Massachusetts’ Pending AI Bill Would Reach Certain AI Systems Used in Decisions Concerning Legal Services
H.97 remains in House Ways and Means, with no new official action since December 2025. If enacted, the proposal would impose risk-management, disclosure, and anti-discrimination duties on certain developers and deployers of high-risk AI systems.
Massachusetts lawmakers are still considering a broad proposal to regulate certain high-risk artificial intelligence systems, including systems used in legal services. But the measure—H.97, House Docket 4053—is not law, and its last recorded legislative action came nearly nine months ago.
The bill was filed on January 17, 2025, and referred to the Joint Committee on Advanced Information Technology, the Internet and Cybersecurity on February 27, 2025. The committee held a public hearing that included H.97 on September 11, 2025, according to the Legislature’s hearing record and archived webcast.
On December 24, 2025, the Legislature recorded H.97 as “Accompanied by H94,” reported it favorably from committee, and referred it to House Ways and Means. As of September 20, 2026, the bill remains pending there, with no later official action listed in its legislative history.
What H.97 would cover
The proposal would regulate “high-risk” AI systems that make, or are a substantial factor in making, consequential decisions. A consequential decision under the bill may concern education enrollment or an education opportunity, employment or an employment opportunity, a financial or lending service, an essential government service, health-care services, housing, insurance, or a legal service.
That scope matters because the bill is not confined to consumer-facing chatbots or generative-AI tools. It is aimed at systems that can materially affect a person’s access to services, opportunities, or benefits in consequential settings.
The bill’s text would place obligations on both developers and deployers of covered systems. Among other provisions, it would require:
developer documentation about a system’s intended use, known limitations, and risk-management practices;
deployer risk-management programs and recurring impact assessments;
measures intended to prevent unlawful discrimination;
notices to consumers before a high-risk AI system makes, or is a substantial factor in making, a consequential decision concerning them;
explanations for certain adverse decisions;
correction and appeal opportunities in specified circumstances;
public disclosures concerning covered systems; and
general disclosure when consumers interact with an AI system, unless it would be obvious to a reasonable person that the person is interacting with an AI system.
The bill expressly includes a “legal service” among the areas in which a consequential decision may occur. That does not mean every AI tool used by a law firm or other legal-services organization would be covered. Coverage would turn on the bill’s definitions, exclusions, and exemptions—including whether the system makes, or is a substantial factor in making, a decision that has a material legal or similarly significant effect on the provision or denial of, or cost or terms for, a legal service to a Massachusetts resident.
Enforcement would rest with the Attorney General
H.97 would assign enforcement exclusively to the Massachusetts Attorney General. A violation would constitute an unfair trade practice under Chapter 93A, the state’s consumer-protection law.
The proposal expressly states that it would not create a private right of action. If enacted, deployers would have to notify Massachusetts-resident consumers before a covered consequential decision and, following an adverse decision, give them opportunities to correct incorrect personal data and appeal. Human review on appeal would be required only if technically feasible, and the appeal opportunity itself would be subject to the bill’s best-interest and life-or-safety exception. H.97 would not authorize a private action under the proposed chapter.
No current compliance deadline
Because H.97 has not passed, it imposes no current legal duties and has no operative compliance date.
As drafted, the bill says it would take effect no later than six months after passage, and many substantive obligations would have to be satisfied no later than six months after the law’s effective date. Those timelines are contingent on enactment and should not be treated as active deadlines.
The H.94 reference does not establish a merger
The December 2025 history entry linking H.97 to H.94 is worth reading carefully. The Legislature’s records show that H.97 was “Accompanied by H94,” then received a favorable committee report and a referral to House Ways and Means.
That sequence reasonably indicates that H.97 was the measure that procedurally advanced at that point. It does not, however, establish that H.94 was merged into H.97, incorporated into it, or rewritten as part of it. A stronger conclusion would require an official committee report, executive-session record, poll documentation, or comparable legislative material explaining the relationship between the two bills.
For now, H.97 is best understood as a pending Massachusetts AI-governance proposal—one with potentially significant reach, including into legal services, but without present legal effect.
Oklahoma Judge's Reported ChatGPT Citation Failure Puts AI Verification On The Bench
The next AI-citation case is not about a lawyer filing a brief with fake authority.
It is about a judge's order.
In Stephens County, Oklahoma, Associate District Judge Lawrence M. Wheeler denied a mother's motion for a psychological evaluation in a paternity and custody case. The order cited two Oklahoma Court of Civil Appeals decisions that the challenger later told the Oklahoma Supreme Court did not exist. News reports, citing an August letter from Stephens County District Attorney Jason Hicks to the Oklahoma Attorney General, say Wheeler later told an Oklahoma State Bureau of Investigation investigator that he used ChatGPT for research and that at least two case citations generated by ChatGPT and included in the order did not exist.
That makes the episode different from the familiar lawyer-sanctions pattern. The basic verification duty is the same: a legal authority must exist, and it must support the proposition for which it is used. But when the false authority appears in a judicial order, the harm profile changes. The order itself becomes the source of legal pressure. It can impose fees, reprimand counsel, change the trajectory of a family-law case, and force the affected party to seek emergency appellate relief before the error is corrected.
The record also shows the case did not end with a headline. The challenged order was vacated. The public reprimand was purged. Related attorney-fee and penalty issues were stayed or reversed for evidentiary hearings. The Oklahoma Supreme Court original proceeding was dismissed after those corrective orders. Wheeler later recused from the underlying case.
That is the full story: a custody fight, an AI-tainted order, a writ petition, a corrective retreat, a dismissal, a recusal, and a later public investigation report that did not become a criminal prosecution.
The Case
The underlying case is Adriane E. Capers v. Marvin A. Jones, No. FP-2022-16, in Stephens County District Court. The Stephens County docket shows the paternity action was filed in September 2022.
By 2025, the docket reflected continuing custody, visitation, attorney-fee, and motion practice. On September 29, 2025, Capers filed a motion requesting a psychological evaluation and mental-health testing and assessment of Jones. The motion invoked Oklahoma's mental-examination procedure, and the later Supreme Court filing says it also cited Oklahoma's family-law mental-examination statute.
On November 17, 2025, the Stephens County court filed a "Notice of Decision & Order" denying the motion. The order itself was signed November 19.
The order said the paternity action had been pending for more than three years under a temporary order. It said Jones had temporary sole custody under a prior order, while Capers had no visitation. It also said Capers had offered no specific facts, medical evidence, or other support showing that Jones's mental condition was in controversy or that a mental examination was necessary.
The order could have stopped with that case-specific analysis. It did not.
After quoting the U.S. Supreme Court's Schlagenhauf v. Holder standard for mental examinations, the order stated that the Oklahoma Court of Civil Appeals had "explicitly adopted" Schlagenhauf for Oklahoma section 3235 examinations in Cummings v. Cimarron Elevator Co., 1998 OK CIV APP 44, 958 P.2d 594. It also cited Hawkins v. Linhart, 2009 OK CIV APP 106, 234 P.3d 240, for the proposition that section 3235 is not self-executing and requires an "in controversy" and "good cause" showing.
Those citations became the problem.
The Fake Cases Were Not A Footnote
The fake cases mattered because the order used them as part of the legal analysis supporting denial of the examination motion.
The order also went further. It found Capers's motion "frivolous in nature" and intended to harass Jones. It awarded Jones "whatever attorneys fees and costs he incurred" because of the motion, added those amounts to a prior fee award, publicly reprimanded Capers's counsel for "stooping to such frivolous trial tactics," and warned that future filings of similar character could face sanctions under 12 O.S. section 2011.
Capers then went to the Oklahoma Supreme Court.
On February 19, 2026, she filed an application to assume original jurisdiction and a petition for writ of prohibition in Capers v. Wheeler, No. PR-123810. The proceeding named Wheeler, not Jones, as respondent and arose from Stephens County case FP-2022-16.
The brief in support did the citation work the trial-court order had not done. It said the order's citation "1998 OK CIV APP 44" actually yields Robbins v. Robbins, a custody-jurisdiction/ex parte-communication case that does not address section 3235 or Schlagenhauf. It said "958 P.2d 594" points instead to Harpole v. State, an Idaho case, not an Oklahoma Court of Civil Appeals decision adopting Schlagenhauf. It said "2009 OK CIV APP 106" yields Bunch v. Terpenning, a Consumer Credit Code case, and "234 P.3d 240" points to a Washington case, not the claimed Oklahoma authority.
The brief's conclusion was cautious but clear: Cummings v. Cimarron Elevator Co. and Hawkins v. Linhart "appear to be non-existent."
That careful wording is important. The court filing did not need to prove a grand theory of AI. It showed that the authorities named in the trial-court order did not match the reporter citations or Oklahoma appellate numbers the order gave them. For a litigant facing fees, sanctions warnings, and a public reprimand of counsel, that was enough to make the order unstable.
The Corrective Orders
The first correction came quickly.
On February 26, 2026, the Stephens County court entered an agreed order. It vacated the November order denying the psychological-evaluation motion, set the motion for an evidentiary hearing, and purged the public reprimand. It also stayed the October 14 attorney-fee decision and daily $50 penalty, and it set related fee issues for reconsideration at an evidentiary hearing.
The next day, the court entered an amended agreed order. The amendment made the cleanup more explicit. It vacated the finding that the psychological-evaluation motion was frivolous and vacated the $50 daily penalty.
On March 3, Capers moved to dismiss the Supreme Court proceeding. The motion said Wheeler had entered orders vacating the previous decisions complained of and had taken corrective action. It argued the case could be voluntarily dismissed or treated as moot because effective relief was no longer needed.
The Oklahoma Supreme Court granted the dismissal that same day and struck the scheduled referee hearing.
That procedural sequence matters. The Supreme Court did not issue a merits opinion deciding whether Wheeler used AI or whether the nonexistent cases independently required relief. The challenge was dismissed after the trial court corrected the orders. The public record therefore supports a narrower, more precise conclusion: the order with the nonexistent citations was challenged, the challenged provisions were vacated or corrected, and the appellate original proceeding ended because the corrective action removed the need for emergency relief.
The Recusal
The docket did not end there.
On April 20, 2026, Wheeler entered an order of disqualification. The order said that, after further consideration of the facts and circumstances involved in the litigation, the court recused itself and asked for another judge to be assigned. On April 27, the Stephens County docket recorded an assignment order.
That means the case moved to another judge after the fake-citation episode. It does not, by itself, tell us the full reason for the recusal. But in context, it is part of the case's procedural afterlife: the same judge whose order cited the two nonexistent cases vacated the order, corrected related sanctions and fee issues, and then stepped away from the case.
The Investigation Reporting
The AI part became public months later.
NewsOn6 reported that Stephens County District Attorney Jason Hicks sent an August 17, 2026 letter to Oklahoma Attorney General Gentner Drummond asking that Hicks's office be disqualified from any potential prosecution because Wheeler regularly presided over cases involving the office. According to that report, Hicks wrote that allegations referred by the Oklahoma Council on Judicial Complaints included claims that Wheeler used ChatGPT to produce a court order; Hicks also wrote that Wheeler acknowledged using case citations generated by ChatGPT and that at least two citations in the order did not exist.
KFOR/Yahoo and NewsNation reported the same core point, and Reason's Volokh Conspiracy quoted Reuters as reporting the same attribution to the August 17 letter: Wheeler allegedly told an OSBI investigator he used ChatGPT for research, wrote the order himself, and included two nonexistent citations generated by ChatGPT. NewsOn6 also reported that Hicks's letter referenced separate allegations, including an allegation that Wheeler offered to amend the order in exchange for dismissal of a writ seeking Oklahoma Supreme Court relief, and allegations involving jury deliberations.
Those are investigative allegations and reported statements from a letter. They should not be overstated. The Oklahoma Attorney General's office told NewsOn6 that its Criminal Justice Division reviewed the OSBI investigation and determined that the evidence did not support a criminal prosecution. The same statement said the Oklahoma Supreme Court and the Court on the Judiciary have ultimate jurisdiction over judicial discipline for inappropriate judicial behavior, regardless of whether conduct violates a criminal statute.
That distinction is critical. No criminal prosecution is not the same thing as "nothing happened." It means the attorney general did not see a criminal case. The judicial-discipline question belongs somewhere else.
Why This Is Different From Lawyer Hallucination Cases
Most AI citation failures reach public view because a lawyer filed a bad brief. Courts then respond with sanctions, fee awards, bar referrals, brief-striking orders, or warnings.
This case inverts that pattern.
Here, the trial-court order itself included the false authorities. The litigant then had to challenge the order by writ. That is a different institutional risk because judges do not merely advocate. They decide.
When a lawyer's AI-generated citation fails, the court can reject it. When a judge's AI-generated citation fails, the order may already have shifted leverage, imposed costs, changed hearing posture, criticized counsel, or forced appellate intervention before the defect is corrected.
That does not mean judges can never use AI. Courts are already experimenting with AI for administration, drafting support, translation, transcript workflows, research, and self-help tools. The lesson is narrower and more serious: if AI enters the path toward an order, the judge or chambers must verify the legal source before it becomes judicial authority.
The verification standard cannot be lower on the bench than it is for lawyers.
What Court Systems Should Learn
The practical fix is not mysterious.
First, chambers should separate drafting assistance from authority verification. A tool can help organize issues or locate possible sources, but no cited case should enter an order until a human verifies that the case exists, that the citation matches, and that the case supports the proposition used.
Second, court systems should treat citation checking as part of order quality control. That is especially important for orders imposing fees, sanctions, contempt exposure, professional criticism, or custody-related consequences.
Third, judges and staff need disclosure and escalation rules. If an order is later found to contain AI-generated false authority, the correction process should be prompt, transparent, and docketed. Vacatur and amended orders can fix the litigation problem, but the system also needs a way to document how the failure happened and how recurrence will be prevented.
Fourth, AI policies for courts should cover judicial work, not only lawyer filings. Many court AI rules focus on lawyers, parties, and self-represented litigants. This episode shows why internal judicial workflows need the same discipline.
Fifth, courts should preserve the difference between technological assistance and judicial responsibility. The order is the court's act. A model cannot bear responsibility for a citation that becomes part of a judicial ruling. The human legal institution owns that step.
Bottom Line
The Stephens County episode is a warning from the other side of the bench.
In Capers v. Jones, a trial-court order denying a psychological-evaluation motion cited two Oklahoma appellate cases that the later Supreme Court filing showed did not match real Oklahoma authority. The order imposed consequences beyond denial of the motion. The affected party sought extraordinary relief. The challenged order and related sanctions issues were vacated or corrected. The Supreme Court proceeding was dismissed after that correction. The judge later recused. News reports, citing the district attorney's letter, say the judge acknowledged to investigators that the nonexistent citations came from ChatGPT research.
The legal system already knows what to say to lawyers: verify before filing.
This case adds the judicial version: verify before ruling.
China's Top Court Turns AI Disputes Into Litigation Rules
China's Supreme People's Court has moved AI governance from policy abstraction into courtroom administration.
On September 7, 2026, the court released Opinions on lawfully hearing AI-related dispute cases. The court described the document as the first AI-related judicial adjudication-rule document issued by a national highest court. It has five parts and 24 articles, and it directs Chinese courts on how to approach AI disputes under existing law.
That distinction matters. The Opinions are not a standalone national AI statute. They do not create a single licensing regime for AI systems, and the court's own materials say China has not yet enacted a specialized AI law. Instead, the Opinions use existing legal frameworks, including civil, cybersecurity, data security, copyright, anti-unfair-competition, consumer-protection, personal-information, and civil-procedure laws, to give courts a working map for AI litigation.
For companies, that may be more important than it sounds. A statute tells the market what the legislature has commanded. A top-court adjudication document tells litigants how disputes are likely to be framed when something goes wrong.
The practical message is direct: companies operating AI systems in or connected to China should expect judges to ask who controlled the system, what risks were foreseeable, what safeguards were used, what evidence can be produced, and whether AI-assisted filings or outputs were verified before they reached a court, consumer, user, or counterparty.
What The Opinions Cover
The Opinions are broad. They do not focus only on one fashionable AI problem, such as hallucinated legal citations or deepfakes. They organize AI disputes across several recurring litigation categories.
First, they address tort liability for AI-related harm. The court says liability should be assessed under existing laws, and that fault should generally be the baseline where no statute imposes strict liability or presumed fault. In judging fault, courts are told to consider the AI application's context, degree of autonomy, transparency of technology and information, risk level, risk-reduction measures, and the user's ability to foresee and control the harmful conduct.
That is an important governance signal. The inquiry is not just "did the model cause harm?" It is also whether the developer, provider, user, seller, or other actor had a practical ability to understand and reduce the risk.
Second, the Opinions cover personality rights and privacy. They address AI face-swapping, voice cloning, digital resurrection of deceased people, doxxing, human search, and AI-enabled invasions of privacy. The court's Q&A emphasizes that the document is meant to protect name, likeness, reputation, privacy, voice, and related personality interests while still allowing lawful innovation.
Third, the Opinions address generative-AI service-provider responsibility. The court's materials describe a notice-and-action structure for some AI-generated personality-rights harms: if generative AI automatically creates content that infringes reputation or privacy interests, and the rightsholder gives a proper notice, the service provider may face liability if it does not take necessary measures in time. The court also addresses users who intentionally induce infringing AI outputs through prompts.
This is not a simple "platforms always liable" rule. It is closer to a governance question about knowledge, notice, control, and response. The Q&A explains that generative-AI providers may have a basis to rely on a notice-removal style approach because they cannot predict every user prompt or generated output in advance, but that protection is not a license to ignore obvious or notified harms.
Fourth, the Opinions address consumer and product disputes. They include algorithmic price discrimination, fake celebrity endorsements, AI product liability, autonomous-driving and driver-assistance accidents, and the evidentiary role of vehicle or system data. For physical AI products, courts are told to look at defects, use scenarios, warnings, system limitations, updates, user control, and applicable standards. For automated or assisted driving accidents, courts may require manufacturers, sellers, operators, or data controllers to provide truthful and complete event records where needed to determine the facts.
Fifth, the Opinions address AI intellectual property disputes. They discuss AI-generated content, open-source software, patent eligibility and inventorship, technology contracts, data sets, trade secrets, unfair competition, and attacks on AI operational security through techniques such as malicious labeling or adversarial examples.
Finally, they address procedure. Courts are directed to improve fact-finding and evidence review in AI-related cases, use technical expertise where needed, and sanction AI-assisted misconduct in litigation. The Opinions specifically state that litigation participants who use AI to generate pleadings, case-search reports, or other submitted materials should verify their truth and accuracy before submission, disclose AI assistance to the court, and bear responsibility for the content.
That last piece should sound familiar to lawyers outside China. It is the same institutional anxiety appearing in U.S. courts, where AI tools have created fake-citation problems, judicial-process questions, and new pressure to document human review. Clearon recently covered a U.S. appellate example involving judicial AI use and reassignment questions. The China Opinions show that the courtroom-governance problem is not local.
The IP Piece Is Carefully Limited
The most commercially important part may be the IP section, but the court is careful about what it does and does not decide.
The Opinions say that when AI-generated content allegedly infringes copyright, courts should consider the type of AI service, industry characteristics, training-data sources, each party's participation, necessary measures taken, and profit. The Q&A adds that a party should not escape responsibility merely because the challenged content was generated by AI. Responsibility should be tied to control, duty of care, role in the generation process, training data, preventive measures, and economic benefit.
The Opinions also address evidence. A claimant alleging that an AI developer or provider infringed copyright must make a preliminary showing that the challenged content was AI-generated and substantially similar to the claimant's work. But if the developer raises a non-infringement defense, courts may require evidence about training-data sources, training process records, model operating modes, and scientific or theoretical bases where necessary.
That is a serious litigation-design issue for AI companies. It means that documentation around training data, model operation, filtering, and deployment cannot be treated only as internal engineering history. It may become litigation evidence.
At the same time, the court leaves two contested issues unresolved. The Q&A says the Opinions do not decide copyrightability of AI-generated content or the legal characterization of using others' works to train large models, because views remain divided and further experience is needed.
That restraint is important. It means companies should not read the Opinions as a final answer to every China AI copyright question. The better reading is that the court is building a litigation framework first: responsibility, evidence, duties, and dispute handling, with some harder substantive questions reserved for later cases or rules.
Technology Is Not An Exemption Card
One of the court's strongest themes is that AI technology does not erase responsibility.
The Supreme People's Court's accompanying analysis says technology is not an "exemption card." That framing is not a statutory test, but it captures the practical posture of the Opinions. Courts are being told to look past generic statements that AI is autonomous, unpredictable, or technically complex, and instead ask what the relevant actor could know, prevent, verify, explain, or control.
That matters across the whole document.
For generative-AI providers, the question becomes whether the provider had notice of infringing content and whether it took necessary measures. The accompanying analysis also discusses the red-flag principle under existing Civil Code rules, while acknowledging that the Opinions do not create a standalone red-flag provision. For users, the question becomes whether the user intentionally induced harmful output or knew of a prior work and used AI to generate substantially similar content without a valid defense. For product sellers and manufacturers, the question becomes whether warnings, usage limits, system data, and foreseeable risks were handled accurately. For litigants and lawyers, the question becomes whether AI-generated submissions were verified and disclosed.
This is the governance lesson: in AI disputes, courts may not be satisfied with broad product descriptions. They may want records.
Companies should be ready to explain how the system was designed, what warnings were given, what safeguards were available, how outputs were monitored, what contractual limits applied, what logs exist, how user reports and notices were handled, and who made escalation decisions.
The Courtroom-Use Rule Is A Compliance Signal
The litigation-materials rule is one of the clearest parts of the Opinions.
The court says litigation participants who submit pleadings, case-search reports, or other materials generated with AI should carefully verify the truth and accuracy of relevant laws, judicial interpretations, cases, and other content before submitting them. They should also explain the AI assistance to the court and bear responsibility for authenticity and accuracy.
That is not just a courtroom etiquette point. It is a compliance signal for law firms, in-house litigation teams, expert witnesses, and vendors that sell legal AI tools.
A legal AI workflow that cannot show who checked the output, what source was reviewed, and what changed before filing is going to be weak under this kind of rule. The same problem appears in U.S. practice: courts are not usually interested in whether a lawyer used a fashionable tool. They are interested in whether the lawyer verified what was filed.
For companies, this means AI use policies should distinguish between ordinary drafting assistance and materials that become evidence, legal argument, expert work, regulatory submissions, customer notices, or public commitments. The higher the consequence, the stronger the source-control and human-review record should be.
What Companies Should Do Now
The Opinions are formally about Chinese courts, but they are useful beyond China because they show how judges may organize AI disputes.
First, map AI risk by dispute category, not only by product category. A single AI system can produce privacy claims, consumer claims, IP claims, product-liability questions, contract disputes, evidence issues, and unfair-competition allegations. Legal teams should know which parts of the product create which litigation records.
Second, preserve system and data documentation that may become evidence. Training-data provenance, model-operation records, filtering decisions, prompt logs, output histories, user notices, complaint records, takedown steps, and human-review records can all become important. The point is not to hoard data without limits. It is to align retention, privacy, and litigation-readiness before a dispute starts.
Third, update notice-and-response workflows for AI-generated harms. If a user reports an AI-generated impersonation, voice clone, defamatory output, privacy invasion, or infringing generation, the company should have a defensible triage path. That path should record what notice was received, whether it was complete, what content or prompt was involved, what measure was taken, and when.
Fourth, review AI product warnings and marketing. The Opinions tie responsibility to use scenarios, system limitations, foreseeable risks, and whether users were accurately informed. Overstating autonomy, reliability, or safety can create downstream litigation risk.
Fifth, separate AI-assisted legal work from ordinary productivity use. Litigation materials, case-search reports, evidence summaries, and expert materials need verification and disclosure controls. A legal department can allow AI assistance and still require source validation before anything is submitted.
Finally, avoid treating unresolved questions as settled. The court deliberately left AI-generated-content copyrightability and training-data legality open. That leaves room for future cases, regulations, or guidance. Companies should keep legal positions flexible and source-bound rather than building policies around overconfident predictions.
The Takeaway
China's Supreme People's Court has not solved every AI law question. It has done something more operational: it has told courts how to begin hearing AI disputes.
The Opinions organize AI litigation around responsibility, control, evidence, verification, notice, product warnings, data use, IP documentation, and courtroom integrity. That is the practical center of AI governance. The hard questions are not limited to whether an AI system is powerful. They include who controlled it, who benefited from it, who could foresee harm, who received notice, what records exist, and whether humans verified the legally consequential output.
For companies, the lesson is not to treat China as a silo. The themes in the Opinions match broader global pressure: courts and regulators increasingly expect AI governance to be explainable in records, workflows, controls, and human accountability.
The companies best positioned for this environment will not be the ones with the longest AI policy. They will be the ones that can prove, in a dispute, how their systems were governed before the dispute arrived.
Federal Cyber Agencies Turn AI Model Distillation Into a Governance Issue
AI model distillation is no longer only a research method, a competition issue, or a private terms-of-service dispute between model providers and would-be imitators.
CISA Cybersecurity Advisory AA26-251A, issued by NSA, CISA, and FBI, pushes the issue into cybersecurity and national-security governance. The advisory says China-based AI companies are conducting systematic extraction of proprietary functionalities and capabilities from U.S. AI companies' models through industrial-scale knowledge distillation campaigns. It also recommends account-level detection, targeted response changes, and cross-organization intelligence sharing.
That does not make the advisory a new binding AI regulation. It is guidance and threat reporting, not a statute, rule, court judgment, or adjudicated finding. But it may still shape the expected control environment.
The practical legal point is direct: if federal cyber agencies now describe malicious industrial-scale distillation as a coordinated threat to U.S. AI companies, then access governance, subscription controls, API contracts, evidence preservation, and incident response belong in legal and compliance review too.
What The Advisory Says
The advisory distinguishes legitimate distillation from the activity it is warning about.
Knowledge distillation can be a lawful and useful AI-development technique. It can be used to transfer capabilities from a larger model to a smaller one, improve efficiency, support research, or build products within authorized boundaries. The agencies' concern is different: "aggressive, malicious, and targeted" industrial-scale distillation activity that extracts restricted proprietary functionality and capabilities from U.S. frontier AI models.
According to the advisory, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, likely with Chinese government awareness, extracted billions of tokens across millions of exchanges or requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. The advisory says these campaigns were not incidental experimentation but a systematic strategy to shorten development timelines and reduce the financial cost of building frontier models.
Those are agency assertions, not adjudicated findings. Companies assessing the allegations should keep that distinction clear in public statements, customer notices, contract disputes, and enforcement positions.
The described access routes are also important. The agencies say requests were routed through native APIs, remote cloud providers, third-party aggregators, and gray-market API proxies referred to as "transfer stations." The advisory also describes bulk procurement of premium subscriptions shared across teams of developers.
The tactics identified by the agencies include chain-of-thought reasoning extraction, automated failover between pathways during blocking attempts, and quality evaluation frameworks designed to detect defensive countermeasures. Those details matter because they move the issue away from ordinary high-volume usage and toward an adversarial pattern: distributed access, evasion of traceability, and adaptation when a provider tries to block activity.
The advisory then recommends three immediate actions: comprehensive detection and mitigation, targeted response changes, and cross-organization intelligence sharing. Those recommendations are operational, but the compliance implications are broader.
Why It Matters Legally
The advisory turns model distillation into a governance question because the alleged behavior sits across several legal and operational domains at once.
First, there is the contractual layer. If a model provider's terms restrict scraping, automated extraction, reverse engineering, model training, resale, account sharing, or access from restricted regions, then suspicious distillation activity will often become a terms-of-use enforcement matter. That requires a record of what terms applied, what product path was used, what logs support the violation, and what response the company took.
Second, there is the account-governance layer. The advisory's indicators include subscription-to-usage ratios, immediate maximum usage from new accounts, enterprise-scale throughput patterns, shared accounts from multiple IP addresses or user agents, 24/7 sustained usage without human variation, anomalous subscription-to-API usage ratios, coordinated pathway switching, and metadata sanitization. Those are not only security signals. They are governance signals about identity, authorization, and permitted use.
Third, there is the intermediary layer. The advisory identifies native APIs, cloud providers, third-party aggregators, and proxy networks. Model companies will need to ask whether aggregator agreements, cloud marketplace terms, resale limits, logging rights, audit rights, abuse reporting, geographic controls, and termination provisions support the response federal agencies are now recommending.
Fourth, there is the incident-response layer. Industrial-scale distillation may not look like a classic breach involving stolen credentials or exfiltrated customer databases. It may look like permitted interfaces being used at impermissible scale for an impermissible purpose. A high-confidence distillation campaign may require legal hold decisions, evidence preservation, customer-impact analysis, law-enforcement referral evaluation, and executive reporting even if no system vulnerability was exploited.
Finally, there is the communications layer. A provider that detects suspected distillation has to decide what to tell users, customers, aggregators, peer companies, the government, and possibly the public. Overstating attribution can create legal and commercial problems. Saying too little can undercut enforcement and ecosystem defense.
Subscription And API Abuse Are Now Governance Signals
One of the advisory's most important points is that subscription abuse and API abuse belong in the same picture.
Many AI companies have treated consumer subscriptions, enterprise subscriptions, developer APIs, cloud channels, and aggregator access as different product surfaces with different controls. The advisory describes adversaries moving across those surfaces, including bulk premium-subscription procurement, shared accounts, remote cloud providers, third-party aggregators, and gray-market proxies.
That creates a compliance design problem. If the abuse team sees suspicious subscription behavior but API security sees only permitted traffic, the company may miss the combined pattern. If an aggregator has logs the model provider cannot access, the provider may not be able to prove coordinated pathway switching. If identity verification is strong in enterprise contracts but weak in premium individual subscriptions, a determined actor may arbitrage the gap.
The legal team should not try to run the detection program. But it should help define what records the program needs to preserve: account creation metadata, relevant terms, plan type, payment and subscription history, source IP and user-agent patterns, API-key identifiers and associated audit records, rate-limit history, model-selection history, aggregator identifiers, abuse tickets, warnings, suspensions, and internal escalation decisions. Retention must still respect privacy commitments, data-processing agreements, and legal limits.
Contracts should also catch up. Provider terms should address account sharing, automated extraction, use of outputs to train competing models, resale or brokering of access, circumvention of regional or product restrictions, metadata obfuscation, and high-volume coordinated use. Aggregator and cloud arrangements should specify abuse-monitoring responsibilities, required logs, response timelines, data-sharing rights, and termination mechanics.
Procurement teams should read the advisory from the other side as well. Enterprises buying frontier-model access through intermediaries should understand whether those intermediaries can meet abuse-detection, logging, and investigation obligations.
Response Controls Raise Their Own Legal Questions
The advisory recommends targeted response changes for high-confidence malicious distillation attempts. It specifically discusses approaches such as differential privacy or downgraded responses for suspected malicious distillation activity, and it recommends varying response changes across requests to reduce the payoff of extraction efforts.
Those recommendations are significant, but they need governance.
From a security perspective, the logic is understandable. If a provider can identify a malicious extraction campaign with high confidence, it may want to reduce the training value of its outputs. The advisory also points providers toward MITRE ATLAS and NIST's adversarial machine learning guidance, which provide structured language for attacks, mitigations, and lifecycle controls.
From a legal and product perspective, response alteration raises hard questions. When is confidence high enough? Who approves the control? Could it affect innocent users caught in the same pathway? How will the provider document why it used a downgraded response, differential privacy technique, or other output modification?
The answer should not be to avoid defensive controls. It should be to govern them.
Companies should define decision thresholds, approval roles, rollback procedures, customer-impact review, and records for response changes. They should also decide in advance how they will handle researchers, auditors, red teams, and authorized evaluators, because those groups may generate patterns that resemble adversarial testing but are governed by permission. The advisory specifically recommends informing AI safety researchers and third-party evaluators of model changes while continuing to apply strong distillation mitigations.
The advisory's recommendation to vary response changes across requests also requires care. Publicly restating the advisory's recommendation is one thing. Building internal playbooks that disclose exactly how to detect or defeat those controls is another. Legal and security teams should keep sensitive operational details limited to need-to-know channels and avoid turning public communications into a roadmap for evasion.
What AI Companies Should Do Next
AI companies do not need to treat the advisory as a statute. They should treat it as a clear statement of federal cyber-agency expectations.
Start with classification. Define when suspected model distillation becomes a security incident, a trust-and-safety enforcement matter, a legal escalation, or all three. The trigger should account for volume, coordination, account-sharing indicators, circumvention signals, aggregator involvement, and attempts to bypass blocking.
Then review the account-control stack. Subscription plans, enterprise workspaces, API organizations, developer accounts, payment patterns, reseller channels, and aggregator traffic should be correlated where policy and law permit. The advisory's indicators are useful because they are mostly behavioral rather than content-dependent: immediate maximum use, enterprise-scale throughput, 24/7 patterns, anomalous subscription-to-API ratios, shared accounts, coordinated pathway switching, and metadata sanitization.
Next, update contracts and enforcement records. Terms should be clear enough to support enforcement against unauthorized model training, resale, account sharing, circumvention, and automated extraction. API and aggregator contracts should support investigation, logging, abuse response, and suspension or termination when needed.
Build an information-sharing design before a major event. The advisory calls for cross-organization intelligence sharing across providers, clouds, and API aggregators. That sharing should have rules: what indicators can be shared, whether personal data is involved, how confidentiality is handled, how attribution is caveated, whether antitrust counsel should review competitor coordination, and when government reporting is appropriate.
Finally, map the program to recognized security frameworks. The advisory points to MITRE ATLAS and NIST AI 100-2 E2025. That does not make either source binding law. But using a shared taxonomy can help legal, security, engineering, and procurement teams speak the same language when documenting attack patterns, mitigations, and control maturity.
The Takeaway
CISA AA26-251A is a cyber advisory, not a new AI statute. It does not create a licensing regime, impose direct regulatory penalties, or adjudicate the conduct it describes.
But it still changes the governance conversation.
The federal government is now framing industrial-scale malicious distillation as a coordinated threat involving account abuse, API access, aggregator pathways, proxy markets, adaptive evasion, and proprietary model capability extraction. That framing will likely influence customer expectations, contract negotiations, audit questions, incident-response planning, and enforcement posture.
For AI companies, the practical lesson is not to declare all distillation suspect. Legitimate distillation remains part of AI development. The problem is unauthorized, targeted, industrial-scale extraction through pathways that evade the provider's rules and controls.
That means the response has to be both technical and legal. Detection without enforceable terms is weak. Terms without logs are hard to act on. Response controls without governance create risk. Information sharing without rules can create confidentiality, privacy, attribution, and competition-law problems.
The advisory's deeper message is that frontier-model access is now part of cybersecurity governance. The companies that operate those models will need to prove not only that they can build capable systems, but that they can govern access, detect abuse, preserve evidence, approve responses, and share what the ecosystem needs to know without overclaiming what the evidence shows.
The FRONTIER Act Narrows the Federal AI Preemption Fight
The Great American AI Act draft was a warning shot.
The FRONTIER Act is the narrower bill.
On July 23, 2026, Representative Jay Obernolte introduced H.R. 9925, the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, or FRONTIER Act, with Representative Lori Trahan and other bipartisan cosponsors. GovInfo lists the bill as introduced in the House and referred to the House Committee on Energy and Commerce and the House Committee on Science, Space, and Technology.
That matters because the earlier Great American AI Act materials were still a discussion draft. Clearon's earlier coverage treated them that way. H.R. 9925 is different: it is introduced bill text, though still only a pending bill, and it shows where the sponsors moved after the first round of criticism.
The short version is this: the bill still tries to create a federal rulebook for frontier AI risk. But the state-law preemption clause is more targeted than the broad discussion-draft fight suggested.
What The Bill Would Cover
The FRONTIER Act is not a general AI law for every company using automated tools.
It is aimed at frontier models and frontier developers. The bill defines a frontier model as a foundation model trained using more than 10^26 integer or floating-point operations, including the original training run and later fine-tuning, reinforcement learning, or other substantial modification.
It then builds tiered duties around developers that meet revenue and AI-development-spending thresholds. Some duties apply to frontier developers generally, while the public-framework, audit, registration, and independent-verification layers turn on the larger statutory tiers.
A "large frontier developer" would have to have gross revenues in excess of $50 million and incur at least $1 billion in AI-related development expenditures, measured together with affiliates during the preceding 36-month period and determined as of the first day of each calendar month. A "very large frontier developer" would have to have gross revenues in excess of $5 billion and incur at least $10 billion in AI-related development expenditures under the same affiliate-inclusive, monthly measurement structure.
Those thresholds are doing important work. The bill is not trying to regulate ordinary business AI deployments, routine SaaS use, or most smaller model builders in the same way. It is aimed at the companies training and operating the most capable frontier systems.
The Public Framework Requirement
For large frontier developers, the main operational duty starts with a public frontier AI framework.
By the later of one year after enactment or 90 days after first qualifying as a large frontier developer, the developer would have to write, implement, comply with, and clearly publish a frontier AI framework on a public website.
That framework would have to address how the developer identifies catastrophic-risk thresholds, assesses whether a model could cross those thresholds, reviews the results of risk assessment and mitigation before deployment or internal use, uses third parties to assess risk, updates the framework, secures nonpublic model weights, responds to critical safety incidents, and implements internal governance.
This is more concrete than a voluntary responsible-AI pledge. It would turn frontier risk governance into a public compliance artifact.
That does not mean every detail becomes public. The bill allows redactions to protect trade secrets, risk-prevention mechanisms, cybersecurity, public safety, national security, or compliance with federal or state law. But the structure still points toward a world where the largest developers need a publishable governance file, not just internal assurances.
Audits, Reports, And Incident Duties
By the later of one year after enactment or 90 days after first qualifying as a large frontier developer, and annually thereafter, the bill would require a large frontier developer to retain a third party to audit compliance with the developer's own frontier AI framework.
The audit structure matters because it would not merely ask whether the developer has a framework. It would ask whether the developer is following it. The auditor would need demonstrated competence, including access to technical expertise in frontier-model safety, and the bill bars either side from holding a financial interest in the other.
H.R. 9925 also would require model-level transparency reports before or concurrent with deployment of a new frontier model or a substantial modification. Those reports would include release date, supported languages, output modalities, intended uses, restrictions or conditions, catastrophic-risk assessments, assessment results, third-party involvement, and other steps taken under the framework. The summaries would have to be provided in machine-readable format to facilitate verification of model claims.
Critical safety incidents get a separate clock. The bill would require the Under Secretary of Commerce for AI Security to create a confidential reporting mechanism within 180 days after enactment. A frontier developer would have to report a critical safety incident within 72 hours after learning facts sufficient to establish a reasonable belief that one occurred. If the incident poses an imminent risk of death or serious physical injury, the developer would have to report to law enforcement within 24 hours.
For compliance teams, those deadlines are the practical signal. If the bill moves, frontier developers would need escalation criteria and evidence records before an incident happens.
The Independent Verification Layer
The heaviest obligations fall on very large frontier developers.
By the later of one year after the Under Secretary first licenses an independent verification organization with capacity to accept an engagement or 90 days after a developer first qualifies as very large, the developer would have to retain a licensed IVO to perform ongoing assessments.
Those assessments would cover the adequacy of the developer's frontier AI framework, governance practices, risk monitoring, and mitigation of detected risks. They would apply not only to released models, but also to catastrophic risks from internal use of frontier models.
The IVO would need access to unredacted materials, records, personnel, systems, and other information reasonably necessary for the assessment. The developer could impose reasonable security and confidentiality protocols, but material limits on access would have to be described in the assessment report.
The IVO report would have to address scope, limitations, the adequacy of the developer's framework and governance, identified failures or weaknesses, recommended corrective actions, and certifications about accuracy, qualifications, conflicts of interest, and compliance with regulations.
That is a significant compliance design. It would create a regulated market for AI verification organizations and make the independence of that market a policy issue in its own right. The bill recognizes that by requiring annual Government Accountability Office reports on the IVO market, including barriers to entry and threats to independence from the AI industry.
The Preemption Clause Is Narrower, But Still Important
The earlier discussion draft drew attention because it tried to divide federal and state authority over AI. H.R. 9925 keeps that fight, but narrows the covered field.
Section 9 preempts state and local laws that impose new substantive obligations on artificial intelligence developers with respect to a defined "Covered Subject Area." For this section, the bill uses a broader definition of "artificial intelligence developer": an entity that builds, designs, codes, produces, trains, or owns an AI model for internal or third-party use, excluding entities that are solely deployers.
That means Section 9 is not limited to the bill's narrower "frontier developer" definition, even though the covered subject areas are tied to frontier AI risk transparency, frontier AI third-party auditing and independent verification, and frontier AI incident reporting.
That is not the same as preempting all state AI law.
The bill expressly preserves generally applicable laws that do not target AI developers. It also preserves state authority to regulate the use or deployment of AI systems by deployers or users, including through consumer protection, civil-rights, contract, criminal, or privacy laws, so long as those laws do not impose substantive obligations on developers with respect to model development, training, evaluation, or release.
It also preserves state laws specifically relating to protection of minors from harms arising from AI systems, including sexually explicit content, self-harm content, exploitation, age verification, parental controls, and similar matters. And it preserves state procurement and use rules for state governments.
That narrowing is the legal story. The sponsors appear to be moving from a broader preemption fight toward a more focused claim: if Congress creates a federal catastrophic-risk transparency, audit, verification, and incident-reporting regime for frontier developers, states should not create parallel developer-side obligations in the same lane.
States would still have room to regulate many downstream AI uses. The hardest disputes would sit at the boundary. A state rule framed as product transparency, child safety, consumer protection, or procurement may be preserved. A rule that reaches developer-side frontier risk testing, reporting, audits, certifications, or release conditions may be challenged as preempted.
Emergency Orders Are The Enforcement Backstop
H.R. 9925 also gives the Secretary of Commerce emergency-order authority.
The Secretary could suspend or restrict a frontier developer's development, deployment, or internal use of a frontier model upon finding that the activity presents an imminent catastrophic risk. The bill sets procedures for written findings, technical assessments where methods have been published, consultation with the Under Secretary, provisional and final orders, judicial review, and penalties.
Violating an emergency order could trigger civil penalties of up to $10 million per violation. Willful violations could carry criminal penalties of up to $1 million per violation, imprisonment for up to 10 years, or both.
Those provisions are narrow, but they show the bill is not only a reporting proposal. It would give the federal government a direct intervention tool for imminent catastrophic risk.
What Companies Should Watch
Most companies would not become frontier developers under H.R. 9925. But the bill still matters outside the frontier lab because it sketches the federal-state boundary Congress may try to draw.
Frontier developers should watch the thresholds, the definition of catastrophic risk, the content of the public framework, the 72-hour and 24-hour incident clocks, the registration/disclosure duty, and the IVO assessment process.
Companies that deploy third-party AI systems should watch a different issue: what the bill leaves to states. H.R. 9925 preserves state regulation of deployers and users, including consumer protection, civil rights, privacy, contract, criminal law, child safety, procurement, and state-government use. That means a federal frontier bill would not erase downstream state compliance work.
Audit and assurance providers should watch the IVO licensing rules. The bill would require independence, conflict-of-interest controls, technical competence, access to developer records and systems, and signed certifications. That is closer to regulated assurance than ordinary consulting.
State-policy teams should watch the boundary language. The next fight will not be "federal law or state law." It will be whether a particular state rule targets developer-side frontier risk governance or downstream use.
Bottom Line
The FRONTIER Act is the introduced-bill version of a narrower federal AI bargain.
It would place public frameworks, third-party audits, incident reporting, independent verification, registration, and emergency-order authority around the largest frontier developers. In return, it would limit state and local developer-side obligations in the covered catastrophic-risk transparency, audit, verification, and incident-reporting lanes.
That is why H.R. 9925 is worth tracking even if it is far from enactment. It is one of the clearest current attempts to answer the question that keeps coming back in U.S. AI law: which layer belongs to Washington, and which layer remains with the states?
When AI Errors Come From the Court, Not the Lawyer
Most legal AI sanctions stories start with a lawyer filing a defective brief.
This one starts with the court.
In Jackson Federation of Teachers v. Fitch, the Fifth Circuit is considering Mississippi's appeal from a preliminary injunction in a challenge to HB 1193, a state law addressing diversity, equity, and inclusion programs and practices in public K-12 and postsecondary education. The appeal challenges that injunction. Separately, before oral argument, the panel asked the parties to address whether, "especially in light of the use of AI by the district court," the matter should be assigned sua sponte to a different district judge.
That makes the case different from familiar matters involving errors in lawyers' AI-assisted filings. The question is no longer just what courts should do with defective AI-assisted advocacy. It is what an appellate court should do when a court order prepared with AI assistance is docketed with errors.
The Fifth Circuit has not ruled. But the record already makes the case useful for judges, court administrators, and litigators because it turns AI governance inward.
What Happened
The district case began as a First Amendment challenge to Mississippi HB 1193. Plaintiffs including educators, advocacy groups, and students sought temporary and preliminary relief against enforcement of parts of the law.
On July 20, 2025, U.S. District Judge Henry T. Wingate entered a temporary restraining order. The public district docket states that the court granted the plaintiffs' motion for a temporary restraining order only, and that the main document was later replaced on July 23.
Mississippi officials then filed an unopposed motion to clarify and correct the docket, which the court granted by text order on July 23. They later filed a separate motion directed to preserving the record, with attachments including the original TRO, July 23 emails, amended TRO orders, the July 23 text order, and a second amended TRO order.
The case then moved beyond the TRO stage. On August 18, 2025, Judge Wingate entered a preliminary injunction and disposed of several pending motions. Mississippi officials appealed, and the Fifth Circuit docketed the appeal as No. 25-60496.
The AI issue resurfaced in the appellate court. The district docket records an August 24, 2026, Fifth Circuit letter addressing whether, in light of the district court's AI use, the matter should be assigned sua sponte to a different district judge.
That is the article-worthy development. The appellate court is not merely reacting to a bad lawyer filing. It is asking whether a court's own AI-related drafting failure bears on the administration of the case going forward.
Wingate's Own Explanation
Judge Wingate later addressed the episode in an October 21, 2025 letter responding to questions transmitted after Senate Judiciary Committee Chairman Chuck Grassley wrote about the matter.
The letter says a law clerk used Perplexity, a generative AI tool, "strictly as a foundational drafting assistant" to synthesize publicly available information on the docket for the July 20 TRO. It also says the law clerk did not input sealed, privileged, confidential, or otherwise nonpublic case information.
The problem, according to the letter, was human review. Judge Wingate wrote that his chambers' standard practice is for draft opinions to go through several levels of review, including cite checking, before docketing. But the July 20 order was an early draft that had not gone through that standard process. He called docketing it a mistake and said the root cause was "a lapse in human oversight," specifically posting a draft opinion instead of a final one and failing to put the draft through final review.
That distinction matters.
The court's explanation does not present AI as the decision-maker. It presents AI as part of a drafting workflow that failed because a draft skipped the human controls that were supposed to stand between internal work product and a public judicial order.
Judge Wingate also wrote that the flawed order was removed from public view because he did not want parties, including pro se litigants, to believe the draft order should be cited in future cases. He said the clerk's office would retain the errant order under record-retention requirements and noted that it had been attached as an exhibit to a motion.
For future controls, the letter says chambers implemented a mandatory independent review by a second law clerk before draft opinions, orders, and memorandum decisions are submitted to him, and that cited cases are printed from Westlaw and attached to a final draft.
The Appellate Problem
The hard issue for the Fifth Circuit is not simply whether the initial TRO had mistakes.
It is whether the later preliminary injunction can be separated from the earlier AI-assisted drafting failure, and whether reassignment is needed to protect the administration or appearance of justice.
Public reporting describes the August 31 argument as focused on that point. The ABA Journal, relying on Law.com reporting, says Judge Jerry Smith questioned why an erroneous citation still appeared in the amended order and asked whether that was a serious matter. Law Commentary reports that Judge Kurt Engelhardt pressed how the appellate court could be confident inaccurate material had not affected the district judge's analysis.
Those are reported argument exchanges, not a merits ruling. The Fifth Circuit may affirm, reverse, remand, reassign, or avoid some of the AI process questions depending on how it resolves the appeal. But the court's own pre-argument letter makes clear that reassignment was on the panel's agenda because of the district court's AI use.
That is enough to make the episode important even before a decision.
Why This Is Different From Lawyer Hallucination Cases
The usual AI-citation case turns on lawyer duties: competence, candor, supervision, and the signature on a filing. Courts ask who checked the authorities and how counsel responded when defects were found.
Judicial AI use raises a parallel but distinct governance problem.
Judges and chambers staff do not file advocacy documents. They issue orders that bind parties, guide lower proceedings, and may be cited by future litigants. A hallucinated citation in a brief can mislead the court. A hallucinated fact, party, record reference, or legal statement in an order can become the court's own statement unless caught before docketing.
That difference changes the control environment.
For lawyers, the key governance questions are who drafted, who signed, who verified, and who corrected. For courts, the questions become:
What AI tools may chambers staff use for research, synthesis, or drafting?
What information may be entered into those tools?
What review steps must happen before an order leaves chambers?
Who verifies names, parties, declarations, citations, record references, and statutory quotations?
What happens when an erroneous order has already appeared on the public docket?
How does the court preserve a transparent record while preventing parties from relying on a flawed draft?
Those are not abstract questions anymore. Jackson Federation of Teachers puts them inside a live appellate reassignment dispute.
The Record Problem Matters
One reason this episode is uncomfortable is that judicial correction is different from ordinary document revision.
Drafts often change inside chambers. That is normal. But once an order appears on the docket, later replacement raises record and reliance questions. Judge Wingate's letter says he thought leaving a flawed order on the public record would be confusing because it was not a final opinion and contained errors. It also says a copy remains retained and that the errant order appears as an exhibit to a motion.
That may be a practical answer. It may or may not satisfy every concern about docket transparency. The Fifth Circuit has not yet said.
For legal teams, the useful point is narrower: when AI-assisted judicial work product reaches the docket by mistake, the correction path itself becomes part of the dispute. The merits question and the process question can become hard to separate.
What Courts Should Take From This
The most realistic lesson is not that courts can never use AI-assisted tools.
It is that court use requires controls that account for the institutional role of judicial orders.
At minimum, chambers policies should distinguish between:
AI-assisted public-source synthesis;
citation checking;
legal research;
drafting;
summarizing party submissions;
handling sealed or confidential materials; and
final review before docketing.
The controls should also define which tasks are categorically off limits, which tools are approved, what data can be entered, and which human review steps are mandatory. A policy that says "use responsibly" is too vague for an order-writing workflow.
The most important control may be mundane: no AI-assisted draft should be docketed until a human reviewer verifies the parties, procedural posture, cited authority, record references, quotations, statutory language, and relief ordered. If the order relies on a source, someone must confirm the source exists and says what the order says it says.
That is not anti-technology. It is court administration.
What Litigators Should Watch
For litigators, the case creates several practical watch points.
First, if an order appears to contain AI-shaped errors, preserve the record carefully. Mississippi's motion practice around the TRO created a record that later became part of the appellate reassignment discussion.
Second, distinguish correction from cure. A replacement order may fix visible errors, but the appellate question may become whether earlier errors affected later reasoning or the appearance of fair process.
Third, avoid overclaiming. A drafting-process failure is not the same thing as proof that AI decided the case. Judge Wingate's letter says the July 20 order was an early draft and that the failure was human oversight. The appellate court still has to decide what legal consequence, if any, follows from that.
Fourth, watch the remedy. Reassignment would not be judicial discipline and would not decide the underlying constitutional challenge. It would change who handles further district court proceedings.
Bottom Line
The Fifth Circuit's pending reassignment question shows the next stage of legal AI risk.
Courts have spent the last few years telling lawyers that AI does not excuse false filings. Now an appellate panel is asking what happens when AI-related errors appear in a court's own work.
The answer should not be panic or denial. It should be governed use, transparent correction, and enough human review that a draft assisted by AI cannot become a public judicial order before the court has verified the names, citations, record, law, and reasoning it is about to make official.
For courts and litigators, that is the real lesson: AI review is no longer just a filing-control problem. It is a judicial-process problem too.
D.C. Court Says AI Citation Ignorance Is No Longer Credible
The D.C. Court of Appeals has now said the quiet part plainly: lawyers can no longer credibly claim they did not know generative AI can invent legal authority.
In Douglas v. Deutsche Bank National Trust Co., the court struck Deutsche Bank's appellee brief after discovering four nonexistent cases. The order says one of Deutsche Bank's lawyers used Google's generative AI search tool to assist in finding authority and did not verify the cited cases before the brief was filed.
That would be enough for a short sanctions note.
But the published order is more useful than that. It treats the fake citations as a supervision, competence, and appellate-rule problem. It also exposes a harder institutional question: what should an appellate court do when its existing rules let it strike a defective brief and refer the matter for discipline, but may not clearly authorize more targeted sanctions against the lawyers responsible?
That makes Douglas worth reading beyond the usual warning not to paste AI output into a brief.
What Happened
The appeal started as a foreclosure case. Deutsche Bank had won judgment on the pleadings in D.C. Superior Court, and Barry Douglas appealed without counsel.
After the appeal was submitted without argument, the D.C. Court of Appeals reviewed Deutsche Bank's brief and found multiple case citations it could not locate or confirm. On June 22, the court ordered Deutsche Bank to show cause why the brief should not be struck for citing nonexistent cases that were possibly the product of AI hallucinations.
The next day, attorney Loishirl W. Hall responded in her own capacity. According to the order, she confirmed that four cited authorities did not exist and acknowledged that they were not legitimate legal authority. She explained that she had used Google's generative AI search tool to help locate case authority and had not verified the existence or accuracy of the citations before filing.
The firm, McCabe, Weisberg & Conway, filed a separate response. The order says the firm represented that it prohibits employees from using AI in drafting legal correspondence or documents and trains employees that citations must be verified regardless of source. But the court noted that the firm did not attach the policy and did not detail what it had done to supervise or review Hall's work.
The court's result was direct: Deutsche Bank's brief was stricken.
It also referred the matter to the Office of Disciplinary Counsel for whatever investigation that office deems appropriate.
The Court's Real Message
The order is not anti-AI. It says the court's intent is not to discourage lawyers from using AI and acknowledges that lawyers may now need at least an understanding of AI at their own peril.
The line the court draws is different.
AI use does not change the lawyer's duty to verify legal authority. The order says the use of AI is now so pervasive in legal practice that lawyers can no longer credibly claim ignorance of its pitfalls, including hallucinated legal authority. It cites ABA Formal Opinion 512, D.C. and other professional-responsibility guidance, and a growing body of court decisions involving fabricated AI citations.
That framing matters because it moves the issue out of novelty territory.
A lawyer who files a brief with fake cases is not just making a technology mistake. The conduct potentially implicates duties of competence and candor. The tool may explain how the error entered the draft. It does not excuse the filing.
The order also rejects a common mitigation argument: that some real authority existed elsewhere in the brief. A hallucinated citation, the court says, is worse than no citation. It wastes court resources, misdirects the court, deprives the client of credible advocacy, and undermines the adversarial process.
The Firm-Supervision Point
One of the most important parts of the order is its treatment of the law firm response.
The firm tried to separate itself from the attorney who used the AI search tool. The court was not satisfied with that posture. It emphasized that every firm attorney whose name appeared on the brief bore some responsibility, and it faulted the absence of detail about how the firm supervised or reviewed the work.
That is the operational lesson for law firms.
A policy against AI drafting is not enough if the firm cannot show how the policy is communicated, enforced, and built into filing review. Nor is annual training enough if no one can explain who checked the authorities before the brief went out.
The concurrence is especially useful on this point. Senior Judge Glickman did not say every lawyer listed on a complex brief must personally check every citation. He recognized that citation verification can be a group effort. But he also pointed toward concrete controls: training and retraining lawyers, adopting clear AI-use policies, requiring lawyers to confirm compliance, and using trained paralegals or other review processes to check citations and case descriptions before filing.
That is a more realistic governance model than either banning AI in theory or requiring every senior lawyer to redo every cite check personally.
The Sanctions Gap
The unusual part of Douglas is not just the fake citations. It is the court's discussion of remedy.
The panel struck the brief under D.C. Appellate Rule 28 and referred the matter to disciplinary counsel. But it also referred the sanctions-authority question to the court's Rules Committee for analysis and possible clarification.
Judge Glickman's concurrence explains why.
Federal courts have used several tools in AI citation cases, including Rule 11, appellate disciplinary rules, inherent authority, fee shifting, monetary sanctions, bar referrals, and suspension. The D.C. Court of Appeals does not have exactly the same rule structure. The concurrence says D.C. Appellate Rule 38 is aimed at frivolous appeals, petitions, or motions, not ordinary briefs containing some fake citations. D.C. Appellate Rule 46 addresses admission to the bar, not attorney discipline for conduct unbecoming a member of the bar. Inherent-authority sanctions require bad faith, and the existing record did not establish that Hall or the firm acted intentionally, knowingly, recklessly, or with bad faith rather than negligently or incompetently.
That left the court with what the concurrence called a comparatively weak response: striking the brief, which can penalize the client for counsel's misconduct, plus public admonishment and disciplinary referral.
That institutional problem is important. AI citation failures are becoming common enough that appellate courts may need remedial tools calibrated to lawyer conduct rather than only party consequences.
Why This Is Different From The Usual Hallucination Story
There have already been many AI citation cases. Clearon has covered several of them.
Douglas adds three useful points.
First, it is a published order from D.C.'s highest local court. That gives the decision weight in a jurisdiction with its own appellate rules and professional-responsibility system.
Second, the court expressly says ignorance of generative AI citation risk is no longer credible. That is a clean marker for law firms that still treat AI training as optional background rather than core competence.
Third, the concurrence shifts the discussion from punishment after failure to governance before filing. The point is not merely "check your citations." It is build a review process that can catch both fabricated authorities and subtler AI-generated inaccuracies.
That last point matters because fake case names are not the hardest problem. They are often the easiest to find. The concurrence warns that AI inaccuracies may be more dangerous because they can cite real authorities for propositions those authorities do not support, confuse party arguments with holdings, or mishandle the hierarchy of authority.
For legal teams, that means a citation-validation process should not stop at existence checks. Someone still has to read the source and confirm that the quoted language, holding, proposition, jurisdiction, and procedural posture are right.
What Legal Teams Should Do Now
The practical controls are not exotic.
Law firms and legal departments should require every filing workflow to answer five questions before submission:
Who used AI, if anyone, and for what task?
Who verified that every cited authority exists?
Who checked that each authority supports the proposition for which it is cited?
Who reviewed quotations, parentheticals, procedural descriptions, and record references?
Who owns escalation if a court or opposing party flags a possible hallucination or unsupported citation?
Those questions should be answered in the workflow, not after a show-cause order.
AI policies also need to distinguish between search, drafting, summarization, cite checking, and final advocacy. The risks are different. A lawyer using an AI search feature to find authority still must verify the source. A lawyer using AI to draft arguments raises a deeper problem because the lawyer may outsource the judgment that advocacy requires.
That is why the safest firm policy is not a slogan about whether AI is allowed. It is a documented review path for each use case, backed by supervision, training, file-level certification, and a plan for candor if something goes wrong.
Bottom Line
Douglas is not a ruling that lawyers may never use AI.
It is a warning that AI use has become ordinary enough that courts now expect ordinary competence around it.
The D.C. Court of Appeals struck Deutsche Bank's brief because fake citations reached the appellate record. It referred the matter for possible discipline. And it flagged that its own rules may need a better sanctions mechanism for AI-fabricated citation cases.
For law firms, the takeaway is simple: AI citation risk is no longer a training footnote. It is part of appellate quality control, supervision, professional responsibility, and client protection.
Minnesota's Nudification Law Survives xAI's Preliminary-Injunction Bid
Minnesota's AI nudification law remains in force after xAI lost its request for a preliminary injunction.
That is the immediate result of a September 4 order from Judge Donovan W. Frank in the District of Minnesota. The court denied xAI's bid to block enforcement of Minnesota Statutes section 325E.91 while the case proceeds. xAI filed a notice of appeal to the Eighth Circuit the same day.
The ruling matters because it is a live federal test of a state law aimed directly at covered nudification tools. But it should not be overstated. The court did not finally decide whether Minnesota's law is constitutional. It denied interim relief because xAI waited too long to seek emergency relief and did not make a sufficient showing of irreparable harm. The court also found that the balance of harms and public interest independently favored Minnesota.
For AI companies, the practical message is narrower and more immediate: constitutional objections may remain available, but they may not keep a state AI safety law offline during litigation.
What Changed Since The First Clearon Article
Clearon previously covered Minnesota's Chapter 72 after the court denied xAI's temporary restraining order before the law's August 1 effective date.
The new development is different. The court has now ruled on the preliminary-injunction request after briefing and argument. It again left the law in place, but this time in a longer memorandum opinion that addresses the injunction factors and the state's evidentiary showing.
The docket also moved quickly after the ruling. On September 4, xAI filed a notice of appeal from the order denying a preliminary injunction.
So the case is no longer just an emergency timing fight. It is now an active appellate test over whether Minnesota's tool-level approach can remain enforceable while the constitutional challenge continues.
What Minnesota's Law Does
Minnesota's Chapter 72 created section 325E.91, titled "Prohibition on Nudification Technology."
The statute prohibits a person who owns or controls a website, application, software, program, or other service from allowing a user to access, download, or use the service to nudify an image or video. It also prohibits nudifying an image or video on behalf of a user and bars advertising or promoting a service that performs those actions.
The law defines "nudify" as altering or generating an image or video to depict an intimate part not shown in the original unaltered image or video of an identifiable individual, where the result is realistic enough that a reasonable person would believe the intimate part belongs to that individual.
There is an exemption when the service requires the user's technical skill to nudify an image or video. The statute also says it does not alter or amend Section 230 protections and must be construed consistently with federal law.
The enforcement risk is substantial. The Minnesota Attorney General may enforce the law and seek civil penalties of up to $500,000 for each unlawful access, download, or use. A depicted individual may also bring a civil action for damages, punitive damages, injunctive relief, attorney fees, costs, and other equitable relief.
The law took effect August 1, 2026.
Why The Court Denied Interim Relief
The court's preliminary-injunction ruling rests on two main grounds: delay and irreparable harm, plus the balance of harms and public interest.
The delay point is direct. H.F. 1606 was signed on May 7. xAI filed its lawsuit and emergency motion near the end of July, roughly three months later and only days before the law took effect. Judge Frank wrote that xAI is a sophisticated and well-resourced litigant and that, if it genuinely feared irreparable harm, it would have acted more quickly.
That timing problem mattered both at the temporary-restraining-order stage and at the preliminary-injunction stage.
The court also rejected xAI's irreparable-harm showing. xAI pointed to the risk of large civil penalties, commercial injury, engineering work to implement Minnesota-specific controls, increased moderation, potential user loss, and alleged First Amendment injury.
The court found those showings insufficient for interim relief. It treated the civil penalties as monetary in nature. It noted that xAI had already disabled its nudification tool in Minnesota, making penalties unlikely on the record before the court. It also described xAI's evidence of engineering cost, moderation burden, and user loss as vague, conclusory, or speculative.
On the First Amendment point, the court did not say First Amendment harm can never be irreparable. It said that even in First Amendment cases, a movant must make a clear showing of likely irreparable harm, and delay can independently support denial of a preliminary injunction.
The Merits Are Still Open
The court did not resolve xAI's First Amendment challenge.
That distinction is important. The order says the parties "sharply contest" the strength of xAI's First Amendment claim. xAI argues it is likely to succeed. Minnesota disputes xAI's standing to assert its users' First Amendment rights, disputes xAI's own asserted First Amendment interest, and argues the statute is valid under any level of scrutiny.
Judge Frank called the constitutional issues complex, especially in the context of new technology and public risk. The court said those issues deserve full consideration and may be addressed in the future through the state's motion to dismiss or later permanent-injunction proceedings.
So this is not a final ruling that Minnesota's statute survives First Amendment review. It is a ruling that xAI did not justify blocking the law now.
That posture should shape how companies read the decision. The order is strongest as a lesson about emergency relief, evidentiary showings, and litigation timing. It is not yet a definitive answer on how far states may go in regulating generative image tools.
The Public-Interest Record Helped Minnesota
The court also found that the balance of harms and public interest tipped "steeply" in Minnesota's favor.
The order points to the legislative record around harms from AI nudification technology. It describes testimony about missed work, fear, family harm, and the emotional burden of realistic sexualized images and videos. It also cites evidence about widespread use of nudification apps, synthetic sexual images of adults and children, school-related harms, and reports involving AI-generated child sexual abuse material.
That record mattered because Minnesota framed the law as a response to a specific product-safety and victim-protection problem. The court accepted, for purposes of the preliminary-injunction balance, that the state has an interest in curbing the generation and proliferation of those images.
xAI's harm showing did not outweigh that public-interest evidence at the interim stage.
For future challenges to AI laws, that is a useful signal. Courts may look closely at whether the state built a factual record explaining the harm and whether the challenger can identify concrete, imminent harm from enforcement. Abstract concern about overbreadth may not be enough to suspend a statute while the merits are still pending.
What The Appeal Means
xAI's same-day notice of appeal keeps the fight alive.
The appeal does not automatically mean Minnesota's law is invalid, and it does not by itself suspend enforcement. Unless a court grants stay relief or reverses the district court's preliminary-injunction ruling, section 325E.91 remains in effect while the litigation continues.
The appeal also means the Eighth Circuit may soon have to address how emergency-relief principles apply to state AI laws that regulate expressive tools, user misuse, product controls, and synthetic sexual imagery.
That is a narrower appellate question than the ultimate merits question. An appellate court reviewing a preliminary-injunction denial can focus on delay, irreparable harm, balance of equities, public interest, and likelihood of success without finally deciding every constitutional issue.
Even so, the appeal will be watched closely because the underlying statute is unusual. Minnesota did not merely create a takedown system after abusive content is posted. It restricted covered access to nudification functionality itself.
What AI Companies Should Do Now
Companies offering image generation, image editing, avatar tools, video generation, or transformation features should treat this as a live compliance development.
The first question is not whether Minnesota will ultimately win. The first question is whether the company can explain, today, whether its product lets users generate realistic altered depictions of intimate parts of identifiable people and what controls prevent that result.
Product, legal, and trust-and-safety teams should be able to answer:
whether the system can create the category of output Minnesota defines as "nudified";
whether controls operate before generation, before export, before sharing, or only after abuse reports;
whether geographic controls have been implemented for Minnesota users;
whether logs can show what controls were active at the relevant time;
whether policy enforcement is enough under a statute aimed at service access rather than only user misconduct;
whether any relied-on "technical skill" argument is actually supported by product design; and
how the company would respond if another state copied Minnesota's access-level model.
This is especially important because the district court considered xAI's already-implemented Minnesota controls when weighing harm. A company that waits until enforcement is imminent may have a harder time arguing that compliance work, moderation burden, or lost users justify emergency court relief.
What Not To Overread
There are three limits to keep in view.
First, the order does not decide whether Minnesota's law is constitutional.
Second, the order does not say every state law aimed at AI image tools will survive. It is tied to this statute, this record, xAI's timing, and xAI's evidence of harm.
Third, the order does not erase federal-law questions. Minnesota's statute expressly says it does not alter Section 230 protections and must be construed consistently with federal law. How that clause works in practice may matter later.
The safer reading is practical: Minnesota's law stays active for now, and challengers to similar AI laws will need a stronger emergency-relief record if they want to stop enforcement before the merits are decided.
Bottom Line
Minnesota has won the first full preliminary-injunction round in the xAI challenge to its nudification law.
That does not settle the First Amendment merits. But it does leave Minnesota's tool-level nudification statute in effect while xAI appeals.
For AI companies, the compliance takeaway is immediate. If a state law regulates access to a covered image-generation or editing function, waiting until the eve of enforcement to challenge it can weaken the emergency-relief case. And if a company has already built state-specific controls, it should preserve the evidence showing what changed, when it changed, and why.
The next phase will likely unfold in the Eighth Circuit. Until then, Minnesota's law remains a live example of how states may try to regulate AI-enabled synthetic intimate imagery upstream, at the product-access layer.
Seattle Times and Newsday Add Trademark Dilution to the OpenAI Publisher Fight
The newest newspaper suit against OpenAI and Microsoft is not just another training-data complaint.
The Seattle Times Company and Newsday LLC filed a seven-count complaint in the Southern District of New York on September 4, 2026. The case accuses OpenAI entities and Microsoft of using the publishers' journalism without permission in generative AI systems, including ChatGPT, Copilot, and Bing Chat.
That part fits the broader publisher-litigation pattern.
The more interesting feature is the claim mix. The complaint pleads copyright infringement, vicarious copyright infringement, two DMCA copyright-management-information counts, and three trademark-dilution counts. In other words, the case is not framed only around whether model training is fair use. It also tries to make allegedly hallucinated or misattributed AI output a brand-injury problem.
For companies building or deploying AI answer products, that is the part worth watching.
What The Complaint Alleges
The complaint says OpenAI and Microsoft copied large quantities of Seattle Times and Newsday journalism without permission or compensation. The publishers allege the defendants obtained articles by scraping their websites, bypassing paywalls, using datasets derived from WebText, WebText2, Common Crawl, and Microsoft's Bing search index, and then using that material to train, fine-tune, ground, and operate large language models.
Those are allegations, not findings. OpenAI and Microsoft have not lost this case. No court has ruled that the complaint's factual claims are true.
But the pleading is concrete enough to matter. It identifies The Seattle Times and Newsday as regional publishers with long-running copyright-registration programs, registered marks, paywalled websites, and active claims that AI systems can reproduce or closely paraphrase their journalism.
The complaint also alleges output examples. It says ChatGPT reproduced an 88-word passage from The Seattle Times' Pulitzer-winning Boeing 737 MAX coverage after being prompted with the headline and URL. It also includes Newsday examples where model output allegedly tracked or reproduced article text.
That is the copyright side of the case. The complaint's broader move is to connect those alleged outputs to two other theories: DMCA removal or distribution of copyright management information and dilution of the newspapers' marks.
The Seven Counts
The complaint pleads seven counts.
Count I is direct copyright infringement under 17 U.S.C. section 501. The publishers allege that copies of their works were reproduced, stored, processed, used in training datasets, used for training, fine-tuning, and grounding, and disseminated through generative output containing copies or derivatives.
Count II pleads vicarious copyright infringement against Microsoft and several OpenAI-related entities. The theory is that Microsoft and parent or affiliated OpenAI entities allegedly had the right and ability to control the infrastructure and conduct that produced the copying, while also profiting from it.
Counts III and IV are DMCA claims under 17 U.S.C. section 1202(b). Count III alleges removal of copyright management information such as author names, titles, copyright notices, and terms-of-use information. Count IV alleges distribution of works or output knowing that copyright management information had been removed.
Counts V, VI, and VII are trademark dilution. Count V is a federal Lanham Act dilution claim. Count VI is a Washington dilution claim for The Seattle Times. Count VII is a New York dilution claim for Newsday.
That structure matters because it pushes the case beyond the now-familiar training-copying fight.
Why The Trademark Counts Are The Signal
Most AI publisher cases are described as copyright cases, and many of them are. This complaint is broader.
The trademark-dilution counts rest on a different harm theory. The publishers allege that OpenAI and Microsoft products reproduce, output, and associate THE SEATTLE TIMES and NEWSDAY marks with AI-generated material that the publishers did not create, review, or publish. The complaint characterizes this as both blurring and tarnishment.
That is a useful distinction for AI companies.
Copyright law asks whether protected expression was copied, whether a use is infringing, whether fair use applies, and what remedies follow. Trademark dilution asks whether a famous or distinctive mark is being impaired or tarnished by association with someone else's product or output.
The complaint's theory is that hallucinated or misattributed AI answers can do more than copy text. They can attach a publisher's name to inaccurate, fabricated, or substandard content and thereby weaken the source-identifying value of the mark.
That theory will have hurdles. Trademark dilution is not a shortcut around copyright doctrine, and the plaintiffs still have to prove the elements of each claim. But the pleading is a reminder that output governance is not only about avoiding verbatim reproduction. It is also about attribution, brand association, source labeling, and whether users may believe a reputable publisher stands behind text it never reviewed.
The DMCA Counts Also Matter
The DMCA counts are quieter but potentially important.
The publishers allege that their articles carried copyright management information, including copyright notices, author and title information, and terms-of-use information. They then allege that OpenAI and Microsoft removed that information while building datasets, training and operating models, and generating output containing copies or derivatives.
The second DMCA count alleges distribution of works or generated output with that information removed.
Those claims can matter even where the core copyright issue is contested. A defendant might argue about fair use for training, while still facing separate questions about whether copyright-management information was stripped or omitted in a way section 1202 forbids.
That does not mean the DMCA claims will succeed. Courts have not treated every metadata or attribution omission as a section 1202 violation. The point is narrower: the complaint asks the court to look at the data pipeline and output pipeline, not just the final model-training question.
For AI governance teams, that makes provenance and attribution controls more than a content-policy nicety. They can become litigation facts.
The Requested Remedy Is Aggressive
The prayer for relief asks for damages, profits, injunctions, and attorney fees. It also asks the court to order impoundment or destruction, under 17 U.S.C. section 503, of copies of the publishers' works and all LLMs and training datasets incorporating those works or derivatives.
That remedy request will draw attention, but it should be read carefully.
A complaint can ask for broad relief at the start of a case. That does not mean the court will grant it. It does not mean a court has found that any model must be destroyed. And it does not mean the defendants lack defenses.
Still, the request shows how plaintiffs are framing leverage. They are not asking only for a license fee after the fact. They are asking the court to treat the alleged copying as embedded in datasets, model systems, and commercial products.
That framing is why these cases matter beyond one pair of newspapers.
How This Fits With The Existing OpenAI Copyright Fight
The timing is notable. The Seattle Times and Newsday complaint was filed the same day summary-judgment motions were due in the consolidated OpenAI copyright litigation before Judge Sidney H. Stein.
Clearon has already covered that public-access calendar. The merits briefing in the consolidated case is expected to become visible in stages, with opening summary-judgment briefs and Rule 56.1 statements due for public refiling on September 17 to the extent no party or third party seeks sealing.
That means this new complaint lands while the broader OpenAI copyright fight is moving into a decisive merits phase.
The new case is separate at filing. The complaint's docket is No. 1:26-cv-07644. But it was filed in the same district, against OpenAI and Microsoft, and it overlaps with the same broad questions about publisher content, training data, retrieval, output substitution, and fair use.
The practical point is that companies should not treat the OpenAI litigation map as one monolithic case. Different plaintiffs are testing different combinations of claims. This one adds a strong masthead and attribution angle.
What Not To Overstate
There are four easy mistakes to avoid.
First, this is a complaint, not a ruling. The allegations are unproven.
Second, the trademark counts do not automatically solve the copyright case. They add a separate theory tied to brand dilution, hallucinated attribution, and association with AI-generated output.
Third, the remedy request for destruction of models and datasets is a demand, not an order. It is important because of what it signals, but it is not an operative court command.
Fourth, the case does not answer the fair-use question pending in the broader OpenAI litigation. The defendants can still argue that training-stage copying is lawful, that output examples are not legally sufficient, that DMCA elements are not met, or that trademark dilution is not available on these facts.
The safer reading is that the case expands the pressure points.
What To Watch Next
The first thing to watch is whether the case is related, coordinated, or otherwise drawn into the orbit of the existing OpenAI copyright proceedings in the Southern District of New York.
The second is how OpenAI and Microsoft respond to the trademark-dilution counts. If they move to dismiss, the court may have to decide how far publisher-brand theories can go when the alleged harm comes from AI output rather than traditional source confusion.
The third is whether the DMCA counts survive early motion practice. Section 1202 claims often turn on knowledge, causation, and whether removed information plausibly enabled or concealed infringement.
The fourth is how the complaint's output examples hold up. The more specific and reproducible the examples are, the more pressure they may put on controls around memorization, retrieval, attribution, and paywalled content.
For AI companies, this is the operational lesson: copyright-risk controls and brand-risk controls cannot be separated cleanly. Training data, retrieval stores, output filters, attribution rules, and refusal behavior all create the factual record future plaintiffs will use.
Bottom Line
The Seattle Times and Newsday case is not just another publisher complaint against OpenAI and Microsoft.
It is a seven-count pleading that combines copyright, vicarious liability, DMCA CMI, and trademark-dilution theories. The copyright claims will get the headline, but the trademark counts may be the more useful governance signal.
If a model generates text that users associate with a real publisher, the risk is no longer only whether protected expression was copied. It may also be whether the output misuses the publisher's name, weakens its brand, or attaches that mark to content the publisher did not make.
That is why this case belongs on the AI litigation watchlist. It shows how the publisher fight is evolving from training-data law into a broader dispute over output, attribution, brand integrity, and the economics of answer engines.
OpenAI's Copyright Summary-Judgment Fight Now Has a Public-Access Calendar
The next major filings in the consolidated OpenAI copyright litigation will not become fully visible all at once.
That is the point of a September 3 stipulated sealing order entered by Judge Sidney H. Stein in the Southern District of New York. The order does not decide the merits of the copyright claims. It does not finally determine which material will remain sealed. And it should not be read as a finding that OpenAI, Microsoft, publishers, authors, or other parties are entitled to keep the summary-judgment record from public view.
It does something narrower but still important: it sets a two-track calendar. Daubert briefing and summary-judgment exhibits can move through provisional sealing and later omnibus sealing motions. Summary-judgment briefs and Rule 56.1 statements follow a separate public-refiling process with earlier dates.
For companies and publishers watching the case, the dates now matter almost as much as the arguments.
What The Order Actually Does
The order is a stipulated omnibus sealing order for summary-judgment and Daubert briefing in In re OpenAI, Inc. Copyright Infringement Litigation, No. 1:25-md-3143-SHS-OTW. It applies to all cases in the consolidated proceeding.
The parties told the court that the coming briefing is expected to refer to or attach material designated as Protected Discovery Material under the protective order. They asked to handle many sealing issues through later omnibus motions after briefing, rather than through separate sealing motions at the moment every brief or exhibit is filed.
Judge Stein approved that structure.
The practical result is a two-track public-access schedule. Exhibits, expert reports, declarations, and Daubert materials may be provisionally sealed if they contain or refer to protected discovery material. Summary-judgment briefs and Rule 56.1 statements are treated separately, with earlier public-refiling dates and party-by-party sealing procedures.
That distinction matters because the briefs are where the parties' legal theories should become visible first. The evidentiary record may take longer.
The Key Summary-Judgment Dates
The court has already set the summary-judgment schedule: motions by September 4, 2026, oppositions by October 9, 2026, and replies by November 6, 2026.
The sealing order adds the public-access timing around those filings.
For opening summary-judgment briefs and Rule 56.1 statements, a moving party must file any motion to seal its own protected material by September 4. Other parties and third parties have until September 14 to support requests to maintain under seal portions of another party's brief or Rule 56.1 statement. By September 17, the parties must publicly re-file their summary-judgment briefs and Rule 56.1 statements, leaving unredacted the portions that no party or third party has sought to seal.
The same pattern repeats for oppositions. Opposition briefs and responsive Rule 56.1 statements are due October 9. Supporting statements for another party's proposed sealing are due October 14. Public refiling is due October 15 at 5:00 p.m. ET.
For reply briefs, sealing motions are due November 6. Supporting statements for another party's proposed sealing are due November 16. Public refiling is due November 19.
Those dates are now the public-access map for the merits phase of the case.
The Exhibits Move On A Slower Calendar
The order gives exhibits and expert materials a different timeline.
For Daubert briefing and summary-judgment exhibits, including expert reports and declarations, the parties may provisionally seal materials that contain or refer to Protected Discovery Material. The parties and affected third parties are relieved from the usual contemporaneous sealing-motion and short justification requirements for those provisionally sealed materials.
But the relief is temporary.
Anyone who wants provisionally sealed material to remain sealed must file an omnibus sealing motion by January 13, 2027. Responses are due January 20. Any provisionally sealed material that no party or third party moves to seal by January 13 must be publicly filed by January 27.
That is important for two reasons.
First, the January schedule means the public may see the legal briefs before it sees the full evidentiary fight. Second, it means the current order is not a final secrecy ruling. It is a staging order. It defers the sealing fight for many exhibits, but it also creates a deadline for that fight.
Why This Matters Beyond Procedure
OpenAI's copyright cases have already become one of the central legal battlegrounds over generative AI training, publisher substitution, retrieval systems, outputs, and licensing leverage.
The summary-judgment phase is where those arguments may become more concrete.
The court may be asked to decide, or at least frame, questions about training-stage fair use, market substitution, acquisition practices, output behavior, protected expression, and the weight of expert evidence. Those are not abstract issues for AI companies or rightsholders. They go directly to how AI developers build datasets, evaluate licensing exposure, structure retrieval and output controls, and explain risk to boards, customers, investors, and regulators.
That is why the sealing calendar deserves attention. Until the public filings appear, outside observers should be careful about any claim that one side's summary-judgment arguments have already won, collapsed, or shifted the law. The briefs may be filed under seal first. The public versions will arrive later, subject to redactions tied to pending sealing requests.
The safer takeaway is procedural: the merits fight is moving into summary judgment, and the public record is scheduled to emerge in stages, subject to later sealing decisions.
What Not To Overstate
There are three easy mistakes to avoid.
First, this is not a ruling on fair use. It does not decide whether OpenAI's training uses are lawful, whether particular outputs infringe, whether acquisition conduct matters separately, or whether publishers and authors can prove market harm.
Second, this is not a permanent sealing decision. The order permits provisional sealing and sets deadlines for later sealing motions. It also says nothing prevents a party from challenging another party's or third party's request to maintain material under seal.
Third, the order does not mean the public will have no meaningful access to the arguments. The opposite is closer to the point. It identifies specific dates when public refiling must occur for the summary-judgment briefs and Rule 56.1 statements, with unredacted material where no sealing request has been made.
In other words: the order creates a staged process for handling protected discovery material in a sprawling litigation record.
What To Watch Next
The first date to watch is September 17, when public versions of the opening summary-judgment briefs and Rule 56.1 statements are due. That is likely to be the first meaningful public window into the parties' merits arguments at this stage, subject to requested redactions.
The second date is October 15 at 5:00 p.m. ET, when public opposition briefs and responsive Rule 56.1 statements are due.
The third is November 19, when public reply briefs are due.
The fourth is January 13, 2027, when any party or third party seeking to keep provisionally sealed exhibits and expert materials under seal must file an omnibus motion. January 27 is the follow-on public-filing deadline for provisionally sealed materials no one moved to seal.
Those dates should guide how companies read the next wave of coverage. Early reports may be based on sealed docket entries, partial public material, party statements, or secondhand descriptions. The more reliable analysis will come after the public versions are filed and the court's sealing process narrows what remains subject to a sealing request.
Bottom Line
The September 3 order is not the copyright ruling everyone is waiting for.
It is the calendar that tells us when that fight becomes visible.
Opening summary-judgment arguments must be publicly re-filed by September 17 to the extent no party or third party has sought sealing. Opposition and reply briefs follow in October and November. Exhibits and expert materials may remain provisionally sealed longer, but the order sets January deadlines for formal sealing motions and public filing where no sealing request is made.
For Clearon readers, that means the next phase of the OpenAI copyright litigation should be tracked by date and document type, not just headline. The legal arguments, factual record, and expert evidence will not surface together. They are scheduled to emerge in layers, subject to later sealing decisions, and each layer may matter for AI training, publisher licensing, output controls, and copyright-risk planning.