
Using AI for legal work isn't just a technology decision. It's an ethics decision, and the American Bar Association and dozens of state bars have made clear there is no special carve-out for it. The same Model Rules of Professional Conduct that have always governed a lawyer's work, competence, confidentiality, supervision, candor, and reasonable fees, apply in full the moment an AI tool touches a client matter.
That reframing matters because most of the public conversation about legal AI treats it as a productivity question. For a bar association, it's a professional-responsibility question, and the two don't always point the same direction. This guide covers what the rules actually require, in plain terms, and what that means for a firm or legal department deploying AI on real client work.
ABA Formal Opinion 512, issued in July 2024, is the ABA's first comprehensive guidance on generative AI, and it doesn't create new rules. It interprets seven existing Model Rules and applies them directly to AI tools.
Model Rule | What it requires for AI use |
|---|---|
1.1 Competence | Understand the specific tool's capabilities and limits, including hallucination risk, well enough to supervise it |
1.4 Communication | Disclose AI use to the client where it's material to the representation or the client asks |
1.5 Reasonable fees | Bill for time actually spent, including AI review and verification, not a pre-AI baseline |
1.6 Confidentiality | Prevent client information from being disclosed, retained, or used to train a shared model without consent |
3.3 Candor to the tribunal | Never file AI-generated citations or quotations without independently verifying they exist and say what's claimed |
5.1 / 5.3 Supervision | Treat AI like nonlawyer assistance: verify its work product and retain ultimate responsibility for it |
5.5 Unauthorized practice | Keep client-facing AI tools from giving what could be construed as legal advice without a lawyer's review |
Rule 1.1 has always required a lawyer to have the legal knowledge, skill, and preparation reasonably necessary for a matter. Formal Opinion 512 applies that directly to AI: a lawyer doesn't need to be a computer scientist, but does need to understand a given tool's capabilities and, more importantly, its limitations, especially its tendency to generate plausible-sounding but false information.
Courts have made the consequence of skipping this step very concrete. In Mata v. Avianca, the first widely reported case of its kind in 2023, two New York attorneys were fined $5,000 after citing six nonexistent cases that ChatGPT had invented. That was not an isolated incident. Sanctions for AI-fabricated citations have continued every year since, and the penalties have grown: in Couvrette v. Wisnovsky, decided across orders in late 2025 and early 2026, two attorneys were sanctioned a combined total of over $110,000 for briefs containing fifteen nonexistent cases and eight fabricated quotations.
The pattern in every one of these cases is the same: a lawyer treated an AI-generated draft as finished work rather than as a draft that still required the verification Rule 1.1 has always demanded. "The AI got it wrong" has never been, and still isn't, a defense.
Rule 1.6 requires a lawyer to make reasonable efforts to prevent unauthorized disclosure of, or access to, client information. Formal Opinion 512 flags two specific risks this creates with AI: the possibility that a shared tool retains or trains on client data, and the possibility that several lawyers using the same general-purpose tool inadvertently expose one client's information through another's session or prompt.
In practice, that means confirming, in writing, that a vendor does not train shared models on client data, understanding exactly where that data is stored and processed, and in some circumstances securing informed client consent before using AI on their matter, particularly where the engagement involves especially sensitive information. A firm that can't answer those questions for a given tool doesn't yet have a defensible basis for putting client data into it.
Rules 5.1 and 5.3 have always required lawyers to supervise the work of nonlawyer assistants and make reasonable efforts to ensure their conduct is compatible with the lawyer's own professional obligations. Formal Opinion 512 treats AI the same way: whatever supervision a paralegal's draft would get, an AI tool's output needs at least that much, and arguably more given the specific hallucination risk involved.
"Reasonable supervision" isn't satisfied by a lawyer glancing at a finished draft. It requires a documented process: what the tool was given, what it produced, what a human checked, and what was changed before anything left the building. Without that record, a lawyer has no way to demonstrate the supervision actually happened if a client, opposing counsel, or a bar disciplinary committee later asks.
The ABA opinion sets the framework, but individual state bars regulate lawyers directly, and most have now weighed in themselves. As of early 2026, more than 47 state bars have issued formal opinions or detailed guidance on AI use, up from just 6 in mid-2023.
Florida was first, issuing Ethics Opinion 24-1 in January 2024, walking through the full set of duties, competence, confidentiality, communication, and reasonable fees, that generative AI touches. California issued its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law in November 2023, making it the earliest formal material guidance from any state bar, even ahead of the ABA. Texas Opinion 705, issued in February 2025, is explicit about the point that mattered most in the sanctions cases above: it requires human oversight of AI-generated work specifically to prevent the submission of fabricated citations. New York City Bar Formal Opinion 2024-5 covers generative AI in practice generally, and Formal Opinion 2025-6 addresses the narrower question of using AI to record, transcribe, and summarize client conversations.
The details vary by state, but the substance converges on the same four duties the ABA opinion names: competence, confidentiality, supervision, and reasonable billing. A firm operating in multiple states should check its home bar's specific opinion rather than assuming the ABA framework alone covers it.
Rule 5.5 concerns aren't limited to AI tools used internally by lawyers. They apply directly to client-facing AI, chatbots, intake tools, self-service document generators, that can produce something a reasonable person would read as legal advice. If that output isn't reviewed by a lawyer before it reaches a client, the tool risks practicing law without a license attached to it.
The safer pattern is to scope any client-facing AI tool narrowly, intake, scheduling, document collection, general information, and route anything that shades into advice on a specific person's legal situation to an attorney before it goes out. The line isn't always obvious in advance, which is why firms need to define it deliberately rather than find out where it sits after the fact.
Every requirement above points toward the same operational need: a documented, reviewable definition of exactly what an AI system is allowed to do on its own, and clear proof that a human checked its work before anything left the firm. That's precisely what an Agent Operating Procedure is built for. Instead of a system prompt buried in a vendor's configuration, an AOP is a plain-language document a managing partner or general counsel can actually read: it names which tasks the AI employee can complete unsupervised, such as drafting a first-pass redline against a defined playbook, and which ones always require a lawyer's sign-off before they're final.
That same system needs to produce a full decision audit trail as a matter of course: what the AI employee was given, what it drafted or found, who reviewed it, and what changed before it went out. That record is the concrete evidence a Rule 5.1 or 5.3 supervision inquiry, or a malpractice claim, would actually ask for.
Confidentiality obligations under Rule 1.6 also make deployment model a real decision. Firms and legal departments handling especially sensitive client data often need more than a shared SaaS tool can offer, which is why on-prem and bring-your-own-cloud (BYOC) deployment options matter here specifically, letting client data stay inside an environment the firm already controls. And because legal work is built on precedent and institutional practice, a system that accumulates a firm's own playbooks and past corrections over time, what Zamp calls a Company Brain, gets more useful with each matter instead of starting cold every time.
For the broader definition of what an AI employee is and how the model works across functions, see our complete guide to AI employees. For the operational side of AI in a legal function specifically, our guides to AI contract management and analysis and the complete guide to AI legal assistants cover what an AI employee actually does day to day, once the compliance framework above is in place.