The American Bar Association has confirmed that law firms can use generative AI in 2026, but every use has to clear the same ethical bar that governs the rest of your practice. The ABA's Formal Opinion 512, issued July 29, 2024, is the reference point: AI is permitted, but lawyers must still satisfy their duties of competence, confidentiality, communication, candor, supervision, and reasonable fees. The safe path is to use AI where those duties are easy to meet and to build a review step everywhere client interests are at stake.
What the ABA Actually Said
Formal Opinion 512 is the ABA's first comprehensive ethics guidance on generative AI. It does not ban the technology. Instead, it maps AI use onto the existing Model Rules of Professional Conduct. The themes that matter most for day-to-day practice:
Confidentiality (Model Rule 1.6). Entering client information into a generative AI tool raises the risk that the information could be disclosed or improperly surface in a later output. Lawyers must understand how a given tool handles input before putting anything sensitive into it.
Competence (Rule 1.1). Lawyers must understand the tool's benefits and limits, including its tendency to produce confident, wrong answers.
Candor (Rule 3.3). The now-infamous fabricated-citation cases fall here. AI output going to a tribunal must be verified.
Communication and fees (Rules 1.4, 1.5). Clients may need to be told about AI use, and firms cannot bill as if AI-assisted work took the hours it saved.
Safe, Confidentiality-Friendly Use Cases
Start where client confidentiality is easy to protect:
Legal research on public law. Summarizing statutes, regulations, and published opinions, with every citation verified before use.
First drafts of internal documents. Memos, checklists, and templates that contain no client-identifying facts.
Plain-language explainers. Turning dense material into client-friendly summaries, reviewed by a lawyer.
Administrative writing. Marketing copy, internal policies, and non-client correspondence.
Where the Real Risk Lives
Two failure modes account for most trouble:
- Confidentiality breaches. A lawyer pastes privileged facts, a draft contract, or discovery material into a consumer AI account with no data protections. This is the same shadow-AI problem every business faces, but with privilege on the line. Use a business-tier tool with contractual data protections, and for the most sensitive matters, consider a private or on-device model where data never leaves your systems.
- Unverified output. Relying on AI-generated citations or analysis without a lawyer checking every one. The rule is simple: AI drafts, a lawyer signs.
A Confidentiality-Safe Setup
| Practice | Why It Matters |
|---|---|
| Use business/enterprise tiers with data protections | Prevents client data from training the model or leaking into outputs |
| Ban client data in consumer accounts | Closes the most common Rule 1.6 exposure |
| Require human verification of all output | Satisfies competence and candor duties |
| Write an AI usage policy | Gives staff clear, enforceable rules |
| Keep a matter-level record of AI use | Supports communication and fee obligations |
Our AI usage policy guide includes a template you can adapt for a firm, and the OpenWriter case study shows how on-device AI keeps privileged text off the cloud entirely.
The Bottom Line
The ABA has cleared lawyers to use generative AI, provided they meet the duties that already define competent practice. Keep client information out of consumer tools, verify every AI output that leaves the firm, disclose where communication and fee rules require it, and put a short policy behind it all. Do that, and AI becomes a genuine advantage rather than a malpractice risk.
For firms in Orange County and across Southern California, a SafeStart AI Audit maps where confidential data is at risk today and delivers a policy and roadmap built around your ethical obligations. Book a free discovery call to begin.
Frequently Asked Questions
Can lawyers ethically use generative AI?
Yes. The ABA's Formal Opinion 512, issued July 29, 2024, confirms lawyers may use generative AI, but must satisfy their existing ethical duties: competence, confidentiality, communication, candor, supervision, and reasonable fees. AI is permitted; unsupervised or careless use is not.
What is the biggest AI risk for law firms?
Two: breaching client confidentiality under Model Rule 1.6 by entering client information into a tool that could expose it, and relying on unverified AI output, including fabricated case citations, without a lawyer's review. Both are avoidable with the right tools and a review process.
Can I put client information into ChatGPT?
Not into a standard consumer account. Client information entered into a self-serve tier could end up in later outputs or be used for training, which raises confidentiality concerns under Model Rule 1.6. Use a business-tier or enterprise tool with appropriate data protections, and for the most sensitive matters consider a private or on-device model.
Do I have to tell clients I used AI?
It depends on the circumstances and your engagement terms, but Opinion 512 ties disclosure to your duties of communication and reasonable fees. If AI materially shapes the work or affects billing, communication obligations may require telling the client. When in doubt, disclose.
One email a week on AI for business: which tools are worth paying for, what to keep out of chatbots, and what's changing for small businesses, in plain language.
Subscribe to the NewsletterMore from SafeLab
Public bids live on dozens of disconnected agency portals. Here is how we built FindBids to read every solicitation with AI and match small contractors to the handful of bids they can actually win.
A staffing agency had AI licenses and almost no adoption. Here is how role-specific training on their own live workflows turned unused seats into daily use, with PII rules agreed on up front.
AEO is how you get named and recommended inside AI answers from ChatGPT, Perplexity, and Google AI Overviews. Here is what it is, how it differs from SEO, and how to do it.