Skip to main content
ABA Formal Opinion 512: An Ethics Control Matrix for Law Firm Generative AI

ABA Formal Opinion 512: An Ethics Control Matrix for Law Firm Generative AI

Fusion Legal & Tax · September 11, 2026Thought leadership9 min read

Generative AI governance can sound abstract until a lawyer pastes matter information into a tool, relies on its research, sends its draft to a client, files its language with a court, or records time for the work. At each point, governance becomes professional responsibility.

That is the practical significance of ABA Formal Opinion 512 (the full opinion, free from the ABA). Issued July 29, 2024, it was the ABA Standing Committee on Ethics and Professional Responsibility’s first formal opinion addressing lawyers’ use of generative AI. The opinion does not create a separate code of “AI ethics.” It applies familiar duties—competence, confidentiality, communication, supervision, candor, meritorious advocacy, and reasonable fees—to a technology whose outputs can be fluent without being reliable.

For law firms, the next step is therefore not another high-level statement that AI must be used responsibly. It is an ethics control matrix: a documented connection between each professional duty, the risk created by a particular AI workflow, the control that addresses that risk, and the evidence showing the control was followed.

Opinion 512 is a baseline, not a universal safe harbor

The first interpretive discipline is jurisdictional. The ABA Model Rules and Formal Opinion 512 provide an influential national framework, but lawyers remain governed by the professional-conduct rules adopted in their jurisdictions. Courts may also impose orders or local requirements addressing AI-assisted submissions. A current 50-state survey of AI and attorney-ethics guidance accordingly advises lawyers to check their governing bar’s latest rules and relevant court requirements because the landscape continues to evolve.

A firm should not describe compliance with Opinion 512 as proof that every state-law or tribunal-specific obligation has been satisfied. The more defensible posture is narrower: use Opinion 512 as the control architecture, then layer applicable state rules, client requirements, protective orders, and court directives onto it.

The six-duty control matrix

Ethical dutyWhat Opinion 512 requires firms to confrontOperational control
CompetenceUnderstand the tool’s capabilities, limitations, and risks; independently evaluate its workApproved-use cases, training, verification protocols, and human sign-off
ConfidentialityEvaluate how prompts, uploads, outputs, retention, and vendor access may expose client informationVendor review, data-classification rules, restricted inputs, and consent procedures
CommunicationDetermine when AI use is material to the representation or requires consultation or informed consentMatter-level disclosure triggers and documented client communications
SupervisionEnsure lawyers and nonlawyer personnel use approved tools consistently with professional obligationsWritten policy, role-based training, technical restrictions, and escalation paths
Candor and meritorious advocacyVerify factual assertions, authorities, quotations, and citations before submissionSource-level review and filing certification workflow
Reasonable feesBill for work actually performed and assess whether AI-related charges are reasonableTime-entry guidance, expense rules, and review of fixed-fee assumptions

The value of this matrix is not the table itself. It is the requirement that each row become part of the firm’s daily workflow.

1. Competence means understanding the specific tool and checking its work

Model Rule 1.1 requires the “legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation,” including an understanding of the “benefits and risks associated” with technology used to provide legal services. The ABA’s summary of Opinion 512’s competence analysis places generative AI inside that existing obligation.

This does not require every lawyer to become a machine-learning engineer. It does require more than knowing how to enter a prompt. As summarized by Practical Law, lawyers must “reasonably understand the GenAI tool’s capabilities and limitations” and independently verify its output.

A competence control should answer:

  • What tasks is this tool approved to perform?
  • Does it retrieve identifiable authorities, predict text, summarize supplied documents, or combine those functions?
  • What sources can the user inspect?
  • What happens when the tool lacks sufficient information?
  • What categories of output require primary-source verification?
  • Who remains responsible for the final legal judgment?

The important distinction is between output review and professional judgment. A lawyer may confirm that a quotation appears in a case and still fail to assess whether the case remains good law, applies in the relevant jurisdiction, or supports the proposition asserted. Verification protocols must therefore test both source accuracy and legal significance.

2. Confidentiality begins before information enters the prompt

Model Rule 1.6 covers information relating to a representation, regardless of its source, unless disclosure is authorized or another exception applies. Opinion 512 asks lawyers to consider whether information entered into a generative AI system could be accessed, retained, reused, or disclosed beyond the firm.

The relevant review is tool-specific. Practical Law’s detailed summary says lawyers should examine the provider’s terms of use, privacy policy, contractual provisions, and data-handling practices, consulting technology professionals when necessary. That assessment should address at least:

  • whether prompts or uploaded documents are retained;
  • whether inputs or outputs may be used for model training or product improvement;
  • whether vendor personnel or subprocessors may access the information;
  • whether the firm can control retention and deletion;
  • whether access is segregated by user and matter;
  • whether contractual confidentiality and security commitments apply; and
  • what happens to firm data when the relationship ends.

A useful internal rule is: treat every prompt and upload as a proposed data transfer until the firm’s review establishes otherwise. Labels such as “enterprise,” “private,” or “legal AI” should begin the diligence inquiry, not conclude it.

Client consent is also not reducible to generic engagement-letter boilerplate. The ABA’s Rule 1.6 summary emphasizes informed consent when protected information would otherwise be disclosed. At the same time, Opinion 512 does not impose a blanket rule that every use of AI must always be disclosed; the need for disclosure or consent depends on the use and its implications, as the state-by-state ethics overview notes.

Firms need a decision tree, not a universal checkbox.

3. Client communication should be triggered by materiality

Model Rule 1.4 requires lawyers to “reasonably consult” with clients about the means used to pursue their objectives. In the AI context, the communication question is not simply, “Was software involved?” Legal research platforms, document-management systems, and drafting tools have long been part of legal work.

The stronger question is whether the particular AI use is material to the client’s decisions, confidentiality expectations, agreed scope, cost structure, or confidence in the work. The ABA’s discussion of Model Rule 1.4 ties the duty to information important for the client to receive and consultation about the means used to accomplish the client’s objectives.

A firm’s communication protocol should identify triggers such as:

  1. entering information relating to the representation into a system whose operation creates a consent issue;
  2. using AI in a way that materially affects how a significant task will be performed;
  3. a client’s express instruction, outside-counsel guideline, or engagement term governing AI;
  4. an AI-related expense the firm proposes to pass through; or
  5. a client question about whether or how AI was used.

The resulting conversation should be concrete: the tool, the task, the information involved, the anticipated benefit, the material risks, and the safeguards. Transparency is useful only when it gives the client enough precision to make an informed decision.

4. Supervision requires policy, training, and technical enforcement

Rules 5.1 and 5.3 extend the analysis beyond the individual lawyer operating the tool. Practical Law’s summary explains that firms should make reasonable efforts to ensure that personnel are trained and comply with professional obligations concerning secure data handling, privacy, and confidentiality.

That makes a purely aspirational policy inadequate. A workable supervisory program should include:

  • an approved-tools register with designated owners;
  • prohibited, conditionally permitted, and ordinary use cases;
  • role-based access rather than shared accounts;
  • restrictions on confidential or personally identifying data;
  • mandatory source verification for legal and factual assertions;
  • separate review requirements for client communications and tribunal filings;
  • training for lawyers, paralegals, administrative personnel, contractors, and temporary staff;
  • a process for reporting unintended disclosures or unreliable outputs; and
  • scheduled reassessment when a vendor changes its model, terms, integrations, or retention practices.

Supervision also reaches procurement. If the technology committee approves a system without involving lawyers responsible for ethics, information security, records management, and billing, the firm may evaluate the product’s features without evaluating the legal workflow it will enter.

5. Candor turns verification into a filing control

Generative AI may produce persuasive prose while misstating facts, inventing authorities, altering quotations, or omitting controlling law. Under the duties of candor and meritorious advocacy, the lawyer—not the software provider—remains responsible for material submitted to a tribunal.

Practical Law’s account of Opinion 512 states that AI-assisted work must be carefully reviewed so that citations, assertions, analysis of authority, and arguments are not false. The control should be source-level and reproducible:

  • open every cited authority;
  • confirm the court, date, jurisdiction, and precedential status;
  • compare every quotation with the source;
  • verify record citations and factual assertions;
  • conduct the analysis needed to identify adverse or controlling authority; and
  • check applicable local rules, standing orders, and judge-specific directives concerning AI.

“Human reviewed” is too vague to be a control. Firms should define what was reviewed, against which sources, by whom, and before which external use.

6. AI efficiency must be reflected honestly in fees

Opinion 512’s clearest operational example concerns hourly billing. The ABA states that if a lawyer spends 15 minutes prompting a tool to draft a pleading, the lawyer may charge for that time and for the time reasonably needed to review the draft for accuracy and completeness. But “in most circumstances, the lawyer cannot charge a client for learning how to work a GAI tool”.

The core principle is straightforward: AI does not convert time that was not worked into billable time. Nor does it make every software charge a reimbursable client expense. Firms should distinguish among:

  • time actually spent performing and reviewing client work;
  • general training and firm overhead;
  • matter-specific technical work that may be reasonably necessary;
  • subscription costs absorbed by the firm; and
  • expenses the engagement permits the firm to pass through.

Fixed and contingent fees require a reasonableness analysis under their governing rules and agreements; they should not be treated as permission to ignore substantial changes in how work is performed. AI adoption should prompt firms to revisit pricing assumptions, staffing leverage, quality-control time, and the value delivered—not to recreate hypothetical hours that automation eliminated.

The implementation question: can the firm produce evidence?

A mature AI program should be able to show more than the existence of a policy. Depending on the workflow, useful evidence may include:

  • the approved version and configuration of the tool;
  • completed vendor-security and confidentiality review;
  • the use case for which approval was granted;
  • training records;
  • client consent or communication where required;
  • source-verification and supervisory sign-offs;
  • incident and exception records; and
  • billing guidance tied to actual workflows.

Not every AI interaction needs a new administrative file. The documentation should be proportionate to the sensitivity of the data, the significance of the task, the reliability of the tool, and the destination of the output. A public-marketing outline and a dispositive-motion draft should not travel through identical controls.

That is the durable lesson of Formal Opinion 512. Responsible adoption is not a choice between innovation and protection. It is the work of designing systems in which lawyers can use capable tools while preserving the judgment, confidentiality, candor, communication, supervision, and billing discipline that make legal services trustworthy.

This article provides general educational information for legal-industry discussion and is not legal advice for any particular firm, lawyer, matter, or jurisdiction.

Have Questions?
Chat with Margot