After a period of stagnation in recent years, the discovery market is currently facing significant pressure to change. The integration of artificial intelligence and cloud-based technologies into workflows, and AI-generated content itself becoming the subject of investigations, are new phenomena that are impacting existing methods and analytical procedures in the areas of litigation, investigation, compliance, cybersecurity, and regulatory affairs. This raises questions such as: Which eDiscovery costs are still justified? Will agents soon replace eDiscovery teams? Is moving to the cloud the only option and who in the company makes this decision?
In cooperation with Deloitte, the Deutscher AnwaltSpiegel hosted a roundtable on 26 August 2026 at the F.A.Z. Tower in Frankfurt/Main to discuss the findings of a recent study with experts from corporations and corporate law firms.
The discussion was based on a Bilendi survey of 505 companies of all sizes and across all industries in Germany, Austria, and Switzerland (known as the “DACH” countries), which Deloitte conducted in 2025 – with the goal of repeating it annually in the future. Initial results for 2026 are already available and largely confirm the current state of affairs.
On the panel, Thomas Fritzsche, Head of Discovery & Data Management, and Dr. Klara Weiand, Head of Analytics & Innovation (both partners at Deloitte), discussed the findings with Dr. Martin Mozek, Director of Compliance at Samsung Electronics; Kaan Gürer, LL.M., Partner in the Antitrust & Foreign Investment Group at Linklaters; and Dr. Sebastian Jungermann, Partner at Arnecke Sibeth Dabelstein. The event was moderated by Prof. Dr. Thomas Wegerich, publisher of Deutscher AnwaltSpiegel.
Discovery in the “DACH” region
To kick things off, Thomas Fritzsche and Klara Weiand outlined the key findings from the survey in a brief keynote presentation. According to their findings, discovery is no longer just a concern for legal, compliance, and IT departments – data leakage incidents have made cybersecurity a key player. Corporate security and internal audit departments are also increasingly integrating methods and technologies from the field of discovery. Although discovery has become a cross-functional discipline, the necessary cross-departmental collaboration still falls short of requirements in many places.
According to the study’s findings, the discovery business in German-speaking countries is fragmented: Most companies report fewer than 10 cases over the past five years, and case durations typically range from one to six months. Nevertheless, large-scale proceedings – sometimes spanning several years – occur regularly.
Particularly revealing are the differences in review costs, which range from less than €0.10 to more than €2 per document. Fritzsche explained the relationship between case volume and cost awareness: Companies with little experience initially tend to underestimate costs. As case volume increases, awareness of the actual effort involved grows, but so does the ability to standardize – which in turn limits costs.
About 70% of the companies surveyed conduct discovery projects entirely in-house; only 6% outsource them completely. When specific services are outsourced, they primarily involve specialized tasks – digitization, data backup, data analysis, data hosting, and digital forensics – but not the core responsibilities.
According to the study’s findings, traditional document review may be on the verge of becoming obsolete. Automated analyses and AI are replacing manual review processes. According to Weiand, the central question is no longer whether AI will be used, but rather in which use cases its results are reliable enough. Fact and fiction are still too closely intertwined in the highly demanding discovery environment.
Weiand distinguished between two case profiles: Standardizable investigations with clear relevance criteria benefit greatly from automation – the focus shifts from processing to quality assurance and approvals. Complex investigations, on the other hand, in which the specific issues only become clear as the process unfolds, remain cost-intensive: Quality assurance, legal classification, documentation, and management drive up costs. The fact that traditional document review is scarcely mentioned in the study as an outsourced service is no coincidence, as many companies simply no longer conduct it in this form.
AI and antitrust law – discovery in practice
In the ensuing discussion, Martin Mozek drew attention to growing demands and shifting expectations regarding the collection and analysis of data, as well as the assessment of facts, which arise from the use of AI. While AI shifts the value-creation curve, he noted, it does not replace experts. Anyone who wants to successfully utilize new media and methods needs experts who can monitor AI-supported processes, critically evaluate results, and manage risks. In this context, Fritzsche pointed out a problem with the next generation: Young colleagues who have grown up with AI intuitively assume its results are reliable – even though warnings about “hallucinations” are given as early as the introductory course.
The chatbot use case highlighted this tension: Discovery chatbots already provide value added for standardizable questions and early-case assessment. However, when dealing with large, heterogeneous data sets, their functionality is limited, as one must already possess a great deal of knowledge to be able to interpret the results. A desired “democratization” of data access will only be realized when those who work with the data also understand what AI actually delivers – and what it does not.
Kaan Gürer focused on the antitrust use case. AI is already useful in traditional antitrust proceedings, but still primarily takes a supporting role. Today, AI makes a significant contribution to preselection, prioritization, data privacy reviews, and early-case assessment. However, AI cannot yet guarantee completeness and traceability – both of which are key requirements of regulatory authorities.
As a concrete example, he cited an antitrust investigation in which an AI model, despite specific prompts, repeatedly returned the same documents from Switzerland – while relevant results from Germany or France were missing. The problem could not be resolved even through dialogue with the AI provider, as reproducibility and transparency were lacking. His conclusion is therefore: “It’s not about humans or machines, but rather where to make clever use of humans and where to use machines.” AI is particularly valuable for pattern recognition and the initial legal categorization of large data sets – areas where repetitive selection work is required. According to Gürer, regulatory authorities are quite open to discussions about methodology; the European Commission, for example, more so than the UK’s Competition and Markets Authority (CMA).
Sebastian Jungermann broadened the perspective to include antitrust damages proceedings, U.S. litigation support, and M&A due diligence. AI leads to significant efficiency gains in these areas as well – especially in light of growing data volumes, which are themselves increasingly AI-generated and thus “require explanation”: When machines communicate with machines, in the end, no one may know what actually happened. Results are sometimes unreliable, misleading, or simply wrong – and AI cannot yet replace the experienced consultant.
Jungermann also pointed to a new reality in the defense sector: Companies transitioning from the civilian to the defense sector are confronted with high-security requirements that prohibit certain data from being stored in the cloud. This fundamentally changes data management. At the same time, discovery software, data rooms, and matter management are increasingly converging. Anyone who wants to succeed in this market must invest today in analytical expertise and digital forensic capabilities within IT.
The human factor and co-determination in data management
One question from the audience addressed the human factor in investigations. The panel agreed that “traditional” interviews with the relevant individuals remain indispensable. After all, it always starts with conversations, because in complex cases, one simply doesn’t yet know what to look for – or who, if anyone, is even a relevant custodian. Mozek summed it up: “You often waste a lot of time sifting through an incredible number of documents. If I’d been able to ask just two months earlier, I would have wrapped up the case long ago.”
Gürer reported that the format of interviews is changing – more digitization, more transcription – but that personal contact remains irreplaceable when dealing with key individuals: Body language, contradictions, and investigative conversations. Fritzsche described a specific case in which only a direct conversation revealed that a team had deleted the relevant chats –whereupon the backups, which contained the complete chat, were consulted. “In these tense situations, this conversation is simply essential.”
Another question from the audience brought a topic that had hardly been discussed so far into the spotlight: Employee prompts as a potential source of insight in investigations. Fritzsche considered prompts to be one of the most promising data sources from a detection perspective: “With prompts, one can assume that no one has yet considered that they could be analyzed.” Mozek confirmed that monitoring AI use within companies is currently a topic of open discussion. Gürer pointed out a particularly interesting aspect: Prompts could reveal how employees use compliance training – for example, to research how antitrust violations are committed without attracting attention. He recalled the Michelin case, in which an antitrust authority used AI to uncover coded language in earnings calls – a new, disguised form of price-fixing that was, in turn, exposed by AI.
The discussion led directly to the issue of employee participation. Mozek strongly recommended involving works councils early on and comprehensively – even on matters not subject to employee participation. Clear company agreements governing access to corporate data during investigations create legal certainty and prevent costly delays in the event of an emergency. Gürer added a crucial point: The authorities aren’t interested in what was agreed upon internally – they take whatever they find. If you want to be on equal footing with the authorities, you must be able to act immediately.
New risk areas: From dark data to AI-generated content
Dark data, long a nightmare scenario in discovery, has lost its significance. The new risk areas are AI-generated content, mobile devices, cloud data, social media posts, and transaction data – with AI-generated content at the top of the list.
Fritzsche pointed out a fundamental shift: Until now, the rule was that existing data derives its evidentiary value from the fact that its authenticity can be verified. But when AI generates premium-quality data that is indistinguishable from the real thing, a new fundamental problem arises: “Right at the very beginning of the discovery process – during the collection of evidentiary data – we will have to explain why we can assume that the data is reliable.” Deepfakes – that is, deceptively real voicemails and video messages – are just the tip of the iceberg. One open question that occupied the panel remains: Will AI expose AI?
When it comes to the cloud, the study paints a surprising picture: While there is intense discussion about the software used and data processing, most companies see hardly any risks associated with cloud storage. The challenge lies not in the cloud itself, but in managing the volumes of data generated within it.
The session concluded with a look into the near future: Weiand predicted that individual AI use cases will converge into integrated workflows in the coming years – no longer isolated, standalone solutions, but a seamless process spanning the entire eDiscovery process. Fritzsche added: “We’ll see more agents involved in discovery. But we’re only just beginning to gain experience – and the dialogue we’re having now will be extremely important over the next few years.” Jungermann urged that the decline in specialists be prevented: “If experts are no longer being trained because young people aren’t being hired, we’ll create a huge gap.” Mozek concluded with an image that aptly summarized the discussion: Compliance requests so well-written that one begins to doubt whether they were really written by a human – and whether the consultant’s response might, in turn, be processed by AI.
It will be interesting to see in which direction discovery and data management will evolve in the coming years.
