Blog

AI Ethics Rules Every Law Firm Must Follow in 2026

Industrial workshop with a robotic arm welding sparks beside a metal sign reading AI ETHICS: compliance, fairness, privacy.

AI ethics for law firms is no longer a future-facing topic reserved for bar association panels and legal technology conferences. It is already part of the day-to-day reality of legal practice, client communication, digital marketing, intake, research, drafting, and firm operations.

The issue is not whether law firms can use AI. They can.

The real question is whether they can show that AI is being used responsibly, with proper attorney oversight, confidentiality protections, vendor review, client communication, and human verification. That distinction matters.

A law firm may use AI to help draft content, summarize information, improve workflows, support intake, organize marketing data, or speed up research. But if the firm does not understand the risks, supervise the output, protect client information, and document how the technology is being used, AI can quickly become an ethics problem instead of an efficiency tool.

This article is for general educational purposes only and is not legal advice. Law firms should consult their jurisdiction’s rules of professional conduct, applicable court rules, ethics opinions, and ethics counsel before adopting AI policies or workflows.

AI Ethics for Law Firms Starts With Existing Professional Duties

The most important thing to understand is that AI does not create an entirely new ethics universe for lawyers. Instead, AI brings existing professional duties into a new context.

The American Bar Association addressed this directly in Formal Opinion 512 on generative artificial intelligence tools. The opinion does not prohibit lawyers from using generative AI. It explains that when lawyers use these tools, they remain bound by the professional obligations that already govern their practice.

That means attorneys must still protect confidentiality, provide competent representation, supervise work performed under their authority, communicate properly with clients, avoid false statements, and charge reasonable fees.

In practical terms, the question is not:

“Can our law firm use AI?”

The better question is:

“Can we show that our firm used AI in a way that complied with our professional duties?”

That is the standard law firms should be thinking about before they use AI in client work, legal marketing, intake systems, website content, chatbots, email automation, advertising, or internal workflows.

The Core Duties Law Firms Should Understand

Several professional duties come up repeatedly in AI ethics guidance for attorneys. These duties are not abstract. They directly affect how a firm should use AI tools in practice and marketing.

Competence

Lawyers do not need to become software engineers to use AI responsibly. But they do need to understand the basic capabilities and limitations of the tools they use.

That includes knowing that AI tools can generate inaccurate answers, fabricate citations, misunderstand legal context, miss jurisdiction-specific distinctions, and produce confident-sounding content that still needs attorney review.

Competence means knowing enough to avoid blind reliance.

A lawyer using AI to help draft a blog post, summarize case information, review a marketing claim, or prepare a client-facing resource should understand that the output is only a starting point. It is not a substitute for professional judgment.

Confidentiality

Confidentiality may be the most obvious AI risk for law firms.

If an attorney or staff member enters client facts, case strategy, intake details, names, documents, or confidential communications into an AI tool without understanding how that data is stored or used, the firm may create a serious ethics issue.

The California Bar’s Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law specifically warns that lawyers should understand whether information entered into a generative AI tool may be used for training or otherwise disclosed. Oregon’s Formal Opinion 2025-205 similarly emphasizes the importance of understanding how AI tools handle, retain, and protect information.

For law firms, this means vendor review is not optional.

Before client information touches any AI system, the firm should know:

  1. Whether the vendor uses prompts or uploaded data to train its models
  2. Where data is stored
  3. Who can access the data
  4. Whether data can be deleted
  5. What security standards the vendor follows
  6. What contractual protections are in place

A privacy policy alone may not be enough. The firm should understand the actual contractual terms that govern the tool.

Candor and Accuracy

AI-generated content can sound polished while still being wrong. This is especially dangerous in legal work because hallucinated cases, fake citations, inaccurate legal standards, and misleading factual claims can create serious professional consequences.

Courts have already sanctioned lawyers for relying on AI-generated legal authorities that turned out to be fake. In some cases, the consequences have included monetary penalties, fee awards, reputational damage, and loss of permission to appear in a matter.

The lesson is simple: a lawyer’s signature, filing, website, ad, article, or client communication still belongs to the lawyer. If AI helped create it, that does not shift responsibility away from the attorney or the firm.

Every citation, legal claim, factual statement, advertising claim, and client-facing message should be reviewed before it is used.

Communication With Clients

AI may also raise client communication issues.

Law firms should consider when clients need to be told that AI tools are being used, especially if those tools touch confidential information, affect the way legal work is performed, record or summarize conversations, or influence costs.

The New York City Bar Association’s Formal Opinion 2025-6 addresses ethical issues involving AI tools that record, transcribe, or summarize conversations with clients. The opinion advises attorneys to obtain client consent before using AI to record a client call, consider confidentiality and privilege issues, and review any transcript or summary that may be preserved or relied upon. That is a useful reminder for all firms.

A vague reference to “technology tools” may not be enough in every situation. Clients should understand what is happening with their information when AI is involved in a meaningful way.

Reasonable Fees

AI can make certain tasks faster. That efficiency creates billing questions. The Florida Bar’s Ethics Opinion 24-1 addresses several issues related to generative AI, including confidentiality, competence, oversight, fees, and advertising. One important takeaway is that lawyers must avoid unreasonable billing practices when AI tools reduce the time required to complete certain tasks.

For example, it may be reasonable to bill for attorney review, judgment, editing, verification, and strategic work. It is much harder to justify billing a client for time spent simply learning how to use a tool or charging as if a task took hours when AI completed a first draft in minutes.

Law firms should decide in advance how AI-assisted work will be billed and documented.

Supervision

Supervision may be where many law firms face the greatest exposure. Rules 5.1 and 5.3 require lawyers with managerial or supervisory authority to make reasonable efforts to ensure that other lawyers and nonlawyer assistants comply with professional obligations. That matters because AI use often happens quietly.

An associate might use AI to summarize a memo. A paralegal might use AI to draft a client email. A marketing vendor might use AI to create website content. An intake team member might rely on an AI-generated response. A chatbot might answer questions from a potential client before anyone at the firm reviews the exchange.

If the firm has no policy, no approved tools list, no review process, and no training, it becomes much harder to show that AI use was properly supervised. The compliance burden cannot simply be pushed down to staff or outsourced to a vendor. The firm still needs oversight.

State and Local Bar Guidance Is Adding More Detail

ABA Formal Opinion 512 is a leading national source of guidance, but law firms should not treat it as the only authority. Lawyers must also review their own state rules, court rules, ethics opinions, and local bar guidance.

Several jurisdictions and bar organizations have issued especially practical AI guidance worth reviewing, including California, Florida, Texas, North Carolina, Oregon, Pennsylvania, and the New York City Bar Association.

The details vary, but the themes are consistent:

  1. Lawyers must understand the limits of AI tools
  2. Confidential client information must be protected
  3. Human review is required before AI output is used or relied upon
  4. Lawyers remain responsible for work product
  5. Vendors should be evaluated before client data is shared
  6. AI use may need to be disclosed depending on the context
  7. Billing practices must remain reasonable
  8. Advertising and marketing content must still comply with lawyer advertising rules

For example, Texas Ethics Opinion 705 makes clear that AI-generated work product may be a useful starting point, but lawyers remain responsible for the final accuracy and quality of the work.

North Carolina’s 2024 Formal Ethics Opinion 1 also emphasizes that lawyers using AI remain fully responsible for its use and impact in the client’s case.

Oregon’s Formal Opinion 2025-205 highlights confidentiality, vendor due diligence, training, supervision, and competent use.

The point is not that every state has identical requirements. They do not.

The point is that the direction is clear. Law firms should expect regulators, courts, clients, and opposing counsel to take AI governance more seriously over time.

The Ethical Risks That Catch Law Firms Off Guard

Most law firms understand that AI has risks. The problem is that the risks often show up in routine workflows that feel harmless.

A lawyer may think, “I’m just asking AI to clean up a paragraph.”

A staff member may think, “I’m just summarizing an intake form.”

A marketing partner may think, “I’m just using AI to draft website content.”

A chatbot vendor may say, “The system is only answering basic questions.”

But ethics issues often arise from exactly those ordinary uses.

Confidentiality Breaches From Unvetted AI Tools

Free or consumer-facing AI tools may have terms that allow information entered into the system to be stored, reviewed, or used to improve the product. Not every tool works the same way, and some paid or enterprise tools offer stronger protections, but the firm has to know the difference before using them with client-related data. This is why vendor vetting matters.

A law firm should not enter client facts, case details, medical records, financial information, immigration history, litigation strategy, privileged communications, or confidential intake notes into a tool unless the firm has reviewed and accepted the data handling terms.

The solution is not necessarily to avoid AI completely. The solution is to use AI with controls. That means approved tools, written policies, staff training, access limits, and clear rules about what information can and cannot be entered into AI systems.

Hallucinations and False Authority

AI hallucinations are one of the best-known risks for attorneys. A hallucination is not just a strange answer. It can be a fake case, a false quote, an invented statute, a wrong legal standard, or a misleading summary presented with confidence. For lawyers, that is especially dangerous.

A court filing with fabricated citations can lead to sanctions. A website article with inaccurate legal information can mislead potential clients. A social media post that overstates a result can create advertising concerns. An AI-generated FAQ that sounds like legal advice can create confusion about the attorney-client relationship.

Human review is not a formality. It is the safeguard.

Unsupervised AI and Unauthorized Practice Concerns

AI also raises concerns when tools communicate directly with potential clients. This is especially relevant for law firm chatbots, automated intake systems, website forms, email sequences, SMS follow-ups, and AI-assisted lead qualification workflows.

If an AI system is collecting information, answering questions, suggesting next steps, or creating the impression that legal guidance is being provided, the firm needs to be careful.

The system should not provide individualized legal advice without appropriate attorney involvement. It should not create confusion about whether an attorney-client relationship has been formed. It should not ask for sensitive information without proper privacy protections. And it should not make promises about outcomes.

This does not mean law firms cannot use automation or AI-assisted intake. They can. But the workflow should be designed to support intake, scheduling, routing, and follow-up while preserving attorney oversight where legal judgment is required.

AI Ethics Also Applies to Law Firm Marketing

Many discussions about AI ethics focus on research, drafting, discovery, or litigation. Those are important, but law firm marketing deserves just as much attention.

Marketing content can create ethics issues when it is inaccurate, misleading, unsupported, improperly uses client information, exaggerates results, or fails to include required disclaimers.

AI can make those risks easier to create at scale. A law firm might use AI to generate:

  1. Blog posts
  2. Practice area pages
  3. Attorney bios
  4. FAQs
  5. Google Business Profile content
  6. Social media posts
  7. Email newsletters
  8. Video scripts
  9. Ad copy
  10. Chatbot responses
  11. Review responses
  12. Intake follow-up messages

Each of those assets can create risk if it includes inaccurate legal claims, misleading advertising language, client-identifying details, unsupported comparisons, or content that sounds like legal advice instead of general information.

That is why law firms should treat AI-assisted marketing content with the same seriousness as other client-facing communications. The content should be reviewed for accuracy, advertising compliance, jurisdictional relevance, confidentiality, and tone before it is published.

Vendor Vetting: Questions Law Firms Should Ask Before Using AI

Every AI product used by a law firm creates a vendor relationship. Every vendor relationship creates risk if the firm does not know how the vendor handles data, accuracy, access, storage, deletion, and security.

That includes legal research platforms, drafting tools, transcription tools, document review systems, intake software, CRM platforms, chatbots, advertising platforms, and marketing agencies that use AI as part of their workflow.

Before adopting an AI tool or AI-assisted vendor, firms should ask:

  1. Does the vendor use customer inputs to train its AI models?
  2. Is that restriction written into the contract?
  3. Where is data stored?
  4. Who has access to the data?
  5. Is data encrypted in transit and at rest?
  6. Can data be deleted upon request?
  7. How is deletion verified?
  8. Does the vendor provide SOC 2, ISO 27001, or similar security documentation?
  9. What logs are kept?
  10. Can the firm control user permissions?
  11. Does the vendor support confidentiality obligations?
  12. What happens if the tool generates inaccurate output?
  13. Who reviews AI-generated work before it reaches clients, courts, or the public?
  14. What subcontractors or third-party tools are involved?
  15. Does the vendor provide documentation that the firm can keep in its compliance file?

A vendor that cannot answer these questions clearly may not be the right fit for legal workflows. For marketing vendors, the same principle applies.

If a marketing agency uses AI to create legal content, manage intake campaigns, draft ad copy, write social media posts, create chatbot responses, or summarize client-related information, the firm should understand how that AI is being used.

The ethics obligation does not disappear because the work is outsourced.

Contractual Safeguards Law Firms Should Consider

Law firms should work with counsel when drafting vendor agreements, but from a practical perspective, AI vendor contracts should address several key areas.

Non-Training Language

The agreement should state whether the vendor is prohibited from using the firm’s data, prompts, documents, client information, or outputs to train models. A verbal assurance is not enough.

Data Storage and Deletion

The agreement should explain how data is stored, how long it is retained, where it is stored, and how deletion requests are handled.

Confidentiality and Security

The vendor should commit to appropriate confidentiality and security protections. The firm should also confirm whether the vendor uses subcontractors, third-party APIs, or other tools that may touch the data.

Review and Responsibility

Law firms should be clear internally and externally that AI output is not final legal work product until it has been reviewed by a qualified attorney.

Error Handling

If AI-generated work is used in marketing, intake, drafting, or communication, the firm should know what process exists to identify and correct errors. This is especially important for law firm website content, ads, FAQs, chatbots, and automated follow-up systems.

Client Consent, Disclosure, and Documentation

Law firms should also think carefully about how AI use is disclosed to clients.

Disclosure will not look the same in every setting. A firm using AI to help organize internal marketing reports may not have the same disclosure obligation as a firm using AI to summarize client meetings or process confidential matter information.

But when AI touches client data, client communications, billing, recorded meetings, or substantive work, disclosure and consent may become much more important.

A strong engagement letter or AI addendum may include:

  1. Which categories of AI tools may be used
  2. The purposes for which the tools may be used
  3. Whether confidential information may be processed through those tools
  4. Confirmation that attorneys review AI-generated work before relying on it
  5. A statement that clients may ask questions about AI use
  6. Any available option to decline certain AI uses
  7. The firm’s commitment not to enter confidential information into public or unsecured AI systems

Law firms should not rely on vague language if the use of AI is meaningful to the client’s matter.

Specificity is safer.

Building an AI Ethics Policy for Your Law Firm

A written AI policy is one of the clearest ways a law firm can show that it is taking supervision seriously. A good policy does not need to be overly complicated, but it should be specific enough to guide real behavior.

At minimum, the policy should include:

  1. Approved AI tools
  2. Prohibited AI tools
  3. Prohibited uses
  4. Rules for confidential information
  5. Rules for client consent and disclosure
  6. Human review requirements
  7. Citation and source verification requirements
  8. Marketing content review requirements
  9. Chatbot and intake automation rules
  10. Vendor approval procedures
  11. Documentation standards
  12. Training requirements
  13. A schedule for reviewing and updating the policy

The policy should also make clear that AI output is never automatically final. Whether the output is a legal memo, a blog post, a client email, an ad, a chatbot response, or a draft FAQ, someone qualified must review it before it is used.

This is especially important for law firm marketing. A legal marketing team may know SEO, PPC, content, and conversion strategy, but the firm still needs attorney review for accuracy, ethics, advertising compliance, and jurisdictional nuance.

What This Means for Law Firm SEO, AI Search, and Content Marketing

AI ethics for law firms is not separate from digital marketing anymore.

It directly affects SEO, AI search visibility, Google Business Profile content, legal directories, attorney bios, ads, intake pages, FAQs, social content, and review management.

As AI search becomes more common, law firms will likely want more content that answers real client questions in a clear, authoritative way. That is good marketing. It can also be good client education.

But AI-assisted content needs guardrails. A law firm should avoid publishing content that:

  1. Gives jurisdiction-specific legal guidance without review
  2. Overpromises outcomes
  3. Implies guaranteed results
  4. Uses confidential client information
  5. Creates misleading comparisons
  6. Fabricates statistics or citations
  7. Sounds like individualized legal advice
  8. Fails to include appropriate disclaimers
  9. Uses AI-generated legal claims without attorney verification
  10. Is duplicated across multiple locations without meaningful review

The goal is not to make law firm content boring. The goal is to make it trustworthy.

Strong legal marketing should help potential clients understand their options, recognize when they may need counsel, and feel confident contacting the firm. It should not mislead them, confuse them, or create unnecessary ethics exposure.

Practical AI Governance Checklist for Law Firms

If your firm is using AI or planning to use it, start with a practical checklist.

1. Inventory Every AI Tool in Use

Do not assume you know what your team is using.

Ask attorneys, staff, vendors, and marketing partners to identify every AI tool involved in research, drafting, intake, communications, reporting, marketing, ads, content, chat, transcription, summaries, or workflow automation.

2. Classify the Risk

Not every AI use carries the same risk.

Using AI to brainstorm a generic blog topic is different from entering confidential case facts into a public tool. Using AI to summarize anonymous marketing data is different from using AI to summarize a recorded client call.

Classify tools by the type of data they handle and the type of output they produce.

3. Approve or Prohibit Tools

Create an approved tools list.

Also create a prohibited tools list, especially for systems that should not receive confidential client information.

4. Require Human Review

Set a clear rule: AI output must be reviewed before it is used, relied upon, sent, filed, published, or shared.

5. Review Vendors

Do vendor due diligence before signing with AI-assisted software platforms, marketing agencies, intake providers, chatbot companies, transcription tools, and CRM systems.

6. Update Client Disclosures

Review engagement letters, privacy policies, website disclaimers, intake forms, and consent language to determine whether AI-related disclosures are needed.

7. Train the Team

Do not assume attorneys and staff understand AI risks.

Training should cover confidentiality, hallucinations, prompt safety, client consent, billing, marketing content, advertising rules, and review requirements.

8. Revisit the Policy Regularly

AI tools change quickly. Bar guidance is also evolving.

A policy created today should not sit untouched for years. Build a review schedule and update the policy when tools, rules, or workflows change.

The Bigger Takeaway

AI ethics for law firms is not about avoiding technology. It is about using technology in a way that protects clients, protects the firm, and preserves professional responsibility.

The firms that handle this well will not simply be the ones using the newest tools.

They will be the ones that can clearly explain:

  1. Which tools they use
  2. Why they use them
  3. What data those tools touch
  4. How client information is protected
  5. Who reviews the output
  6. How errors are prevented
  7. How vendors are vetted
  8. How clients are informed when needed

That level of governance may become a competitive advantage.

Clients are becoming more aware of AI. Courts are paying attention to AI-generated filings. Bar associations are publishing guidance. Marketing platforms are adding AI features. Intake systems are becoming more automated. Search engines and AI answer tools are changing how potential clients find law firms.

Law firms do not need to panic. But they do need a plan.

If your firm is using AI in marketing, content, intake, advertising, CRM workflows, or client communication, the safest path is to build those systems around confidentiality, attorney review, vendor accountability, and clear documentation from the beginning.

Thrive Business Marketing designs AI-assisted marketing workflows with attorney confidentiality, review, and compliance concerns in mind. Through the CaseFlow System, Thrive helps law firms connect visibility, content, lead capture, intake follow-up, CRM workflows, and reporting in a more organized way.

AI can support law firm growth. But for law firms, growth systems should be built with professional responsibility in mind from the start.

Frequently Asked Questions About AI Ethics for Law Firms

What does ABA Formal Opinion 512 say about AI ethics for law firms?

ABA Formal Opinion 512 explains that lawyers who use generative AI remain responsible for complying with existing professional obligations, including competence, confidentiality, communication, candor, supervision, and reasonable fees. The opinion does not ban AI use, but it makes clear that lawyers must use AI responsibly and with appropriate oversight.

Do law firms need a written AI ethics policy?

A written AI policy is strongly recommended. It helps document how the firm supervises AI use, which tools are approved, which uses are prohibited, how confidential information is protected, and when human review is required. A written policy can also support training and vendor management.

Can lawyers use AI to write website content or blog posts?

Lawyers and law firms may use AI as part of the content creation process, but AI-generated marketing content should be reviewed before publication. The review should check legal accuracy, advertising compliance, confidentiality, jurisdictional relevance, and whether the content could be misunderstood as legal advice.

What is the biggest confidentiality risk when law firms use AI?

One of the biggest risks is entering client information into AI tools without knowing whether that information may be stored, reviewed, or used to train the system. Law firms should review vendor terms before allowing client-related information to be entered into any AI tool.

Should law firms disclose AI use to clients?

Disclosure depends on the context, jurisdiction, and how AI is being used. If AI touches client information, records or summarizes client conversations, affects substantive legal work, or has billing implications, the firm should carefully evaluate whether specific disclosure or consent is needed.

Can law firms use AI chatbots for intake?

Law firms can use chatbots and automation to support intake, scheduling, routing, and follow-up, but they should be careful that the system does not provide individualized legal advice without attorney oversight. Chatbots should be designed with confidentiality, disclaimers, data handling, and review procedures in mind.

What should law firms ask AI vendors before using their tools?

Law firms should ask whether the vendor uses customer inputs to train models, where data is stored, who can access it, how deletion works, what security certifications exist, what logs are kept, and whether the vendor contract includes confidentiality and data protection commitments.

How does AI ethics affect law firm marketing?

AI ethics affects law firm marketing because AI can be used to generate website content, ads, social posts, FAQs, chatbot scripts, intake responses, review responses, and email campaigns. Each of those assets can create risk if it contains inaccurate legal claims, misleading advertising language, confidential information, or unreviewed AI-generated guidance.

Suggested References

For firms that want to explore the issue further, the following resources are useful starting points:

ABA Formal Opinion 512 on Generative Artificial Intelligence Tools

California Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law

Florida Bar Ethics Opinion 24-1

Texas Ethics Opinion 705

North Carolina 2024 Formal Ethics Opinion 1

Oregon Formal Opinion 2025-205

New York City Bar Formal Opinion 2025-6

Justia’s AI and Attorney Ethics Rules 50-State Survey

Are You Ready To Thrive?

Or send us a message

Name(Required)

Below you agree to our Privacy Policy and Terms of Service.

Categories