With every client engagement, the number one question we are asked: “How can we lower our legal and review costs while ensuring compliance with our discovery obligations, especially with the growing volume of data on our employees’ mobile devices? Can AI help?” The simple answer is yes – for most data. Agentic AI is actively emerging in eDiscovery review with the promise of lowering costs and delivering faster answers. The reality, though, is that most organizations’ mobile data collection processes are simply not ready, with traditional collection processes resulting in costly overcollections of data not relevant to a matter.
As discussed in our most recent blog, AI Can Now Read Everything You Collect. Should You Have Collected It?, overcollecting data can open an organization to privacy exposure, custodian consent problems, cross-border risk, and heightened proportionality obligations. The most defensible collection is still the one scoped to what a matter actually requires.
Forensics vs. AI Collections – Understanding the Difference
Forensic tools built for law enforcement are now being marketed to corporations with the pitch of collecting evidence in minutes instead of weeks, digging into unparsed and proprietary mobile databases, and linking data across multiple devices to map relationships in a case. These capabilities assume the same starting point: collect the data from the whole phone and store it in an AI-searchable cloud storage for analysis across multiple devices and data sources. The AI is impressive. Yet, it goes against the “collect only what’s necessary” legal strategy.
Agentic AI is beginning to make eDiscovery review nearly frictionless for email, enterprise chat, and document repositories. That is the good news. The uncomfortable news? As AI agents take over document review for the data sources, the ability to handle mobile data remains fundamentally different. Agentic AI workflows are not yet ready for smartphone collections at scale.
The Defensibility Fight Has Moved—But Not for Mobile
For the last decade or more, arguments over eDiscovery defensibility have centered on review: search terms, technology-assisted review (TAR) protocols, privilege calls, reviewer consistency. Agentic AI collapses much of that debate (and costs). Alvarez & Marsal predicts regulators and courts will simply assume agentic AI has touched the review. When that assumption becomes the default for email and collaboration tool archives (e.g., Microsoft Teams), the value proposition is clear: faster, cheaper, more consistent review with an auditable AI chain.
But that assumption breaks down when applied to mobile. Rather than answering how reliably the agent processed a complete data set, the question shifts to “Where did the data come from, and can you prove it’s complete, scoped, and untainted?” This is a fundamentally different problem that agentic AI cannot solve upstream.
Smartphones now carry the most consequential business conversations: text threads, WhatsApp, Signal, ephemeral chats, collaboration app fragments. They are also the hardest custodial source for defensibly collecting data at scale. Unlike email or enterprise systems that generate logs and leave digital breadcrumbs, mobile devices hold fragmented conversations across dozens of applications with minimal infrastructure oversight. An AI agent ingesting a bloated forensic image of a custodian’s phone does not produce a cleaner outcome; it produces a faster, more confident outcome and a more expensive problem. Privilege leakage, PII contamination, and out-of-scope personal data all get amplified downstream, not filtered out.
The New Rule 26(f) Question and Where It Points
Recent commentary on Rule 26(f) disclosure thresholds for agentic AI makes the point plainly: when agents act on evidence, parties will need to disclose not just that AI was used, but also to what kind of data it was pointed at. This reframes the meet-and-confer in ways that are different depending on the data source.
For email and enterprise repositories, the question is manageable: “Your AI agent reviewed 2 million documents using [model]; how did you validate the training data and test the model’s recall?” That is a conversation about AI rigor, not data collection.
For mobile, opposing counsel’s most productive questions remain foundational: How was the mobile data collected? Was the extraction scope-limited or a full device dump? Was it hash-verified at the source? Was custodian personal data segregated before an agent ever saw it? The Rule 26(f) conversation does not rescue you from these questions; it exposes that they were never answered in the first place.
Protective order fights, like Morgan v. V2X, have already signaled that courts are already policing what discovery data goes into AI tools. Pair that trajectory with an AI-review workflow that assumes clean input, and the collection layer becomes the single, most challengeable link in the chain.
What AI Review Assumes about Mobile Input
In the race to define the agentic AI eDiscovery category, most vendor platforms claim to solve the collection problem for all data sources. For email and enterprise chat, they largely have. For mobile, not so much. Consider what happens when an AI agent encounters mobile data typically collected today:
- Hash verification assumes integrity from the start. An AI review platform ingests mobile data and builds its statistical confidence model on the assumption that what it is seeing is the complete, untampered source. But if the data has arrived unverified, extracted by an MDM without cryptographic validation or imaged on a technician’s laptop without chain-of-custody documentation, the agent has no way to detect degradation. When opposing counsel challenges whether a particular WhatsApp thread is genuine or asks whether the extraction captured ephemeral messages before they are automatically deleted, a downstream AI model cannot retroactively establish that the source was sound. The reputational and litigation cost lands on the company, not the collection tool.
- Scope-limited extraction assumes the collection matches the legal hold. A financial services company issues a litigation hold to 80 BYOD custodians and needs to preserve all communications related to a trading investigation. An AI agent is trained to review only those communications. But if the collection captured the entire phone – every message app, every collaboration tool, every note – the agent will perceive the hold as broader than intended. It will flag potentially relevant material outside the investigation scope, including privilege logs that must be individually resolved. A scope-limited collection involving only Microsoft Teams and SMS that’s date-range restricted and hash-verified at source would provide the agent a cleaner input and a more defensible perimeter.
Getting an Organization Ready for Mobile
The uncomfortable reality is that most organizations and legal teams are still grappling with how to incorporate mobile data into the eDiscovery process. According to eDiscovery Today’s 2025 State of the Industry Report, only 37.5% of respondents said they discover data from mobile devices in all or most of their cases.
The data gap between what AI agents need and what most organizations can currently deliver creates a compounding risk. Legal teams are actively rolling out agentic AI-based solutions for reviewing email and structured enterprise data, where the technology is genuinely transformative. The risk with this success is that it will create organizational momentum to apply the same workflow to mobile data before mobile data collection has caught up.
Actions You Can Take Now
If you are a general counsel, compliance lead or legal ops executive planning your future eDiscovery roadmap, following are three practical shifts to consider implementing now:
- Separate your mobile collection strategy from your agentic AI deployment. Agentic AI is a transformative tool for email, enterprise chat repositories, document systems, and other centrally managed data sources. Do not assume the same workflows apply to mobile. Instead, map your current mobile collection process independently. Document how you collect from BYOD and corporate devices today. Can you extract from remote employees without travel? Can you scope collection to specific apps and date ranges, or do you always image the whole device? Can you hash-verify at extraction, or does verification happen downstream? For any process step you cannot answer definitively, schedule a collection vendor audit before you sign a contract with an AI review platform.
- Build collection requirements into your AI-assisted review RFP. Ask AI vendors: “What do you assume about the completeness and integrity of data you’ll ingest?” For email and enterprise sources, the answer will be sophisticated and confidence-building. For mobile, listen carefully: If the answer is vague or outsources the problem back to you, that could be a signal that the agentic AI solution you are evaluating is not yet the right tool for mobile-heavy matters. A vendor serious about agentic AI review should distinguish between what the solution can reliably handle and what still requires foundational collection discipline. Ask your collection vendors whether they can meet mobile-specific requirements at scale, including hash-verified extractions, scope-limited data, documented chain of custody, and personal data segregation. If they cannot, mobile data should not feed an agentic workflow.
- For matters heavy in mobile data, segregate custodian personal data from the outset. Do not collect it and filter it later. That approach fails whether you are using AI or not. Build scoping rules into the extraction process itself, excluding photos, notes, personal email accounts, health app data, and messaging apps unrelated to business. Make that segregation cryptographically verifiable. When the court or opposing counsel asks, “Where did this data come from?” the answer should be “From a scope-limited extraction that excluded personal data by design and was hash-verified at source.” That approach is defensible regardless of whether you feed the results to an AI agent or a human reviewer.
Agentic AI is transforming eDiscovery for the data sources it is currently equipped to handle. Mobile data is not yet one of them. Treating it as if it were can only make bad mobile collection faster, more visible, more expensive and far riskier.
