Butler Snow had a written AI policy from June 2023, an AI committee and more than 400 lawyers. In July 2025 Judge Anna Manasco still disqualified three of its partners, reprimanded them publicly and referred them to the Alabama State Bar over fabricated citations, while sparing the firm. Her verdict on the paperwork: “They benefitted from repeated warnings, internal controls, and firm policies about the dangers of AI misuse… And yet here we are.”

That is the first thing to understand about AI ethics rules for lawyers in 2026. There are now a great many of them, and they all say the same thing: the old rules apply in full, and the lawyer, not the tool, is responsible. What differs between the ABA, the SRA, the CCBE, BRAK and ÖRAK is the detail. When is consent needed? What must the vendor contract say? Does the court want a certificate? Is the sanction a costs order or a criminal statute?

This page is the map: six duties across fourteen jurisdictions, each with its source, its date and the one thing it adds to the baseline.

The six duties every jurisdiction touches

Nobody has invented a new rule for AI. Every regulator has taken six existing duties and explained how they bite when the drafting assistant is a language model.

Duty US baseline (ABA Formal Opinion 512) Sharpest formulation elsewhere
Competence “need not become GAI experts” but “must have a reasonable understanding of the capabilities and limitations” ÖRAK: AI use permitted only where staff have “KI-Kompetenz”
Confidentiality “must evaluate the risks that the information will be disclosed to or accessed by others outside the firm” Upper Tribunal: pasting client letters into ChatGPT “is to place this information on the internet in the public domain”
Communication and consent Informed consent before client information enters a self-learning tool; boilerplate clauses “not sufficient” CCBE: be transparent “if it can reasonably be assumed that an informed client would object”
Reasonable fees “A fee charged for which little or no work was performed is an unreasonable fee” Virginia: “may not bill for time saved by using generative AI”
Candour Rules 3.1 and 3.3 apply to every citation, whoever drafted it Illinois Appellate Court: “The only acceptable standard is zero false citations”
Supervision “Managerial lawyers must establish clear policies regarding the law firm’s permissible use of GAI” Ayinde: “the profession can expect the court to inquire whether those leadership responsibilities have been fulfilled”

One refinement. Several courts now treat verification as a duty in its own right: the Upper Tribunal’s judicial review form requires a statement of truth that every authority “(a) exists; (b) may be located using the citation provided; and © supports the proposition of law for which it is cited”. Keep that formula.

The baseline: ABA Formal Opinion 512

The ABA issued Formal Opinion 512 on 29 July 2024. It addresses ten Model Rules, from competence to supervision, and the later state opinions cover the same ground; the full walkthrough is in ABA Formal Opinion 512 explained. Competence rests on Comment 8 to Model Rule 1.1, adopted by 40 states plus DC and Puerto Rico, and the opinion contains the sentence that will age best: “it is conceivable that lawyers will eventually have to use them to competently complete certain tasks for clients.” Confidentiality turns on whether the tool is “self-learning”; if so, “a client’s informed consent is required prior to inputting information relating to the representation”. Fees: bill the minutes spent prompting and reviewing, never the time saved, and never the time spent learning the tool.

US states: what each opinion adds

By one tracker’s count more than twenty-five state bars had issued AI opinions or guidance by 2026. The table covers those that add something to the baseline; the full list is in the state bar AI ethics opinions map.

State Instrument and date What it adds to the baseline
California COPRAC Practical Guidance, rewritten 14 May 2026 First rules for agentic AI: “Lawyers must not permit AI systems to autonomously file documents, communicate with the court, or make representations on the lawyer’s behalf”
Florida Ethics Opinion 24-1, 19 Jan 2024 “A lawyer may not delegate to generative AI any act that could constitute the practice of law such as the negotiation of claims”; chatbots must identify themselves
New York City Formal Opinions 2024-5 (7 Aug 2024) and 2025-6 (22 Dec 2025) Open versus closed systems; even with consent, “avoid entering details that can be used to identify the client”; 2025-6 covers AI note-takers on client calls
New Jersey Preliminary Guidelines, 25 Jan 2024 Disclosure only if the client asks or “cannot make an informed decision about the representation without knowing”; no pleading certification
Pennsylvania and Philadelphia Joint Formal Opinion 2024-200, 22 May 2024 “Lawyers must be proficient in using technological tools to the same extent they are in employing traditional methods”; transparency “with clients, colleagues, and the courts”
Kentucky KBA E-457, March 2024 Fees must fall when AI cuts the time; disclose when AI costs are billed or a court requires it
District of Columbia Ethics Opinion 388, April 2024 Quotes NPR’s “an omniscient, eager-to-please intern who sometimes lies to you”; bill “only actual time spent”
Texas Opinion 705, Feb 2025 “Lawyers cannot blindly rely upon or use answers given by generative AI tools”; no “hourly fees for the time that was ‘saved’”
North Carolina 2024 FEO 1, 1 Nov 2024 Rule 5.3 reaches “third-party software companies”; delegating substantive tasks needs advance informed consent; three hours reduced to one is billed as one
Virginia State Bar guidance, Aug 2024 “No per se requirement to inform a client”; “may not bill for time saved”
Illinois Supreme Court AI Policy, eff. 1 Jan 2025 AI use “may be expected, should not be discouraged, and is authorized”; “Disclosure of AI use should not be required in a pleading”

The disclosure split is the one to remember: Pennsylvania wants transparency by default; New Jersey, Kentucky, Virginia and North Carolina say there is no routine duty, with consent triggered when client data leaves the firm or substantive work is delegated. Do lawyers have to disclose AI use? walks the decision tree.

US courts: standing orders and appellate warnings

Courts got there before the bars. Judge Brantley Starr of the Northern District of Texas issued the first standing order on 30 May 2023: every filing must certify that no portion was drafted by generative AI or that any AI language “was checked for accuracy, using print reporters or traditional legal databases, by a human being”. The Fifth Circuit went the other way on 12 June 2024, rejecting a circuit-wide certification rule because the rules already require accuracy: “‘I used AI’ will not be an excuse for an otherwise sanctionable offense.” Individual judges’ orders sit between those poles; court AI standing orders explains how to check yours.

Appellate courts have supplied the standard of care. The Ninth Circuit in Lnu v. Blanche (3 June 2026): “A competent and diligent attorney must also read and reason.” The Illinois Appellate Court in Scott v. Illinois Human Rights Commission (28 July 2026), at $1,500 per false citation: “no matter how much one pays for ‘premier’ or ‘corporate’ versions of AI products, it does not negate an attorney’s obligation to verify all citations of authority.”

Check the court's AI order before you file
For a filing in [court, judge], using only the court's website at [URL] and the attached standing order or local rule, tell me whether this judge or court has a generative-AI certification, disclosure or verification requirement; the exact wording the certificate must contain; whether the tool and affected portions must be identified; and any exemption for legal research platforms. Quote each requirement verbatim with its source.
Then draft the certificate for this filing, in which AI assisted with [describe] and every citation was verified by [name] in [Westlaw / Lexis] on [date].
If you find no order on the sources provided, write "NO ORDER FOUND ON THE SOURCES PROVIDED" and stop.

England and Wales: SRA, Law Society, Bar Council, judiciary

The English position was set by a court. In Ayinde v Haringey and Al-Haroun v Qatar National Bank [2025] EWHC 1383 (Admin), decided 6 June 2025, Dame Victoria Sharp P and Johnson J dealt with five non-existent cases in one matter and 18 non-existent citations out of 45 in the other. Paragraph 6 is now quoted everywhere: “Freely available generative artificial intelligence tools, trained on a large language model such as ChatGPT are not capable of conducting reliable legal research.”

In August 2026 the SRA issued its warning notice on misuse of AI (17 August 2026) after 42 reports of potential misuse in a year. “AI has no separate legal personality; solicitors and regulated individuals who use AI in the course of delivering legal services remain accountable for their work and outputs, regardless of how that work has been prepared.” And: “Reliance on an output of AI would not be a suitable defence.” Client data may only be entered where it “is not used to train AI models except where explicitly authorised”, failing which “legal professional privilege may be permanently waived and unable to be recovered”. The SRA warning notice explained covers the day-to-day consequences.

The Law Society’s “Generative AI – the essentials” (updated June 2026) gives the simplest rule of any regulator: “If you are using a free, online generative AI service where you have no operational relationship with the vendor other than use, do not put any confidential data into the tool.” The judicial guidance of 31 October 2025 tells judges “not to enter private information into public AI tools”; the Bar Council updated its own guidance for barristers on 26 November 2025, with the reminder that “LLMs do not have a conscience or social and emotional intelligence”.

The pendulum now has a second side. The UK Jurisdiction Taskforce’s Legal Statement on Liability for AI Harms (July 2026) says at paragraph 67 that “a professional could also be liable for failing to use AI for a task when a professional exercising reasonable care and skill would have done so.”

The EU: CCBE guides, Ireland, and AI Act Article 4

The CCBE guide on generative AI (2 October 2025) tells lawyers to “refrain from entering any personal, confidential, or other data related to the client into the user interface of the Gen AI… unless there are appropriate safeguards in place”: contractual confidentiality or zero retention, a data processing agreement, or a local deployment. It adds the point most lawyers miss: you may be in breach “already at the point of inputting the data into a system, for example as prompts”. The CCBE’s technical guide (27 March 2026) supplies the vendor questions; the Law Society of Ireland adds that “free and paid consumer versions of GenAI systems are not suitable for securely handling personal data or client confidential data”.

Article 4 after the Digital Omnibus

Law firms are deployers under Article 3(4) of the AI Act, and the Article 4 AI-literacy duty has applied since 2 February 2025. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) rewrote the obligation from “ensure” a sufficient level of literacy to “take measures to support the development of” it, and deferred the Annex III high-risk regime to 2 December 2027. National market surveillance authorities gained enforcement powers on 2 August 2026.

The European Commission’s AI-literacy Q&A says what the duty demands. Asked whether a company whose staff use ChatGPT for writing must comply: “Yes, they should be informed about the specific risks, for example hallucination.” It warns that “simply relying on the AI systems’ instructions for use or asking the staff to read them might be ineffective” and notes that Article 99 carries no fine for Article 4; penalties follow national law and are “more likely if there is proof of an incident due to lack of appropriate training”. The EU AI Act for law firms has the timeline.

Draft the Article 4 AI-literacy record for your firm
Draft an AI-literacy record for a law firm of [N] staff in [Germany / Austria / Ireland] documenting compliance with Article 4 of the EU AI Act as amended by Regulation (EU) 2026/1744. Structure: (1) inventory of AI systems in use, including free tools such as ChatGPT, DeepL and Copilot; (2) our role as deployer; (3) risk level of each system, noting that ordinary law-firm tools are not Annex III high-risk; (4) measures by staff group covering how the models work, hallucination, professional-secrecy rules and verification; (5) dates, formats (hands-on, not lecture) and attendance records; (6) refresh cycle.
Do not cite the AI Act or national law beyond what I have stated; mark any legal statement you add [VERIFY].

Germany, Austria and Switzerland: where confidentiality is criminal law

I practise in Vienna, so this is the section I read most carefully. The German-speaking jurisdictions differ from the common-law world in one structural respect: professional secrecy is backed by criminal statutes, so “may I paste this into ChatGPT?” is answered by § 203 StGB, § 9 RAO and Art. 321 StGB rather than by an ethics opinion. KI in der Kanzlei: BRAK, DAV und ÖRAK is the German-language treatment.

Germany Austria Switzerland
Basis § 43a Abs. 2 BRAO; § 203 StGB § 9 Abs 2 RAO; disciplinary law Art. 13 BGFA; Art. 321 StGB; DSG
Public tools BRAK: only “abstract” prompts allowing no inference about a mandate ÖRAK: entering mandate data is “standesrechtlich unzulässig” SAV: confidential information “nicht in KI-Systeme eingegeben werden” outside three permitted set-ups
Vendor requirement § 43e BRAO: contract in text form with criminal-law instruction; prefer German or European servers § 40 Abs 3 RL-BA 2015 agreement, Art 28 GDPR DPA, ten-point signed checklist On-premise, or a provider under the SAV cloud guidelines, or informed client consent and waiver
Duty to inform clients None as of December 2024; a contractual clause recommended “im Zweifel” No general duty in the guidance that I have seen; what it does require is documented staff “KI-Kompetenz” as a condition of use Agree a liability limitation where AI is used by arrangement

The BRAK Hinweise (Stand December 2024) are the German reference. The rule for language models: “Wenn möglich, sollten bei Sprachmodellen nur ‘abstrakte’ Anfragen (sog. ‘prompts’) gestellt werden, die auch im Kontext keinerlei Rückschlüsse auf ein bestimmtes Mandat zulassen.” Stripping names is not enough where “sich Mandatsinformationen aus dem Kontext ergeben können”, and the § 203 StGB test is whether the provider could read your prompts, not whether it does. The DAV’s Stellungnahme 32/2025 (July 2025) is warmer: “Der Anwaltschaft steht es frei, die ihr durch KI eröffneten Möglichkeiten zu nutzen”, and anonymisation is “nicht zwingend” for a contracted provider, though mandatory for public tools. The courts have been consistent regardless: the LG Frankfurt (25 September 2025) called it a basic professional duty not to adopt a chatbot’s suggested sources unchecked, and the KG Berlin (20 November 2025) requires lawyers to check whether citations come from a “fantasierenden” KI.

The ÖRAK guidance (September 2025) is the strictest text on this page: “Die anwaltliche Sorgfaltspflicht erfordert daher eine ausnahmslose Überprüfung und Verifizierung aller KI-generierten Ergebnisse”, and “Die Eingabe von mandatsbezogenen oder sonstigen vertraulichen Informationen in öffentliche oder ungesicherte KI-Systeme stellt einen Bruch der Verschwiegenheit dar und ist standesrechtlich unzulässig.” A provider may only receive mandate data if it meets § 40 Abs 3 RL-BA; otherwise “nur abstrakte und anonyme Fragen (ohne Mandantenbezug)”. The OGH showed the consequence on 7 October 2025 when it rejected a nullity appeal drafted “offenbar ohne fachliche Kontrolle… durch sogenannte ‘künstliche Intelligenz’” without substantive reply.

Canada and Australia in brief

Canada’s Federal Court requires a Declaration “in the first paragraph stating that AI was used in preparing the document, either in its entirety or only for specifically identified paragraphs” (notice updated 7 May 2024). The Law Society of Ontario’s white paper (April 2024) says to “only charge for the time actually spent by the licensee on the file”.

Australia has the most prescriptive court rule anywhere. NSW’s Practice Note SC Gen 23 (commenced 3 February 2025) provides that “Gen AI must not be used in generating the content of affidavits, witness statements, character references or other material that is intended to reflect the deponent or witness’ evidence and/or opinion”; affidavits must say it was not used; submissions must verify that citations “(a) exist, (b) are accurate, and © are relevant”; and “such verification must not be solely carried out by using a Gen AI tool or program.” Victoria’s SC Gen 25 (14 May 2026) adds that “One AI tool cannot be used to confirm the content generated by another AI tool.”

Malpractice insurance: what underwriters now ask

The insurance picture is calmer than the headlines. Chris Newbold of ALPS told the Daily Record on 25 August 2026: “We’re not seeing a lot of what I would call direct AI claims at this point”, though “adoption might be moving faster than governance”. Lee Norcross of the broker L Squared said one surplus-lines insurer’s AI exclusion is “the exception, not the rule”, and added: “AI does not have a law license to lose.” What has changed is the questionnaire, and the artefacts that answer it are a written policy, a vendor due-diligence file, informed-consent language, training records, a pre-filing verification log, a usage log and an incident procedure; legal malpractice insurance and AI mistakes goes through each.

How to use this map in a firm policy

A policy that quotes Opinion 512 back at the regulator is not a control; Butler Snow proved that. A policy that works maps each duty to a mechanism and names the strictest rule the firm actually faces.

  1. Identify the binding layer per matter type. A Frankfurt team answers to § 203 StGB and BRAK; a New York team to Opinion 512, NYC 2024-5 and the judge’s standing order; a London team to the SRA Code and Hamid. Cross-border teams take the strictest.
  2. Classify data into three tiers. Public and abstract material may go anywhere; client material only into a no-training commercial tier after anonymisation; privileged strategy, witness evidence and anything to be filed only into an enterprise zero-retention or legal platform, or a local model. The law firm AI policy template has the tier table.
  3. Write the vendor test into the policy. The District of Colorado’s protective-order language in Morgan v. V2X (30 March 2026) is ready-made: no tool unless the provider is contractually prohibited from “(1) storing or using inputs to train or improve its model; and (2) disclosing inputs to third parties except where essential”.
  4. Make verification a logged step. Existence, quotation, holding, status, jurisdiction, and who checked what and when.
  5. Replace boilerplate consent with the real thing. Opinion 512 wants the client told why, what risk and what benefit; the CCBE asks whether an informed client would object.
  6. Keep a training record. Rules 5.1 and 5.3, SRA Code 3.5 and 3.6, Article 4 and ÖRAK’s competence condition converge on the same evidence: who was trained, on what, when, hands-on. The Commission’s view that reading the manual “might be ineffective” is why AI Lab for Lawyers runs as four live two-hour sessions on real, anonymised documents; its confidentiality-tier exercise is step 2 done by hand.
  7. Review quarterly. NYC Bar 2024-5 says the duty to understand a tool’s terms is continuing because they “can change frequently”. Anthropic changed its consumer training default in August 2025; a policy dated 2024 describes different products.
Audit your AI policy against the rules that bind you
Here is our current AI policy: <policy>...</policy>. We are a [size] firm with lawyers admitted in [jurisdictions] appearing before [courts]. Using only the rules pasted below <rules>[e.g. ABA Formal Opinion 512, NYC Bar 2024-5, the judge's standing order, the SRA warning notice, the BRAK Hinweise]</rules>, produce a gap table: Duty (competence / confidentiality / consent / fees / candour / supervision) | Rule and quoted requirement | Where our policy addresses it (quote) | Gap | Proposed wording | Evidence we would keep.
Treat every "lawyers should be careful" sentence as a gap unless it names a tool tier, a step or a record. Where a duty has no supplied rule, write "NO RULE SUPPLIED" rather than inventing one.

Where to go next: the whole ethics and regulation cluster is indexed from its hub, the tool-by-tool confidentiality tiers live in the confidentiality cluster, and the prompts above, with the consent and verification prompts they pair with, are in the prompt library. If you would rather practise the classification and verification steps on your own documents than read about them, that is what AI Lab for Lawyers is for.

Frequently asked questions

What are the ethics rules for lawyers using AI?

No jurisdiction has written new rules for AI. Instead, bars and courts apply the existing duties: competence (understand the tool's limits), confidentiality (do not put client information into a tool that may disclose it), communication and consent, reasonable fees (bill actual time, not time saved), candour to the court (verify every citation) and supervision of staff and vendors. ABA Formal Opinion 512, the SRA warning notice, the CCBE guide and the BRAK and ÖRAK guidance all follow this pattern.

Is there a duty of technology competence?

In the US, Comment 8 to Model Rule 1.1 requires lawyers to keep abreast of 'the benefits and risks associated with relevant technology'; 40 states plus DC and Puerto Rico have adopted it. ABA Opinion 512 says lawyers need not become AI experts but must have 'a reasonable understanding of the capabilities and limitations' of their tools. The SRA warning notice cites its Code's competence and supervision paragraphs (3.2, 3.5, 3.6); ÖRAK makes AI use conditional on documented staff 'KI-Kompetenz'.

Do lawyers need client consent to use AI?

It depends on the tool and the jurisdiction. ABA Opinion 512 requires informed consent before client information goes into a 'self-learning' tool, and says boilerplate engagement-letter language is not enough. Florida 24-1 recommends consent where confidential information is disclosed to a third party. New Jersey, Kentucky, Virginia, North Carolina and BRAK impose no routine duty to tell clients about ordinary AI use; Pennsylvania leans towards transparency; the CCBE asks whether an informed client would object.

What does the EU AI Act require of law firms?

Law firms are deployers under Article 3(4). Article 4 has required them since 2 February 2025 to take measures supporting the AI literacy of staff who use AI systems, including free tools such as ChatGPT or DeepL. The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) replaced 'ensure' with 'take measures to support the development of' literacy. Ordinary law-firm tools are not Annex III high-risk systems. No certificate or AI officer is required.

Which countries regulate lawyers' AI use most strictly?

Germany, Austria and Switzerland, because confidentiality breaches are criminal offences (§ 203 StGB, § 9 RAO with disciplinary law, Art. 321 StGB) and the bars require provider contracts with statutory minimum content before any client data is entered. Australia's NSW Supreme Court has the most prescriptive court rule: generative AI may not be used to draft affidavits or witness statements, and every affidavit must say so. England and Wales has the most active enforcement, with SRA referrals and wasted-costs orders.

Can a lawyer be disciplined for using ChatGPT?

Not for using it, but for what follows. Damien Charlotin's database listed 2,039 court decisions involving hallucinated material on 12 September 2026, 811 involving lawyers. Sanctions include a suspension of one year and one day in Colorado (90 days served), $15,000 per lawyer in the Sixth Circuit, disqualification and bar referrals in Johnson v. Dunn, and SRA, BSB and ICO referrals in England. As the Fifth Circuit put it, 'I used AI' will not be an excuse.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.