Skip to content
OnPrem

AI and legal discovery — using it without breaching your obligations

The implied undertaking is a duty to the court, not a courtesy to the other side. AI review has to be organised around it.

Published 26 July 2026

Document review is the single most time-intensive workflow in litigation practice, and it is one of the most obvious places AI can meaningfully help. It is also the workflow where the confidentiality and use-of-documents obligations are strictest, most explicit, and most likely to produce a genuine professional problem if handled poorly.

This is a practical article about doing AI-assisted review well.

The implied undertaking

The Harman undertaking — often called the implied undertaking or the Hearne v Street undertaking in Australia — restricts the use of documents produced in discovery to the proceeding in which they were produced. The undertaking is owed to the court, not to the disclosing party, and its breach is a contempt.

The undertaking prohibits, in broad terms:

  • Using the documents for any purpose other than the proceeding
  • Disclosing them to persons unrelated to the proceeding
  • Retaining them beyond the proceeding without leave

Australian courts have consistently treated the undertaking seriously. It applies to your own client’s documents produced by the other side, to the other side’s documents produced to you, and to third-party documents produced under subpoena.

Where AI-assisted review interacts with this

The straightforward question: does using a public AI service to summarise or search discovered documents breach the implied undertaking?

The honest answer is that it is legally uncertain in a way you do not want to test. What is beyond doubt is that:

  • Transmitting discovered documents to a third-party AI service is a use of those documents
  • It is not a use directly incidental to the conduct of the proceeding
  • It is a disclosure to a person unrelated to the proceeding (the AI provider)
  • It is a retention of the documents by that third party, potentially indefinitely, and outside your control

Whether the specific circumstances would be found to be a technical breach is fact-dependent. Whether they would be found by a court to be undesirable is much less uncertain.

The safe assumption is that transmitting discovered documents to a cloud AI service is, at best, an argument you would rather not have, and at worst a formal breach that would be professionally serious to defend.

The rules of court

Beyond the implied undertaking, the various state and federal rules of court impose specific obligations around document handling in discovery.

Court-ordered protective regimes are becoming more common — particularly in complex commercial litigation and in matters involving trade secrets, personal or health information, or classified material. Where a protective order exists, it will typically:

  • Restrict which persons may access the documents
  • Require documents to be stored in specific ways
  • Prohibit copies, transmission or use beyond the specified scope
  • Include specific undertakings from each person granted access

An AI service is a person for these purposes — or at any rate, transmitting the documents to it makes them accessible to persons not covered by the order. If a protective regime is in place, cloud AI use is not just risky; it is straightforwardly outside the terms of the order.

The client confidentiality overlay

Discovered documents produced by your own client remain subject to your professional duty of confidentiality. Discovered documents produced by another party may be subject to their confidentiality obligations, which your client has agreed to respect by accepting them under the discovery framework.

Neither obligation is diminished by AI use. If anything, the specificity of AI use makes the obligation sharper — a lawyer casually reading a document is a use contemplated by the discovery framework; a lawyer transmitting the document to a third-party service for automated processing is not.

What AI-assisted review can properly look like

The prohibition is not on using AI — it is on using AI in a way that transmits the documents outside your control. There are several patterns that avoid the transmission problem and preserve the productivity benefit.

On-premise AI. The documents stay on your infrastructure. The AI runs on your infrastructure. No transmission, no third-party disclosure, no implied undertaking issue. This is the cleanest architectural answer and it is the pattern this firm exists to build.

Purpose-built e-discovery platforms with on-premise or in-tenancy AI. Relativity, Everlaw, DISCO and similar platforms have added AI capabilities. Where properly configured — particularly with in-tenancy or private model options — these can be an acceptable answer, subject to the platform’s specific data handling arrangements. Check where the AI actually runs and whether the platform’s arrangements have been specifically assessed for your matter.

In-house LLMs on cloud infrastructure your firm controls. Some larger firms are running open models on their own cloud tenancy (typically AWS or Azure). This is technically more complex than on-premise and has its own security considerations, but it can be an acceptable middle path for firms with the technical capability to maintain it properly.

What it should not look like

Pasting excerpts of discovered documents into ChatGPT (any tier), Claude, Gemini or similar to summarise, categorise, or query, is the pattern to avoid. Enterprise tiers of these products help with the general privacy analysis; they do not help with the specific implied-undertaking problem.

The practical review workflow

If you have on-premise AI available for review, the practical workflow looks something like this.

Ingestion. Documents are loaded into the review system, which sits on your firm’s infrastructure. Metadata is extracted; deduplication and near-deduplication is performed automatically. This alone reduces review volume significantly.

Categorisation. AI-assisted categorisation into responsive/non-responsive, or into thematic groups, is applied. Each categorisation is reviewable — the AI is producing suggestions for review, not final calls.

Privilege review. AI can flag likely privileged documents for closer review by lawyers. This does not replace lawyer review; it directs it.

Summarisation. Large document sets can be summarised at various levels — per-document, per-custodian, per-theme — with the underlying documents remaining accessible. This turns the “read everything to work out what matters” problem into a “read the summaries, then dig into what matters” problem.

Chronology and timeline construction. AI can extract dates, actors and events across the document set to construct a working chronology, which lawyers refine.

Retrieval-augmented querying. Once the corpus is loaded, natural-language queries against it become possible. “Show me every reference to the September 2023 meeting where the pricing model was discussed” is a valid question, answered without transmitting anything anywhere.

Each of these workflows compounds the value proposition of AI-assisted review in a way that pasting-excerpts-into-ChatGPT never can, precisely because it works with the whole corpus rather than snippets.

The talking point that matters at partner level

The reason AI-assisted review is worth solving properly, rather than banning outright, is competitive.

Firms that do this well can absorb larger discovery volumes at lower cost with higher quality first-pass review. They can offer clients more comprehensive review in the same time budget. In a market where clients increasingly resist paying for junior lawyers reading documents, the firms with proper AI-assisted review will win the work.

The firms that solve it via public cloud AI will do so at professional risk they have not accounted for. The firms that ban AI outright will lose the work to firms that solve it. The firms that solve it via appropriate infrastructure — on-premise or properly-scoped in-tenancy — will be the ones that navigate the transition well.

The infrastructure decision is not a technology decision. It is a strategy decision for the practice.

This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.

Want to know what your firm is actually exposing?

We will walk through where confidential material is most likely leaving, and tell you plainly whether an on-premise system is worth it for a firm your size.

Request an assessment