Blog Litigation Support

Privilege Log Automation: What Actually Works in Production Review

Automated privilege log drafting works at the description-generation level. The attorney-client call still requires an attorney. Here's where the line sits — and why the tools that overstate their capability get challenged on motions.

Structured log entries on legal review paper

Privilege logs are, in theory, a solved problem. The document exists. The privilege applies or it doesn't. The description follows a standard formula. In a world where each document takes 30 seconds to log, a 2,000-document privilege set takes about 17 attorney-hours — annoying, but manageable.

In practice, production review for a contested commercial matter frequently produces privilege sets of 3,000 to 8,000 documents. At a mid-size firm billing $350/hour for second-year associates, the logging task alone represents $50,000 to $140,000 in attorney time before the substantive work begins. Partners don't budget that. Associates resent it. The privilege log gets drafted fast, which means it gets drafted sloppily, which means it gets challenged.

Automation is the right answer for the description-drafting component. Understanding where the right answer ends is the more important question.

What a Privilege Log Entry Actually Requires

Under Federal Rule of Civil Procedure 26(b)(5) and its state analogs, a privilege log entry must describe the nature of the document, the date, the author and recipients, and the privilege basis with enough specificity that opposing counsel and the court can assess the claim without disclosing the privileged content.

The description is the contested element. Courts have consistently held that boilerplate descriptions — "email communication reflecting legal advice" — are inadequate. The description must convey what kind of legal advice is involved, even without disclosing the substance of the communication. "Email from outside counsel to CEO re: regulatory compliance strategy for Q3 supplier contract" is adequate. "Email re: legal matter" is not.

This is precisely the task that description generation can handle well. The automated system reads the document's sender, recipients, date, and subject matter, and generates a description that is specific enough to meet the adequacy standard without disclosing the privileged content. This is language generation in a constrained domain with clear output criteria — well within what current NLP tools do reliably.

Where Automation Has Genuine Limits

The description-generation task is separable from the privilege determination task. Conflating them is where automation tools create liability.

The attorney-client communication question

The foundational question for attorney-client privilege is whether the communication was made for the purpose of obtaining or providing legal advice, in the context of an attorney-client relationship, with a reasonable expectation of confidentiality. Each element of this test requires judgment about the facts of the specific matter, the nature of the relationship, and the purpose of the communication at the time it was created.

An automated system can flag that a document is from an attorney to a corporate officer. It cannot determine whether the attorney was acting in a legal capacity or a business capacity for that communication — a common issue in in-house counsel communications where the attorney is also a C-suite executive involved in business decisions. That determination requires a human who understands the context of the matter.

The work product doctrine distinction

Work product protection under Rule 26(b)(3) protects documents prepared in anticipation of litigation. The "anticipation of litigation" threshold — when a company or its counsel could reasonably anticipate that litigation was likely — is a fact-specific judgment that turns on the specific communications, internal discussions, and external events at a specific point in time. No automated system can reliably make this determination. The reviewing attorney has to.

Crime-fraud exception screening

Documents that fall within the crime-fraud exception to attorney-client privilege are not protected. Identifying whether a communication was made to obtain legal assistance in furtherance of a crime or fraud requires the attorney to read the document and assess it against the specific allegations in the litigation. This is not automatable, and the consequence of incorrect automation here — logging a non-privileged crime-fraud-excepted communication as privileged — can expose the firm to sanctions.

The Practical Division of Labor

The appropriate automation workflow in privilege review separates the machine task from the attorney task clearly:

  1. Machine identifies candidates: Documents that contain attorney communications, attorney names in the to/from/cc fields, attorney-recipient forwarded communications, and documents with privilege-associated metadata (attorney work folders, legal team document management tags). This is pattern-matching on structured data — reliable and fast.
  2. Machine generates descriptions: For each candidate document, the system generates a draft log entry description based on the document's metadata and content. The description is specific enough to be adequate if the privilege determination is correct.
  3. Attorney makes the determination: The reviewing attorney reads the candidate document and determines whether it is in fact privileged, and if so, under what doctrine. The attorney reviews the machine-generated description for accuracy and amends as needed. The attorney makes the final decision on each entry.
  4. System aggregates the log: The finalized entries are compiled into a production-ready privilege log in the required format.

Steps 1, 2, and 4 are automatable with high reliability. Step 3 is not. The system that compresses the attorney's role in step 3 to a rubber-stamp is the system that produces a challengeable log.

What Gets Challenged and Why

Privilege log challenges in litigation typically attack one of three things: inadequate description, overbroad assertion (logging documents that aren't actually privileged), or failure to log discoverable documents (logging only some of the documents that should be on the log while producing others that should be withheld).

Automation, done correctly, actually reduces all three failure modes. Consistent description generation reduces the variance in description quality that leads to "inadequate description" challenges. Systematic candidate identification reduces the likelihood of inconsistent privilege assertion. Structured document tracking reduces the inadvertent production of documents that should be withheld.

Automation done incorrectly — where the privilege determination itself is automated — tends to produce overbreadth problems. Systems that flag everything with an attorney name as potentially privileged without the human determination step log too much, and the overage gets challenged as improper assertion. Courts are increasingly skeptical of privilege logs that appear to be generated by automated tools without meaningful attorney review, and when discovery disputes arise around these logs, the burden is on the withholding party to demonstrate that the privilege determination was made by a qualified attorney.

What We Built For

Undwrlyft's litigation support module automates steps 1, 2, and 4 in the workflow above. We identify candidates, generate descriptions, and compile the log. We do not make privilege determinations, and the interface is designed to make the attorney's determination step visible and auditable — not to minimize or obscure it.

The reviewing attorney's call on each document is logged as part of the review record. The output includes a review trail showing which documents were reviewed by which attorney, when, and with what determination. This is not overhead — it's what you need if the log is challenged and you have to demonstrate that privileged documents were reviewed by an attorney who made the determination.

For a 5,000-document privilege set, our tooling reduces the attorney review time from the 17-hours-per-1,000-documents baseline to something closer to 4-5 hours per 1,000 documents, because the attorney is reviewing descriptions and making determinations, not also doing the metadata extraction and description drafting from scratch. The attorney's time goes to the judgment task. The machine's time goes to everything else.

That's the right division. Overstating automation's role in the determination step isn't just technically wrong — it's a risk the firm takes on in the litigation context, and it's a risk that materializes when the log gets challenged.