TL;DR: Law firms need AI governance that addresses three distinct risks: privilege waiver from using non-enterprise AI tools with client documents; ethics rule compliance under ABA Formal Opinion 512 (Rules 1.1, 1.6, and 5.3); and court AI disclosure requirements that vary by jurisdiction. A written AI policy, approved tool list, supervision protocols, and client disclosure language are the four deliverables every firm should have in place.
Law firms are not just general businesses that happen to use AI. They are professional service organizations with fiduciary duties, privilege obligations, and ethics rules that create governance requirements that go beyond what a typical company needs. The governance question for a law firm is not just "are we GDPR-compliant" or "do we have a vendor DPA." It is also: "if we use this AI tool in client work, are we waiving privilege, violating our ethics obligations, or creating malpractice exposure?"
In 2026, these questions have become more pressing. Courts are sanctioning attorneys for AI-generated hallucinations in filings. Bar associations have issued formal ethics opinions. Some courts now require disclosure of AI use as a condition of filing. The firms that have governance in place are navigating this environment with confidence; the firms that do not are discovering the rules one sanctions order at a time.
The Mata v. Avianca moment
In June 2023, a federal judge in the Southern District of New York sanctioned attorneys who submitted a brief citing multiple non-existent cases that had been generated by ChatGPT. The attorneys had not verified the citations. The firm and attorneys were fined. The decision was covered in every major legal publication.
Mata v. Avianca did not create new legal rules. It applied existing professional responsibility standards: Rule 1.1 (competence) and Rule 3.3 (candor to the tribunal). What it did was make concrete what had been abstract: AI can produce legally plausible but completely false citations, and an attorney who files without verifying has violated their professional obligations.
Since Mata, courts have moved to require disclosure. The reasoning is that if attorneys are using AI in their work, courts need to know so they can calibrate expectations and address issues quickly. Disclosure requirements are not punitive; they are a structural response to the demonstrated risk of unverified AI output appearing in the record.
Court AI disclosure requirements
Requirements vary by court and are updated frequently. As of mid-2026, the following are in effect:
Southern District of New York (Standing Order 24-MC-0031): Attorneys must certify in any filing whether they used generative AI in drafting the document. If AI was used, the attorney must certify that the AI-generated content was reviewed and verified by a human attorney for accuracy. Failure to comply may result in sanctions.
Northern District of California: A standing order requires disclosure if generative AI was used to draft any portion of a brief or other filing. The order applies to AI-generated text, not to standard spell-check or grammar tools.
Fifth Circuit: Requires a certification in any brief or motion that no portion was drafted using AI tools without human review, or alternatively a disclosure identifying which portions were AI-assisted and confirming they were verified.
Individual judge standing orders: Many federal judges have their own standing orders that go further than the district-wide rules. Before any filing, attorneys should check both the local rules and the assigned judge's standing orders.
State courts: Requirements are developing. California, New York, and Florida have seen bar guidance that effectively requires disclosure when AI-generated content appears in court filings, even absent a formal court order.
Practical step: Add a court AI disclosure check to your filing workflow. Before submitting any document, confirm whether the court has an AI disclosure requirement. If yes, add the required certification. If AI was used, confirm that a human attorney reviewed the specific AI-generated content for accuracy.
ABA Formal Opinion 512
ABA Formal Opinion 512, issued in 2023, is the governing ethics framework for AI use by lawyers. It analyzes three Model Rules:
Rule 1.1 (Competence): Comment 8 to Rule 1.1 already required lawyers to keep abreast of changes in the law and its practice, including the benefits and risks of relevant technology. Opinion 512 applies this to AI: lawyers must understand how the AI tools they use function, including the risk of hallucinations, the basis on which the AI generates responses, and the limitations of the tool for legal research. Using AI without understanding it does not satisfy the competence standard. Neither does relying on AI output without verification.
Rule 1.6 (Confidentiality of Information): A lawyer may not disclose client information without authorization. Uploading client documents to an AI tool that retains inputs or uses them for training is a disclosure. The analysis requires examining: (a) what the vendor's terms say about data retention and training; (b) whether a confidentiality agreement governs the relationship; (c) whether using the tool falls within the implied authorization of the representation. For general-purpose consumer AI tools, the analysis often fails on points (a) and (b). For enterprise legal AI platforms with contractual confidentiality protections and no training on user data, the analysis is much more favorable.
Rule 5.3 (Responsibilities Regarding Non-Lawyer Assistance): When a non-lawyer (including AI) performs work for a client, the supervising attorney is responsible for ensuring that the work meets professional standards. This has two practical implications. First, when an attorney uses AI to draft or research, they are responsible for the accuracy and completeness of the output. Second, when a partner supervises an associate or paralegal who uses AI, the partner is responsible for ensuring the AI-assisted work product is adequately reviewed. AI does not reduce the supervisor's responsibility; it creates a new surface on which that responsibility must be exercised.
State bar guidance roundup
New York State Bar Association: Issued guidance in early 2024 recommending that lawyers: conduct due diligence on AI vendor confidentiality and security practices; verify AI-generated legal research before relying on it; consider whether the client's matter requires disclosure of AI use; and maintain competence by keeping current with AI developments.
California State Bar: Released a formal guidance document addressing competence, confidentiality, billing, and supervision. On billing: charging hourly rates for AI-assisted work at the same rate as human work, when the AI materially reduced the time required, may raise fee ethics issues under Rule 1.5.
Florida Bar (Opinion 24-1): AI use is ethically permissible under Florida Rules when: (a) the attorney has obtained reasonable assurance of vendor confidentiality; (b) the AI-generated work is reviewed for accuracy; (c) fees charged reflect the actual work involved. The opinion also notes that using AI in client communications without disclosure may be impermissible in some circumstances.
Texas: No formal bar opinion as of mid-2026, but the Professional Ethics Committee has issued informal guidance stating that the ABA Opinion 512 framework applies under Texas Disciplinary Rules. Texas lawyers are advised to follow ABA Opinion 512 pending formal state guidance.
DC Bar: Ethics Opinion 388 requires that AI tools used in client work have contractual confidentiality protections in place. The opinion treats the vendor confidentiality requirement as a precondition of use, not just a best practice.
Privilege risk from AI tools
Attorney-client privilege protects confidential communications between attorney and client made for the purpose of legal advice. The privilege can be waived by voluntary disclosure to a third party outside the privilege.
When an attorney uploads a privileged client document to an AI tool, the key question is whether this constitutes a disclosure to a third party. The analysis depends on:
Vendor data practices: Does the vendor retain inputs for model training? If yes, the document has been shared with the vendor's systems in a way that could be used for purposes beyond the specific query. This is the clearest risk factor.
Vendor contractual relationship: Is there a confidentiality agreement (DPA or enterprise services agreement) that prohibits the vendor from using inputs for training and that establishes reasonable security? A strong contractual relationship reduces the disclosure risk, analogously to how sharing privileged information with consultants or experts under a confidentiality agreement does not waive privilege.
SOC 2 and security: Does the vendor have enterprise-grade security? Security controls are relevant to the completeness of the confidentiality protection.
Approved tools for legal work: Enterprise legal AI platforms (such as Westlaw AI, LexisNexis+, Harvey, and several others) have been specifically designed for legal use with no training on client data, dedicated infrastructure, and DPAs. These platforms carry materially lower privilege risk than general consumer AI tools.
Practical rule: Do not upload privileged client documents to any AI tool that does not have: (1) a signed DPA or enterprise agreement with confidentiality protections; (2) an explicit no-training-on-inputs provision; (3) SOC 2 Type II or equivalent certification. For all other tools, use only non-confidential, non-client data.
Associate and paralegal AI supervision
Rule 5.3 applies to partners supervising associates and to attorneys supervising paralegals. When either group uses AI in client work, the supervising attorney has the same responsibility they would have if a junior attorney or paralegal had done the underlying work.
This means supervisors need to develop specific review practices for AI-assisted work:
For AI-generated legal research: Verify every citation independently. Do not rely on the AI's summary of a case; read the actual decision.
For AI-generated drafts: Review the draft with the same scrutiny you would apply to a junior associate's first draft, with additional attention to statements of law (which may be hallucinated) and factual accuracy.
For AI-assisted document review: Sample the AI's outputs. If AI is categorizing documents as responsive or non-responsive, sample enough of each category to assess accuracy before relying on the classification.
For AI use in client communications: Review all AI-generated client communication before it is sent. AI drafting of routine client emails is generally acceptable under supervision; AI drafting of advice letters requires careful review as it would for any substantive advice document.
Law firm AI policy structure
A law firm AI policy should cover:
- Approved tools: A list of AI tools approved for use in client work, with any restrictions on what data can be uploaded. Unapproved tools for client-data work.
- Prohibited uses: General-purpose consumer AI tools for client documents; AI use without supervision for filings or client advice; billing practices inconsistent with actual AI-assisted time savings.
- Verification requirements: Mandatory citation verification for AI-generated legal research; review requirements for AI-drafted documents before client delivery or filing.
- Supervision requirements: How partners are expected to supervise AI-assisted work by associates and paralegals.
- Court disclosure process: How to determine whether a court AI disclosure is required and the procedure for adding the required certification.
- Client disclosure: Whether and when to disclose AI use to clients; template language for engagement letters.
- Incident reporting: How to escalate if an AI tool produces a confidentiality concern, such as receiving outputs that appear to be another client's information.
Client disclosure obligations
There is no across-the-board requirement to disclose AI use to clients, but the analysis under Rule 1.6 and fee rules suggests that disclosure is appropriate in several circumstances:
- When client documents are uploaded to an AI tool (given the confidentiality analysis above)
- When AI materially reduces the time required for a task and the fee arrangement is hourly
- When AI is used in a high-stakes matter where the client would reasonably want to know
A practical approach is to include AI use language in the engagement letter, describing at a general level that the firm uses AI tools with appropriate confidentiality protections, and giving the client an opportunity to ask questions or impose restrictions.
For clients with their own AI policies or data handling restrictions (common in financial services, healthcare, and government contracting), review their AI policies before using any AI tools in their matter.
Related reading
- AI Hallucination Sanctions Tracker 2026: $145K in Fines, One Fix
- AI acceptable use policy template for small teams
- AI vendor due diligence checklist 2026
- AI vendor evaluation checklist
- GDPR-compliant AI assistants comparison
- AI tool register template
- Anthropic vs OpenAI GDPR compliance comparison
- AI governance for small teams, complete guide
- SEC AI governance investment advisers 2026
- AI VDR compliance governance guide 2026
- Are your AI chats privileged? The Heppner discovery ruling
- AI liability insurance in 2026: what coverage actually exists and what smal
- AI Output Copyright Risk: Which Providers Indemnify You and What to Do Befo
