Executive Summary
eDiscovery is undergoing a fundamental transformation, driven by two converging trends: the rapid adoption of generative AI in review workflows, and the rapid shift from email to chat-based communication as the primary business record. While both offer clear efficiency gains, they introduce new risks that cannot be managed through technology alone.
Generative AI, particularly large language models (LLMs), produces variable outputs and may generate inaccurate or unsupported content if not properly controlled. Its effectiveness is also limited by the quality and type of underlying data, with non-textual and numeric-heavy materials often falling outside reliable AI analysis. To ensure defensible outcomes, organisations must implement validation, human oversight, AI review methodologies, and clear governance aligned with evolving legal and regulatory expectations.
At the same time, chat-based data in Asia is highly fragmented across platforms, devices, and jurisdictions, frequently within Bring Your Own Device (BYOD) environments. Rapid application updates, strong encryption, and frequent device replacement further undermine assumptions of completeness. In this landscape, defensible eDiscovery depends less on speed or scale, and more on sound judgment, transparent methodologies, and governance frameworks that acknowledge practical constraints while managing legal risk.
Making AI Defensible
Artificial Intelligence (AI) technologies are undeniably powerful, but they come with inherent risks that organisations must understand and manage. Recognising these limitations and implementing robust controls is essential to maximising the benefits of AI deployment.
For generative AI powered by LLMs ,variability in responses is a common characteristic. Even when posed with the same question, AI outputs can differ in wording, factual details, and supporting rationale. In eDiscovery, this means that relevancy or privilege review predictions, explanations, and related descriptions may vary slightly each time the model processes the same input.
Prompt design is another important part of defensibility. Prompts are not simply user inputs; they shape how the model interprets the review task, applies criteria, and explains its outputs. For AI-assisted review to be reliable, prompts and related instructions should be tested, controlled, and documented as part of the methodology, particularly where they influence relevancy, privilege, issue coding, or summarisation decisions.
Another critical concern is AI hallucination – instances where AI generates inaccurate or fabricated information not grounded in the source material. This can include invented facts or distorted details that do not reflect the actual content of the documents being analysed.
To address these challenges, robust validation mechanisms, including statistical validation workflows, prompt testing and version control, continuous input refinement, and human oversight are key to maintaining the consistency and reliability of AI predictions. These controls help ensure explainable and defensible outcomes.
It is also important to note that AI for eDiscovery review currently works only with the text available within a document; metadata, images, and other non-textual elements are typically excluded from consideration. Documents that are predominantly numeric, such as Excel spreadsheets, may provide limited value for generative AI predictions. For images or scanned documents, it is critical to ensure that high-quality optical character recognition (OCR) text is generated prior to AI processing.
Beyond technical considerations, the legal and regulatory landscape for AI is evolving rapidly. The question is no longer whether AI should be used in eDiscovery, but how it can be explained, validated, and defended if challenged. Organisations should proactively incorporate robust AI governance frameworks into their strategies to ensure compliance with data privacy requirements, emerging laws, applicable standards, and regulatory expectations.
Chat Data Changes Everything
Across Asia, chat-based communication has become an everyday business tool rather than an informal alternative. Organisations now operate in environments where conversations routinely take place across multiple messaging applications – WhatsApp, WeChat, LINE, Telegram, KakaoTalk, Signal, and others – often on the same device and for different business contexts. This diversity is further complicated by the widespread use of BYOD alongside corporate-issued devices. While corporate devices are typically subject to clear policy controls, Mobile Device Management (MDM) oversight, and defined chains of custody, BYOD environments introduce immediate challenges around scope, consent, privacy, and proportionality. From an eDiscovery perspective, there is rarely a single, consolidated dataset to collect; instead, relevant chat data is distributed across platforms, devices, and accounts, each governed by different technical, legal, and jurisdictional constraints. This complexity is driven by several factors, including:
- parallel use of multiple messaging platforms across markets and counterparties
- intermingling of personal and business communications on BYOD devices
- platform-specific data structures, encryption, and retention behaviour
- cross-border storage and access considerations
These realities mean that chat data collection in Asia is fundamentally a governance exercise, not simply a technical one.
The situation is further complicated by the pace at which both messaging applications and mobile devices evolve. Platforms update frequently, introducing features such as disappearing messages and multi-device synchronisation that materially affect what data exists and how long it persists. Forensic tools, even established ones, do not always keep pace, resulting in periods of partial support or inconsistent results. At the same time, modern usage patterns – regular device upgrades, trade-ins, and resets – erode continuity, particularly in BYOD environments where older devices may never enter organisational custody. As a result, mobile devices increasingly function as transient access points rather than stable evidence repositories. For legal and eDiscovery teams, the practical implication is clear: success lies not in attempting to keep pace with every platform or device change, but in establishing defensible collection strategies that acknowledge these constraints, document them clearly, and align with broader organisational governance.
Questions to Ask Early
A more defensible approach begins before collection or review starts. Useful questions include:
- Which communication channels are likely to contain relevant evidence?
- Are those communications held on corporate devices, BYOD devices, cloud accounts, or multiple linked devices?
- What privacy, consent, employment, secrecy, or cross-border restrictions apply?
- What data may be unavailable because of encryption, deletion, retention settings, application limitations, or device replacement?
- If technology assisted review is used, what is it being used for, what checks are in place, and who is responsible for the final judgment?
- What prompts, instructions, or model settings will be used, and how will they be tested, approved, and documented?
- What records will be retained to demonstrate how AI-assisted decisions were reached?
- How will assumptions, exceptions, limitations, and quality control steps be documented?
These questions help shift eDiscovery from a reactive data processing exercise to a more proactive risk management process. The objective is not to create unnecessary processes, but to make sure that key assumptions, limitations, and decisions are visible before they become points of challenge.
Conclusion
Modern digital evidence work is rarely perfect. The data may be incomplete, the systems may be fragmented, and the practical constraints may be real. What matters is whether the approach is reasonable, deliberate, and capable of being explained. As communications continue to move across chat platforms, mobile devices, cloud accounts, and personal environments, defensibility will depend on good judgment supported by clear process, not process for its own sake.