Trade Secret Is Not a Privilege
A complaint has been filed over a decision your model made — a rejection, a denial, a price. The first substantive motion will be about whether the other side gets to look inside it. The answer, in nearly every court, is yes, on terms.
The question is never whether the model is confidential. It is what protective architecture lets it be examined anyway. Defendants who arrive with a two-tier order and a source code protocol drafted shape the outcome. Defendants who arrive asserting that it is proprietary get the order the plaintiff wrote.
The Premise Most Defendants Get Wrong
Trade secret is a basis for protection, not for refusal
The rules contemplate exactly this situation: a party may ask the court to order that a trade secret or other confidential commercial information not be revealed, or be revealed only in a designated way. That is a mechanism for conditioning disclosure, not for withholding it. An objection that says only 'proprietary' is an objection that has not asked the court for anything.
The gate is relevance and proportionality, and an automated screen clears it easily
Discovery reaches non-privileged matter relevant to a claim or defence and proportional to the needs of the case. When the defence is that the decision was made on legitimate criteria and a model produced the criteria, the model is not a side issue. Proportionality arguments about burden land much better than relevance arguments about secrecy.
Refusing tends to cost more than producing
A defendant who declines to explain the system that made the decision is a defendant asking a jury to accept a justification it cannot inspect. Preclusion of the evidence you withheld, adverse inference, or a ruling that the business-necessity defence cannot be supported are all worse outcomes than a well-drafted protective order.
Your vendor's secret is your problem to litigate
The confidentiality belongs to the vendor; the discovery obligation belongs to you. The vendor has no automatic seat at the table, and the deadline runs against the party, not the supplier. If the contract does not give you a right to obtain the material and a cooperation obligation with a named turnaround, you will be negotiating both under a court's calendar.
Six Categories They Will Ask For
They are not equally contestable. Knowing which is which is what turns a discovery fight into a negotiation you can win parts of.
The decision for this person
Inputs received, output produced, model version, the threshold in force, the stage at which they were dropped and every human action afterwards. This is the narrowest and most obviously discoverable item in the case, and it is the one most frequently impossible to reconstruct.
The population
Scores and outcomes for the comparator group — everyone the same rule ran on, in the same period, for the same role or product. The same rule applied to everyone is what makes an automated system a population question rather than an incident.
Model versions and change history
Which version scored the plaintiff, when it was replaced, and what changed. A rescoring on today's model answers a different question than the one asked, and offering it without saying so is how a good-faith production becomes a credibility problem.
Features, weights and thresholds
What the system measured, what it weighted, and who set the cut. The last of those is usually not the vendor's secret at all — the threshold is chosen by the customer, and it is often the single most consequential and least documented decision in the file.
Training and validation data, or a description of it
The most contested category and the one most amenable to compromise. Courts will often take a description, a schema, sampling, or aggregate statistics where the full corpus would be disproportionate or would carry other people's personal information.
The vendor's own testing
Bias audits, validation studies, accuracy testing and internal tickets about them. These are discoverable, they are frequently more useful than the source code, and they are often obtainable under a lighter confidentiality tier than the model itself.
The Protective Order Courts Actually Enter
A two-tier order is the working default
Ordinary 'Confidential' for business material, and an attorneys'-eyes-only tier restricting the most sensitive items to outside counsel and retained experts, with named individuals acknowledging the order in writing. One flat tier either over-protects everything or under-protects the model.
Source code gets its own protocol, borrowed from patent practice
A standalone computer in a secure room, no network, inspection by named experts, logged sessions, limits on printed excerpts and a process for challenging a designation. This machinery is well developed in patent litigation and courts import it readily; proposing it is far more effective than resisting inspection outright.
Expert access is the real negotiation
Expect a fight over which experts may look and under what competitive-activity restrictions, not over whether an expert may look at all. Objections to a specific person, made early and on a stated basis, work. A blanket objection to expert inspection generally does not.
Designations are challengeable and over-designation is punished
Marking the entire production attorneys'-eyes-only invites a motion you will lose and damages your credibility on the designations that mattered. Designate narrowly and be able to justify each category.
Sealing at trial is a separate and harder question
A protective order governs the exchange between parties. Filing under seal engages the public's right of access and requires its own showing, judged document by document. Material that was properly confidential in discovery is not automatically confidential on the docket.
The Control Problem With Your Vendor
Find out whether vendor-held data is within your control
A party must produce responsive material in its possession, custody or control — and a contractual right to obtain documents can put a vendor's records within your control even though they sit on someone else's servers. Read your own agreement for audit and data-access rights before you certify that you do not have the data. Answering that question wrong is a sanctions problem, not a drafting problem.
Expect a subpoena to the vendor either way
Where the material is genuinely outside your control, the plaintiff can subpoena the vendor as a non-party. You will still be involved: the vendor will seek protection, you will want a say in the designations, and the production will describe your configuration to the other side whether you participate or not.
Preserve on both sides of the contract, in writing
Your own hold is the easy half. Send the vendor a written preservation instruction naming the requisition or decision, the date range and the individual, and get an acknowledgement. Routine deletion on a vendor's retention schedule after litigation is reasonably anticipated is the failure mode the electronic-discovery rules were written about.
Know that per-candidate scores often age out first
Vendor retention windows for individual scores are frequently shorter than the period between the decision and the complaint. There is no version of this that improves with time, and the absence sits on the party with the recordkeeping duty rather than on the supplier.
Fix the contract for next time while you remember the pain
The clauses that matter are narrow and specific: a right to obtain per-record inputs and outputs for a legal proceeding, retention that matches your limitation periods, a litigation-cooperation obligation with a named turnaround, and an indemnity that does not evaporate the moment the claim is about your threshold rather than their model.
Questions Defendants Ask
Can we refuse to produce the model because it is a trade secret?
No — trade secret status is a reason to control how material is disclosed, not a reason to withhold it. The civil rules expressly provide for orders requiring that a trade secret or other confidential commercial information not be revealed, or be revealed only in a designated way, which is the court telling you what to ask for. The motions that succeed propose an architecture: a two-tier protective order, an attorneys'-eyes-only designation for the most sensitive items, a source code inspection protocol, named experts who sign on to the order. The motions that fail assert proprietary status and stop. The second kind also tends to invite a worse result than production would have been, because a defendant relying on a justification the other side cannot inspect is inviting preclusion of that justification.
The vendor has the data, not us. Does that end it?
Rarely, and assuming it does is one of the more expensive mistakes available. A party must produce responsive material within its possession, custody or control, and control has been read to include a legal right to obtain documents on demand — which is exactly what an audit clause or a data-access right in your services agreement can create. So the first task is not to answer the interrogatory; it is to read your own contract and find out whether the answer is true. If the material really is outside your control, the plaintiff will subpoena the vendor as a non-party, and you will still be in the middle of it: the vendor will move for protection, your configuration and threshold will be described to the other side, and you will want a voice in the confidentiality designations even though the production is not yours.
Will we have to hand over our training data?
Often not in full, and this is the most negotiable item in the case. Courts routinely accept substitutes where the full corpus would be disproportionate or would sweep in other people's personal information: a description of sources and composition, a schema, a statistically defensible sample, aggregate distributions, or the validation results rather than the underlying records. What usually is produced, because it is narrow and directly probative, is the scoring data for the plaintiff and for the comparator population. Two practical notes. Offering a reasonable alternative early tends to define the compromise; refusing and being ordered later tends to produce a broader order than you would have negotiated. And the vendor's own bias-audit and validation documents are frequently more useful to both sides than the training data, while being far easier to produce.
What if the version that scored the plaintiff no longer exists?
Say so immediately and precisely, and be ready to explain what happened to it. Where electronically stored information that should have been preserved is lost because reasonable steps were not taken and it cannot be restored or replaced, the court has a graduated set of responses, running up to an adverse-inference instruction where it finds a party acted with intent to deprive the other side of the information. The distinguishing facts are usually mundane: when the duty to preserve arose, what instruction went out, and whether it reached the vendor whose retention schedule was doing the deleting. Rescoring the plaintiff on the current model is not a substitute and should never be offered as one without a clear statement that it is a different model — an undisclosed substitution is how a preservation problem becomes a credibility problem.
Who chose the cut score — and why does that question keep coming up?
Because it is usually the most consequential decision in the file and the least documented, and because it is almost never the vendor's trade secret. A vendor supplies a scoring system; a customer decides where to draw the line for a particular role, product or portfolio, and that choice determines who is screened out. In discovery it produces a characteristic sequence: the defendant points at the vendor's validation material, the plaintiff points out that the validation was run at the vendor's thresholds on the vendor's population, and the question of who set this threshold, on what evidence, for this use is left sitting with the defendant. It is worth answering internally before anyone files anything, because if the answer is that nobody recorded it, that is a fact about your governance you would rather find on your own schedule.
The Control Test
Open the services agreement for the system that makes your highest-volume automated decision. Find the clause that lets you obtain per-record inputs and outputs for a legal proceeding, and the one that sets the retention window for individual scores. Give it fifteen minutes.
If both clauses are there, your answer to a possession-custody-or-control question is a reading exercise. If neither is, you have just learned what your next contract renewal is actually about — and renewals are negotiated far better than discovery deadlines are.
Related Reading
- Expert testimony about a model — what happens to the material once an expert has it.
- Litigation holds over AI logs — the preservation duty that arrives before the complaint does.
- Answering a discrimination charge — the administrative stage this often grows out of.
- Vendor contract terms for AI systems — the clauses that make the control question easy.
- Adverse impact and the four-fifths rule — what the population data gets used to compute.