Skip to main content

Artificial intelligence has moved quickly from a novelty to a practical tool in litigation and internal investigations. Lawyers, investigators, compliance teams, and corporate legal departments now use AI-assisted systems to summarize documents, organize chronologies, search large data sets, identify patterns in communications, draft outlines, translate materials, and prepare first-pass analyses. The attraction is obvious. Litigation and investigations often involve enormous volumes of electronically stored information, compressed deadlines, and high expectations from courts, clients, regulators, boards, and business leaders. AI can help legal teams move faster, reduce duplication, and surface information that might otherwise remain buried. But the central professional obligation has not changed. Lawyers remain responsible for the accuracy of their work, the protection of privileged information, the reasonableness of discovery conduct, and the candor owed to courts and opposing parties. AI may assist the work, but it does not assume the lawyer’s duties.

Please note this blog post should be used for learning and illustrative purposes. It is not a substitute for consultation with an attorney with expertise in this area. If you have questions about a specific legal issue, we always recommend that you consult an attorney to discuss the particulars of your case.

The most important starting point is that AI is not a substitute for professional judgment. Generative AI tools can produce fluent, confident, and well-organized text, but fluency is not the same thing as accuracy. A document summary may omit a material qualification. A chronology may place events in the wrong sequence. A legal research response may cite a real case for a proposition it does not support, or worse, may invent authority that does not exist. A suggested investigative theme may be useful, but it may also reflect assumptions embedded in the prompt, the training data, or the selected document set. In litigation, those weaknesses can become costly because courts expect lawyers to make reasonable factual and legal inquiries before filing papers, certifying discovery responses, or advancing positions. In internal investigations, those weaknesses can distort witness preparation, board reporting, remediation decisions, and disclosures to regulators. AI is therefore best understood as an accelerator of legal work, not as an independent source of truth.

The need to verify legal citations has become the most public example of AI risk in litigation. The lesson from the early sanctions cases is not that lawyers may never use generative AI. The lesson is that lawyers may not outsource their Rule 11, candor, and competence obligations to a tool that can produce nonexistent or unreliable authority. In Mata v. Avianca, Inc., lawyers submitted filings that included fictitious judicial decisions generated by ChatGPT, and the court imposed sanctions after concluding that the lawyers had abandoned their responsibilities when they failed to verify the cases and continued to rely on them after serious questions were raised.¹ The reputational harm from that kind of error can exceed the monetary sanction. A court that discovers fake citations may lose trust not only in the brief, but in counsel’s broader presentation of the case. In high-stakes litigation, credibility is an asset, and AI misuse can spend that asset quickly.

The same concern appeared at the appellate level in Park v. Kim, where the Second Circuit addressed a brief that cited a nonexistent case generated through ChatGPT.² The court’s response underscored a basic principle: a lawyer who signs or submits a filing is representing that the legal authorities are real and that the cited propositions have been checked. It is not enough to say that a tool produced the language. Nor is it enough to review the output for grammar, tone, or general plausibility. Citation verification requires confirming that the case exists, that it has not been reversed or limited in a material way, that it comes from the cited court, that the quoted or paraphrased proposition actually appears in the source, and that the case supports the argument being made. AI can help generate research paths, but every cited case, statute, rule, regulation, quotation, and record reference must be independently verified before use.

A professional AI workflow for litigation should therefore separate idea generation from authority verification. It may be reasonable to ask an AI tool to suggest issues to research, identify possible standards, summarize a known case, or help organize a draft argument. But the lawyer should then move to authoritative research platforms, official court sources, or the underlying record to verify each proposition. In practical terms, the final brief should be treated as if no AI tool had participated at all. The attorney of record must be able to defend every citation, every factual assertion, and every characterization of the record. When a court asks where a proposition comes from, “the AI said so” is not an answer; it is an admission that the lawyer may not have completed the necessary professional review.

The same verification discipline applies to factual citations. AI tools are increasingly used to summarize deposition transcripts, exhibits, contracts, emails, spreadsheets, and chat messages. Those summaries may be useful for orientation, but they should not be treated as evidence. If a brief states that a witness admitted a fact, the cited transcript page must actually contain that testimony. If an investigation report says that an employee approved a payment on a certain date, the underlying document must support the statement. If a privilege log describes a communication as legal advice, the log entry must be based on an actual review of the communication and surrounding context, not merely on an AI-generated classification. The more persuasive and polished the AI output appears, the more important it becomes to confirm the source material.

Privilege presents a separate and often less visible risk. Litigation and internal investigations depend on attorney-client privilege and work-product protection. Those protections can be fragile when confidential information is transmitted outside the protected relationship or placed into tools whose retention, training, access, or security practices are unclear. ABA Formal Opinion 512 emphasizes that lawyers using generative AI must consider duties of competence, confidentiality, communication, supervision, meritorious claims, candor, and reasonable fees. ³ That guidance reflects the larger point that AI use is not ethically neutral. A lawyer who enters privileged witness interview notes, legal strategy, settlement assessments, trade secrets, personal data, or internal investigation findings into an external AI platform may create unnecessary confidentiality and waiver risk unless the tool, the contract, and the workflow have been vetted.

In internal investigations, privilege concerns deserve special attention because investigations often involve sensitive facts, multiple stakeholders, and uncertain future audiences. A company may investigate allegations of harassment, fraud, cybersecurity incidents, accounting issues, bribery, conflicts of interest, trade-secret theft, or regulatory violations. Counsel may need to collect documents, interview witnesses, brief management, report to a board committee, interact with auditors, and potentially make disclosures to regulators or law enforcement. AI tools can help organize the work, but they can also blur the boundary between legal advice, business advice, compliance operations, and public-relations messaging. If a tool is used to generate interview outlines, summarize witness statements, compare accounts, or draft findings, the investigation team should preserve the legal purpose of the work and document the role of counsel. The privilege analysis will depend on the facts, and AI should not be allowed to obscure who requested the work, why it was performed, who had access to it, and how the information was used.

A sound privilege protocol should address the type of AI tool being used before privileged or confidential information is entered. Some tools are public consumer products, some are enterprise systems with contractual confidentiality commitments, some are hosted within a client-controlled environment, and some are embedded in eDiscovery or document management platforms. Those distinctions matter. A public tool that uses prompts to improve models presents different risks from a private, contractually controlled legal technology platform. Even in a secure environment, teams should consider data minimization. The tool should receive only the information necessary for the task, and sensitive identifiers should be removed where feasible. Access controls should be limited to the investigation or litigation team. Prompt histories, output histories, audit logs, and exported reports should be managed as potential work product or privileged material when appropriate. The team should also decide whether prompts and outputs are being retained, where they are stored, and whether they may become discoverable.

Federal Rule of Evidence 502 remains important in this environment because inadvertent production of privileged material is a recurring risk in large-scale discovery.⁴ AI-assisted review may reduce some risks by identifying potentially privileged documents, but it can also create overconfidence. A model may miss privileged communications that use unusual language, involve non-lawyer intermediaries, or appear in attachments, comments, chat threads, or collaboration platforms. Rule 502(d) orders are often valuable because they can provide protection against waiver from inadvertent disclosures in federal litigation, but a protective order is not a substitute for a reasonable privilege review process. The better approach is to combine negotiated non-waiver protections with careful tool selection, defensible review protocols, quality control, and human oversight.

eDiscovery is one of the areas where AI has the longest track record, especially through technology-assisted review, predictive coding, clustering, email threading, near-duplicate detection, and continuous active learning. The Sedona Conference’s TAR materials reflect the reality that technology-assisted review is no longer exotic; it is part of modern discovery practice when used in a defensible manner.⁵ The legal question is rarely whether technology may be used. The more important question is whether the process is reasonable, proportional, validated, and appropriately documented. Courts and parties generally care less about the label placed on the tool and more about whether the producing party used a defensible method to identify, preserve, review, and produce responsive nonprivileged information.

The proportionality standard in Federal Rule of Civil Procedure 26 is central to AI-assisted discovery.⁴ Litigation discovery is not supposed to be a search for every possible document at any cost. It is limited to nonprivileged matter that is relevant to claims or defenses and proportional to the needs of the case. AI tools can support proportionality by helping parties understand data volumes, prioritize likely relevant materials, reduce duplicative review, and focus discovery on the sources most likely to matter. But proportionality also requires transparency and reasonableness. A party should be prepared to explain why it selected certain custodians, date ranges, data sources, search terms, review workflows, or TAR protocols. AI may make those decisions more efficient, but it does not eliminate the obligation to make them thoughtfully.

Preservation is another area where AI creates both opportunity and risk. Legal holds must be implemented when litigation is reasonably anticipated, and those holds increasingly need to address modern data sources such as messaging platforms, mobile devices, collaboration tools, ephemeral communications, shared drives, cloud storage, project management systems, and structured databases. AI can help map information sources, identify custodians, and detect communication patterns, but it can also create new data that must be understood. Prompts, outputs, summaries, model-generated chronologies, review tags, confidence scores, audit trails, and investigation dashboards may themselves become relevant depending on the dispute. Before deploying AI in a matter, counsel should decide what will be retained, what will be deleted in the ordinary course, what will be treated as work product, and what might be subject to a litigation hold.

Sanctions risk in eDiscovery often arises from unreasonable preservation failures, incomplete searches, inaccurate certifications, or misleading discovery responses. Federal Rule of Civil Procedure 37(e) addresses failures to preserve electronically stored information and provides a framework for remedies and sanctions when ESI that should have been preserved is lost because a party failed to take reasonable steps.⁴ AI can help prevent discovery failures, but it can also become part of the failure if legal teams rely on it blindly. For example, a party that uses an AI tool to identify responsive documents but performs no validation may struggle to defend the process if major gaps appear later. A party that uses an automated privilege classifier without quality control may face disputes over waiver or claw back. A party that certifies discovery responses without understanding the technology behind the search may run into Rule 26(g) concerns. The safest practice is to treat AI-assisted discovery as a supervised process that requires documentation, testing, sampling, and escalation of anomalies.

Rule 26(g) is especially important because it requires that discovery responses and objections be signed after a reasonable inquiry.⁴ In the AI context, that means counsel should understand enough about the tools and workflow to make the certification honestly. The lawyer need not personally code every document or understand every mathematical detail of a machine-learning model, but the lawyer must understand the process well enough to evaluate whether it is reasonable for the matter. That includes knowing what data was collected, what was excluded, how the review population was created, how the model or search process was trained or configured, what quality-control measures were used, how privilege was handled, and what limitations remain. A lawyer who cannot answer those questions may not be ready to certify the response.

Internal investigations require a similar discipline, even when no formal discovery request is pending. Investigation findings often become the foundation for employment decisions, regulatory disclosures, board actions, remediation plans, insurance notices, public statements, and litigation strategy. AI-generated summaries can be valuable, but the investigation team should not let them replace witness assessment or evidence evaluation. Witness credibility often turns on nuance, hesitation, context, motive, opportunity, and corroboration. A transcript summary may miss those features. A sentiment analysis tool may overstate what can reliably be inferred from tone or word choice. A pattern-detection tool may identify correlations that are not meaningful. In a serious investigation, AI should support the investigator’s analysis, not flatten the factual record into an apparently simple answer.

Bias and fairness concerns also matter. AI tools may reflect limitations in training data, design choices, or user prompts. In employment investigations, for example, a tool that summarizes complaints, ranks witness importance, or groups communications by topic may inadvertently amplify assumptions about role, seniority, language, gender, race, disability, nationality, or communication style. Even when the tool does not expressly consider protected characteristics, proxy variables may influence outputs. The legal team should therefore avoid treating AI-generated prioritization as neutral merely because it appears technical. Human review remains necessary, especially when investigation results may affect discipline, termination, reporting obligations, or reputational consequences.

The use of AI in witness preparation and interviews should be handled carefully. It may be useful to ask an AI tool to generate a draft interview outline based on known issues, relevant policies, and a verified chronology. It may also be useful to identify topics that should not be overlooked. But the final interview plan should be lawyer-directed and tailored to the witness. Overreliance on AI-generated questions can lead to generic interviews, missed follow-up questions, or undue emphasis on themes that the tool inferred from incomplete information. After the interview, AI can help organize notes or compare testimony to documents, but the lawyer should verify the summary against the actual notes, transcript, or recording if one exists. Investigation integrity depends on accurate capture of what was asked, what was answered, what was not answered, and what remains unresolved.

Confidentiality is also a client-communication issue. Depending on the matter, the client may need to understand whether AI tools are being used, what categories of information will be processed, what safeguards are in place, and whether the use of those tools affects cost, risk, or strategy. ABA Formal Opinion 512 recognizes that lawyers must consider communication obligations when using generative
AI. ³ In many routine situations, a client may not need a detailed explanation of every technology used in a law practice. But where the tool will process highly sensitive information, materially affect the work product, introduce unusual risks, or substitute for tasks the client expects a lawyer to perform, informed communication becomes more important. Transparency can also help avoid later disputes over billing, confidentiality, and quality control.

Billing practices deserve attention because AI can change the time required to perform legal tasks. A lawyer may use AI to draft the first version of a memo, organize deposition topics, or summarize a production set. That efficiency may benefit the client, but lawyers should not charge for time not actually spent or bill AI-assisted work as if it were performed manually if that would make the fee unreasonable. At the same time, the use of AI does not eliminate the value of legal judgment, supervision, verification, and strategic analysis. The ethical issue is not whether AI was used; it is whether the fee is reasonable, the work was competently performed, and the client was not misled about the nature of the services.

Court rules and judge-specific standing orders add another layer of risk. Since the first widely publicized AI citation sanctions, many courts and judges have considered or adopted requirements addressing AI-generated filings. Some require disclosure of AI use, some require certification that citations and legal content have been verified by a human, and some rely on existing rules rather than AI-specific mandates. The Fifth Circuit considered but ultimately did not adopt a special AI certification rule, which illustrates the unsettled and evolving nature of court responses. The practical lesson is that lawyers should check the rules of the jurisdiction, the local court, and the assigned judge before filing. Even where no AI-specific rule exists, the traditional duties of candor, competence, and reasonable inquiry still apply.

A defensible AI governance program for litigation and investigations should be practical rather than theatrical. Policies that simply prohibit all AI use may be unrealistic and may drive experimentation into unsupervised channels. Policies that allow unrestricted use are equally dangerous. The better model is controlled adoption. Legal teams should classify tools by approved use, limit sensitive data to approved environments, require verification of legal and factual citations, preserve privilege protocols, document eDiscovery workflows, train lawyers and staff, and create escalation procedures for unusual outputs or high-risk uses. The goal is not to remove every risk. The goal is to make AI use intentional, supervised, and defensible.

Training is particularly important because many AI errors are user errors. Lawyers and staff need to understand that prompts matter, that outputs can be incomplete or false, that confidential information should not be entered into unapproved systems, and that AI-generated work requires review. They should also learn how to use AI effectively. A vague prompt may produce a vague answer. A prompt that asks for a conclusion without providing verified source material may invite fabrication. A prompt that asks a tool to summarize only provided documents is safer than one that asks the tool to supply legal authorities from memory. A prompt that requires the tool to identify uncertainty, quote source passages, or provide document references may improve review, but those references still must be checked.

Documentation should be calibrated to the matter. Not every AI-assisted drafting task requires a formal memo to the file. But high-risk uses should be documented. In eDiscovery, documentation may include collection decisions, search methodology, TAR protocol, validation results, sampling approach, privilege review procedures, and quality-control outcomes. In internal investigations, documentation may include tool approvals, data sources, access limits, confidentiality protections, human review steps, and the basis for final findings. If the process is later challenged, contemporaneous documentation will be more persuasive than after-the-fact reconstruction.

The legal profession should avoid both panic and complacency. AI is neither a forbidden shortcut nor a magic solution. Used responsibly, it can improve litigation preparation, reduce review burden, make investigations more organized, and help lawyers see patterns in complex records. Used carelessly, it can generate fake citations, expose privileged information, distort factual findings, and increase sanctions risk. The dividing line is not the technology itself. The dividing line is whether lawyers maintain control over the work.

The most defensible approach is simple in principle, even if demanding in practice. Use AI where it improves efficiency, organization, and insight. Do not use it as an unverified authority. Protect privileged and confidential information before entering it into any system. Treat eDiscovery technology as part of a supervised and validated legal process. Confirm legal citations, factual assertions, and record references against original sources. Preserve the lawyer’s role as the professional who exercises judgment, communicates with the client, and stands behind the work. In litigation and internal investigations, AI can be a powerful assistant, but responsibility remains human.

Contact Tishkoff

Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).

Sources

1- Mata v. Avianca, Inc., 678 F. Supp. 3d 443, United States District Court for the Southern District of New York, 2023. https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2022cv01461/575368/54/

2- Park v. Kim, 91 F.4th 610, United States Court of Appeals for the Second Circuit, 2024. https://nce.fd.org/sites/nce/files/seminar-docs/artificial-intelligence-and-criminal-defense-practice/Park%20v%20Kim_0.pdf

3- American Bar Association Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, “Generative Artificial Intelligence Tools,” July 29, 2024. https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-october/aba-ethics-opinion-generative-ai-offers-useful-framework/

4- Federal Rule of Civil Procedure 26; Federal Rule of Civil Procedure 37(e); Federal Rule of Evidence 502. www.uscourts.gov/sites/default/files/2025-02/federal-rules-of-civil-procedure-dec-1-2024_0.pdf

5- The Sedona Conference, TAR Case Law Primer, Second Edition, 2023. https://www.thesedonaconference.org/publication/TAR_Case_Law_Primer

This publication is for general informational purposes and does not constitute legal advice. Reading it does not create an attorney-client relationship. You should consult counsel for advice on your specific circumstances.