Yes, lawyers can use AI. The ABA said so directly in Formal Opinion 512, issued July 2024 on generative AI, and dozens of state bars have published guidance since. No ethics rule anywhere tells you to avoid AI. The rules tell you to be competent with it, keep client information confidential, supervise what it produces, never mislead a court with what it wrote, and charge fairly for the time it saves.
That distinction matters, because the lawyers who get in trouble are almost never the ones who used AI. They are the ones who filed what it wrote without reading it.
I run 10 law firms. AI touches intake, document review, demand letter drafting, and client communication at every one of them. The ethics side is not a philosophical problem. It is an operations problem with five parts, and each part has a fix you can put in place this week.
The five duties, and what each one means at your desk
| Duty | Rule | What it means for daily AI use | The safeguard |
|---|---|---|---|
| Competence | 1.1, comment 8 | You must understand what the tool does well and where it fails. You do not need to be an engineer. | Use the tool yourself for 30 days before anyone else on staff does |
| Confidentiality | 1.6 | Tools that train on your inputs are the risk. Client facts go in, and you no longer control them. | Paid business or enterprise plans with no-training terms; get client consent where the information is sensitive |
| Supervision | 5.1, 5.3 | AI output is treated like work from a nonlawyer assistant. You stay responsible for all of it. | Named reviewer on every AI-assisted document before it leaves the firm |
| Candor | 3.3 | Hallucinated citations are the sanctions machine. Courts have zero patience for this. | Every cite pulled and read in Westlaw, Lexis, or the actual reporter before filing |
| Fees | 1.5 | You cannot bill an hour for a task AI finished in a minute. | Bill review time, not phantom drafting time; move repeat work to flat fees |
Competence
Comment 8 to Model Rule 1.1 says you should keep up with the benefits and risks of relevant technology. Generative AI is relevant technology now. The bar is understanding, not expertise. You should be able to explain, in a sentence, why the tool sometimes invents a case citation. If you cannot, you are not yet competent to supervise its output, and that is fixable in an afternoon. The roadmap on this site walks through the order that actually builds that understanding.
Confidentiality
Rule 1.6 is where most firms have a real gap. Free consumer AI accounts often retain inputs and may use them to improve the model. Paid business and enterprise plans from the major providers say the opposite in their terms, and that is the line that matters. Read the terms, save a PDF of them, and put the approved tools on a list.
Whether you need client consent before entering client information is a judgment call that depends on what you are entering and how protected the tool is. Entering a public court filing is different from entering a client’s medical history. When in doubt, get consent, or strip the identifiers first.
Supervision
Rules 5.1 and 5.3 already tell you how to think about this. AI is assistance from a nonlawyer. You review the work, you correct it, you sign it, you own it. Nothing about that framework is new. The volume is what is new, which is why the review step has to be assigned to a person by name rather than left as everybody’s job.
Candor to the tribunal
Rule 3.3 is the one that ends careers. In Mata v. Avianca (S.D.N.Y. 2023), lawyers filed a brief with citations ChatGPT had fabricated, doubled down when questioned, and drew sanctions plus national press coverage. More sanctions orders have followed in several jurisdictions since, with the same fact pattern every time.
The rule at my firms is short: no citation goes into a filing unless a human pulled it up and read it in Westlaw, Lexis, or the reporter. Not a summary. The case. This is non-negotiable, and it is the single policy that prevents almost every AI disaster you have read about. If you want research output you can actually check, purpose-built legal research tools that link to primary sources beat a general chatbot for this specific task.
Fees
Rule 1.5 requires reasonable fees. If AI turns a three-hour memo into forty minutes of review, the hourly client gets a forty-minute bill. That is uncomfortable for hourly firms and it is also clearly the rule. It is one of the better arguments for flat fee and contingency work, where efficiency gains stay with the firm that built them.
Do you have to tell clients?
Most guidance says there is no general duty to disclose routine AI use, the same way you do not disclose that you used a word processor or a research database. Disclosure becomes necessary when the use is material to the representation, when your engagement agreement or the client’s instructions require it, or when you would be putting confidential information into a tool without adequate protection.
The clean solution is to handle it once, in writing, at the start:
Use of technology. The Firm may use software tools, including
artificial intelligence tools, to assist with legal research,
drafting, document review, and administrative work. All work
product is reviewed by a licensed attorney who remains
responsible for it. The Firm uses only tools whose terms
protect the confidentiality of client information.
Sophisticated clients increasingly ask about this anyway. Having the clause already there reads as competence rather than as a confession.
Advertising rules apply to AI content too
Everything your bar says about lawyer advertising applies to marketing that AI wrote or generated. No false or misleading statements, no unsupported comparisons, no promises of results, required disclaimers still required. The tool does not change the rule.
One newer wrinkle: a growing number of states now require disclosure when an ad uses AI-simulated imagery, voices, or actors. If you are producing avatar videos or synthetic voiceover, check your state before it runs.
Building your firm’s AI policy
One page. Seven items.
- Approved tools, listed by name, with the specific plan tier that has no-training terms.
- Prohibited inputs: client identifiers, medical records, settlement figures, privileged communications, anything sealed. Say it explicitly.
- Verification requirements: every citation checked in a primary source, every factual claim traced to a document in the file.
- The named reviewer for each category of AI-assisted work, and the rule that nothing leaves the firm unreviewed.
- Billing rules: what gets billed, what does not, and which matters move to flat fee.
- Training: who gets trained, on what, and how often it repeats.
- Who to ask when something is unclear, by name, so nobody guesses.
Print it, sign it, review it every six months. State guidance is moving fast, so check your own bar’s current position rather than relying on anything you read a year ago, including this page. California, Florida, New York, New Jersey and many others have published guidance, and it changes. None of this is legal advice, and I am not your lawyer.
Do this today
Open the terms of service for whatever AI tool your staff is already using, whether you approved it or not. Find the sentence about training on customer data. If it is not the answer you want, upgrade the plan or ban the tool this week. Then write item 3 of the policy above, the verification rule, and send it to your whole team by email so there is a record. Those two moves close the gap that produces almost every sanction order.
If you have not picked a primary tool yet, start with Claude on a paid plan and read the data terms first.