ABA Formal Opinion 512: What Law Firms Actually Have to Do About AI
It restates duties your lawyers already owe and applies them to prompts. The gap is not the guidance. It is that most firms have nothing that records what actually gets typed into a browser.
TL;DR
ABA Formal Opinion 512, issued 29 July 2024, creates no new duties. It applies the Model Rules lawyers already owe, competence under Rule 1.1 and confidentiality under Rule 1.6 among them, to generative AI tools. On confidentiality it asks two concrete questions: does the lawyer understand how the tool handles, stores, and reuses input, and has the client given informed consent where the input could reveal confidential details. Most firms can answer the policy question. Far fewer can answer the second pair, because nothing records what staff actually type into public tools. The workable response is a five-control stack: policy, training, sanctioned tools, prompt-level protection, and a usage record.
Table of Contents
What Opinion 512 Actually Says
ABA Formal Opinion 512 does not ban generative AI, and it does not create new obligations. It takes duties that have existed for decades and states that they attach to every prompt a lawyer sends. That is the whole opinion in one sentence, and it is why the practical burden lands on information governance rather than on the ethics rules themselves.
The American Bar Association's Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, titled "Generative Artificial Intelligence Tools," on 29 July 2024, as the ABA's first ethics guidance specifically on generative AI use by lawyers. Reading the full text of Opinion 512, it holds that lawyers using generative AI tools must fully consider their duties under the Model Rules of Professional Conduct: competence under Rule 1.1, confidentiality under Rule 1.6, communication with clients under Rule 1.4, candor toward the tribunal, supervisory responsibilities over subordinate lawyers and nonlawyers who use AI, and reasonable fees under Rule 1.5 tied to actual time and value when AI is used.
Firms have managed this shape of problem before. Opinion 512 is the same analysis the profession applied to cloud storage and e-discovery vendors: know what the vendor does with the data, and make sure the engagement permits the disclosure. The difference is volume and speed. A lawyer interacts with a vendor's data handling terms once per contract. A lawyer interacts with a public chatbot's data handling terms, in practice, every single prompt.
The Confidentiality Core: Data Handling and Informed Consent
The confidentiality paragraph is the part your firm will be asked about, by clients and by state bar counsel. As the National Conference of Bar Examiners' Fall 2024 analysis summarizes it, Opinion 512 requires lawyers to understand how a given generative AI tool handles, stores, and potentially reuses input data before entering information relating to a client representation, and to obtain informed client consent before inputting information that could reveal confidential details unless an exception to Rule 1.6 applies.
Strip out the citation format and that is two gates. Gate one is knowledge: can the lawyer describe, in plain language, where the prompt goes, how long the provider keeps it, and whether it can be used for training. Gate two is consent: if the answer to gate one is "somewhere, indefinitely, and possibly," the client needs to have agreed to that before the text leaves the firm. A lawyer who cannot pass gate one cannot even evaluate gate two. That is the quiet failure mode in most firms, and it is operational, not ethical ignorance.
The consumer tooling makes gate one genuinely hard. Retention defaults and training-use defaults differ between consumer and business tiers of the same product, and they change without notice. If you want the specifics of what one major provider does with pasted text on each tier, we break that down in Can Lawyers Use ChatGPT with Client Data?
What State Bars Added Since
Opinion 512 quickly became the shared reference point. The Kathrine R. Everett Law Library at UNC noted in February 2025 that Opinion 512 had become the framework cited by subsequent state bar opinions, with over 30 states having released AI-specific guidance for lawyers by early 2025. States are not copying it. They are extending it into their own trouble spots.
Two extensions matter for firm policy. The Texas State Bar Professional Ethics Committee's Opinion No. 705, issued February 2025, holds that lawyers using generative AI must maintain human oversight of AI-generated work product to prevent submission of fabricated case citations to courts, tying the duty directly to competence and candor obligations. The New York City Bar Association's Formal Opinion 2025-6 holds that lawyers using AI to record, transcribe, or summarize client conversations must address confidentiality safeguards and obtain client consent given the sensitivity of the recorded content.
The direction of travel is consistent: each new opinion narrows the space where a firm can say it never thought about a specific AI workflow. Meeting notes captured by an AI transcription tool are now their own ethics topic. Fabricated citations are their own topic. None of these opinions require technology purchases. All of them assume the firm knows what its people are doing with these tools, and that assumption is where most firms break.
The Operational Gap: Policy Without a Record
The numbers describe the gap plainly. ILTA's 2025 Technology Survey, as reported by eDiscovery Today, found that only 45% of law firms report having an official policy governing generative AI use or a list of vetted applications, even though 80% of firms are already using or exploring the technology. Most firms that use AI have not finished writing the rules for it. That is a governance gap, but it is the smaller one.
The larger gap is enforcement. Even the firms with a policy mostly lack any record of what the policy governs. Opinion 512 asks what a lawyer entered into a tool and what the tool did with it. A policy binder answers neither question. And the stakes of unverified AI output are no longer abstract: according to ComplexDiscovery, courts issued a combined $145,000 in sanctions tied to AI-generated fake citations in Q1 2026 alone, with 1,313 court proceedings involving AI-generated content documented as of April 2026, 496 of them involving licensed attorneys.
This is where shadow AI enters the picture, because almost none of this exposure arrives through approved channels. It arrives through a browser tab, a personal account, and a deadline. We cover the general problem in our shadow AI overview and the detection playbook in how to detect shadow AI. If you are evaluating tooling options for the legal sector specifically, our comparison of shadow AI approaches for law firms lays out the categories side by side.
The Five-Control Stack
Firms that can answer ethics questions about AI without improvising tend to run the same five controls, in roughly this order. Each one closes a specific failure mode left open by the one before it.
- A written policy. Short, current, and specific about which data classes may go to which tools. ILTA's numbers show this is still not universal.
- Training that names the rules. Associates know ChatGPT exists. What they lack is the connection between a pasted deposition summary and Rule 1.6. Training closes that specific gap, not a general AI awareness gap.
- Sanctioned tools. A fast path to approved AI is the only proven counterweight to the two-minute signup path. If the sanctioned route takes weeks, the policy is competing with a browser bookmark and losing.
- Prompt-level protection. Opinion 512's confidentiality analysis turns on what leaves the firm and what the receiving tool does with it. Controls that operate on the prompt itself, before it leaves, act directly on that variable instead of around it.
- A usage record. When a client or the bar asks what was entered and what was protected, "we have a policy" is not an answer. A record of what left and what was masked is.
Controls four and five are where most firms have nothing in place, and they are the two that convert the policy from a document into evidence. Our legal solution page covers how those layers work in practice for law firm workflows.
Where Prompt-Level Protection Fits
To be explicit about scope: nothing in this section is legal advice, and whether any control satisfies your obligations is a question for your ethics counsel. The operational point is narrower. Opinion 512 asks what entered the tool. A control that changes what enters the tool changes the facts the analysis runs on.
This is what Secured AI does. It sits between the user and the model, and:
- Detects and masks identifiers on the device before the prompt leaves: names, dates of birth, account and record numbers, contact details, and custom patterns.
- Includes legal data detection covering client names, matter numbers, case names, opposing parties, witness names, contract terms, and settlement details.
- Restores real values locally after the response returns, with a zero-knowledge vault whose master key is never stored server-side.
- Keeps a usage record: what left and what was masked.
- Applies matter-level policies and role-based access.
- Works with OpenAI and DeepSeek, requires no behaviour change for staff, and is built with compliance-focused architecture.
The masked prompt still goes to the model. The lawyer still reviews the output, per the supervision duties the opinion restates. But the confidentiality question shifts from "did the client consent to their matter details sitting on a vendor server" to a question about text that no longer contains those details. That is a materially easier question to answer, and the usage record means the firm can show its work.
Frequently Asked Questions
What does ABA Formal Opinion 512 require of law firms?
Is it an ethics violation for a lawyer to paste client information into ChatGPT?
Which state bars have issued AI ethics guidance for lawyers?
Does Opinion 512 ban generative AI in legal work?
Our firm has a written AI policy. Is that enough?
Close the gap between the policy and the prompt
Secured AI detects and masks client identifiers on the device before a prompt leaves, restores real values locally, and keeps a record of what left and what was masked. Built with compliance-focused architecture for firms that need answers to the questions Opinion 512 raises. See how it works for legal teams.

