In July 2024, the American Bar Association's Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512 — the first formal guidance the ABA has issued on a lawyer's use of generative AI.[1] It is not an alarmist document. It does not prohibit AI use. It does something more consequential: it places the compliance obligation squarely on the lawyer and identifies the specific Model Rules that apply.

Eighteen months after the Opinion's publication, most law firms have read it. Fewer have examined what it actually demands from their AI infrastructure choices.

What the Opinion Says

Formal Opinion 512 identifies five Model Rules as principally applicable to generative AI use: competence (Rule 1.1), confidentiality (Rule 1.6), communication with clients (Rule 1.4), candor toward tribunals (Rule 3.3), and supervisory responsibilities (Rules 5.1 and 5.3).

The confidentiality analysis is the most operationally significant. The Opinion states directly: under Model Rule 1.6, a lawyer using generative AI must be cognizant of the duty to keep confidential all information relating to the representation of a client, regardless of its source, unless the client gives informed consent.

The "regardless of its source" language is not rhetorical. It means that the confidentiality obligation applies to the act of transmitting information to an AI system, not just to the AI system's output. The question the Opinion implicitly poses — but does not answer directly — is whether transmitting client information to a third-party inference server is consistent with Rule 1.6.

The State Bar Landscape Is Moving Faster

The ABA issues guidance. State bars issue enforceable opinions that carry disciplinary weight. The state-level picture in 2025 and 2026 is more prescriptive than the ABA's Formal Opinion 512 framework.

Opinion No. 705 of the Professional Ethics Committee for the State Bar of Texas, issued in February 2025, addresses lawyers’ use of generative AI directly and requires caution about entering confidential information into tools whose handling of that data the lawyer does not control.[3] The Texas opinion does not create a categorical prohibition, but it does establish that the lawyer's due diligence obligation includes understanding where data goes when it is submitted to an AI system — not just whether the vendor has a privacy policy.

The Florida Bar's Opinion 24-1, issued January 2024, requires that lawyers prioritise client confidentiality when using AI — a deceptively simple statement that requires lawyers to evaluate each AI tool against a confidentiality standard, not merely an enterprise security standard.

The direction of travel across state bars is towards firm-level governance rather than individual judgement — supervisory duties under Rules 5.1 and 5.3 are the mechanism, and Formal Opinion 512 reads them onto generative tools directly.[2] A firm reading only the ABA guidance is reading the floor.

The Waiver Risk Is Real

In February 2026 the Southern District of New York held, in United States v. Heppner, that material generated through a consumer-tier AI assistant was protected by neither the attorney-client privilege nor the work-product doctrine.[4][5] Two independent grounds carried it: the tool’s terms permitted the provider to disclose user data and to use prompts for training, so no reasonable expectation of confidentiality survived; and the research was not conducted at counsel’s direction. The court expressly left open whether an enterprise product excluding training and offering contractual confidentiality would support a different analysis — while cautioning that contractual protection alone does not establish privilege.

But the ruling's underlying logic is not bounded by the consumer/enterprise distinction. The court's reasoning turned on third-party disclosure: when information is transmitted to a third party's infrastructure for processing, the confidentiality of that information depends on the third party's practices, the terms of service under which the disclosure was made, and the reasonable expectations of the parties — not on whether the disclosure was intentional.

Enterprise AI vendors have responded to this risk with contractual controls: zero-data-retention provisions, data processing agreements, confidentiality warranties. These controls are meaningful. They do not eliminate the structural exposure that comes from transmitting privileged information outside the firm's network.

What Compliant Infrastructure Actually Looks Like

Formal Opinion 512 does not specify an infrastructure standard. It does identify what the standard requires: that all information relating to the representation be kept confidential. Working backwards from that requirement produces a set of infrastructure characteristics that a compliant AI deployment must satisfy.

First, inference must happen within the firm's control boundary. If AI processing occurs on infrastructure the firm does not control, the firm cannot guarantee that transmitted data remains confidential in the way Rule 1.6 requires. Control boundary means either the firm's own hardware or infrastructure over which the firm has contractual and operational control that is not dependent on the vendor's continued compliance.

Second, matter isolation must be architectural, not policy-based. If multiple matters are processed through a shared inference context — even on the firm's own servers — there is a risk that information from one matter can influence or contaminate the context of another. This is not a hypothetical risk. It is how shared inference systems work. Matter isolation that is enforced at the infrastructure level, rather than through application-layer controls, is the only architecture that provides genuine separation.

Third, audit logging must be comprehensive and immutable. Opinion 512's supervisory obligations require that lawyers can account for what AI systems did during a representation. That requires logging that captures every AI action at the matter level, that cannot be altered after the fact, and that is reviewable by the responsible attorney.

These are not aspirational standards. They are the infrastructure translation of existing ethical obligations. The firms that build AI deployments around them will face fewer compliance problems. The firms that adopt cloud AI tools and hope that contractual protections are sufficient will eventually discover where the gap is.