Litigation is where AI summarisation lands hardest — a discovery bundle of ten thousand pages, reduced to a chronology and an issues list, is real, measurable value on work that was always brutal. It is also the one practice with a catastrophic failure mode: a hallucinated case citation placed in front of a judge. This isn't hypothetical in South Africa. In Mavundla and Northbound Processing, our courts found fabricated AI citations in the papers and referred the lawyers to the Legal Practice Council — and in one, the tool was trained on SA law and hallucinated anyway. This leaf is the litigation read for the AI era: where the summarisation is gold, and where the generated citation is a professional-conduct event.
Civil litigation in South Africa runs through a court hierarchy — Magistrates' Courts, the High Court, the Supreme Court of Appeal, and the Constitutional Court — on a process of pleadings, discovery, and trial or motion. In the High Court, discovery is governed by Rule 35 of the Uniform Rules of Court: each side must disclose the relevant documents in its possession, with relevance measured against the pleadings. The volume of that record is exactly why AI summarisation is attractive here.
The thing that changes the AI calculus in litigation is the lawyer's status. A legal practitioner is an officer of the court with a duty of candour: what you put in the papers, you vouch for. A fabricated citation isn't a bad search result — it's a breach of that duty, governed by the Legal Practice Act 28 of 2014 and enforced by the Legal Practice Council. That is why the same hallucination that's a shrug in a chatbot is a career event in a court file.
The genuine, defensible use of AI in litigation is reading and structuring the material that already exists. A discovery bundle too large to read in the time available, reduced to a chronology. A witness statement cross-checked against the documents. A long judgment or expert report summarised. A first-pass relevance review across thousands of discovered documents. This is document-grounded work: the model operates on the record in front of it, and a human verifies the output against the source. Used this way — on real documents, with the citation being a page in the bundle, not a case name — AI is one of the most valuable tools litigation has seen.
Summarising a document you gave the model is retrieval: the answer is in the source, and you can check it. Asking the model for "the leading cases on X" is generation: the answer comes from its training, and it will invent a plausible one if it doesn't have a real one. The entire safety of AI in litigation is on the right side of that line — grounded in the record, never generating the law.
This is not a foreign cautionary tale. South African courts have already dealt with it, more than once.
In Mavundla v MEC: Department of Co-Operative Government and Traditional Affairs, KwaZulu-Natal (Case No. 7940/2024P), a legal team's application relied on nine cases — of which only two existed, and one of those was mis-cited. The advocate admitted she had not verified the authorities, relying on a junior's research from "an online tool"; the fabricated cases had been generated by ChatGPT. In Northbound Processing (Pty) Ltd v The South African Diamond and Precious Metals Regulator (Case No. 2025-072038, Gauteng High Court), the heads of argument again contained fictitious citations. The Acting Judge referred the lawyers to the Legal Practice Council for a misconduct investigation, holding that even without an intent to mislead, "the risks posed to the administration of justice if fake material is placed before a court are such that… admonishment alone is unlikely to be a sufficient response."
The consequence of an AI-fabricated citation in SA is not a red face — it is a referral to the Legal Practice Council, potential adverse costs, and a judgment, on the public record, naming the practitioner. The failure mode is disciplinary, not merely reputational, and the courts have signalled they will treat it seriously.
The most important detail in Northbound is easy to miss: the lawyer said the platform was "exclusively trained on South African legal judgments and legislation." It hallucinated anyway. This is the trap to name plainly. A jurisdiction-specific model reduces the odds of a foreign wrong answer; it does not remove the mechanism of hallucination. A generative model produces the most probable next tokens, and a plausible-looking citation is exactly what that machinery is good at inventing. The safeguard is not a better-trained model — it is grounding (the tool retrieves and quotes a real, checkable source) plus verification (a human confirms every authority against the report). Trusting a tool because it's local is how a careful firm ends up in the second paragraph of a reported judgment.
Two constraints govern how a model may touch the litigation record. First, legal professional privilege — South African law recognises two forms, legal advice privilege and litigation privilege — protects communications and work product from disclosure. Running privileged material through a third-party model, or into a tool whose terms allow training on inputs, can jeopardise the privilege the whole strategy depends on. Second, discovery bundles are dense with personal information — parties, witnesses, third parties — so processing them with AI is a POPIA event, and a section 72 transfer question if the tool processes offshore.
The residency and privilege answer has to be settled before the record goes near a model: a tool that keeps the data in country and does not train on inputs, used on documents the client owns. Get it right and AI is a discovery superpower; get it wrong and you've waived privilege or exported personal information to win a chronology. See the Data privacy & POPIA leaf.
The signature failure. A plausible case name, a real-looking citation, and no such judgment. In SA it has produced LPC referrals and named practitioners. Verify every authority against a real report — SAFLII, the law reports — before it enters the papers.
A local model narrows foreign errors; it does not stop hallucination. Northbound is the proof. Grounding and human checking are the safeguards, not the training set.
Feeding privileged strategy or work product into a model whose terms permit training on inputs can jeopardise the privilege. The tooling decision is a legal one, made before the record is uploaded.
Discovery is full of third-party personal data. Processing it with an offshore tool is a section 72 transfer question. Keep it in country and the question closes.
In Mavundla, the authorities came from a junior's "online tool" and went in unverified. Delegating the search does not delegate the duty to verify — the practitioner who signs still vouches for every line.
The clearest value: taming the discovery bundle. Summaries, chronologies, and relevance review on documents the client owns, kept in country, with a human verifying against the source. The drudgery of the record compresses; the advocacy and the strategy stay with the practitioner.
High-volume, document-heavy matters — claims, recoveries, standard disputes — where triage and summarisation across many files is the win. The tool reads and structures; the lawyer decides exposure and approach, and checks every authority.
The practice pattern the SA cases demand: every AI-surfaced authority is opened and read in a real report before it's cited; every proposition of law is checked; the practitioner who signs the papers has personally confirmed the citations. Build the workflow so verification isn't optional — because the court has made clear it isn't.
Mavundla and Northbound mean SA practitioners can't claim the risk is theoretical or foreign. The judiciary has signalled that fabricated AI citations are a professional-conduct matter, with LPC referral and costs on the table even absent an intent to mislead. The bar is verification, and the courts are enforcing it.
Everything safe about AI in litigation reduces to one principle the rest of the tree keeps returning to: ground the tool in the real record and verify the output. A summariser pointed at the bundle is a superpower; a generator asked for the law is a liability. The data-and-trust thesis, applied where the stakes are a judge.
The record is privileged and personal. Where it's hosted, whether the tool trains on it, and whether it crosses the border are decisions made before the first upload — the residency answer the tree gives everywhere. See Data privacy & POPIA.
Disputes is where the tree's grounding thesis stops being an engineering preference and becomes a professional-conduct rule.
The rules, the Act, the regulator, and the case-law database — read the Mavundla and Northbound judgments themselves on SAFLII rather than a summary.