Blog

AI Risks for Law Firms Every Attorney Must Know in 2026

Clay-model man at a laptop surrounded by AI-risk icons (data breach, inaccurate output, ethical risks, client confidentiality, liability) with law books and a gavel nearby.

AI risks for law firms are accelerating faster than most practices are building the guardrails to manage them. The exposure from AI tools in legal practice is real, documented, and already generating sanctions, bar complaints, and client disputes, cases like Mata v. Avianca, Inc. and United States v. Cohen make that concrete. Attorneys who assume existing malpractice coverage or bar compliance habits will absorb new technology liability may be operating on a false premise; insurers are increasingly scrutinizing AI-related errors, and policy exclusions in this area are an emerging risk worth verifying with your carrier.

At Thrive Business Marketing, we work exclusively with law firms on their digital presence and marketing systems. That front-row seat to how legal teams actually implement AI in day-to-day operations reveals a consistent pattern: technical adoption outpaces policy, and the policy gap is where liability accumulates. The risks don’t sit in one corner of the firm. They span three distinct zones: practice management, client communication, and marketing.

This article maps the specific AI risks in each zone and gives you a framework you can act on immediately, not just awareness of a problem that already exists.

Why AI risk is now a professional liability issue, not just a tech concern

The ABA issued Formal Opinion 512 in July 2024, and it settled any ambiguity about whether generative AI falls under existing ethical obligations. It does. The duties of competence, confidentiality, and supervision now explicitly extend to AI tools. Florida Bar Ethics Opinion 24-1, NYCBA Formal Opinion 2024-5, and guidance from state bars in California and Illinois followed, each reinforcing the same core principle: using AI without understanding how it handles data is already an ethics violation in progress.

The duty of competence has expanded in a specific direction. Attorneys must now understand not just the law, but how their tools handle data. Whether the AI tool you use trains on your inputs, shares queries with third parties, or stores confidential material on external servers is a competence question, not an IT question. If you can’t answer it, you’re not in compliance.

Bar rules require supervising non-lawyer assistants. ABA Formal Opinion 512 makes clear that AI vendors now fall into this category. Firms that adopt AI tools without vetting the vendor, defining escalation protocols, or establishing review checkpoints are effectively supervising no one, and that supervision gap creates direct exposure if something goes wrong with the output.

AI risks for law firms in practice management: hallucinations and hidden liability

The highest-visibility AI risk for law firms is an AI system generating plausible but entirely fabricated case law. Mata v. Avianca, Inc. in 2023 made this concrete: attorneys were sanctioned $5,000 and required to complete AI-focused CLE after submitting nonexistent judicial opinions created by ChatGPT. In 2024, United States v. Cohen repeated the pattern with Google Bard-generated hallucinations. These aren’t outliers. They’re a predictable outcome of using generative AI without verification protocols built into the workflow.

Hallucinated citations aren’t flagged by the AI. They arrive with the same confident tone as accurate ones. Blind reliance on AI output is a direct breach of the duty of candor to the tribunal and the duty of competence to the client. Courts have made this explicit across multiple rulings, and the sanctions record is growing. Through 2025, documented consequences include disqualification from cases, public reprimands, and mandatory bar referrals, in addition to monetary fines.

Shadow AI: the silent confidentiality threat

A quieter risk runs through most firms without triggering any visible alert: shadow AI. Attorneys and staff using personal ChatGPT accounts or free consumer tools on client matters create confidentiality breaches the firm doesn’t know are happening. There’s no audit trail, no vendor agreement, no data processing terms, and no way to confirm where client information traveled once it entered a public AI interface. This is how serious privilege problems develop silently.

Client communication and confidentiality: where disclosure breaks down

When client data enters an AI tool, the threshold question isn’t just security, it’s consent. NYCBA Formal Opinion 2025-6 addressed AI transcription and summarization of client calls directly: attorneys must obtain informed consent before recording and must verify transcript accuracy before relying on those summaries. NYCBA Formal Opinion 2024-5 goes further, stating that without explicit client consent, New York attorneys cannot input confidential information into open AI systems that share data with third parties.

The distinction between open and closed AI systems matters practically. Open systems, which include most consumer-facing tools, send queries to external servers, may use those queries for model training, and provide no guarantee of data isolation. Closed or enterprise systems provide contractual data segregation, specific security certifications, and defined data retention terms. Based on current state bar guidance including ABA Formal Opinion 512, Florida Bar Ethics Opinion 24-1, and NYCBA Formal Opinion 2024-5, attorneys should treat open or self-learning systems as off-limits for confidential client data absent explicit informed consent. Using a consumer-grade interface for client work without that consent doesn’t meet the threshold, regardless of how the attorney uses the output.

ABA Opinion 512 is explicit on one specific point that trips up many firms: boilerplate language in engagement letters does not satisfy the informed consent requirement for self-learning AI tools. The consent must name the specific tool, describe the specific data being entered, explain the actual risks including potential data exposure, and outline the safeguards in place. General language acknowledging that “technology may be used” fails this standard entirely.

AI risks for law firms in legal marketing: bias, data leakage, and advertising ethics

Most attorneys focus AI risk concerns on practice management tools and overlook the marketing stack entirely. That oversight is expensive. AI-driven advertising platforms use demographic and behavioral data that can produce discriminatory audience selection. The Florida Bar issued 127 ethics complaints in 2024 involving AI-generated ads, with discriminatory targeting and missing disclaimers among the documented violations. The algorithm’s intent is irrelevant under bar advertising rules; the outcome determines the exposure. For a broader look at how firms can use AI effectively while keeping humans in the loop, see AI-infused marketing.

Content tools used by generalist marketing agencies present a separate category of risk. These tools routinely generate hallucinated statistics, unverifiable case outcomes, and superlative language. Under bar advertising rules, a law firm cannot run ads claiming “best results” or citing case outcomes without a specific, verifiable basis. AI-generated marketing content that a non-legal agency publishes without bar advertising knowledge can create immediate ethics exposure for the firm whose name appears on the ad. Platform-level failures and vendor behavior can amplify those risks, see Meta’s double-edged approach to AI for an illustration of how platform choices increase exposure.

Data leakage through your marketing stack deserves a specific audit. Many AI marketing platforms train their models on user data, which can include intake form submissions, CRM records, and campaign performance data connected to prospect information. If your marketing vendor’s AI is ingesting data from your intake forms or client inquiry pipeline, sensitive prospect information may be feeding external model training without your knowledge or consent. This is a confidentiality exposure hiding in what looks like a routine marketing integration. Guidance on overcoming AI bias in advertising also outlines steps agencies and firms can take to minimize discriminatory targeting while protecting data.

How Thrive’s CaseFlow System handles AI marketing without the exposure

Thrive Business Marketing built the CaseFlow System specifically for law firms, which means the architecture accounts for legal-industry risks from the start. Client intake data, case inquiries, and prospect information flowing through CaseFlow operate in controlled environments. That data doesn’t connect to external AI training pipelines, and attorneys maintain visibility over what’s being used and why.

CaseFlow uses AI assistance for targeting and optimization, but human review governs all content output before publication. No hallucinated case results, no fabricated attorney credentials, no superlative language that triggers bar advertising rules. A human with direct knowledge of those rules reviews final output before anything goes live. That single checkpoint substantially reduces the category of risk that generalist agencies often don’t recognize exists.

A generalist agency running AI content at scale has no institutional knowledge of bar advertising compliance. They’re running the tool, not evaluating the output against your state’s ethics guidelines. Thrive’s background in legal marketing means bar advertising compliance is built into the review process, not researched after a complaint is filed.

A practical risk control framework every firm can start this week

Awareness of these risks requires documented action, not just general concern. The following framework draws directly from ABA Opinion 512, current bar guidance, and vendor contract standards.

Vendor due diligence non-negotiables

Before adopting any AI tool, require written confirmation that client data will not be used for model training. Get documentation of all third-party subprocessors. Confirm SOC 2 or ISO 27001 certification, and secure contractual indemnification for IP infringement or data breaches caused by the AI’s output. If a vendor won’t provide these assurances in writing, treat the refusal as a disqualifying red flag.

Internal policy and verification protocol essentials

Every firm needs a written AI use policy that defines approved tools by name, prohibits inputting PHI, PII, or privileged material into unapproved systems, and requires independent verification of every AI-generated citation against primary sources such as Westlaw or LexisNexis before any filing or client communication. Per ABA Formal Opinion 512, that verification step is not optional, it’s a component of competent representation. The policy must also address shadow AI explicitly, naming personal or consumer-grade tools as prohibited for any client-related work.

Client consent language must name the specific AI tool and describe the specific data type being processed. Per ABA Formal Opinion 512, “Technology may be used” in an engagement letter does not meet the standard. The consent must be specific, documented, and retained in the matter file. Every workflow that uses AI should also include an audit trail: who used the tool, what data was submitted, what review was completed, and who approved the final output. That documentation is your defense if the process is ever challenged.

AI obligations are extensions of existing duties, not new ones

The duty of competence now includes understanding how your tools handle data. The duty of supervision now extends to vendors. The duty to protect client confidentiality doesn’t pause because an AI tool is faster or cheaper to use. These obligations existed before generative AI arrived, and they didn’t become optional when it did.

All three risk zones covered here, practice management, client communication, and marketing, require active and documented controls. Most firms have at least reviewed practice management risks after the Mata v. Avianca headlines. Far fewer have audited their marketing stack for the same category of exposure, and that’s where many practitioners expect the next wave of bar complaints to emerge.

If you’re ready to address the AI risks your law firm’s marketing stack is carrying right now, Thrive Business Marketing can help. The CaseFlow System was built for this environment, with privacy-first architecture, human-reviewed content, and bar advertising compliance embedded in the process. Contact Thrive to walk through how the CaseFlow System addresses the specific risk zones covered here, and how your firm can use AI where it genuinely helps without passing hidden liability to your clients or your license.

Are You Ready To Thrive?

Or send us a message

Name(Required)

Below you agree to our Privacy Policy and Terms of Service.

Categories