As in the program, when I refer to the rules I mean the ABA Model Rules of Professional Conduct. Most states have rules based on the Model Rules, but the numbering and language vary, so check your own jurisdiction’s rules and ethics opinions.
Today I joined Stephen Embry and Natalie Robinson Kelly for the ABA Law Practice Division webinar Proceed With Caution: AI Tools, Legal Ethics and the Traps Hiding in Plain Sight. Attendees submitted questions during the program, and I want to answer them here.
If I Have to Review Everything Anyway, Why Use AI at All?
The short answer is that reviewing is often, but not always, faster than creating. Most of us have supervised associates or paralegals. We review their work too, though perhaps not as closely as we should because we have more trust for them than we do for generative AI. The rules treat AI much the same way as our non-attorney staff. Under Rules 5.1 and 5.3, you verify what AI produces as you would the work of any attorney over whom you have supervisory authority, as well as non-attorney employees, vendors, or consultants.
Whether AI saves you time depends on the task and how much verification is required. As I mentioned during the webinar, increased efficiency in the office is possible through the use of AI. Tasks such as finding a date for an appointment, creating a PowerPoint, entering data, and drafting an email tend to be sped up with AI. Other tasks may actually be slower, especially when you have to verify every individual citation or double check the original document to make sure a summary is accurate. On the other hand, as I also mentioned, you might get a better result when you collaborate with AI because the AI might push you by providing more information or engaging in discussion to help you see new issues. It isn’t always about speed. Sometimes it is about a better result.
Aren’t a Lawyer’s AI Searches Protected as Work Product?
The ABA will be presenting a webinar on privilege in December. However, I can give you the lay of the land as it stands right now. As you may recall, in Heppner, a criminal case, the judge found that a represented party’s AI chats were not privileged, though he left open whether the answer might change if a lawyer had directed the client to use AI. Essentially, what this means is that if your client enters documents or information you gave them into an AI, that information might be discoverable. I wrote about that in Claude AI Privilege Waiver: What U.S. v. Heppner Means for Your Clients. In Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC, a Texas Business Court went the other way and protected some of a represented party’s ChatGPT conversations as work product. I covered that case in Work Product Protection Extends to a Represented Party’s AI Chats. For a broader look at the cases, see Where are we on AI and Privilege?.
The concern comes from (a) violating a client’s confidentiality, (b) the potential for your client’s data to be trained on or shared by the AI, and (c) the general lack of opinions on this particular issue. Also, of concern is whether the lawyer is violating laws such as HIPAA by using consumer tools that do not generally satisfy what is required under those laws. So, while a lawyer’s use of AI may be protected under some circumstances, using the wrong tool could still result in that content getting out, or it could result in a lawyer failing to use a secure enough tool for the type of data they are entering.
Keep in mind that work product for lawyers is not the only question we have to analyze. We have to look at the underlying ethical and legal issues as well. Whether work product protects a lawyer’s work does not address the issue of using a properly confidential tool to protect that data. For example, the emails you write in a free Gmail account may well be protected by work product, but the fact that Google uses AI to scan those free accounts is problematic under both the ethical rules and any laws that provide further protection to the data in question.
On another note, if you want to know how to turn off AI scanning for Gmail, here are instructions. But I still do not recommend free Gmail. When a product is free, your data is often the price. That is fine with your own data but not with your clients’. Also, you should use your own domain name for branding purposes.
Can I Upload Documents Covered by a Protective Order?
You have to start with the order itself. A typical protective order lists who may see material designated as confidential, such as counsel of record and their staff, retained experts, the court, and sometimes litigation support vendors. Some courts are requiring that only generative AI tools with certain contractual protections be used on the opposing party’s confidential data. Take a look at the Morgan case for examples of what a court required in a protective order and you will see how the judge limited what tools may be used. If a judge requires specific contractual protection, then some tools simply may not be used for data covered by a protective order.
If you want to use AI on protected material, you have options. See whether the tool fits a category the order already permits, such as a litigation support vendor bound by the order. Raise it with opposing counsel and seek a stipulation that addresses AI tools. Or ask the court. The sample law firm AI use policy in my materials prohibits entering information subject to a protective order into any AI tool without express authorization. That is where I would start.
Can What I Put Into an AI Tool Create an Ethics Problem for Me and My Case?
Yes. Rule 1.6(c) requires a lawyer to “make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” Some AI tools keep your data confidential, and some do not. Most consumer versions have training turned on by default, which means the tool uses what you enter to train itself, and you cannot pull that data back out once it is in. The solution to that problem is to turn off training, but there are other problems that must be resolved. Paying for a tool does not guarantee confidentiality either. Read the privacy policy and terms of service, choose an account level that fits your client’s needs, and redact when the tool does not protect confidential data.
Redaction is not necessarily simple when you are using a generative AI tool. AI can identify a person from details such as a birth date, a location, or a well-known event, so information you assume is harmless may still identify your client. This means you need to redact confidential data properly and thoroughly.
Encryption does not solve the problem. Encryption protects the documents while they travel and while they are stored, but the provider has to decrypt them to process them. What matters is whether the provider trains on your data, how long it keeps it, whether its employees can review it, and whether its contract obligates it to protect the data.
The risk to your case is separate from the risk to your license. Putting privileged communications or strategy into a consumer tool may jeopardize privilege, and the law on that point is still developing. If the material is under a protective order, see the answer above. You certainly don’t want to violate a court’s protective order by using a generative AI that you are not permitted to use.
Isn’t It Safer to Avoid AI Altogether?
I think it is acceptable to choose not to use generative AI in your own work. However, avoiding it is increasingly challenging. A lot of the software you already use has AI built in, spell check in Word being the most familiar example. Your client may paste your advice into ChatGPT. Opposing counsel may file a brief with hallucinated citations, and you will need to recognize them. Even courts have had issues with hallucinations.
Remember comment [8] to Rule 1.1 ties competence to keeping abreast of “the benefits and risks associated with relevant technology.” This doesn’t only cover your own use of that technology. It covers use by others, especially when it is routinely being used by those you will encounter in your practice. As a result, the safer course is to learn how the tools work, choose appropriate ones, and verify what they produce. If you don’t want to use AI, you certainly may try to avoid it. But also make sure you understand how it can impact your practice and your clients so you can mitigate any potential risks that will impact your cases.
The Car Rental Example: Was It a Permissions Problem, or Did the AI Hack In?
The example is PocketOS, which provides reservation, payment, and vehicle tracking software for car rental companies. An AI agent was assigned a routine task in the company’s staging environment. When it hit a credential mismatch, it found an API token sitting in another file and used it to issue a delete command on a volume that turned out to be shared across environments. The production data was gone, and so were the backups. I wrote about it in “It Took 9 Seconds”: AI Agent Deletes Entire Company Database, Lessons for Law Firms.
So, to answer the question, it was both a human-in-the-loop failure and a permissions problem, and no hacking was involved. The agent had explicit instructions never to run destructive or irreversible commands without permission. It violated them, and afterward it produced a written confession saying so. It did not break in. It used a token it found, and that token had blanket permissions. The API required no confirmation for destructive actions. The agent was supposed to be working in staging, and the token it found could reach production.
That is the difference between an instruction and a permission. Telling an agent to stop and wait for a human is an instruction, and as you will recall from our discussion, AI tools do not always follow instructions. Taking away the agent’s ability to act without approval is a permission, and the system enforces it whether or not the agent cooperates.
The sample policy in my materials builds on this. It limits agents to the data, systems, and tools necessary for the specific task, requires the firm to define in writing which actions need attorney approval, and states that “Irreversible permissions must not be granted without human approval gates.”
How Does AI Losing Memory Lead to Hallucinations?
An AI tool can hold only so much of a conversation at one time. In a long chat, or one with large documents attached, earlier material gets dropped or condensed to make room. The instructions you gave at the start can fall away. Details from a document you uploaded an hour ago may no longer be available to the tool. When the tool no longer has the source in front of it, it fills the gap with something that sounds right. That is where hallucinations creep in.
A few habits help. Start a new chat for a new task. You can ask the old chat to create a handoff, which is a text document containing important details from the last chat. You can also restate the instructions that matter rather than assuming the tool still has them. Give the tool the actual case or document rather than asking it to recall one. Ask it to quote the source and tell you where the quote appears and then check it. For long documents, work in sections.
Memory across chats is a different feature. Some tools now remember your prior conversations, and they may make assumptions from that history. That can help, but it can also carry details from one matter into another. Know whether the feature is on in the tool you use.
For more see AI Handoff Checklist: When to Start Fresh & What to Capture – JLE
Do We Need Client Consent to Use AI, and How Do We Convince a Client Who Says No?
At a minimum, consider disclosing your use of AI in your engagement agreement, and answer honestly if a client asks whether you use it. A false or misleading answer is its own violation of the rules requiring honesty with your clients. My sample engagement language commits the firm to using tools that do not train on or retain client data, or to obtaining the client’s informed consent before submitting confidential information to a tool that does. The sample policy goes further. Where AI plays a material role in the work, such as research, drafting substantive documents, or analysis that shapes strategy, it calls for explaining the benefits, risks, and limitations to the client and seeking informed consent. Your jurisdiction may require more, so check its opinions.
If a client tells you not to use AI, you must not use it. I would not try to talk a client out of that decision. I would explain how you use AI, what you verify, how the tools you use protect the client’s information, and how AI affects the cost of the work, and then let the client decide. Find out where the boundaries are. A client who objects to generative AI may be fine with spell check. Put the restriction in writing, have the client sign it, and make sure everyone working on the matter knows about it. If you do not want to take the representation on those terms, turn down the client.
Can I Charge a Surcharge When AI Saves Me Time?
Rule 1.5 requires fees to be reasonable. If you bill hourly, bill the time the work actually took, not the time it used to take. Adding a charge for time you did not spend because AI made the work faster runs into that rule.
You do not have to be penalized for working efficiently, though. You can raise your rate to reflect the value of your knowledge and experience. You can use a mixed model, with a flat rate for the underlying work and an hourly rate for your time working with AI. Or you can charge a flat or value-based fee, which gives the client predictability and gives you appropriate compensation if it is calculated correctly. Whichever approach you choose, explain it fully in your engagement or fee agreement before the work begins. My materials include sample fee language for these different options.
ABA Formal Opinion 512 also addresses when a lawyer may pass the cost of an AI tool through to a client. Read that section before you add any AI charge to an invoice.
Thank You
Thank you to everyone who attended and sent in questions, and to Stephen and Natalie for a good discussion. If you have further questions, please feel free to reach out to me via the web form on this site.