SecurityTechInsider AI security & governance
EN/ NL
Governance

Demonstrable control over AI use by lawyers: from data practices to matter accountability

Recent bar opinions such as ABA 512 and NYC Bar 2026-2 call for demonstrable governance per matter. Here is how to translate those requirements into a workable

15 September 2026 4 min
Illustration for this article: Demonstrable control over AI use by lawyers. The cut edges of a thick stack of blank paper, fanned slightly, raking light along the fibres.
Lawyers must now document AI tool use per matter and verify all output before client delivery. Image: SecurityTechInsider — original editorial illustration

You must now document which AI tool processes which client data in each matter, demonstrate that you assessed the tool's data practices beforehand, treat all AI output as a draft requiring your own verification, and record who approved its use. This is no longer optional: professional ethics rules now require demonstrable control.

An analysis of 15 September 2026 of demonstrable governance per matter in legal practice argues that AI use by lawyers falls under existing professional duties and that firms must be able to show how they comply with them. The American Bar Association issued Formal Opinion 512 in 2024, the first national ethics opinion on generative AI in the legal profession, and in July and August 2026 concrete guidance followed from the Alabama State Bar and the New York City Bar Association. In our assessment, this logic applies equally to notaries and other professionals bound by confidentiality and due care: the shift from cautious prompts to demonstrable control per matter is now a regulatory expectation, not an option.

What does professional ethics now require of AI use?

ABA Formal Opinion 512 places generative AI directly under existing rules of conduct. A lawyer need not be an AI expert, but must have reasonable understanding of the capabilities and limitations of each specific tool in use. The opinion links AI to three core duties: competence in the technology, protection of client confidentiality, and verification of output before use. The Alabama State Bar's July 2026 update reinforced this by clarifying that lawyers may not bill hours saved by AI, but must bill the time spent reviewing, correcting and applying AI-generated work with professional judgement. That places accountability exactly where the rules require it: with human verification.

Which failure modes and duties must you manage?

  • Undisclosed data processing — sending client information to a tool without assessing where it goes or how long it is retained.
  • Unverified output — relying on AI-generated text, citations or legal analysis without checking accuracy and completeness.
  • Lack of client transparency — failing to inform clients that AI was used in their matter or how it was used.
  • No audit trail — using AI without recording which tool, which data, which output and who approved it.
  • Incompetence in the tool — deploying AI without understanding its specific limitations or failure modes.
  • Confidentiality breach — choosing a service provider without assessing its security, data retention or processing location.

What concrete controls must you be able to demonstrate?

  1. Assess each tool before use — document the tool's data retention policy, processing location, security measures and known limitations specific to your use case.
  2. Record the matter and the tool — maintain a log showing which AI tool processed which client data, in which matter, and the lawful basis for that processing.
  3. Verify and correct all output — review AI-generated work for accuracy, completeness and compliance before it leaves your control, and document that review.
  4. Obtain and record approval — ensure a responsible lawyer approves AI use in the matter and that approval is recorded with the date and the approver's name.
  5. Inform the client — tell the client that AI was used in their matter, which tool was used and what role it played in the work product.
  6. Supervise the workflow — establish firm policy making the verification step visible and accountable, not hidden behind a productivity claim.

How does the New York City Bar guidance change practice for sensitive work?

Formal Opinion 2026-2 addresses AI use for recording, transcribing and summarising conversations with non-clients. The opinion emphasises that lawyers must protect confidentiality and privilege, must safeguard consent and transparency around AI recording, and that the choice of service depends partly on the provider's security and data processing. This shows that even seemingly neutral applications touch on confidentiality. The same applies to notarial practice: AI drafts for deeds, summaries or due diligence can be useful, provided the tool has been assessed beforehand and human control remains central.

What tooling can support this layer, and what remains your own judgement?

A verification console positioned above your AI tools can make verification steps, corrections and sources visible for inspection, supporting the audit trail you now need. Privacy-preserving techniques can replace sensitive values with synthetic equivalents before processing, failing safely if the privacy check does not pass. These tools can make safe usage patterns demonstrable and auditable. The professional final judgement—whether to use AI in a matter, which tool to use, and whether the output is fit for purpose—always remains with you. No tool can carry that responsibility.

Sources: This article draws on reporting and guidance from Epiq, Reuters, New York City Bar Association, Legal AI Compliance and Arjun Jaggi.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.