A partner at a San Francisco litigation firm recently praised an associate for using Casetext to cut research time in half on a complex motion. Two weeks later, she learned the associate had been pasting client names, case facts, and opposing counsel strategy notes directly into the AI prompt. Nobody had told him not to. Nobody had told him the bar had opinions about exactly that.
That scenario is playing out at small firms across California and the country right now.
The Problem: AI Tools Are Moving Faster Than Firm Policies
Attorneys are adopting AI-powered legal research tools fast. Westlaw AI, Casetext (now part of Thomson Reuters), Harvey, and a growing list of competitors promise faster research, better case synthesis, and smarter drafting support. For a five-attorney firm competing against larger practices, those efficiency gains are genuinely compelling.
But most small firm attorneys - busy running practices, not monitoring bar bulletins - haven’t read the ethics opinions that state bar associations have been quietly releasing over the past two years.
The California State Bar issued practical guidance on generative AI in 2024. The Florida Bar, New York State Bar Association, and the American Bar Association have all weighed in with formal ethics opinions or guidance documents. More opinions are coming. The consensus across jurisdictions isn’t that you shouldn’t use AI - it’s that you have specific professional obligations when you do.
The gap between how quickly attorneys are adopting these tools and how slowly most small firms are updating their internal policies is where ethics violations happen. Not from bad intent. From nobody stopping to ask the right questions.
Why This Matters for Law Firms
Three core professional conduct obligations are directly implicated by AI research tools, and they don’t disappear just because the technology is new.
Competence under Model Rule 1.1. The ABA’s Comment 8 to Model Rule 1.1 has long required attorneys to keep up with “changes in the law and its practice, including the benefits and risks associated with relevant technology.” Generative AI tools are explicitly in scope. Competence here doesn’t just mean knowing how to click the buttons - it means understanding how the tool generates output, what its known failure modes are (hallucinated citations being the most notorious), and how to verify results before relying on them. Using AI output without that understanding isn’t efficient. It’s a potential disciplinary exposure.
Confidentiality under Model Rule 1.6. When you or your staff types client facts, case details, or litigation strategy into a third-party AI tool, you may be disclosing confidential information. Whether that disclosure is permissible depends almost entirely on the vendor’s data handling practices. Does the tool use your inputs to train its models? Who can access the data? Is it stored, and for how long? These aren’t abstract questions. California Business and Professions Code § 6068(e) independently obligates California attorneys to protect client confidences, and it applies to every input field in every tool you use.
Supervision under Model Rules 5.1 and 5.3. Partners and supervising attorneys are responsible for the work product - and the conduct - of associates and non-attorney staff. That responsibility doesn’t transfer to the AI tool. If an associate submits a brief with a fabricated citation, the supervising partner has an exposure problem. If a paralegal uploads a client’s financial records to an unapproved AI tool, the responsible attorney has a confidentiality problem. “I didn’t know they were using it that way” is not a defense the rules recognize.
How to Address AI Ethics Compliance at Your Firm
The good news: you don’t need a 40-page policy manual. Most bar ethics concerns around AI research tools can be addressed with a clear, practical internal framework covering four areas.
1. Approved tools and vetting criteria. Designate which AI tools your firm has reviewed and approved for use. That review should include reading the vendor’s terms of service and privacy policy - specifically looking for whether inputs are used for model training, whether data is stored, and whether the vendor offers a business associate agreement or enterprise data protection addendum if needed. Thomson Reuters, for example, offers data handling commitments for Casetext in its enterprise agreements. Know what you’ve agreed to before anyone types a client name.
2. Prohibited inputs. Define clearly what cannot go into any AI research tool unless it’s been explicitly approved for that data type. A short list works. Client names, matter numbers, opposing party details, financial data, and verbatim communications are reasonable starting points for a default-prohibited category. Researchers can describe a legal scenario in general terms without identifying the client - this protects confidentiality while still getting most of the efficiency benefit.
3. Output verification requirements. Every citation generated by an AI tool must be verified against the primary source before it goes into any filing or client communication. This isn’t optional and it isn’t bureaucratic - it’s what the competence obligation requires. Build a simple verification step into your workflow: researcher checks citations in Westlaw or Lexis before the work product leaves their desk. Document that it happened.
4. Training and acknowledgment. Your policy only works if people know about it and understand why it exists. A short training session - even 30 minutes - covering the bar’s current ethics guidance, your firm’s approved tool list, and the prohibited inputs rule is worth doing. Have attorneys and staff sign an acknowledgment. If something goes wrong later, that acknowledgment matters.
None of this requires slowing down the productivity gains AI tools can deliver. It just means capturing those gains without the professional liability exposure.
What to Look for in an IT Partner
If your firm is evaluating AI tools - or trying to get compliant use of existing tools under control - your IT provider should be able to help, not just with the technology but with the policy framework.
Ask any prospective IT partner these questions:
- Do you have experience helping law firms evaluate AI tool vendors for data handling compliance?
- Can you help us review vendor terms of service through a privacy and confidentiality lens?
- Do you have templates or frameworks for AI acceptable use policies specific to professional services firms?
- How do you handle ongoing monitoring if a vendor updates its data handling practices after we’ve deployed a tool?
A managed IT provider who works with law firms should understand that your compliance obligations aren’t generic - they’re governed by bar rules, state professional conduct codes, and client engagement agreements. If your IT partner can’t speak to those specifically, that’s a gap worth addressing.
The Bottom Line
Bar associations across the country are actively issuing ethics opinions on AI legal research tools, and the obligations they describe - competence, confidentiality, and supervision - apply right now, regardless of firm size. A clear internal policy covering approved tools, prohibited inputs, and output verification is the practical solution. It’s not complicated. It just has to be done.
Frequently Asked Questions
Has the California State Bar issued specific ethics guidance on using AI tools for legal research?
Yes. The California State Bar published practical guidance on generative AI in 2024 that addresses attorney competence, confidentiality, and supervision obligations in the context of AI use. California attorneys should review this guidance alongside the California Rules of Professional Conduct, particularly Rule 1.6 on confidentiality and Rule 3.4 on candor. Additional formal opinions are expected as the technology continues to evolve.
Can I use Casetext or Westlaw AI without violating attorney-client confidentiality?
It depends on the vendor’s data handling practices and how you use the tool. Enterprise agreements for platforms like Casetext through Thomson Reuters typically include data protection commitments that address confidentiality concerns - but you need to read those agreements and confirm the specific terms apply to your subscription. Avoiding client-identifying details in prompts is a practical safeguard regardless of what the contract says.
What happens if an associate uses an AI tool incorrectly and submits a brief with a hallucinated citation?
The supervising attorney carries professional responsibility exposure under Model Rules 5.1 and 5.3, which require partners to establish systems that confirm subordinate attorneys comply with the rules of professional conduct. Courts have already sanctioned attorneys in multiple jurisdictions for submitting AI-generated citations that didn’t exist. The attorney of record - not the AI tool - is responsible for the accuracy of every citation in a filed document.
Do bar ethics rules require attorneys to disclose to clients that AI tools were used in their matter?
Current ethics guidance varies by jurisdiction. Some state bar opinions recommend or require disclosure when AI tools play a meaningful role in legal work, particularly in drafting. The ABA’s formal opinion and several state bar opinions address this. The safest approach is to address AI use in your engagement letter or client communications policy, so clients understand your firm’s practices from the start.
If you’re working through AI legal research tools ethics compliance challenges at your firm, let’s talk. One82 works exclusively with CPA firms, law firms, and financial advisory companies in the Bay Area - we know your world.