Should you use AI as a legal practitioner?

Last Updated: July 14, 2026

Whether considering case management systems, document generation platforms, or translation services, the practice of law has always required careful judgment about which tools to trust with sensitive client matters. As AI tools increasingly become a part of the legal landscape, firms may be asking the same questions that they would about any technology: Is it secure? What are our obligations? How do we use it responsibly? This guide is designed to help answer those questions. Lawyers can find information here on how ABA guidance maps onto their responsibility for client confidentiality, vetting a vendor’s data security practices, and staying compliant while using AI.


Note: ABA guidance serves as a universal baseline for lawyers’ professional and ethical responsibilities, but state bars and local courts may have different and overlapping rules, and lawyers should make sure their practice is current with them. State-by-state guidance updates can be tracked through the live tracker here.

Whether considering case management systems, document generation platforms, or translation services, the practice of law has always required careful judgment about which tools to trust with sensitive client matters. As AI tools increasingly become a part of the legal landscape, firms may be asking the same questions that they would about any technology: Is it secure? What are our obligations? How do we use it responsibly? This guide is designed to help answer those questions. Lawyers can find information here on how ABA guidance maps onto their responsibility for client confidentiality, vetting a vendor’s data security practices, and staying compliant while using AI.


Note: ABA guidance serves as a universal baseline for lawyers’ professional and ethical responsibilities, but state bars and local courts may have different and overlapping rules, and lawyers should make sure their practice is current with them. State-by-state guidance updates can be tracked through the live tracker here.

Whether considering case management systems, document generation platforms, or translation services, the practice of law has always required careful judgment about which tools to trust with sensitive client matters. As AI tools increasingly become a part of the legal landscape, firms may be asking the same questions that they would about any technology: Is it secure? What are our obligations? How do we use it responsibly? This guide is designed to help answer those questions. Lawyers can find information here on how ABA guidance maps onto their responsibility for client confidentiality, vetting a vendor’s data security practices, and staying compliant while using AI.


Note: ABA guidance serves as a universal baseline for lawyers’ professional and ethical responsibilities, but state bars and local courts may have different and overlapping rules, and lawyers should make sure their practice is current with them. State-by-state guidance updates can be tracked through the live tracker here.

Lawyers' Duty of Competence Extends to Technology 

The ABA’s Model Rules of Professional Conduct have long required lawyers to provide competent representation to their clients. What competence looks like has evolved alongside the practice itself, as new technologies have changed the baseline requirements for providing adequate representation.

“Rule 1.1 recognizes that ‘competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.’ Comment [8] explains that ‘[t]o maintain the requisite knowledge and skill [to be competent], a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technologies.’”

ABA Formal Opinion 512

The ABA goes on to say that, as AI tools continue to develop, it is possible that lawyers will eventually have to use them to competently complete certain tasks. They draw a useful analogy to illustrate this point, explaining that a lawyer today could not provide adequate legal services without knowing how to use email or create an electronic document. While this doesn’t mean that AI use is compulsory, it does mean that staying informed about these tools is part of a lawyer’s professional responsibility.

Confidentiality and Data Security

Lawyers handle some of the most sensitive personal data clients can have: passports, medical histories, financial statements, and intellectual property. The duty to protect this information doesn’t change when AI enters the picture; it just requires applying the same professional judgment to a new category of technology.

What the ABA requires

Under Model Rule 1.6, lawyers must keep confidential all information relating to client representation, regardless of its source. When inputting client data into an AI tool, they are required to evaluate the risk of unauthorized disclosure of that information.

"...[Lawyers] must make ‘reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to representation of the client…Before lawyers input information relating to the representation of a client into a GAI tool, they must evaluate the risks that the information will be disclosed to or accessed by others outside the firm."

—ABA Formal Opinion 512

In practice, this means that firms should be diligent about vetting AI vendors’ data security practices, just as they would when inputting client information into any third-party platform. It was only a few years ago when a similar conversation took place regarding the potential risks of cloud storage. The ABA provided very similar guidance to lawyers then as they do now about generative AI: lawyers are required to think carefully and deliberately about the risk of unauthorized disclosure of client information and the data security practices of the third-party system they are entrusting it to. The level of protections AI platforms provide to safeguard confidentiality depends on the vendor and who their product is intended to serve.

Free/Consumer tools carry the greatest risk

General-purpose consumer AI tools, like the free versions of large language models, are currently not designed with attorney-client confidentiality in mind. In its primary opinion on legal AI guidance, Formal Opinion 512, the ABA says that these models, which train responses on user data and then disperse those responses to others, “by their very nature, raise the risk that information relating to one client’s representation may be disclosed improperly.” Thus, an attorney using a free version of a self-learning AI model is directly at odds with their obligation to maintain client confidentiality. In that light, any AI platform used at a firm should provide verifiable zero-retention guarantees and commitments not to train publicly used models on customer data.

This idea applies to firm-wide AI adoption, as well as individual use of AI by paralegals and junior lawyers. Recently, a legal industry survey found that, within firms, individual use of AI is higher than firm-wide adoption. This means that attorneys are likely using AI tools even when their firm has not formally adopted a platform, opening up supervisory liability in cases where attorneys may be using free/public AI vendors that lack confidentiality protections.

Client prompt + file

Model retains patterns

Other users access model

What to look for in an AI vendor

The process of AI vendor evaluation should mirror the approach firms would take with any third-party software handling client data. When assessing a tool, look for:

  • No training on client data for improvement of LLMs accessible by others

  • SOC 2 certification or equivalent independent security audit

  • End-to-end encryption in transit and at rest

  • A confidentiality agreement that creates enforceable obligations

  • Clear explanations of where data is stored and who can access it

What the courts are saying: AI use and attorney-client privilege

Many legal professionals may have seen headlines about cases raising concerns around AI use and attorney-client privilege. In February 2026, two federal courts issued decisions that drew significant attention from the legal community for being among the first to address how generative AI intersects with attorney-client privilege and work product protection. In each case, the final verdict depended on the type of AI tool being used or the individual using it.

U.S. v. Heppner: Using AI without confidentiality obligations could waive the right to attorney-client privilege

In United States v. Heppner, the U.S. District Court for the Southern District of New York considered a case in which a financial services executive generated legal strategy materials using a publicly available generative AI tool without direction from his attorneys. The court denied both attorney-client privilege and work product protection. Its reasoning rested on three grounds: 

  1. The communications were not confidential under the platform’s own terms of service.

  2. They were not communications with an attorney made for the purpose of obtaining legal advice.

  3. They were not prepared at the direction of counsel or reflective of attorney mental impressions.

The court emphasized that if a generative AI platform’s privacy policy permits the collection, retention, training on, or disclosure of user inputs and outputs, there is no reasonable expectation of confidentiality. In this case, the platform’s terms expressly allowed for this, meaning that, from the court’s perspective, entering legal strategy into the tool was functionally the same as sharing it with a third party. The decision was therefore based not on the notion that any use of AI in a legal setting waives attorney-client privilege, but that this particular tool had no enforceable confidentiality obligations. 

Another important aspect of the case was that the materials were prepared by the client through an AI tool without the direction of his attorney, which waived any potential work product protection that might have applied if his lawyers had used AI to draft them. The court left the door open for a different outcome under different circumstances. It expressly noted that had counsel directed the use of the AI platform, it might have functioned “in a manner akin to a highly trained professional” acting as the lawyer’s agent, which could have supported a different privilege analysis.

Warner v. Gilbarco: AI platforms as “tools, not persons”

Warner v. Gilbarco, decided the same month by the U.S. District Court for the Eastern District of Michigan, provided similar guidance on the work-product doctrine and AI use. In this case, Warner, a non-attorney who was representing herself, used an AI platform to analyze materials related to the case. The opposing party sought to compel production of those AI-assisted materials, arguing that disclosing them to an AI platform had waived any applicable protection.

The court denied the request and upheld work product protection, reasoning that because Warner was representing herself, she was effectively functioning as her own attorney. Therefore, the materials reflected her own mental impressions prepared in anticipation of litigation. The court further asserted that generative AI platforms are “tools, not persons.” The presiding judge went on to say that if simply uploading information onto an AI platform waived protection, then this “would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed.”

U.S. v. Heppner

Public AI tool + no attorney direction = confidentiality and work-product protections failed

Warner v. Gilbarco

Pro se attorney using AI = work-product protection upheld ("tools not persons")

What these mean in practice

Heppner and Warner are only a few examples of a continuously evolving landscape around AI use, and that landscape will keep developing as more courts weigh in. However, a through line runs across these decisions: protecting client confidentiality is what matters most. Notably, neither case suggested that an attorney entering information into an AI tool inherently waives privilege or work product protection. What mattered instead was who was using the AI and what kind of tool it was. 

The practical takeaway follows from that. Attorneys should use AI vendors whose terms provide real, enforceable protections: no training on user inputs or outputs, no disclosure of user data to third parties, and the ability to retain control over and delete that data. A tool with those safeguards supports a reasonable expectation of confidentiality, whereas a platform whose terms permit training or disclosure may not.

Beyond vetting the tool, attorneys should stay aware of how this area is developing. The decisions discussed here are among the more prominent today, but they are early ones, and more opinions are bound to follow. The practitioners best positioned to use AI responsibly will be those who pair safe, well-vetted platforms with a habit of keeping an eye on what the courts continue to say.

Accuracy, Verification, and Professional Judgment

Another prominent topic in the world of AI use and law is accuracy and verification. AI can draft, summarize, research, and organize, but it can also be wrong. “Hallucinations,” or AI outputs that are factually incorrect or fabricated, are a known limitation of large language models. While these errors have become less prevalent as AI tools have advanced, the stakes of an unverified error in legal practice can be high.

What the ABA says about verification

ABA Formal Opinion 512 is clear that delegating work to AI does not eliminate the lawyer’s responsibility for its accuracy; however, it also offers practical guidance on what verification requires, which is not always a full manual review. If a lawyer uses AI to summarize several lengthy contracts, for example, the ABA says the lawyer is not necessarily required to review the entire set of contracts to verify the results, provided the lawyer has previously tested the tool’s accuracy on a smaller set of documents.

Verification matters regardless of the AI platform being used, but the ABA does offer some specific guidance about the type of vendor a lawyer relies on:

"A lawyer’s use of a GAI tool designed specifically for the practice of law or to perform a discrete legal task, such as generating ideas, may require less independent verification or review, particularly where a lawyer’s prior experience with the GAI tool provides a reasonable basis for relying on its results.”

—ABA Formal Opinion 512

In this section, the ABA draws a distinction between general-purpose consumer AI and legal-specific AI. This means that tools built for legal workflows, with legal data and attorney use cases in mind, may carry a lower baseline verification burden, particularly once you have established familiarity with the tool’s performance. 

The long-established responsibility of attorneys to verify any work they did not personally produce is a continued obligation in the presence of potential hallucinations. Lawyers can combine this diligence with testing the AI platform and becoming familiar with its capabilities to provide the most solid defense against fabricated or inaccurate citations/cases. In any case, whether reviewing documents produced by AI or paralegals, lawyers retain final judgment and verification throughout the drafting process.

When using AI, attorneys remain responsible for

  • Legal analysis and strategic decisions

  • Verification of all citations before filing

  • Final review of all court submissions and client-facing documents

  • Professional judgment on negotiations, settlement positions, and case strategy

  • Supervision of junior attorneys and non-lawyer staff using AI tools

AI drafts

Attorney verifies + edits

File

Disclosure of AI Use to Clients

Under a lawyer’s responsibility to communicate with clients about notable aspects of their representation, many have wondered whether AI use in a case marks a large enough distinction to warrant a disclosure. There is no universal ABA rule requiring disclosure every time AI is used. The ABA’s guidance under Model Rule 1.4, which requires lawyers to keep clients reasonably informed, is context-dependent. Whether disclosure is required depends on the nature of the AI use, the sensitivity of the information involved, and what a client would reasonably expect to know.

"It is not possible to catalogue every situation in which lawyers must inform clients about their use of GAI. Again, lawyers should consider whether the specific circumstances warrant client consultation about the use of a GAI tool, including the client’s needs and expectations, the scope of the representation, and the sensitivity of the information involved."

—ABA Formal Opinion 512

Much of the existing guidance on when and whether to disclose AI use remains ambiguous, and it would be misleading to suggest otherwise. What Opinion 512 does provide, though, is a set of circumstances in which client consultation is clearly warranted, even without a bright-line rule. 

Examples of instances when disclosure may be required

  • A client asks how the work was done or whether AI was used 

  • The engagement agreement or client’s outside counsel guidelines require disclosure 

  • The lawyer intends to input highly sensitive information relating to the representation into the tool 

  • The tool’s output will influence a significant decision in the legal matter, e.g., using AI to evaluate likely litigation outcomes or to inform jury selection

The ABA also suggests that AI, like other technologies such as email, electronic research, and cloud-based document storage, may become so common in the practice of law that it will be taken as a given, expected part of representation. Therefore, what feels like a notable disclosure today may soon read as a routine description of how modern legal work is done. While there isn’t a universal baseline for when disclosure is or is not required, a firm can get ahead of these questions by addressing AI use directly in its engagement agreements, as it likely already does with other technologies.

State Bar Guidance and Staying Compliant

While the ABA lays out a general framework of professional and ethical guidelines for lawyers, state bars carry the actual authority to enforce the rules of professional conduct. Many states have not yet formally addressed the use of AI, but that guidance is proliferating quickly. States, as well as local courts, may provide guidance that is distinct or overlaps with that of the ABA. The following independently maintained trackers show what guidance, if any, states and local courts have released:

State bar ethics guidance:

Court orders and local rules:

How to figure out the rules in your jurisdiction:

When lawyers want to know what the rules on AI actually are for a given matter, there are three main places to look:

  1. The ABA: The ABA Model Rules and Formal Opinion 512 set the universal framework. The ABA itself does not regulate or discipline individual lawyers, but its guidance is the foundation most states build from, and it points in the general direction lawyer conduct should follow.

  2. State Bars: This is where enforcement authority actually lives. State bars have issued both formal and informal opinions on AI, and while most track the ABA closely, some diverge on specific points like disclosure expectations, billing for AI-assisted work, and supervision requirements. Where a lawyer’s state has spoken, its guidance governs over the general ABA framework.

  3. Specific courts and judges before whom lawyers practice: Beyond bar rules, individual courts and even individual judges have issued standing orders and local rules addressing AI use in filings. 

The takeaway is that compliance here is not a fixed target; it is layered and still changing. Notably, courts are generally not saying that lawyers cannot use AI. More often, they are setting conditions on how and when it may be used: requiring, for example, that attorneys certify whether generative AI was used in a filing and confirm that any AI-assisted content was reviewed and verified by a person.

When lawyers want to know what the rules on AI actually are for a given matter, there are three main places to look:

  1. The ABA: The ABA Model Rules and Formal Opinion 512 set the universal framework. The ABA itself does not regulate or discipline individual lawyers, but its guidance is the foundation most states build from, and it points in the general direction lawyer conduct should follow.

  2. State Bars: This is where enforcement authority actually lives. State bars have issued both formal and informal opinions on AI, and while most track the ABA closely, some diverge on specific points like disclosure expectations, billing for AI-assisted work, and supervision requirements. Where a lawyer’s state has spoken, its guidance governs over the general ABA framework.

  3. Specific courts and judges before whom lawyers practice: Beyond bar rules, individual courts and even individual judges have issued standing orders and local rules addressing AI use in filings. 

The takeaway is that compliance here is not a fixed target; it is layered and still changing. Notably, courts are generally not saying that lawyers cannot use AI. More often, they are setting conditions on how and when it may be used: requiring, for example, that attorneys certify whether generative AI was used in a filing and confirm that any AI-assisted content was reviewed and verified by a person.

Local rules

State rules

ABA baseline

Summing Up

The bottom line

Responsible AI use in legal practice doesn’t require mastering every new tool or being an expert on every emerging rule; however, lawyers can stay compliant with ethical and professional guidelines by following a few durable habits that have always applied to their jobs. These habits include verifying the work that carries their name, being transparent with clients about their representation, and checking the applicable rules before they rely on a tool. Choosing an AI vendor that has enforceable protections and also one that can serve as a partner, growing with a firm on their AI journey, is equally important. 

A practical compliance checklist

Before adopting any AI tool:

  • Review the vendor’s privacy policy and confirm it does not train public models on user data

  • Confirm SOC 2 certification or equivalent security audit

  • Verify that client data is encrypted in transit and at rest

  • Establish a confidentiality agreement with the vendor

  • Check the applicable rules at all three levels: the ABA framework, the specific opinions of the state bar the lawyer belongs to, and any standing orders or local rules in the courts and before the judges where they practice

While using AI:

  • Verify all citations and legal authorities before filing

  • Maintain final decision-making authority over all documents

  • Document AI involvement where required for disclosure

  • Comply with any court-specific certification or disclosure requirements for filings

  • Train all staff (attorneys and non-lawyers) on the firm’s AI use policy

  • Monitor evolving guidance across the ABA, state bars, and local courts

Resources

The following resources are recommended for staying current on AI ethics in legal practice:

How to Contact Us

For questions about this guide or Parley's compliance features, please email us at [email protected]