Most attorneys think of AI sophistication as a binary: either you’re using ChatGPT or you’re not. That framing hides the real exposure. Even firms that feel “ahead” on AI typically have six live work-streams they haven’t fully staffed — each with its own malpractice, confidentiality, or competitive risk.
This represents an existential threat for law firms and their clients, and it’s imperative all lawyers and law firms address these issues:
- Lawyer training and oversight. AI tools are only as safe as the person prompting them. Ongoing training isn’t optional — it’s how you catch hallucinated citations and bad output before they hit a filing.
- Vendor diligence on privacy and security. Is the tool your associates are using training on your client data? If you don’t know the answer, you don’t have a policy — you have exposure. This needs continuous review, not a one-time check.
- Client-facing disclosure and consent. Three distinct obligations here: telling clients you use AI tools, warning them against running your privileged communications and work product through AI tools that aren’t provably private and secure, and updating your engagement agreement language to reflect all of it.
- AI in your tech stack. “Vibe coding” and AI-assisted development can meaningfully speed up how fast your own systems get built and maintained — a competitive edge most firms aren’t touching yet.
- AI in security. Law firms are an increasingly attractive hacking target, and legacy antivirus won’t cut it. Next-generation antivirus (NGAV), real-time behavioral detection, and machine-learning/cloud-telemetry platforms (CrowdStrike Falcon, SentinelOne, etc.) are becoming the baseline, not the upgrade.
- AI in marketing. There’s a new visibility battle underway — being surfaced in AI-generated answers is the new SEO, and most firms haven’t started competing there.
None of these are “someday” projects. Each must be treated as an active work-stream with its own risk profile.
Lawyer Training and Oversight
By now, most lawyers have heard of instances of other lawyers being admonished or sanctioned for fake citations in their filings due to AI hallucinations. See for example, Lawyer’s use of “fake and hallucinated” citations gets reprimand from U.S. appeals court. Such risks and problems can be greatly reduced by appropriate, recurring and ongoing lawyer training.
Lawyer training is needed for more than how to properly use AI for writing briefs or other documents. Lawyers need to be able to recognize when AI is being integrated into their email (i.e. Microsoft’s Copilot) or web browser (i.e. Google’s Gemini) or other systems (i.e. practice management, document management, billing systems, videoconferencing and more).
For example, it’s quite common for an attorney to join a videoconference established by his or her client, and it’s also quite common for such a client to have their own “AI Transcription Service” (i.e. Otter.ai). How does an attorney know such use of an AI transcription service is safe, and won’t destroy privilege or confidences? Did the attorney warn the client about the dangers of mishandling the transcription of a videoconference?
This isn’t a hypothetical concern. AI meeting tools like Otter, Fireflies, and Zoom AI Companion function as a third-party sitting in on the conversation, and courts have historically treated third-party access to privileged conversations as a potential waiver event. Otter.ai itself is currently facing litigation alleging it recorded, transcribed, and used the contents of private conversations — including for AI model training — without proper consent from all participants. See Otter.ai Lawsuit Highlights Privacy & Compliance Risks of AI Note-Taking. Compounding the risk, roughly a dozen U.S. states — including California, Florida, Illinois, Maryland, and Pennsylvania — require all-party consent before a conversation can be recorded at all, meaning an AI notetaker joining a call can trigger a wiretap violation independent of any privilege question. See AI Transcription Tools: Privacy, Privilege and Ethical Pitfalls.
Ongoing training is critical to maintaining these issues as top-of-mind for lawyers and their clients.
Vendor Diligence on Privacy and Security
AI systems are powerful, because they constantly train on data. Knowledge is power, and training on data increases the knowledge available to AI systems.
This means all AI systems must train to improve over time. The question is, what information is used to train AI systems? It’s almost a sure bet that if you’re using an AI system without paying for it (i.e. Google’s AI feature in its search engine, or the free accounts of Gemini, ChatGPT or Claude) the AI is being trained on your interaction with it. As one example, OpenAI’s own documentation confirms that free-tier ChatGPT conversations are used to train its models by default unless a user manually opts out, while paid Business and Enterprise tiers carry a contractual guarantee that customer data is not used for training. See Enterprise privacy at OpenAI. Firms should confirm the equivalent terms for whichever AI vendor and tier they actually use — the free-versus-paid line isn’t always where lawyers assume it is.
If an AI trains on your interaction, and that interaction contains privileged or otherwise attorney-client confidential information, such privilege or confidential information is going into the public domain.
Therefore, it is absolutely critical that NO privileged or otherwise attorney-client confidential information be fed into an AI unless you are certain that AI will not train on your data. This is easier said than done, and it requires constant vigilance — and education for the client, not just the lawyer.
Client-Facing Disclosure and Consent
On July 29, 2024, the American Bar Association’s Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, the first formal guidance addressing lawyers’ use of generative AI. It touches competence (Model Rule 1.1), confidentiality (Model Rule 1.6), communication with clients (Model Rule 1.4), candor to the tribunal (Model Rules 3.1 and 3.3), supervisory duties over non-lawyer and lawyer use of AI (Model Rules 5.1 and 5.3), and reasonable fees. Two points from that opinion matter most for client communication: lawyers should obtain a client’s informed consent before feeding that client’s confidential information into a generative AI tool, and the opinion specifically cautions that boilerplate consent language buried in an engagement letter is unlikely to be adequate on its own.
That guidance points to three distinct, ongoing obligations to clients:
Disclosure that the firm uses AI tools. Clients are entitled to know, in plain language, where and how AI is used in the handling of their matter — not as a one-time notice, but as a standing practice that gets revisited as tools change.
Warning clients about their own AI use. Clients increasingly bring their own AI into the relationship — a videoconferencing bot, a personal ChatGPT account, a “smart” email assistant — without necessarily grasping that running privileged communications or work product through a tool that isn’t provably private and secure can waive the very protections the engagement is meant to preserve. Some jurisdictions’ bar associations have already weighed in directly on this; for example, the New York City Bar’s Formal Opinion 2025-6 addresses vetting AI notetakers for retention, training use, vendor access, and deletion rights. Firms should confirm what guidance, if any, their own state bar has issued, since obligations here are set at the state level and can vary. For an example of what a client notice could look like, read this law firm’s post entitled, Warning to Clients About AI Use in Legal Matters.
Updating the Engagement Agreement. Given ABA Formal Opinion 512’s caution against relying on generic boilerplate, engagement agreement language should be specific enough to put clients on genuine notice of how AI is used on their matter and what is expected of them in return, rather than a single catch-all clause.
This is general legal information about a developing area of professional responsibility, not legal advice. Applicable ethics rules vary by state, and firms should confirm current guidance with their own state bar and malpractice carrier before finalizing engagement agreement language.
AI in Your Tech Stack
“Vibe coding” — a term coined by computer scientist Andrej Karpathy in early 2025 — describes telling an AI coding agent what you want a program to do in plain conversational language, and letting the agent write, test, and refine the code, often without the person prompting it fully understanding what’s happening under the hood. See What Is Vibe Coding? A Guide for Lawyers and Legal Teams.
Lawyers and legal operations teams are already using it to build practical, narrow-purpose tools: client intake forms that generate a preliminary engagement letter, side-by-side contract comparison tools that flag and plain-language-explain redlines, interactive training modules, and time-recording utilities. What began as individual attorneys’ weekend experiments has become a legitimate innovation channel even at some of the largest firms. Used deliberately, it’s a genuine speed advantage for building and maintaining firm systems — most firms aren’t touching it yet, which is exactly why it’s a competitive opening.
It’s also a governance blind spot if left unmanaged. Lawyers have been known to build these tools entirely outside firm IT infrastructure — hosted on personal cloud accounts, invisible to the firm’s security and compliance controls until something breaks or a client asks an uncomfortable question. Treat vibe-coded tools the same as any other piece of firm technology touching client data: they need an owner, a security review, and a place in firm inventory before they touch a real matter.
AI in Security
Law firms sit on exactly the kind of data criminals want — financial records, trade secrets, and sensitive personal information about clients and employees — which makes the profession a disproportionately attractive target. Recent survey data puts real numbers on that exposure: in a survey of 500 U.S. law firms, 20% reported being the target of a cyberattack, and 8% reported actually losing sensitive data as a result — while only 34% reported having an incident response plan in place. See The Latest Law Firm Cyberattack Statistics.
Traditional antivirus relies on recognizing known malware signatures — it can’t catch what it’s never seen before. Next-generation antivirus (NGAV) instead uses machine learning and behavioral analysis to flag suspicious activity in real time, even from entirely new attack methods, and increasingly folds in cloud telemetry and identity protection alongside core endpoint defense. Platforms like CrowdStrike Falcon and SentinelOne’s Singularity are the two most prominent examples competing in this space, and both have expanded well beyond antivirus into full endpoint detection and response (EDR), cloud workload security, and identity protection. See Cybersecurity 2026: The Year Ahead in AI, Adversaries, and Global Change. For firms still running legacy, signature-based antivirus as their primary defense, this is no longer a nice-to-have upgrade — it’s baseline coverage against how modern attacks actually work.
Side Note: You May Need to Upgrade Your License to Microsoft Defender Antivirus
Note that Microsoft Defender Antivirus, the tool built into every Windows machine by default, is NOT an EDR on its own — it handles local, pre-execution antivirus protection on the individual device, not the organization-wide detection and response an EDR/NGAV platform provides. Microsoft’s own documentation on Defender for Endpoint describes standard Defender Antivirus as the “next-generation protection component” that must be paired with (or licensed up to) Defender for Endpoint — specifically Plan 2 (as of the date of this article) — to get full EDR capabilities such as behavioral detection, automated investigation and remediation, and threat hunting. See Why you should use Microsoft Defender Antivirus together with Microsoft Defender for Endpoint and Microsoft Defender for Endpoint: features and plans. Many firms assume that because Windows “already has Defender,” they have EDR coverage — they don’t, unless IT has specifically licensed and configured the upgrade. Confirm with your IT professional whether your firm has actually upgraded to Defender for Endpoint Plan 2 (or an equivalent third-party EDR/NGAV product) rather than relying on the antivirus that ships with Windows by default.
AI in Marketing
The way people find a lawyer is changing faster than most firms’ marketing plans. “Generative Engine Optimization” (GEO) — sometimes called Answer Engine Optimization — refers to building content and authority signals so that a firm is actually cited when someone asks an AI tool a legal question, rather than just ranking on a traditional search results page.
The shift is already well underway in the legal vertical specifically. One 2026 analysis found that legal search queries trigger Google’s AI Overviews more than three-quarters of the time — the highest rate observed across any professional services vertical — and that the overlap between a firm’s traditional top-10 search ranking and its actual citation in an AI Overview had collapsed to somewhere between 17% and 38%, depending on the query. See Generative Engine Optimization: How To Make Your Law Firm Visible In AI Answers. In plain terms: ranking well on Google no longer means an AI assistant will mention your firm when a prospective client asks it a question, and the two are increasingly separate games that both need to be played.
That means the metrics that matter are shifting too — from page rank and click volume toward citation frequency and “share of voice” in AI-generated answers. Practically, this rewards firms that structure content as clear, direct, and complete answers to the specific questions real clients ask, rather than dense marketing copy optimized for keywords. Firms that haven’t started adapting content for this are, for now, largely invisible in a growing share of how prospective clients actually search.
Here’s a quick, practical test: try navigating to your own firm’s website with “/llms.txt” added to the end of the domain (for example, yourfirm.com/llms.txt). Proposed in 2024 by Jeremy Howard of Answer.AI, llms.txt is a plain-text file placed at the root of a domain that gives AI crawlers a structured summary of a site’s content and purpose — conceptually similar to how a robots.txt file guides traditional search engine crawlers. See Meet llms.txt, a proposed standard for AI website content crawling. One important caveat: llms.txt remains a proposed standard, and as of this writing none of the major AI providers — OpenAI, Google, or Anthropic — have officially confirmed that their crawlers actually read or rely on it. See What Is LLMs.txt & Should You Use It?. So its absence isn’t proof of anything on its own — but if your firm’s website doesn’t have one, that’s a reasonably reliable sign that no one on your marketing team has turned their attention to AI visibility yet, since firms actively working on GEO tend to pick up this kind of low-effort, low-risk step early. If the file is there, at least someone’s paying attention; if it’s not, treat that as a prompt to ask your marketing team where AI visibility sits on their list.
In Summary
Dealing with AI is a LOT more than simply managing attorney use in the firm. You need to address these six (6) areas in AI now.
Law 4 Small Business (L4SB). A little law now can save a lot later. A Slingshot company.