
Rules for AI in Your Law Practice
AI technology has probably already snuck into your office. Most people we talk to have tried it by now. They pasted a paragraph into ChatGPT to see what would happen, got something useful back, and quietly started using it for first drafts. Nobody set any ground rules. Nobody asked the client. It just sort of started.
That’s very similar to how how every office technology is adopted, from the fax machine forward. But the rules of professional conduct affect how lawyers use technology, AI is no exception. With that in mind here are some baseline things to consider.
1. No client information into free AI tools
Free consumer AI tools are not built for confidential material. They are built for volume, and their terms are written accordingly. When you paste a client’s financial disclosure, a draft trust, or an opposing party’s production into a free chatbot, you have disclosed it to a third party under terms you almost certainly have not read.
Prof.Cond.R. 1.6 requires you to “act competently to safeguard information relating to the representation of a client against unauthorized access by third parties and against inadvertent or unauthorized disclosure,” and to take “reasonable precautions to prevent the information from coming into the hands of unintended recipients.”
Two things people get wrong about this:
Anonymizing is not enough. A distinctive fact pattern in a small county is identifiable from three details. Removing the name does not make the matter unrecognizable.
“I just asked a general question” is a thin line. If your general question contains the actual facts, you have disclosed the actual facts.
If you take nothing else from this post: free tier, no client data. Ever.
2. Know what AI tools do with your data
Here is where most lawyers stop reading and just assume the paid version is fine. It usually is — but because of specific contract terms, not because you paid money. And the difference between tiers of the same product can be total.
The two largest vendors both publish this in plain language. It is worth seeing the actual words.
OpenAI, on its consumer products:
“When you use our services for individuals such as ChatGPT and Codex, we may use your content to train our models.”
OpenAI, on its business products:
“By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API.”
Anthropic, on its commercial products:
“By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.”
Anthropic’s consumer plans (Free, Pro, Max) work slightly differently: your conversations are used for model improvement only if you turn that setting on, if a conversation is flagged for safety review, or if you join an opt-in program.
So the two companies handle their consumer products differently from each other — OpenAI trains by default unless you opt out, Anthropic trains only if you opt in. That difference is exactly the point. You cannot reason from the logo. You have to check the product, the tier, and your own settings.
3. Consider client consent
Using AI to check a citation format does not require a client conversation. Using it to draft substantive work product on a client’s matter is a different question.
The practical middle ground most firms land on:
- Add a short, plain-language paragraph to your engagement letter describing that you may use AI-assisted tools, what safeguards you apply, and that you remain fully responsible for all work product.
- Get specific informed consent before putting confidential client material into any tool where there is real risk.
- If a client asks whether you use AI, answer straight. Always.
- If a client says not to use it on their matter, honor that and note it in the file.
And remember that Prof.Cond.R. 5.1 and 5.3 make this a firm-wide question. You are responsible for what your staff puts into these tools, not just what you put in yourself. Everyone who touches client files needs to know the rule, not just the lawyers.
4. Bill for the time you actually spent
This is not a new principle and it is not really about AI. The ABA has said for decades that “the economies associated with the result must inure to the benefit of the client.” AI is just a faster typewriter if you want to think of it that way.
5. Read everything AI writes for you. Then read it again.
In 2026 the Eleventh District Court of Appeals sanctioned an Ohio attorney who filed an application to reopen a murder appeal. The filing quoted statements attributed to the prosecuting attorney. The statements were never made ChatGPT invented them. Counsel had sworn to the truth of the filing under penalty of perjury.
Verification has to be broader than citations. Two months after his sanctions hearing, if an attorney files a motion that still contained the chatbot’s own closing question sitting in the body of the document asking whether he would like it to draft the next argument section.
So: verify every case, every quotation, every record cited against the original source. Then read the whole thing again, start to finish, the way you would read a brief a first-year associate handed you. Because functionally, that is what it is.
