Home/ Guides/ Law Firm AI Governance

Law firm AI governance: bar rules and the malpractice carrier questionnaire.

Law firm AI governance answers to two audiences. The bar rules set the duty; the malpractice carrier asks at renewal whether you meet it. Both want the same four pieces of evidence, all four architectural: where client data comes to rest, whether the ethical wall holds inside the AI layer, what the audit log records, and who signed off.

Written for managing partners, operating partners, and firm administrators who need the renewal answer and the client answer to be documented rather than asserted.

For20 to 150 attorneys
TriggerLPL renewal or bar review
Fee band$45K to $180K fixed
Last updatedAugust 2026

The short answer.

Two things happened inside two years and most firms treat them as one problem. The bar told you what your duty is. Your insurer started asking whether you discharge it. The rules came first and they are not new law: ABA Formal Opinion 512, issued July 29, 2024, works through competence, communication, fees, confidentiality, candor, and supervision without inventing an obligation that did not already exist. The insurance question is newer and has sharper teeth, because an answer on a renewal application is a representation, and a wrong representation is a coverage problem rather than a discipline problem.

Both audiences want the same thing and it is not a policy document. A policy states intent. What a bar investigator asks after a bad filing, an underwriter asks at renewal, and a corporate client asks under its outside counsel guidelines is whether the firm can reconstruct what happened: which tool ran, on which matter, what data left which environment, and who read the output.

So AI governance at a law firm is an architecture problem wearing a compliance costume. The policy is a weekend of writing. The layer underneath takes engineering.

What the rules require

The duty is old. Only the tool is new.

01Competence and verification.Formal Opinion 512 does not ask lawyers to become AI experts. It asks for a reasonable understanding of a tool's capabilities and limitations, and sets no universal verification standard: the review required depends on the tool and the task. It does warn that uncritical reliance on generated content risks malpractice.

The Stanford RegLab and HAI study published in May 2024 tested purpose-built legal research tools against more than 200 preregistered queries: Lexis+ AI and Ask Practical Law AI were wrong more than 17 percent of the time, Westlaw AI-Assisted Research more than 34 percent.
Rule 1.1Verification is task-dependent
02Confidentiality and consent.The opinion cautions that self-learning tools risk disclosing one client's information improperly, and concludes that informed consent is required before inputting representation information into such a tool. Boilerplate does not carry it; the client needs the lawyer's judgment on why the tool is used and the specific risk.

The Florida Bar reached the same conclusion in Opinion 24-1, approved January 19, 2024, treating the tool as a nonlawyer assistant requiring supervision.
Rules 1.6 and 1.4Consent is per-tool, not per-firm
03Supervision, at the management level.This clause puts the managing partner in frame. Under Rules 5.1 and 5.3 as read by Formal Opinion 512, managerial lawyers must establish clear policies on the firm's permissible use of these tools, and supervisory lawyers must make reasonable efforts to ensure lawyers and nonlawyers comply, with training on usage, confidentiality, and secure data handling.

A policy nobody was trained on and nobody monitors is evidence of a defect rather than a defense against one.
Rules 5.1 and 5.3Policy, training, oversight
04Fees and candor.Lawyers billing hourly must bill only actual time, and Formal Opinion 512 states that a fee charged for which little or no work was performed is unreasonable. Florida's Opinion 24-1 agrees.

Candor is the failure everyone has read about. In Johnson v. Dunn, decided in the Northern District of Alabama in July 2025, three attorneys at a large firm were sanctioned over filings containing citations fabricated with ChatGPT. The firm had an AI policy. The policy did not catch it, because a policy is not a checkpoint.
Rules 1.5 and 3.3A policy is not a control

Underneath the ABA opinion sits a layer of state guidance, and the volume is the point. One tracker indexes 51 state-level entries, 15 of them formal ethics opinions. A multi-state firm answers to a moving set of overlapping instructions, which argues for a record rather than a policy tuned to one.

The carrier side, stated honestly

What your malpractice carrier is asking, and what is only rumored.

One question is documented. The rest is happening in the room.

There is a lot of confident writing on this topic and not much survives a check. The most widely circulated claim, that more than 60 percent of legal malpractice carriers now ask about AI on their applications, traces to a vendor FAQ with no source attached, so we are not repeating it. Same for the claim that CNA added a supplemental AI questionnaire at renewal: primary-source review shows an ethics bulletin, which is a different thing.

What is documented is narrower and more useful. AmTrust's lawyers professional liability application, form LPLPRO-APP-01 0523, asks whether the firm allows the use of artificial intelligence software to draft documents and requests a description if the box is checked. In primary-source review of US LPL forms, that is the one verbatim AI question located.

The nearest documented read is from an adjacent line of business: Aon's accountants risk control lead, speaking in April 2026 about CPA firm underwriting, described underwriters asking whether firms use AI, police it, and have protocols in place, and expected more detailed questions within a year or two.

The claims data turned over this year, which is what moves underwriting.

Underwriters ask about a risk once it starts producing claims, and that threshold was crossed in 2026. EPIC Insurance Brokers released its 16th Annual Lawyers' Professional Liability Claims Survey on May 21, 2026, drawing on senior claims executives at 13 LPL insurers that collectively cover more than 80 percent of Am Law 200 firms. Seven of the 13 reported an increase in AI-related claims over the past year, alongside the first rise in overall claim frequency in five years. EPIC's Eileen Garczynski put accountability in one line: the duty of competence cannot be outsourced to an algorithm.

Exclusions have not landed on LPL paper yet, which is the window.

As of a primary-source review dated May 2026, no major US lawyers professional liability writer, including CNA, Travelers, Chubb, Hartford, Markel, ALPS, and the state mutuals, had publicly filed an explicit AI exclusion on LPL paper. Filed AI exclusions exist on other lines: W.R. Berkley's form PC 51380 00 (06-24) carries an absolute artificial intelligence exclusion on management liability, not legal malpractice.

Read that as a window rather than an all-clear. The cyber market is the obvious analogue, and whether LPL follows it from silent coverage to questionnaires to exclusions is not yet on paper.

Why the answer matters more than the question: it is a representation.

The reason to care about a checkbox is not the checkbox. Answers on an insurance application are representations, and in many states a material misrepresentation can rescind a policy retroactively without any intent to deceive. Applying Kentucky law, the Sixth Circuit in 2012 upheld rescission of an LPL policy in Continental Casualty Co. v. Law Offices of Melbourne Mills, Jr., PLLC, where the firm answered no on potential claims while a bar investigation was pending; the statute required the misrepresentation to be material and not intentional.

A firm that certifies it does not permit AI drafting, then discovers an associate ran a brief through a consumer chatbot, has a representation problem sitting underneath its next claim. The defense is not a stricter policy. It is knowing the answer, from a system, on the day the form is signed.

The build-side answer

What a governance-clean AI system looks like architecturally.

The four-layer AI control stack for a law firm: layer one is a single controlled egress point the firm operates, holding credentials, applying retention terms and pinning provider and model version, answering Rule 1.6; layer two is query-time authorization against live matter entitlements in iManage, NetDocuments, Clio or Litify with exclusions logged, inheriting the ethical wall under Rules 1.0(k) and 1.10; layer three is a matter-level audit log of ten fields written at the point of the call and exportable, evidencing supervision under Rules 5.1 and 5.3; layer four is a named attorney clearing the work product with every authority checked against the primary source before signature, under Rules 1.5 and 3.3
Each layer emits evidence. The renewal packet is generated, not drafted.

Where the data comes to rest.

The confidentiality question has a physical answer and most firms cannot give it. Four things need to be contractually verifiable rather than believed after a demo: where matter content sits while a model processes it, whether that is inside your tenancy or a vendor's, whether any provider retains inputs or trains on them, and which agreement makes each enforceable by name and clause.

The consequence is a single controlled egress point. Every AI call leaves through one service the firm operates, which holds the credentials, applies the retention terms, strips what should never leave, and refuses anything not on the approved list. Pin the provider and model version there, so a vendor's quiet substitution shows up as a configuration commit.

The ethical wall has to be inherited, not rebuilt.

Model Rule 1.0(k) defines screening as the isolation of a lawyer from a matter through timely procedures adequate to protect the information, and Rule 1.10 lets a proper screen avoid imputation. Your document management system enforces that through access control lists on matter workspaces; a retrieval layer on the same repository can flatten it in one indexing run.

Index-time filtering, where documents are excluded when the index is built, breaks the moment a wall goes up after ingestion, which is exactly when walls go up. The correct pattern is query-time authorization: every retrieval evaluates the asking user's live entitlements in iManage, NetDocuments, Clio, or Litify on Salesforce and returns nothing they could not open by hand. Log the exclusions too, because an answer that silently dropped three screened matters looks identical to one where nothing was screened.

The audit log, at matter level, owned by the firm.

This is the artifact everything else resolves to. Vendor consoles record usage per seat because seats are what vendors bill on; bar rules, outside counsel guidelines, and carriers all care about matters.

The record needs enough fields for a stranger to reconstruct one event a year later without interviewing anyone: matter number, user, tool and model version, task category, the documents or fields sent, the destination environment, whether that client's guidelines permitted it, the reviewing lawyer, the outcome, and timestamps. Written once at the point of the call, those ten fields turn an audit request into an afternoon rather than a two-week investigation that produces an estimate. Store it where your matter records live and make it exportable; a professional liability tail outlives any tool you are running today.

The human review gate, named as a checkpoint rather than a habit.

Every firm will tell you a lawyer reviews the output. Johnson v. Dunn is what that assurance is worth without a mechanism, and the firm there had a policy. Review that lives in a document is a habit; review that lives in a workflow is a control.

Make it structural. AI-assisted work product carries a status until a licensed attorney clears it, the clearing attorney is captured by identity, not initials in a comment, and the attestation is one sentence they can stand behind. Handle citations as their own gate: every authority checked against the primary source by a person, logged, before signature. The gate is also where the fee record comes from, so Rule 1.5 becomes a query.

The renewal packet, generated rather than written.

With that layer running, the renewal answer stops being a drafting exercise. The packet is the dated policy and its version history, the approved and prohibited tool lists, the vendor diligence file with retention terms named by clause, training completion figures, the screening confirmation, the matter-level activity report, the incident procedure, and a named accountable partner.

Attach what exists and mark what does not as a commitment with a date. A dated commitment reads as credible; a present-tense description of a capability you lack ends a relationship.

What we would commission, and what we have actually shipped.

Everything above except the logging layer is work a firm does itself in about a week: the policy, the tool lists, the training, the accountable partner. The record is the part that is not writing, and that is a build against iManage, NetDocuments, Clio, or Litify on Salesforce.

Stated plainly, because this category is full of claims nobody can check. Our nameable law reference is Jim Glaser Law, where we built five channel-specific voice agents covering PPC, Organic, TV, Meta, and LSA; those agents have handled 3,787 calls across 5,514 minutes, and Jimmy takes reference calls. Across clients our systems have handled more than 6,000 live calls, and our own AI receptionist answers at (617) 675-9067. Closest to this record-keeping problem is an engagement we can describe but not name: a 47-attorney litigation firm whose matter, invoice, and IOLTA trust accounting platform we commissioned, carrying 13,296 matters, 4,396 clients, and 5,684 invoices, with a trust ledger that reconciles byte-identical. A state bar audits that class of record, which is the standard an AI audit log has to meet.

What we have not shipped is a completed AI governance logging layer at a law firm, and we are not going to describe one that does not exist. What we would commission is the architecture above, at the bands published on the pricing page: $45,000 to $180,000 against a written scope, a working prototype on your real data in 7 to 10 days before any fee is owed, four to seven weeks to production, inside your own Azure, AWS, or Google cloud tenant under NDA, with code, prompts, models, runbook, and integration documentation owned by the firm at handoff. A compliance record you rent is one whose export format can change.

Ready when you are

Book the 45-minute diagnosis.

Bring your renewal application and your current AI policy, if one exists. We read them against what your systems can evidence today, tell you which answers are already true, and name what would have to be built before the next renewal. If nothing needs building, we say so on the call.

Frequently Asked Questions

What does ABA Formal Opinion 512 actually require a law firm to do?

Formal Opinion 512, issued July 29, 2024, applies existing Model Rules to generative AI rather than creating new ones: competence under 1.1, communication under 1.4, fees under 1.5, confidentiality under 1.6, candor under 3.3, and supervision under 5.1 and 5.3. Managerial lawyers must establish clear policies on the firm's permissible use of these tools, and supervisory lawyers must make reasonable efforts to ensure lawyers and nonlawyers comply.

Does my malpractice carrier ask about AI at renewal?

Increasingly in conversation, so far rarely in writing on the form. The only verbatim AI question located on a US lawyers professional liability application in primary-source review is AmTrust's, on form LPLPRO-APP-01 0523, asking whether the firm allows the use of artificial intelligence software to draft documents. The nearest documented read is from an adjacent line of business: Aon's accountants risk control lead, speaking in April 2026 about CPA firm underwriting, described underwriters asking whether firms use AI, police it, and have protocols in place, and expected more detailed questions within a year or two.

Can an inaccurate AI answer on an application void our coverage?

An answer on an insurance application is a representation, and in many states a material misrepresentation can rescind a policy retroactively without any intent to deceive. Applying Kentucky law, the Sixth Circuit upheld rescission of a lawyers professional liability policy in 2012 in Continental Casualty Co. v. Law Offices of Melbourne Mills, Jr., PLLC, holding the misrepresentation had to be material and not intentional. Answer from a record rather than an impression.

Is a written AI policy enough for the bar and the carrier?

A policy answers the governance question and no other; it states intent. What a bar investigator, an underwriter, or a client asks at review is what happened on a specific matter: which tool ran, what data it processed, who reviewed the output, and when. That record lives in systems or it does not exist.

Do we need client consent before putting matter content into an AI tool?

For self-learning tools, Formal Opinion 512 says a client's informed consent is required before inputting information relating to the representation, because such tools risk disclosing one client's information improperly. Boilerplate does not carry it; the client needs the lawyer's judgment on why the tool is used and the specific risk. The Florida Bar reached the same place in Opinion 24-1, approved January 19, 2024.

Can we bill for time an AI tool saved?

No. Formal Opinion 512 is direct: lawyers billing hourly must bill only their actual time, and a fee charged for which little or no work was performed is unreasonable under Rule 1.5. Florida's Opinion 24-1 puts it as efficiency gains not becoming falsely inflated time claims. A firm that cannot tell which tasks a tool touched cannot show its entries are clean.

Where to look next.

If a client is asking the same questions your carrier is, answering client AI questions in outside counsel RFPs is the response template. For what a program contains at this size, read AI governance without the enterprise theater, and run the security questions to ask before an AI build against any tool at intake.

The systems these controls attach to: iManage, NetDocuments, Clio, and Litify on Salesforce. Conflicts and intake are covered in law firm intake and conflicts automation, and data readiness covers what has to be true before any of it indexes cleanly.

For the firm-level view, the law firm practice page lists the workflows most often commissioned, how to choose an AI consultant for a law firm is the vetting checklist, and Harvey against a commissioned build is worth reading before a demo. Fee bands are on AI consulting cost for law firms, the engagement shape is on the commission process.