Use-case guide
AI in Legal Services
Lawyers and AI are a high-friction combination — the profession is regulated, the use cases (research, drafting, e-discovery, due diligence) are all data-sensitive, and the malpractice consequences of getting it wrong are paid in disbarment proceedings rather than dollars. Multiple US courts have sanctioned counsel for filing briefs with AI-hallucinated case law. State bars (California, Florida, New York, DC) have issued formal opinions on AI use. The EU AI Act treats AI used in administration of justice as high-risk. And the underlying data — client confidences, settlement terms, IP — is among the most jealously guarded in any industry.
For: Law firm partners, in-house GCs, legal-tech founders, bar-association compliance officers, courts and judicial admin
What's at stake
Administration of justice is high-risk under the EU AI Act
Annex III §8 covers AI 'intended to be used by a judicial authority or on its behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts'. That includes legal-research and brief-drafting tools used by judges, court staff, and arguably by counsel preparing for court.
Hallucinated case law is a sanctionable offence
Multiple US federal courts have issued sanctions and standing orders requiring AI-tool disclosure or human verification of citations. The duty of candour to the tribunal does not yield to AI convenience.
Client confidentiality + AI vendors = vetted DPAs
Sending privileged or work-product material to a third-party AI vendor without proper data-processing terms, training-data carve-outs, and access controls is a per-se ethics violation in most jurisdictions. The ABA's Formal Opinion 512 (2024) is the gold standard reference.
Bills built on AI work invite challenge
Charging hourly for work substantially done by AI without disclosure has surfaced in fee disputes. Several state bars now require disclosure of AI assistance in bills above a certain materiality threshold.
Regulations that apply
EU AI Act
LawAI used to assist judicial decision-making is high-risk (Annex III §8). Full Annex III duty stack applies to providers AND deployers — including law firms procuring legal-tech for court-facing work.
Where in the text: Annex III §8; Articles 9-15.
ABA Formal Opinion 512 (2024)
GuidelineAuthoritative statement on lawyers' duties when using generative AI: confidentiality, communication with clients, charging for AI-assisted work, supervisory duties, and candour to tribunals.
Where in the text: ABA Standing Committee on Ethics and Professional Responsibility, Formal Op. 512.
US federal court AI standing orders
GuidelineEastern District of Texas, Northern District of Illinois, and a growing list of judges require pre-filing disclosure of AI use or human verification of all citations. Sanctions have been imposed under Rule 11.
Where in the text: Mata v. Avianca (S.D.N.Y. 2023); Park v. Kim (2d Cir. 2024).
GDPR + UK DPA + state privacy laws
LawClient data sent to AI tools is processed data; vendor selection, data-transfer mechanisms, retention, and subject-access rights all apply. Special-category data (health, criminal records) has further constraints.
Where in the text: GDPR Articles 5, 6, 28, 32, 35.
Do
- ✓Verify every legal citation an AI produces against a primary-source database before filing or sending. Hallucination rates on case law remain materially non-zero.
- ✓Use a vetted enterprise AI tool with a strong DPA, no-training carve-out, SOC 2 controls, and a kill-switch for client matters. Public ChatGPT-style consumer tiers are not safe for privileged matter.
- ✓Disclose AI use to the court when a local order or rule requires it, AND to the client per ABA Op. 512's communication duty.
- ✓Build a firm-wide AI policy covering vendor approval, allowable use cases, supervisory expectations for associates/paralegals, and client-engagement-letter language.
- ✓Maintain an AI training programme for fee-earners. Courts and bars increasingly distinguish between supervised, competent AI use and reckless use.
Don't
- ✗Don't paste a client's confidential settlement memo into a consumer LLM. Even pseudonymised, that's an ethics complaint waiting to happen.
- ✗Don't rely on AI's confidence as a quality signal — these models hallucinate citations with high conviction.
- ✗Don't bill substantial hours for work the AI did and you reviewed in minutes without making the billing reflect that — courts and clients have started discovery on this in fee disputes.
- ✗Don't deploy AI in judicial-facing functions inside the EU without confirming the supplier's AI Act conformity package; the deployer is liable too.
- ✗Don't ignore state-specific AI rules — California, Florida, NY, DC, and several others have AI-specific bar guidance that goes beyond ABA Op. 512.
Also worth knowing
Watch the ABA's Model Rules update cycle — Rule 1.1 (competence) and Rule 1.6 (confidentiality) are being amended in many states to address AI explicitly. For UK and Commonwealth firms: the SRA's 2024 guidance and the Law Society's AI policy provide jurisdiction-specific framing. EU-side, the Council of Bars and Law Societies of Europe (CCBE) has issued cross-border ethical guidance for AI use.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.