The Next AI Issue in Criminal Cases
A federal court in West Virginia recently issued one of the most interesting AI orders I have seen. It does not deal with fabricated cases, disclosure statements, or whether a lawyer used ChatGPT to draft a brief. Instead, it addresses whether a criminal defense team may use AI to review discovery produced by the government.
Once you see the kinds of materials involved, the reason for the court’s concern becomes clear. The order applies to sensitive materials such as confidential-source information, witness-security information, medical records, details about ongoing investigations, and footage involving minors. These are not ordinary documents, and placing them into an AI system can raise real questions about retention, training, third-party access, and whether the information can ever truly be deleted.
The order applies specifically to the legal defense team. Before defense counsel may place sensitive material into any AI tool, counsel must obtain the government’s written consent, identify the tool, and certify that it will not retain or use the material for training or expose it to unauthorized third parties. Counsel must also certify that reasonable measures have been taken to maintain confidentiality and that the material will be deleted from the tool when the case ends. The order defines AI broadly enough to include generative AI services and AI-assisted software, whether cloud-based or otherwise, and separately bars the defense from using publicly accessible systems that retain submitted data and use it for training.
What makes the order especially interesting is the structure it creates. The government now makes the first call about whether the defense may use a particular AI tool to review sensitive discovery produced by the government. I have not seen this structure in a standing order before.
There are understandable arguments on both sides. The government may have information that explains why particular material requires special protection. It may also have a strong interest in ensuring that sensitive material does not leave a controlled environment. At the same time, the defense may increasingly view AI as a useful way to search large productions, organize communications, identify names, construct timelines, or locate important information buried in thousands of files.
The order brings those interests together through an approval process, but it does not appear to distinguish among different categories of AI tools at the outset. Its definition is broad enough to function as a catch-all. A consumer chatbot, an enterprise platform, an AI-assisted discovery product, and a locally operated system may all fall within it. The differences among those systems would presumably become part of the defense’s request and the government’s evaluation.
Those differences recently surfaced in Morgan v. V2X, Inc., where a federal magistrate judge permitted the parties to use AI with confidential discovery if the provider was contractually prohibited from storing or using the information for training and from disclosing it to third parties except as necessary to provide the service. The provider also had to allow deletion, and the party using the system had to retain documentation of those protections.
The Morgan court also recognized the practical consequence of that approach. The required protections could exclude many low-cost public AI tools, while qualifying commercial products might require an enterprise license that an individual litigant or appointed lawyer could not obtain or afford.
The West Virginia order does something different. Instead of establishing technical conditions that permit use, it requires the defense to describe the proposed AI tool, make the required certifications, and obtain authorization from the government first.
I keep wondering how the decision will work in practice. Some government offices may have ready access to cybersecurity personnel, privacy officers, forensic specialists, and sophisticated technology support. Others may not. A prosecutor may understand exactly why a piece of discovery is sensitive while having much less experience evaluating a vendor’s retention terms, administrative access, security architecture, or deletion controls.
The relevant information may not be easy to find either. Product names alone may reveal very little. The same platform can have different terms and security protections depending on the account, contract, configuration, and manner in which it is deployed. Even a detailed vendor description may leave unanswered whether the actual version proposed by the defense satisfies the certifications required by the order.
The approval structure also leaves a procedural question. The order creates a clear method for challenging whether particular discovery was properly designated as sensitive. The parties must try to resolve the dispute, and either side may file a motion if they cannot. I do not see the same express process for a disagreement over the government’s decision to approve or reject a particular AI tool.
It is too early to know how often defense lawyers will want to use AI on sensitive material, how the government will evaluate those requests, or whether disagreements will arise. What is clear is that the question has changed.
For the last several years, most court orders involving AI have focused on the finished product. Did the lawyer verify the cases? Did AI help prepare the filing? Did the document contain fabricated authority? This order reaches an earlier stage of the case. It governs whether and how one side may use AI to understand the evidence in the first place.
This is a new development. It puts security, technical competence, affordability, adversarial process, and judicial review into the same conversation. I will be watching this one closely.

