← All Publications
August 24, 2026

Do Androids Dream of Billable Hours?

A Practical Guide to AI Governance and Ethics for Lawyers

In this article for IAPP, Brenda Leong discusses how for lawyers, AI is both a client-advising issue and an internal governance challenge, requiring technical literacy, strong controls , careful vendor and billing practices and human accountability for all AI-assisted legal work. Please note that the original publication is paywalled, but the full text is displayed below.

Read the original article here →


Lawyers find themselves at an interesting place in the artificial intelligence landscape. 

On one hand, legal counsel serves as trusted advisors guiding C-suites, compliance and privacy officers, and product engineering teams through an accelerating flow of AI regulation and operational risk management. 

On the other hand, lawyers are also active operators and direct consumers of these exact same technologies, embedding large language models, automated research platforms and agentic systems into daily firm operations and supporting client deliverables. 

Navigating this dual role requires considering how to apply controls across both client counseling and firm workflows: most importantly, regardless of how autonomous or sophisticated an algorithm becomes, professional accountability remains entirely with the human. 

A lawyer cannot outsource independent legal judgment, ethical duties or final responsibility for legal output. But at the same time, lawyers may not realistically be able to carry out those duties without using these tools. Understanding AI is no longer a competitive advantage; it is quickly becoming a core prerequisite for legal services. 

What is an AI-using lawyer to do? Court rules, state bar opinions and vendor products are all moving targets. Here is a tour of the landscape as it stands now.

Technical understanding is a governance prerequisite.

You cannot govern what you don’t understand, and a growing body of guidance treats basic AI literacy as part of the competence a lawyer owes clients. That starts with knowing what a large language model actually does: it generates plausible text, images, audio/video or code based on patterns, and while its functions can overlap with search or analysis tools, the final output is always a prediction, not based on any underlying truth.

Hallucination, therefore, is only one kind of inaccuracy. Failure modes also include wrong quotations, distorted holdings, invented records or facts and unsupported conclusions, all of which can end up in a document that otherwise looks polished and well-sourced.

The clearest example of emerging risk is the rise of agentic Al. That is, goal-oriented systems that can plan multitask processes, call tools/systems, search data storage, send messages and execute transactions, all with limited human intervention. An ordinary chatbot can produce a bad – imaginary, wrong or incomplete – answer, which the lawyer may catch before it goes anywhere. But an agent can act on that bad answer before anyone reviews it: filing with the court, drafting or sending communications, or changing or deleting a record.

That redefines the risk assessments needed. California’s 2026 bar guidance explicitly updates the Al-relevant competence analysis to account for agentic systems, and the outcome is the need for a set of controls that barely existed five years ago: least-privilege access, restricted external actions, mandatory human approval before anything is filed or sent, logging and a reliable kill switch.

Rising expectations also include sophisticated security approaches to identify prompt injections, the instructions buried in a webpage, email, or other input that may hijack an Al system’s behavior. Lawyers will need to understand all these things well enough to ask vendors directly, assimilate responsibly and operate carefully, both at the organizational and individual level.

The rules of professional conduct still apply, what does that mean for AI?

As Al adoption has accelerated, state bar associations across the country have worked to provide regulatory guidance to help lawyers understand their responsibilities under traditional professional standards. Official bar entities like the American Bar Association and state bar associations – including at least Alabama, Alaska, California, the District of Columbia, Florida, Illinois, Kentucky, Mississippi, New Jersey, New Mexico, New York, North Carolina, Oregon, Pennsylvania, Texas, Virginia, Washington and West Virginia – have issued formal advisory opinions, ethics guidelines and/or practical toolkits addressing Al in legal practice.


While there are some variations, a fairly consistent consensus is emerging. Every jurisdiction reinforces that existing rules of professional conduct fully apply to Al tools, without exception. Under the ABA Model Rules of Professional Conduct Rule 1.1, Competence, lawyers must possess a reasonable understanding of an Al tool’s capabilities and limitations before deployment. Under Rule 1.6, Confidentiality, practitioners are required to safeguard client information, which in the case of Al, may mean against unauthorized exposure or vendor model training. Rules 5.1 and 5.3, Supervision, mandate that partners and managers oversee Al tools and non-lawyer assistance with equal rigor. Finally, Rule 3.3, Candor, and Rule 1.5, Reasonable Fees, establish that lawyers remain strictly accountable for all court filings and cannot charge clients unearned hourly fees for tasks automated by technology.


While there is a lot of common ground, there are a few noteworthy regional distinctions. West Virginia’s Legal Ethics Opinion 24-01 takes a markedly strict stance compared to the national trend by requiring written informed consent from clients before entering confidential data into generative Al tools. Florida’s Ethics Opinion 24-1 focuses heavily on lawyer marketing, warning against deceptive synthetic media, Al-generated voices or unvalidated claims of predictive accuracy. Virginia’s Legal Ethics Opinion 1901 provides vital clarity on billing economics, emphasizing that while lawyers cannot bill hypothetical unworked hours under hourly structures, Al efficiency strongly favors the adoption of alternative, value-based fee arrangements such as fixed or flat fee projects

Lawyers are businesspeople too, and must govern AI in operations.

Responsible Al use is, quite directly, a management problem. A firm that doesn’t provide approved tools and usable workflows for legitimate Al-assisted work will end up with shadow Al – lawyers and staff using consumer tools outside any firm control, simply because no sanctioned alternative is available.

A workable governance program establishes accountability, includes a cross-functional group of ethics, information security, privacy, IT and practice leadership, and is based on an inventory of Al-enabled products, including embedded features, data access and approved versus prohibited uses.

Vendor contracting must adapt. Firms need to negotiate for no model training or improvement on firm inputs unless expressly approved, as well as clear retention and deletion commitments, security, audit rights and specified liability terms matched to the realistic scope of harm. A firm cannot outsource that responsibility to a vendor.

Likewise for billing, lawyers may still bill hourly, but it must be limited to actual time spent, not the hypothetical time a task would have taken without Al assistance. Lawyers also have to get smart about the tools on their own time. Several authorities specifically caution against billing a client for the lawyer’s own learning curve on Al. Flat fee or fixed fee arrangements are one proposed solution and may see further adoption for some of this specialized work.

Litigation has its own set of specific AI uses and risks.

In courtroom practice, multiple jurisdictions have made it increasingly clear that technical ignorance is no defense against Al-based errors. The initial era of cautionary warnings marked by cases like Mata v. Avianca in the Southern District of New York in 2023, where counsel relied on ChatGPT for fabricated precedents, has changed into a regime of stricter enforcement.

In 2026, appellate and district courts across the country issued severe penalties for hallucinated or error-ridden court filings. In Lnu v. Blanche in the U.S. Court of Appeals for the Ninth Circuit, 2026, the Ninth Circuit suspended two attorneys from practice for six months following citation fabrications and a lack of candor during post-filing inquiries.

Federal and state courts in Alabama, Mississippi, New York and Texas have issued public reprimands, monetary fines and mandatory bar referrals. In addition, courts have started admonishing lawyers for failing to identify and report errors in their opponent’s court filings, under a diligence standard.

In e-discovery and evidence, lawyers must apply established Technology-Assisted Review principles rooted in landmark decisions like Da Silva Moore v. Publicis Groupe.
Defensibility hinges on process, statistical sampling, validation and human oversight rather than algorithmic transparency alone.

When presenting machine-generated or Al-enhanced evidence, litigators must navigate Federal Rule of Evidence 901 for authentication and Rule 702 for expert reliability, while tracking developments around proposed Rule 707, which aims to standardize reliability standards for machine-generated outputs.

Privilege and work product when using AI are still unsettled questions.

This is a high-interest topic, with the least settled law, and lawyers should be cautious about assuming more protection than currently exists. The basic elements of privilege haven’t changed – a confidential communication between appropriate parties for the purpose of legal advice – but routing that communication through a third-party Al provider will raise waiver questions if the disclosure wasn’t reasonably necessary or if the provider’s terms undermine a reasonable expectation of confidentiality.

Vendor commitments, data controls and standardized processes reduce that risk, but no court has established a categorical safe harbor even for enterprise Al tools.

The early case law illustrates how fact-specific this is. In United States v. Heppner, a federal court rejected privilege and work-product claims over documents the defendant generated independently using a consumer version of an Al tool, emphasizing that the tool wasn’t counsel and that consumer privacy terms undermined confidentiality. But the court explicitly declined to resolve how an enterprise tool used at counsel’s direction would fare.

By contrast, Warner v. Gilbarco treated an Al tool as just that, a tool, and found protection for a prose plaintiff’s litigation analysis, while Morgan v. V2X recognized potential work-product protection but still amended a protective order to restrict use of confidential discovery material in mainstream Al tools without adequate contractual safeguards.

So far, outcomes turn on specific facts about the tool, the terms and who directed the work, and none of it should be read as a green – or red – light for enterprise LLM use with client materials.

Disclosure rules are likely to be unclear or inconsistent for awhile.

Beyond the privilege question, several other pieces of this landscape are genuinely in flux.

There is no uniform national disclosure rule to say whether a lawyer must tell a client or a court about Al use. Today, this depends on jurisdiction, materiality and whether a court has issued a specific order, ranging from low-risk internal use to West Virginia’s notably stricter written-consent position.

New York’s Part 161, Florida’s amended filing rule and Rhode Island’s interim guidelines each took different approaches within the same few months, a suggested federal Rule 11 amendment on citation certification remains at an early, unpublished stage and individual judges’ standing orders vary enough that they need to be checked matter by matter. A compliance program built around today’s rules needs a built-in process to continuously check for updates.

The bottom line: Lawyers are responsible on both sides.

Al is neither a magical substitute for legal analysis nor a temporary trend that practitioners can ignore. It represents a permanent change in how legal services are delivered. The emerging standard of the legal competence rule will demand continuous technical literacy: the ability to design structured prompt workflows, trace retrieval sources, evaluate vendor security architecture, govern autonomous agents and rigorously verify all synthetic outputs.

The tools will keep changing. A lawyer’s obligation to understand them well enough to use them responsibly will not.

By requiring technical understanding as well as uncompromising human accountability, lawyers can gain the benefits of Al while preserving their professional integrity and the trust of their clients.


Reprinted with permission from IAPP. © 2026 IAPP. Further duplication without permission is prohibited. All rights reserved.