Formal Opinion 512 was issued on 29 July 2024 by the ABA Standing Committee on Ethics and Professional Responsibility. It is fifteen pages, it is readable in half an hour, and it is the document a chief defender will be asked about when the office proposes to use any of this.
It is worth reading for what it does not do as much as for what it does.
What it requires
Competence. Lawyers need not become experts in the technology, but they must have a reasonable understanding of the capabilities and limitations of the specific tool they use, and the opinion is explicit that this is not a static undertaking [1]. That obligation sits on Rule 1.1 and its Comment 8, which tells a lawyer to keep abreast of the benefits and risks associated with relevant technology [2].
The sentence everyone quotes is the one about verification: a lawyer’s reliance on, or submission of, a tool’s output without an appropriate degree of independent verification or review could violate the duty of competence [1]. The sentence that follows is the one worth arguing about. The appropriate amount of verification depends on the tool and the specific task, and the opinion gives an example: a lawyer who has already tested a summarization tool against a manually reviewed subset need not re-review everything [1]. So the standard is not “check everything forever”. It is “know what your checking regime is, and why it is enough for this task”.
Confidentiality. Before inputting information relating to a representation, lawyers must evaluate the risk that it will be disclosed to or accessed by others outside the firm, and inside it [1]. For self-learning tools, the opinion concludes that client informed consent is required before inputting information relating to the representation, and adds that boilerplate language in an engagement letter purporting to authorize the use of such tools is not sufficient [1]. It also sets a baseline every office can meet: read and understand the terms of use, privacy policy and related contractual terms of any tool you use, or consult someone who has [1].
Supervision. Managerial lawyers must establish clear policies on permissible use, and supervisory lawyers must make reasonable efforts to ensure that lawyers and nonlawyers comply, including through training on the tools’ capabilities, limitations and secure data handling [1]. Where the tool comes from outside the firm, the opinion applies the outsourcing analysis: vendor credentials, security policies, confidentiality agreements, and a forum for relief if the agreement is broken [1].
Fees. A lawyer billing hourly must bill actual time. The opinion’s own example: if you spend fifteen minutes putting information into a tool to draft a pleading, you may charge for that fifteen minutes plus the time you spend reviewing the draft for accuracy and completeness [1]. And you may not charge a client to learn a tool you will use regularly for clients, because maintaining competence in your own tools is your problem, not the client’s [1].
What it does not say
It does not ban anything. It does not name products, endorse a category, or tell you that a tool marketed to lawyers is safer than a general one.
It does not impose a general duty to tell the court you used a tool. On litigation duties it points to candor and meritorious contentions, and a footnote sends lawyers to the applicable court’s local rules on AI use [1]. Standing orders vary by judge, and they are what binds you.
It does not impose a general duty to tell the client either. Whether Rule 1.4 requires disclosure turns on the facts, and the opinion says that depending on the circumstances, client disclosure may be unnecessary [1]. But you must disclose if the client asks how the work was done, or if the engagement terms require it [1]. And where no information relating to the representation goes into the tool, informed consent is not triggered at all; the opinion’s example is idea generation [1].
It does not set a number. There is no percentage of output you must check, and no safe harbor for tools that advertise verification.
Complying in a defender office
Five things, none of which require a budget:
- Write the policy. One page: which tools are permitted, for which tasks, with which categories of information, and who approves an addition.
- Read the terms, and keep the reading. For each tool, record who can access inputs, whether inputs train the model, and how long they are retained. The California guidance makes the same point, and adds the risk in plain words: generative AI may produce outputs that are probabilistic, not deterministic, and plausible but inaccurate, including citations to authority that does not exist [3].
- Default to no client information leaving the building, and treat any exception as a decision with a name attached to it. Public defenders rarely have an engagement letter to renegotiate, which makes the default matter more.
- Fix the verification rule per task, not per tool. Research and drafting that cites authority gets an existence check and a support check on every citation. Mata v. Avianca is the cautionary tale not because a model invented cases, but because nobody performed the check before filing, and asking the model whether its cases were real was treated as though it were one [4].
- Train, and keep a record that you did. Supervision is judged by reasonable efforts, and reasonable efforts leave a paper trail.
None of this is exotic. It is the same discipline offices already apply to investigators, interpreters and cloud storage, pointed at a tool that writes in complete sentences.
What Opinion 512 leaves open is where the verification should live. It has to be independent of the model’s own claim about itself, and it has to run before the document leaves. The argument Apodicta makes is that the cheapest place to put it is in code outside the model, so it runs on every line rather than on the lines a tired lawyer thinks to check.