How law firms can implement AI safely

Safe implementation is not a decision made at the moment of purchase. It is a short set of infrastructure choices made before any tool touches a client matter: what the vendor may do with the data, which outputs a human must see, and who is accountable when something is wrong.

The order matters more than the content

Most firms already know the components of responsible AI use. Policy, vendor review, human oversight. The failure is almost never ignorance of the list. It is sequence: tools go live on real matters, and the governance work is scheduled for later, where it stays.

That ordering is the whole problem, because every day of ungoverned use generates data you cannot retroactively protect. Once a client's medical records have been pasted into a consumer chatbot with a broad retention clause, writing a policy the following month does not pull them back.

What ABA Opinion 512 actually says

Formal Opinion 512, issued July 29, 2024, is worth reading directly rather than in summary, because the summaries in circulation tend to add requirements it does not contain and omit ones it does.

The obligations it maps to existing rules:

  • Competence, Rule 1.1. A lawyer must have a reasonable understanding of the capabilities and limitations of the specific tool in use. Not AI generally. The tool.
  • Confidentiality, Rule 1.6. Before entering information relating to a representation, the lawyer must evaluate the risk of disclosure, which may require informed client consent depending on the tool and the data.
  • Communication, Rule 1.4. In some circumstances the client should be told that AI is being used on their matter.
  • Supervision, Rules 5.1 and 5.3. Firms must have measures giving reasonable assurance that AI use across the firm conforms to professional obligations, which is where a policy becomes practically necessary.
  • Fees, Rule 1.5. A lawyer may not bill a client for hours the tool did not take. This is the provision most often left out of secondhand summaries and the one with the clearest financial consequence.

A correction worth making. Opinion 512 is often described as requiring firms to maintain a written AI use policy. It recommends that firms consider adopting such policies and it is far more emphatic about a different duty: independent verification of output by the lawyer. Policies are excellent practice and we recommend one. Citing the opinion for a mandate it does not contain weakens the credibility of everything else in your compliance file.

State guidance also varies, sometimes materially. California, Florida, New York, New Jersey, and Texas have all issued their own guidance, and a firm should work from its own jurisdiction rather than the Model Rules alone.

Vendor evaluation: the seven questions

This is the step that protects clients, and it happens before procurement rather than after. Ask for written answers.

  1. Retention. How long are inputs stored, and what is the mechanism for deletion? "We do not store data" is not an answer until it names a retention window.
  2. Training. Are inputs used to train or improve models, for the vendor or any upstream model provider? Confirm this for subprocessors, not just the vendor.
  3. Tenant isolation. Can one firm's data be reached by another? Ask how, specifically. The answer reveals whether the vendor built for regulated markets or is describing an aspiration.
  4. Key custody. Is data encrypted at rest, and who holds the keys? A single shared key across all customers is a very different risk profile from a key per firm.
  5. Subprocessors and location. Which third parties touch the data and in which jurisdictions?
  6. Breach commitments. What notification timeline is contractual, not aspirational?
  7. Written agreement. Will the vendor sign terms covering confidentiality obligations? A vendor unwilling to put it in a contract has answered the question.

Question three and question four are the ones that separate serious legal vendors from general software. Most tools cannot answer them concretely.

Human review, tiered by consequence

Requiring attorney review of every AI output sounds rigorous and fails in practice, because a rule nobody can follow gets ignored entirely. Tier it by what happens if the output is wrong.

TierExamplesRequirement
Mandatory reviewCourt filings, client advice, demand letters, anything sent to an opposing partyAttorney reads in full before it leaves the firm
Verification requiredAny citation, statutory reference, or deadlineChecked against the primary source, every time, no exceptions
Spot checkInternal summaries, first-pass document sorting, research starting pointsSampled periodically, output labeled as AI-assisted

The citation row deserves its own line because it is the failure mode that has actually produced sanctions. Courts across multiple jurisdictions have disciplined lawyers for filings containing citations that did not exist. Verification against the primary source is the single highest-value control in this entire article.

What a vendor answer looks like when it is real

Articles on this subject usually end by telling firms to ask hard questions. Here are our answers to our own list, so you have a reference point for what a specific answer sounds like.

Tenant isolation and key custody. Each firm's integration credentials are encrypted under a data key belonging to that firm alone. Those keys live in a dedicated table that denies all access by default and is readable through exactly one code path. The key that wraps them is derived through a separate key-derivation step, so possession of one firm's encrypted material does not help an attacker reach another firm's.

Verification. Statutory deadlines are computed only where the underlying rule has been attorney-verified. Where a rule is unverified, the platform reports the gap and declines to produce a date. That costs a feature and is the correct trade, because a confident wrong deadline in a calendar is worse than a blank field: it looks handled.

Output review. Generated language that could read as legal advice is routed to a review queue rather than shipped silently, and the underlying rules are documented in our UPL compliance guide for legal AI platforms.

Where to start this week

If your firm is currently AI-adjacent, the highest-value hour is spent on inventory rather than policy. Find out which tools attorneys are already using, on what, and under whose account. Firms are consistently surprised, and you cannot govern what you have not enumerated.

After that, the sequence is covered in what makes a firm AI-native, the policy contents in what belongs in a law firm AI use policy, and the resource-constrained version in AI adoption for small and midsize firms.

Frequently asked questions

How should a firm protect client confidentiality when using AI?

Three written answers before client data moves: retention window, whether inputs train the model, and whether a configuration exists that contractually prevents both. Rule 1.6 requires reasonable efforts, and reasonable efforts begin with knowing the terms.

What is ABA Formal Opinion 512?

The ABA ethics committee's July 2024 guidance applying existing Model Rules to generative AI: competence, confidentiality, communication, supervision, candor, and fees. It creates no new rules and is most emphatic about the lawyer's independent verification of output.

Which AI outputs require mandatory attorney review?

Anything filed with a court, sent as client advice, relied on for a matter decision, or communicated to an opposing party. Citations and deadlines require source verification in every tier without exception.

What should vendor evaluation cover?

Retention, training use, tenant isolation, key custody, subprocessors and data location, breach notification timelines, and willingness to sign written confidentiality terms. Tenant isolation and key custody are the two most firms forget to ask and the two that most reliably distinguish a legal-market vendor.

Can a small firm do this without a technology team?

Yes. Governance is reading and deciding rather than engineering, and it does not scale with headcount. What does not work at any size is deploying first and governing later.

This article is general information about legal technology governance. It is not legal advice and not an ethics opinion. Firms should consult their own counsel and their state bar's guidance, which may impose requirements beyond the ABA Model Rules, before adopting an AI policy or deploying any tool on client matters.

Ask us the seven questions.We answer themin writing.

Caseworth was built for firms that run a real vendor review. Per-firm key isolation, documented retention, no training on client data, and deadlines computed only from attorney-verified rules.