Chapter Nine

Ethics and Lawyer Oversight of AI Legal Research

The ethics of AI legal research are governed by rules of professional conduct already in force, principally competence, confidentiality, communication with the client, supervision of assistance, and candor to the tribunal. A lawyer who uses an AI legal research agent owes the client what she owes when the work is done by an associate or a contract research service. She must understand the tool, supervise what it produces, protect the client's confidences, and answer for every statement that goes out under her name. ABA Formal Opinion 512, issued in July 2024, reached that conclusion for generative AI generally, mapping the technology onto the Model Rules rather than writing new ones.

Yes. Lawyers can ethically use AI for legal research under their own supervision, the way the profession has always used assistance a lawyer did not personally perform. No rule of professional conduct prohibits it. Formal Opinion 512 and the state guidance that followed treat the threshold question as settled. They address instead the conditions that attach to the use.

Those conditions run through the whole opinion. It opens by stating that lawyers using generative artificial intelligence tools "must fully consider their applicable ethical obligations," then works through competence, confidentiality, communication, supervision, candor to the tribunal, and fees in turn. Every one of those duties survives the arrival of the technology intact. The tool is a new place a lawyer has to look to satisfy them.

State authorities moved faster than the ABA and reached the same conclusions. The Florida Bar issued Opinion 24-1 in January 2024. The Texas ethics committee followed in February 2025 with Opinion 705, which states that a lawyer must independently verify AI-generated content before relying on it. California's Committee on Professional Responsibility and Conduct revised its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law in 2026, at the California Supreme Court's request, to address agentic AI specifically. All of these are advisory. What binds a lawyer is the rule of professional conduct in her own jurisdiction. The opinions say how the committees read it.

The duty of competence may come to point toward these tools rather than away from them. No authority says so today. Neither Comment 8 nor Formal Opinion 512 suggests that a lawyer risks a competence problem by declining to adopt AI. Our own expectation is that the question arrives eventually, in the way the profession's expectations about electronic research and electronic filing arrived. When it does, it will belong to each lawyer and firm to answer.

Read together, the rules and the guidance settle on responsibility rather than on permission or prohibition. A lawyer may use an AI legal research agent. She may not hand it her professional judgment. The California committee states the principle in one line: "any use of AI must not diminish or abdicate professional judgment."

When a lawyer uses AI for legal research, the ethics rules require competence in the tool, supervision of the work it produces, protection of the client's confidences, communication with the client where the use bears on the representation, and candor to the tribunal about the authorities in any filing. Responsibility for the finished work product stays with the lawyer.

DutyModel RuleWhat it requires in AI legal research
Competence1.1Knowing how the tool retrieves and states the law, the errors it produces, and which of its statements the lawyer must still confirm
Confidentiality1.6Reasonable efforts against inadvertent or unauthorized disclosure of information relating to the representation, and against unauthorized access to it
Communication1.4Consulting the client where the use bears on the representation, the fee, or the client's own instructions
Meritorious claims and candor3.1 and 3.3Confirming every authority and quotation in a filing before it is signed
Supervision5.1 and 5.3Reasonable efforts to ensure the assistance is compatible with the lawyer's professional obligations
Fees1.5Charging for the lawyer's time actually spent rather than for the time the tool saved

Competence and supervision do most of the daily work. Competence requires the lawyer to understand the tool well enough to use it responsibly and to evaluate its work product critically. Supervision requires a lawyer using nonlawyer assistance to make reasonable efforts to ensure that the assistance is compatible with her professional obligations. An AI legal research agent is nonlawyer assistance of a new kind, so Rule 5.3 applies to it as naturally as it applies to a paralegal or a contract research service.

The candor duties reach the courtroom, where an unchecked citation carries immediate consequences. A lawyer certifies the legal contentions in a filing when she signs it, whatever produced the draft. Texas Opinion 705 states that a lawyer must independently verify AI-generated content before relying on it. The California committee states that the duty of candor to the tribunal cannot be delegated to AI. Neither treats the tool's fluency as a substitute for the lawyer's own confirmation, which is why a legal research system built to be confirmed rather than trusted makes the duty practical to discharge at the volume an agent produces.

No jurisdiction has yet put artificial intelligence into its rules of professional conduct. California has come closest. Directed by the state Supreme Court in an August 2025 letter, COPRAC approved a package of proposed amendments on March 13, 2026 that would write AI into six existing rules rather than create a standalone AI rule. The proposals reach competence, communication, confidentiality, candor to the tribunal, and the supervision of both lawyers and staff. One would provide that a lawyer's duty "includes the obligation to verify the accuracy and existence of cited authorities, including ensuring no cited authority is fabricated, misstated or taken out of context, before submission to a tribunal, including any cited authorities generated or assisted by artificial intelligence or other technological tools." The comment period closed on May 4, 2026. The amendments are not final. The California Supreme Court has the last word.

Everywhere else the obligations come from rules drafted before any of this technology existed, applied to a new kind of assistant. Because that application is being worked out jurisdiction by jurisdiction, a lawyer admitted in more than one state has more than one body of guidance to follow.

The duty of technological competence requires a lawyer using AI for legal research to know how the tool states the law, the errors it produces, and which of its statements she must still confirm. Comment 8 to ABA Model Rule 1.1 is the source, providing that maintaining competence means keeping abreast of "the benefits and risks associated with relevant technology."

Forty states have adopted the duty of technology competence in some form, joined by the District of Columbia and by Puerto Rico, which in 2025 created a freestanding rule for it rather than a comment. LawSites has tracked the adoptions since the ABA amended Comment 8 in 2012. In most American jurisdictions the duty is adopted and in force, whatever the comment's hortatory phrasing suggests.

Lawyers need not become experts in generative AI. Formal Opinion 512 calls instead for a reasonable understanding of the capabilities and limitations of the specific tool a lawyer uses, for the specific task at hand. The opinion treats that understanding as a standing obligation to be kept current rather than a one-time acquisition, reasoning that the pace at which these tools change requires lawyers to stay vigilant about their benefits and risks.

Agentic systems ask more of the lawyer, because they act between her instructions. The California committee directs a lawyer to understand the extent of a system's autonomy, the circumstances in which it acts without prompting, the data sources it can reach, and the safeguards standing between it and an error. The committee states the relationship as a sliding scale, in which the greater the system's autonomy, the greater the lawyer's obligation to put oversight in place.

Competence in a legal research tool comes down to a few determinable facts about it. A lawyer should know whether its statements are grounded in primary law or generated from a model's parameters, whether the authorities it cites are confirmed to exist and to remain good law before the work product is delivered, and whether the propositions it writes have been checked against the passages cited to support them. Grounding in curated primary law is the subject of Chapter 5. Citator verification of good law is Chapter 6. The audit that compares each legal proposition against its cited passage is Chapter 8. Whatever the system leaves unchecked, the lawyer checks herself.

The lawyer is responsible for AI legal research output, completely and without dilution. Responsibility for legal advice cannot be delegated to software. Neither a vendor's accuracy claim nor a disclosure to the client transfers any part of it. The lawyer who signs a filing certifies its legal contentions, whatever produced the draft.

Rule 11 is where that certification lives. A lawyer signing a filing certifies that its legal contentions are warranted by existing law or by a nonfrivolous argument for extending, modifying, or reversing it. The certification is personal to the person who signs, which is why courts sanctioning lawyers over fabricated citations have reached the signature rather than the software that produced the text.

The exposure is professional rather than commercial. A fabricated citation in a filing draws sanctions against the lawyer who signed it. Research the lawyer never confirmed, acted on by a client to its cost, supports a malpractice claim that names the lawyer. A vendor's contract may allocate commercial risk between the firm and the vendor. It cannot allocate a professional duty, which runs from the lawyer to the client and to the court. The California committee reaches the same conclusion, stating that a lawyer remains fully responsible for any work product generated with the assistance of AI.

Undiluted responsibility is a design requirement before it is a warning. If the lawyer answers for every legal proposition, the system that produces those propositions has to be built so she can confirm them. That means a pinpoint citation identifying the passage behind each statement, a record of the checks already performed, and an interface that places the source passage beside the statement it supports. The failures that make the checking necessary, the invented citation and the misstated authority, are the subject of Chapter 7. Chapter 8 describes the validation audit that answers them.

The alternative design asks the lawyer for faith. A system that returns a confident narrative with citations at the end, with no way to trace a statement to the language supporting it, leaves her holding a duty she has no efficient means to discharge. The duty remains the lawyer's. Only the difficulty of satisfying it changes.

A lawyer supervises an AI legal research agent under Model Rule 5.3, making reasonable efforts to ensure the agent's work is compatible with her own professional obligations. In practice that means framing the research question, keeping the agent's research plan visible, requiring a citation for every legal proposition, and reviewing the finished memorandum before any of it becomes advice.

Rule 5.3 already governs a paralegal and a contract research service, so the supervision a partner gives a junior associate is the working analogy for an agent. Every firm already runs that workflow. The lawyer brings the agent the facts of the matter, the pleadings, and the issue to be researched, then reads what comes back. Between those two moments the agent works, adjusting and extending the scope as the research teaches it more, with its plan and its steps visible to the lawyer throughout. Chapter 8 sets out what that review consists of once the memorandum is validated.

Rule 5.3 asks for reasonable efforts, a standard about method rather than outcome. When the assistant is software, reasonable efforts take the form of a research plan the lawyer can inspect, sources identified for every statement, checks whose results are recorded, and a review that happens before the work product becomes advice. Each of those is a property of the system, which is why tool selection largely determines whether supervision is possible at all.

The duty reaches past the individual matter. Formal Opinion 512 states that managerial lawyers must establish clear policies on the firm's permissible use of these tools. It states as well that supervisory obligations include ensuring subordinate lawyers and nonlawyers are trained in their ethical and practical use. The California guidance adds that policies and training need revisiting as the systems change. A firm with no written policy has a harder case to make that it took reasonable efforts, however carefully its individual lawyers work.

Agentic capability draws a further line. The California committee states that a lawyer may not deploy an agentic system in a way that lets it make substantive legal determinations, communicate legal advice, prepare and file pleadings, or otherwise act in a representative capacity without meaningful supervision and review. Research delivered for a lawyer's review sits comfortably on the permitted side. Autonomous filing crosses the line.

The profession has run this workflow for a century. No one expects a first-year associate's memorandum to reach the client unreviewed. The same expectation governs the agent. A system designed for oversight makes that review fast.

A law firm protects client confidentiality in AI legal research by controlling the client information entered into the tool, restricting the firm systems the agent can reach, and getting written answers from the vendor before any client matter touches it. Rule 1.6 requires reasonable efforts against inadvertent or unauthorized disclosure of information relating to the representation, and against unauthorized access to it.

A legal research question carries the facts of the matter into the tool. It carries the theory the lawyer is testing and, often, the weakness she is testing for. A question about whether a particular course of conduct triggers a particular liability tells any reader a great deal about the client. Research prompts hold more than they appear to hold.

A firm resolves most of the analysis by putting concrete questions to the vendor before the first matter runs. The questions are whether the platform holds recognized independent security certification, whether agent activity is restricted to the matters and documents the active user is authorized to access, whether client data is used to train models, and whether especially sensitive work can run on infrastructure under the firm's own control. The answers belong in writing. The California guidance states that reasonable efforts require more than reliance on generalized marketing assurances. Chapter 11 sets out the evidence to ask for on each of these questions at the evaluation stage, and what a thin answer looks like.

Formal Opinion 512 answers the training question directly. Where a tool is self-learning, so that information entered into it may surface in responses to other users, the opinion concludes that a client's informed consent is required before the lawyer inputs information relating to that client's representation. Knowing which category a tool falls into is part of the competence duty. The answer belongs in writing from the vendor rather than in inference from a privacy policy.

An agent connected to firm email, document management, and matter files holds persistent reach into confidential information across every client the firm serves. The California guidance directs lawyers to evaluate and limit that scope, warning that a poorly configured agentic system may disclose confidential information across matters or expose privileged material. The safeguard is to bind the agent to the permissions of the user who directed it, so its reach matches that lawyer's reach exactly.

Sometimes. No rule imposes a blanket duty to disclose that AI was used. Formal Opinion 512 calls for disclosure when the client asks how the work was done, when the engagement agreement or the client's outside counsel guidelines require it, when the use bears on the basis or reasonableness of the fee, and when the tool's work product will influence a significant decision in the representation.

The duty behind those circumstances is Rule 1.4, which requires a lawyer to consult with the client about the means used to pursue the client's objectives. The opinion declines to catalogue every case. The governing question stays the one Rule 1.4 always asks, which is what this client must know to make an informed decision about the representation.

Entering client information into a self-learning tool calls for informed consent rather than notice, obtained in advance rather than reported afterward. Disclosure tells the client what happened. Consent gives the client the decision.

Many sophisticated clients have already answered the question in their outside counsel guidelines, which are the first place to look on any matter. Some prohibit generative AI outright, some require notice, some require consent, and some say nothing, leaving the lawyer to apply Rule 1.4 herself. The courts have added an obligation of their own, now court-system wide rather than judge by judge. New York's Unified Court System adopted Part 161 in March 2026, effective June 1, 2026, which permits the use of AI in preparing a submission and requires no disclosure of it. What it requires instead is that the filer independently review the paper for fabricated or fictitious cases, statutes, or other material, with the signature certifying that the review was done. Disclosure and certification requirements vary, so the local rules deserve a look alongside the engagement letter.

The clean practice is to settle the question at the front of the engagement. A short provision in the engagement letter satisfies the communication duty in most matters, describing the firm's use of AI legal research tools, the safeguards applied, and the lawyer's continuing responsibility for the work. What the firm may charge for that work is a separate question, taken up in Chapter 10.

AI legal research produces research, never advice, because the agent has no knowledge of the client, the strategy, or the forum. Authority runs thin on questions of first impression, leaving the system less to ground its statements on. The underlying corpus may not cover every jurisdiction a practice touches. And well-cited prose invites more confidence than any individual legal proposition has earned.

The knowledge limit is the one nothing in the system can close. The agent does not know that the judge assigned to the matter has ruled the other way twice, that the client will not tolerate the remedy the strongest argument would require, or that the matter is worth settling regardless of the law. Turning legal research into advice requires exactly what the agent has no access to, which is the reason the profession's supervision model fits this technology so closely.

Where the law is thin, fewer authorities exist for the system to rest a statement on. Thin support should be visible in the work product rather than papered over. A memorandum that reports the absence of controlling authority and shows what it found in adjacent doctrine instead is doing its job. One that assembles a confident answer from three loosely analogous cases overstates its support.

Jurisdictional coverage repays testing. A tool strong on federal case law may be thinner on the state trial court decisions the practice actually turns on. Coverage claims are easy to test with authorities the lawyer already knows, which is work for the evaluation stage that Chapter 11 covers in full.

Automation bias, the tendency to accept a machine's conclusion because a machine produced it, compounds all of these, because it operates on the lawyer rather than on the system. The California guidance notes that generative AI encourages reliance because it generates responses in a manner that projects confidence. Work product that reads like a careful associate's memorandum receives the benefit of the doubt that years of careful associates have earned. Work product that places each source passage beside the legal proposition it supports answers that problem directly. Confirming a statement costs seconds. Trust becomes something the lawyer checks rather than something she extends.