Skip to main content
How Do Law Firms Keep Up With State Bar AI Guidance?

How Do Law Firms Keep Up With State Bar AI Guidance?

Fusion Legal & Tax · September 25, 2026Thought leadership8 min read

The emerging body of state-bar AI guidance is often presented as a map: identify the jurisdiction, read its opinion, and add the jurisdiction to a compliance checklist. That is useful research, but it is not yet a durable way to protect clients, preserve lawyers’ judgment, and support thoughtful AI adoption.

The stronger model is jurisdictional change control. A firm should be able to identify which authority governs a matter, translate that authority into an operational safeguard, detect when the authority changes, and preserve evidence that the safeguard was followed.

That distinction matters because AI guidance does not arrive in one standardized form. It may appear as a formal ethics opinion, an informal advisory opinion, practical guidance, an amendment to professional-conduct rules, or a court-specific order. In jurisdictions without AI-specific guidance, lawyers still operate under existing duties involving competence, confidentiality, communication, supervision, candor, and reasonable fees.

As the Spellbook state-bar overview reported in June 2026, regulators continue to apply those established duties to changing AI capabilities. So the question worth asking is not simply, “Does this state have an AI opinion?” It is: What rules, guidance, and tribunal requirements apply to this use, in this matter, today?

ABA Formal Opinion 512 is a baseline—not a safe harbor

The ABA Standing Committee on Ethics and Professional Responsibility released Formal Opinion 512 on July 29, 2024. The ABA described it as its first formal opinion addressing lawyers’ growing use of generative AI.

Opinion 512 is an important organizing framework, particularly where a jurisdiction has not published AI-specific guidance. But firms should classify it accurately: the ABA Model Rules and an ABA formal opinion do not automatically displace the professional-conduct rules adopted in a lawyer’s licensing jurisdiction.

The opinion says lawyers using generative AI must “fully consider their applicable ethical obligations.” Its framework centers on:

  • Competence: Model Rule 1.1 requires the “legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation,” including an understanding of “the benefits and risks associated” with technology used to deliver legal services.
  • Confidentiality: Under Model Rule 1.6, a lawyer must protect information relating to a representation, regardless of its source, unless the client gives informed consent or another exception applies.
  • Communication: Model Rule 1.4(a)(2) requires a lawyer to “reasonably consult” with the client about the means used to accomplish the client’s objectives.
  • Fees: Model Rule 1.5 requires reasonable fees and expenses. The ABA explains that a lawyer who spends 15 minutes prompting a tool may charge for that time and the time reasonably required to review the resulting draft for accuracy and completeness. “In most circumstances,” however, the lawyer may not charge a client for learning to operate the tool.

Those principles are a national reference point. They are not a substitute for checking state rules, the terms of an applicable ethics opinion, and the requirements of the tribunal before which the lawyer is appearing.

How state guidance changes the analysis

Two documents can address similar AI risks while carrying different authority, scope, and publication histories.

Missouri’s Informal Opinion 2024-11, adopted April 25, 2024, expressly identifies itself as an informal opinion and says it is not intended to provide an exclusive list of ethical considerations. It directs lawyers developing firm AI policies to consider rules involving competence, confidentiality, candor, duties to opposing parties and counsel, supervision, and professional independence.

On competence, the Missouri opinion quotes the governing rule: “A lawyer shall provide competent representation to a client. Competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.” It also states that lawyers should obtain education and training to determine which generative-AI systems are appropriate for firm use, recognizing that not every platform is designed for lawyers.

California illustrates how practical guidance can translate established duties into operational safeguards. The State Bar’s Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law says lawyers must not input confidential client information into a generative-AI system that lacks adequate confidentiality and security protections. It advises lawyers to anonymize client information where possible and review the tool’s terms of use, privacy policy, and related contractual terms.

The guidance also warns that generative-AI output “could include information that is false, inaccurate, or biased.” Lawyers must critically review and correct generated work, including citations to authority, before submitting it to a court.

For compliance teams, the lesson is larger than either state’s particular approach: saving an ethics document is not enough. Firms need to know whether it remains current and whether its status is formal, informal, advisory, or mandatory.

Build an AI authority register—not merely an approved-tools list

Most law-firm AI programs begin with vendor approval. That is necessary, but it answers only whether a product may be available for use. It does not establish whether a particular use is appropriate for a particular client, matter, jurisdiction, or tribunal.

A more useful safeguard is an AI authority register. For every jurisdiction in which the firm regularly practices, the register should record:

FieldWhat the firm should capture
JurisdictionLicensing jurisdiction, matter jurisdiction, and tribunal
Source typeConduct rule, formal opinion, informal opinion, practical guidance, standing order, local rule, or judge-specific order
Authority levelBinding, interpretive, advisory, or informational
Publication and effective datesIncluding the date last checked
Supersession statusCurrent, amended, withdrawn, or replaced
Covered technologyGenerative AI, transcription, agentic systems, research, drafting, analytics, or other uses
Triggering activityClient-data input, court filing, autonomous action, client communication, or billing
Required safeguardReview, consent, disclosure, supervision, vendor diligence, data restriction, or fee review
Control ownerResponsible lawyer, practice leader, general counsel, privacy lead, or technology team
Evidence retainedReview record, approval, client communication, training record, or vendor assessment

This register should link directly to the operative document—not merely to a news article, survey, or bar-association landing page. Secondary summaries can help teams discover developments, but the person updating a firm safeguard should verify the underlying authority.

Turn ethical duties into practical safeguards

Policies become useful when a firm can tell whether lawyers and staff are actually following them. Each core duty should therefore map to a workflow and an evidence trail.

1. Competence becomes use-case qualification

Tool familiarity is not the same as competent use. Before deploying AI for a new category of work, a firm can document:

  • what the system is expected to do;
  • what inputs it will receive;
  • where its outputs will be used;
  • what failure modes are reasonably foreseeable;
  • what level of lawyer review is required; and
  • whether the reviewing lawyer has access to the underlying authorities or source materials.

The objective is not to make every lawyer a machine-learning engineer. It is to ensure that the responsible lawyer understands the tool well enough to protect the client and exercise independent professional judgment.

2. Know exactly where client information goes

“Approved vendor” should not mean “all data may be entered.” The firm should identify:

  • whether prompts and uploaded documents are retained;
  • whether inputs may be used to train or improve a model;
  • which subprocessors or third parties may receive data;
  • whether administrators can access prompts or outputs;
  • what deletion, access-control, and incident-response terms apply; and
  • which categories of client or matter information are prohibited from the system.

Client consent is not a universal cure, nor is it universally required. Firms should evaluate communication and consent under the governing rules and the circumstances of the representation.

3. Go back to the source, every time

A lawyer should not treat a fluent answer as verified legal work. A meaningful review requires the reviewer to return to the cited case, statute, regulation, record, or contract provision—not merely ask the same model whether its first answer was accurate.

For court-bound work, the review record might identify:

  • the lawyer who performed the review;
  • the date of review;
  • the authorities checked;
  • whether quotations and record citations were compared with their sources; and
  • whether the relevant court has an AI disclosure rule, certification, standing order, or filing restriction.

This is protective infrastructure: it supports careful advocacy while keeping responsibility with the lawyer.

4. Supervision becomes role-based access and escalation

AI policies should apply to partners, associates, contract lawyers, paralegals, and administrative staff. Access should correspond to training and role. Higher-risk uses—such as substantive legal analysis, client-facing output, court filings, or tools capable of taking actions—should have a defined escalation path.

A tool that can send a message, modify a document repository, retrieve client files, or initiate another process presents a different control question from a chatbot that produces text for review. Firms should assess access and supervision based on what a system can do, not simply how the vendor labels it.

5. Reasonable fees become time-entry integrity

AI efficiency should be reflected honestly in timekeeping. The ABA’s July 2024 summary permits billing for time actually spent prompting and reviewing output, while stating that, “in most circumstances,” a lawyer cannot bill a client for learning to use a generative-AI tool.

A workable billing safeguard can require lawyers to record the task actually performed, the actual time spent, and the substantive review completed. Firms may also need separate decisions about whether vendor charges are overhead or properly chargeable expenses under governing rules and engagement terms.

When guidance changes, how does your policy keep up?

A state-by-state spreadsheet without an owner will age quickly. Firms should establish a recurring process:

  1. Monitor licensing jurisdictions, active litigation forums, and jurisdictions material to transactional matters.
  2. Triage each development by authority level, effective date, affected technology, and practice group.
  3. Compare the development against current policies, engagement language, vendor configurations, billing procedures, and court-filing workflows.
  4. Approve the necessary change through a designated ethics or AI-governance owner.
  5. Implement the change through technical restrictions, templates, training, or matter-specific instructions.
  6. Record the effective date, decision-maker, affected users, and evidence of rollout.
  7. Retire superseded guidance while retaining the prior version for audit and matter-history purposes.

For a Colorado-based firm, that process should begin with Colorado’s governing professional-conduct framework and the requirements of the relevant Colorado tribunal. Federal matters, multistate representations, and lawyers admitted elsewhere can add other layers. The controlling analysis should follow the actual matter and lawyer—not the location of the firm’s headquarters or its software vendor.

The strategic opportunity is disciplined adoption

Rapidly evolving guidance does not require law firms to choose between innovation and professional responsibility. It requires them to connect the two.

The firms best positioned to adopt AI will not necessarily be those with the longest list of tools. They will be those that can show how each use was authorized, what information it could access, who reviewed its output, which jurisdictional requirements applied, and how the firm updated its safeguards when those requirements changed.

That is the next stage of legal AI governance: moving from static policy to a living, jurisdiction-aware compliance system that helps lawyers use new capabilities thoughtfully while preserving the judgment, confidentiality, candor, and accountability on which the profession depends.

Have Questions?
Chat with Margot