What the opinion is, and why advisory does not mean inert
On July 29, 2024 the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, Generative Artificial Intelligence Tools. Its synopsis sets the frame: lawyers using these tools “must fully consider their applicable ethical obligations, including their duties to provide competent legal representation, to protect client information, to communicate with clients, to supervise their employees and agents, to advance only meritorious claims and contentions, to ensure candor toward the tribunal, and to charge reasonable fees.”
Seven duties, none of them new. The opinion is advisory, and the Model Rules it construes bind no lawyer until a jurisdiction adopts them, which means the operative text for any given firm is its own state’s rules. Texas is the clean illustration: its Professional Ethics Committee reached its own conclusions in Opinion 705 in February 2025 under the Texas Disciplinary Rules, where the confidentiality provision is Rule 1.05 and not Model Rule 1.6.
None of which makes Opinion 512 inert. It is the ABA’s reading of the rules most states modeled theirs on, and its influence is visible in what has followed it. What it does not do is create anything a firm can be certified against. There is no compliance with Formal Opinion 512 available for purchase, and a partner can reasonably treat any vendor who suggests otherwise as having answered the diligence question already.
Eight Model Rules get real analysis: 1.1, 1.4, 1.5, 1.6, 3.3, 5.1, 5.3 and 8.4(c). Rule 3.1 is quoted without being developed. Footnote 4 flags Rules 7.1, 1.7 and 1.9 as further live issues and closes by telling lawyers to “consider all rules before using GAI tools,” which is the Committee saying the list is not the point.
Competence attaches to the specific tool, and the expertise can be borrowed
Under Rule 1.1 the opinion is careful about how much it asks. “To competently use a GAI tool in a client representation, lawyers need not become GAI experts. Rather, lawyers must have a reasonable understanding of the capabilities and limitations of the specific GAI technology that the lawyer might use.”
Two features of that standard matter operationally. It attaches to the specific product and not to artificial intelligence as a subject, so it cannot be satisfied in the abstract. And it can be satisfied through someone else: lawyers should “either acquire a reasonable understanding of the benefits and risks of the GAI tools that they employ in their practices or draw on the expertise of others who can provide guidance about the relevant GAI tool’s capabilities and limitations.” On the confidentiality side the opinion says the same about vendor terms: read them, “or consult with a colleague or external expert who has read and analyzed those terms and policies.”
That is a relief and a dependency. A firm may concentrate the reading in one competent person, and it then depends on that person, which is an arrangement with a name attached and a place in the calendar or it is nothing.
The standard also moves. “This is not a static undertaking. Given the fast-paced evolution of GAI tools, technological competence presupposes that lawyers remain vigilant about the tools’ benefits and risks.” Products change under the same name, and no vendor is obliged to make a change legible to a busy partner.
All of which converges on an unglamorous fact. A firm that cannot say which tools are in use across its practice groups cannot assess competence, because the assessment has no object.
How much verification is enough, answered with a worked example
The opinion sets no flat verification rule. “The appropriate amount of independent verification or review required to satisfy Rule 1.1 will necessarily depend on the GAI tool and the specific task that it performs as part of the lawyer’s representation of a client.”
It then works an example more useful than the principle. If a lawyer uses a tool to review and summarize numerous lengthy contracts, the lawyer “would not necessarily have to manually review the entire set of documents to verify the results if the lawyer had previously tested the accuracy of the tool on a smaller subset of documents by manually reviewing those documents,” comparing them to the tool’s summaries and finding the summaries accurate. A tool “designed specifically for the practice of law or to perform a discrete legal task, such as generating ideas, may require less independent verification or review, particularly where a lawyer’s prior experience with the GAI tool provides a reasonable basis for relying on its results.”
Sample testing can substitute for full review, then, but only where the testing happened and can be pointed to. The limit follows immediately: lawyers “may not abdicate their responsibilities by relying solely on a GAI tool to perform tasks that call for the exercise of professional judgment,” and “regardless of the level of review the lawyer selects, the lawyer is fully responsible for the work on behalf of the client.”
Confidentiality: the holding, its carve-out, and its expiry date
Rule 1.6 covers information relating to the representation regardless of source, and the opinion notes in a single sentence that Rules 1.9(c) and 1.18(b) “require lawyers to extend similar protections to former and prospective clients’ information.” Easy to miss, and it is the sentence that would reach an intake chatbot handling prospective client information.
The central holding concerns self-learning tools, meaning tools that train on what is put into them. The mechanism described is specific: information input on one matter is “later revealed in response to prompts by lawyers working on other matters, who then share that output with other clients, file it with the court, or otherwise disclose it.” The risk runs outside the firm and also sideways inside it, to people screened by an ethical wall, or to colleagues who “could inadvertently use the information from one client to help another client, not understanding that the lawyer is revealing client confidences.”
The conclusion: “because many of today’s self-learning GAI tools are designed so that their output could lead directly or indirectly to the disclosure of information relating to the representation of a client, a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool.”
Three things about that sentence get lost in the summaries.
First, the consent has content. “For the consent to be informed, the client must have the lawyer’s best judgment about why the GAI tool is being used, the extent of and specific information about the risk, including particulars about the kinds of client information that will be disclosed, the ways in which others might use the information against the client’s interests, and a clear explanation of the GAI tool’s benefits to the representation.” Then the door closes on the obvious shortcut: “merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient.”
Second, there is a carve-out. It is narrower than it sounds and useful anyway. “Today, there are uses of self-learning GAI tools in connection with a legal representation when client informed consent is not required because the lawyer will not be inputting information relating to the representation.” The example given is idea generation, expressly qualified as being “in a manner that does not require inputting information relating to the representation.” A firm that identifies those uses in advance gives its lawyers somewhere to go that is neither a consent conversation nor a rule problem.
Third, and least quoted: footnote 34, attached to the holding itself. “This conclusion is based on the risks and capabilities of GAI tools as of the publication of this opinion. As the technology develops, the risks may change in ways that would alter our conclusion.”
The Committee wrote an expiry date into its own most consequential holding. Two years on, that is the most important sentence in the opinion, because it means any answer a firm reaches is provisional by design. What has to exist is not a settled position in a policy document. It is a way of asking the question again when a vendor ships a feature.
The vendor diligence the opinion actually specifies
Most coverage tells firms to review their vendors. The opinion says what to review. Pointing to earlier opinions “developed to address cloud computing and outsourcing of legal and nonlegal services,” its own outsourcing opinion 08-451 together with cloud computing opinions from Florida and Iowa, it says those opinions “suggest that lawyers should”:
- ensure the tool “is configured to preserve the confidentiality and security of information, that the obligation is enforceable, and that the lawyer will be notified in the event of a breach or service of process regarding production of client information”;
- investigate the tool’s “reliability, security measures, and policies, including limitations on the [the tool’s] liability”;
- determine whether the tool “retains information submitted by the lawyer before and after the discontinuation of services or asserts proprietary rights to the information”; and
- “understand the risk that [GAI tool servers] are subject to their own failures and may be an attractive target of cyber-attacks.”
Carried over from the outsourcing opinions: reference checks and vendor credentials, the vendor’s security policies and protocols, its hiring practices, confidentiality agreements, “understanding the vendor’s conflicts check system to screen for adversity among firm clients,” and “the availability and accessibility of a legal forum for legal relief for violations of the vendor agreement.”
Notice on service of process, liability caps, post-termination retention, proprietary claims over inputs, vendor conflicts screening, and whether there is a forum in which to sue. Those are questions for whoever negotiates the firm’s contracts, and the answers belong in a record and not in that person’s memory.
Communication: six situations, and an express refusal to close the list
Opinion 512 imposes no blanket duty to disclose AI use. “The facts of each case will determine whether Model Rule 1.4 requires lawyers to disclose their GAI practices to clients or obtain their informed consent to use a particular GAI tool. Depending on the circumstances, client disclosure may be unnecessary.” But the Committee does not leave the reader with a shrug. Six situations are identified.
1 and 2. The client asks, or the engagement terms require it. Lawyers “must disclose their GAI practices if asked by a client how they conducted their work, or whether GAI technologies were employed in doing so, or if the client expressly requires disclosure under the terms of the engagement agreement or the client’s outside counsel guidelines.” Outside counsel guidelines tend to bind first in practice, because they arrive as a contract.
- The lawyer proposes to input information relating to the representation. Clients “would need to be informed in advance, and to give informed consent, if the lawyer proposes to input information relating to the representation into the GAI tool.” This is the Rule 1.6 path arriving through Rule 1.4.
- The use is relevant to the basis or reasonableness of the fee.
- The output will influence a significant decision in the representation. The examples given are evaluating potential litigation outcomes and jury selection. “A client would reasonably want to know whether, in providing advice or making important decisions about how to carry out the representation, the lawyer is exercising independent judgment or, in the alternative, is deferring to the output of a GAI tool.”
- The client retained the lawyer for particular skill and judgment. There may be situations where undisclosed use “would violate the terms of the engagement agreement or the client’s reasonable expectations regarding how the lawyer intends to accomplish the objectives of the representation.”
The Committee then declines to close the list: “It is not possible to catalogue every situation in which lawyers must inform clients about their use of GAI.” It adds that even where nothing is required lawyers may tell clients anyway, and that “the engagement agreement is a logical place to make such disclosures and to identify any client instructions on the use of GAI in the representation.”
Fees: the section that reaches the invoice
Under Rule 1.5 lawyers billing hourly “must bill for their actual time,” and the illustration is plain. Where a lawyer spends fifteen minutes inputting information to produce a draft pleading, the lawyer may charge for those fifteen minutes plus the time spent reviewing the draft. Quoting Formal Opinion 93-379, efficiency changes nothing: “it nonetheless will not be permissible to charge the client for more hours than were actually expended on the matter.”
The holding partners tend not to see is the next one, because it closes the obvious workaround. “If using a GAI tool enables a lawyer to complete tasks much more quickly than without the tool, it may be unreasonable under Rule 1.5 for the lawyer to charge the same flat fee when using the GAI tool as when not using it.” The Committee cites a Delaware decision applying the same principle to contingency fees, and quotes a Maryland disciplinary decision: “A fee charged for which little or no work was performed is an unreasonable fee.” A firm with an alternative fee or contingency book cannot manage this by billing hours honestly, because there are no hours in the arrangement.
For the cost of the tools the opinion sets a functional test and not a menu. “To the extent a particular tool or service functions similarly to equipping and maintaining a legal practice, a lawyer should consider its cost to be overhead and not charge the client for its cost absent a contrary disclosure to the client in advance.” Grammar checking inside word processing software is overhead. A third-party service billed per use to review thousands of contracts for one client is different, and there “it would ordinarily be reasonable for the lawyer to bill the client as an expense for the actual out-of-pocket expense incurred for using that tool.” For a proprietary in-house tool the firm may agree rates with the client in advance; absent agreement it may charge “no more than the direct cost associated with the tool (if any) plus a reasonable allocation of expenses directly associated with providing the GAI tool, while providing appropriate disclosures to the client consistent with Formal Opinion 93-379.”
On learning time the rule is narrower than it is usually reported. A lawyer “may not charge a client to learn about how to use a GAI tool or service that the lawyer will regularly use for clients because lawyers must maintain competence in the tools they use, including but not limited to GAI technology.” Where a client explicitly asks that a specific tool be used and the lawyer does not know it, billing may be appropriate, subject to a condition that is easy to drop: “the lawyer and the client should agree upon any new billing practices or billing terms relating to the GAI tool and, preferably, memorialize the new agreement.”
One note for anyone reading the hourly holding as the Committee ignoring firm economics. In the competence discussion, considering whether lawyers will eventually be expected to use these tools, it observes at footnote 23 that “Model Rule 1.5’s prohibition on unreasonable fees, as well as market forces, may influence lawyers to use new technology in favor of slower or less efficient methods.” The incentive question was in front of it.
Candor, and where the sanctions actually come from
Rule 3.3 “makes it clear that lawyers cannot knowingly make any false statement of law or fact to a tribunal or fail to correct a material false statement of law or fact previously made to a tribunal.” That word carries weight, and it is part of why the hallucination cases are so rarely disciplinary matters.
The provision without a knowledge requirement is the one to read twice. Rule 8.4(c) bars “conduct involving dishonesty, fraud, deceit or misrepresentation,” and the opinion states: “Even an unintentional misstatement to a court can involve a misrepresentation under Rule 8.4(c). Therefore, output from a GAI tool must be carefully reviewed to ensure that the assertions made to the court are not false.”
The review standard is broader than citation checking. Before submitting materials, duties to the tribunal require lawyers “to review these outputs, including analysis and citations to authority, and to correct errors, including misstatements of law and fact, a failure to include controlling legal authority, and misleading arguments.” A missing controlling case is not something a citation checker finds. Neither is a plausible argument resting on a misread of a case that does exist.
Rule 3.1 appears alongside 3.3 and 8.4(c) but is only quoted, never applied. The practical link is not hard to draw, though the opinion does not draw it: an assertion resting on authority that does not exist has no basis in law or fact.
The opinion does not define “tribunal.” Model Rule 1.0(m) does, and it reaches beyond courts to an arbitrator in a binding arbitration proceeding, and to a legislative body, administrative agency or other body acting in an adjudicative capacity, meaning where a neutral official will render a binding legal judgment directly affecting a party’s interests after the presentation of evidence or argument. For a firm with an arbitration or regulatory practice, the analysis does not stop at the courthouse.
Worth separating the ethics exposure from the practical one. In these cases the sanctions have typically come from Rule 11, from courts’ inherent power, and from state analogues rather than from disciplinary proceedings. New York’s model rule, discussed below, grounds its certification in existing authority and cites 22 NYCRR 130-1.1 and 130-1.1a on frivolous conduct, adding that an attorney submitting a paper “is additionally bound by the Rules of Professional Conduct.” For a litigating firm the fee shifting, the published order, and the client’s reaction to reading it arrive long before any disciplinary question does.
Supervision: the provision that makes this a management question
Every duty above belongs to an individual lawyer. Rules 5.1 and 5.3 do not, and the opinion splits them precisely.
“Managerial lawyers must establish clear policies regarding the law firm’s permissible use of GAI, and supervisory lawyers must make reasonable efforts to ensure that the firm’s lawyers and nonlawyers comply with their professional obligations when using GAI tools.” Two duties, two categories of lawyer, and a reasonable efforts standard rather than a guarantee.
Training sits alongside. Supervisory obligations “include ensuring that subordinate lawyers and nonlawyers are trained, including in the ethical and practical use of the GAI tools relevant to their work as well as on risks associated with relevant GAI use.” Training “could include the basics of GAI technology, the capabilities and limitations of the tools, ethical issues in use of GAI and best practices for secure data handling, privacy, and confidentiality.” One concrete suggestion in the footnotes deserves more attention than it gets: that material produced by these tools be marked as such wherever it is stored, so a later reader knows what they are holding.
For providers outside the firm, Rule 5.3(b) itself imposes “a duty on lawyers with direct supervisory authority over a nonlawyer to make ‘reasonable efforts to ensure that’ the nonlawyer’s conduct conforms with the professional obligations of the lawyer.” The substantive content comes from the earlier outsourcing opinions, which the Committee carries forward: those opinions recognize that when outsourcing to third-party providers, lawyers must ensure, “for example, that the third party will do the work capably and protect the confidentiality of information relating to the representation.”
This is the provision that answers the most common thing said when the subject comes up, which is that the firm’s lawyers are careful people. That may well be true, and it is not what Rule 5.1 asks about. The question is whether managerial lawyers established policies and whether supervisory lawyers made reasonable efforts against them, and careful individuals are evidence of neither.
What Formal Opinion 512 does not say
It prohibits no category of AI use. It requires no disclosure in every matter. It requires no particular policy, format, tool or vendor, and it endorses none. It certifies nothing. It is advisory, it binds no lawyer, and it construes rules that are not binding until adopted.
It also does not reach agentic tools, meaning systems that take sequences of actions without being prompted at each step. That was barely a practical question in July 2024 and is the live one now.
What has changed since July 2024
Opinion 512 remains the ABA’s formal ethics guidance. Movement since has been at the state level and it has not converged. Some context first: Florida’s Professional Ethics Committee got there before the ABA did, with Opinion 24-1 on January 19, 2024, which Opinion 512 goes on to cite five times, including on client-facing chatbots under Florida’s advertising rule.
The most instructive development since is a court rule. New York’s Unified Court System added 22 NYCRR Part 161 by administrative order dated March 25, 2026, effective June 1, 2026, and its structure is more interesting than the coverage suggests. Section 161.3 states a system-wide policy that AI use in preparing papers “should not be prohibited, as long as such use is in accordance with the duties and responsibilities that apply to individuals who submit papers to a court,” and that attorneys and parties “should not be required, upon submitting papers, to disclose to the court that they have used AI in the preparation of such papers.” Section 161.4 then leaves it to each court, “in its discretion,” to implement a part rule, and encourages courts that do so to adopt the model rule at Appendix A.
The certification everyone quotes lives in that model rule, not in the statewide policy. Where a court adopts it, any filer using an AI tool “is required to carefully review the paper and independently ensure that it contains no fabricated or fictitious cases, statutes, or other material,” and by signing certifies the review was done, with sanction available where it was not. Appendix A opens with a line that should look familiar: every attorney or party using such a tool “is expected to understand that tool’s capabilities and limitations.” That is Opinion 512’s competence standard migrating out of an advisory ethics opinion and into a court rule. Note also section 161.2(b), which excludes from the definition of “paper” any materials “constituting or proffered as evidence in the case,” on the basis that they raise separate considerations.
The practical consequence for a New York litigator is that the operative standard varies from court to court, which is a tracking obligation and not a policy question.
Elsewhere, the New York City Bar has issued two opinions on an everyday practice most firm policies do not mention: Formal Opinion 2025-6, “Ethical Issues Affecting Use of AI to Record, Transcribe, and Summarize Conversations with Clients,” on December 22, 2025, and its companion Formal Opinion 2026-2, “Ethical Use of AI for Recording, Transcribing, and Summarizing Non-Client Conversations,” on August 5, 2026. The second reaches co-counsel, prospective clients, opposing counsel, witnesses, and the firm’s own investigators.
In California the state Supreme Court directed the State Bar in August 2025 to consider moving its 2023 practical guidance into the Rules of Professional Conduct and to consider agentic tools. The Bar’s professional responsibility committee approved proposed amendments to six rules on March 13, 2026 for public comment: 1.1, 1.4, 1.6, 3.3, 5.1 and 5.3. Proposed Comment [2] to rule 1.1 reads: “When using technology, including artificial intelligence, a lawyer must independently review, verify, and exercise professional judgment regarding any output generated by the technology that is used in connection with representing a client.” A verification duty is moving from standalone guidance into the Rules’ official commentary.
| Jurisdiction | Instrument | Disclosure of AI use required | What it turns on instead |
|---|---|---|---|
| ABA Model Rules | Formal Op. 512, July 29, 2024 | No blanket duty | Six fact-driven situations, including client request and outside counsel guidelines |
| New York courts | 22 NYCRR Part 161, effective June 1, 2026 | No, and the policy says filers should not be required to | Where a court adopts the model rule, the signature certifies independent review for fabricated material |
| Florida | Ethics Op. 24-1, January 19, 2024 | Not generally | Confidentiality, verification, billing, and limits on client-facing chatbots |
| New York City Bar | Formal Ops. 2025-6 and 2026-2 | Addresses consent to record and transcribe, rather than disclosure of use | Client and non-client conversations treated separately |
| California | COPRAC proposals, March 13, 2026 | Under consideration | Proposed amendments to six rules, including an express duty to review and verify output |
The pattern is not that standards are tightening. They are diverging on the question most likely to arise, which is whether AI use has to be surfaced and to whom. A policy that hard-codes one jurisdiction’s answer will be wrong somewhere. A record of which tool was used, on what basis, and who checked the output produces the answer for whichever standard turns out to apply.
What a firm has to be able to show
The useful question is not what a firm should do. It is what it would be asked to produce, and by whom. Clients are the likeliest first source: the Association of Corporate Counsel has published Top 10 GenAI Transparency & Readiness Questions for Outside Counsel, covering policies, accountability, data handling, quality control and billing. Outside counsel guidelines get there faster still, because they arrive as contract terms. And AI governance is increasingly part of professional-risk conversations.
Read against Opinion 512, seven things would need to exist in retrievable form.
- An inventory of tools in use, recording for each whether it trains on inputs, what the contract says about retention, notice on breach or service of process, liability limits, and proprietary claims, and what the tool is approved for.
- A named decision-maker and written criteria for approving a new tool or a higher-risk use.
- A rule about inputs, including which uses fall inside the opinion’s no-input carve-out and so need no consent conversation.
- A consent position per tool, distinguishing self-learning tools from the rest, and covering prospective and former clients as well as current ones.
- A verification standard by task type, with the sample testing recorded where sample testing is what justifies the level of review.
- A written billing position, covering actual time, flat and contingent arrangements, learning time, and how tool cost is classified under the overhead test.
- A way to track court and client requirements, since part rules, standing orders and outside counsel guidelines change independently of any ethics opinion.
Firms that have addressed AI have usually addressed it with a policy document. That is a reasonable start and a different thing. An AI policy is not AI governance. The gap shows up in the survey data: 43% of respondents said their firm has no formal AI policy and no plans to create one, and 9% have one in place and actively enforce it.
Source: 8am 2026 Legal Industry Report, fielded September to October 2025, more than 1,300 responses across roles, firm sizes and geographies.
The distance between having a policy and enforcing one is the distance Rule 5.1 is aimed at.
If you want to see where your firm currently sits against these seven, the AI Governance Readiness Assessment takes about three minutes.
Where a firm reasonably starts
None of this requires a committee. Find out which tools are actually in use, which is usually a shorter and more surprising list than expected, and decide in advance how the firm will handle what that exercise turns up, because uncertainty about the answer is what usually keeps the question from being asked. Establish for each tool whether it trains on inputs, which is a contract question with a factual answer. Name who approves, and write down the criteria. Then set the verification standard and the billing position, because those two are the ones tested by someone outside the firm.
The rest can mature with use. What the opinion asks for is not a finished system. Read footnote 34 again and it is asking for something harder and cheaper: a firm that can still answer the question after the technology has moved.
CounselRisk builds and operates governance machinery for law firms. This article is general information and not legal advice. Formal Opinion 512 is advisory, and the ABA Model Rules are not binding until adopted by a jurisdiction, so jurisdiction-specific conclusions belong to the firm and its counsel. CounselRisk is operated by QbitBrains LLC.