Andersen v. Stability AI Ltd.
- William Orrick
- 3:23-cv-00201
- U.S. District Court · Northern District of California
- 6
Counsel of record per CourtListener. Firm names are approximate and have been consolidated across spelling variants.
In Andersen v. Stability AI Ltd., Judge Orrick barred Plaintiffs from giving specified confidential materials to expert Dr. Zhao after finding competitive risk outweighed their need.
The ruling affects Plaintiffs, Defendants, and Plaintiffs’ expert Dr. Ben Yanbin Zhao: materials designated “ATTORNEYS’ EYES ONLY” or “HIGHLY CONFIDENTIAL – SOURCE CODE” may not be disclosed to Dr. Zhao.
What happened
In Andersen v. Stability AI Ltd., the parties disagreed about whether Plaintiffs could give their expert, Dr. Ben Yanbin Zhao, access to materials marked “ATTORNEYS’ EYES ONLY” or “HIGHLY CONFIDENTIAL – SOURCE CODE.” Plaintiffs said Dr. Zhao’s expertise in generative artificial intelligence made him especially valuable, while Defendants argued that his research tools could harm their models and products.
The court found that Dr. Zhao’s work was functionally competitive with Defendants’ work because he develops tools that make generative artificial-intelligence models less reliable. It also found that other qualified experts were available, so Dr. Zhao was not uniquely qualified to review the materials.
Judge Orrick ruled that the risk of harm to Defendants outweighed Plaintiffs’ need for disclosure. The court granted Defendants’ request that materials with those confidentiality designations not be disclosed to Dr. Zhao.
The detailed version
- Andersen v. Stability AI Ltd. · No. 3:23-cv-00201
- William Orrick
- July 14, 2025
Background
The court considered the parties’ joint discovery letter about Plaintiffs’ proposed disclosure of highly confidential materials to their expert, Dr. Ben Yanbin Zhao. Defendants objected to giving Dr. Zhao access to materials designated “ATTORNEYS’ EYES ONLY” or “HIGHLY CONFIDENTIAL – SOURCE CODE,” including source code and training data.
Dr. Zhao is described as a computer science professor at the University of Chicago who researches generative artificial intelligence and machine learning. He leads the Glaze Project, which develops tools intended to protect human creators from certain uses of generative artificial intelligence. The opinion identifies Glaze as a tool that changes digital artwork to prevent artificial-intelligence models from accurately copying an artist’s style, and Nightshade as a tool that changes image data so models produce distorted or incorrect results for some prompts.
Plaintiffs argued that Dr. Zhao was an academic researcher, not an actual competitor, and that reviewing Defendants’ source code or training data would provide no substantive benefit to his research. Defendants argued that disclosure would create serious competitive risks because Dr. Zhao’s work develops tools that undermine generative-artificial-intelligence models.
Legal standard
The court explained that an expert may testify when the expert’s knowledge, skill, experience, training, or education will help the factfinder understand evidence or decide a disputed fact. A party ordinarily receives some deference in selecting and preparing an expert with relevant experience. That interest must be balanced against the risk that confidential information will be improperly used or disclosed.
Under the parties’ protective order, the party opposing disclosure had the burden of showing that the risk of harm from disclosure, considering the proposed safeguards, outweighed the receiving party’s need to disclose the material to its expert. The court therefore considered Defendants’ risk of harm and Plaintiffs’ need for disclosure.
Court’s analysis
The court rejected Plaintiffs’ argument that Dr. Zhao could not be a competitor because he was an academic rather than a company competing for the same customers or revenue. The court found that his work was “in functional competition with Defendants” because his tools attack or reduce the reliability of generative-artificial-intelligence models. The court noted that Dr. Zhao had not agreed to stop developing other data-poisoning tools or researching ways to make image-generating models less effective during the litigation.
The court did not suggest that Dr. Zhao would intentionally misuse information. Instead, it found that highly confidential information could become intertwined with his broader knowledge and later be disclosed through his future work, even if he tried to keep the information separate. The court concluded that Defendants had shown a risk of harm from disclosure.
The court then considered whether Dr. Zhao had unique knowledge that justified allowing him to review the highly confidential materials. It accepted that qualified experts in artificial-intelligence image generation who were not employed by Defendants’ direct competitors might be limited. But it found that the field was not so narrow that Dr. Zhao was the only qualified expert. The court cited academic papers and another academic expert designated in a similar case as evidence that other qualified experts existed.
Although the court recognized that Dr. Zhao was qualified, it found that he was not uniquely qualified to help the court and jury understand how generative-image models memorize, output, and allegedly infringe copyrighted work.
Ruling
The court held that the risk of harm to Defendants outweighed Plaintiffs’ need to disclose materials designated “ATTORNEYS’ EYES ONLY” or “HIGHLY CONFIDENTIAL – SOURCE CODE” to Dr. Zhao. It granted Defendants’ request that information bearing those designations not be disclosed to him.
The court expressly stated that it was not deciding whether Dr. Emily Wenger could be designated as an expert in this case; that dispute was not before it.
Read the full 6-page opinion on CourtListener, the free public archive maintained by the Free Law Project.