Published on This Week in AI

AI in Legal Discovery: Rules, Obligations, and Risks of Using AI for eDiscovery

The use of AI in litigation discovery has moved from a specialist technique to standard practice in large document review matters. Machine learning tools are used to prioritize, categorize, and identify relevant documents from collections that may number in the millions. This shift brings genuine efficiency — but it also brings professional obligations, disclosure questions, and cross-border complications that legal teams must understand before deploying these tools in live matters.

From TAR to Modern AI: A Brief History

Technology-assisted review (TAR) — also called predictive coding — emerged as a recognized approach to document review in the early 2010s. The core methodology involves training a model on attorney-reviewed seed documents, then having the model predict relevance across a larger population of documents. Courts in the US and UK began approving TAR protocols and in several cases acknowledged that TAR could be as reliable as traditional linear review when properly implemented and validated.

Modern AI tools used in discovery differ meaningfully from first-generation TAR. Contemporary platforms incorporate large language models capable of semantic search, concept clustering, cross-format deduplication, and near-duplicate identification at scale. They can summarize document populations, identify custodians from conversational patterns, generate chronologies, and flag potential privilege markers across entire collections simultaneously. The capabilities are substantially greater — but so are the obligations around understanding, documenting, and validating what the tool has done.

The Competence Obligation

Lawyers have a professional obligation to be competent, and competence now includes understanding the technology used in practice. In ABA Model Rule 1.1 jurisdictions, Comment 8 notes that keeping abreast of changes in the law and its practice includes understanding the benefits and risks of relevant technology. Applied to AI-assisted review, this means attorneys supervising AI tools must understand the tool's methodology well enough to make defensible decisions about its configuration, training, and validation — and to identify when its outputs require additional scrutiny.

Competence does not require that supervising lawyers understand the underlying model architecture. It does require that they understand what the tool was configured to find, what confidence thresholds or cutoffs were applied, and what quality control steps were taken to verify the output. An attorney who relies entirely on vendor-supplied defaults without understanding them is exposed to competence challenges if the production is later attacked.

Quality Control and Defensibility

The use of AI does not reduce the obligation to produce a defensible, complete, and proportionate document set. Courts expect parties using AI-assisted review to document their methodology. A robust quality control protocol typically includes: sampling of documents categorized as non-relevant to assess recall; review of borderline outputs; precision testing across the relevant population; and a written record of the protocol chosen and the results obtained. These records may be subpoenaed or requested by opposing counsel in challenges to the production.

The defensibility of the review depends not on whether AI was used but on whether the methodology was reasonable, the validation was appropriate, and the results were monitored throughout the review. A documented, tested AI-assisted review process can be more defensible than an undocumented linear review — but the documentation is essential.

Disclosure Obligations

Courts in several US jurisdictions have issued standing orders or individual case management orders requiring parties to disclose their use of AI tools in document review. In the absence of a standing order, disclosure may still be required under general duty of candor obligations, under the cooperative discovery requirements applicable in many courts, or where AI tool use is material to understanding the scope and methodology of a production. Legal teams should check applicable local rules and standing orders at the outset of any matter involving AI-assisted review, and should build disclosure questions into their standard matter-opening checklist.

The trend toward mandatory AI disclosure in litigation is likely to accelerate. Practitioners should assume that disclosure will be required or requested in significant matters and structure their methodology accordingly — keeping clear records from the start rather than reconstructing them later.

Privilege Review and AI

AI does not change the fundamental rule that privilege determinations are the attorney's responsibility. AI tools can flag documents containing terms commonly associated with legal advice, attorney identity, or work product characteristics, but an attorney must make the final privilege call. Inadvertent production of privileged documents through AI-assisted review creates risk that should be managed through claw-back agreements agreed in advance of production, particularly in US federal matters where Federal Rule of Evidence 502(d) orders can provide prospective protection. The volume and speed capabilities of AI tools make pre-production privilege review protocols more important, not less.

Cross-Border: GDPR and eDiscovery

Responding to US discovery requests often requires collecting and processing personal data of individuals located in the EU. The GDPR's data minimization principle — which requires processing only what is necessary for the specified purpose — creates tension with the broad relevance standard under US discovery rules. Transfer of document sets containing EU personal data to a US review platform may require appropriate safeguards under GDPR Chapter V, and processing for litigation purposes must be assessed against applicable legal bases. Legal teams should engage privacy counsel at the outset of any cross-border discovery matter to structure collection and review in a way that satisfies both jurisdictions' requirements. The tension between US discovery obligations and EU data protection law remains an active area of regulatory and litigation development. For related AI regulatory context, see our overview of EU AI Act obligations for businesses.

Vendor Selection

Choosing an AI-assisted review vendor is itself a professional decision. Legal teams should assess whether the vendor's methodology has been independently tested, whether the tool's outputs can be audited and explained, whether the vendor's security practices are adequate for the sensitivity of the matter, and what contractual protections apply if errors in the AI output result in over-disclosure or missed production. The defensibility of the review is only as strong as the documented basis for vendor selection — a point that becomes important if opposing counsel challenges the methodology. For a broader perspective on how AI tool use raises accountability questions, see our analysis of legal liability when AI systems cause harm.

Frequently Asked Questions

Must lawyers disclose when they use AI for eDiscovery?

Disclosure requirements vary by jurisdiction and by individual court standing orders. Several federal courts have issued standing orders requiring affirmative disclosure of AI use in document review. Even absent a specific rule, duty of candor obligations and the cooperative discovery norms in many courts mean parties should be prepared to describe their review methodology when asked. The safest approach is to disclose proactively and document the methodology from the outset.

Can AI be used to make privilege determinations in discovery?

AI can flag documents that exhibit characteristics commonly associated with privilege — attorney names, legal advice language, work product indicators — but the final determination of privilege must be made by an attorney. Delegating privilege calls to an AI tool without attorney review would create significant professional responsibility exposure. AI accelerates privilege identification; it does not replace the attorney judgment required.

What is proportionality under Rule 26 and how does AI affect it?

Rule 26(b)(1) of the Federal Rules of Civil Procedure limits discovery to what is proportional to the needs of the case, considering factors including cost, burden, and the importance of the issues at stake. AI can support proportionality arguments in both directions: it can reduce the cost of processing large data sets, making broader collection proportionate; or it can demonstrate that a targeted, AI-assisted review identified all responsive materials without requiring exhaustive manual review. The key is a documented methodology that shows why the approach chosen was proportionate to the matter.

What are the risks of using AI in eDiscovery without proper quality controls?

Without documented quality controls, a party may be unable to defend the completeness or accuracy of its production if challenged. Courts have sanctioned parties for inadequate discovery methodology, and using AI tools without adequate validation and oversight compounds rather than reduces these risks. The efficiency gains from AI are only realized if they do not create vulnerability in the defensibility of the underlying production.