Skip to main content
Back to Insights
AI AdvisorySep 12, 20268 min readBy Justin Kane

The Law Firm AI Policy ABA Opinion 512 Actually Requires

ABA Formal Opinion 512 sets out real duties for lawyers using generative AI. Here is what it says in plain language, and why a downloaded template does not satisfy it.

The Law Firm AI Policy ABA Opinion 512 Actually Requires illustration

In July 2024, the ABA's Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first formal guidance on generative AI. Most managing partners responded sensibly: they got a policy. The problem is what kind. A template downloaded and circulated as a memo does not do what the opinion actually asks of a firm, and the gap between those two things is where the risk lives.

Here is what Opinion 512 says in plain language, and what a policy that takes it seriously looks like.

What Opinion 512 actually says

The opinion does not create new rules. It applies the existing Model Rules to generative AI, and it lands on six duties that matter for a firm policy.

Competence. Lawyers do not need to become AI engineers, but they need a reasonable understanding of the capabilities and limits of the specific tools they use, kept current as the tools change. Practically, you cannot delegate judgment to a tool you do not understand, and not knowing that these tools fabricate is no longer a defense.

Confidentiality. This is the heart of it. Before information relating to a representation goes into a generative AI tool, a lawyer has to evaluate the risk that it will be disclosed to or accessed by others, including the vendor and, with self-learning tools, other users downstream. In some circumstances that means informed client consent first, and general consent language buried in an engagement letter is unlikely to qualify. Informed consent means the client actually understands what tool, what data, and what risk.

Communication. Whether you must tell a client you are using AI depends on the circumstances: the client may have asked, the use may be significant to the representation, or consent may be required under the confidentiality analysis. The policy question for the firm is who decides, and when, rather than leaving it to each lawyer's improvisation.

Supervision. Managerial lawyers must establish clear policies on the firm's use of generative AI, and supervising lawyers are responsible for AI-assisted work by associates and staff. This is the paragraph that quietly makes an AI policy mandatory in substance. A firm with no policy has managers not doing what the opinion says managers must do.

Candor and verification. AI output gets verified before it is relied on or filed. Courts have already sanctioned lawyers for filing fabricated citations, and the duty of candor to a tribunal does not flex because a tool wrote the brief. A lawyer is accountable for every representation made to a court, whatever drafted it.

Fees. If AI lets you do six hours of work in one, you bill the one when billing hourly. Passing tool costs through to clients requires disclosure and a reasonable basis, and time spent gaining general competence with AI is firm overhead, not billable time.

The gap between a template and a policy

A downloaded template can recite all six duties and still fail the firm, because the duties are only half the policy. The other half is your firm: which tools your lawyers actually use, which practice groups touch which kinds of confidential material, how work is reviewed before it goes out, and what your engagement letters already say. A template has no answers to those questions, so it defaults to language vague enough to be universally true and operationally useless. When something goes wrong, a vague policy protects no one, and it may read as evidence that the firm knew the duties and did not build the controls.

The pattern we see: the memo went out eighteen months ago, nobody was trained, the approved-tools section names tools nobody uses, and associates are quietly on personal accounts for the tools they actually want. That firm is worse off than it thinks, because it has documented a standard it is not meeting. And the exposure is not hypothetical. Clients now ask about AI in outside counsel guidelines, insurers ask about it at renewal, and opposing counsel will ask about it the first time an AI-assisted error surfaces in a matter.

The sections a real policy needs

Approved tools, by name and plan. The specific tools the firm has vetted, on the specific plans, because the consumer and enterprise versions of the same product carry different data terms. Everything else is out of bounds by default, with a fast path for requesting additions so the list does not calcify.

Data classification for privileged and confidential material. The line is the obligation on the material, not the document type. Privileged material, material under a protective order, and confidential client information each carry different handling requirements, and the policy has to say which class can touch which tool. For the most sensitive material, the honest answer is often no AI tool at all until the firm has approved a specific tool, on enterprise terms, for exactly that use, and the policy should say so plainly. We wrote more about where that line sits in AI for law firms: what's safe and what's not.

Human review requirements. Who verifies AI-assisted output, at what depth, before it reaches a client or a court. A named lawyer is accountable for every filing and every deliverable. The tool is never the author of record.

Client disclosure decisions. When the firm discloses AI use, when it seeks consent, and what the engagement letter says. Decided once, at the firm level, with an escalation path for edge cases, so the confidentiality analysis Opinion 512 requires actually happens instead of being skipped under deadline pressure.

Billing treatment. How AI-assisted time is recorded and billed, and how tool costs are handled. This is the section most templates skip entirely, and it is the one your clients will eventually ask about.

Training. What every lawyer and staff member must complete before using any approved tool, and how often it refreshes.

How to make it stick

A policy circulated as a memo has a half-life of about a week. What makes it real is certification. Every lawyer and staff member completes short training built on the firm's actual tools and actual matters, then signs an acknowledgment, renewed annually and whenever the policy changes. Certification changes the posture of the whole document. It gives the managing partner an answer to the supervision duty, it gives the firm a record when a client or an insurer asks how AI is governed, and it means the first associate anyone interviews will describe the same rules the policy states.

It also has to be owned. Someone, a partner or an outside advisor acting as one, owns the approved list, reviews new tools, and updates the policy as the tools change, because they will. That ownership is the core of our AI governance work, and for firms that want the whole arc from assessment through rollout to certification, it is how we work with law firms.

Key takeaways

  • Opinion 512 applies existing duties to generative AI: competence, confidentiality, communication, supervision, candor, and fees.
  • The supervision duty effectively makes a real firm AI policy mandatory in substance.
  • Boilerplate consent language is not informed consent to put client information into a specific tool.
  • A real policy names tools and plans, classifies material by obligation, and settles review, disclosure, and billing at the firm level.
  • Certification, not a memo, is what makes the policy defensible.

Talk it through

Ready to replace the template with a policy that fits your firm? Start with a 45-minute call.

Frequently asked questions

Related reading

More from the DoubleChecked library.

AI Readiness Checklist

The questions every regulated firm should answer before adopting AI

Free Guide
Free Executive Resource

The Regulated Firm's AI Readiness Checklist

Six questions that decide whether your firm can adopt AI without putting client data, a renewal, or an examination at risk. Walk them before your next audit, not after.

  • Where client data is leaving your environment through personal AI accounts
  • Whether your AI controls would survive a SOC 2 audit or an examination
  • Where a human, not the model, needs to ratify the output

We respect your inbox. Unsubscribe at any time.