The AI remarks, reported by NBC affiliate WCMH and republished by AOL, were part of an address principally about judicial independence. But the more practical story for IT administrators is the collision Kennedy described: courts are being pressed to adopt AI tools while their case-management data — including material that may contain sensitive personal information — sits in systems operated by third parties.
Ohio’s own breach notices establish that this is not a hypothetical concern. A March 2026 intrusion involving Thomson Reuters Court Management Solutions’ C-Track platform affected the production environment serving 10 of Ohio’s 12 appellate districts. The court says it still has not determined what personal information was exposed or who was affected. That uncertainty should govern any conversation about feeding court data into generative AI services.
The breach reached the production platform, not a disposable test system
The Ohio Supreme Court said it was notified on July 24 about a cybersecurity incident involving C-Track, an appellate case-management system hosted by the court and managed by Thomson Reuters Court Management Solutions, a West Publishing unit. The vendor later told Ohio that unauthorized access had taken place on the court’s production platform, which holds filing-system data for the 10 appellate districts that use C-Track.
Those 10 districts are the First through Seventh, Ninth, Eleventh, and Twelfth. Ohio’s Eighth District in Cuyahoga County and Tenth District in Franklin County do not use C-Track and were identified by the court as unaffected by this particular incident.
That distinction deserves emphasis. “Production” is not merely a technical classification. In a court environment, it can mean filings, party names, addresses, attachments, docket material, and other records that must be retained, disclosed selectively, redacted, or sealed under legal rules. The First District Court of Appeals has separately said its C-Track deployment is an internal case-processing tool rather than its electronic filing service, so the incident did not prevent parties from filing documents. But operational continuity is not the same thing as confidentiality: the underlying question of which nonpublic information was accessed remains open.
Reuters reported on September 2 that Thomson Reuters’ investigation found an unauthorized party had obtained certain C-Track files in March, after the company detected suspicious activity on June 30. Ohio was notified weeks later, on July 24, and issued its public notice on September 2. The sequence is a reminder that a hosted platform’s detection and notification timeline may be very different from an agency’s public-disclosure timeline.
For system owners, the gap is not academic. An organization cannot begin meaningful review of exposed record classes, notification obligations, access logs, or downstream data-sharing risks until its vendor provides enough technical detail to identify what was accessed.
Ohio has not received a full account of the vendor’s security changes
Ohio’s September 2 statement contains an unusually candid limitation: Thomson Reuters told the court that enhanced security measures had been deployed, but the court said it had not received comprehensive details of those measures.
That leaves administrators with an unresolved vendor-assurance problem. Courts were told remediation occurred, but Ohio did not say which controls changed, whether the compromise involved authentication, administrative access, backups, a software vulnerability, or a third-party integration. It also did not identify the threat actor, describe the method of entry, or say whether the affected files were encrypted at rest and exfiltrated in readable form.
Thomson Reuters’ public C-Track notification lists affected court systems in 11 U.S. states, the U.S. Virgin Islands, and Ontario. Reuters independently reported the multi-jurisdictional scope. Kennedy’s figure of 18 supreme courts, as quoted by WCMH, is broader than the public vendor list’s description of affected court systems and has not been explained in Ohio’s published breach notice. The public record supports a large multi-jurisdiction incident; it does not yet provide a clean, comparable count of affected supreme courts.
That mismatch is more than a semantic quibble. Affected entities may include appellate courts, trial-court systems, former clients, clerk offices, and judicial administrative organizations. Incident reporting should distinguish the number of jurisdictions, court systems, production tenants, records, and individuals. Those figures answer different questions, and merging them can overstate or obscure exposure.
The immediate action for any government IT team using a hosted case-management, e-filing, records, or legal-research platform is to ask the vendor for the specifics Ohio says it has not yet received:
- The vendor should identify the precise tenant, environment, date range, and data stores accessed or copied.
- The vendor should provide a record-level description of affected information, including sealed, redacted, juvenile, financial, identity, and health-related material where applicable.
- The vendor should explain the initial-access path, the controls added after discovery, independent validation of those controls, and whether those changes apply to every customer environment.
- The customer should obtain logs and indicators of compromise sufficient to test whether related accounts, exports, integrations, or local copies were involved.
A promise that security was “enhanced” is not a substitute for a remediation report that security staff can evaluate.
Kennedy’s AI boundary is a governance principle, not a new Ohio rule
Kennedy told the Ohio Judicial Conference that judicial decision-making cannot be delegated to AI. She also expressed concern that sensitive court data could be fed into an AI model, and said she is participating in a national consortium examining proper use of AI in courts.
Her formulation is sensible and narrow: use technology with human accountability intact, and do not allow a model to supply the legal analysis or outcome of a case. Yet readers should not mistake the speech for a newly issued statewide AI policy, procurement ban, or enforceable rule governing every Ohio court.
The Supreme Court’s own AI Resource Library demonstrates that Ohio is already assembling guidance rather than treating AI as an entirely new subject. The library links to National Center for State Courts material, state-level AI guidance, and other judiciary policies. It also warns lawyers that AI-assisted legal research can produce fictitious citations and legal propositions. Ohio appellate opinions have already confronted filings containing fabricated authorities, so this is not an abstract future risk.
What remains missing is the operational policy that court staff and local IT organizations need: a definitive public standard for what data may enter public AI tools, enterprise AI tenants, legal-research AI products, transcription systems, document-review services, and internally hosted models. A resource library educates. It does not tell a clerk’s office whether it may paste a draft order into an AI assistant, whether an uploaded attachment becomes provider training data, or how a court must preserve prompts and outputs when they influence administrative work.
Courts do not need to ban every AI-enabled function to address that gap. They need classifications and controls. Public records can be handled differently from nonpublic records; approved enterprise tools differently from consumer chatbots; optional drafting assistance differently from a workflow that ranks, recommends, or resolves legal outcomes. The central discipline is to prevent confidential material from crossing an unapproved boundary merely because a tool is easy to use.
The vendor breach changes the threshold for trusting AI assurances
The C-Track incident and Kennedy’s AI remarks concern different technologies, but they turn on the same administrative question: who controls court data after it leaves a local workstation or courthouse network?
With C-Track, Ohio relied on a system hosted by the court but managed by a vendor. With generative AI, a court may use a vendor model, cloud service, legal platform, or integrated assistant. In both cases, a public institution has to know where data resides, which parties can access it, how activity is logged, whether data is retained, and what happens after a security event.
The breach therefore strengthens the case for treating AI adoption as a data-governance project before it becomes a productivity project. Courts and public agencies should inventory AI features embedded in existing software — including document systems, research platforms, communications tools, and endpoint products — rather than assuming AI arrives only through a separately purchased chatbot.
They should also require contractual answers to questions that are often buried in product documentation: whether prompts or uploaded files are retained; whether customer data is used for model training; where inference is processed; how data is segmented between customers; which subprocessors participate; and how quickly the vendor must disclose a suspected compromise.
Kennedy’s warning is most useful when read this way. The issue is not whether judges will be replaced by a model. The nearer risk is that poorly governed AI use can move court data into systems whose security, retention, and decision pathways are harder to see than the courthouse systems they are meant to improve.
Ohio’s next meaningful update should be the breach investigation’s determination of what data was actually exposed and whether affected people will receive direct notice. Until then, the state has a live demonstration of why courts should demand evidence — not assurances — before entrusting sensitive records to another managed platform.