A first-year associate pasted “summarize this brief” into a consumer chatbot. Two citations did not exist. The motion went out. The judge noticed.
That story stopped being rare in 2024. Bar counsel built intake forms specifically for AI misconduct complaints.
Mata v. Avianca started the public record. Park v. Kim extended it. Dozens of quieter sanctions across state and federal courts have done the rest.
The tool did not violate the rule. The attorney did.
2026 is the year formal guidance becomes practical enforcement:
- State bars have published opinions.
- Court rules have been amended.
- Disciplinary boards are working through their first real backlog of AI complaints.
This guide translates current state bar AI rules for lawyers into operational decisions. Workflow, intake, billing, supervision, and your firm website. Written for managing partners, founders, compliance attorneys, and legal operations leaders.
Where State Bar AI Rules for Lawyers Came From
The American Bar Association published Formal Opinion 512 in July 2024. It became the operational baseline for every state bar that followed.
ABA 512 treats generative AI as a stress test on five duties lawyers already carry:
- Competence.
- Confidentiality.
- Communication.
- Candor.
- Supervision.
State bars built on the foundation quickly:
- California: practical guidance, late 2023.
- Florida: Ethics Opinion 24-1, early 2024.
- New York: AI disclosure rules in filings after Mata v. Avianca.
- North Carolina State Bar: 2024 Formal Ethics Opinion 1.
- Texas, Arizona, Michigan, Oklahoma: court rules, task force reports, committee opinions.
Where the trackers live:
- Bloomberg Law: active guidance comparison.
- Justia: running 50-state survey.
- State bar ethics pages: primary sources.
There is no jurisdiction left where a lawyer can claim AI ethics uncertainty.
The conversation moved from “should lawyers use AI?” to “show me your written policy, your approved tool list, your verification log, and your supervision records.”
A different question. It asks for a different answer.
The Five Lawyer Duties Behind Every State Bar AI Rule
Every state bar AI opinion published since ABA 512 maps onto five Model Rules. These are the load-bearing walls.
Competence Under Rule 1.1: Knowing Your AI Tools
Rule 1.1 requires reasonable knowledge of relevant technology. ABA Comment 8 made it explicit in 2012. Generative AI tightened the requirement.
Competence now means understanding:
- What an AI tool does.
- How can it fail?
- Where its outputs require independent verification.
How the failure plays out:
- An associate uses a consumer chatbot to draft a motion.
- Citations get copied without checking.
- Partner signs the filing.
- Citations are hallucinated.
- Sanctions follow, supervision is called into question, and the firm bears the record.
Mata v. Avianca is the canonical example. Park v. Kim extended the same logic.
What your firm operationalizes:
- Baseline training requirement.
- Approved tool list.
- Verification rule for every AI-generated citation or factual claim.
- Written acknowledgment from every attorney and staff member who uses AI.
Confidentiality Under Rule 1.6: Client Data and AI Inputs
Confidentiality covers everything related to representation. Entering client information into an AI may constitute a disclosure if the tool stores, trains on, or transmits that data outside controlled environments.
The disclosure is often invisible. A junior associate pastes a confidential memo into a consumer chatbot. The “summarize this” prompt just transmitted privileged information to a third-party data vendor that retains it for model training.
Enterprise vs. consumer:
- Enterprise: zero-retention terms, no model training on customer data, SOC 2 attestation, contractual confidentiality.
- Consumer free-tier: none of those protections, and the terms of service usually contemplate using inputs to improve the model.
Case management software with embedded AI raises the same questions:
- Where does the inference run?
- Under what retention terms?
- Who has access?
What your firm operationalizes:
- Approved tool list scoped by data sensitivity.
- Written confidentiality reviews for every AI tool and embedded AI platform.
- Vendor due diligence documentation.
- Hard rule: no confidential client information in any public model.
Communication Under Rule 1.4: Disclosing AI Use to Clients
Rule 1.4 requires keeping the client reasonably informed about means of representation. State bars diverge on AI, but the trend points toward more disclosure.
Two broad camps:
- Strict: California, Florida, and others treat material AI use as a Rule 1.4 issue when it meaningfully affects work product, cost, or confidentiality posture.
- Situational: others stop short of a blanket mandate, expect disclosure when a reasonable client would want to know.
Billing transparency runs straight through this. If AI compressed three hours of work into thirty minutes, billing the full three hours is a problem under both Rule 1.4 and Rule 1.5.
What your firm operationalizes:
- Engagement letter section addressing AI use generally.
- Client-specific disclosure for sensitive matters.
- Billing that reflects actual time and value.
Candor Under Rule 3.3: Verifying AI-Generated Citations
Rule 3.3 prohibits knowingly false statements of fact or law to a court. Verification applies to anything you submit, regardless of who or what drafted it.
Hallucinated citations are the textbook Rule 3.3 problem in 2026. Federal and state judges have issued standing orders requiring AI disclosure or verification certifications.
The common failure pattern:
- An attorney uses an AI research tool.
- Accepts a confidently cited case without checking Westlaw or Lexis.
- Include it in a brief.
- The case is real, the holding is misstated.
- The opposing party catches it.
- Discussion now involves both Rule 3.3 and Rule 1.1.
What your firm operationalizes:
- Every AI-sourced citation and factual claim is independently verified before it leaves the firm.
- Verification is logged.
- No exceptions for urgency.
Supervision Under Rules 5.1 and 5.3: Managing AI Like Staff
Supervision binds partners to the conduct of subordinate attorneys and non-lawyer staff. AI sits inside that obligation.
Generative AI acts like a non-lawyer assistant:
- Fast.
- Confident.
- Incapable of recognizing its own errors.
Rule 5.3 historically covered paralegals, contract attorneys, and outside vendors. AI tools and data management vendors now fall in the same frame.
A managing partner who has not approved tools, documented training, or written a verification procedure is short of Rule 5.1 in 2026.
What your firm operationalizes:
- Written AI policy signed by leadership.
- Designated AI compliance lead (partner or senior associate).
- Quarterly review of approved tools and incidents.
- Supervision protocols for any matter involving AI-generated work product.
State Bar AI Rules: A State-by-State Breakdown
The duties are universal. The specifics shift by jurisdiction.
- California: practical guidance from late 2023. Strict confidentiality language. Client disclosure is situational.
- New York: aggressive after Mata v. Avianca and Park v. Kim. Several judges require AI disclosure in filings. The NYSBA 2024 report sets a high standard of competence and supervision.
- Florida: Ethics Opinion 24-1, one of the earliest detailed opinions in the country. Addresses confidentiality, provider oversight, fee billing, and client consent for material use of AI.
- Texas: moved through court rules and the State Bar Task Force on AI and the Law. Federal judges in Texas were the first to require AI certifications in filings.
- Arizona: committee guidance on competence, confidentiality, and fees. Pragmatic, treats AI as a tool category that triggers existing duties.
- Michigan: existing rules of professional conduct plus committee opinions. Focus on competence and confidentiality.
- Oklahoma: guidance through articles and CLEs. Leans on ABA 512. Written for solo and small-firm practitioners.
- North Carolina State Bar: 2024 Formal Ethics Opinion 1. Clear focus on confidentiality, billing, supervision, and competence. Often cited as a model for internal policy.
- Illinois: the Attorney Registration Disciplinary Commission has issued enforcement guidance reinforcing the rules of professional conduct for attorneys using artificial intelligence tools.
Divergence points worth tracking:
- Informed consent expectations.
- Confidentiality thresholds (enterprise vs. consumer lines drawn differently).
- Supervision language (some states explicitly extend 5.3, others do not).
- Disclosure expectations vary by judge, not just by state.
Multi-state firms should follow the strictest applicable standard.
Where Lawyers Find Authoritative AI Resources
State bars are publishing more than opinions. They are publishing operational resources that every attorney can use this week.
Toolkits, Websites, and Bar Association Programs
Most state bar associations now host an artificial intelligence toolkit on their websites. Expect a landing page, a member registration page for CLEs, a link to the law library, and self-help guides for solo and small-firm practice.
The North Carolina State Bar, the Illinois Attorney Registration Disciplinary Commission, and the State Bar of California each maintain a dedicated artificial intelligence program. The North Carolina State Bar toolkit is among the most operational, and its member registration page funnels attorneys straight into CLE credit.
These toolkits typically cover:
- Best practices for generative artificial intelligence inside daily artificial intelligence practice.
- Court rules, court rules amendments, and standing orders on artificial intelligence tools, by jurisdiction.
- Sample written policies, AI tools verification checklists, and toolkit templates aligned with the rules of professional conduct.
- Trust account management programs and trust accounting guidance for fee disputes that touch AI.
- Data privacy guidance for client information, AI tools, and data management vendors.
- Lists tied to each state’s certified lawyer referral service, and intake links for the certified lawyer referral service program in states that screen for AI competence.
- Best practices around the human or machine question when reviewing AI-generated work.
How the Attorney Registration Disciplinary Commission and Peer Bodies Use These Resources
When bar counsel investigates an artificial intelligence law complaint, the investigator often starts from the same artificial intelligence practice resources every attorney should already be reading. The Illinois Attorney Registration Disciplinary Commission has published guidance on generative artificial intelligence and the rules of professional conduct. The Attorney Registration Disciplinary Commission is one of several enforcement bodies that track AI-related complaints in their annual reports.
State bar websites in California, Florida, New York, and Texas surface similar updates on artificial intelligence programs and generative artificial intelligence advisories for any attorney building an artificial intelligence practice. The license fee notice and registration renewal cycle in many states now includes attestation language about competence with artificial intelligence tools.
Government law offices and prosecutors face parallel guidance from their own ethics committees. Government law offices have also begun publishing internal generative artificial intelligence policies that mirror private-firm posture. The Attorney Registration Disciplinary Commission and similar bodies will continue to refine how the rules of professional conduct apply to artificial intelligence law in 2026.
Beyond the Bar Websites
An attorney serious about an artificial intelligence practice should also track:
- Bar association websites and bar association newsletters that interpret the rules of professional conduct, including the ABA Center for Innovation.
- Local law library access for federal and state court rules and judicial standing orders shaping day-to-day artificial intelligence practice.
- Practitioner chat rooms, listservs, and moderated chat rooms on bar association websites.
- Subject-specific chat rooms for AI ethics, run by state and specialty bar associations.
- Email alerts from your state bar AI committee, including events such as the Florida Bar Annual Meeting at the Amelia Island Resort Spa.
- Vendor documentation for case management software with embedded AI tools.
- Generative artificial intelligence (GAI) vendor pages with security attestations and retention terms, plus generative AI release notes.
- Best practices memos shared on firm intranets and bar association websites.
A practitioner who can name three artificial intelligence tools, two state bar AI resources, and one written generative artificial intelligence policy for daily artificial intelligence practice is functionally competent under Rule 1.1. An attorney who cannot is exposed.
10 AI Compliance Moves That Keep Your Firm Off Bar Counsel’s Desk
An operational layer that your firm can run this quarter.
- Approved Tool List. Written, with permitted use cases, data sensitivity tier, and known limitations. Anything off-list is off-limits.
- Written AI Policy. Five pages, not forty. Cover scope, approved tools, prohibited inputs, verification rule, supervision, billing posture, disclosure rule, and incident reporting.
- Quarterly Review Cadence. Vendor terms update. New models ship with different retention defaults. Quarterly keeps it current.
- Verification Procedures. Every AI-generated citation, statute, regulation, or factual claim is independently verified and logged at the matter level. Same rule for paralegals.
- Training Refreshes. Annual minimum, quarterly micro-updates for significant changes. Documented attendance.
- Billing Policies. Reflect on time spent, value delivered, and AI assistance that meaningfully affected the deliverable. Several bars now treat opaque AI billing as a Rule 1.5 issue.
- Confidentiality Reviews. Every tool that touches client data is reviewed before approval and re-reviewed annually.
- Data Retention Checks. How long is the data stored? Does the customer segregate it? What is the deletion policy?
- Vendor Due Diligence. Treat AI vendors like outside counsel: ownership, security posture, sub-processors, jurisdiction, indemnification.
- Data Privacy Posture. A short memo on each approved tool, kept current, lives with the approved tool list.
Your Law Firm Website as AI Compliance Infrastructure
Your website is a compliance infrastructure. Bar counsel can review it in under a minute.
Where Firms Create Ethical Exposure
- Marketing Claims (Rule 7.1): “AI-powered legal strategy” can read as if the tool were practicing law.
- AI Chat Widgets: They can appear to be legal advice. “Do I have a case?” needs a tight scope, clear handoff, and disclaimers.
- Unauthorized Practice Risk: the firm owns the outcome, even when a vendor built the widget.
- Attorney Bios and Case Results: AI can invent credentials and outcomes. Source from the attorney, verified.
- Intake Forms (Rule 1.6): confidential data flows in. Weak third-party retention controls start the risk at your front door.
- Outcome Promises and Comparisons: “We’ve never lost a case” and disfavored comparison language invite scrutiny, no matter who wrote the copy.
What a Defensible Site Does
- Discloses where AI is used on the site, including chat and intake assistants.
- Uses consent and data-handling language matching the firm’s real confidentiality protocol.
- Avoids capability overpromises.
- Documents that are authored by substantive copy when needed.
A modern custom lawyer web design pulls those pieces into one coherent posture.
Safe vs. Risky AI Use Cases for Lawyers
AI itself is not unethical. Unsupervised use is.
Safer AI Use Cases for Law Firms
- Legal Research With Verification: AI as a starting point; Westlaw/Lexis/Bloomberg Law for confirmation; citation log kept.
- Routine Correspondence: client letters, scheduling, follow-ups, edited and signed by the attorney.
- Discovery Summarization on Enterprise Tools With Zero Retention: with attorney sampling for accuracy.
- Marketing Content Drafted by AI and Edited by Humans: humans who know the firm’s voice and ethics rules.
- Internal Knowledge Management: summarizing memos, practice-area briefings, and organizing precedents.
- Document Review on Enterprise Platforms: at scale, with attorney supervision at every stage.
Risky AI Use Cases Lawyers Should Avoid
- Citation Generation Without Verification: still the most common path to sanctions.
- Client Confidential Information in Public Models: a Rule 1.6 issue regardless of intent.
- Substantive Client Communications Sent Without Attorney Review.
- Court Filings Produced by AI and Submitted Without Human Verification.
- Case Strategy in Tools That Retain Inputs for Training.
- Predictive Case Outcome Tools Used as Decisional Rather Than Informational.
A tool moves from the second list to the first when:
- Retention is controlled.
- The work is verified.
- Supervision is documented.
- Use is disclosed when required.
The line is procedural.
Lawyer AI Compliance Checklist: 7 Steps to Take This Week
Run them in order. Document each one.
- Inventory AI Tools. Every tool in use, including embedded AI in case management software. Note vendor and data sensitivity tier.
- Compare Tools Against State Guidance. Collect opinions for every jurisdiction in which the firm practices. Flag any tool failing the strictest applicable standard.
- Review Intake Language. The intake form, website disclosures, and any AI chat widget align with the firm’s actual confidentiality posture.
- Review Website Claims. Audit every page for outcome promises, AI capability statements, and bio accuracy. Remove anything you cannot substantiate. The same standard applies to paid acquisition, where mastering ppc for lawyers starts with ad copy that meets Rule 7.1.
- Review Confidentiality Posture. Re-read vendor terms for every tool that touches client data. Document retention, training, and breach notification.
- Align Billing Disclosures. Engagement letters and billing practices reflect actual AI use and the value-versus-time issue.
- Establish Verification Standards. Write a one-page rule. Distribute it. Require sign-off from every attorney and staff member who uses AI.
Most firms can complete this list in a single week. A handful of partners, a paralegal, and a Friday afternoon is enough.
Key Takeaways on State Bar AI Rules for Lawyers
Five Model Rules carry the weight of AI compliance:
- Competence under Rule 1.1.
- Confidentiality under Rule 1.6.
- Communication under Rule 1.4.
- Candor under Rule 3.3.
- Supervision under Rules 5.1 and 5.3.
ABA Formal Opinion 512 reframes each duty in terms of predictable generative AI failure modes. State bars from California to North Carolina have built on it.
The rules are settled. Enforcement is catching up.
Bar counsel checks for operational proof:
- Written policy.
- Approved tool list.
- Verification log.
- Vendor due diligence.
- Billing transparency.
- Supervision records.
Your Website Is Part of Your AI Compliance File
Your website and intake flow are often the first place an ethics complaint gets traction. They are public, easy to screenshot, and tend to drift out of sync with how the firm actually works.
If you say you use AI, your site should show the same discipline this guide recommends: clear boundaries, clear data handling, and clear human accountability.
A defensible website posture looks like this:
- Plain-language disclosures about any AI used in chat, intake, or content drafting.
- Intake language that matches your real confidentiality and retention rules.
- Marketing claims that stay inside Rule 7.1 and avoid implying a tool is practicing law.
- A review process for bios, credentials, and case results so AI never “fills in” facts.
If you want a second set of eyes to review whether your site and intake align with your internal policy, you can schedule a call.
FAQs: State Bar AI Rules for Lawyers
1. Do Lawyers Have to Disclose Their Use of AI to Every Client?
No. Disclosure is expected only when AI materially affects work product, cost, or confidentiality. Most firms cover routine use in the engagement letter and add matter-specific disclosure for sensitive work.
2. How Can Lawyers Use AI Tools Competently and Safely?
Use enterprise plans with zero data retention, keep confidential client information out of public models, and verify every AI-generated citation or factual claim before it leaves the firm.
3. Can a Lawyer Use ChatGPT or Claude for Client Work?
Yes, on enterprise plans with contractual confidentiality and supervision. Treat every output as a draft and verify every legal or factual statement before sharing or filing. Watch each chatgpts policy update; retention and training defaults shift more often than the rules of professional conduct do.
4. How Should Lawyers Handle AI-Generated Citations?
Treat every AI-generated citation as unverified. Pull the case, statute, or regulation in Westlaw, Lexis, or Bloomberg Law, confirm the holding, and log the verification before filing.
5. Is Using AI Itself Sanctionable for Lawyers?
No. Sanctions come from the underlying conduct: fabricated citations, confidentiality breaches, weak supervision, misleading marketing, or unreasonable fees. AI use itself is permitted when the lawyer verifies outputs and exercises independent judgment.
Recent Post
Brian Dordevic
Elements of a Good Website (Beyond the Fancy Animations)
READ MORE
Brian Dordevic
State Bar Rules on AI Use: A Lawyer’s Compliance Guide
READ MORE
Brian Dordevic
ADA Website Compliance Deadlines 2026: The Critical Compassion Gap
READ MORE