry a few years ago. Two more provisions in this uh protective order show how carefully this was tailored for an AI case. Section 2.19 makes training data attorneys' eyes only. So the data sets at the heart of the merits, books three and the pile, are viewable by opposing counsel and experts under attorney's eyes only designation rather than walled off in the most restrictive tier. And section 2.18 defines source code for this dispute, specifically expressly including, quote, training pipeline code, data ingestion or filtering scripts, tokenization or pre-processing scripts, and model architecture files while

Protective Order DPAs And Tool Security

Kelly Twigger

carving training data out of that definition. The ESI protocol itself says that source code is not covered and will get its own separate protocol, which tells you that's going to be the real technical fight and over exactly how Cerebrus GPT was built. It's still coming and we'll be ready for it. This whole section raises another theme that we regularly discuss here on the case of the week. The level of complexity and thought put into this protocol means that both sides sat down early on and understood what they were going to want for this case. Now they had the open AI case as a guide, right? So they've got multiple cases across the country that have dealt with exactly this issue of using copyrighted materials for the development of an LLM. And so there's there's a there's a playbook, if you will, for them to be able to follow. But the point is they followed it. They they sat down and said, here are all the issues we're going to come across, and let's put them all down here and let's deal with it. And the over-designation is one of the ones that they included. Kudos. Love that. All right. Now there is still a pretty big equity problem sitting underneath all of this. A protocol like this, which um requires disclosures, validation at a 95% confidence level, audit logs, prompt red lines on a three-day clock. That's only achievable while by a well-resourced party with sophisticated vendors. At the other end of the spectrum, the pro se litigants that we saw in Warner and Morgan, we're seeing a wave of them using consumer AI tools to be able to run their own cases. And that is already creating real problems for courts and for opposing counsel that have to sift through AI-generated filings and productions that nobody validated or governed at all. The same technology is producing two opposite problems at once. At the top, sophisticated parties voluntarily building elaborate governance like this protocol, and at the bottom, parties using AI with none. This order is a template for the first group, those sophisticated parties. It does nothing for the second group. And the gap between those sophisticated parties and those pro-se litigants, what we refer to as access to justice, is widening. Now we flagged that gap when we talked about Morgan because Judge Braswell specifically raised it, and it is only getting sharper. Put these decisions, these two orders here on the map that we've been building all year. In Warner, Heppner, and Morgan episodes that we covered here, the AI user was a litigant using a chat bot to think through a case and question whether the prompts were privileged. The question was whether the prompts were privileged. This order is a different region of the map entirely. Here, the AI user is council and their vendors using AI as the engine that culls and produces documents, and the question is governance. Same technology, completely different discovery problem. What is striking about Cerebrus is that the parties did not wait for anyone to rethink the rules. They wrote their own by agreement and the magistrate judge signed off on them. All right, let's talk about our takeaways. Here's what to do with this: start with the thing that reaches every one of your cases and not just this one. Your clients are already using AI, whether their businesses sanction it or not. That means that litigators, you now have an affirmative obligation to understand how AI artifacts and evidence are created and to plan for preserving them, producing them, and asking for them in discovery. This is where key evidence is going to live. And as the open AI cases have already shown us, prompts can be evidence of intent. What a person asked the model and how they asked it can go directly to state of mind. If you are not thinking about AI-generated material as discover as a discoverable source of ESI in every matter, you need to start now. If you are in-house, you need to understand how AI is being used to create information within each of the business units within your company. If you are outside counsel, you need to sit down with your clients now and start understanding that so that you don't have to take two months before after your duty to preserve has already risen in litigation to figure it out, because then you'll have preservation problems. Before you adopt a protocol like this one, decide whether you actually want its obligations. Nothing in rules 26 or 34 requires prompt disclosure, validation, reporting, or illusion testing. This is a stipulation, and stipulations bind you. The detail may buy predictability and fewer fights in this particular case, but you are expanding your own obligations and trading away protections. So make that trade on purpose, not by copying a form. Next, if you are the responding party and you will use AI to review, build your AI review protocol before you deploy the tool, not after. Settle your hosting environment, your thresholds, your validation plan, and your prompt disclosure position in advance because you may be handing all of it to the other side. If you are the requesting party, this order legitimizes real leverage. Demand the AI election, the validation metrics, the illusion testing, and the prompts and ask whether they checked for hallucination or oversummarization. On prompts, decide your position before you agree to anything. They are protectable work product under Warner and Morgan, and here the parties gave that up by stipulation. Now, difference being that in Warner and Morgan, the prompts used were to be able to determine case strategy. They were the lawyers' perceptions. Here, the prompts are being used to determine the set of information and then the subset of information to be produced, to be reviewed and then produced. So there's a difference between the prompts, but typically those that information, how we determine the

Takeaways For Litigators And Teams

Kelly Twigger

set of information to be reviewed, and then how we get to the subset to be produced has always been privileged. That process has been privileged. This is changing that dynamic in this case based on the party's stipulation. On tools, know your data terms. The order verified the DPAs behind these parties' chat GPT and Harvey accounts. Other tools will qualify for to meet the obligations that are set out in this protocol, but you have to review your tool's own DPA and confirm it meets a no training and security requirements. A consumer account will not clear the bar, just like Judge Brasswell said in Morgan. Get your verification into the record if necessary so that it's there. You don't have to prove it to the court in a later hearing. Watch your designations. Because the AI tool restriction attaches only to protected material. Designate with discipline if you are producing, challenge over-designation under section six if you are receiving. And do not overlook the unglamorous detail because it is where cases get fought. The protocol handles short message data from Teams and Slacks in units of no less than a 24-hour period, preserving emojis and threading. It lets a requesting party demand current versions of up to a hundred hyperlinked version documents within 14 days. It requires production of version history from collaboration tools. It sets the privilege log in Excel within 45 days and excludes party to outside council communications after the complaint was filed on October 30th, 2025. That's pretty standard. Sophisticated parties sweat these details for a reason. Don't leave them out of your protocols. There are so many takeaways from just reviewing this one protocol. And we include all of the ESI protocols and decisions in Minerva 26 for exactly this reason to let you see how other parties have handled the scope of drafting a protocol based on the complexity of their case. This case, very highly complex. A lot of information likely going to be dealt with, and they're going to use sophisticated ways to determine the scope of that information and to review it, hence the detailed protocol that we have here. Do you need that for every case? No, you don't. But you need to think about what it is you do need. So learn these things. Make educated decisions. Don't just pull a form off a shelf and decide that one's going to work for your case because it worked for the last case. No one understand your clients' sources of ESI. Understand how they're using AI. Or if they aren't, exclude it. Get in the game with these things. Don't just take what your client is telling you verbatim. Test it. Understand what's out there because you're the one signing the discovery responses. You're the one with the Rule 26G obligations. And AI tools don't change that. All right, that's our case of the week for this week. If you take nothing else, take this away. Generative AI is no longer riding under the tar umbrella. And the parties writing these protocols right now are setting the template that you will be handed next year. But a stipulation is a choice. And before you sign one that looks like this, be sure you want everything in it because nothing in the rules made you agree to it. And everything in it will bind you. That's also why we built Minerva 26, the discovery strategy platform that connects case law rules and real real-world workflows, so teams can turn developments like this into a defensible plan instead of reinventing the protocol in every meet and confer. If it's about the discovery of ESI, it's covered in Minerva 26. If this was helpful, please share it with a colleague who is about to negotiate an ESI protocol in a case where either side might use AI and post it on LinkedIn with your biggest takeaway because the fastest way to level up discovery strategy is to have these conversations in public. And if you haven't already, please subscribe to the Meet and Confer podcast so you don't miss the next episode that changes what reasonable looks like. Thanks for listening. We'll be back next time with another case of the week.