Skip to main content
FIELD REPORT · LAWYER AI ETHICS

AI Ethics for Lawyers: State Bar Rules, Opinion 512, and a Firm AI Policy

A drafting kit for the firm AI policy your bar counsel will sign off on, mapped to Model Rules 1.1, 1.6, 5.3, and 7.1.

PUBLISHED
May 13, 2026
READ TIME
8 MIN
AUTHOR
ONE FREQUENCY
KEY FACTS
Topic
lawyer AI ethics, ABA Opinion 512, law firm AI policy
Industry
lawyers
Published
May 13, 2026
Read time
8 min
Word count
1,493

Every state bar in the country published or revised AI guidance between January 2024 and March 2026, and the convergence is real — but the practical posture for a 2-to-15 attorney firm is still confusing because the rules sit across four Model Rules, eight or nine state opinions, and a growing pile of court-issued standing orders. The result is a managing partner who knows AI is a Rule 1.1 competence obligation, suspects Rule 1.6 confidentiality might be at stake, has heard about ABA Opinion 512, and has no idea what the firm AI policy is supposed to actually say.

This piece is the drafting kit — Model Rules mapped to AI-specific controls, the firm AI policy structure, the engagement-letter language, the CLE cadence, and the bar-counsel review checklist. The broader strategic frame is in the 2026 playbook; program governance lives on /ai-enablement.

The four Model Rules that govern AI in practice

Rule 1.1 — Competence

Comment 8 to Rule 1.1 imposed a duty of technological competence in 2012. ABA Formal Opinion 512 (July 2024) clarifies that the duty now includes understanding the AI tools used in client representation — capabilities, limitations, training-data exposure, and hallucination risk. The lawyer reviewing the output owns the output. Not knowing how the tool works is not a defense.

Operational implication: every billing attorney needs documented training on the specific AI tools the firm uses, refreshed annually.

Rule 1.6 — Confidentiality

Client information cannot go into AI systems that train on inputs. Consumer tiers of ChatGPT, Claude, Gemini, and Copilot train on inputs by default. Enterprise SKUs contractually disable training. ABA Opinion 512 and most state opinions converge on the position that enterprise tiers meet the floor; consumer tiers do not.

Informed consent under 1.6(a) is the open question. Bar opinions are converging on disclosure when AI materially shapes work product — California, Florida, New York County, and New Jersey have published guidance, all pointing toward client disclosure for material uses.

Operational implication: enterprise contracts required for all client-facing AI use; engagement letters updated with disclosure language.

Rule 5.3 — Supervision of nonlawyer assistants

AI tools function as nonlawyer assistants under 5.3. The supervising attorney is responsible for ensuring the conduct of the assistant is compatible with the lawyer's professional obligations. Output requires the same review as a paralegal's first draft.

Operational implication: documented review workflow for every AI-generated artifact that touches client work product.

Rule 7.1 and 7.3 — Marketing and solicitation

AI-generated marketing content must comply with the truthfulness requirements of Rule 7.1. AI-driven outreach must not cross into prohibited solicitation under 7.3. The firm cannot use AI to manufacture testimonials, simulate client communications, or generate scaled prospect outreach that would be impermissible if a human did it.

Operational implication: marketing AI use covered in the firm AI policy with explicit prohibitions.

State opinions worth reading

  • ABA Formal Opinion 512 (July 2024). Cornerstone opinion mapping competence, confidentiality, supervision, candor, and fees to AI use.
  • California State Bar Practical Guidance (November 2023). First comprehensive state guidance; heavy on Rule 1.6.
  • Florida Bar Opinion 24-1. Disclosure and informed consent.
  • NYCLA Formal Opinion 749 (2024). Confidentiality and supervision.
  • New Jersey Supreme Court guidance (January 2024). Court filings and Rule 11 / 3.3 obligations on AI-generated citations.
  • DC Bar Ethics Opinion 388. Supervision and competence intersection.

Firm policy should reference the home-jurisdiction opinion and update annually.

The firm AI policy — the structural sections

A workable firm AI policy for a 2-to-15 attorney firm runs 8–14 pages and contains nine sections.

Section 1 — Scope and purpose

What the policy covers (all AI tools used in firm operations), what it does not (personal use on personal accounts), and the firm's stated AI posture (e.g., "we use AI to augment attorney work product, never to substitute for attorney judgment").

Section 2 — Approved tools list

A named list of approved tools with the contractual posture for each — training disabled, data residency, deletion terms, breach notification. No tool gets used on client work that is not on this list. Updated quarterly.

Section 3 — Prohibited uses

Explicit prohibitions: consumer AI tiers for client information, AI-generated case citations without verification, AI-drafted court filings without attorney review, AI-driven scaled solicitation outreach, AI-generated testimonials or reviews.

Section 4 — Confidentiality controls

Rule 1.6 implementation. How client information is segregated, what tools have access to what data, the data-loss-prevention configuration in Microsoft 365 or Google Workspace, and the consequence of policy violation.

Section 5 — Client disclosure and consent

The engagement-letter language and the threshold for additional disclosure. Most firms in 2026 use a standing disclosure in the engagement letter for routine AI use plus a matter-specific disclosure for AI-heavy work product (briefs primarily drafted by AI, AI-driven discovery review on large productions).

Section 6 — Supervision and review

The documented review workflow per artifact type. Pleadings get partner review; routine client emails get attorney review; internal memos get senior-paralegal review.

Section 7 — Training and competence

The CLE cadence (annual minimum), the tool-specific training requirement on onboarding, and the documentation standard.

Section 8 — Marketing and external communication

Rule 7.1 compliance, ghostwriting policy on partner bylines, prohibition on AI-generated testimonials, AI disclosure in marketing footers where required.

Section 9 — Incident response

What happens when something goes wrong — a hallucinated citation, a confidentiality breach, a client complaint. Reporting line, remediation steps, bar-counsel notification triggers.

Engagement-letter language

A working clause in 2026 reads roughly:

"Our firm uses generative AI tools to assist in legal research, drafting, document review, and administrative work. These tools operate under contractual confidentiality terms that prohibit training on your information. Attorney judgment and review apply to all work product. You may opt out of AI-assisted work at any time."

The clause does not itemize every tool. It establishes use, confidentiality posture, attorney responsibility, and opt-out. Firms doing AI-driven discovery on large productions should plan for matter-specific addenda.

CLE and competence

  • Onboarding training. 2 hours of AI-specific training per new attorney and paralegal.
  • Annual CLE. Most states offer (and several mandate) AI-specific CLE — Florida and New York have led.
  • Quarterly tool updates. 30-minute briefings when tools change materially.
  • Annual policy review. Managing partner plus a designated ethics partner, with bar-counsel sign-off where the firm uses outside ethics counsel.

Bar-counsel review checklist

For firms using outside ethics counsel, the annual review should cover approved-tools list and contractual posture, confidentiality controls, engagement-letter language, supervision workflows, training records, marketing materials for Rule 7.1 compliance, the incident log, and state opinions issued in the prior 12 months. The review takes 4–8 hours of outside counsel time annually — the cheapest insurance the firm buys.

How this ties into the firm AI program

The policy is the floor. The full program on /ai-enablement includes governance, training, tool selection, intake-automation workflows, and ongoing measurement. Firms that treat the policy as one-time tend to drift out of compliance within 12 months as tools get adopted ad-hoc.

FAQ

Q: Does ABA Opinion 512 require informed consent for all AI use? A: No. It requires informed consent where AI materially shapes the work product. Routine use — Westlaw AI for research, Spellbook for a first-pass NDA redline — generally falls under standing disclosure in the engagement letter. Heavy AI use — AI-driven discovery review on a major production — typically warrants matter-specific disclosure.

Q: Can a firm use the same policy across multiple state jurisdictions? A: Yes, with state-specific addenda. The core policy is largely uniform; the disclosure thresholds, CLE mandates, and any state-specific opinions get layered as appendices.

Q: What about contract-review automation — does that trigger disclosure? A: Routine AI-assisted contract review under attorney supervision generally does not require additional disclosure beyond standing engagement-letter language. The supervising attorney's judgment is the product.

Q: How does this relate to the intake workflow's compliance posture? A: Intake automation has its own compliance considerations — UPL, conflicts, confidentiality of intake content. They live under the same firm AI policy umbrella but get treated as a named workflow in the policy.

Q: What about court-issued AI standing orders? A: A growing number of federal and state courts require AI-disclosure certifications on filings. The firm policy should require attorneys to check court-specific standing orders before any filing. Westlaw and Lexis both maintain updated trackers.

Q: How does the firm handle a hallucinated citation that lands in a filing? A: Immediate withdrawal of the affected pleading, notification to the court under Rule 3.3 candor obligations, internal review for root cause, and process update. The Mata v. Avianca pattern (2023) created the operational playbook every firm should have on the shelf.


For a policy draft sized against your firm's tools, practice mix, and home jurisdiction, reach out. The cornerstone playbook is on the 2026 strategic guide; engagement scope on /ai-for/lawyers.

SOURCES

Cited and consulted.

  1. 01ABA Formal Opinion 512 — Generative AI Toolsamericanbar.org · accessed May 8, 2026
  2. 02ABA Journal — Legal Ethics Coverageabajournal.com · accessed May 8, 2026
  3. 03Lexology — Legal Ethics and AIlexology.com · accessed May 8, 2026
  4. 04Bloomberg Law — Ethics and Practicenews.bloomberglaw.com · accessed May 8, 2026
View All Insights
NEXT STEP

Ready to ship the next outcome?

One Frequency Consulting brings 25+ years of technology leadership and military discipline to every engagement. First call is operator-grade scoping — sixty minutes, no charge.