The Direct Answer
Litigators should treat AI-assisted discovery as a managed evidence process, not as an automatic privilege waiver or a substitute for counsel. A defensible protocol starts when litigation is reasonably anticipated, defines the information that must be preserved, controls which systems may search or summarize it, and requires a human decision whenever a model could affect production, privilege, or settlement. By September 24, 2026, the most defensible position is that ordinary rules still govern: Rule 26 requires proportional disclosure, Rule 37(e) addresses lost electronic information, and a claim of privilege or inadvertent disclosure must be evaluated under applicable law rather than inferred from the word “AI.”
Also worth reading: What are the AI discovery disclosure rules courts are enforcing in 2026, and what do litigators need to disclose about their use of generative AI? · How Do Legal Teams Maintain Compliance When Deploying Agentic E-Discovery Tools? · How Are Autonomous Multi-Agent Systems Reshaping Legal E-Discovery and Document Drafting in 2026?
The protocol should cover prompts, outputs, embeddings, logs, and cached responses because those artifacts can reveal facts, sources, attorney mental impressions, or security-sensitive information. It should also establish approved models, permitted data, retention periods, audit records, validation thresholds, and escalation paths. Speed is a legitimate benefit, but it is not a defense to an erroneous designation, missed document, or disclosure outside the court’s order. The practical objective is not zero human involvement; it is narrower, documented human involvement at the points where legal judgment and machine error intersect.
Why Conventional Discovery Rules Still Control Generative AI
Generative AI changes the volume, speed, and form of discovery, but it does not suspend the Federal Rules of Civil Procedure. Under Rule 26(b)(1), a party must provide only information relevant to a claim or defense and proportional to the needs of the case. Rule 26(b)(2)(B) can excuse discovery of information not reasonably accessible because of undue burden or cost, although that protection is not a blanket exemption for all unstructured or high-volume data. AI may make millions of documents searchable in less time, but the court can still require access when the technology, burden, and requested information justify it.
Rule 34 generally requires production within 14 days after a request, subject to the rules governingESI and objections. Rule 37(e) addresses the loss of ESI that should have been preserved in anticipation of litigation when reasonable preservation steps were not taken and the information cannot be restored or replaced. An AI system that creates ephemeral prompts, then deletes them while producing other records, may create a preservation problem even if the original source documents remain available. A responsible protocol therefore treats each source, transformation, and output as part of the evidentiary record.
The distinction between assisted technology and autonomous decision-making matters as well. Predictive coding, OCR, deduplication, and machine-learning review have long operated within the same rules, while newer systems can summarize email threads, rank responsiveness, propose privilege calls, and generate deposition exhibits. Harvey’s discussion of AI-assisted document review reflects the commercial benefit of faster review, but the associated commentary from JD Supra correctly emphasizes that established eDiscovery fundamentals remain relevant. AI can accelerate review while leaving counsel responsible for defensibility, confidentiality, and the content of every production.
Privilege, Prompts, and Discoverable AI Conversations
AI prompts are not uniformly privileged and are not uniformly discoverable. A prompt may contain a factual request, attorney mental impressions, legal strategy, or a third party’s confidential information, and those categories receive different treatment. Communications with an AI service may not be privileged merely because a lawyer entered them, especially when the service is configured not to retain content or when ordinary users could pose similar queries. Conversely, a prompt is not automatically discoverable merely because it was sent to a computer; the legal analysis still depends on the person, purpose, contents, and circumstances of the communication.
A 2026 Orrick analysis reported in the research material, titled “Court Rules AI Conversations Are Not Privileged,” discusses United States v. Heppner and its consequences for organizations using AI. Counsel should read the actual decision and procedural posture before treating the report as a universal rule, because the holding, jurisdiction, record, and specific treatment of confidentiality can control. Arnold & Porter’s analysis of AI prompts, privilege, and discovery similarly supports a fact-specific approach rather than a blanket waiver. A defensible response is to identify potentially privileged inputs, separate legal strategy from ordinary research, and document why a particular interaction should or should not be produced.
Privilege logging should distinguish the source document from the AI-generated summary. A summary can waive nothing by itself, but producing it may reveal privileged facts or invite arguments about the underlying prompt. Model outputs can also contain fabricated citations, unsupported statements, or altered quotations, which affects evidentiary use even if the output is not privileged. The protocol should require verification against the source before an AI response is used in a filing, expert report, settlement communication, or witness examination. A prompt or output should never be labeled privileged solely because a vendor markets the tool as confidential; the governing professional duties and court orders must be checked.
A Practical Protocol for AI-Assisted Review
The first operational step is to issue a litigation hold before routine deletion, summarization, or model training changes the evidentiary environment. Counsel should identify custodians, relevant time ranges, data sources, connected applications, and AI tools, with special attention to shared drives, messaging platforms, code repositories, and vendor portals. Where the organization cannot determine whether relevant information may be lost, it should suspend deletion for the affected systems until the scope is understood. A preservation notice should state that interactive tools, prompts, retrieved context, and outputs connected to the matter are within scope, not just traditional email and documents.
The second step is to map the processing environment and prohibit unapproved transfers. Organizations should record the model provider, deployment region, account configuration, retention setting, training policy, subprocessors, and whether prompts are used to improve a provider’s models. Litigation teams often need contractual assurances that data will not be retained or used for model training, but contractual language alone does not override applicable preservation duties. If sensitive information must be analyzed, a controlled environment with restricted access, encryption, documented deletion, and a reproducible audit trail is preferable to uploading files to a consumer-facing service.
The third step is to validate the system before relying on its results. Testing should use a representative sample, track precision and recall where appropriate, measure near-duplicate handling, and examine errors across custodians, languages, date ranges, and document types. There is no federal rule requiring a universal 95 percent accuracy rate or a one percent error ceiling. Instead, validation should be proportional to the case and should identify the consequences of false negatives, false positives, privilege errors, and hallucinated outputs. Counsel should also test whether citations generated by the model exist and whether quoted text appears in the retrieved source.
The fourth step is to preserve an audit record of what happened. That record should identify the model and version, prompt or configuration, source corpus, retrieval method, user, timestamp, output, and subsequent human edits. A defensible chain may require exporting chat histories and processing logs in a standard format, but teams should not assume that an interface’s export includes every backend artifact. Responses to interrogatories, objections, and requests for production should explain material uses of AI when they affect completeness, methodology, or the basis for a representation. Human approval should be mandatory before privilege determinations, merits positions, or production decisions are communicated to an opposing party or court.
Comparing AI Workflows and Conventional Alternatives
| Feature | AI-first review | Traditional assisted review | Managed service review |
|---|---|---|---|
| Main strength | Rapid search, summarization, and prioritization | Search, coding, OCR, and deduplication under lawyer control | Provider-managed processing, hosting, and review staffing |
| Human control | Requires role-based approval and audit logging | Substantial, but varying by platform | Defined through the service contract and case plan |
| Privilege exposure | Prompts, retrieved context, and outputs require classification | Source documents and coder decisions still require classification | Provider access and subprocessors require contractual and legal review |
| Cost pattern | Potentially high upfront platform, integration, and validation cost | Moderate technology and internal staffing cost | Often priced per collection, gigabyte, document, reviewer hour, or subscription |
| Best fit | Large, complex matters needing rapid issue retrieval | Matters with known custodians and established review criteria | Organizations lacking processing, hosting, or review capacity |
| Principal weakness | Opaque errors, vendor dependence, and prompt governance problems | Slower for large review populations and manually intensive coding | Less direct control, variable transparency, and dependence on provider staffing |
Managed services can be the best alternative for a small litigation team facing a sudden preservation obligation, particularly when it lacks secure processing capacity. The service agreement should still specify custodians and data sources, permitted AI uses, privilege reviewers, audit materials, deletion practices, subcontractors, incident notification, and the treatment of attorney communications. A provider’s statement that its platform is “enterprise grade” is not a substitute for reviewing the contract, architecture, access controls, and actual case configuration. Comparison should therefore be based on defensible process and total matter cost, not on a feature checklist.
Common Mistakes That Create New Litigation Risk
One common mistake is beginning a model review before collecting or preserving the underlying information. Search and summarization can make records appear complete while leaving gaps in message archives, application logs, or deleted drafts. Another mistake is failing to distinguish relevance from privilege, causing a model to rank a document highly because it contains legal terminology without confirming who created it or why. Teams also err by treating summaries as substitutes for source documents, which creates a poor record when a witness must authenticate a statement or opposing counsel disputes context.
A further error is assuming that cloud deployment automatically resolves privilege and confidentiality. The provider’s product design, contract, account settings, and jurisdiction all matter, and a single misconfigured account can expose an entire collection. Organizations should not use unredacted source documents merely because the model is hosted privately; outputs, telemetry, and vendor support access can remain separate risks. Courts have also shown increasing attention to expert AI use, with Arnold & Porter discussing a 2026 decision under Rule 26 in which an expert’s prompts were treated as fair game in the reported setting. That development makes reproducible queries and source verification more important, not less.
The final error is measuring performance with a small demonstration and applying it to every production population. A tool that performs well on clean, English-language email may fail on spreadsheets, image-only PDFs, foreign-language records, or mixed families of duplicates. Teams should test error types separately and revisit results when the corpus, model, or retrieval configuration changes. They should also preserve the original data and processing history so that another reviewer can reproduce the work without relying on the AI vendor.
When to Act and What AI E-Discovery May Cost
A team should act as soon as litigation is reasonably anticipated, a complaint or investigation creates a realistic prospect of claims, or a preservation notice is received. Waiting until a production deadline removes time needed to collect data, assess sources, obtain contractual protections, and test a system. For high-risk matters, the initial budget can be measured in days: define custodians, stop routine deletion, inventory AI accounts, secure chat histories, and decide whether a forensic collection is needed. The team should not train or fine-tune a model on case data merely because the deadline is approaching.
Illustrative 2026 pricing varies too much for a single universal figure, but several ranges help frame planning. Processing and hosting may cost roughly $5 to $50 per gigabyte per month, while managed technology licensing can run from several thousand dollars to tens of thousands of dollars per month. Ordinary document review commonly falls near $0.10 to $2 per document, while complex financial, technical, or multilingual review can reach several dollars per document. Private deployment, extensive integrations, and high-volume summarization can push total matter costs into six figures, even when the per-document price appears low.
The correct comparison is total cost per defensible output, including validation, privilege review, remediation, hosting, and expert explanation. A lower subscription fee may be more expensive if it requires manual reconstruction of deleted prompts, repeated search runs, or a supplemental review after an error. Buyers should ask for a written methodology, security documentation, uptime commitments, deletion certification, and an explanation of how model or vendor changes affect reproducibility. They should also confirm whether the quoted price includes data export, migration, audit logs, and assistance responding to a Rule 26 or Rule 37 dispute.
The Best Governance Model for 2026
The strongest approach combines ordinary eDiscovery discipline with controlled experimentation. Harvey, NetDocuments, DISCO, and other vendors are expanding AI features, while commentary from JD Supra, the National Law Review, K&L Gates, Arnold & Porter, and Orrick emphasizes that prompt handling, privilege, and disclosure remain contested. Those developments make a written protocol more valuable than a purchasing decision. The protocol should be matter-specific, reviewed by technology and litigation personnel, and updated when a court order, vendor change, or new case development affects the workflow.
The protocol should also distinguish three levels of AI use: search and retrieval, review assistance, and autonomous recommendation or action. Search and retrieval may have limited output risk, but review assistance still requires source validation, and autonomous recommendations require approval before they affect production or legal positions. This separation prevents a procurement decision from becoming an unexamined delegation of legal judgment. It also gives a court a clearer account of what the system did and what the lawyer did, which matters if a party must explain proportionality, loss, privilege, or the reliability of an expert’s work.
By September 24, 2026, AI can reduce the time needed to locate, summarize, and prioritize evidence, but it cannot decide whether a case is preserved, whether a communication is privileged, or whether an output is true. The defensible organization can show that it identified its sources, controlled its systems, tested its assumptions, recorded its decisions, and corrected errors. That record is more valuable than a dramatic claim of automation because it connects speed with the duties that courts and opposing parties already enforce.