Skip to main content
Secured AI - Protecting You in the AI Age
Legal AI Governance

ABA Formal Opinion 512: What Law Firms Actually Have to Do About AI

It restates duties your lawyers already owe and applies them to prompts. The gap is not the guidance. It is that most firms have nothing that records what actually gets typed into a browser.

August 26, 202611 min read

Listen to this article (3 min)

The Law Firm AI Compliance Stack: Opinion 512 timeline, the six duties in scope, the operational gap, the five-control stack, and the usage record test

TL;DR

ABA Formal Opinion 512, issued 29 July 2024, creates no new duties. It applies the Model Rules lawyers already owe, competence under Rule 1.1 and confidentiality under Rule 1.6 among them, to generative AI tools. On confidentiality it asks two concrete questions: does the lawyer understand how the tool handles, stores, and reuses input, and has the client given informed consent where the input could reveal confidential details. Most firms can answer the policy question. Far fewer can answer the second pair, because nothing records what staff actually type into public tools. The workable response is a five-control stack: policy, training, sanctioned tools, prompt-level protection, and a usage record.

What Opinion 512 Actually Says

ABA Formal Opinion 512 does not ban generative AI, and it does not create new obligations. It takes duties that have existed for decades and states that they attach to every prompt a lawyer sends. That is the whole opinion in one sentence, and it is why the practical burden lands on information governance rather than on the ethics rules themselves.

The American Bar Association's Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, titled "Generative Artificial Intelligence Tools," on 29 July 2024, as the ABA's first ethics guidance specifically on generative AI use by lawyers. Reading the full text of Opinion 512, it holds that lawyers using generative AI tools must fully consider their duties under the Model Rules of Professional Conduct: competence under Rule 1.1, confidentiality under Rule 1.6, communication with clients under Rule 1.4, candor toward the tribunal, supervisory responsibilities over subordinate lawyers and nonlawyers who use AI, and reasonable fees under Rule 1.5 tied to actual time and value when AI is used.

Firms have managed this shape of problem before. Opinion 512 is the same analysis the profession applied to cloud storage and e-discovery vendors: know what the vendor does with the data, and make sure the engagement permits the disclosure. The difference is volume and speed. A lawyer interacts with a vendor's data handling terms once per contract. A lawyer interacts with a public chatbot's data handling terms, in practice, every single prompt.

What State Bars Added Since

Opinion 512 quickly became the shared reference point. The Kathrine R. Everett Law Library at UNC noted in February 2025 that Opinion 512 had become the framework cited by subsequent state bar opinions, with over 30 states having released AI-specific guidance for lawyers by early 2025. States are not copying it. They are extending it into their own trouble spots.

Two extensions matter for firm policy. The Texas State Bar Professional Ethics Committee's Opinion No. 705, issued February 2025, holds that lawyers using generative AI must maintain human oversight of AI-generated work product to prevent submission of fabricated case citations to courts, tying the duty directly to competence and candor obligations. The New York City Bar Association's Formal Opinion 2025-6 holds that lawyers using AI to record, transcribe, or summarize client conversations must address confidentiality safeguards and obtain client consent given the sensitivity of the recorded content.

The direction of travel is consistent: each new opinion narrows the space where a firm can say it never thought about a specific AI workflow. Meeting notes captured by an AI transcription tool are now their own ethics topic. Fabricated citations are their own topic. None of these opinions require technology purchases. All of them assume the firm knows what its people are doing with these tools, and that assumption is where most firms break.

The Operational Gap: Policy Without a Record

The numbers describe the gap plainly. ILTA's 2025 Technology Survey, as reported by eDiscovery Today, found that only 45% of law firms report having an official policy governing generative AI use or a list of vetted applications, even though 80% of firms are already using or exploring the technology. Most firms that use AI have not finished writing the rules for it. That is a governance gap, but it is the smaller one.

The larger gap is enforcement. Even the firms with a policy mostly lack any record of what the policy governs. Opinion 512 asks what a lawyer entered into a tool and what the tool did with it. A policy binder answers neither question. And the stakes of unverified AI output are no longer abstract: according to ComplexDiscovery, courts issued a combined $145,000 in sanctions tied to AI-generated fake citations in Q1 2026 alone, with 1,313 court proceedings involving AI-generated content documented as of April 2026, 496 of them involving licensed attorneys.

This is where shadow AI enters the picture, because almost none of this exposure arrives through approved channels. It arrives through a browser tab, a personal account, and a deadline. We cover the general problem in our shadow AI overview and the detection playbook in how to detect shadow AI. If you are evaluating tooling options for the legal sector specifically, our comparison of shadow AI approaches for law firms lays out the categories side by side.

The Five-Control Stack

Firms that can answer ethics questions about AI without improvising tend to run the same five controls, in roughly this order. Each one closes a specific failure mode left open by the one before it.

  1. A written policy. Short, current, and specific about which data classes may go to which tools. ILTA's numbers show this is still not universal.
  2. Training that names the rules. Associates know ChatGPT exists. What they lack is the connection between a pasted deposition summary and Rule 1.6. Training closes that specific gap, not a general AI awareness gap.
  3. Sanctioned tools. A fast path to approved AI is the only proven counterweight to the two-minute signup path. If the sanctioned route takes weeks, the policy is competing with a browser bookmark and losing.
  4. Prompt-level protection. Opinion 512's confidentiality analysis turns on what leaves the firm and what the receiving tool does with it. Controls that operate on the prompt itself, before it leaves, act directly on that variable instead of around it.
  5. A usage record. When a client or the bar asks what was entered and what was protected, "we have a policy" is not an answer. A record of what left and what was masked is.

Controls four and five are where most firms have nothing in place, and they are the two that convert the policy from a document into evidence. Our legal solution page covers how those layers work in practice for law firm workflows.

Where Prompt-Level Protection Fits

To be explicit about scope: nothing in this section is legal advice, and whether any control satisfies your obligations is a question for your ethics counsel. The operational point is narrower. Opinion 512 asks what entered the tool. A control that changes what enters the tool changes the facts the analysis runs on.

This is what Secured AI does. It sits between the user and the model, and:

  • Detects and masks identifiers on the device before the prompt leaves: names, dates of birth, account and record numbers, contact details, and custom patterns.
  • Includes legal data detection covering client names, matter numbers, case names, opposing parties, witness names, contract terms, and settlement details.
  • Restores real values locally after the response returns, with a zero-knowledge vault whose master key is never stored server-side.
  • Keeps a usage record: what left and what was masked.
  • Applies matter-level policies and role-based access.
  • Works with OpenAI and DeepSeek, requires no behaviour change for staff, and is built with compliance-focused architecture.

The masked prompt still goes to the model. The lawyer still reviews the output, per the supervision duties the opinion restates. But the confidentiality question shifts from "did the client consent to their matter details sitting on a vendor server" to a question about text that no longer contains those details. That is a materially easier question to answer, and the usage record means the firm can show its work.

Frequently Asked Questions

What does ABA Formal Opinion 512 require of law firms?
It requires lawyers using generative AI tools to fully consider their existing duties under the Model Rules of Professional Conduct: competence, confidentiality, communication with clients, candor toward the tribunal, supervisory responsibilities over subordinate lawyers and nonlawyers using AI, and reasonable fees tied to actual time and value. On confidentiality, it expects lawyers to understand how a tool handles, stores, and potentially reuses input data, and to obtain informed client consent before inputting information that could reveal confidential details unless an exception to Rule 1.6 applies. It is guidance on duties lawyers already owe, not a new rulebook.
Is it an ethics violation for a lawyer to paste client information into ChatGPT?
Opinion 512 does not name tools and does not ban pasting. It frames the analysis: did the lawyer understand the tool's data handling and retention practices before entering information relating to a representation, and did the client give informed consent where the input could reveal confidential details. That determination depends on the jurisdiction and the facts of the engagement. How your firm responds is a question for your ethics counsel.
Which state bars have issued AI ethics guidance for lawyers?
A growing list, with Opinion 512 serving as the reference framework cited by subsequent state bar opinions. Texas and the New York City Bar examples are covered above with links to the underlying opinions. Check your own state bar's current guidance, because the list has kept growing since 2024.
Does Opinion 512 ban generative AI in legal work?
No. It treats generative AI as a tool to which the Model Rules already apply. It also reaches areas beyond confidentiality, including supervisory duties when subordinate lawyers or nonlawyer staff use AI, and fee reasonableness when AI compresses the time a task takes.
Our firm has a written AI policy. Is that enough?
A policy answers the governance question, not the confidentiality one. Opinion 512's analysis operates at the level of individual inputs: what was entered, what the tool does with it, and whether consent covered it. A policy without any record of actual use leaves those questions unanswered, which is why the control stack in this guide ends with a usage record rather than a document.

Close the gap between the policy and the prompt

Secured AI detects and masks client identifiers on the device before a prompt leaves, restores real values locally, and keeps a record of what left and what was masked. Built with compliance-focused architecture for firms that need answers to the questions Opinion 512 raises. See how it works for legal teams.