The Model Rules of Professional Conduct were written long before anyone had to think about a language model. They were written on the understanding that confidentiality is the foundation of the relationship and that a lawyer remains personally responsible for how their tools and their assistance handle client information. That premise transfers to AI without amendment — which is precisely the problem for vendors whose answers were written for a different buyer.

Rule 1.6 — confidentiality, and what "reasonable efforts" costs

Rule 1.6(a) prohibits revealing information relating to the representation without informed consent. Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorised disclosure. Comment 18 makes the standard a balancing test — sensitivity of the information, likelihood of disclosure absent additional safeguards, cost and difficulty of those safeguards, and the extent to which they would impair the representation.

Two things follow. First, the analysis is fact-specific: what is reasonable for a routine lease is not what is reasonable for a cross-border investigation. Second, it moves over time. Safeguards that were once expensive and difficult are neither, and a vendor's assurance that everyone else is doing the same thing is not one of the enumerated factors.

Rule 1.1 — competence includes the tool

Comment 8 to Rule 1.1 requires a lawyer to keep abreast of the benefits and risks of relevant technology. Applied to AI procurement this is not a general exhortation to be modern. It means that choosing a system without understanding where client data is processed, what it is retained for and what the model does with it is a competence question before it is a privacy one.

The practical consequence: "our IT team evaluated it" is not a complete answer, because the duty sits with the lawyer responsible for the matter.

Rules 5.1 and 5.3 — supervising something that is not a person

Rule 5.1 covers supervision of subordinate lawyers; Rule 5.3 covers nonlawyer assistance, including outside vendors. The obligation is to make reasonable efforts to ensure that the assistance behaves compatibly with the lawyer's own professional obligations.

Formal Opinion 512 applies that framework to generative tools directly, and the interesting consequence is structural. Supervision of a person can be exercised through instruction and review after the fact. Supervision of a system has to be exercised through the system: a gate the output stops at, a record of who cleared it, and a version the approval attaches to. A platform with no gate is a platform on which the rule cannot be satisfied by anything except vigilance.

Rule 1.4 — the conversation you may owe the client

Rule 1.4 requires the client to be reasonably informed and to be consulted where informed consent is needed. Opinion 512 is explicit that disclosing a client's confidential information to a generative AI tool requires informed consent — which means the firm has to be able to describe, accurately, what the tool does with it.

A firm that cannot answer "where does it go, how long does it stay, who else can reach it" cannot obtain informed consent, because there is nothing to be informed about.

Rule 1.5 — the fee question AI created

Rule 1.5(a) prohibits an unreasonable fee, and Formal Opinion 93-379 remains the clearest statement of what that means in billing practice: no billing more time than was spent, no billing two clients for the same hour, no charging overhead as professional time. Opinion 512 extends the reasoning to generative tools — efficiency gained is not time that may be billed.

That is a systems requirement, not a policy one. If a platform records agent work in the same units as attorney time, the distinction depends on someone remembering to make it every day for years.

What this means for vendor selection

Four questions cover most of the ground, and a vendor that cannot answer all four in writing has told you something useful.

  • Where is client data processed, by whom, and under whose retention policy?
  • Is there a supervision gate the output must pass, and is the approval recorded against a version?
  • Can the firm produce a complete record of a matter's AI activity without the vendor's involvement?
  • Is agent work recorded separately from attorney time, by the system rather than by convention?

On-premise deployment answers the first structurally and makes the third trivial. It does not answer the second or the fourth on its own — those are product questions, and they are worth asking of every vendor, including the ones that run locally.