Courts were right to act when lawyers began filing fabricated cases, false quotations, and unverified AI output. But the governing principle was never complicated: if a lawyer signs a filing, the lawyer owns it. In the leading sanctions decision, the court emphasized that there is “nothing inherently improper” about using a reliable AI tool; existing rules already make lawyers the gatekeepers for accuracy. Mata v. Avianca, Inc., 678 F. Supp. 3d 443, 448 (S.D.N.Y. 2023).
The Northern District of West Virginia has now gone somewhere different. Its June 16, 2026 standing order does not merely require lawyers to verify filed work. It reaches inside the criminal-defense team’s discovery process and requires government consent before the defense may use broadly defined AI tools to review designated sensitive material.
The danger behind the order is real. No competent lawyer should upload confidential-source information, witness-security material, medical records, private communications, or footage involving minors into a public chatbot that may train on, retain, or expose the data. But a sound premise does not make every remedy sound. Existing professional-conduct rules already require technological competence, confidentiality, vendor diligence, and supervision. Federal Rule of Criminal Procedure 16(d)(1) already permits tailored protective orders when sensitive discovery creates a specific risk.
The new order does not fill a regulatory gap. It adds a prosecutor-controlled permission layer.
TL;DR
- ●The order correctly identifies serious risks in placing sensitive criminal discovery into consumer or data-retentive AI systems.
- ●The district's own local rules already bind counsel to the West Virginia Rules of Professional Conduct and the ABA Model Rules. Those rules — and ABA Formal Opinion 512 — already require lawyers to understand their technology, protect representation-related information, evaluate outside vendors, and supervise AI use.
- ●Using the right tool is part of that duty. Suitability turns on the specific product tier, contract, configuration, connector, permissions, data path, and workflow — not the vendor's name or an “enterprise” label.
- ●Rule 16(d)(1) already lets courts impose case-specific discovery protections for good cause, including measures designed to protect witnesses and confidential sources.
- ●The order nevertheless requires the defense to obtain the government's written consent before using any broadly defined AI tool, including enterprise and locally hosted systems that may satisfy the order's stated safeguards.
- ●It does not state when the required certifications entitle counsel to consent, set a response deadline, or provide an express tool-denial review procedure, and it imposes no parallel requirement on the prosecution.
- ●The better answer is a vendor-neutral security standard, reciprocal protection, lawyer accountability, and prompt judicial review — not an adversary's permission slip.
What the Standing Order Actually Requires
The order applies to all criminal actions filed in the Northern District of West Virginia. It designates eleven categories of “Sensitive Materials,” including personal identifiers, confidential-source information, undercover-agent identities, witness-security information, unrelated private communications, medical and mental-health records, investigative methods, information about ongoing or future investigations, tax information, and footage or identifying information involving minors.
Several limitations are sensible. Public materials, information obtained outside discovery, and materials pertaining solely and directly to the defendant are excluded. The order also creates a process for challenging whether particular material was properly designated sensitive, and material ceases to be sensitive when redaction resolves the basis for its designation.
But the operative restriction is exceptionally broad. No member of the legal defense team may input, transmit, upload, process, generate output from, or otherwise expose sensitive discovery to any AI tool without the government’s prior written consent. “AI tool” includes any automated system using statistical modeling, machine learning, or similar techniques — large language models, generative-AI services, and AI-assisted software, “whether cloud-based or otherwise.”
To obtain consent, defense counsel must identify and describe the tool, certify that it will not retain or use the materials for model training, certify that unauthorized third parties will not receive access, attest to reasonable confidentiality safeguards, and promise deletion at the end of the case. Publicly accessible systems that retain submitted data for model training are categorically forbidden.
The order specifies what counsel must certify, but it does not state when satisfaction of those requirements entitles counsel to consent, what additional grounds may justify denial, or whether a denial must be explained. Nor does it set a response deadline. Its express motion procedure addresses whether material qualifies as sensitive; it does not provide a comparable process for a dispute over a proposed tool. Counsel could presumably seek relief through ordinary motion practice, but the order does not say how a judge should decide that dispute.
And the restrictions run one way. The order regulates the defense team. It does not impose comparable tool identification, certification, or consent requirements on the prosecution.
In re Use of Artificial Intelligence Tools to Review Criminal Discovery, Misc. No. 1:26-MC-38, ECF No. 1, at 1–6 (N.D.W. Va. June 16, 2026).
The Court Is Right About the Risk
“No training” does not mean “no retention.” Retention does not necessarily mean human access. Encryption does not answer who holds the keys. A deletion promise may not reach backups, security logs, or subprocessors. And a familiar product name says little by itself: consumer, business, enterprise, API, and locally hosted versions of a product may operate under materially different contracts and controls.
Commercial and consumer offerings may operate under materially different retention, training, access, and contractual terms. Those terms must be evaluated at the product, plan, and configuration level. The legally relevant unit is therefore not the logo on the screen. It is the specific plan, configuration, contract, retention schedule, access model, and workflow.
That is exactly why lawyers must understand the tool before using it. It is not, however, a reason to treat every system using machine learning as if it were a public training-enabled chatbot.
Using the Right Tool Is Part of the Ethical Duty
The LegalTek Trust Mark™ offers a useful governance model because it asks the question the standing order should ask: not merely “Is this AI?” but “Is this particular system appropriate for this particular data and workflow?” As the Trust Mark explains, “A legal AI system is only as safe as the products, connectors, permissions, terms, data pathways, and human-review gates around it.”
Properly understood, the Trust Mark is a date-stamped due-diligence framework — not a legal safe harbor or a guarantee of confidentiality, privilege, or ethical compliance. It organizes evidence about the controls in place when the review occurs. The final suitability decision remains matter-specific, and responsibility remains with counsel.
That means tool selection cannot stop with a vendor name or a feature list. The Trust Mark separates three review layers because a product may satisfy one and fail another:
| Review layer | Governing question | What counsel must examine |
|---|---|---|
| Standalone product | Can the firm use this product for this category of legal data? | Product terms, privacy commitments, training boundaries, retention and deletion, subprocessors, security, and contractual protections. |
| Connector or AI platform | Can an AI platform access the product for the intended legal workflow? | Platform terms, permissions, access scopes, administrator controls, data movement, audit logs, and action authority. |
| Actual workflow | Can this use operate within the lawyer's duties? | Matter and user scoping, memory, read-versus-write authority, human approval, source verification, incident response, rollback, and re-review after material changes. |
Availability is not approval. “Enterprise” is not a synonym for safe. A locally hosted tool is not necessarily well governed. And software designed for lawyers can still have unacceptable terms, permissions, or retention practices. The right tool is the one whose actual deployment fits the task, the sensitivity of the information, and the safeguards counsel can verify.
Context matters. A tool may be appropriate for summarizing public statutes but inappropriate for unredacted witness-security material. A consumer version may be wrong for a task even though a separately contracted commercial deployment could meet the required controls. Sometimes the right tool is a read-only system. Sometimes it is a tightly scoped local or enterprise environment. And sometimes the right answer is no AI use until the material is redacted or adequate protections are documented.
Least authority by default
Start with read-only access where possible; disable sending, filing, deleting, paying, publishing, or other external actions unless specifically reviewed; and require a real human approval gate before client-facing, court-facing, financial, or system-changing action. That is what responsible legal AI governance looks like. It regulates the data path and the power granted to the system — not the marketing label attached to it.
There Is No Ethics Gap to Fill
The district’s own rules already establish the governing standard. Local Rule of General Procedure 84.01 requires lawyers practicing in the Northern District of West Virginia to comply with both the professional-conduct rules adopted by the Supreme Court of Appeals of West Virginia and the ABA Model Rules of Professional Conduct. N.D.W. Va. LR Gen P 84.01.
Those rules are technology-neutral by design.
Rule 1.1 and Comment 8 require counsel to understand the benefits and risks of relevant technology. Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of, or access to, information relating to a representation. That protection is broad: it is not limited to facts supplied by the client. Comments 3 and 18 direct counsel to consider the scope of representation-related information, its sensitivity, the likelihood of disclosure, the cost and difficulty of safeguards, and whether those safeguards would impair the lawyer’s ability to represent the client. Rules 5.1 and 5.3 require policies, training, and supervision when lawyers, staff, and outside service providers assist with the work. W. Va. R. Pro. Conduct 1.1 cmt. 8; 1.6(c) & cmts. 3, 18; 5.1; 5.3.
ABA Formal Opinion 512 applies those familiar duties directly to generative AI. Before placing representation-related information into a tool, lawyers must evaluate the risk of access or disclosure inside and outside the firm. They should read and understand the provider’s terms of use, privacy policy, and related contracts — or consult someone qualified to do so. The opinion explains that counsel must make reasonable efforts to evaluate outside providers and identifies security practices, confidentiality commitments, reliability, retention, contractual protections, and breach procedures as relevant diligence considerations. Law-firm managers must establish AI policies and train lawyers and nonlawyers in secure data handling. Formal Opinion 512 is advisory guidance rather than binding law, but it explains how the binding rules apply to this technology. ABA Comm. on Ethics & Pro. Resp., Formal Op. 512, at 2–11 (2024).
West Virginia had already reached the same conclusion before this standing order. Its Lawyer Disciplinary Board explained that existing rules are adaptable to AI, that lawyers must understand the technology well enough to comply with their duties, and that counsel using generative AI must protect confidentiality, supervise the work, and understand provider safeguards. W. Va. Lawyer Disciplinary Bd., Legal Ethics Op. 24-01, Artificial Intelligence, at 3–8 (June 14, 2024). The opinion is advisory, but its reasoning is directly on point.
This framework is not lax. A lawyer who places protected discovery into an unvetted consumer system may face professional discipline or malpractice exposure and, when a court order or contract applies, sanctions or contractual consequences. A disclosure can cause damage that no later remedy can fully repair. That reality justifies preventive protection and aggressive enforcement. It does not establish that the prosecutor should decide which compliant tools the defense may use.
Criminal Discovery Law Already Supplies Preventive Protection
Ethics rules protect the client and govern counsel’s conduct. They are not the only safeguard. Rule 16(d)(1) separately authorizes a federal court, for good cause, to restrict discovery or grant other appropriate relief. That authority is preventive: a judge need not wait for a breach.
The federal criminal-justice system already has a technology-specific model for applying that authority. Joint guidance from the Department of Justice and the Administrative Office of the U.S. Courts recognized that large productions would increasingly require software-assisted review and that no single approach fits every case. It made security a responsibility of all parties. When the parties cannot agree on appropriate protection, it recommends that the producing party seek a court order governing the particular ESI at issue and raise the issue anew for later productions. That is materially different from a districtwide rule that gives the prosecution advance approval authority over every defense AI tool. Dep’t of Just. & Admin. Off. of the U.S. Cts. Joint Working Grp. on Elec. Tech. in the Crim. Just. Sys., Recommendations for Electronically Stored Information (ESI) Discovery Production in Federal Criminal Cases 1–5 (Feb. 2012).
Rule 16.1 follows the same allocation: counsel confer about discovery procedures, and either party may ask the court to determine or modify the time, place, manner, or other aspects of disclosure. The district’s local rules are more protective still. Local Criminal Rule 16.09 permits the court to restrict discovery after a sufficient showing, allows an ex parte submission, and provides for an evidentiary hearing. Local Criminal Rule 16.02 supplies a revealing contrast: when the government declines requested disclosure, it must identify the withheld categories, give specific written reasons, and immediately notify the magistrate judge so a hearing can be expedited. The AI order gives no comparable decisional rules to govern refusal of a proposed defense tool. Fed. R. Crim. P. 16.1(a)–(b); N.D.W. Va. LR Cr P 16.02, 16.09.
In an unpublished plain-error decision arising from the same district, the Fourth Circuit rejected a challenge to orders requiring certain discovery to remain in counsel’s custody after the government identified risks to confidential informants and cooperating witnesses. United States v. Navarro, 770 F. App’x 64, 65 (4th Cir. 2019) (per curiam). That illustrates an appropriate use of Rule 16: a concrete risk, identified materials, and a tailored restriction.
Courts also recognize the other side of the balance. Good cause requires a specific, serious injury; broad and unsupported allegations do not suffice. United States v. Wecht, 484 F.3d 194, 211 (3d Cir. 2007). A federal court within the Fourth Circuit applied that principle to narrow an overbroad blanket criminal-discovery order and required the government to identify the materials needing protection. United States v. Brittingham, No. 6:21-cr-00014, 2022 WL 3006849, at *1–2 (W.D. Va. July 28, 2022).
The existing structure therefore already does both jobs. Professional rules govern counsel’s technology and vendors. Rule 16(d)(1) permits additional, case-specific protection for witness safety, privacy, or investigative interests. A districtwide prosecutorial veto over every broadly defined AI tool is not necessary to accomplish either purpose.
Where the New Order Goes Too Far
It regulates a label instead of the risk
The order’s findings focus on public, consumer, and data-retentive AI. Its operative language reaches much further. Technology-assisted review, automated classification, translation, transcription, redaction, forensic analytics, image analysis, and locally hosted document tools may all use statistical modeling or machine learning. Such tools can include systems that do not transmit data outside the defense environment or that operate under enforceable terms prohibiting training and restricting access.
A rule aimed at unsafe data practices should define unsafe data practices. “AI” is too broad a proxy.
It makes the opposing party the initial decision-maker
The government has a legitimate interest in protecting witnesses, sources, minors, and ongoing investigations. But in an adversarial criminal case, the prosecution should not be the defense team’s default technology regulator.
The work-product doctrine reflects the need for counsel to prepare a case with a meaningful degree of privacy and extends to materials prepared with the help of investigators and other agents. United States v. Nobles, 422 U.S. 225, 238–39 (1975). That does not automatically make every software selection privileged. It does underscore the structural concern: defense preparation should not be exposed to unnecessary control by the opposing party. Objective standards should govern in the first instance, with a neutral judge resolving genuine disputes.
It leaves the approval decision undefined
What must the government evaluate? A vendor’s public policy? The defense contract? System architecture? Subprocessor list? Security audit? Data-flow diagram? Backup schedule? Can consent be withheld because an assistant U.S. attorney lacks sufficient technical information? Must the government explain a denial? How quickly must it decide when trial deadlines are running?
The order answers none of those questions. It specifies counsel’s certifications, but without criteria governing the consent decision, it invites inconsistent results and delay.
It creates a foreseeable access problem
Institutional offices may have security teams, procurement staff, enterprise contracts, and approved platforms. Individual appointed lawyers and small defense firms may not. Requiring a technical submission and adversary approval for tools that could make voluminous evidence review affordable may burden the lawyers who need those tools most.
That consequence is not inevitable, and the order may be administered reasonably. But the structure creates the risk. In criminal litigation, where the government often begins with greater investigative and technological resources, a defense-only barrier deserves especially careful justification.
A Narrower Rule Would Protect the Same Interests
The court could preserve every legitimate security objective without making the prosecutor the defense team’s AI gatekeeper.
- 1Prohibit dangerous data practices. Sensitive discovery should never enter a system that uses protected inputs for model training, permits unauthorized human review, lacks adequate access controls, or cannot meet defined retention and deletion requirements.
- 2Create a vendor-neutral safe harbor. Compliance should turn on objective safeguards: encryption, access restriction, enforceable no-training terms, disclosed subprocessors, defined retention, breach notice, auditability, and a reliable deletion or return process.
- 3Require lawyer accountability — not adversary permission. Counsel can certify compliance to the court and maintain the supporting vendor assessment. A false certification would carry real consequences.
- 4Apply equivalent standards to both sides. Sensitive discovery does not become less sensitive when the government processes it.
- 5Use Rule 16(d)(1) when a case needs more. The government may seek additional restrictions by showing good cause tied to identified material and a specific risk.
- 6Give disputes to a neutral judge. The process should include a response deadline, written criteria, and prompt judicial review. Sealed or ex parte submissions should be available when revealing a defense workflow could expose protected strategy.
- 7Fund compliance. If the required safeguards demand technology beyond the reach of appointed counsel, CJA funding or a court-provided secure platform should be available without forcing disclosure of defense strategy to the prosecution.
That approach regulates what matters: data handling, access, retention, accountability, and harm.
The Better Rule: Govern the Risk, Not the Defense
The Northern District of West Virginia deserves credit for taking sensitive discovery seriously. The categorical prohibition on public systems that retain and train on protected data is easy to defend. No lawyer should need a special order to know that conduct is unacceptable — but a bright line can still educate and deter.
The broader consent regime is different. It does not close an ethical loophole. It subjects defense counsel’s professional judgment to prosecutorial approval, reaches tools that may not present the danger described in the order, and does not state when the required certifications entitle counsel to consent.
Legal AI needs governance. It needs confidentiality, oversight, understanding, scrutiny, and accountability — the core principles already reflected in ABA Formal Opinion 512, the LegalTek COUNSEL Framework, and the LegalTek Trust Mark™. What it does not need is an opponent-issued permission slip.
Protect the discovery. Enforce the duties. Let a neutral court decide real disputes. But the prosecutor should not be the defense team’s AI gatekeeper.
Authorities and Source Notes
- In re Use of Artificial Intelligence Tools to Review Criminal Discovery, Misc. No. 1:26-MC-38, ECF No. 1, at 1–6 (N.D.W. Va. June 16, 2026).
- Fed. R. Crim. P. 16(d)(1), 16.1(a)–(b); N.D.W. Va. LR Gen P 84.01; N.D.W. Va. LR Cr P 16.02, 16.09; W. Va. R. Pro. Conduct 1.1 cmt. 8; 1.6(c) & cmts. 3, 18; 5.1; 5.3.
- ABA Comm. on Ethics & Pro. Resp., Formal Op. 512, Generative Artificial Intelligence Tools 2–11 (July 29, 2024).
- W. Va. Lawyer Disciplinary Bd., Legal Ethics Op. 24-01, Artificial Intelligence 3–8 (June 14, 2024) (listed by the Office of Lawyer Disciplinary Counsel as L.E.O. 2024-01).
- U.S. Dep't of Just. & Admin. Off. of the U.S. Cts., Joint Working Grp. on Elec. Tech. in the Crim. Just. Sys., Recommendations for Electronically Stored Information (ESI) Discovery Production in Federal Criminal Cases, Introduction 1–2, Recommendations 1–2, 5, Strategies 5, 10–11 (Feb. 2012).
- Mata v. Avianca, Inc., 678 F. Supp. 3d 443, 448 (S.D.N.Y. 2023); United States v. Navarro, 770 F. App'x 64, 65 (4th Cir. 2019) (per curiam); United States v. Wecht, 484 F.3d 194, 211 (3d Cir. 2007); United States v. Brittingham, No. 6:21-cr-00014, 2022 WL 3006849, at *1–2 (W.D. Va. July 28, 2022); United States v. Nobles, 422 U.S. 225, 238–39 (1975).
- Technical terms were checked against current commercial-data guidance published by OpenAI, Anthropic, Microsoft, and Google as of August 6, 2026. Provider terms differ by product, plan, configuration, and contract and may change.
- LegalTek.ai, The LegalTek Trust Mark™: Connector Readiness — The Next Layer of AI Trust (last reviewed July 9, 2026).
Editorial Transparency
AI tools assisted with source retrieval, comparison, citation checking, and drafting. The standing order, docket, cited ethics authorities, rules, cases, current provider policies, and LegalTek Trust Mark materials were checked against primary or official sources in preparing this draft. Final editorial review remains the author’s responsibility.
Matthew A. Mishak, Esq. is the Managing Attorney of Mishak Law LLC and the Founder and CEO of LegalTek.ai (SilverTung), an AI powered legal practice management and governance platform. He brings twenty years of Ohio legal practice across domestic relations, criminal defense, and municipal law, and is the architect of the COUNSEL framework operationalizing ABA Formal Opinion 512.
Disclaimer: This article is for general informational purposes only and is not legal advice. It is based solely on public court filings, published authorities, and official public materials and does not reflect non-public information. Reading it does not create an attorney–client relationship. LegalTek.ai is a technology company, not a law firm. This may constitute attorney advertising.
Related reading: LegalTek.ai Blog









