The EU AI Act's enforcement is now live, and legal departments are scrambling to classify their eDiscovery workflows. While most teams understand the need for compliance, many misunderstand how to achieve it.
The Act regulates not just the technology you use, but the role your organization plays in relation to that technology. Two organizations can deploy the same AI tool and face entirely different obligations. One might be a provider, the other a deployer, and this distinction determines your compliance burden, documentation requirements, and liability exposure.
Here's why teams keep getting this wrong, and how to fix it.
Why These Mistakes Keep Happening
Legal departments often treat the EU AI Act like a technology checklist when it's actually a role-definition exercise. You're asking "what AI do we use?" when you should be asking "what are we doing with this AI, and does that change our regulatory status?"
The confusion stems from three sources. First, the Act's provider-deployer framework doesn't map cleanly onto traditional vendor-client relationships. Second, eDiscovery workflows often involve customization, integration, and workflow automation that can shift your classification without anyone realizing it. Third, legal teams defer to IT or procurement to "handle compliance" when the classification decision requires legal judgment about workflow ownership and control.
The result: you misclassify your role, underestimate your obligations, and discover the gap during an audit or regulatory inquiry.
Mistake 1: Assuming Vendor Contracts Define Your Role
Why it happens: Your team assumes that if you licensed the AI tool from a vendor, they're the provider and you're just a user. The contract says they're responsible for the technology, so you treat compliance as their problem.
The consequence: Customization changes the equation. If you've integrated the AI tool into proprietary workflows, trained it on your data, or built decision logic around its outputs, you may have crossed into provider territory without realizing it. The EU AI Act looks at functional control, not contractual labels.
The fix: Map every eDiscovery AI workflow to these questions: Did we customize the model? Did we integrate it with other systems in a way that creates new functionality? Do we control the decision-making logic that uses the AI output? If yes to any of these, you need a legal review of your classification, not just a vendor assurance letter.
Mistake 2: Treating All AI Tools the Same
Why it happens: Your team groups all AI-powered eDiscovery tools into one compliance bucket because they all use machine learning. Technology-assisted review, predictive coding, auto-classification, and generative summarization all get the same treatment.
The consequence: The EU AI Act uses a risk-based framework. A tool that auto-tags documents for review carries different obligations than one that generates legal advice or makes custodian decisions. If you classify everything as "limited risk" because most eDiscovery tools are low-stakes, you miss the high-risk workflows that trigger stricter requirements.
The fix: Classify each workflow individually based on its function and impact. Ask: What decision does this AI enable? Who relies on that decision? What's the consequence if it's wrong? A tool that flags potentially privileged documents for attorney review is not the same as a tool that auto-applies Legal Hold to custodians based on predicted relevance. Document your risk assessment for each workflow, and revisit it when you change how the tool is used.
Mistake 3: Ignoring Generative AI Experiments
Why it happens: Your team is testing generative AI for deposition prep, contract analysis, or privilege log drafting. These are "pilot projects" or "productivity experiments," so no one flags them for compliance review. They're not part of your formal eDiscovery workflow yet.
The consequence: Generative AI tools, especially those that produce legal work product or influence litigation strategy, can trigger provider obligations if you're customizing prompts, fine-tuning outputs, or embedding them into repeatable workflows. By the time the pilot becomes standard practice, you're already non-compliant.
The fix: Treat every generative AI experiment as a compliance event from day one. Before you run the pilot, classify the tool's role, document the workflow, and determine whether your use constitutes deployment or provision. If you're building custom prompt libraries, training the model on your matter data, or automating its outputs into work product, you're not just experimenting; you're deploying an AI system that needs classification.
Mistake 4: Failing to Document the "Why" Behind Classification Decisions
Why it happens: Your team classifies a workflow as "deployer" or "provider" based on a quick assessment, then moves on. No one writes down the reasoning, the factors considered, or the edge cases that almost changed the decision.
The consequence: When a regulator or auditor asks why you classified a workflow the way you did, you have no documentation. You can't reconstruct the decision, you can't show that it was reasonable, and you can't demonstrate that you revisited it when circumstances changed. The lack of documentation turns a defensible decision into an indefensible gap.
The fix: Create a classification record for every AI-powered eDiscovery workflow. Include: the tool name, the vendor, the workflow description, the classification decision (provider or deployer), the factors that drove the decision, the date of the decision, and the next review date. Store this in your Records and Information Management system as part of your compliance documentation. When you update the workflow, update the classification record.
Mistake 5: Assuming U.S.-Only Operations Exempt You
Why it happens: Your organization is U.S.-based, your litigation is in U.S. courts, and your data is in U.S. data centers. You assume the EU AI Act doesn't apply because you're not operating in Europe.
The consequence: The Act has extraterritorial reach. If your eDiscovery workflow processes data from EU residents, supports litigation involving EU parties, or uses AI systems that were trained on EU data, you may fall under the Act's jurisdiction. Cross-border discovery, multinational litigation, and cloud-hosted AI tools all create compliance exposure.
The fix: Audit your eDiscovery workflows for EU touchpoints. Ask: Do we process personal data of EU residents? Do our AI tools operate in or serve the EU market? Do we support matters with EU parties or EU regulatory exposure? If yes, consult with EU-qualified counsel to determine your obligations. Don't wait until you receive a regulatory inquiry from a European data protection authority.
Mistake 6: Letting IT or Procurement Own the Classification Decision
Why it happens: Your organization treats AI compliance as a technology issue, so IT evaluates the tools and procurement negotiates the vendor contracts. Legal gets looped in only when someone needs a signature.
The consequence: IT can tell you what the technology does. Procurement can tell you what the contract says. Neither can tell you whether your use of the technology makes you a provider or deployer under the Act. That's a legal judgment that requires understanding both the regulatory framework and the operational workflow. When IT or procurement makes the call, they optimize for the wrong variables.
The fix: Legal must own the classification decision. IT and procurement provide input, but the final determination requires legal analysis of the workflow's function, the organization's control over the AI system, and the compliance obligations that follow. Build a cross-functional review process where IT describes the technology, procurement presents the contract terms, and legal makes the classification call. Document who made the decision and why.
Prevention Checklist
Use this checklist before deploying any AI tool in your eDiscovery workflow:
- Identify the AI tool's function and the decision it enables
- Determine whether the tool is customized, integrated, or used as-is
- Classify the tool's risk level under the EU AI Act's framework
- Assess whether your organization is a provider, deployer, or both
- Document the classification decision and the factors that drove it
- Confirm whether the workflow has EU touchpoints or extraterritorial reach
- Assign legal ownership of the classification decision
- Set a review date to revisit the classification if the workflow changes
- Store the classification record in your Records and Information Management system
- Brief the eDiscovery team on their compliance obligations under the classification
Misclassification isn't a paperwork problem. It's a liability that compounds every time you use the tool. Get the classification right before you scale the workflow.



