Your State Bar Just Set AI Rules: The 2026 Ethics Map for Solo and Small Firm Attorneys
Executive Summary
- AI related lawyer duties are increasingly enforced through existing ethics rules and court sanctions authority. New York added a statewide court rule, 22 NYCRR Part 161, adopted March 25, 2026 and effective June 1, 2026 across the Unified Court System.
- Alabama issued Formal Opinion 2026-01, among the most operationally detailed state bar AI guidance published to date, with an eleven item pre filing checklist and one of the earliest sustained discussions of agentic AI.
- California may go further. On March 13, 2026, COPRAC approved proposed amendments to six Rules of Professional Conduct. If the California Supreme Court adopts them, AI obligations become express disciplinary requirements rather than advisory guidance.
- The sanctions record is no longer theoretical. A live database recorded more than 1,800 hallucination decisions worldwide at its August 8, 2026 snapshot, and consequences in the most serious filing cases now exceed $110,000.
- The published opinions converge on six practical duties: competence, verification, confidentiality, client communication, supervision, and reasonable fees. A small firm can address all six with a written policy, a verification protocol, and a documentation habit.
In this article
- What do state bar AI rules actually require in 2026?
- ABA Formal Opinion 512 set the national baseline
- Alabama Formal Opinion 2026-01 is the most operational guidance yet
- New York moved AI from ethics opinion to court rule
- California is converting guidance into disciplinary rules
- How the major jurisdictions compare
- What the sanctions record actually shows
- Billing is where small firms create avoidable exposure
- Confidentiality: the contract is the problem, not the price
- A 90 day AI governance plan for a small firm
1. What do state bar AI rules actually require in 2026?
State bar AI rules in 2026 require lawyers to independently verify every AI generated citation and factual assertion before filing, to protect client confidentiality when entering information into AI systems, to supervise staff use of AI tools, and to bill only for time actually spent rather than the time a task would have taken without AI. No jurisdiction has banned generative AI in legal practice, and every jurisdiction that has spoken holds the lawyer, not the tool, responsible for the output.
That is the short version, and it has been stable since the American Bar Association issued Formal Opinion 512 on July 29, 2024. What changed in 2026 is the enforcement posture, and it changed unevenly. Three jurisdictions moved in the first half of the year, but they moved by three different mechanisms, and the difference between those mechanisms determines what actually binds you.
New York adopted a statewide court rule that governs AI assisted papers in Unified Court System cases. Alabama published guidance detailed enough to function as a compliance manual, though it applies existing professional conduct rules rather than creating new ones. California proposed amendments that would write AI duties directly into the Rules of Professional Conduct, where a violation means discipline rather than criticism, but those amendments are not yet adopted.
Keep that distinction in view. Only New York has a new binding instrument, Alabama interprets rules that already applied to you, and California has a proposal. All three describe the same underlying duties, which is why a firm that builds to the strictest reading is well positioned wherever it practices. That matters most to solo and small firms, because the obligations are identical regardless of headcount, and the Alabama State Bar said so directly.
2. ABA Formal Opinion 512 set the national baseline
ABA Formal Opinion 512, issued July 29, 2024 by the Standing Committee on Ethics and Professional Responsibility, established that generative AI use implicates at least six existing Model Rules: competence, confidentiality, communication with clients, candor toward the tribunal, supervisory responsibilities, and reasonable fees. Nearly every state opinion since has been built on its framework.
Three of its holdings matter most to small firms.
On competence, the opinion is deliberately modest about technical expertise. Lawyers do not need to become AI engineers, but they do need a reasonable understanding of what a tool does, what it does not do, its known limitations, and how its outputs can fail. Because the technology changes quickly, the duty includes periodically reassessing tools already in use.
On verification, Opinion 512 establishes that submitting AI generated work containing unverified false legal or factual assertions can implicate, at minimum, the competence and candor duties under Model Rules 1.1 and 3.3. The candor duty attaches to representations made to a tribunal, so the exposure crystallizes at the moment of filing rather than at the moment of drafting. This is the reasoning that subsequent sanctions decisions have followed.
On fees, the opinion drew a line many small firms have not yet absorbed. A lawyer may not charge clients for time spent learning a technology for general use in the practice, the narrow exception being where a client specifically requests a particular tool in a matter. Section 8 takes up the billing consequences in full.
3. Alabama Formal Opinion 2026-01 is the most operational guidance yet
Alabama Formal Opinion 2026-01, titled “Artificial Intelligence Use: Best Practices Under Existing Professional Conduct Rules,” is among the most operationally detailed AI ethics guidance any state bar has published, with one of the earliest sustained discussions of agentic AI. Rather than stating principles and stopping, the Alabama State Bar opinion maps each duty to a named Rule of Professional Conduct and closes with an eleven item checklist to run before every AI assisted filing.
Read the title carefully, because it signals the document’s legal status. This is guidance on best practices under rules that already existed, not a new disciplinary rule. The recommendations carry real weight as a standard of care, but they are not freestanding prohibitions.
Across thirteen sections it addresses competence under ARPC 1.1, verification under ARPC 1.1, 3.1, and 3.3, confidentiality under ARPC 1.6, client communication under ARPC 1.4, supervision under ARPC 5.1 and 5.3, fees under ARPC 1.5, candor under ARPC 3.3, and unauthorized practice of law under ARPC 5.5, 5.3, and 8.4.
Vendor selection is a competence issue
Alabama makes an argument most opinions leave implicit: selecting an AI tool without evaluating its accuracy or data retention policies may itself be a failure of competence under Rule 1.1. That shifts the compliance obligation earlier, to the purchasing decision, rather than locating it entirely at the point of filing.
Agentic AI gets its own section
Section XI addresses agentic AI separately, defining it as autonomous systems that use reasoning and planning to execute multi step tasks rather than merely generating content. A generative tool drafts a discovery response when prompted. An agentic tool might draft it on detecting a new file, email it to the client, calendar the deadline, and update the case management system, all without further attorney input.
Alabama’s response is a clear recommendation rather than a rule. The guidance advises that lawyers not deploy agentic tools on client matters without a documented human review checkpoint before the tool acts, that they define in writing what the agent is and is not authorized to do autonomously, and that they audit its activity logs regularly. These sit in the opinion’s best practices section, which means a lawyer who ignores them has not automatically violated a rule, but will have a hard time explaining the omission if the agent does something the client did not authorize.
The website chatbot problem
Section X raises an exposure small firms create routinely and rarely think about. If a firm deploys a website chatbot that answers prospective clients’ legal questions in real time, giving specific legal advice without flagging that it is not an attorney and without attorney review, that may constitute unauthorized practice of law, and the lawyer who deployed it may be responsible under Rules 5.5, 5.3, and 8.4. The opinion adds a marketing caution: avoid presenting AI tools as though the software itself is the lawyer.
4. New York moved AI from ethics opinion to court rule
New York adopted 22 NYCRR Part 161, “Use of Artificial Intelligence Technology,” on March 25, 2026, effective June 1, 2026, making it binding across every court in the Unified Court System in both civil and criminal matters. This is the structural difference that matters. An ethics opinion interprets a disciplinary rule. A court rule governs the filing itself, and the court in front of you enforces it directly.
Note the boundary of that reach. Part 161 covers the Unified Court System, so it does not automatically govern filings in federal courts sitting in New York, in executive branch administrative tribunals, or in other non UCS forums. A practice with a federal or agency docket must check those forums separately, since many federal judges have issued their own standing orders on AI use.
The New York State Bar Association summary and the rule’s text establish four things small firms need to understand.
First, AI use is permitted. The stated policy is that attorney and party use of AI tools in preparing papers should not be prohibited, provided it accords with the duties already applying to anyone submitting papers to a court.
Second, disclosure is not required. Section 161.3 imposes no obligation to tell a court that an AI tool was used, since existing duties attach to every submission regardless of how it was produced.
Third, review is mandatory. Any attorney or party who uses an AI tool in preparing a paper filed in, submitted to, or served in a case must carefully review it and independently ensure it contains no fabricated or fictitious cases, statutes, or other material.
Fourth, individual courts can add requirements. Section 161.4 permits additional part rules, and Appendix A supplies an optional model rule under which a signature certifies that careful review was performed. Be precise about how the layers interact: the review obligation above is statewide and applies whether or not your court adopts the model rule, which adds only an express certification. Courts retain existing authority to sanction under 22 NYCRR 130-1.1 and to address candor under Rule 3.3, so Part 161 channels existing sanctions authority rather than creating a new penalty scheme.
The practical consequence is that Part 161 is a floor, not a ceiling. Check the individual court’s rules before every filing. Alabama agrees, warning that court specific requirements are proliferating and that checking them is not a one time task.
5. California is converting guidance into disciplinary rules
California is among the first jurisdictions to propose incorporating AI specific language directly into its Rules of Professional Conduct, which would make the obligations enforceable through the discipline system rather than persuasive as advisory guidance. On March 13, 2026, the State Bar’s Committee on Professional Responsibility and Conduct approved proposed amendments to six rules and opened a 45 day public comment period that closed May 4, 2026.
The rulemaking did not originate with the bar. The California Supreme Court directed it in an August 22, 2025 letter instructing COPRAC to consider whether the principles in the bar’s November 2023 practical guidance on generative AI should move into the formal rules, and to address agentic tools specifically.
The committee chose not to draft a standalone AI rule, weaving new language into six existing ones instead, on the view that AI sharpens existing duties rather than creating new ones: Rule 1.1 on competence, Rule 1.4 on client communication, Rule 1.6 on confidentiality, Rule 3.3 on candor toward the tribunal, Rule 5.1 on supervisory lawyers, and Rule 5.3 on nonlawyer assistants.
Two proposals go beyond what other jurisdictions currently require. The Rule 1.4 amendment would mandate disclosure to the client when AI use presents a significant risk or materially affects the scope, cost, manner, or decision making of the representation. The Rule 1.6 amendment would define “reveal” to include exposing confidential information to AI systems where that exposure creates a material risk of misuse.
One caution before you act on this. The amendments are proposed, not adopted; any change requires adoption by the California Supreme Court, and neither the timing nor the final content is settled. A firm that builds its policy around the six duties in the existing opinions will already satisfy most of what California is proposing.
6. How the major jurisdictions compare
The major jurisdictions differ far more in instrument and enforceability than in substance, which is good news for a firm practicing in several states. Florida issued Opinion 24-1 in January 2024, Texas issued Opinion 705 in February 2025, and North Carolina issued 2024 Formal Ethics Opinion 1, all landing on the same core duties as Alabama and the ABA.
| Jurisdiction | Instrument | Status | Disclosure to client or court | Distinctive requirement |
|---|---|---|---|---|
| ABA | Formal Opinion 512 | Issued July 29, 2024. Persuasive only. | Not categorically required | Cannot bill for general time learning a technology |
| Alabama | Formal Opinion 2026-01 | Issued 2026. Guidance under existing rules, not a new rule. | Not mandated, strongly encouraged in engagement letter | Agentic AI review checkpoint and eleven item checklist, both as best practices |
| New York | 22 NYCRR Part 161 | Adopted March 25, 2026. Effective June 1, 2026. Binding in UCS courts. | Expressly not required to the court | Mandatory independent review; sanctions may be available under existing 22 NYCRR 130-1.1 |
| California | Amendments to Rules 1.1, 1.4, 1.6, 3.3, 5.1, 5.3 | Proposed March 13, 2026. Not adopted. | Would require client disclosure in defined circumstances | Would make AI duties disciplinary rather than advisory |
| Texas | Opinion 705 | Issued February 2025. Persuasive. | Not categorically required | Hourly billing efficiencies must benefit the client |
| Florida | Opinion 24-1 | Issued January 2024. Persuasive. | Informed consent recommended where an outside tool creates confidentiality risk | Applies lawyer advertising restrictions to AI claims |
Read the table by column, not by row. Whatever your jurisdiction, the operational answer is the same: verify everything, control where client data goes, supervise your staff, and bill honestly. The variation is only in what a breach produces.
7. What the sanctions record actually shows
The sanctions record shows that hallucination decisions have become widespread across jurisdictions, and that financial consequences in the most serious filing cases are now substantial. The AI Hallucination Cases database maintained by Damien Charlotin, cited in news media and in several judicial decisions, recorded 1,868 decisions worldwide at its August 8, 2026 snapshot, 1,297 of them in the United States.
Three caveats. The database updates continuously, so treat the totals as a dated snapshot. Its classification facets overlap, since one decision can carry more than one defect tag, so the category counts do not sum to the total. And not every tracked decision produced a sanction: judicial responses run from a warning through monetary penalties, disqualification, and referral for discipline.
With that said, the composition is the part small firms should sit with. Pro se litigants account for roughly 1,096 of the tracked decisions and practicing lawyers for roughly 724, so this is not solely a self represented litigant problem. Fabricated authority is the most commonly tagged defect at 1,556 decisions, followed by misrepresented authority at 782.
By practice area, the distribution tracks small firm work closely. Contract matters lead at 435 decisions, followed by administrative at 250, civil rights at 191, employment at 170, and tort at 163. These are not exotic appellate specialties. They are the docket of a general civil practice.
Four decisions that define the range
Mata v. Avianca, Inc., 678 F.Supp.3d 443 (S.D.N.Y. 2023), is the origin point. Judge P. Kevin Castel imposed a $5,000 penalty jointly and severally on June 22, 2023 after counsel submitted six fabricated cases produced by ChatGPT, finding bad faith based on conscious avoidance and misleading statements to the court.
Johnson v. Dunn, 792 F.Supp.3d 1241 (N.D. Ala. 2025), shows that firm size is no shield. On July 23, 2025, Judge Anna Manasco sanctioned three attorneys at a large national firm with public reprimand, disqualification from the case, and referral to the Alabama State Bar. Two other attorneys and the firm itself were released without sanction. The lawyer who generated the citations admitted he inserted them without verifying a single one.
Ibach v. Stewart, decided April 24, 2026, brought a state supreme court into the conversation. The Alabama Supreme Court dismissed the appeal as frivolous under Rule 38 of the Alabama Rules of Appellate Procedure and ordered counsel to pay $17,200 in fees and costs to the appellee, to pay double appellate costs, and to file nothing further in that court unless another attorney signs it. At a show cause hearing on February 4, 2026, the attorney admitted that many authorities in his briefs did not exist, accepted sole responsibility, and conceded that sanctions were appropriate.
Couvrette v. Wisnovsky in the District of Oregon is the most expensive matter reported to date. Counsel filed 15 nonexistent citations and eight fabricated quotations across three briefs, and the consequences came in two orders. A December 12, 2025 order required lead counsel to pay $15,500 to the Clerk, calculated at $500 per nonexistent case and $1,000 per fabricated quotation. A March 23, 2026 order added $94,704.38 in fees and costs, apportioned 85 percent to lead counsel and 15 percent to local counsel, for a combined total of approximately $110,204.
Note what the client lost. In Ibach the appeal was dismissed; in Johnson counsel was removed. The professional consequences fall on the lawyer, but the harm lands on the client, which is why these are competence and candor violations rather than procedural stumbles.
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.
8. Billing is where small firms create avoidable exposure
Billing is the AI obligation small firms breach most often and notice least, because it happens quietly on a timesheet rather than publicly in a filing. Alabama Formal Opinion 2026-01 states the rule directly under ARPC 1.5: lawyers may bill only for time actually spent, not for the time a task would have taken but for the use of AI.
The opinion’s own example is the cleanest statement of the principle available. If AI drafts a brief in ten minutes that would have taken four hours, the lawyer cannot bill four hours as if the AI did not exist. What is billable is the review: time spent reviewing, correcting, and exercising legal judgment over AI output is genuine professional work, on the same theory that reviewing a junior associate’s draft is billable. The distinction is between capturing time you spent and capturing time you saved.
Alabama also addresses subscription costs. Its view is that AI subscriptions are generally overhead rather than a direct client charge, unless the client agrees otherwise in writing, by analogy to how most firms have treated Westlaw and Lexis. That is Alabama’s position and a common treatment, not a uniform rule everywhere, so confirm how your own state handles cost pass through before changing a billing practice.
Texas Opinion 705 reaches the same destination from another angle, holding that AI efficiencies must benefit the client financially in hourly engagements and that attorneys cannot bill for hours not genuinely worked. Flat fee firms should not assume the issue passes them by: ABA Formal Opinion 512 cautions that a flat fee can itself become unreasonable if AI materially reduces the work the fee was set to cover.
The practical fix takes one paragraph in your engagement letter. Alabama recommends obtaining client agreement on AI billing upfront, which converts an ambiguous area into a documented understanding before the first invoice.
9. Confidentiality: the contract is the problem, not the price
The confidentiality exposure in most small firms is not the choice to use AI, it is the failure to check whether the specific version and contract in use permit retention, model training, or third party access to what you type. Alabama Formal Opinion 2026-01 frames the issue in three words in its section heading: input is disclosure.
Its reasoning is that most platforms collect, retain, or reuse user inputs unless expressly prohibited by contract. Entering client information into such a system may create privilege risks courts have not uniformly resolved, and may constitute disclosure to a third party under some platforms’ terms of service.
Alabama draws the practical distinction between tiers of the same product. Enterprise versions typically prohibit using inputs to train the provider’s models, while free consumer versions of those same tools generally do not. That is a reliable rule of thumb and a good starting filter.
Do not let it become the whole analysis. Price is a proxy, not the standard. Some paid tiers carry weaker protections than their marketing implies, and some free tools now offer retention opt outs that change the picture. What governs is the actual contract, the account configuration, the retention and training terms, and the sensitivity of the data going in. The question is never “did I pay for this,” it is “what do the terms let this provider do with what I typed.”
Under ARPC 1.6, Alabama requires lawyers to understand the provider’s data handling practices, avoid entering identifiable client information unless adequate safeguards exist, and obtain informed client consent where confidentiality risks cannot be eliminated. Florida Opinion 24-1 reached a compatible standard in January 2024, requiring research into a program’s retention, sharing, and self learning policies before use with confidential information.
One consequence is easy to miss. AI prompts, drafts, and interaction logs may be discoverable in some circumstances, for example if a party’s use of AI is placed at issue or if logs sit on a system under a litigation hold. Whether they are turns on the forum, the claims, privilege, and preservation duties, so treat it as a live risk rather than a certainty. Alabama recommends retention policies that expressly address AI interactions, and that AI summaries never replace the original source documents.
GOVERNANCE INSIGHT
Supervision is where a small firm’s exposure multiplies fastest.
Alabama treats AI as a nonlawyer assistant under ARPC 5.1 and 5.3, which means a lawyer can be held accountable for AI generated errors exactly as for the errors of supervised staff. The named risk is delegation: when a lawyer hands AI use entirely to a staff member who lacks the legal training to recognize a hallucination, the supervising lawyer remains fully responsible for the final product regardless of who operated the tool.
10. A 90 day AI governance plan for a small firm
A solo or small firm can establish a defensible AI governance baseline in 90 days using three phases: inventory and policy in the first 30 days, verification and supervision protocols in the second 30, and documentation and review habits in the third. None of it requires a compliance department, and most of it comes directly from the best practices sections of the published opinions.
Treat this as a governance model, not a recitation of binding law. No jurisdiction reviewed here mandates a written AI policy as a standalone requirement. It is a risk control, and the most useful one available to a small firm, because it turns the supervision duty under Rules 5.1 and 5.3 into something you can demonstrate. Tailor the specifics to your jurisdiction, practice area, and the courts you appear in.
Days 1 to 30: inventory and written policy
List every AI tool anyone in the firm uses on client work, including tools embedded in software you already license. For each, record the tier, whether the contract prohibits training on your inputs, and what the retention terms say. Alabama treats this evaluation as a competence obligation attached to the purchasing decision, so the inventory is not administrative housekeeping.
Then write the policy: which tools are approved, what tasks they may be used for, and what verification is required before AI assisted work leaves the firm. Alabama recommends centralizing approval of firm wide tools and considering an AI compliance coordinator to vet tools, maintain use logs, and answer staff questions.
Days 31 to 60: verification and supervision
Build verification into your filing workflow rather than leaving it to individual discipline. Alabama’s standard is that every AI generated citation is independently verified against Westlaw, Lexis, or a comparable authoritative database before filing, and that AI generated factual summaries are run against the underlying source documents.
Set the supervision rule at the same time. Nonlawyer staff should never submit AI generated work product without attorney review. If your practice touches New York courts, Part 161’s independent review obligation has applied to every paper filed in a Unified Court System case since June 1, 2026. This is also the phase for client facing deployments: if your website runs a chatbot answering legal questions, either put attorney review behind it or make clear it is not an attorney and does not give legal advice.
Days 61 to 90: documentation and recurring review
Documentation is what converts a policy into a defense. Alabama recommends recording, for each matter, which tool was used, the date, what it was asked to do, what it generated, and what verification the supervising lawyer performed.
Add three recurring habits. Check local rules and standing orders before filing in any court, because those requirements are changing quickly. Reassess your tools periodically for changes to retention practices and reliability, since Alabama treats technological competence as ongoing rather than static. And put AI literacy into your annual continuing legal education planning.
Firms wanting a structured way to measure where they stand can map this against an established framework. The NIST AI Risk Management Framework and ISO/IEC 42001 both scale down to small organizations and give you vocabulary that clients and insurers increasingly recognize. The same governance questions we walked through for small registered investment advisers facing SEC expectations apply here with different rule numbers attached.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
Frequently Asked Questions
Do I have to tell the court that I used AI to write a brief?
In most jurisdictions, no. New York’s 22 NYCRR Part 161, effective June 1, 2026, expressly declines to require disclosure of AI use to the court, since the duties attached to a submission apply regardless of how it was produced. But Section 161.4 lets individual courts add their own rules, and many federal and state judges have issued standing orders requiring disclosure or certification. Check local rules and standing orders before every filing.
Can I bill a client for the time AI saved me?
No. Alabama Formal Opinion 2026-01 states that lawyers may bill only for time actually spent, not the time a task would have taken but for the use of AI: if AI drafts a brief in ten minutes that would have taken four hours, you cannot bill four hours. You can bill the time you spend reviewing, correcting, and applying legal judgment to the output. Texas Opinion 705 similarly holds that AI efficiencies must benefit the client financially in hourly engagements.
Is it a confidentiality violation to put client facts into ChatGPT?
It can be, and the deciding factor is the contract governing your specific account, not whether you paid for it. Alabama Formal Opinion 2026-01 frames the issue as “input is disclosure,” noting that most platforms retain or reuse inputs unless a contract prohibits it, and that enterprise versions typically carry those prohibitions while free consumer versions generally do not. Under ARPC 1.6 you must understand the provider’s data handling practices and obtain informed consent where the risk cannot be eliminated.
What are the actual penalties for filing AI hallucinated citations?
They range from a warning to six figures, and often include non monetary consequences. Mata v. Avianca produced a $5,000 sanction in 2023, and in Johnson v. Dunn in July 2025 three attorneys received public reprimand, disqualification, and referral to the state bar. The Alabama Supreme Court dismissed the appeal in Ibach v. Stewart on April 24, 2026 as frivolous and ordered $17,200 in fees and costs. Couvrette v. Wisnovsky reached approximately $110,204 across a December 2025 sanctions order and a March 2026 fees award.
Does my two person firm really need a written AI policy?
No jurisdiction reviewed here mandates one as a standalone requirement, but it is the most effective risk control available to a small firm. Alabama Formal Opinion 2026-01 states that its guidance applies equally to solo practitioners, small firms, and large firms regardless of resources. Because Rules 5.1 and 5.3 make a supervising lawyer accountable for AI errors as for the errors of supervised staff, a policy naming approved tools, permitted tasks, and verification steps is what lets you show supervision happened.
Is the AI website chatbot on my firm’s site a compliance risk?
It can be. Section X of Alabama Formal Opinion 2026-01 warns that a chatbot answering prospective clients’ legal questions in real time, without flagging that it is not an attorney and without attorney review, may constitute unauthorized practice of law under Rules 5.5, 5.3, and 8.4, with responsibility falling on the lawyer who deployed it. The opinion also cautions against marketing AI tools as though the software itself is the lawyer.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.