Bottom line up front: the state bar opinions issued in 2024–2025 (New York, California, and Florida among them) permit lawyers to use generative AI — while holding them to the duties they already have: competence, confidentiality, supervision, and in some circumstances informed client consent. The sharper risk is not an ethics complaint; it is a privilege-waiver argument from opposing counsel. The defensible position is architectural: client confidences are technically prevented from reaching AI tools, so there is nothing to argue about. This is an engineering firm's read for law-firm IT leaders — bring your ethics counsel into any policy decision.
What the opinions actually converge on
Strip away the jurisdictional differences and the 2024–2025 guidance lands on four duties:
- Competence: a lawyer using AI must understand, at a practical level, what the tool does with inputs — including whether prompts are retained or used for training.
- Confidentiality: client information may not be disclosed to a third-party AI service without safeguards. A consumer chatbot that retains conversations is a third party.
- Supervision: AI output must be reviewed like the work of a junior — the sanctions cases that made headlines were supervision failures, not AI failures.
- Consent (situational): several opinions suggest informed client consent before inputting client confidences into tools that retain or train on data.
The privilege problem is sharper than the ethics problem
Attorney-client privilege protects communications that are kept confidential. When privileged material is routed through a retaining, non-confidential AI service, opposing counsel has a ready argument: the disclosure was voluntary and inconsistent with confidentiality, so privilege is waived. Whether that argument ultimately wins is unsettled — and unsettled is exactly where a firm does not want to be, at deposition, about its own conduct.
Note the asymmetry: an ethics inquiry evaluates the lawyer's diligence; a waiver fight evaluates the data path. That is why the durable answer is technical, not procedural.
Outside counsel guidelines are forcing the issue anyway
Corporate clients increasingly write AI restrictions directly into outside counsel guidelines — disclosure of AI use, prohibitions on client data in public tools, and audit rights. Firms that can demonstrate an enforced control answer those questionnaires in one paragraph. Firms with a memo-only policy answer them with hope.
The architecture that ends the argument
- Publish the policy: which tools are approved, what content is prohibited — client identities, privileged communications, deal terms, PII. (Our control-mapped template adapts to a firm in an afternoon; swap the CUI definitions for client-confidence categories.)
- Enforce it at the network: route firm AI traffic through a locally hosted scanning proxy that detects client-matter identifiers, privileged-material markers, and PII in prompts and blocks them before transmission. Scanning happens on the firm's own infrastructure (self-hosted Docker) — no third party receives content in order to check it, which matters, because a cloud-scanning DLP would itself be a disclosure vector.
- Keep the log: a tamper-evident record of allowed and blocked events is the supervision evidence — for the ethics inquiry, the client audit, and the waiver fight that never gets traction because the answer is "the material never reached the tool."
What this looks like at a 50–500 attorney firm
Deployment is a network-level change, not a per-laptop rollout: point the firm's AI tools at the proxy endpoint, and every associate keeps ChatGPT while the firm gains the control. The short answer page covers the common questions (consent, legal-vertical AI tools, monitoring without reading privileged prompts), and the legal industry overview maps the detection patterns to law-firm data types. To see what your attorneys are actually sending to AI tools today, the $499 assessment runs 14 days on your own infrastructure and reports every flagged event — the baseline your managing partner will ask for eventually, produced before it's asked for.